InPlace

Legal

Privacy policy

The same policy shown inside the system, in English. Section 3 describes what happens at the model provider in the provider’s own terms, not as an undertaking by the operator. The Hebrew version governs.

1. What is collected, and why

Account details: name, email address, telephone (optional) and role — for identification, permissions and sign-in. Business data: suppliers, orders, invoices, payments and documents the customer uploads — in order to provide the service itself. Activity logs: sensitive actions are written to an audit log with the identity of whoever performed them and the reason — for security and accountability. Technical data: sign-in tokens and push notifications on the device — for operation. The legal basis for processing: performance of the engagement with the customer, and the user’s consent on joining.

2. Who processes the data

The data is stored and processed by the sub-processors the service uses: Supabase (database, authentication and file storage), OpenAI (automatic interpretation of the content of uploaded documents), Cloudflare (application hosting), Resend (operational email) and Sentry (error reporting). The operator does not sell personal information and does not use it for advertising.

3. What happens at the model provider

When a document is sent for automatic interpretation, its content reaches OpenAI. The details below were checked against the provider’s official terms on 24.08.2026, and they describe what the provider says — not an undertaking given by the operator in its place.

Training: under the provider’s terms, data sent through the API is not used to train models unless the organisation has explicitly chosen to share it. The operator has not chosen that. Retention: the provider may retain input and output for up to 30 days in order to provide the service and detect abuse, and for longer where the law requires it or where it is needed to protect the service or a third party from harm. Human review: abuse logs may include the text itself, and under the provider’s terms they are accessible to its authorised employees and to third-party contractors bound by confidentiality, for the purpose of abuse review only.

What the system does, and what carries no promise: on every call the system asks the provider not to store the response for later retrieval (store: false). That is a request in the provider’s interface and not an undertaking by it, and it does not prevent the abuse logs described above. A zero-retention arrangement with the provider requires prior approval and a separate agreement; while no such agreement exists, the operator does not promise zero retention.

Where processing happens: no regional restriction has been configured with the provider, so processing and temporary storage there may take place outside Israel, including outside the European Union. Israel is not a supported region at the provider. Even on region-restricted plans, system data and metadata may leave the region.

4. Customer separation and security

Each customer’s data is separated at the database level (row-level security by organisation), access is encrypted (TLS), sensitive actions require a fresh password check, and files are kept in a private bucket whose access is restricted to the organisation alone.

5. Retention and deletion

Financial records are kept for the duration of the engagement and in accordance with record-keeping obligations under the law. Deletion of a financial record is a “soft delete” that preserves audit traceability. On ending the engagement you may request a copy of the data and deletion of whatever there is no legal obligation to keep.

6. Your rights

Under the Israeli Protection of Privacy Law, 5741-1981 (as amended by Amendment 13), you have the right to review the information collected about you, to request correction of incorrect information, and to request deletion subject to obligations under the law. To raise a matter — contact the business that invited you, or the service operator.

7. Cookies and local storage

The service uses browser local storage to manage sign-in and to work offline (receipt drafts and photographs waiting for a connection). No advertising cookies and no third-party tracking are used.

Operated by In Place, HaRotem 14, Kfar Adumim, Israel. Registration number 036689081. Telephone +972-54-254-7074.