Privacy Policy
Last updated: September 2026
This Privacy Policy describes how Belle (the "Operator", "we") collects, uses, processes and protects personal data when you use our app and web platform (the "Services"), in accordance with the Protection of Privacy Law, 5741-1981 (including Amendment No. 13), the Protection of Privacy Regulations (Data Security), 5777-2017, and the Protection of Privacy Regulations (Transfer of Data to Databases Abroad), 5761-2001.
The Policy applies to customers, to providers and applicants to join, to persons a service was booked for, and to website visitors. The Operator is the "controller" of the Platform's databases in respect of the purposes it determines; independent providers may be separate controllers of professional records they keep themselves (section 10). Privacy, rights and information-security requests: privacy@belle.win. The Operator's privacy protection officer can be reached at that address. In the event of a conflict between this Policy and the terms of use on anything concerning processing of personal data – this Policy prevails, subject to law.
Principles: we collect data for defined and explained purposes and limit it to what is necessary; we do not sell personal data; health data, home address, live location and identity and bank documents receive enhanced protection and restricted permissions; customer data is disclosed to the provider only to the extent and at the time required to perform the booking; and providers and processes are chosen with security and privacy by default in mind.
Notice under section 11 of the Protection of Privacy Law: you are not legally obliged to provide us with data, and doing so depends on your will and consent; however, without identification, contact, address and payment details we cannot open an account, verify identity, place a booking, pass an address to the provider, collect payment, issue a payment document or provide support, and without a health declaration the provider may refuse to treat. The purposes for which the data is collected and the recipients to whom it is disclosed are set out in sections 2 and 3 below. Consent to processing necessary for the booking is given as part of the service request; non-essential consents – providing health data, publication of images, marketing mailings, location permission – are requested separately. Consent to future processing may be withdrawn, without affecting the lawfulness of processing already performed and without requiring deletion of data there is a legal duty or need to keep.
1. The Data We Collect
We collect personal data needed to operate a two-sided marketplace for services:
Account and profile data: name, email address, phone number, profile picture, gender (to address you in the appropriate form), language, preferences, account identifier, account status, consent history and authentication means (including sign-in through an external identity provider such as Google or Apple, from which we receive a name, email, identifier and picture – not your password).
Location and address data: the exact physical address provided for at-home service visits, floor, arrival instructions, entry code and parking, and the device's location where you have allowed it.
Payment and financial data: credit or debit card tokens, the payment method type and its last four digits, the result of a pre-authorisation or charge, amount, tip, refund and chargeback; bank account details (for providers; the account number is stored encrypted and displayed only in part) and transaction history, handled securely through licensed payment processors that meet the PCI-DSS standard. We do not store raw credit card numbers or CVV on our servers.
Service data and health notes: appointment history, ratings, reviews and optional medical disclosures (for example skin sensitivity, allergies, pregnancy, medication, previous treatments, patch test, a medical event) provided directly to enable safe treatment. The health declaration is "data of special sensitivity" as defined in the Protection of Privacy Law following Amendment No. 13, and is collected only with your explicit consent. We ask you to provide only data necessary for the treatment; do not provide a full medical diagnosis or medical file.
Technical and usage data: IP address, device identifiers, browser type, operating system, app version, date and time, pages and clicks, errors and crashes, language and time zone, collected through essential cookies, mobile development kits and the usage-tracking and session-recording tool set out in section 7.
Fraud and security signals: sign-in attempts, changes of payment method, an unusual device, suspicious transactions, complaints, blocks and verification results from the payment processor.
Correspondence: messages in the Platform chat between customers and providers and with support, WhatsApp messages you send back to us, support requests, files and images you attached, and resolution records.
Data about providers and applicants: identity card and photo, dealer/company number, business name and address, dealer type, training certificates and licences, insurance certificates, tax certificates (bookkeeping, withholding), portfolio, declarations (including a self-declaration of no legal restriction and no convictions – we do not receive information from the Criminal Register and do not require an extract), availability data and service areas, location during an active appointment (to update the customer on arrival), bookings, cancellations, lateness, ratings, complaints, earnings through the Platform, commission, refunds and reserve, and details of authorised assistants where provided.
Data about others: when a customer books a service for another person or for a group, we collect the name and health declaration of the service recipient; the person booking is responsible for obtaining their consent to the disclosure of the data, in particular health data.
Referral data: referral code, the identity of the referrer and the referred person and the credit balance, for the referral programme.
Sources of the data: directly from you; from the other party to the booking (confirmation, arrival report, complaint, rating); from the payment processor; from identity providers (Google, Apple) according to your permission; from a public register or the issuer of a document for verifying a business, certificate or licence; from your device and browser; and from an insurer, adviser or authority in the event of a complaint, claim or investigation, according to law.
2. How We Use the Data
We process personal data for the following purposes:
Providing the service: connecting customers with providers (including automatic matching by proximity, availability, rating and performance history), forming a direct contract between the customer and the provider, executing bookings, and calculating and processing split payments (service price, platform fee, tip, commission, refunds).
Safety and verification: verifying users' identity, verifying providers, certificates, insurance, tax and bank account, managing ratings and reviews, and enforcing the terms of use.
Protecting location privacy: the customer's full street address is passed to the provider only shortly before the appointment window, according to the period set by the Operator and displayed in the app. Until then providers see a general geographic area only.
Communication: sending transaction confirmations, appointment status alerts, reminders, arrival updates, payment documents and critical safety updates.
Legal compliance: meeting accounting, tax and regulatory obligations under Israeli law, including issuing payment documents in the name of providers, requesting allocation numbers where required, and retaining the documents.
Fraud prevention and enforcement: identifying duplicate accounts, fictitious bookings, circumvention of the Platform, unjustified chargebacks, abuse, harassment, intrusion and security incidents; recording late cancellations and no-shows and restricting bookings as a result.
Documenting consents: keeping the text of the documents you accepted, the time of acceptance, the version, the account identifier and a digital fingerprint of the text, as evidence of consent.
Support and complaint handling: reviewing correspondence and booking data to handle requests, complaints, mediation, preserving evidence, safety incidents, claims and insurance proceedings.
Service improvement and statistical analysis: measuring performance, statistical research and testing, on the basis of aggregated or anonymised data wherever possible.
Marketing mailings: only with your explicit consent under section 30A of the Communications (Telecommunications and Broadcasting) Law, 5742-1982, and you may unsubscribe at any time; health data will not be used for marketing segmentation.
Organisational changes: due diligence and disclosure to an acquirer in the course of a merger, investment or sale of the business, under confidentiality and appropriate safeguards.
Any further compatible purpose brought to your attention and permitted by law.
3. Sharing the Data
We share data only to the extent required to operate the Platform:
Between the parties in the marketplace: sharing the customer's relevant contact details, address (at the time stated in section 2) and health declaration with the assigned provider, to enable the home visit; and sharing the provider's name, business name, dealer/company number and the business contact details required for a distance sale transaction, picture, rating, categories and location en route with the customer. The provider is contractually bound to use the data for that treatment only, not to copy it, not to market with it and to delete it afterwards.
Payment processors: sharing payment details with a duly licensed payment processor, whose identity is shown on the payment screen, for pre-authorisation, charging, split settlement, refunds and transfers to providers, and for customer identification (KYC), fraud prevention and financial compliance required of it by law; the payment processor may also process data as an independent controller under its own terms.
Third-party infrastructure providers: cloud hosting and infrastructure (Google Cloud – application servers and file storage; Vercel – website hosting), product analytics and session recording (PostHog - data hosted in the European Union), email services (Resend), push notifications (Apple's and Google's notification services via Expo), map and address services (Google Maps), the payment-document issuing system and customer-support software, acting as data processors ("holders") under a contractual commitment to confidentiality and data security, and receiving only what they need.
Competent authorities: disclosing data where required by law, a court order or a law-enforcement investigation concerning safety threats or criminal conduct, including the Tax Authority, the Privacy Protection Authority, the Consumer Protection Authority, the Ministry of Health and the police. We examine authority and scope where possible, and do not disclose data on the basis of an informal request with no basis.
Error monitoring and crash reporting: a third-party error-reporting service (Sentry) that receives error and crash reports from the website and the app, for the purpose of detecting and fixing malfunctions. The reports pass through automatic filtering that removes names, addresses, phone numbers, email addresses and authentication tokens before they are sent. The service acts as a data processor under a contractual commitment to confidentiality. The server logs themselves are kept in our cloud infrastructure and are not passed to this service.
WhatsApp communication: operational messages about appointments - confirmation, reminder, cancellation and notice of a new chat message - are also sent via WhatsApp. Delivery is through Meta's WhatsApp Business Platform, and the conversations are managed in a shared Chatwoot inbox. Both services act as data processors under a contractual commitment to confidentiality, and receive the recipient's name, phone number and the content of the messages - including messages the user sends back to us. Unlike personal WhatsApp conversations, these business messages are not end-to-end encrypted, and therefore the customer's exact address is never included in them; it is disclosed only inside Belle, after authentication.
Insurers and advisers: the Operator's insurers, legal advisers, accountants, tax advisers and auditors, in the event of a claim, a safety incident, an audit or a regulatory demand, and subject to confidentiality.
The provider's insurer: following a damage event, and at your request, we will give you the details of the provider and its insurer, and give the provider the details of the event, for the exercise of rights under law.
Transfer of the business: in the course of a merger, investment, sale of the business or reorganisation, to an investor, financier, acquirer or the absorbing entity, in due diligence under confidentiality and subject to the continued application of this Policy.
Transfer outside Israel: our cloud, hosting, monitoring, analytics and messaging providers operate, in part, outside Israel (including in the United States and the European Union). Such transfer is made in accordance with the Protection of Privacy Regulations (Transfer of Data to Databases Abroad), 5761-2001 – to countries ensuring an adequate level of protection or subject to a contractual commitment of the recipient to comply with the conditions of Israeli law, including limited purposes, confidentiality, security, deletion, assistance with rights, incident reporting and restriction of onward transfer. You may contact us for general information on the categories of countries and providers.
We do not sell personal data, do not pass it to data brokers and do not pass it to third parties for their own marketing purposes.
4. Data Security and Protection
We apply organisational, administrative and technical security measures - including SSL/TLS encryption, restricted access controls and secured server environments - to protect personal data against unauthorised access, loss or misuse. The database is managed according to the security level applicable to it under the Protection of Privacy Regulations (Data Security), 5777-2017, bearing in mind that it includes data of special sensitivity: permission management and authentication, encryption in transit and at rest as needed, separation of environments, backups, logs and monitoring, updates, vendor management and staff training; bank account numbers are stored encrypted; access to health data, address, identity and bank documents is limited to role holders on a need-to-know basis; and operations on data are logged. Payment secrets are not stored with us beyond the token. No system is completely immune, and therefore we do not promise absolute security. In the event of a suspected security incident we will investigate, contain, preserve evidence, remediate and assess risk; a serious security incident will be reported to the Privacy Protection Authority and to the data subjects in accordance with our legal duties, in a notice that will include the type of data, the implications, the steps taken and recommendations. Providers are required to secure the device on which the app is installed and to report to us within 12 hours any exposure of customer data. The user is responsible for keeping the verification code and device safe and for being alert to impersonation; Belle will never ask for a full password or CVV in a message. Responsible disclosure of a security vulnerability should be sent to privacy@belle.win, without intrusive testing and without accessing data.
5. Your Privacy Rights
Under the Protection of Privacy Law (and consistent with international standards), the user has the following rights in respect of personal data about them:
Right of access: you may request access to the personal data we hold about you, yourself or through a person lawfully authorised.
Right of rectification: you may ask us to correct or update data that is incorrect, incomplete, unclear or out of date.
Right of deletion and account closure: you may delete the account through the app settings or by contacting support, subject to data-retention obligations under law (for example tax records, consent records, fraud prevention and records needed for defence against claims). A deleted account can be restored within the period displayed in the app from the date of deletion; after that the personal data is deleted permanently, except data that must be kept.
Right to object to mailings and withdraw consent: you may withdraw consent to advertising messages at any time (unsubscribe via the link, the settings or by contacting us; unsubscribing does not apply to operational messages), revoke location permission in the device settings, and withdraw consent to publication of an image for future use; withdrawing consent does not affect the lawfulness of processing performed before it.
How to submit a request and timelines: requests to exercise rights should be sent to privacy@belle.win or through the app, and should include name, contact details, the type of request and details for verification; do not send a copy of an ID document unless requested through a secure channel. We will respond within 30 days or within the period set by law. We may require reasonable identity verification, refuse a request that infringes the rights of another or is prohibited by law, and explain the decision. You may also lodge a complaint with the Privacy Protection Authority or approach a competent court.
Automated decisions: the matching mechanism, the display order of providers (by category, availability, area, distance, rating, completion of bookings, cancellations, response speed and preferences), the recording of repeat cancellations, booking restrictions and fraud detection are based on automated processing. A sponsored result, if displayed, will be marked. A significant action such as a permanent block is reviewed by a person, and you may contact support to clarify or appeal a decision that affected you. We make no medical decision on the basis of an algorithm.
6. Data Retention
We retain personal data for as long as the account is active, or as required for the operational purposes set out in this Policy, resolving disputes and meeting legal or tax retention obligations. Default periods: payment documents, bookings, statements and accounting records – 7 years from the end of the relevant tax year under tax law; consent records for the legal documents – for the limitation period after the account is closed; health declaration – visible to the provider only around the booking, hidden from the ordinary interface afterwards, and deleted within 12 months of the last appointment, unless required for safety, insurance or defence against a claim – in which case it is kept in a restricted, encrypted archive for up to 7 years; chat conversations and support requests – 24 months from the end of the appointment, and up to 7 years in a complaint or dispute; system and security logs – up to 12 months, and longer for an incident or investigation; provider location during an appointment – deleted at the end of the appointment, with arrival/completion points kept up to 90 days or up to 7 years in a dispute; marketing consents and unsubscriptions – as long as the marketing continues plus 7 years to prove compliance; provider documents (identity, tax, insurance, training) – for the term of the engagement plus 7 years; an applicant not accepted – 24 months. At the end of the period the data is deleted, destroyed, de-identified or anonymised, unless there is a legal hold, an investigation, a claim or a new obligation. Backups are deleted in the backup cycles and not always immediately, but access to them is restricted and the data in them is not used for a new purpose.
7. Cookies and Analytics
7.1. The website uses essential cookies, such as a sign-in cookie (an encrypted session identifier that keeps you signed in) and a language-preference cookie. These cookies are required to operate the website and do not require consent; you may delete them in the browser settings, after which you will need to sign in again. In addition, the website uses the usage-tracking tool described in section 7.3.
7.2. The website does not use advertising or social-network cookies, and does not share browsing data with advertising networks. Should we add in the future other non-essential cookies not described in this section - they will be activated only after your consent, through a choice mechanism displayed on the website, and this Policy will be updated.
7.3. Usage tracking and session recording: to understand how the service is used and to improve it, the website and the app use a usage-tracking and session-recording tool (PostHog, with data hosted in the European Union), for internal use only. The tool records the pages visited, clicks and a replay of the session, and once you sign in this data is linked to your account. Everything typed into fields is masked in the recordings. The data is not sold or shared with advertisers, and recordings are kept for a limited period of 30 days. PostHog acts as a data processor under a contractual commitment to confidentiality.
8. Minors
The Services are intended for persons aged 18 and over. We do not knowingly collect data about minors and do not knowingly open an account for a minor, except the name and health declaration of a minor for whom a parent or guardian booked a service, which is provided by the parent/guardian and under their responsibility, to the minimum extent necessary. We will not use data about a minor for targeted marketing and will not publish their image without the guardian's explicit consent. If we learn that data was collected from a minor without authority, we will delete it or regularise the consent; a parent wishing to delete such data should contact us.
9. Recordings, Correspondence and Images
9.1. Chat conversations on the Platform are stored and may be read by the Operator's staff for safety, complaint investigation, prevention of fraud and circumvention, enforcement of the terms of use and compliance with law. Phone calls with support may be recorded after notice, and will be used for quality, evidence and limited training.
9.2. We do not record the treatment itself, and we do not allow either party to record or publish the other without consent. A customer's image, face, body or treatment result ("before/after") will not be published by Belle or by the provider without separate, documented consent, specifying purpose, channel, duration and whether the image is anonymous; you may refuse without affecting the service, and withdraw consent for future use. It may not be possible to remove a copy already published by a third party, but we will act reasonably to remove what is within our control.
10. Provider Data – Special Provisions
10.1. Provider data is collected for verification, managing the engagement, matching bookings, collection and payment, issuing payment documents in their name (including name, address, dealer number, amount, VAT and allocation number), safety, fraud prevention, legal compliance and handling claims, and is disclosed to customers (name, business name, dealer/company number, business contact details, picture, rating, categories and location en route), to the payment processor, to infrastructure and messaging providers, to the payment-document issuing system, to an accountant and the Tax Authority according to law, to insurers, advisers and authorities under law. ID number, bank account, tax documents, full policy and private address are not published to customers, except a detail that must be disclosed or that was chosen as the business address.
10.2. The provider's location is collected only during an active appointment, to update the customer on arrival, and is not collected outside it; there is no continuous tracking.
10.3. The self-declaration of no legal restriction and no convictions is not information from the Criminal Register, is not disclosed to customers and is kept under restricted permission.
10.4. Performance data (confirmed bookings, cancellations, lateness, ratings) is used for ranking, safety and operations; declining a request not yet confirmed will not on its own be used as a measure for a sanction.
10.5. The provider is a "holder" of customer data passed to it through the Platform, and is bound under the engagement agreement to use the data for the treatment only, to a prohibition on copying, storing and marketing, and to deletion after the treatment. To the extent the provider keeps its own customer records for its business – it is the controller of them, responsible for giving its own privacy notice, for security and for responding to rights; Belle does not control independent processing outside the Platform, but will act against a breach that comes to its knowledge. A complaint about unauthorised use should be sent to privacy@belle.win.
10.6. A provider may request access to and correction of data about them; data about customers or about the Operator's systems will not be disclosed in such a request.
11. Officer, Databases and Documentation
Belle periodically examines whether its databases require registration, notification to the Privacy Protection Authority or the appointment of a privacy protection officer under Amendment No. 13 to the Law, considering the number of data subjects, the types of data and the scope of activity, and maintains a database definitions document, a security procedure, permission and vendor management, incident documentation, training and risk surveys in accordance with law. Requests to the officer: privacy@belle.win.
12. Changes to the Policy
We may update this Policy from time to time due to a change in law, technology, a provider, a service or a risk. The updated text will be published on the Platform with an update date and version, a material change will be brought to the attention of a registered user by notice in the app or by email at least 14 days before it takes effect (unless required immediately for compliance or security), and new consent will be requested if a new purpose requires it. Previous versions are kept for documentation. Continued use after the update constitutes agreement to it.
13. Contact Us
If you have questions, data inspection requests, or privacy concerns, contact our privacy protection officer at:
privacy@belle.winRequests not about privacy: support@belle.win. Please state the subject of the request without sending medical information or an ID document through an unsecured channel; we will contact you to complete verification where needed. Database controller: Belle. In the event of a conflict between the Hebrew version and the English version, the Hebrew version prevails.
Annex – Data Categories, Purpose, Recipients and Retention
- Account and contact – sign-in, booking, support – cloud, messaging, support – while the account is active + up to 7 years as needed
- Address and arrival – performance and safety – the provider (close to the appointment), maps – the booking + a period for disputes
- Health – suitability and safety – the provider, a limited team, an insurer in an incident – visible around the booking; 12 months; restricted archive up to 7 years if needed
- Payment – charging, refunds, fraud – the payment processor, bank – per law and disputes; Belle does not store a full card
- Payment documents – reporting and retention – the provider, the issuing system, the Tax Authority – 7 years under tax law
- Live location – arrival and safety – the other party to the booking – during the booking; limited points up to 90 days
- Support, chat and complaints – resolution, evidence, insurance – the parties, advisers, insurer – 24 months; up to 7 years in a complaint
- Logs and security – security, fraud, malfunctions – cloud, Sentry (after filtering) – up to 12 months
- Usage and session recordings – understanding and improving the service – PostHog – recordings: 30 days
- Marketing – mailings and measurement – messaging – until unsubscribe + 7 years of records
- Provider documents – verification, tax, insurance – staff, advisers, the payment processor – the engagement + up to 7 years