Privacy Policy
This is a business-to-business service, for businesses only. Hagog International is a wholesale importer and does not sell to private consumers. This policy explains what information the platform collects, why it is used, who processes it alongside us, and what your rights are.
The controller of the information is Hagog International, a wholesale importer of children's bicycles, scooters, ride-ons, helmets and spare parts, operating from Baqa al-Gharbiyye since 1976. Contact: phone 04-6383380, WhatsApp 050-8256676, email office@hagog.co.il. Registered name: Hagog International Ltd., company no. 511437386, P.O.B 168, Baqa al-Gharbiyye 30100.
This policy covers the whole Hagog International website: the public pages, the catalog, the public showroom screen, the wholesale access application form, the customer portal behind sign-in, and the service messages we send you by email and WhatsApp.
The policy is written in Hebrew and the Hebrew text is the binding version. The English and Arabic versions are provided for your convenience.
The service is for businesses only
The platform serves businesses — bicycle shops, chains and resellers. The information we collect is business information and the details of the people who act for the business (name, phone, email, role on the account). We do not open accounts for private individuals and we do not sell to end consumers.
The service is not intended for minors. We do not knowingly collect information about anyone under 18, and if such information is found it will be deleted, subject to the audit-trail limits described below.
What we collect
Two public forms. The request-access form collects the business name, the contact name, an email and a phone, and sometimes a city and a business type. The contact form collects the business name, the contact name, an email, an optional phone and the company or authorised-dealer number (ח.פ.), and a copy of it is also emailed to the office. In both cases the enquiry is stored with us as a prospective-customer record and passed to a sales rep; it does not create an account and gives no access to the system. The tax number is currently kept as a note on the enquiry, and a rep re-keys it when the account is opened.
A browse seat (prospect). A sales rep may give an applicant who has not yet been approved a browse seat: sign-in with the same email address (a browsing seat can only be opened on an email address), base prices only, and a quote pad that cannot place an order. Granting the seat is written to the audit log. The quote is sent through a WhatsApp link to the rep — meaning the content of the quote passes through your own WhatsApp app.
The company account and its users. For the account we hold the company name, phone, tax number, customer number, business type, the assigned rep, the pricing tier or special prices attached to the account, and the agreed assembly charge. For each user we hold a name, an email and/or a phone (at least one — these are the sign-in identifiers), the role on the account, the preferred language, the email and WhatsApp notification preferences, and whether the user is active or disabled.
Delivery addresses. An account can hold several delivery points: label, street and number, city, postal code, and the name and phone of a contact at the delivery point.
Orders. Each order holds the order number, the item lines (product, colour or a mixed-colours instruction, quantity), the unit price fixed at the time of the order and the list price at that moment, the assembly option and its charge, any approved overall discount, the order total, the requested delivery date, any special notes you wrote, the delivery address chosen, and who submitted the order — including the identity of the staff member if it was submitted on your behalf.
Carts and drafts. The cart is stored on our server rather than in your browser, so a large order can be built over several days. Alongside your own cart we keep drafts that a rep or an administrator builds for the account, and temporary working copies created when an existing order is opened for editing.
Sign-in and session data. For every sign-in code request we store the identifier typed (an email, or a phone in international format), the channel used, an encrypted hash of the code, the number of attempts and the expiry. For every live session we store a hash of the renewal token, a device fingerprint (a hash of the browser and language), the browser string, the IP address, the last-active time, the expiry, and the reason the session was ended, if it was.
Audit log and status history. The system records material actions: successful and failed sign-ins, changes to roles and sign-in identifiers, account creation and joining invitations, price and tier changes, special-price requests and decisions, order edits, the start and end of acting on a customer's behalf, and every order status change — with who did it, when, and the values before and after.
In-app messages. Each item in your inbox stores the event type, the parameters the text is built from, an internal link where there is one, and when it was read. The message text is not stored ready-made; it is rendered in the reader's language at the moment of display.
Price negotiation records. When a rep asks for a non-standard price on an order line we store the requested price, the rep's justification, any counter-offer from an administrator, and the decision. These records are internal and are not shown to the customer.
Card clearing. Card clearing through the system is not in use, and the system does not take card details. [[NEEDS OWNER: Is card clearing through the platform actually in use, or is the terminal not yet live?]]
Business documents. Invoices, quotes, delivery notes and product sheets created or uploaded for the account are stored and linked to it (and sometimes to a specific order).
What we do not collect. The site carries no advertising tools, no social-network pixels and no third-party traffic analytics; we do not collect location, we do not buy customer data from outside sources, and we do not store card details.
Why we use the information, and the legal basis
To consider applications for a business account, to get back to you, and to open the account when the application is approved.
To run the account: to work out the price that applies to you (base price, tier, contract price or special price), to show the catalog according to your permission, and to keep your cart.
To handle orders: approval, warehouse picking, delivery, and producing documents and printouts.
To communicate with you: sign-in codes, joining links, order confirmations, notices of a change or a cancellation, and system messages — through the channels you chose in your preferences.
To keep the service secure: rate limiting, preventing account sharing, and detecting misuse of sessions.
To meet accounting and legal obligations and to keep the commercial record of the transactions between us.
Legal basis. The information is given with your consent when you fill in the form and use the service, and it is needed for the business relationship between us and to meet our obligations under the law, all in accordance with the Israeli Privacy Protection Law, 5741-1981, and its amendments. You are not legally obliged to give us information, but without the details requested we cannot consider an application, open an account or supply orders.
No automated decisions. We do not make business decisions by automated processing alone; account approval, special prices and order approval are made by a person. We do not sell, rent or pass information to third parties for advertising purposes.
Passwordless sign-in, codes and sessions
Sign-in is passwordless: you type an email or a phone number and receive a one-time code by email or WhatsApp. The code is valid for ten minutes, dies after five wrong attempts, and at most three codes may be requested for the same identifier in any fifteen minutes (and at most ten a day over WhatsApp).
The system never stores the code itself, only an encrypted hash of it. The same principle applies to session tokens and to joining links — the original value is sent to you and is not kept in the database.
Protection against customer enumeration. When an identifier the system does not know is typed, the answer on screen is exactly the same as the answer for a known one, and a decoy record is even written that can never authenticate. The sign-in screen therefore cannot be used to find out who our customers are. One exception: if the identifier belongs to an access application still being handled, the screen says the application is under review and shows our rep's contact details — and nothing at all about the applicant.
Sessions and devices. The access token is valid for twelve minutes and renews itself; the session itself ends after twelve hours without activity, and in any case ninety days after sign-in. Up to three active devices are allowed per user, and across a company account up to three times the number of active users; beyond that the session unused for longest is ended. Re-use of a token that has already been rotated ends the session, as a defence against token theft. Signing out ends the session.
The joining link. An account is opened by a personal, single-use link valid for seven days. Anyone holding that link can complete the joining process until it is used or expires — please do not forward it.
When a staff member acts on a customer's behalf
A sales rep or an administrator can shop for a customer: see the storefront at your account's prices and build an order for it. The capability is limited to the storefront; on the management, warehouse and editing screens the staff member always appears as themselves.
Every such action is recorded: its start and end are written to the audit log, the order keeps the identity of the staff member who actually submitted it alongside the account, and a permanent banner on screen names the company being acted for.
Limits: only one account can be acted for at any moment, the permission expires after one hour, and warehouse staff can never act on a customer's behalf.
Prices and who sees them
A visitor who is not signed in sees no prices at all; a browse seat sees base prices; an approved customer sees the prices of their own account; the public showroom screen shows no prices. Your account's special prices are visible only to the users of your account and to authorised staff, and internal records such as special-price requests are never shown to the customer.
The audit trail and what it means for a deletion request
The audit log and the order status history are append-only records: the database itself blocks any update or deletion of these rows, not merely the application code. Clearing records and stored documents can likewise only be created and read.
A deletion request therefore cannot erase order history and audit records — they are the commercial record of the transactions between us and we are required to keep them. Instead of deletion, a user is disabled and can no longer sign in, and an account is moved to the archive. Products and colours are likewise withdrawn rather than deleted, so old orders stay faithful to what was actually bought.
What is deleted: the contents of your cart, unused sign-in codes — removed immediately when a sign-in identifier is changed — and live sessions, which are ended when you sign out or when a user is disabled. To delete messages from your inbox, or to end sessions on other devices, ask us and we will do it; there is no self-service control for either at present.
Third parties that process information for us
We do not sell or rent information. The following service providers process it for us, each for the purpose it is needed for:
Supabase — the database and storage service that holds all platform data, including account details, orders, audit logs and product images. [[NEEDS OWNER: In which region or country are the Supabase database and storage hosted?]]
The hosting provider of the application itself, through which traffic to the site passes. [[NEEDS OWNER: Who hosts and deploys the application (Vercel, for example), and in which region does it run?]]
Amazon SES (Amazon Web Services) — the email delivery service. [[NEEDS OWNER: In which AWS region is the SES sending identity configured?]] It receives the recipient's address and the message content: sign-in codes, joining links, order confirmations with their line detail, change and cancellation notices, and the alert to the office about a new enquiry from the website.
Twilio — WhatsApp message delivery. It receives the phone number and the message content or the template variables: sign-in codes, joining links and order notifications.
Google Cloud Translation — machine translation of catalog text (product names and descriptions, category and colour names) from Hebrew into English and Arabic. Only catalog content is sent to this service; no customer, order or price data is sent to it.
Google Fonts — when our server produces a PDF of an order or the catalog it loads fonts from Google's font service. This happens from our server and not from your browser, and carries no customer details.
A card clearing company — card clearing through the system is not in use, so no data is passed from it to a clearing company. [[NEEDS OWNER: Which clearing company or payment gateway is actually used, and what is the address of its privacy policy?]]
The accounting system — the official tax invoice or receipt is issued in a separate accounting system and not in this platform. [[NEEDS OWNER: Are customer and order details transferred to an external accounting system (Kod Bina, for example), what is transferred, and who operates it?]]
Transfers outside Israel. Some of the service providers above are international companies. [[NEEDS OWNER: Is information stored or processed outside Israel, in which countries, and on what basis is it transferred?]]
Cookies and local storage in your browser
The site sets no advertising cookies and no traffic-analytics cookies. The cookies that are stored are either necessary to run the service or remember a preference you chose.
Necessary cookies: hagog_access — your access token (twelve minutes); hagog_refresh — session renewal (thirty days); hagog_imp — a staff member acting on a customer's behalf (cleared when the browser closes, and valid for at most one hour); hagog_sess — a marker that a session exists and the moment the access token expires, so a page you left open renews itself instead of asking you to sign in again; it holds no identity and no token. The first three are inaccessible to code running in the browser; hagog_sess is deliberately readable by the page, which is the whole of its purpose. All four are restricted to our site and sent over an encrypted connection.
Preference cookies (kept for up to a year): NEXT_LOCALE — the interface language; hagog_theme — light or dark mode; hagog_font_scale, hagog_contrast, hagog_motion, hagog_filter, hagog_links, hagog_readable — the accessibility settings you chose in the accessibility widget (text size, contrast, reduced motion, colour filter, link highlighting, readable font); hagog_vat_display — prices shown with or without VAT; hagog_sidebar — whether the side menu is collapsed.
Local storage in your browser, which is never sent to us: the muting of the alert on the warehouse screen, and the moment your session was last renewed (so two open tabs never renew it twice). The list of recently viewed products (up to twelve product identifiers) is also held on your device, but it IS sent to our server each time the portal home loads — only to turn those identifiers into products to show you; we do not store it. The colour-theme and accessibility preferences are kept in cookies only, as described above. In addition, while a staff member is acting on a customer's behalf, two temporary markers are held in the browser tab and disappear when it is closed.
You can delete or block cookies in your browser settings. Blocking the necessary cookies will prevent you from signing in; blocking the preference cookies or local storage leaves the site working, but your choices will not be remembered.
Security
Separation between customers is enforced in the database itself: every business table carries a row-level security policy, and every query over account data runs under the identity of its user and account. Even a software error cannot expose another account's data, because the restriction does not rely on the application code alone.
Permissions are separated by role: system administrator, sales rep, warehouse staff, customer account administrator, customer user and browse seat. Warehouse staff see no prices by default, and financial documents such as invoices are not accessible from the warehouse screens.
Further measures: codes and tokens are stored only as encrypted hashes; card details are never stored; requests arriving from other sites are blocked; forms and the sign-in screen are rate limited; and the public form carries a trap that identifies bots.
No system is completely secure. If you learn of a fault or suspect a security incident, write to us at office@hagog.co.il and we will deal with it. In the event of a serious security incident we will act and report as the law requires.
How long information is kept
Periods fixed in the system: a sign-in code is valid for ten minutes; a session ends after twelve hours without activity, and in any case ninety days after sign-in; a joining link is valid for seven days; permission to act on a customer's behalf expires after one hour; the recently-viewed list is limited to twelve items and is kept only in your own browser.
[[NEEDS OWNER: How long are accounts, orders, enquiries that never became accounts, sign-in and session records, audit logs and in-app messages kept — and which of these periods follow from accounting or other legal duties?]]
Your rights
Under the Israeli Privacy Protection Law, 5741-1981, and its amendments, you may review the information held about you, ask to correct information that is incorrect, incomplete, unclear or out of date, ask for it to be deleted — subject to the limits described in this policy and to our legal duties — and ask not to receive marketing approaches.
Some of this you can do yourself in the portal: choose your notification channels and their language, manage delivery addresses (account administrator), and sign out on the device you are using.
To exercise a right, contact us at office@hagog.co.il, by phone on 04-6383380, or on WhatsApp at 050-8256676. To protect the account's information we will confirm that the person asking is authorised by the business before we release anything. [[NEEDS OWNER: What response time do you want to commit to for access and correction requests?]]
If you do not receive an answer, you may approach the Privacy Protection Authority at the Ministry of Justice.
[[NEEDS OWNER: Has a privacy protection officer been appointed, and if so what are their name and contact details, if they differ from the office details?]]
Changes to this policy
We may update this policy, for example when new capabilities or service providers are added. The updated text will be published on this page alongside the date of the update. [[NEEDS OWNER: How do you want customers told about a material change to the policy — by email, by a message in the portal, or with no commitment?]]
Contact
Hagog International, Baqa al-Gharbiyye. Phone 04-6383380, WhatsApp 050-8256676, email office@hagog.co.il. [[NEEDS OWNER: What is the full physical address for sending privacy enquiries?]]
[[NEEDS OWNER: What update or effective date should appear at the foot of the policy?]]
