Privacy Policy
Last updated: August 27, 2026
MyVaad is a platform for managing residential building committees (vaad bayit): dues collection, votes, resident notifications, and tools for management companies. Doing that means handling personal data — and this policy explains, in plain language, what we collect, why, who it is shared with, and what your rights are.
This policy is written to comply with the Israeli Privacy Protection Law, 5741-1981, including Amendment 13 (in force since August 2025), and the Privacy Protection (Data Security) Regulations, 5777-2017.
1. Who and what this policy covers
This policy applies to the myvaad.co.il website and all MyVaad services (the "Service"), operated by Codebyte ("we"). It applies to everyone who uses the Service: residents, apartment owners, committee members, and management companies.
The Hebrew version of this policy is the binding one; this English version is provided for convenience.
2. What data we collect
We collect only what the Service needs to run:
- Account details — name, phone number, email address (if provided), and your chosen sign-in method: one-time SMS code, passkey, or a Google/Facebook account.
- Building association — the building's address, your apartment number, and your role (resident, apartment owner, committee member, or management-company staff).
- Payment information — charges, amounts, dates, payment status, and receipts. Your card details never reach us: they are entered directly on a secure, PCI DSS-compliant payment page operated by Pelecard, the payment services provider. The transaction itself is cleared through a terminal registered to Phoenix Gama Ltd (company no. 512711789), the licensed clearing company.
- Votes — a record of your participation in building votes. In a secret ballot, the choice itself is stored completely separately, with no link to the voter — the system has no way to reconstruct who voted for what.
- Messages — the content of messages sent through the system and delivery data (sent / delivered / read) on WhatsApp, SMS, and email.
- Technical data — IP address, device and browser identifiers, and basic usage data. Under Amendment 13 these count as personal data, and we treat them accordingly.
- Waitlist (pre-launch) — if you leave an email address on the "coming soon" page, we store that address, the date you signed up, the page it came from, and your browser's User-Agent string for abuse prevention. No IP address is stored on this record. It is used for one launch announcement and nothing else.
3. Where the data comes from
Data reaches us from three sources: directly from you (when signing up and using the Service); from your building's committee or management company, who enter the resident list and charges; and from payment confirmations received from Pelecard after a payment is made.
A committee or management company that provides us with residents' details is responsible for doing so lawfully and within its authority to manage the building.
4. Who owns the database, and who holds it
For building data — the resident list, charges, payments, and votes — the building committee or management company is the owner of the database under Israeli law. MyVaad acts as the "holder": we process that data on their behalf, under their instructions, and only for the building's purposes.
For your user account and the technical data about your use of the site, MyVaad is the database owner.
5. What we use the data for
We use personal data only for these purposes:
- Running the Service — managing charges and payments, issuing receipts, running votes, and handling resident requests.
- Service messages — payment reminders, payment confirmations, vote invitations, and building updates.
- Security — identifying users, preventing unauthorized access, and preventing fraud.
- Legal obligations — bookkeeping records and responding to lawful requests from competent authorities.
- Improving the Service — based on aggregated usage data that does not identify individuals.
We will not use your data for a purpose other than the one it was provided for, unless you consent or the law permits it. We do not sell personal data, do not pass it to advertisers, and do not run direct-mail services for third parties.
6. Who the data is shared with
Within your building: committee members and the management company see residents' payment status as part of their role. Residents do not see other residents' personal information.
Outside the building, we rely on sub-processors to run the Service:
- Supabase — database hosting and authentication, on servers in the European Union (Frankfurt, Germany).
- Vercel — website hosting and basic, cookie-less usage analytics (a US company with global infrastructure).
- Pelecard — operates the secure payment page and receives the card details, in Israel. They go directly to Pelecard and never pass through us.
- Phoenix Gama Ltd (company no. 512711789) — the licensed clearing company whose terminal the Service uses. It receives the transaction details in order to clear the payment and transfer the funds; it does not receive your card details from us.
- Meta (WhatsApp Cloud API) — delivery of WhatsApp messages.
- An Israeli SMS provider — delivery of text messages.
Every sub-processor is bound by a data-processing agreement and security commitments. Transfers of data outside Israel are made in accordance with the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001 — to countries providing an adequate level of protection (such as EU member states) or under appropriate contractual safeguards.
We disclose data to law enforcement or other parties only when legally required to do so.
7. Data security
We implement the requirements of the Privacy Protection (Data Security) Regulations, 5777-2017, including: encryption of data in transit and at rest, role-based access controls (each user sees only what their role allows), access logging, and environment separation. Payment card details are never stored on our systems.
No system is completely immune, but we review and update our security measures on an ongoing basis.
8. Security incidents — what happens if something goes wrong
In the event of a serious security incident, we will notify the Privacy Protection Authority within 72 hours of discovery, as required by Amendment 13. Where the incident poses a high risk to your rights, we will also notify you without undue delay, in clear language, including what happened and the steps you should consider taking.
9. How long we keep data
Data is kept for as long as the account or the building is active on the Service. Payment and accounting records are kept for up to 7 years, as required by Israeli tax and bookkeeping law.
When a building leaves the Service, the committee receives a full export of the building's data, and the data is deleted or anonymized within a reasonable time afterwards — except what the law requires us to keep.
A waitlist record is kept until the launch announcement is sent and deleted within 30 days after it. You can have it removed sooner, at any time, by writing to privacy@myvaad.co.il — withdrawal is exactly as easy as signing up, as Section 8C requires.
10. Your rights
Under the Privacy Protection Law, you have the following rights:
- Access — to receive a copy of the data we hold about you (Section 13 of the Law).
- Correction and deletion — to request correction or deletion of data that is inaccurate, incomplete, or out of date (Section 14 of the Law).
- Withdrawal of consent — to withdraw consent you have given, as easily as it was given.
- Direct mail — to demand removal from any direct-mailing list (to the extent one exists).
Contact us at privacy@myvaad.co.il and we will respond within 30 days, as the regulations require. If you believe your privacy has been violated, you may also contact the Israeli Privacy Protection Authority.
11. Cookies
We use essential cookies only — for sign-in, security, and preferences such as language. Site usage is measured with Vercel Web Analytics, which uses no cross-site tracking cookies and builds no advertising profile. There are no advertising cookies on the site.
12. Minors
The Service is intended for adults aged 18 and over, and we do not knowingly open accounts for minors. If we learn that an account was opened for a minor without a parent's or guardian's consent, we will delete it.
13. Changes to this policy
We will update this policy from time to time; the date of the last update appears at the top of the page. We will give advance notice of any material change through the Service.
14. Contact
For any privacy question: privacy@myvaad.co.il. The Service is operated by Codebyte, Israel.