zuz

Privacy

מדיניות פרטיות

בשורה אחת

zuz היא אפליקציית תחבורה ציבורית. אין בה חשבון משתמש, אין רישום, ואין מזהי פרסום או כלי מעקב. רוב מה שהאפליקציה יודעת עליך שמור אצלך במכשיר ולא נשלח לשום מקום.

  • לא נאסףשם, אימייל, טלפון, אנשי קשר, תמונות או פרטי תשלום — אין באפליקציה מסך הרשמה או התחברות.
  • לא נאסףמזהה פרסום, פרופיל שיווקי, מעקב בין אפליקציות או SDK של אנליטיקה.
  • במכשיר בלבדמועדפים, חיפושים אחרונים, העדפות מסלול, שפה, ערכת נושא והנסיעה הפעילה.
  • נשלח לשרתנקודת ציון (מיקום או מרכז המפה) ויעד — כדי להחזיר תחנות קרובות ומסלול. אינם משויכים לזהות ואינם נשמרים כהיסטוריה אישית.
  • נשלח לשרתנתוני חיבור טכניים שכל שרת אינטרנט רואה: כתובת IP, סוג המכשיר וזמן הפנייה.
  1. מי אחראי למידע

    אפליקציית zuz (להלן "האפליקציה") מופעלת על ידי [שם בעל האפליקציה], [מספר ח.פ. / ע.מ.], מכתובת [כתובת] (להלן "אנחנו").

    מסמך זה מסביר איזה מידע האפליקציה אוספת, למה, עם מי הוא משותף וכיצד תוכל לשלוט בו. הוא חל על אפליקציית zuz למכשירי Android ו־iOS ועל שירות הצד־שרת שלה בכתובת api-bus.editcrafted.com.

    המסמך נכתב בעברית ובאנגלית. בכל סתירה בין הנוסחים, הנוסח העברי גובר.

  2. איזה מידע נאסף

    האפליקציה אוספת רק את המידע הדרוש כדי לתפקד. אין בה חשבון משתמש, ולכן אין לנו שם, אימייל, מספר טלפון או סיסמה שלך.

    מידע מיקום

    אם תאשר את ההרשאה, האפליקציה קוראת את מיקום המכשיר בזמן שימוש בלבד (foreground). אין מעקב מיקום ברקע, אין שירות מיקום מתמשך, ואין תיעוד של המסלול שעברת. המיקום משמש לשלושה דברים:

    • הצגת תחנות בקרבתך ומיקומך על המפה;
    • מילוי נקודת המוצא בתכנון נסיעה ("המיקום שלי");
    • חישוב מרחקי הליכה והתקדמות לאורך נסיעה פעילה.

    אם לא תאשר את ההרשאה, האפליקציה ממשיכה לעבוד — היא מתמקדת במרכז המפה או במרכז ברירת המחדל של האזור שנבחר.

    חיפושים ויעדים

    טקסט שאתה מקליד בשדות חיפוש, והנקודות שאתה בוחר כמוצא ויעד, נשלחים לשרת שלנו כדי להחזיר תוצאות. הם אינם משויכים לזהות שלך ואינם נשמרים אצלנו כהיסטוריית חיפוש אישית.

    מידע טכני על החיבור

    כמו כל שרת אינטרנט, השרת שלנו רושם לכל פנייה את כתובת ה־IP, סוג המכשיר והדפדפן (User-Agent), הנתיב שנקרא, וחותמת זמן. מידע זה משמש לתפעול, לאבחון תקלות ולהגנה מפני שימוש לרעה (הגבלת קצב פניות). שים לב שנתיב הפנייה יכול לכלול את נקודת הציון שנשלחה לחיפוש.

    מה שהאפליקציה לא עושה: אין בה SDK של אנליטיקה, פרסום או crash reporting; אין מזהה פרסום; אין מעקב בין אפליקציות או אתרים (App Tracking Transparency); ואין מכירה או שיתוף של מידע למטרות שיווק. אנחנו לא מוכרים מידע ולא משתפים אותו עם מפרסמים או ברוקרים.

  3. מה נשמר במכשיר שלך

    החלק הגדול של המידע האישי שלך נשמר באחסון הפרטי של האפליקציה במכשיר (AsyncStorage), ואינו נשלח אלינו ואינו מגובה בשרתינו:

    מהמה זה כולל
    מקומות מועדפיםבית, עבודה ומקומות שהגדרת, כולל שם ונקודת ציון
    קווים מועדפיםמזהי הקווים שסימנת
    חיפושים אחרוניםיעדים ותחנות שביקרת בהם לאחרונה
    היסטוריית תכנון נסיעהזוגות מוצא–יעד אחרונים
    העדפות נסיעהסוגי תחבורה, זמן הליכה מרבי, קריטריון מיון
    נסיעה פעילהתמונת מצב של הנסיעה הנוכחית, כדי שתשרוד סגירת אפליקציה
    מיקום אחרון ידוענקודת ציון אחת, למשך 24 שעות, כדי לקצר את זמן העלייה
    העדפות תצוגהשפה, ערכת נושא, אזור (ישראל / ניו יורק), הגדרות התראות
    מטמון תפעולינתוני מסלולים ומיקום המפה האחרון, לחיסכון בתעבורה

    כל אלה נמחקים כשמסירים את האפליקציה או מנקים את נתוני האפליקציה בהגדרות המכשיר. חלקם ניתנים למחיקה גם מתוך האפליקציה (למשל ניקוי חיפושים אחרונים או מועדפים).

  4. מה נשלח לשרת שלנו

    השרת שלנו הוא שירות חסר־מצב לצורכי תחבורה: הוא מקבל שאלה, מחזיר תשובה, ואינו מנהל פרופיל משתמש. אין בו טבלת משתמשים, אין מזהה קבוע למכשיר, ואין קישור בין שתי פניות שונות שלך.

    • תחנות קרובות — נקודת ציון ורדיוס.
    • תכנון נסיעה — נקודת מוצא, יעד, שעה והעדפות (סוגי תחבורה, זמן הליכה).
    • חיפוש מקומות — הטקסט שהקלדת ונקודת ייחוס לשיפור הרלוונטיות.
    • זמני אמת — קוד תחנה או קו.
    • עדכון נסיעה פעילה — מצב הנסיעה והרגליים שנותרו, כדי לבדוק אם כדאי להציע מסלול חלופי.

    כל אלה מעובדים בזמן אמת ואינם נשמרים כהיסטוריה המשויכת אליך. מה שכן נשמר לזמן קצוב הוא יומן השרת הטכני המתואר בסעיף 2.

  5. הרשאות שהאפליקציה מבקשת

    הרשאהלמהחובה?
    מיקום מדויק ומשוער (בזמן שימוש)תחנות קרובות, "המיקום שלי", ניווט הליכהלא — האפליקציה עובדת גם בלעדיה
    התראותתזכורות ירידה והתקרבות לתחנה במהלך נסיעהלא
    רטטמשוב פיזי לצד התראהלא
    אינטרנטשליפת לוחות זמנים וזמני אמתכן

    האפליקציה חוסמת במפורש הרשאות קריאה וכתיבה לאחסון המכשיר ולהצגה מעל אפליקציות אחרות. אין גישה למצלמה, למיקרופון, לאנשי הקשר או ליומן.

    אפשר לבטל כל הרשאה בכל רגע דרך הגדרות המכשיר — ב־Android: הגדרות ← אפליקציות ← zuz ← הרשאות; ב־iOS: הגדרות ← zuz.

  6. התראות

    כל ההתראות באפליקציה הן מקומיות: הן נוצרות ומתוזמנות במכשיר שלך. איננו משתמשים ב־push notifications, ולכן לא נוצר ולא נשלח אלינו טוקן התראות, ואיננו יכולים לשלוח לך הודעה יזומה.

    אפשר לכבות סוגי התראות בנפרד ממסך ההגדרות באפליקציה.

  7. שירותי צד שלישי

    כדי להציג לוחות זמנים, מפות וזמני אמת, האפליקציה והשרת פונים לשירותים חיצוניים. מפתחות הגישה לשירותים המסחריים נשמרים בשרת ואינם נכללים באפליקציה עצמה — למעט מפתח המפות של Android, שנדרש להיות במכשיר.

    שירותלשם מהמה נשלח
    Google Maps SDK (במכשיר)הצגת המפה עצמהנקודת המבט של המפה ונתוני מכשיר שגוגל אוספת. כפוף למדיניות הפרטיות של Google.
    Google Places API (בשרת)השלמה אוטומטית של כתובות ומקומותהטקסט שהוקלד ונקודת ייחוס — מהשרת שלנו, לא מהמכשיר
    Google Routes API (בשרת)גיאומטריית קטעי הליכהנקודות התחלה וסיום של קטע הליכה
    משרד התחבורה (GTFS ו־SIRI)לוחות זמנים וזמני אמת בישראלקוד תחנה או קו. הפנייה יוצאת מהשרת שלנו.
    עיריית תל אביב — מידע פתוחשכבות מידע עירוניותאין מידע אישי
    MTA / MTA Bus Timeלוחות זמנים וזמני אמת בניו יורקקוד תחנה או קו. הפנייה יוצאת מהשרת שלנו.
    OpenStreetMap (Overpass)נתוני שבילים ושטחים ציבורייםתחום גיאוגרפי, ללא מידע אישי

    למעט Google Maps SDK שרץ במכשיר, כל הפניות האלה יוצאות מהשרת שלנו. המשמעות: הספקים האלה רואים את כתובת ה־IP של השרת, לא שלך.

  8. עוגיות ומזהי מעקב

    האפליקציה אינה משתמשת בעוגיות, ב־pixels, ב־fingerprinting או במזהי פרסום. אין בה WebView שטוען תוכן פרסומי, ואיננו מפעילים כלי מדידה כלשהו על התנהגותך באפליקציה.

  9. כמה זמן המידע נשמר

    מידעמשך שמירה
    נתונים במכשיר (מועדפים, חיפושים, העדפות)עד שתמחק אותם או תסיר את האפליקציה
    מיקום אחרון ידוע במטמון24 שעות
    שאילתות לשרת (תחנות, מסלול, חיפוש)אינן נשמרות — מעובדות ונזרקות
    יומן שרת טכני (IP, נתיב, זמן)[X ימים], ואז נמחק
    מטמון תוצאות בשרתעד שעה, ואינו משויך למשתמש
  10. הזכויות שלך

    מכיוון שאין באפליקציה חשבון משתמש, השליטה המעשית החזקה ביותר שלך היא ישירה: מחיקת הנתונים מתוך האפליקציה או הסרתה מהמכשיר מוחקת את המידע האישי שלך במלואו, מיידית, בלי לפנות אלינו.

    לפי חוק הגנת הפרטיות (ישראל)

    עומדות לך זכות עיון במידע שנשמר עליך, זכות לבקש את תיקונו או מחיקתו, וזכות לפנות אלינו בכל שאלה על אופן העיבוד. פנייה כזו תיענה בתוך פרק הזמן הקבוע בחוק.

    למשתמשים באיחוד האירופי (GDPR)

    עומדות לך זכויות עיון, תיקון, מחיקה, הגבלת עיבוד, ניידות והתנגדות לעיבוד, וכן זכות להגיש תלונה לרשות הפיקוח במדינתך. הבסיס החוקי לעיבוד המיקום הוא הסכמה (שאותה אפשר לבטל בכל רגע בהגדרות המכשיר); הבסיס לעיבוד יומני השרת הוא אינטרס לגיטימי באבטחת השירות ובתפעולו התקין.

    למשתמשים בקליפורניה (CCPA/CPRA)

    איננו מוכרים ואיננו משתפים מידע אישי כהגדרתם בחוק, ואיננו מבצעים פרסום ממוקד. עומדות לך זכויות לדעת, למחוק ולתקן, ולא נפלה אותך לרעה על מימושן.

    למימוש כל אחת מהזכויות: [כתובת אימייל ליצירת קשר].

  11. העברת מידע אל מחוץ למדינה

    השרת שלנו ממוקם ב־[מדינת אירוח השרת]. שירותי Google עשויים לעבד בקשות בשרתים מחוץ לישראל ולאיחוד האירופי, בהתאם לתנאיהם ולמנגנוני ההעברה החוקיים שלהם. פניות לשירותי משרד התחבורה מעובדות בישראל; פניות לשירותי MTA מעובדות בארצות הברית.

  12. אבטחת מידע

    • כל התקשורת בין האפליקציה לשרת מוצפנת ב־HTTPS.
    • מפתחות גישה לשירותים מסחריים נשמרים בשרת ואינם נשלחים למכשיר.
    • יומני השרת מסננים אוטומטית פרמטרים רגישים (מפתחות, טוקנים, סיסמאות) לפני הכתיבה.
    • הפניות לשרת מוגבלות בקצב לכל כתובת IP, כהגנה מפני שימוש לרעה.
    • גודל וצורת כל בקשה נבדקים לפני עיבוד; שדות שלא הוגדרו מראש נדחים.
    • אין באפליקציה חשבונות משתמש — ולכן אין מאגר סיסמאות שאפשר לפרוץ אליו.

    אף מערכת אינה חסינה לחלוטין. אם נזהה אירוע אבטחה המשפיע על מידע אישי, נפעל בהתאם לחובות הדיווח החלות עלינו.

  13. ילדים

    האפליקציה מיועדת לקהל הרחב ואינה פונה לילדים מתחת לגיל 13, ואיננו אוספים ביודעין מידע אישי מהם. מאחר שאין באפליקציה הרשמה, גם איננו אוספים גיל. אם נודע לך שילד מסר לנו מידע אישי, פנה אלינו ונמחק אותו.

  14. תשלומים

    נכון למועד גרסה זו, האפליקציה אינה מבצעת תשלומים ואינה אוספת פרטי אמצעי תשלום. מסך התשלום הוא תצוגה מקדימה בלבד. אם וכאשר יופעלו תשלומים בפועל, מדיניות זו תעודכן מראש ותפרט את ספק הסליקה ואת המידע שיעובד.

  15. שינויים במדיניות

    נעדכן מסמך זה כשהאפליקציה תשתנה. תאריך התוקף בראש העמוד מציין את הגרסה הנוכחית. שינוי מהותי — למשל סוג מידע חדש שנאסף או שותף חדש — יובא לידיעתך באפליקציה לפני כניסתו לתוקף.

  16. יצירת קשר

    לשאלות על מדיניות זו או למימוש זכויותיך: [כתובת אימייל ליצירת קשר].

    כתובת למשלוח דואר: [כתובת דואר].

    אם אינך מרוצה מהמענה, באפשרותך לפנות לרשות להגנת הפרטיות במשרד המשפטים, או לרשות הפיקוח במדינתך אם אתה תושב האיחוד האירופי.

In one line

zuz is a public transit app. It has no user account, no sign-up, no advertising identifiers and no tracking tools. Most of what the app knows about you stays on your device and is never sent anywhere.

  • Not collectedName, email, phone number, contacts, photos or payment details — the app has no sign-up or login screen.
  • Not collectedAdvertising ID, marketing profile, cross-app tracking or analytics SDK.
  • On device onlyFavourites, recent searches, trip preferences, language, theme and your active trip.
  • Sent to serverA coordinate (your location or the map centre) and a destination, so we can return nearby stops and a route. Not tied to an identity and not kept as personal history.
  • Sent to serverTechnical connection data any web server sees: IP address, device type and request time.
  1. Who is responsible

    The zuz app (the "app") is operated by [Operator legal name], [Company / VAT number], of [Address] ("we", "us").

    This document explains what data the app collects, why, who it is shared with, and how you can control it. It covers the zuz app on Android and iOS and its backend service at api-bus.editcrafted.com.

    This policy is published in Hebrew and English. Where the two differ, the Hebrew version prevails.

  2. What data is collected

    The app collects only what it needs to work. There is no user account, so we hold no name, email, phone number or password for you.

    Location data

    If you grant permission, the app reads your device location only while you are using it (foreground). There is no background location tracking, no persistent location service, and no record of the route you travelled. Location is used for three things:

    • showing stops near you and your position on the map;
    • filling in the origin when planning a trip ("my location");
    • measuring walking distance and progress along an active trip.

    If you decline, the app still works — it centres on the map view or on the default centre of the selected region.

    Searches and destinations

    Text you type into search fields, and the points you pick as origin and destination, are sent to our server so it can return results. They are not tied to your identity and are not stored by us as personal search history.

    Technical connection data

    Like any web server, ours records for each request the IP address, the device and browser type (User-Agent), the path requested, and a timestamp. This is used for operations, fault diagnosis and abuse protection (rate limiting). Note that the request path can include the coordinate sent with a search.

    What the app does not do: it contains no analytics, advertising or crash-reporting SDK; it uses no advertising identifier; it performs no cross-app or cross-site tracking; and we neither sell nor share data for marketing. We do not pass data to advertisers or data brokers.

  3. What stays on your device

    Most of your personal data lives in the app's private storage on your device (AsyncStorage). It is never sent to us and is not backed up on our servers:

    WhatContents
    Favourite placesHome, work and places you saved, with name and coordinate
    Favourite linesThe line identifiers you starred
    Recent searchesDestinations and stops you visited recently
    Trip planning historyRecent origin–destination pairs
    Trip preferencesTransport modes, maximum walking time, sort order
    Active tripA snapshot of the trip in progress, so it survives an app restart
    Last known locationA single coordinate, for 24 hours, to shorten start-up time
    Display preferencesLanguage, theme, region (Israel / New York), notification settings
    Operational cacheRoute data and last map viewport, to save network traffic

    All of this is erased when you uninstall the app or clear its data in your device settings. Some of it can also be cleared from inside the app (for example recent searches or favourites).

  4. What is sent to our server

    Our server is a stateless transit service: it takes a question, returns an answer, and keeps no user profile. There is no user table, no persistent device identifier, and no link between two separate requests you make.

    • Nearby stops — a coordinate and a radius.
    • Trip planning — origin, destination, time and preferences (modes, walking time).
    • Place search — the text you typed and a reference point to improve relevance.
    • Real-time arrivals — a stop or line code.
    • Active trip update — trip state and remaining legs, to check whether a better route should be offered.

    All of these are processed in real time and are not stored as history linked to you. What is retained for a limited period is the technical server log described in section 2.

  5. Permissions the app requests

    PermissionWhyRequired?
    Precise and approximate location (while in use)Nearby stops, "my location", walking navigationNo — the app works without it
    NotificationsGet-off reminders and stop-approaching alerts during a tripNo
    VibrationPhysical feedback alongside an alertNo
    InternetFetching schedules and real-time arrivalsYes

    The app explicitly blocks device storage read/write permissions and drawing over other apps. It has no access to your camera, microphone, contacts or calendar.

    You can revoke any permission at any time in your device settings — on Android: Settings → Apps → zuz → Permissions; on iOS: Settings → zuz.

  6. Notifications

    All notifications in the app are local: they are created and scheduled on your device. We do not use push notifications, so no notification token is generated or sent to us, and we cannot message you unprompted.

    Each notification type can be turned off separately in the app's settings screen.

  7. Third-party services

    To show schedules, maps and real-time arrivals, the app and server call external services. Access keys for commercial services are held on the server and are not shipped inside the app — except the Android maps key, which has to be on the device.

    ServicePurposeWhat is sent
    Google Maps SDK (on device)Rendering the map itselfMap viewport and device data Google collects. Subject to Google's privacy policy.
    Google Places API (server-side)Address and place autocompleteThe text typed and a reference point — from our server, not your device
    Google Routes API (server-side)Walking-leg geometryStart and end points of a walking leg
    Israel Ministry of Transport (GTFS, SIRI)Schedules and real-time arrivals in IsraelA stop or line code. The call originates from our server.
    Tel Aviv Municipality open dataCity data layersNo personal data
    MTA / MTA Bus TimeSchedules and real-time arrivals in New YorkA stop or line code. The call originates from our server.
    OpenStreetMap (Overpass)Footpath and public-space dataA geographic bounding box, no personal data

    Except for the Google Maps SDK running on your device, all of these calls originate from our server. That means those providers see our server's IP address, not yours.

  8. Cookies and tracking identifiers

    The app uses no cookies, tracking pixels, fingerprinting or advertising identifiers. It embeds no WebView loading advertising content, and we run no measurement tool on your behaviour in the app.

  9. How long data is kept

    DataRetention
    On-device data (favourites, searches, preferences)Until you delete it or uninstall the app
    Cached last known location24 hours
    Server queries (stops, routes, search)Not stored — processed and discarded
    Technical server log (IP, path, time)[X days], then deleted
    Server-side result cacheUp to one hour, not linked to any user
  10. Your rights

    Because the app has no user account, your strongest practical control is direct: clearing the data inside the app, or uninstalling it, erases your personal data completely and immediately, without contacting us.

    Under the Israeli Privacy Protection Law

    You have the right to review data held about you, to request its correction or deletion, and to ask us any question about how it is processed. We will respond within the period set by law.

    For users in the European Union (GDPR)

    You have rights of access, rectification, erasure, restriction of processing, portability and objection, and the right to lodge a complaint with your national supervisory authority. The legal basis for processing location is consent (revocable at any time in your device settings); the basis for server logs is our legitimate interest in securing and operating the service.

    For users in California (CCPA/CPRA)

    We do not sell or share personal information as those terms are defined by the statute, and we do not conduct targeted advertising. You have the rights to know, delete and correct, and we will not discriminate against you for exercising them.

    To exercise any right, contact [Contact email address].

  11. International transfers

    Our server is located in [Server hosting country]. Google services may process requests on servers outside Israel and the EU, under their own terms and lawful transfer mechanisms. Calls to Israeli Ministry of Transport services are processed in Israel; calls to MTA services are processed in the United States.

  12. Security

    • All traffic between the app and the server is encrypted with HTTPS.
    • Access keys for commercial services are held on the server and never sent to the device.
    • Server logs automatically redact sensitive parameters (keys, tokens, passwords) before writing.
    • Requests are rate-limited per IP address as abuse protection.
    • Every request's size and shape is validated before processing; fields not explicitly allowed are rejected.
    • The app has no user accounts — so there is no password store to breach.

    No system is completely secure. If we identify a security incident affecting personal data, we will act in line with the notification obligations that apply to us.

  13. Children

    The app is intended for a general audience and is not directed at children under 13, and we do not knowingly collect personal data from them. Since the app has no sign-up, we do not collect age either. If you become aware that a child has provided us with personal data, contact us and we will delete it.

  14. Payments

    As of this version, the app does not process payments and does not collect payment details. The payment screen is a preview only. If and when payments go live, this policy will be updated in advance to name the payment provider and the data processed.

  15. Changes to this policy

    We will update this document as the app changes. The effective date at the top of the page identifies the current version. A material change — a new category of data collected, or a new partner — will be surfaced in the app before it takes effect.

  16. Contact us

    For questions about this policy or to exercise your rights: [Contact email address].

    Postal address: [Postal address].

    If you are not satisfied with our response, you may contact the Israeli Privacy Protection Authority, or your national supervisory authority if you are an EU resident.