1. Introduction — Who We Are
Maorly (“we,” “us,” or “the Service”) is a sole proprietorship (“עוסק פטור”) registered in Israel that provides a platform for creating smart digital event invitations, sending them to guests, collecting RSVPs, and making automated follow-up calls.
The business owner and data controller is Maor Yosef Salem. This Privacy Policy explains what personal information we collect, how we use it, with whom we share it, and what rights you have regarding your information. It applies to our website at https://inv4u.vercel.app and to all services we offer through it.
We operate in accordance with the Israeli Protection of Privacy Law, 5741-1981 and its regulations, as well as the principles of the EU General Data Protection Regulation (GDPR) for visitors from the European Union.
2. Information We Collect
We distinguish between information we collect today and information we plan to collect as part of future services that have not yet launched.
Information we collect today
- Contact details you submit voluntarily through the contact / lead form: full name, phone number, and email address, along with inquiry details (event type, estimated number of guests, date, and a free-text message).
- Basic technical information collected automatically on every visit, as is standard for any website: IP address, browser type, and operating system.
- Payment and billing records— the minimal details needed to issue receipts and reconcile payments you make by bank transfer, Bit, or cash (see “Payments and Billing”).
Account Information We Collect (at signup)
When you create an account, we collect and store the following to operate your account:
- Full name provided at signup.
- Email address and/or phone number used to sign in and to contact you about your event.
- Password — stored only in hashed (encrypted) form by Supabase Auth. We never see or store your password in plain text.
- Event details and guest list— once a package is arranged, when we or you enter the event details (type, date, venue) and the guest list (names and phone numbers). Guest details are processed on your behalf; you are responsible for obtaining your guests’ consent to be contacted.
Future Services — not yet collected
The items below describe data collection planned for upcoming phases of the Service. This collection is not active today, and this policy will be updated when each capability actually launches.
- Event details and guest lists — when the event creation module launches: guest names and the event details entered by the event organizer.
- Guest contact informationfor sending invitations, subject to the event organizer’s consent and their responsibility for obtaining consent from their guests.
- WhatsApp messages sent to event guests via the WhatsApp Business API.
- Voice call recordings and transcripts from automated, AI-powered follow-up calls to guests who have not responded.
- Online credit card payments via Stripe(see “Payments and Billing”). Card data will be handled by Stripe; we will never store card numbers on our servers.
3. How We Use the Information
- To respond to and follow up on inquiries you submit via the form.
- To create and manage your account, authenticate your sign-in, and contact you about your event and the package that fits it.
- To provide, operate, and improve the Service, and to tailor quotes to your needs.
- To send operational notifications to the business owner about new inquiries (via email and WhatsApp).
- To issue receipts, reconcile payments, and meet accounting and tax obligations.
- To secure the website, prevent misuse, and maintain service integrity.
- To comply with applicable legal and regulatory obligations.
- In future services: to send invitations to guests, collect RSVPs, make follow-up calls, and process online payments — subject to the relevant consents.
4. Third-Party Services We Use
We rely on external service providers to operate the Service. These providers process information on our behalf and in accordance with their own privacy policies:
In use today
- Supabase — data storage in a PostgreSQL database and authentication (account management and password hashing) (servers in the EU / US).
- Vercel — website hosting and delivery infrastructure.
- Gmail / Google (SMTP) — sending email notifications.
- Twilio — sending WhatsApp notifications to the business owner.
Planned for future services
- Stripe — online credit card payment processing (card details are handled solely by Stripe and are not stored by us).
- ElevenLabs — voice generation for automated follow-up calls.
- OpenAI Whisper — transcription of voice calls.
- Anthropic Claude — language processing and the logic powering smart conversations.
5. Payments and Billing
We offer several payment methods. For each one, we collect only the minimal information needed to issue receipts, reconcile payments, and meet our accounting and tax obligations.
Payment methods accepted today
- Bank transfer — we receive the bank details needed to identify and reconcile your payment. We do not store sensitive banking information beyond what is required for reconciliation.
- Bit — payments are handled through the Bit app. We receive confirmation of payment but do not store your payment credentials.
- Cash — no digital payment data is collected. We keep only receipt records for accounting purposes.
Record keeping:we retain billing and receipt records for the period required by Israeli tax law — currently seven (7) years for a sole proprietor (“עוסק פטור”).
Future service — online payment
- Stripe— for online credit card payments via the website. We will never store card numbers; all card data will be handled by Stripe’s PCI-compliant infrastructure. Online card payments are not yet available.
6. Data Retention
We retain personal information for as long as it is necessary for the purposes for which it was collected — including providing the Service, responding to inquiries, and meeting legal and accounting obligations. Billing and receipt records are kept for the period required by Israeli tax law (currently seven (7) years for a sole proprietor / “עוסק פטור”). Inactive inquiry data will be deleted or anonymized after a reasonable period, unless we are legally required to retain it for longer. You may request deletion of your information at any time (see “Your Rights”).
7. Data Security
We take reasonable technical and organizational measures to protect information against unauthorized access, use, or disclosure, including encryption in transit (HTTPS), access controls, and reliance on secure infrastructure providers. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Your Rights
Under the Israeli Protection of Privacy Law and the GDPR (where applicable to you), you have the following rights regarding your personal information:
- The right to access the information we hold about you.
- The right to request correction of inaccurate or outdated information.
- The right to request deletion of your information (the “right to be forgotten”).
- The right to object to or restrict certain processing.
- The right to withdraw consent you have given, without affecting the lawfulness of processing carried out beforehand.
- The right to lodge a complaint with the Israeli Privacy Protection Authority.
To exercise your rights, contact us at the email address listed in the “Contact Us” section. We will handle your request within a reasonable time and in accordance with the law.
9. International Data Transfers
Some of our service providers store or process information outside of Israel, including in the European Union and the United States. When transferring information to these countries, we rely on accepted legal mechanisms for protecting the data and choose providers that are committed to recognized standards of data security and privacy.
10. Cookies and Tracking Technologies
The website may use essential cookies and basic technical data required for its proper operation. We do not currently use third-party advertising or marketing tracking cookies. You can block cookies through your browser settings, though doing so may impair some of the website’s functions.
11. Children's Privacy
The Service is not intended for minors under the age of 18, and we do not knowingly collect personal information from children. If you become aware that a minor has provided us with information without the consent of a parent or guardian, please contact us and we will act to delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time, particularly as new services launch. An updated version will be posted on this page alongside a new update date. We encourage you to review this page periodically. Continued use of the Service after an update constitutes acceptance of the updated policy.
13. Contact Us
For any question, request, or matter related to privacy, you can reach us:
Business name:Maorly (sole proprietor / “עוסק פטור,” registered in Israel)
Owner: Maor Yosef Salem
Address: Shalom Shabazi 10, Petah Tikva, Israel
Email: inv4u.business@gmail.com
Website: https://inv4u.vercel.app