Privacy Policy - Practicot
Version 1.3.0
Version: 1.3.0 · Last updated: 02.09.2026
*This English translation is provided for convenience only. The binding version of this policy is the Hebrew original published on this page.*
This policy explains what personal data is collected on the Practicot platform, for what purposes, with whom it is shared, how long it is retained, and what rights you have. This policy forms an integral part of the site's Terms of Service and was written in accordance with the Israeli Protection of Privacy Law, 5741-1981, including Amendment No. 13, and the Protection of Privacy Regulations (Data Security), 5777-2017.
1. Who we are and how to contact us
The platform is operated by Nathan Kummel, Adv., business no. 029693744, 27 Yitzhak Rabin St., Kiryat Ono ("we" or "the Operator").
For any question, request, or exercise of rights under this policy: support@practicot.com.
2. Who this policy applies to, and who is responsible for what
This policy addresses four groups of people, with different roles in each case:
- Customers - independent professionals who subscribe to the service and build a website with it. With respect to them, we are the database controller.
- Visitors and inquirers on customer websites - anyone who fills in a contact form or browses a customer's website. With respect to this data, the customer is the database controller responsible toward you, and we act solely as a holder and processor on the customer's behalf for the purpose of operating the service. Requests to delete or review such data should first be directed to the customer whose site you contacted; if you contact us, we will forward the request to them and assist in fulfilling it.
- People who contact us through the Practicot website itself (the "prefer to talk first" form). With respect to them, we are the database controller.
- Partners in the partner program. With respect to them, we are the database controller.
3. What data is collected
3.1. Customers (subscribers)
- Registration and payment: name, email, phone, the plan purchased and its price. Credit card details never reach us at all and are not stored by us (see Section 5).
- The intake questionnaire: the details you fill in for building your site - full name, profession and experience, business city and address, phone, WhatsApp, public email, social media links, audiences and specialties, free texts you wrote, and files you uploaded (portrait photo, workplace photos, and documents).
- User account: email, name, encrypted password, and a record of the Terms acceptance (version and time).
- Content you created on the platform: pages, articles, images, marketing materials, and site settings.
- Operational records: billing records, support inquiries, and feedback you sent.
3.2. People who inquire through a customer's website
The contact form collects: name, phone, email (if provided), inquiry topic and a free message, plus the page from which the inquiry was sent and the referral source. Together with the inquiry, an exact snapshot of the consent text checked at that moment is stored. Details submitted when booking a meeting through a customer's website (where that customer has this feature active) are handled the same way.
In addition, a communication journey record of your interactions with that business is stored: which messages were sent to you, whether they were delivered, and which links you clicked. This record contains references and timestamps only and does not include message content.
Marketing messages and message sequences: marketing messages are sent only to those who checked a separate, explicit consent on the form, and the consent text is stored as it was shown to you. Every marketing message includes a one-click unsubscribe link, with no login required; unsubscribing takes effect immediately and stops all message sequences. An address that unsubscribed, or whose messages bounced, is stored on a suppression list whose only purpose is to prevent future sending to it; this list is retained even after other data is deleted, for your benefit.
The form is not intended for sensitive data. We explicitly ask that you not include medical or therapeutic information in it.
3.3. Visitors on customer websites (statistics)
Minimal usage data is collected: page viewed, device type, country and city at a general level, referral source (domain name only), search terms typed into the internal site search, and an encrypted statistical identifier that changes daily.
Customer websites contain no advertising tracking cookies and no external analytics services, except the Meta Pixel if the site owner enabled it (Section 3.6). The IP address is used only to compute that daily identifier and is not stored.
3.4. People who contact us through the Practicot website
Name, field of practice, one contact detail (phone or email), a link to an existing website if provided, and free text.
3.5. Partners in the partner program
Contact details, business type and number, bank account details for payment, invoices you uploaded, and a record of the partner agreement acceptance - including agreement version, acceptance time, IP address, and browser details. Clicks on your partner links and an anonymous visitor identifier are also stored for attribution.
What a partner does not see: partners see a masked identifier only (e.g., P-1048). A customer's business name is shown only if the customer explicitly approved it, and partners are never exposed to first names, emails, phone numbers, professional content, or cancellation reasons.
3.6. Meta Pixel (Facebook and Instagram)
A site owner may choose to enable the Meta Pixel on their site. Practicot also runs it on practicot.com itself. When enabled, Meta's code loads in your browser and sends Meta: the address of the page viewed, the page you arrived from, browser and device data, your IP address, and an event name only - page view, inquiry form sent, or a click on a WhatsApp, phone or email button. Your name, phone, email or the content of your inquiry are never sent to Meta. The pixel does not run on booking-management pages and does not run when the site owner previews a draft.
Meta sets cookies in your browser for this (including `_fbp`, and `_fbc` if you arrived from a Meta ad). Purpose: measuring advertising effectiveness and building audiences for advertising on Facebook and Instagram, including showing ads to people who visited the site. Meta also uses the data for its own purposes under [Meta's privacy policy](https://www.facebook.com/privacy/policy), and operates outside Israel.
On a customer site, the site owner is responsible for enabling the pixel and for the use of the audiences (Section 2). You can block the pixel with a browser tracking blocker, and control the ads shown to you in [Meta's ad preferences](https://www.facebook.com/adpreferences).
4. Cookies
The platform makes minimal use of cookies, all of them essential for operation. There are no advertising cookies and no third-party tracking cookies, except the Meta Pixel cookies when it is enabled (Section 3.6):
- Login cookie - identifies the signed-in user in the management area.
- site-preview - lets a customer preview their draft site before publishing. Lifetime: 8 hours.
- portal-tenant - used by a system administrator entering a customer account for support. Lifetime: until the browser closes.
- pr-ref - exists only when the partner program is active, and only if you arrived through a partner link. Stores a random identifier to attribute the signup to the partner. Lifetime: 90 days.
Usage measurement on customer websites uses no cookies at all.
5. Payments
Payment is made on a secure page of the payment processor (Invoice4U, clearing via Cardcom). Credit card details are entered directly with the payment processor, do not pass through our servers, and are not stored by us.
We store: the last four digits, card type and expiry for display purposes, a customer identifier at the payment processor for subscription renewal, and the charge record and amount. Invoices are issued by the payment processor and we keep a reference to them.
6. Use of artificial intelligence
The platform uses an external AI service (OpenAI) for content creation: the site draft based on the intake questionnaire, articles, marketing materials, image descriptions, and reply drafts.
Important to know:
- Business content entered by the customer is sent for processing at that provider.
- When a customer requests a reply draft for an inquiry received through a form, the inquiry content - including the inquirer's name and message - is sent to the provider to compose the draft. The draft is shown to the customer only and is not sent automatically to the inquirer.
- We do not send payment details to the provider.
- The provider acts as a data processor on our behalf. We do not permit use of the data for model training.
7. Google Calendar connection (for customers)
Customers using the meeting-booking feature may, entirely at their choice, connect their Google Calendar to the platform. The connection uses a limited Google OAuth authorization with a narrow scope:
- Availability reading only (free/busy): we read from the calendar only the time ranges in which you are busy, in order to hide occupied slots on your website's booking page. We do not read, store, or display the content of calendar events - no titles, no attendees, and no other details. Visitors see only "available" or "unavailable".
- Managing meeting events: when a meeting is booked through the site, changed, or cancelled, we create, update, or delete a corresponding event on a calendar you own.
- Storage: access tokens are stored encrypted. Calendar content is not stored on our servers.
- Use and sharing: calendar data is used solely to operate the meeting-booking feature. It is not used for any other purpose, is not transferred to third parties, and is not used to train artificial intelligence models.
- Disconnecting: you can disconnect at any time from the portal; upon disconnection the tokens are deleted and access is revoked. You can also revoke the authorization directly in your Google account's security settings.
- Limited Use commitment: The use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. With whom the data is shared
We do not sell personal data and do not transfer it to third parties for their marketing purposes, except Meta when the pixel is enabled, as described in Section 3.6. Data is provided to service providers who act on our instructions and are bound by confidentiality:
- Hosting and cloud infrastructure - storing the database and running the service.
- File and image storage.
- Email delivery - notifications, system emails, and password resets.
- Payment clearing and invoicing - as described in Section 5.
- Artificial intelligence - as described in Section 6.
- Google - sign-in with a Google account if you chose to link it, and the Google Calendar connection as described in Section 7.
- Meta - the pixel, as described in Section 3.6. Meta is not a provider acting solely on our instructions; it uses the data independently under its own policy.
In addition, data may be disclosed where required by law, by court order, or to protect our rights.
Transfer abroad: some providers operate outside Israel, including the cloud, email, and AI providers. Engagements with them are made in accordance with the law applicable to transferring data outside Israel.
9. Why we use the data
- To provide the service: building the site, hosting it, managing content, and receiving inquiries.
- To manage the engagement: billing, invoices, support, and service messages.
- To secure the system and prevent abuse, including detecting repeated login attempts.
- To improve the service using aggregate statistics.
- To comply with legal obligations.
We do not perform advertising profiling and do not make automated decisions with legal effect on you.
10. How long the data is retained
- Inquiries received through a form on a customer website: identifying details (name, phone, email, message content, notes, and replies sent) are deleted automatically after 12 months. Only statistical data remains: time, inquiry topic, originating page, and the consent text. A customer can also permanently delete an inquiry at any time, for example at the inquirer's request.
- Inquiries received by us through the Practicot website: the same rule, 12 months.
- Communication journey records (messages sent, deliveries, clicks): identifiable until the end of the inquiry's retention period (12 months); afterwards the link to your identity is deleted and the data remains statistical only.
- The marketing suppression list: retained indefinitely, so that an unsubscribed address never receives messages again.
- Statistical usage data: deleted automatically after 90 days.
- Failed login attempt counters: deleted automatically within 24 hours.
- Partner link clicks: deleted automatically after 180 days.
- Google Calendar access tokens: stored encrypted for as long as the connection is active, and deleted upon disconnection.
- Account data and site content: retained while the subscription is active. Upon termination, content is kept for a reasonable period to allow return or export, and is then deleted at your request.
- Billing records, invoices, and terms-acceptance records: retained as required by tax and limitations law, including after termination.
11. Your rights
Under the Protection of Privacy Law you have the right to review the data held about you, to request its correction if it is inaccurate, incomplete, or outdated, and to request its deletion.
- Customers and partners: contact us at support@practicot.com. We will respond within a reasonable time and no later than the period set by law.
- Inquirers through a customer's website: the request should be directed to the customer you contacted, who is the database controller. A request sent to us will be forwarded to them and we will assist in fulfilling it.
If you believe we acted unlawfully, you may contact the Privacy Protection Authority.
12. Data security
We apply accepted security measures: traffic encryption, password encryption, full separation between different customers' data at the system level, permission restrictions, controls against repeated login attempts, and logging of sensitive operations.
Support team access to a customer account is for support and maintenance purposes only and is logged.
That said, no online system is completely immune, and we cannot guarantee the total absence of security incidents. In a severe security incident we will act as required by law, including reporting to the authority and notifying those affected.
13. Minors
The service is intended for adult professionals. We do not knowingly collect data about minors under 18. If you become aware that a minor provided us data, contact us and we will delete it.
14. Changes to this policy
We will update this policy from time to time. The updated version will be published on this page with a version number and date. A material change - for example expanding the purposes of use or adding a new data type - will be brought to your attention prominently, and for customers will also require renewed approval on the next login to the system.
15. Contact
For questions and exercising rights: support@practicot.com, or by mail: Adv. Nathan Kummel, 27 Yitzhak Rabin St., Kiryat Ono.
