מדיניות פרטיות
עדכון אחרון: ספטמבר 2026
מה המערכת שומרת
"סידור משמרות" היא מערכת לשיבוץ משמרות לצוותים. כדי לעשות רק את זה, נשמרים עבור כל חבר צוות: שם תצוגה, כתובת מייל, טלפון (אם הוזן), תמונת החשבון מ-Google, מין (לניסוח הפניות בעברית), תפקידים במערכת, האילוצים וההעדפות שהוגשו, ימי היעדרות, והשיבוצים בסידורי העבודה. נשמרת גם העדפת התצוגה (בהיר או כהה), וכשמופעלות התראות לנייד — מזהה ההתראות של אותו מכשיר ותיאור מקוצר של הדפדפן, כדי שאפשר יהיה לשלוח אליו. פנייה דרך טופס "יצירת קשר" נשמרת עם הפרטים שהוזנו בה.
היעדרות מסומנת כחופשה או כמחלה, ואפשר לצרף לה הערה. הסיווג וההערה נשמרים בנפרד משאר ההיעדרות ונגישים למנהלים בלבד — לשאר חברי הצוות מוצגים התאריכים בלבד, כי זה מה שהשיבוץ צריך.
המערכת בנויה על עקרון צמצום המידע: לא נאספים מספרי זהות, דרגות, שיוך יחידתי מזהה או מיקומים — ושמות התפקידים והמשמרות נשמרים ניטרליים.
איפה המידע יושב ומי רואה אותו
כל הנתונים נשמרים בשירותי Firebase של Google (אימות ומסד נתונים), ומוגנים בחוקי הרשאה בצד השרת: חברי צוות רואים את הסידורים והאנשים של היחידה שלהם בלבד, ומנהלים — את מה שבהיקף הניהול שלהם.
לאפליקציה עצמה אין שרת: היא רצה בדפדפן ופונה ישירות ל-Firebase. יש לשירות תהליך מתוזמן אחד, על מכונה בשליטת מפעיל השירות, שרץ פעמיים ביום וגם מיד אחרי פעולה שמצדיקה התראה. התהליך קורא את הנתונים במפתח ניהולי — מפתח שחוקי ההרשאה שלמעלה אינם חלים עליו — כדי לשלוח את ההתראות למכשירים, ובשביל להתאים תשלומים לעסק שביצע אותם. זה תהליך שלנו ולא של צד שלישי, והוא קורא את מה שדרוש לשליחה בלבד.
המידע אינו נמכר ואינו מושכר, ואינו משמש לפרסום. הוא מגיע לצדדים שלישיים רק במידה שהשירות עומד עליהם — הרשימה המלאה בסעיף הבא, ואין מלבדה.
לאילו שירותים חיצוניים מגיע מידע
- Google. Firebase מאחסן את הנתונים ומטפל בהתחברות; Firebase Cloud Messaging מעביר את ההתראות למכשיר; Google Analytics מקבל את מדידת השימוש שמתוארת בסעיף הבא; ויומן Google — רק כשההרשאה ניתנת, ורק כמתואר למטה.
- GitHub ו-Oracle Cloud. התהליך המתוזמן ששולח את ההתראות מופעל דרך GitHub Actions ורץ על מכונה של מפעיל השירות אצל Oracle Cloud. הנתונים אינם נשמרים שם — הם נקראים לזיכרון לצורך השליחה ונמחקים עם סיום הריצה.
- Make. אחרי פעולה שמצדיקה התראה הדפדפן שולח בקשה ריקה לכתובת ב-Make, שכל תפקידה להעיר מיד את התהליך המתוזמן במקום להמתין לריצה הבאה. הבקשה אינה נושאת שום תוכן — לא מי, לא מה ולא למי — אבל כמו בכל פנייה ברשת, כתובת ה-IP של הדפדפן גלויה לשירות שמקבל אותה.
- Grow ו-Morning (חשבונית ירוקה). התשלום מתבצע בעמוד שלהם ולא באתר הזה: פרטי כרטיס האשראי אינם עוברים דרכנו ואינם נשמרים אצלנו. בכיוון ההפוך נמשך מהם דוח התשלומים, וכתובת המייל שבחשבונית היא מה שמקשר תשלום לעסק.
- Google Fonts. דפי השיווק הציבוריים (עמוד הבית, המדריכים, עמוד התשלום) טוענים את הגופן משרתי Google. באפליקציה עצמה, ובעמודי המדיניות האלה, הגופן מוגש מהאתר שלנו.
מדידת שימוש
באתר יש מדידת שימוש, והיא מגיעה ל-Google Analytics (GA4) — שירות של Google, כלומר צד שלישי. היא קיימת כדי לדעת אילו מסכים בשימוש, מה נשבר, ומה עולה למערכת בקריאות למסד הנתונים.
מה נשלח: פתיחת האפליקציה וסגירתה; פתיחת מסך וסגירתו — לפי כתובת המסך וכמה זמן הוא היה פתוח; לחיצה על כפתור או קישור — לפי הכיתוב הקבוע שעליו ("שמירה", "יצירת קשר"); התרחשות שגיאה — לפי סוגה בלבד; ספירה טכנית של כמה מסמכים כל מסך קרא או כתב במסד הנתונים, לפי שם האוסף; ועוד כמה אירועי מוצר בודדים באותה צורה — שדבר מה קרה (שהאפליקציה נפתחה מחדש על מסך הבית, שפעולה הגיעה למבוי סתום), בלי תוכן ובלי מזהה.
מה לא נשלח: החשבון אינו מזוהה מול Analytics — לא מזהה משתמש, לא שם, לא מייל ולא טלפון. לא נשלח תוכן: לא משמרות, לא אילוצים, לא הודעות ולא טקסט חופשי כלשהו. מזהה של סידור עבודה מוחלף בסימן כללי לפני השליחה, ודיווח הדפים האוטומטי של Google — שהיה שולח את שורת הכתובת כמות שהיא — מכובה מהקוד בדיוק מסיבה זו.
מה Analytics אוסף בעצמו: ככל שירות מדידה, הוא מייצר מזהה אקראי שנשמר בדפדפן, ומסיק מכתובת ה-IP מיקום גס (מדינה או אזור), לצד סוג המכשיר, הדפדפן והשפה. אין באתר פרסום, אין רשתות פרסום, והמידע הזה אינו משמש לפרסום ואינו נמכר.
דיווחי תקלה ויומן דיבאג
כשהאפליקציה נשברת נשלח למפעיל השירות דיווח אוטומטי: הודעת השגיאה והמעקב הטכני שלה, גרסת האפליקציה, כתובת המסך שבו קרה, וזיהוי הדפדפן. הדיווח נושא מזהה אקראי שנולד עם טעינת הדף ומת איתה — לא מזהה החשבון — כדי לדעת אם תקלה קרתה לאדם אחד או לכולם בלי לדעת למי. דיווחי התקלה נמחקים אוטומטית אחרי 90 יום.
בנוסף, האפליקציה מחזיקה בזיכרון הדפדפן יומן קצר של הפעולות האחרונות. הוא לא נשלח לשום מקום ונמחק ברענון הדף — אלא אם מסמנים במפורש את התיבה בטופס "יצירת קשר" ומצרפים אותו לפנייה. זו הדרך היחידה שבה הוא יוצא מהמכשיר.
הרשאת יומן Google (אם בחרת לחבר)
חיבור היומן הוא רשות. אם מאשרים אותו, המערכת משתמשת בהרשאה אך ורק כדי: (1) לקרוא את רשימת היומנים שלך — לבחירת יומן היעד; (2) להוסיף, לעדכן ולהסיר ביומן שבחרת את אירועי המשמרות שלך בלבד, המסומנים בתיוג של המערכת. המערכת לא קוראת אירועים אחרים ביומן, לא שומרת את תוכן היומן אצלה, ולא שומרת את אסימון הגישה — הוא חי בדפדפן לזמן קצר בלבד. אפשר להסיר את ההרשאה בכל רגע דרך הגדרות חשבון Google (הרשאות אפליקציות צד שלישי).
השימוש במידע המתקבל מ-Google API עומד ב-Google API Services User Data Policy, כולל דרישות ה-Limited Use: המידע משמש רק לאספקת התכונה שתוארה, אינו מועבר לאיש ואינו משמש לפרסום.
כיצד המידע מוגן
- הצפנה בתעבורה. האתר מוגש ב-HTTPS בלבד, וכל הפנייה לשירותי Google ו-Firebase נעשית בערוץ מוצפן (TLS).
- הצפנה באחסון. הנתונים יושבים ב-Cloud Firestore, שמצפין אותם במנוחה כברירת מחדל בניהול Google.
- בקרת גישה בצד השרת. ההרשאות נאכפות בכללי אבטחה בשרת ולא בממשק: ברירת המחדל היא חסימה, וכל קריאה או כתיבה מותרת רק למי שהכלל מתיר לו במפורש. שינוי בממשק אינו יכול לעקוף אותם.
- כניסה מזוהה בלבד. ההתחברות היא בחשבון Google — אין סיסמאות ואיננו שומרים אף אחת. פתיחת עסק חדש אפשרית בהרשמה עצמית; הצטרפות לעסק קיים היא בהזמנת מנהל בלבד.
- אסימון היומן אינו נשמר. הוא מוחזק בזיכרון הדפדפן למשך הפעולה בלבד — לא נכתב למסד הנתונים, לא נשמר בדפדפן ולא נשלח לשום מקום. רענון הדף מוחק אותו, ויש לאשר מחדש.
- הרשאות מינימליות. מבוקשות שתי הרשאות יומן בלבד, וכל אירוע שהמערכת יוצרת נושא תיוג פנימי — כך שסנכרון חוזר נוגע אך ורק באירועים שהיא עצמה יצרה.
- בלי פרסום ובלי מסחר במידע. אין באתר פרסום, אין רשתות פרסום ואין כלי מעקב פרסומי, והמידע אינו נמכר ואינו מושכר. מדידת השימוש שכן קיימת מפורטת במלואה בסעיף "מדידת שימוש" למעלה.
פתיחת עסק ויצירת קשר
בפתיחת עסק באתר נשמרים שם העסק, מזהה החשבון שפתח אותו ומועד הפתיחה. על עצם הפתיחה נשלחת התראה למפעיל השירות, כדי שיידע שנפתח עסק חדש ויוכל להיות זמין לו; ההתראה נושאת את שם העסק בלבד ואינה מגיעה לאיש מלבדו.
פתיחת עסק היא תחילתה של התקשרות מסחרית — השירות חינמי עד מספר עובדים מסוים ובתשלום מעבר לו, והחיוב חל על החשבון שפתח את העסק. לכן מפעיל השירות רשאי לפנות אל מי שפתח את העסק, במייל או בטלפון השמורים בחשבון, בענייני החשבון והשימוש בשירות: ליווי בהקמה, מענה לתקלות, משוב על השירות ועדכונים בנוגע לתוכנית ולתשלום. אין מדובר בדיוור פרסומי, ואפשר לבקש בכל עת להפסיק פניות כאלה.
שמירה ומחיקה
המידע נשמר כל עוד הצוות משתמש במערכת. הסרה של חבר צוות מוציאה אותו מהיחידה ומכל הרשימות ומבטלת את הגישה שלו, אבל היא אינה מחיקה: הפרופיל עובר לארכיון שרק מנהלי אותה יחידה רואים, כדי שאפשר יהיה להחזיר אותו כפי שהיה, והשם נשאר צמוד לשיבוצים שכבר נעשו — סידור עבודה מהעבר לא משנה את עצמו למפרע. מחיקה מלאה, של הארכיון ושל השם, נעשית לפי בקשה דרך טופס יצירת הקשר.
יחידה שאין בה שום סידור עבודה אפשר למחוק מתוך המערכת, על נתוניה; יחידה שכבר יש בה סידורים נמחקת לפי בקשה, כדי שמחיקה בטעות לא תמחוק את ההיסטוריה של כל הצוות. פניות דרך טופס יצירת הקשר נמחקות אוטומטית אחרי 180 יום, ודיווחי תקלה אחרי 90 יום.
ניתוק היומן מפסיק כל גישה אליו מיידית; אירועים שכבר נוצרו נשארים ביומן עד להסרתם, ואפשר להסיר אותם דרך סנכרון נוסף אחרי שהמשמרות ירדו מהסידור, או ידנית מתוך היומן.
מחיקה ופניות
להסרת חשבון ומחיקת הנתונים, או לכל שאלה על פרטיות — אפשר לפנות דרך טופס יצירת הקשר או למנהל הקבוצה שלך.
הבהרה — כלי חוקי העבודה
סימוני העמידה בחוקי העבודה (מנוחה, עבודת לילה) מחושבים מנתוני הסידור בלבד ואינם ייעוץ משפטי; האחריות לעמידה בדין חלה על המעסיק, כמפורט בתנאי השימוש.
Privacy Policy (English summary)
"Shifts" is a shift-scheduling app for small teams. It stores only what scheduling requires: display name, email, phone (optional), the Google account picture, gender (for Hebrew phrasing), roles, submitted availability constraints, recorded absences and shift assignments, plus the light/dark preference and — when phone notifications are turned on — that device's notification id and a shortened browser description. An absence is tagged as leave or sickness and may carry a note; that tag and note are stored apart from the rest and are visible to managers only, while colleagues see the dates alone. No national ID numbers, ranks, identifying unit affiliation or locations are collected. Data is stored in Google Firebase (Authentication and Firestore), protected by server-side security rules, and is never sold or rented. Google Calendar access, if granted, is optional and used solely to list your calendars and to create, update or remove your own shift events in the calendar you choose; no other calendar data is read or stored, and the access token is kept in the browser only. You can revoke access at any time from your Google Account permissions. Shifts' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. For data deletion or any privacy question, use the contact form.
Data protection. All traffic is served over HTTPS, and every call to Google and Firebase services runs over TLS. Data is stored in Cloud Firestore and encrypted at rest by default under Google-managed encryption. Authorisation is enforced by server-side security rules rather than in the interface: access is denied by default, and each read or write is permitted only where a rule allows it, so no change in the client can bypass them. Sign-in is with a Google account — we store no passwords. A new business account can be opened by self-registration; joining an existing one requires an invitation from its administrator. Opening a business stores its name, the id of the account that opened it and the time it was opened, and notifies the operator that a business was opened — that notice carries the business name only and goes to nobody else. Opening a business also begins a commercial relationship: the service is free up to a number of staff and paid beyond it, and whoever opened the business is the account holder who is billed. The operator may therefore contact them, at the email or phone held on the account, about that account and their use of the service — help with setting up, support, feedback, and notices about the plan and payment. That is not marketing mail, and it can be stopped at any time. The Google Calendar access token is held in browser memory for the duration of the operation only; it is never written to the database, never persisted in the browser, and never sent anywhere else, so reloading the page discards it and consent must be granted again. The app requests only the two calendar scopes it needs, and every event it creates carries a private tag so that later syncs touch only events it created itself.
No servers of our own, with one exception. The app runs in the browser and talks to Firebase directly. One scheduled process, on a machine the service operator controls (run through GitHub Actions on Oracle Cloud), runs twice a day and again right after an event worth notifying about. It reads the data with an administrative key that the security rules above do not apply to, in order to send the notifications to devices and to match payments to the business that made them. It is our process and not a third party's, it reads only what sending requires, and it keeps nothing: the data is held in memory for the run and is gone when the run ends.
Third parties that receive data. This is the whole list. Google: Firebase stores the data and handles sign-in, Firebase Cloud Messaging delivers notifications to the device, Google Analytics receives the usage measurement described below, and Google Calendar only where that permission was granted. GitHub and Oracle Cloud: they run the scheduled process above. Make: after an event worth notifying about, the browser sends an empty request to a Make address whose only job is to wake that process immediately instead of waiting for its next run — the request carries no content at all (not who, not what, not to whom), though as with any network request the browser's IP address is visible to the service receiving it. Grow and Morning (Green Invoice): payment happens on their page and not on this site, so card details never pass through us and are never stored by us; in the other direction their payment report is pulled in, and the email address on the invoice is what links a payment to a business. Google Fonts: the public marketing pages (home, guides, checkout) load their font from Google's servers, while the app itself and these policy pages serve it from our own site.
Usage measurement. The site does measure usage, and it goes to Google Analytics (GA4) — a Google service, and therefore a third party. What is sent: the app opening and closing; a screen opening and closing, by the screen's address and how long it was open; a click on a button or link, by the fixed label written on it; that an error occurred, by its type only; a technical count of how many documents each screen read or wrote in the database, by collection name; and a handful of individual product events of the same shape — that something happened (the app relaunched onto the home screen, an action reached a dead end), with no content and no identifier. What is not sent: the account is not identified to Analytics — no user id, no name, no email, no phone. No content is sent: no shifts, no constraints, no messages, no free text of any kind. A schedule's id is replaced with a generic marker before sending, and Google's own automatic page report — which would have sent the address bar verbatim — is switched off in the code for exactly that reason. What Analytics collects by itself: like any measurement service it creates a random identifier held in the browser and infers a coarse location (country or region) from the IP address, alongside device type, browser and language. There is no advertising on the site, no ad networks, and none of this is used for advertising or sold.
Crash reports and the debug log. When the app breaks, an automatic report goes to the service operator with the error message and its technical trace, the app version, the address of the screen it happened on, and browser identification. The report carries a random id born with the page load and dying with it — not the account id — so that a fault can be told apart as "one person" or "everyone" without knowing who; crash reports are deleted automatically after 90 days. Separately, the app keeps a short log of recent actions in browser memory. It is sent nowhere and is cleared on reload, unless the box on the contact form is explicitly ticked to attach it to a message. That is the only way it leaves the device.
Retention and deletion. Data is retained while the team uses the app. Removing a member takes them out of the unit and out of every list and ends their access, but it is not a deletion: their profile moves to an archive only that unit's managers can see, so it can be restored as it was, and their name stays attached to assignments already made, because a past schedule does not rewrite itself. Full deletion, of the archive and the name, is done on request through the contact form. A unit with no schedules in it can be deleted from within the app along with its data; a unit that already has schedules is deleted on request, so that one mistaken click cannot erase a whole team's history. Contact messages are deleted automatically after 180 days and crash reports after 90. Disconnecting the calendar ends all access to it immediately.