Privacy Policy
Last Updated 13.07.2026
Contact Email: contact@finalscore.app
FinalScore (hereinafter: "the Business") is committed to protecting your privacy. This policy details how information is collected and used, in accordance with the Protection of Privacy Law, 5741-1981 and its regulations. For any questions, you can contact us: contact@finalscore.app
B2B Data Processing Layout (Holder vs. Database Owner): When uploading third-party data (such as customer or employee details of system users) to the platform, the business user serves as the sole "Database Owner". The Business acts solely in the capacity of "Holder" and/or "Processor". The responsibility for obtaining informed consent to collect the information, use it, its legality and reliability, falls entirely on the business user alone. The Business will never bear any liability toward third parties whose data was entered into the system through negligence or omission by platform users.
1. Information Collection
Types of Information We Collect 1.1. Transparency in Information Collection: Due to the nature of the service and Site activity, we collect and process the following information:
- Full name
- Email address
- Date of birth
- Country
- Gender
1.1.1. Legal Clarification: In accordance with Amendment 13 to the Protection of Privacy Law, technical information such as IP address, location data, and digital identifiers is considered personal information to all intents and purposes, and we treat it in accordance with the required level of security and privacy.
1.2. Obligation to Provide Information and Consent (Amendment 13): You are under no legal obligation to provide the information, and its provision depends on your free will and full consent. It is clarified that the information is collected for the purposes detailed in Section 2 below.
1.3. Consequences of Non-Provision: However, non-provision of the required information may result in: blocking of the transaction/service.
1.4. Data Retention Period: We retain the information for the time necessary to fulfill the purposes detailed in this policy, or for a longer period if required by law (e.g., for bookkeeping purposes or legal grounds). Below are the main retention periods:
| Category | Type of Information | Retention Period |
|---|---|---|
| Financial and invoice information | Financial and invoice information | 7 years (according to bookkeeping regulations) |
| Technical and analytical information | Technical and analytical information | Up to 24 months from collection |
2. Purposes of Using Information
2.1. The information will be used by the Business solely for the following purposes:
- Providing and operating the service
- Technical support and customer service
- Analyzing usage and improving the service
- Personalization
2.2. Data Retention Period: Up to one year after the termination of service.
2.3. Non-provision of information: Blocking of the transaction/service.
Use of Anonymized (Statistical) Information: It is hereby clarified that the Business collects Aggregated Non-identifiable Data on system usage patterns. The Business reserves the full and irrevocable right to make any use of this anonymous statistical information, including selling it to third parties, conducting future research, and training artificial intelligence (AI) models or algorithms, without any obligation to pay consideration of any kind to the user.
Transparency and Use of Data for AI Training: The Business clarifies that it may use anonymous technical information (such as usage patterns, performance data, and non-personally identifiable metadata) for the development, training, and improvement of artificial intelligence models and to improve the user experience. It is clarified that identifiable personal information (such as name, phone, or email) is not used to train these models without separate individual consent.
Algorithmic Transparency and Artificial Intelligence (2025 Reform): It is hereby clarified that some service decisions, content adaptation, or price determinations on the Site may be executed automatically through algorithms and/or artificial intelligence (AI) systems. The Business commits that the use of these technologies is conducted fairly and transparently.
3. Information Security
3.1. We implement information security measures in accordance with legal requirements (Protection of Privacy Regulations, Information Security, 2017).
3.2. Medium Security Level (Level 3):
- A Data Protection Officer (DPO) has been appointed for privacy protection matters and a procedure is implemented for immediate reporting of security incidents to the Privacy Protection Authority.
- The Business establishes a mechanism for performing periodic information security audits.
- Complex password procedures and access management.
- Logging and tracking of database access (LOGS).
3.3. Sensitive Information: We process sensitive information (health condition / illnesses) and implement special protective measures accordingly.
3.4. Payment Security: Payment processing on the Site is performed via a secure external clearing company complying with the PCI DSS (Payment Card Industry Data Security Standard). Users' credit card details are encrypted with SSL technology and are not saved on the Business's servers.
4. Transfer of Information to a Third Party - Transparency (Amendment 13)
4.1. We may share information only with essential entities for the purpose of providing the service, according to the details below:
| Category | Provider / Identity | Geographic Location | Purpose | Privacy Policy |
|---|---|---|---|---|
| Clearing and payments | Freemius | According to provider's policy | Executing charges (subject to strict security standard) | See provider's privacy policy |
| Clearing and payments | Tranzila | According to provider's policy | Executing charges (subject to strict security standard) | See provider's privacy policy |
| Marketing and mailing | Lovable, Mailgun | According to provider's policy | Sending updates and benefits (subject to consent) | See provider's privacy policy |
| Data analysis and statistics | Google Analytics (Google Ireland Ltd) | European Union (Ireland) | Improving user experience and traffic analysis | Link |
| Cloud hosting and infrastructure | Lovable Cloud, Supabase | According to provider's policy | Information storage, backup, and security | See provider's privacy policy |
| Artificial Intelligence (AI) | Lovable | According to provider's policy | Improving service, content generation, and automated response | See provider's privacy policy |
4.2. Responsibility and Risk Minimization: Information transferred to third parties will be transferred as much as possible in an anonymous or coded (Hashing) format. The Business remains obligated and responsible to the user regarding the handling of information by these providers in accordance with Israeli law.
4.3. Legal Clarification: The use of these services is subject to the privacy policy and terms of use of each provider separately. We recommend reviewing the privacy policies of the relevant providers.
4.4. International Transfer: Some providers may be located outside of Israel (including cloud providers). In this case, we will ensure that the transfer is carried out subject to adequate legal mechanisms.
5. Convenience Cookies and Tracking Technologies
5.1. This Site uses cookies and tracking tags for ongoing operation, information security, and user experience improvement.
6. User Rights
6.1. The Protection of Privacy Law, 5741-1981, grants you the following rights:
- Right to Review (Section 13 of the Law): Your right to review the information held about you in our database.
- Right to Amend (Section 14 of the Law): If you find that the information about you is incorrect, incomplete, unclear, or outdated, you may contact us to request amendment or deletion of the information (subject to legal provisions).
- Right to Erasure/Be Forgotten: You may request the deletion of your personal information, provided the information is no longer required for service purposes or for binding legal documentation.
Prevention of Spam (Section 30A of the Communications Law): Sending promotional material will only be done subject to obtaining explicit consent for marketing as required by law. It is hereby clarified that you have the right to request removal from the mailing list at any time, easily and free of charge. Removal will be possible in the same manner the message was sent (e.g., replying "Remove" or "הסר" in SMS messages, or clicking the dedicated link at the bottom of every marketing email). Or by directly contacting the address contact@finalscore.app, which will result in immediate deletion from the database.
Additional Rights (GDPR Regulations / International Users): European Union users enjoy expanded rights:
- Data Portability: Your right to receive your personal information in a structured, commonly used, and machine-readable format.
- Right to be Forgotten: The right to demand absolute deletion without delay (subject to legal exceptions in Article 17 of the GDPR).
- Objection to Processing: The right to object to information processing for direct marketing purposes or legitimate interests.
Data Protection Officer (DPO): For inquiries belonging to EU users, you may contact our privacy protection officer at the email address listed above, or our European representatives if appointed.
6.2. Method of Exercising Rights: Requests to exercise rights can be directed to our email address: contact@finalscore.app.
6.3. Section 17 of the Law: The database manager is responsible for the security of the information within it. We operate in accordance with the provisions of the law and regulations for information security.
7. Protection of Minors' Privacy
7.1. The Site is also intended for users under the age of majority. Use of the Site by minors (under the age of 13) is conditional upon obtaining explicit consent from a parent or legal guardian, via: prior written consent.
7.2. In accordance with Amendment 13 to the Protection of Privacy Law, 5785-2025, a parent or legal guardian of a minor has all the rights enumerated in this policy (review, amendment, deletion, objection to processing) regarding the minor's data.
7.3. In the event of a parent or guardian's refusal to give consent, the minor will not be permitted to use the Site, and their data will be deleted from the database.
8. International Information Transfer
8.1. As part of our operations, personal information may be transferred and processed outside the borders of Israel.
8.2. Countries with an Adequate Level of Protection: The transfer of information to European Union (EU/EEA) countries is executed in accordance with the Adequacy Decision granted to Israel.
8.3. Transfer to Other Countries: If information is transferred to countries lacking an adequate level of protection, we will ensure that the transfer is carried out via one of the following mechanisms:
- Standard Contractual Clauses (SCC)
- Explicit consent of the data subject
- Contractual commitment of the recipient to comply with Israeli privacy protection standards
8.4. For more information regarding international transfers and existing safeguards, you may contact us.
9. Notification of a Security Incident
9.1. In accordance with the Protection of Privacy Regulations (Information Security), 5777-2017, in the event of a severe security incident that may cause substantial harm to privacy, we will act as follows:
- Report to the Authority: We will notify the Privacy Protection Authority without delay.
- Notice to Affected Parties: We will notify the affected data subjects if the incident is likely to cause them substantial harm.
- Documentation: We will document the incident, its impact, and the actions taken to address it.
9.2. The notification will include the nature of the incident, the type of information exposed, the potential risks, and recommended steps for protection.
10. Updates to the Policy
10.1. We may update this policy from time to time. Material changes will be published on the Site and/or sent via direct message.
10.2. Continued use of the services after the publication of changes constitutes consent to the updated policy.
10.3. It is recommended to review this policy periodically to check for updates.
11. Privacy Protection Management and Contact
11.1. The Business operates in accordance with the provisions of the law to prevent harm to the privacy of employees and customers.
11.2. Data Protection Officer (DPO): The Company has appointed an information security officer (role: Business Owner) as responsible for privacy protection in the organization. You may contact the officer with any questions regarding your rights under the Protection of Privacy Law, 5741-1981, via the following methods:
- By email - contact@finalscore.app
11.3. Response Time: We commit to responding to privacy inquiries and the exercising of rights (review/amend/delete) within a reasonable timeframe (up to 30 days), in accordance with legal requirements.
This policy was last updated on 13.07.2026
© All rights reserved to FinalScore 2026
