This website is operated by Daniel Mashkov, Licensed Business (Israel). This policy explains how I collect, use, retain, and protect personal data under the Israeli Protection of Privacy Law, 5741-1981, including Amendment 13 (in force since 14 August 2025), and the Protection of Privacy Regulations (Data Security), 5777-2017. California residents get the rights described in the CCPA as amended by the CPRA (see section 8).
Privacy at a glance — Site-form submissions: kept 24 months, then deleted automatically. IP addresses: only a hash, held for up to 60 seconds for rate limiting, never stored in the database. Severe security incidents: reported to the Privacy Protection Authority immediately. Data-subject requests: answered within 30 days.
1. Information I Collect
1.1 Information You Provide Directly
- Contact form: Name, email address, phone number (optional), message content, and attribution data where available (referring site, landing page, UTM source / medium / campaign). Persisted to Supabase (leads table).
- Lead magnet form: Email address, name (optional), the resource you asked for, your website address (optional — so the free audit has a site to review), and attribution data where available. Persisted to Supabase (leads table). To avoid sending the same resource twice, a hash of your email address is also held in Upstash for 24 hours.
- Project intake form: Name, email address, company, current website, project goals, target audience, requested features, budget, timeline, additional details, and attribution data where available. Persisted to Supabase (leads table, lead_type: intake).
- Scope estimator & 2-minute quote: Email address and the answers you picked: project type, selected features, page count (scope estimator), new build or existing site and timeline (2-minute quote), and the resulting scope tier — plus attribution data where available. Neither tool asks for your name or company. Persisted to Supabase (leads table, lead_type: estimator).
- Call booking: Name, email address and the time you choose are sent to Cal.com to create the booking, and a copy of the request is saved to the leads table so I can follow up.
- Site assistant: Questions you type into the site assistant are currently answered on the site itself, from a fixed set of answers written from this site's content. The question text is not stored and is not sent to any AI provider; the site only keeps a count of how many times each answer was used, with nothing that identifies you. If a live AI model is connected in the future, question text — without your name or contact details — would be sent through Cloudflare AI Gateway to the model provider, and this policy will name that provider before that happens.
- Data-subject request form: Name, email address, request type and your description. Persisted to Supabase (dsr_requests table). So the confirmation emails go out at most once a day per requester, a hash of your email address is also held in Upstash for 24 hours.
- Revenue Impact Calculator (/tools/revenue-impact): Monthly visitor count, conversion rate, page load speed, and average order value — entered entirely at your discretion. All calculations are performed client-side in your browser. No input values are transmitted to my servers, stored in any database, or shared with third parties. No personal identifiers are collected or processed by this tool.
- Site report tool: The website address you enter is checked with Google's PageSpeed Insights API when live checks are enabled. It is not stored.
1.2 Information Collected Automatically
- IP address: Your IP address is used for rate limiting on the site's forms and assistant. Only a SHA-256 hash of it is held, in Upstash Redis (EU, Frankfurt), as part of a short-lived counter that expires 60 seconds after your first request; it is never written to the site's database. A hash of an IP address can still be linked back to it, so it is treated as personal data. The hosting and network providers (Vercel, Cloudflare) also process IP addresses in their own request logs. IP addresses are personal data (CJEU, Breyer, C-582/14).
- Google Analytics 4 (GA4): Usage events, referrer, browser and device information. The GA4 script loads with Google Consent Mode v2 set to 'denied' for analytics storage, so no analytics cookies are set until you agree: on the English site by choosing "Accept All", on the Hebrew site by acknowledging the analytics notice. Until then Google may receive cookieless, aggregate pings. A Global Privacy Control signal is treated as a refusal. Automated browsers and the site owner's own visits are excluded.
- First-touch attribution (dm-first-touch): When you arrive, the site records in this tab's sessionStorage the referring site (host and path only — no query string), the landing page path, and any utm_source / utm_medium / utm_campaign values. It stays in your browser, is deleted when the tab is closed, and is sent only as part of a form you choose to submit, so I know where an inquiry came from. It is never shared with advertising platforms.
- Cookies & local storage: cookie-consent (localStorage) stores your consent choice — 'all', 'il-notice' (Hebrew-site analytics notice acknowledged) or 'none' (analytics refused) — and each choice is also recorded, without IP or email, in the consent audit log (see section 4). cookie-consent-gpc records that a Global Privacy Control signal was honored. The consent model (notice with opt-out on the Hebrew site, explicit opt-in on the English site) follows the site language you are viewing — no country detection is used.
- Locale cookie: The site sets no language cookie. The language comes from the page address (/he for Hebrew). Until 4 October 2026 a NEXT_LOCALE cookie was set; a copy stored by an earlier visit holds only "en" or "he", is no longer read, and expires on its own (a session cookie, or about one year if it came from an old /en link).
- Browser storage (dm- keys): Functional preference keys prefixed dm- are kept in localStorage: dm-theme / dm-prefs (theme, accent and motion choices), dm-exit-offer (so the exit offer shows only once), dm-concierge-dismissed (you closed the assistant prompt), dm-perf-checklist (saved checklist progress) and dm-analytics-exclude (owner analytics opt-out). dm-concierge-popped, dm-lead-submitted (you already sent a form in this tab, so the pop-up offers stay closed) and dm-first-touch (above) live in sessionStorage and are cleared when the tab closes. The preference keys hold no personal data and persist until you clear your browser data.
- Vercel Web Analytics: Vercel's Web Analytics component loads on every page and sends page views to Vercel without cookies or personal user identifiers; it is not consent-gated.
1.3 Information of Special Sensitivity (Amendment 13)
Amendment 13 defines categories of "information of special sensitivity", including location data. This site does not deliberately collect any of those categories.
- Location: GA4 derives an approximate country and city from your connection at collection time; Google states that GA4 does not log or store IP addresses. The site itself stores no location data.
- IP address: Treated as personal data: used only, in hashed form, for rate limiting as described above, never stored in the database, and never passed to marketing vendors.
1.4 Why I Ask, and Whether You Have To (Protection of Privacy Law, Section 11)
The controller of this data is Daniel Mashkov, a licensed business (sole proprietor) in Israel, reachable at info@danielmashkov.com. No law requires you to give me any of the details above — it is your choice. Fields a form marks as required, such as your email address, are needed so I can reply; without them the form cannot be sent. Everything else is optional. The details are used only for the purposes in section 2, are passed only to the service providers in section 3 (some outside Israel), and you can ask to see, correct or delete them (section 5).
2. How I Use Your Information
- Responding to your inquiries and delivering requested services
- Preventing abuse via rate limiting (up to 5 requests per minute per IP, on every form endpoint and the site assistant)
- Improving the site based on aggregate usage analytics
- Internal attribution of traffic sources (UTM data, never shared externally)
I do not sell, rent, or share your personal information with third parties for marketing purposes.
I do not send newsletters or marketing email. You receive only replies about the request you made. If I ever want to send you marketing messages, I will first ask for your separate, explicit consent, as section 30A of the Communications (Telecommunications and Broadcasting) Law requires.
3. Subprocessors
I use the following third-party services to process data on my behalf:
- Vercel Inc.: Website hosting, serverless functions and edge network — USA / global edge.
- Supabase Inc.: Database for site-form submissions (leads table), the consent audit log and data-subject requests — EU (Ireland, eu-west-1).
- Airtable Inc.: CRM lead sync — Account + Engagement records for contact / intake / estimator submissions — USA.
- Resend Inc.: Transactional email: new-inquiry notifications to me and the acknowledgment email to you — USA.
- Upstash Inc.: Rate limiting (hashed IP address, 60 seconds) and duplicate suppression for the lead magnet and for data-subject-request emails (hashed email address, 24 hours) in Redis — EU (Frankfurt, eu-central-1).
- Google LLC (GA4): Usage analytics (analytics storage only with consent) — USA.
- Google LLC (Gemini API): The site owner's private operations bot uses Google's Gemini API. When you send an inquiry through the contact form, the project brief or the cost estimator, your name, company and message (not your email address) are sent to Google so the bot can draft a reply; the site owner reads every draft and decides whether to send it — nothing is sent to you automatically. When the owner asks the bot about a specific inquiry, that inquiry's details (name, email and message) are sent to Google to produce the answer. Not used for marketing — USA.
- Sentry Inc.: Error monitoring; personal data is scrubbed from error reports before they are sent — EU (Germany).
- Cal.com, Inc.: Appointment scheduling (on-demand, user-initiated) — USA.
- Cloudflare, Inc.: CDN, DNS, reverse proxy and edge network in front of the entire site — every request and IP address transits Cloudflare, which terminates TLS. Cloudflare Workers also host the operations bot described below — USA / global edge.
- Telegram (Telegram FZ-LLC): Operational notification only: when a form is submitted, the new-lead record (your name, email, and the details you provided) is relayed to the site owner's private Telegram chat so inquiries are seen promptly. Not used for marketing — global.
- Vercel Web Analytics: Privacy-friendly, cookieless aggregate traffic analytics — no personal identifiers and no cross-site tracking — USA.
Cross-border transfers are documented vendor by vendor. Where a processor offers a DPA and SCCs, those safeguards are used; where they are unavailable on a free tier (such as Airtable / Resend), that limitation is disclosed explicitly in the privacy inventory and compliance documentation.
The site assistant sends no visitor data to any AI provider (see "Site assistant" in section 1.1). The site owner's private operations bot uses Google's Gemini API, as listed above.
4. Data Retention
- 24 months — Site-form submissions (Supabase): Deleted automatically by a daily database job.
- 24 months — Airtable CRM lead records (Accounts + Engagements): Reviewed against the same 24-month standard and deleted immediately on request. Automated deletion is being put in place; records of engagements that became paid work are kept as contractual business records.
- 60 seconds — Hashed IP addresses (Upstash Redis): Rate-limit counters expire automatically 60 seconds after your first request.
- 24 hours — Hashed email address for the lead-magnet and data-subject-request duplicate checks (Upstash Redis): Expires automatically.
- Up to 14 months — GA4 data: GA4 event data is kept no longer than the 14-month maximum GA4 allows.
- Until cleared — Cookie consent state: Stored in localStorage.
- Until the tab closes — First-touch attribution (dm-first-touch): Stored in sessionStorage.
- 5 years — Consent audit log (consent_logs, Supabase): Anonymous records kept as proof of consent (PPL Amendment 13; GDPR Art. 7(1)) — no IP, no email stored.
- 5 years — DSR requests (dsr_requests, Supabase): Retained for legal audit trail — no IP stored.
5. Your Rights — PPL Amendment 13 (Israeli Law)
- Right of access: Request information about what personal data I hold about you — response within 30 days.
- Right to correction: Request correction of inaccurate personal data.
- Right to deletion: Request deletion of your personal data before the end of the retention period.
- Right to object: Object to processing of your data for marketing purposes.
To exercise any of these rights, use the secure form — see the Submit a DSR Request button below.
6. Data Security
- HTTPS encryption on all connections
- A Content Security Policy that limits scripts, frames and network connections to this site and a short list of named services
- Rate limiting on all form API endpoints (up to 5 requests per minute per IP)
- Supabase Row-Level Security — stored submissions cannot be read with the site's public key
- Server-side input validation and HTML escaping on all user-provided content
- Access to personal data restricted to Daniel Mashkov only
7. Cookies and Consent
Essential functionality sets no cookie of its own (the language cookie NEXT_LOCALE was removed on 4 October 2026) and uses localStorage keys for your consent choice (cookie-consent) and GPC detection (cookie-consent-gpc), plus functional preference keys prefixed dm-. Analytics cookies (GA4) are never set before you agree. The consent model follows the site language you are viewing: the Hebrew site shows a notice with an opt-out, and analytics cookies are enabled once you acknowledge it; the English site asks for explicit opt-in. A Global Privacy Control signal is treated as a refusal. You may change or withdraw your consent at any time via "Cookie Settings" in the site footer.
8. Do Not Sell or Share My Personal Information (CCPA — California Residents)
I do not sell or share the personal information of California residents for cross-context behavioral advertising. Whether or not the CCPA's thresholds apply to this site, California residents can ask to know, delete or correct the data I hold about them, opt out of sale or sharing, and will not be discriminated against for exercising these rights. Use the Submit a DSR Request button below.
9. Security Incident Response
The Protection of Privacy Regulations (Data Security), 5777-2017 (regulation 11), require a severe security incident to be reported to the Privacy Protection Authority immediately — since 2022 the Authority's position has been immediate notice on discovery, not a 72-hour window. I follow that standard, under this protocol:
Phase 1 — Detect & Contain (first hours)
- Immediate isolation of affected systems
- Initial documentation of breach scope and vector
- Activation of security incident response procedures
Phase 2 — Assess Severity (same day)
- Identify categories of data affected and number of individuals
- Assess the risk to the rights of the people affected
- Document in the internal security-incident log
Phase 3 — Notify the PPA (immediately once identified as severe)
- Submit notification to the Israeli Privacy Protection Authority (PPA)
- Include: nature of the incident, data categories, number of individuals, measures taken
Phase 4 — Notify Individuals (without undue delay)
- Individual notice to affected parties facing high risk
- Content: what occurred, data exposed, recommended actions, contact point
- Report to Israel's National Cyber Directorate (CERT-IL) where relevant
This protocol follows the Protection of Privacy Regulations (Data Security), 5777-2017, and the National Cyber Directorate's incident-reporting guidance.
10. Changes to This Policy & Contact
I may update this policy from time to time. Material changes will be posted on this page with a new "Last updated" date. A change will not be applied to details you have already given me for a new purpose without asking for your consent first.
Contact
For privacy questions or data-subject requests, use the Submit a DSR Request button below, or email info@danielmashkov.com.