Privacy Policy
Last updated September 25, 2026
TOVLI is an appointment-booking platform for businesses. This document explains what information is collected, why, and who can see it. It is written to describe the system as it is actually built.
What is collected
From a business owner: an email address and password for signing in, the business name, address, opening hours, services and prices, details of the staff they define, and any images they upload for their public page.
If a business owner turns notifications on, an identifier for that device or browser, issued by the push service, is kept as well. It identifies an installation rather than a person, and it goes when notifications are turned off.
From a customer booking an appointment, or joining a business's waiting list: a name and a mobile phone number, so the business can confirm the appointment, remind them of it, tell them about a change, or offer them a time that frees up. A business entering a customer itself may record an email address instead of, or as well as, a phone number.
A business may also keep a few optional details of its own about its customers: a date of birth, a preferred language, and free-text notes. TOVLI does not ask the customer for these, does not require them, and does not read them — they are the business’s own record.
A business may also record payments against its appointments — the amount, the method and a note — and the name and contact details of its accountant, so that period summaries can be sent to them.
Technical information: operational logs needed for security and service stability.
What is not collected
Customers have no TOVLI account and no password. An appointment is managed through a personal link carrying a unique capability token, not through registration.
We do not collect card or bank details from end customers, and we do not run advertising trackers on visitors.
Who is responsible for what
Customer information — name, phone number and appointments — is the responsibility of the business the appointment was booked with. That business decides what to collect and whom to answer, and the whole record is deleted when the business is deleted. TOVLI processes it on that business’s behalf and on its instructions only.
Account information belonging to the business owner — the email address and the sign-in — is TOVLI’s own responsibility.
The distinction decides who to write to. A customer asking for their details to be deleted should ask the business they booked with. If the request reaches us instead, we pass it to that business.
Who can see it
Each business sees only its own information. The separation is enforced in the database (Row Level Security), not only in the interface.
A customer sees only their own appointment, through a personal appointment link.
A business's booking page belongs to that business alone. A customer who arrives through one business's link is never shown another.
Where it is stored
Data is held with a cloud infrastructure provider (Supabase, built on PostgreSQL) and on cloud application servers (Vercel), within the European Union.
When a WhatsApp message is sent, the recipient's details also pass to Meta Platforms as a processor, under the WhatsApp Business terms.
When a notification is sent to a device, the device identifier and the notification's contents pass through the operating system's own push service: Apple (APNs) on Apple devices, Google (FCM) on Android devices, and the browser's push service for web notifications. Those services do not receive the appointment diary or the customer list.
Further sub-processors: Resend, which delivers system email — account confirmation and password reset — and TextMe, which delivers SMS. Together with those named above, that is everyone with technical access to the data as at the date of this document, and any change to the list will be recorded here.
Israel has been recognised by the European Union as providing an adequate level of protection, and transfers between Israel and the EU region rest on that basis.
Cookies
The site uses strictly necessary cookies only: the ones that keep a business owner signed in and remember the chosen language. Without them, staying signed in is not possible.
There are no advertising cookies, no third-party cookies and no social network pixels. That is also why there is no consent banner — there is nothing to ask consent for.
Security
Data is encrypted in transit (HTTPS) and at rest. Separation between businesses is enforced in the database itself, so a fault in the interface still cannot expose another business’s data.
Access to production data is limited to those who need it for their role, and sensitive operations are logged.
If a security incident occurs that could affect a person’s rights, we will inform the affected businesses and the competent authority, as the law requires and without undue delay.
Messages to customers
Messages to a business's customers are sent by TOVLI on that business's behalf — from TOVLI's WhatsApp number or TOVLI's SMS sender, unless the business has connected a number of its own. Each message names the business it is sent for, and nothing is sent for a business until TOVLI has switched messaging on for it.
Depending on the business's settings, these are: a confirmation when an appointment is booked, a reminder before it, a notice if it is moved, cancelled or running late, and an offer when a place on the waiting list opens. A business can also answer a customer directly from its inbox.
Promotional messages are sent by SMS, or by WhatsApp only from a number the business owns. An invitation to come back for a service already booked goes only to a customer who did not untick the box on the booking form; an announcement the business writes goes only to a customer who agreed to it explicitly. Each one says that it is an advertisement and how to refuse it. Refusing changes nothing about the appointment or the messages about it.
To send a WhatsApp message, the customer's name, phone number and appointment details pass to Meta Platforms through the WhatsApp Business Cloud API. To send an SMS, the phone number and the text of the message pass to TextMe, an Israeli SMS provider. Both process it as TOVLI's processors, and neither receives the appointment diary or the customer list.
When a customer replies, the reply arrives in TOVLI: its text, the number it came from and the time are stored and shown to the business in its inbox — including a reply from a number that is not on the business's customer list. A customer who replies STOP (or «הסר», «הפסק» or «توقف») stops receiving messages immediately, and the preference is held per business. Every choice a customer makes about messages is recorded with its date, and with the wording they were shown where there was one, and that record is kept while the business is on TOVLI, so the business can show what was agreed.
Retention and deletion
Appointment information is kept while the business remains active on the platform, as its service history.
A business owner can delete their business, and everything held about its customers, themselves from the account screen inside the product, and can delete the whole account from the same screen. For a single customer, the business can move them to the archive — out of its lists and every promotional audience — or mark their number wrong so that nothing is sent to it; their appointments, payment records and messaging choices are kept while the business is on TOVLI. A customer who wants those erased may ask the business or write to us, and we erase them on the business's instruction unless the law requires them to be kept.
Your rights
You have the right to know what information is held about you, to see it, to correct it, and to request its deletion. Requests are received at the address at the foot of the page and answered within the period the law allows.
These rights rest on the Israeli Protection of Privacy Law, 5741-1981 and its regulations. Where a request concerns information given to a particular business, we pass it to that business — it is the one in control of that data.
A business owner can delete their account and their business data themselves, from the account screen in the app, without writing to us.