Skip to content
OpticCount
All documents

Privacy policy

This document explains what information we collect about you, why, who it is shared with, how long it is kept, and how you exercise your rights. It is written to the Israeli Protection of Privacy Law, 5741-1981, including Amendment 13 which came into force on 14 August 2025, and to the Protection of Privacy (Data Security) Regulations, 5777-2017.

Updated:

Who we are

OpticCount is operated by InovyTech Cyber Ltd, company no. 516919370 ("the Company", "we").

InovyTech Cyber Ltd (OpticCount), 41 Hatzivoni St., Kiryat Ono, Israel. Email: OpticCount@inovyTech.com. Phone: +972 55 502 8179. Hours: Sunday to Thursday, 08:30 to 18:00 (Israel time).

Our privacy protection officer is Ori Rinat. Any privacy matter, including exercising your rights, is handled at OpticCount@inovyTech.com.

What this covers, and the difference between the site and the system

The distinction matters, because the two are entirely different in data terms.

  • The marketing site (opticcount.com): a public brochure site. No sign-up, no user account, no inventory. The only information collected is what you choose to type into the contact form or the quote builder.
  • The system (app.opticcount.com): the product itself, used by business customers under a contract. That is where a customer's catalogue, counts and users live.
  • The documentation site (docs.opticcount.com): user guides. A separate site.

Wherever this policy applies to only one of them, it says so explicitly. Anything not marked applies to both.

What the marketing site collects

The split here is between what is collected in any event, and what is collected only if you allowed it.

  • What you type into the form: full name, business name, phone number, industry, and the processes you ticked as relevant.
  • The context of your enquiry: which page it was sent from, the landing page the visit started on, the site you arrived from, any campaign parameters in the address (utm), an advertising click identifier if you came from an ad, the interface language and the time. This travels with the form so we know what you were reading and where you came from. None of it is stored on your device; it accompanies the enquiry itself.
  • As with any web server, our hosting provider keeps technical server logs that include IP addresses, for operation and security.
  • With your consent only: usage data from measurement and advertising tools, such as which pages were viewed, where you arrived from, device and browser type, and a cookie or device identifier.

Measurement and advertising tools are not loaded at all before you have given consent, and you can withdraw it at any time. The full detail, including tool names and categories, is in the cookie policy.

Measurement, advertising and consent

We use measurement tools to understand how the site performs, and advertising tools to measure campaigns and reach the right audience. Under Amendment 13 a cookie identifier, a device identifier and an IP address are personal data, so all of these operate on the basis of consent alone.

On your first visit you are offered a choice by category: strictly necessary (always on), measurement and improvement, and marketing and advertising. The latter two are off by default.

There is no implied consent here: browsing does not constitute consent, no box is pre-ticked, and refusing does not make the site harder to use in any way.

You can change or withdraw consent at any time through "Cookie settings" at the foot of every page. Withdrawal takes effect immediately going forward.

What the system collects

Inside the system, information is produced by the work itself. Most of it is the customer's business data (items, barcodes, quantities), but some of it is personal data and we treat it as such.

  • User details: name, phone or email for sign-in, role in the organisation, and the stores they may access.
  • Activity records: who scanned what, when, and in which store. Corrections and deletions are retained too. This is the heart of the product, and it is also personal data about an employee.
  • System logs: sign-ins, permission changes and errors.
  • Device permissions: camera access to read barcodes, and Bluetooth to pair a scanner. Camera images are never stored; only the barcode value that was read.
  • Billing and licensing: usage volume, plan and accounting documents.

We neither request nor need data of special sensitivity as defined in the law (health, biometric, criminal record and the like). If a customer enters such data into free-text fields on their own initiative, that is their responsibility, and we ask that they do not.

Why we collect it

Information given for one purpose will not be used for another unless we have told you and obtained the consent the law requires.

  • To answer an enquiry you initiated, arrange a demo and prepare a quote.
  • To provide the service: opening an account, authentication, permissions, running counts and producing reports.
  • To bill and administer the contract, and to meet accounting and tax obligations.
  • To secure the service, detect misuse and investigate faults.
  • To send marketing messages, and only where you have given separate, explicit consent.

Are you obliged to give us information, and what happens if you do not

You are under no legal obligation to give us any information. Providing it is voluntary.

That said, some details are simply what makes the thing you asked for possible: without a phone number or email we cannot get back to you, and without user details an account cannot be opened. Withholding them means we cannot provide the service, and that is the only consequence.

Declining marketing messages affects nothing else. It is not a condition of service and will not change your terms.

Who receives the information

We do not sell personal data, rent it, or pass it to advertisers. It is shared only with suppliers who provide us a service, and only to the extent that service requires.

WhoFor what
Hosting and compute providerRunning the site and the system, and storing data
make.comMoving form enquiries into our lead management
AirtableManaging enquiries and prospects
WhatsApp (Meta)Acknowledging an enquiry, and support conversations you start
Google, PostHogMeasuring site usage. With your consent only
Meta and advertising networksCampaign measurement and ad targeting. With your consent only
Payment processorProcessing payment. We do not store card numbers
Integration providersPassing data to the customer's ERP or POS, as they configure
Professional advisersAccounting and legal advice, under a duty of confidence
AuthoritiesOnly where required by law or court order

Every such supplier is contractually required to comply with the law, secure the data and not use it for their own purposes. Where we process data for a business customer we act as a holder on their behalf, and the processing terms are set out in a separate document.

Where data is stored, and transfers outside Israel

The system's servers and the customer data in it are hosted in Israel, and system data is not transferred outside Israel.

Alongside that, some of the external tools listed are operated by international companies. Only limited data is processed with them: contact details submitted in the form (passed to our lead-management pipeline), WhatsApp communication, and measurement or advertising metadata subject to your consent. Such data may also be processed in the European Union and the United States.

For every such transfer we act under the Israeli law governing transfers of data abroad, maintain a high level of security, and make sure an adequate level of protection or a suitable contractual arrangement with the supplier is in place.

Data we received from the European Economic Area is also handled under the Privacy Protection Regulations governing data transferred to Israel from the EEA.

How long we keep it

  • An enquiry that did not become a commercial relationship: up to 24 months from the last contact, then deleted or anonymised.
  • Active customer data: for the duration of the contract.
  • After the contract ends: deleted or anonymised within a reasonable period, except what we must retain by law.
  • Billing and accounting documents: for the retention period set by tax law.
  • System and security logs: for a limited period, as required by the Data Security Regulations.
  • An unsubscribe record: kept indefinitely, because it is the only way to honour your request over time.

Data security

We maintain data security procedures under the Protection of Privacy (Data Security) Regulations, 5777-2017, including a database definitions document, a security procedure, role-based permissions, access control and activity logging.

Traffic to and from the service is encrypted (TLS). Access to data is granted by permission and on a need-to-know basis, and administrative actions are logged.

No system is completely immune, and anyone claiming otherwise is being imprecise. In a severe security incident as defined in the Regulations we will act as the law requires, including notifying the Privacy Protection Authority and informing data subjects where required.

Your rights

To exercise any of these, write to OpticCount@inovyTech.com saying what you are asking for. We will reply in writing within the period the law sets. We may ask you to verify your identity, so that we do not disclose your information to somebody else.

If you are an employee of one of our business customers, your operational data sits in the system under your employer's contract. In that case we will also direct you to them, since they decide what is collected, and we will assist either way.

You are also entitled to complain to the Privacy Protection Authority at the Ministry of Justice.

  • To review the information held about you and receive a copy.
  • To ask that inaccurate, incomplete or out-of-date information be corrected.
  • To ask for deletion of information no longer needed for the purpose it was collected for, or collected unlawfully.
  • To withdraw consent you gave, including consent to marketing, at any time and without giving a reason.
  • To object to your data being used for direct marketing.

Marketing messages

Advertising material will be sent to you only after you have given explicit, separate consent, under section 30A of the Communications (Telecommunications and Broadcasting) Law.

That consent is collected through a separate checkbox that is not pre-ticked, and it is never a condition of receiving a service or a quote.

Every marketing message will carry our name and a simple way to remove yourself. Removal requests are honoured immediately.

A reply to an enquiry you initiated, or an operational message about your account, is not advertising material and does not depend on this consent.

Minors

The service is intended for businesses and for people aged 18 and over. We do not knowingly collect information about minors. If such information turns out to have been collected, it will be deleted.

Cookies and browser storage

The full detail, by category and by tool, is in the cookie policy, together with the way to change your choice at any time.

Changes to this policy

We will update this policy as the service or the law changes. The update date appears at the top of the page, and a material change will be highlighted. The binding version is the one published here.