Privacy Policy: EMA CRM
Last updated: September 24, 2026
EMA CRM is a system for managing donors, contacts and calls that runs on the web (in the browser). Every organization that uses it gets its own separate system with its own server. The organization decides what to enter and who on its team can see it. Yisrael Fried built the system and runs it for the organization.
Who is responsible for the data
The organization using the system owns the data it enters and is responsible for it toward the people listed in it. We run the system for the organization and use the data only to make the system work.
What is stored
About staff who use the system: name, username, email address, role and permissions, and when they last signed in. Passwords are stored only in encrypted form (a hash), and nobody can read them.
About the people the organization manages (donors, leads, contacts), as entered by the organization:
- Name, phone numbers, email addresses, address and neighborhood, and a spouse's name and phone.
- Names for prayer or a dedication, if given to the organization.
- Notes and an update log (for example what was said on a call), with the date and the staff member who wrote it.
- Standing orders and donations: amount, program, how many charges went through and how many are left, and the charge status (for example that a card failed). The system does not store card numbers or bank account details, and it does not charge money. Charging is done by the organization's payment company.
- Appointments and payments for them, campaign and call-list participation, tasks, and emails sent from the system.
Referral phone book: name, field, area, phone, email and notes about professionals and organizations the organization refers people to.
Where it is stored
- Each organization's database is a separate project at Supabase, on servers in Frankfurt, Germany.
- The website runs at Vercel, also in Frankfurt.
- All traffic between the browser and the server is encrypted (HTTPS).
- The hosting providers keep technical access logs (such as IP address and time) for security and reliability.
Who can see it
- Only the organization's staff who were given an account. Each person sees only what their permissions allow, and the server checks permissions on every action.
- The organization's administrator can block an account, and the block takes effect at once.
- We access the data only to fix a problem or when the organization asks for help.
- The data is not sold, not passed on for advertising and not used for anything else.
If the organization turns on sending email from the system, messages go through an email service (Resend), which receives the recipient's address and the message only to deliver it. Until sending is turned on, emails are logged and not sent. Marketing email needs the recipient's consent, and getting it is the organization's responsibility.
Calendar for iPhone and Mac
A staff member can subscribe to the appointment calendar from Apple Calendar with a personal secret link. Anyone who has the link can see the appointments, so it should not be shared. A new link can be made at any time, and the old one stops working.
Cookies and browser storage
- Sign-in cookies, so the system remembers you are signed in. The system cannot be used without them.
- Two display preferences kept in the browser (the calendar view and the tasks view).
- No advertising cookies, no analytics and no tracking.
How long data is kept, and how to delete it
- Data is kept for as long as the organization uses the system.
- Deleting a person in the system also deletes their history, donations and appointments.
- Anyone who wants to see, correct or delete data about themselves contacts the organization, which handles it in the system.
- When an organization stops using the system, its data is deleted at its request.
Changes
If this policy changes, the date above will be updated.
Contact
Privacy questions: onxx0585@gmail.com
מדיניות פרטיות: EMA CRM
עודכן לאחרונה: 24 בספטמבר 2026
EMA CRM היא מערכת לניהול תורמים, אנשי קשר ושיחות, שעובדת באתר (בדפדפן). כל ארגון שמשתמש בה מקבל מערכת נפרדת עם שרת משלו. הארגון מחליט איזה מידע להכניס ומי בצוות רואה אותו. ישראל פריד בנה את המערכת ומפעיל אותה עבור הארגון.
מי אחראי על המידע
הארגון שמשתמש במערכת הוא הבעלים של המידע שהוא מכניס אליה, והוא האחראי עליו כלפי האנשים שמופיעים בה. אנחנו מפעילים את המערכת בשביל הארגון, ומשתמשים במידע רק כדי שהמערכת תעבוד.
איזה מידע נשמר
על אנשי הצוות שמשתמשים במערכת: שם, שם משתמש, כתובת מייל, תפקיד והרשאות, ומתי נכנסו לאחרונה. הסיסמה נשמרת רק בצורה מוצפנת (hash), ואף אחד לא יכול לקרוא אותה.
על האנשים שהארגון מנהל במערכת (תורמים, לידים, אנשי קשר), לפי מה שהארגון מכניס:
- שם, טלפונים, כתובות מייל, כתובת ושכונה, ושם וטלפון של בן או בת הזוג.
- שמות לתפילה או הקדשה, אם נמסרו לארגון.
- הערות ויומן עדכונים (למשל מה נאמר בשיחה), עם תאריך ושם העובד שכתב.
- הוראות קבע ותרומות: סכום, מסלול, כמה חיובים בוצעו וכמה נשארו, ומצב החיוב (למשל שכרטיס נכשל). המערכת לא שומרת מספרי כרטיסי אשראי ולא פרטי חשבון בנק, והיא לא מחייבת כסף. החיוב עצמו נעשה אצל חברת הסליקה של הארגון.
- פגישות ותשלומים עליהן, השתתפות בקמפיינים ורשימות שיחה, משימות, ומיילים שנשלחו מהמערכת.
ספר טלפונים להפניות: שם, תחום, אזור, טלפון, מייל והערות על אנשי מקצוע וארגונים שהארגון מפנה אליהם.
איפה המידע נשמר
- מסד הנתונים של כל ארגון נמצא בפרויקט נפרד אצל Supabase, בשרתים בפרנקפורט, גרמניה.
- האתר עצמו רץ אצל Vercel, גם כן בפרנקפורט.
- כל התקשורת בין הדפדפן לשרת מוצפנת (HTTPS).
- ספקי האחסון שומרים יומני גישה טכניים (למשל כתובת IP ושעה) לצורכי אבטחה ותקינות.
מי רואה את המידע
- רק אנשי הצוות של הארגון שקיבלו משתמש. כל עובד רואה רק את מה שההרשאות שלו מאפשרות, והשרת בודק את ההרשאות בכל פעולה.
- מנהל המערכת בארגון יכול לחסום משתמש, והחסימה חלה מיד.
- אנחנו ניגשים למידע רק כשצריך לתקן תקלה או כשהארגון מבקש עזרה.
- המידע לא נמכר, לא מועבר לפרסום ולא משמש לשום מטרה אחרת.
מיילים
אם הארגון מפעיל שליחת מיילים מהמערכת, המיילים עוברים דרך שירות שליחה (Resend), שמקבל את כתובת הנמען ואת תוכן המייל רק כדי לשלוח אותו. כל עוד השליחה לא הופעלה, מיילים נרשמים ביומן ולא יוצאים. שליחת דבר פרסומת מחייבת הסכמה של הנמען, והארגון אחראי לקבל אותה.
יומן לאייפון ולמק
עובד יכול להירשם ליומן הפגישות מתוך יומן של אפל. ההרשמה נעשית בקישור אישי וסודי. מי שמחזיק בקישור רואה את הפגישות, ולכן כדאי לא לשתף אותו. אפשר ליצור קישור חדש בכל רגע, והקישור הישן מפסיק לעבוד.
עוגיות ואחסון בדפדפן
- עוגיות התחברות, כדי שהמערכת תזכור שנכנסתם. בלעדיהן אי אפשר להשתמש בה.
- שתי העדפות תצוגה שנשמרות בדפדפן (תצוגת היומן ותצוגת המשימות).
- אין עוגיות פרסום, אין כלי סטטיסטיקה ואין מעקב.
כמה זמן המידע נשמר, ואיך מוחקים
- המידע נשמר כל עוד הארגון משתמש במערכת.
- מחיקה של אדם במערכת מוחקת גם את ההיסטוריה, התרומות והפגישות שלו.
- מי שרוצה לראות, לתקן או למחוק מידע עליו פונה לארגון, והארגון מטפל בזה במערכת.
- כשארגון מפסיק להשתמש במערכת, המידע שלו נמחק לפי בקשתו.
שינויים
אם המדיניות תשתנה, התאריך למעלה יתעדכן.
יצירת קשר
שאלות על הפרטיות: onxx0585@gmail.com