שכר משמרות
דף הבית תקנון
עברית English

מדיניות פרטיות

אפליקציית שכר משמרות (Shift Salary) · בתוקף מ-13 בספטמבר 2026
עדכון אחרון: המתג לכיבוי האנליטיקה והמזהה האנונימי שהוצג בהגדרות הוסרו. האנליטיקה האנונימית ודיווח הקריסות פעילים תמיד, ומכיוון שאין בהם דבר שניתן לייחס לאדם או להתקנה שאפשר לנקוב בשמה, אין יותר בקשת מחיקה פרטנית.

מדיניות זו חלה על אפליקציית שכר משמרות, המופעלת על ידי בן באשא ("אנחנו"). יצירת קשר: shiftsalary@benbasha.com.

בקצרה: האפליקציה עובדת לפני הכל לא־מקוונת. כל משמרת, החתמה, מקום עבודה, תעריף וחישוב שכר נשמרים על המכשיר שלכם. אין חשבון, אין סנכרון לענן אלינו, ואין פרסומות, ואנחנו לא מקבלים מזה כלום. מכיוון שמדובר בנתוני אפליקציה רגילים, הם נכללים בגיבוי המכשיר שלכם (iCloud או Google), גיבוי שנמצא בשליטתכם ולא בשליטתנו. כדי לשפר את האפליקציה אנחנו אוספים נתוני שימוש אנונימיים דרך Mixpanel ודיווחי קריסה אנונימיים דרך Firebase Crashlytics: ספירת אירועים כללית ועקבות קריסה המקושרים למזהה אקראי, ולעולם לא השעות, השכר, שמות מקומות העבודה או המיקום שלכם. שניהם פעילים תמיד ואין להם מתג באפליקציה; מחיקת האפליקציה עוצרת את האיסוף לגמרי ומסירה גם את המידע שעל המכשיר. עותקים שנמצאים בגיבויים שלכם נשארים בשליטתכם, ונתוני שימוש או קריסות שכבר נשלחו נשמרים כמתואר בהמשך.

מה נשמר על המכשיר

כל מה שהאפליקציה רושמת נשמר מקומית על המכשיר בלבד (במסד נתונים מקומי) ולעולם לא מועלה לשרת שלנו:

  • מקומות העבודה (שם, צבע, תעריף שעתי, כללי נסיעות ותוספות, ואם הפעלתם תזכורות מיקום — גם נקודת הציון של מקום העבודה)
  • כל החתמת כניסה ויציאה והפסקה, והמשמרות שנגזרות מהן
  • טיפים והתאמות ידניות
  • השכר ברוטו, ועם Pro גם חישוב השכר נטו
  • הגדרות פרופיל השכר (אורך שבוע, בגיר/נוער, נקודות זיכוי, אחוז פנסיה, אופן נסיעות) המשמשות את מנוע הנטו
  • הגדרות האפליקציה, שפת הממשק, והאם Pro פעיל

אין התחברות ואין חשבון: לעולם לא נבקש את השם, הדוא"ל או הטלפון שלכם, ושום נתון מהרשימה הזו לא מועלה לשרת שלנו.

על גיבוי המכשיר. אלה נתוני אפליקציה רגילים, ולכן מערכת ההפעלה כוללת אותם בגיבוי שאתם ממילא עושים לטלפון (גיבוי iCloud ב-iOS, גיבוי אוטומטי של Google באנדרואיד), ומשחזרת אותם כשאתם מגדירים מכשיר חדש. הגיבוי הזה שייך לכם ולחשבון Apple או Google שלכם, אין לנו אליו גישה ולעולם איננו מקבלים אותו. מחיקת האפליקציה מסירה את הנתונים האלה מהמכשיר. האם עותק שורד בתוך הגיבוי שלכם ולכמה זמן, נקבע בהגדרות הגיבוי של iCloud או Google שלכם ולא על ידינו. אם אתם רוצים שלא יישאר עותק בכלל, כבו את האפליקציה בהגדרות הגיבוי של מערכת ההפעלה לפני שאתם מוחקים אותה.

אנליטיקה אנונימית (Mixpanel)

כדי להבין באילו תכונות משתמשים ולתעדף תיקונים, האפליקציה שולחת אירועי שימוש אנונימיים ל-Mixpanel (ספק אנליטיקת המוצר היחיד — אין שום רכיב של מעקב חוצה-אפליקציות או פרסום; דיווח הקריסות הוא שירות נפרד, המתואר בפרק הבא).

מה כן נשלח:

  • שמות אירועים שמתארים מה קרה — למשל: פתיחת האפליקציה, סיום אונבורדינג, יצירת או ארכוב מקום עבודה, החתמת כניסה/יציאה, התחלת/סיום הפסקה, הוספת/עריכת/מחיקת משמרת, השלמת ייצוא, צפייה במסך הרכישה, התחלת/השלמת/כישלון/שחזור רכישה, פתיחת Pro, שינוי שפה או ערכת נושא, והפעלת/כיבוי תזכורות מיקום.
  • מאפיינים כלליים על חלק מהאירועים — למשל החתמת יציאה שולחת משך בדקות מעוגל; מקום עבודה חדש שולח שני ערכי כן/לא (האם יש נסיעות והאם יש כללי תוספת); עריכה שולחת איזה שדה השתנה (שעות/הפסקות/טיפים); אירוע רכישה שולח בכישלון את קוד השגיאה של החנות.
  • צפיות במסך — שם המסך שנפתח. במסכי פירוט ייתכן שיצורף מספר פריט פנימי (מזהה רשומה פנימי של האפליקציה) — מספר טכני, לא מידע אישי.
  • הקשר בסיסי שנשלח עם כל אירוע — פלטפורמה (iOS/Android), שפת הממשק, והאם Pro פעיל.
  • מזהה אקראי שנוצר על המכשיר שלכם כדי לקבץ אירועים מאותה התקנה. הוא אינו השם, הדוא"ל או חשבון שלכם, הוא אינו מזהה הפרסום של המכשיר, והוא מתאפס בהתקנה מחדש. הוא אינו מוצג בשום מקום באפליקציה ואינו קשור לשום דבר שיאפשר לנו לאתר אתכם.

מה לעולם לא נשלח: שעות, תאריכים או משכי המשמרות האמיתיים שלכם; שום סכום שכר, ברוטו או נטו; טיפים; שמות מקומות עבודה; נקודות ציון או מיקום; ושום שם, דוא"ל או טלפון. איננו מוכרים את הנתונים ואיננו משתמשים בהם כדי לזהות אתכם אישית.

Mixpanel מעבדת נתונים אלה כמעבדת מטעמנו; המדיניות שלה: mixpanel.com/legal/privacy-policy.

פעיל תמיד, ואיך עוצרים

האנליטיקה האנונימית ודיווח הקריסות פעילים תמיד, ואין להם מתג באפליקציה. מה שנאסף הוא הרשימה שלמעלה ותו לא: לא שעות, לא שכר, לא שמות מקומות עבודה, לא מיקום, ושום דבר שמזהה אתכם.

כדי לעצור את האיסוף, מחקו את האפליקציה. זה מפסיק אותו לגמרי, ומסיר איתו גם את הנתונים שעל המכשיר (ראו את ההערה על הגיבוי למעלה).

כמה זמן נשמר

  • אירועי השימוש נשמרים אצל Mixpanel לפי מדיניות השמירה שלה עבור הפרויקט שלנו, ודיווחי הקריסה אצל Google לפי המדיניות של Firebase, כל עוד הם מועילים לאבחון האפליקציה. בשני המקומות אין שום דבר שמזהה אתכם.
  • מכיוון שהמזהה האקראי נוצר על המכשיר שלכם, אינו מוצג לכם ואינו מקושר לשום דבר שקשור אליכם, איננו יכולים לדעת אילו רשומות הגיעו מההתקנה שלכם — ולכן אין בקשת מחיקה פרטנית שנוכל לקיים ביושר. זו החלפה מכוונת: הנתונים נשארים בלתי ניתנים לזיהוי במקום להיות ניתנים לאיתור.
  • הנתונים שעל המכשיר (משמרות, מקומות עבודה, שכר) לא דורשים מאיתנו כלום: הם שלכם, אנחנו לעולם לא מקבלים אותם, ומחיקת האפליקציה מסירה אותם מהמכשיר (ראו את ההערה על הגיבוי למעלה).
  • שאלות כלליות על המדיניות: shiftsalary@benbasha.com.

דיווח קריסות (Firebase Crashlytics)

כדי שקריסה במכשיר שלכם תהפוך לתקלה שאפשר באמת לתקן, האפליקציה שולחת דיווחי קריסה אנונימיים ל-Firebase Crashlytics (של Google). דיווח נשלח רק כשהאפליקציה קורסת או נתקלת בשגיאה שהיה עליה להתאושש ממנה — אין זרם רציף של מידע.

מה כן נשלח:

  • עקבות הקריסה — שרשרת שמות הפונקציות בתוך הקוד שלנו שהובילה אליה, יחד עם הודעת השגיאה.
  • הקשר של המכשיר ומערכת ההפעלה — דגם המכשיר, גרסת מערכת ההפעלה, גרסת האפליקציה, זיכרון ואחסון פנויים ברגע הקריסה, והאם האפליקציה היתה פתוחה בחזית.
  • מזהה התקנה אקראי ש-Firebase יוצרת על המכשיר, כדי לקבץ קריסות חוזרות מאותה התקנה. הוא אינו השם, הדוא"ל או חשבון שלכם, הוא אינו מזהה הפרסום של המכשיר, והוא מתאפס בהתקנה מחדש.

דיווח הקריסות עומד באותו מעמד כמו האנליטיקה: פעיל תמיד, בלי מתג באפליקציה, ונפסק כשמוחקים את האפליקציה.

מה לעולם לא נשלח: אותה רשימה בדיוק — שעות, תאריכים או משכי משמרות; שום סכום שכר, ברוטו או נטו; טיפים; שמות מקומות עבודה; נקודות ציון או מיקום; ושום שם, דוא"ל או טלפון. דיווחי הקריסה אינם נושאים שום תוכן ממסד הנתונים שלכם. Google Analytics for Firebase אינו מופעל באפליקציה הזו — Firebase מקבלת אבחון קריסות בלבד, לעולם לא אירועי מוצר.

Google מעבדת נתונים אלה כמעבדת מטעמנו; המדיניות שלה: firebase.google.com/support/privacy.

מיקום ותזכורות (אופציונלי)

המיקום הוא תכונה אופציונלית לכל מקום עבודה שכבויה עד שתפעילו אותה. אם תגדירו מיקום למקום עבודה, האפליקציה יכולה להזכיר לכם להחתים כניסה בהגעה ויציאה בעזיבה.

  • המיקום מחושב כולו על המכשיר. נקודות הציון נשמרות מקומית ונמסרות לשירות ה-geofencing של מערכת ההפעלה כדי שיעיר את האפליקציה כשאתם חוצים את גבול מקום העבודה.
  • המיקום ונקודות הציון שלכם לעולם לא נשלחים מחוץ למכשיר — לא אלינו, לא ל-Mixpanel, לאף אחד. אירועי המיקום אינם נושאים שום נתון מיקום באנליטיקה.
  • באייפון האפליקציה מבקשת הרשאת מיקום "בזמן שימוש", וגם הרשאת מיקום "תמיד" (ברקע), כדי שמערכת ההפעלה תוכל למסור אירועי הגעה ועזיבה כשהאפליקציה סגורה. אפשר לסרב; שעון ההחתמה הידני ממשיך לעבוד במלואו.
  • באנדרואיד הגרסה הזו נשלחת בלי הרשאת המיקום ברקע (ACCESS_BACKGROUND_LOCATION) בכלל, ולכן התזכורת בהגעה ובעזיבה אינה מוצעת שם ולא נשמרות נקודות ציון של מקומות העבודה. האפליקציה אומרת זאת במקום שבו היכולת היתה אמורה להופיע.

התראות

תזכורות המשמרת והתזכורות להחתמה לפי מיקום הן התראות מקומיות שמתוזמנות על המכשיר. אין שרת התראות (push), לא נרשם שום טוקן התראות, ושום נתון התראות לא עוזב את המכשיר.

מנוע השכר נטו

חישוב הנטו של Pro (מס הכנסה עם נקודות זיכוי, ביטוח לאומי ומס בריאות, ופנסיה) מתבצע כולו על המכשיר מטבלאות המובנות באפליקציה (מעודכנות לחוק הישראלי) ומהגדרות השכר שהזנתם. לא נוצר קשר עם שום שירות מס או שכר — אין קריאת רשת חיצונית, ושום נתון שכר לא עוזב את המכשיר.

רכישות ותשלומים

Pro הוא רכישה חד-פעמית הנמכרת דרך ה-App Store של אפל או Google Play. החנות מטפלת בכל התשלום — שום מספר כרטיס, כתובת חיוב או פרט תשלום לא מגיע לאפליקציה. האפליקציה מקבלת רק מטא־נתוני רכישה מהחנות (מזהה מוצר, מצב הרכישה, והאם החנות ביטלה אותה) כדי לפתוח את Pro על המכשיר.

מה האפליקציה לא עושה

  • אין חשבונות, אין התחברות, אין שם / דוא"ל / טלפון
  • אין סנכרון לענן — שום דבר לא מועלה לשרת שלנו
  • אין פרסומות, אין חלון "שקיפות במעקב", אין מזהה פרסום, אין מעקב חוצה אפליקציות
  • איננו מוכרים את הנתונים שלכם
  • הפניות הרשת היחידות שלנו הן האנליטיקה האנונימית של Mixpanel, דיווחי הקריסה האנונימיים של Firebase Crashlytics, מערכת החיוב והרכישות של חנות האפליקציות, וקישורים שאתם בוחרים לפתוח (כמו עמוד זה)

ילדים

שכר משמרות מיועדת לעובדים בוגרים ובני נוער שעוקבים אחר השכר שלהם בישראל, ואינה מכוונת לילדים מתחת לגיל 13.

שינויים

אם המדיניות תשתנה, הגרסה המעודכנת תפורסם בכתובת shiftsalary.benbasha.com/privacy עם תאריך תוקף חדש.

יצירת קשר

שאלות על המדיניות: shiftsalary@benbasha.com

Privacy Policy

שכר משמרות (Shift Salary) · Effective September 13, 2026
Last change: the in-app analytics switch and the Analytics ID shown in Settings were removed. Anonymous analytics and crash reporting are always on, and — because nothing in either store can be traced back to a person or an install you could name — there is no longer a per-install deletion request.

This policy covers the שכר משמרות (Shift Salary) mobile app, operated by Ben Basha ("we"). Contact: shiftsalary@benbasha.com.

The short version: the app is offline-first. Every shift, punch, workplace, rate, and pay calculation stays on your device, in a local database. There is no account, no cloud sync to us, and no ads — we never receive any of it. Because it is ordinary app data, it is included in your own device backup (iCloud or Google), which is your backup under your control, not ours. To improve the app we collect anonymous usage analytics through Mixpanel and anonymous crash reports through Firebase Crashlytics — coarse event counts and crash stack traces tied to a random identifier, never your actual hours, pay, workplace names, or location. Both are always on and there is no switch for them in the app; deleting the app stops all collection, and removes the on-device data too. Copies inside your own OS backups are yours to keep or delete, and analytics or crash data already sent is retained as described below.

What stays on your device

Everything the app records is stored locally on your device only (a local database) and is never uploaded to any server we run:

  • Your workplaces (name, color, hourly rate, travel and premium rules, and — if you enable location reminders — the workplace coordinates)
  • Every punch in / out and break, and the shifts derived from them
  • Tips and manual adjustments
  • Your gross pay and, with Pro, your net-pay calculation
  • Your payroll profile settings (week length, adult/youth, credit points, pension %, travel mode) used by the net-pay engine
  • App settings, interface language, and whether Pro is active

There is no login and no account — we never ask for your name, email, or phone number, and none of this data is ever uploaded to a server we run.

About device backups. This is ordinary app data, so your operating system includes it in the backup you already make of your phone — iCloud Backup on iOS, Google Auto Backup on Android — and restores it when you set up a new device. That backup belongs to you and to your Apple or Google account; we have no access to it and never receive it. Deleting the app removes this data from the device. Whether a copy survives inside your own backup, and for how long, is controlled by your iCloud / Google backup settings, not by us. If you want no copy at all, turn this app off in your OS backup settings before deleting it.

Anonymous analytics (Mixpanel)

To understand which features are used and to prioritize fixes, the app sends anonymous product-usage events to Mixpanel (our only product-analytics provider — there is no advertising or cross-app tracking SDK; crash reporting is a separate service, described in the next section).

What is sent:

  • Event names describing what happened — for example: app opened, onboarding completed, workplace created or archived, punch in / out, break started / ended, a shift added / edited / deleted, an export completed, paywall viewed, a purchase started / completed / failed / restored, Pro unlocked, language or theme changed, and location reminders enabled / disabled.
  • Coarse properties on some events — for example a punch-out sends a rounded duration in minutes; a new workplace sends two booleans (whether it has travel pay and whether it has premium rules); an edit sends which field changed (times / breaks / tips); a purchase event sends, on failure, the store's error reason.
  • Screen views — the name of the screen you open. For detail screens this may include an internal item number (an app-internal record id) — an internal integer, not personal data.
  • Basic context sent with every event — platform (iOS / Android), interface language, and whether Pro is active.
  • A random identifier generated on your device to group events from the same install. It is not your name, email, or an account, it is not the device advertising identifier, and it resets if you reinstall. It is not shown anywhere in the app and is not tied to anything we could use to find you.

What is never sent: your actual shift times, dates, or hours; any wage, gross, or net pay amount; tips; workplace names; GPS coordinates or location; and any name, email, or phone number. We do not sell your data and do not use it to identify you personally.

Mixpanel processes this data as our processor; its policy: mixpanel.com/legal/privacy-policy.

Always on, and how to stop it

Anonymous analytics and crash reporting are always on — there is no switch for them in the app. What they collect is the list above and nothing else: no hours, no pay, no workplace names, no location, nothing that identifies you.

To stop the collection, delete the app. That ends it completely, and takes the on-device data with it (see the backup note above).

Retention

  • Analytics events are retained by Mixpanel under its own retention policy for our project, and crash reports by Google under Firebase's, for as long as they are useful for diagnosing the app. Neither store contains anything that identifies you.
  • Because the random identifier is generated on your device and is not shown to you or linked to anything about you, we cannot tell which records came from your install — so there is no per-install deletion request we could honestly act on. The trade is deliberate: the data stays unidentifiable rather than being made addressable.
  • On-device data (shifts, workplaces, pay) needs no request from us: it is yours, we never receive it, and deleting the app removes it from the device (see the backup note above).
  • General questions about this policy: shiftsalary@benbasha.com.

Crash reporting (Firebase Crashlytics)

So that a crash on your phone becomes a bug we can actually fix, the app sends anonymous crash reports to Firebase Crashlytics (Google). A report is sent only when the app crashes or hits an error it had to recover from — there is no continuous stream.

What is sent:

  • The stack trace of the crash — the chain of function names inside our own code that led to it, plus the error message.
  • Device and OS context — device model, operating-system version, app version, available memory and storage at the moment of the crash, and whether the app was in the foreground.
  • A random installation identifier Firebase generates on your device, so repeated crashes from one install group together. It is not your name, email, or account, it is not the device advertising identifier, and it resets if you reinstall.

Crash reporting is on the same footing as analytics: always on, with no switch in the app, and it stops when you delete the app.

What is never sent: the same list as above — your shift times, dates or hours; any wage, gross, or net pay amount; tips; workplace names; GPS coordinates or location; and any name, email, or phone number. Crash reports carry no content from your database. Google Analytics for Firebase is not enabled in this app — Firebase receives crash diagnostics only, never product events.

Google processes this data as our processor; its policy: firebase.google.com/support/privacy.

Location & geofence reminders (optional)

Location is an optional, per-workplace feature that is off until you turn it on. If you set a workplace's location, the app can remind you to clock in when you arrive and clock out when you leave.

  • Location is evaluated entirely on your device. Your coordinates are stored locally and handed to the operating system's geofencing service so it can wake the app when you cross a workplace boundary.
  • Your location and coordinates are never transmitted off the device — not to us, not to Mixpanel, not to anyone. The geofence events carry no location data in analytics.
  • On iPhone, the app requests "while using" location, and — so the operating system can deliver arrival / departure events while the app is closed — "always" (background) location. You can decline; the manual punch clock keeps working fully.
  • On Android, this release ships without the background-location permission (ACCESS_BACKGROUND_LOCATION) at all, so the arrival / departure reminder is not offered there and no workplace coordinates are stored. The app says so where the feature would otherwise appear.

Notifications

Shift reminders and geofence clock-in / clock-out prompts are local notifications scheduled on your device. There is no push server, no push token is ever registered, and no notification data leaves your device.

The net-pay engine

Pro's net-pay figures (income tax with credit points, Bituach Leumi / National Insurance and health insurance, and pension) are calculated entirely on your device from tables built into the app (updated to Israeli law) and the payroll settings you enter. No tax or payroll service is contacted — there is no external API call, and none of your pay data leaves the device.

Purchases & payments

Pro is a one-time purchase sold through Apple's App Store or Google Play. The store handles the entire payment — no card number, billing address, or payment credential ever reaches the app. The app receives only store-issued purchase metadata (product id, purchase state, whether the store revoked it) to unlock Pro on your device.

What the app does NOT do

  • No accounts, no sign-in, no name / email / phone
  • No cloud sync — nothing is uploaded to a server we run
  • No ads, no App Tracking Transparency prompt, no advertising identifier, no cross-app tracking
  • No selling of your data
  • Our only outbound network traffic is the anonymous Mixpanel analytics, the anonymous Firebase Crashlytics crash reports, the app store's billing / purchase system, and links you choose to open (like this page)

Children

Shift Salary is intended for working adults and youth tracking their own pay in Israel. It is not directed at children under 13.

Changes

If this policy changes, the updated version will be posted at shiftsalary.benbasha.com/privacy with a new effective date.

Contact

Questions about this policy: shiftsalary@benbasha.com

שכר משמרות
דף הבית תקנון שימוש shiftsalary@benbasha.com

© 2026 Ben Basha