This Privacy Policy explains how 7PM Sushi (“7PM Sushi”, “we”, “us”) collects, uses, shares, and protects your personal information when you use the 7PM Sushi mobile app and related services (the “Service”).
By using the Service you agree to this Policy. If you do not agree, please do not use the Service.
- Data controller: 7PM Sushi, ח.פ. 204184717
- Address: Elmesara 1, Baqa ElGarbia
- Privacy contact: privacy@7pmsushi.com · +972 50-889-1759
1. Information we collect
We collect only what we need to take and deliver your orders.
a. Information you provide
- Account & identity: mobile phone number (used to sign in with a one-time code), and, if you choose to add them, your first and last name and email address.
- Delivery details: delivery addresses you save (street, city) and, when you choose to use your current location, your geographic coordinates.
- Order details: items ordered, order notes, pickup/delivery/dine-in selection, and the name and phone number attached to an order.
- Dietary information: any allergies or dietary notes you choose to add to your profile.
- Payment information: when you pay by card, your card details are entered directly into our payment processor (Stripe) and are not stored on our servers. If you choose to save a card, we store only a non-sensitive reference (a token), the card brand, the last four digits, and the expiry month/year.
b. Information collected automatically
- Device location: with your permission, your device’s location is used to help you set a delivery address. We use location only while you are using the app (“when in use”).
- Push notification token: a device token (via Firebase Cloud Messaging) so we can send you order-status updates.
- Technical data: basic information needed to operate the Service, such as IP address and app/device type, processed by our hosting and infrastructure providers.
We do not sell your personal information, and we do not use it for third-party advertising.
2. How we use your information
We use your information to:
- create and secure your account and sign you in via one-time SMS code;
- take, prepare, and deliver your orders, and calculate totals, delivery fees, and estimated times;
- process payments and prevent fraud;
- issue tax invoices/receipts as required by law and send them to you;
- send you order-status notifications and order-related SMS messages;
- provide customer support and respond to your requests;
- maintain, secure, and improve the Service and comply with our legal obligations.
3. Legal bases for processing
Where applicable law requires a legal basis (e.g. GDPR), we rely on:
- Performance of a contract — to take and fulfil your orders and manage your account;
- Legal obligation — to issue and retain tax invoices and meet accounting and tax requirements;
- Legitimate interests — to secure the Service, prevent fraud, and improve our offering;
- Consent — for device location and push notifications, which you can withdraw at any time in your device settings.
4. Sharing your information
We share information only with service providers who help us run the Service, and only as needed:
| Provider | Purpose | Data shared |
|---|---|---|
| Stripe | Payment processing & saved cards | Card details (entered directly with Stripe), name/email, payment amount |
| Twilio | SMS one-time codes and order/receipt messages | Mobile phone number, message content |
| Morning (Green Invoice) | Issuing legally required tax invoices/receipts | Name, phone number, order and payment details |
| Firebase Cloud Messaging (Google) | Push notifications | Device push token |
| Hosting & database providers (Railway, Supabase) | Running the Service and storing data | Account and order data |
We may also disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, safety, and property of our customers, the public, or us.
5. International data transfers
Some of our providers may process data outside your country, including outside Israel and the EEA. Where required, such transfers are made under appropriate safeguards (for example, standard contractual clauses).
6. Data retention
We keep your personal information for as long as your account is active or as needed to provide the Service.
Tax and accounting records. When you place a paid order we are legally required to issue and retain a tax invoice/receipt. These records — which may include your name, phone number, and order details — are kept for the period required by applicable tax law even after you delete your account. This retention is limited to what the law requires.
When information is no longer needed, we delete or anonymize it.
7. Deleting your account and your rights
You can permanently delete your account at any time from within the app: Profile → Delete account.
When you delete your account, we:
- delete your account profile (name, email, phone, saved addresses, allergies);
- remove your saved payment methods from our payment processor;
- remove the personal link between you and your past orders.
As explained in Section 6, we retain the legally required tax-invoice records associated with past paid orders.
Depending on where you live, you may also have the right to access, correct, delete, restrict, or object to the processing of your personal information, to withdraw consent, and to data portability. To exercise these rights, contact us at privacy@7pmsushi.com. You also have the right to lodge a complaint with your data protection authority (in Israel, the Privacy Protection Authority).
8. Security
We use technical and organizational measures to protect your information, including encryption in transit (HTTPS), restricted access, secure authentication, and processing card data through a PCI-DSS-compliant provider (Stripe). No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
9. Children’s privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
10. Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, where appropriate, notify you in the app. Your continued use of the Service after changes take effect constitutes acceptance.
11. Contact us
7PM Sushi Elmesara 1, Baqa ElGarbia Email: privacy@7pmsushi.com Phone: +972 50-889-1759