Privacy Policy

Last updated: August 13, 2026

1. Who we are

The database owner and data controller is Ligal Frish, licensed dealer no. 021996400, trading as Plan B Business, of 8 HaSharon St., Kfar Yona, Israel. Services are delivered in practice by Ligal Frish and Eitan Eshtemaker. The person responsible for privacy enquiries is Eitan Eshtemaker: eytanah@gmail.com, phone 050-777-4424. General enquiries: contact@planb-business.com.

2. What we collect

When you fill in a form on the site (diagnostic meeting, contact, resource download) we collect your full name, email address, phone number, business name and field, and whatever you wrote in the enquiry itself. When you open an account or a Profitable Business subscription we also collect your email address and login details - the password is stored hashed, so we never see it - and usage data inside Profitable Business (progress through modules, ratings, questions and content you created). Card details are held by the payment provider only, never by us. In addition, the site runs measurement and analytics tools (Google Analytics 4, Microsoft Clarity, and subject to your consent also the Meta Pixel) which collect cookie identifiers, IP address, device and browser type, pages visited and how the site is used. Under Amendment 13 to the Israeli Privacy Protection Law these count as "information" even without your name attached, so we treat them as personal data in every respect.

3. Is providing information mandatory?

No. Filling in the site's forms is entirely voluntary and there is no legal obligation to do it. Without contact details, though, we can't get back to you or deliver the service you asked for; and for a Profitable Business subscription, an email address and login details are needed to open the account and perform the contract. The service is for people aged 18 and over. We don't knowingly collect personal data from minors, and if we learn that we have, we delete it.

4. Why we use it

Performance of a contract: delivering the service you asked for, scheduling meetings and advisory sessions, running the Profitable Business subscription and processing payments. Legitimate interest: replying to enquiries, improving the service and the site, fraud prevention and system security. Consent: marketing content, newsletters and updates, and non-essential analytics cookies - consent can be withdrawn at any time. Legal obligation: retaining accounting records and invoices as Israeli law requires, generally for 7 years. We don't use your information for purposes unconnected to the service you asked for, and we don't send unsolicited marketing without your explicit consent.

5. Who we share it with

We never sell personal data. We share it only with the service providers needed to run the business: Grow (Meshulam Ltd.), our Israeli PCI-DSS payment provider, which processes payments, refunds and invoices; CHING, an Israeli provider that manages recurring subscription billing (set-up, renewal and cancellation); Make (Integromat), which routes form enquiries into our CRM; Supabase, the database holding user accounts, form enquiries and Profitable Business content; Cloudflare, which serves the site, protects it from attacks and routes the domain's email, and processes every visitor's IP address and access logs; Google Analytics 4 and Google Tag Manager, for usage measurement and tag management; Microsoft Clarity, for behaviour analysis and interaction recording; the Meta (Facebook) Pixel, for measuring our advertising performance on Meta's networks; email providers including Resend, for confirmations, newsletter and support; and competent authorities, where the law requires it (for example the Tax Authority). Access to your information is limited to the Plan B Business team.

6. Where your data is processed

The business is based in Israel, but the servers of Supabase, Cloudflare, Google, Microsoft and Meta are located outside Israel - mainly in the European Union and the United States - so information reaching those providers is stored and processed abroad. Transfers are made under the Israeli Privacy Protection Regulations (Transfer of Data to Databases Abroad), 5761-2001, and only to providers bound by data-processing agreements and by security and privacy standards no lower than those required in Israel.

7. How long we keep it

Information about enquirers who did not become active clients is deleted after two years at most. Account and Profitable Business subscription data is kept while the subscription is active and for up to 24 months after it closes, except accounting records, which the law requires us to keep for 7 years. Session recordings are deleted after 12 months at most.

8. Your rights

Under the Israeli Privacy Protection Law, and under the GDPR where it applies, you have the right to access the information held about you (section 13 of the Law), to correct information that is inaccurate, incomplete, unclear or out of date (section 14), to request deletion of your information subject to the retention duties the law imposes on us, to object to direct marketing and require removal from the mailing database (sections 17F and 17H) - every marketing message we send carries a one-click unsubscribe link - and to portability, meaning a copy of what you gave us in a readable format. Send any request to Eitan Eshtemaker at eytanah@gmail.com or by phone on 050-777-4424. We answer every request within 14 business days. Privacy officer: the business is not among the bodies required to appoint a privacy protection officer under the Privacy Protection Law, so none has been appointed; responsibility for privacy enquiries rests with Eitan Eshtemaker at the details above. If you believe your rights under the Law have been infringed, you may approach the Privacy Protection Authority at the Ministry of Justice.

9. Security and security incidents

We apply security measures in line with the Israeli Privacy Protection (Data Security) Regulations, 5777-2017: encryption of traffic to and from the site (HTTPS), one-way hashing of passwords so that we cannot read them, permission enforcement at the database level so each user reaches only their own records, restriction of administrative operations to administrators, and no storage of card details in our systems. If a serious security incident affecting your information occurs, we will act as the law requires - handle and document the incident, report it to the Privacy Protection Authority to the extent the law requires, and notify you as soon as possible where there is a concern of harm to you. Automated decisions: we do not make decisions with legal or financial effect on you by automated means alone. Tools on the site that produce a score or recommendation (for example the business diagnostic questionnaire) provide information only, and any decision about a service or its terms is made by a person.

10. Session recording, cookies and consent

To improve the site we use Microsoft Clarity and our own session-recording tool. They record interactions only: clicks, mouse movement, scrolling, and page navigation. What you type into forms is not captured, sensitive fields (password, email, phone) are masked, and recordings never include payment details. Recordings are used solely for product improvement, kept for up to 12 months, and then deleted. Recording runs only when analytics cookies are allowed. For EEA/UK visitors, analytics and marketing cookies run only after you opt in via the cookie banner; for visitors elsewhere, including Israel, they may be on by default until you choose, and you can switch them off at any time via the banner ("cookie settings" in the footer). Full details of each cookie are in our cookie policy.

11. Changes to this policy

We update this policy as the law, the service or our practices change. Material changes are published on the site with the update date at the top of the page, and where we hold your email address we notify you directly as well.

Questions? Email contact@planb-business.com or eytanah@gmail.com, phone 050-777-4424, WhatsApp +972-53-777-0193.