Privacy Policy
Last updated:
This policy explains what personal information Sunday OS processes, why, who it is shared with, and what you can ask us to do about it. It covers the Sunday OS platform and the public pages we operate on our customers' behalf — lead forms, meeting-booking pages and document-signing pages.
1. Who we are
Sunday OS is a sales and customer-management platform. It is operated by "המרכז לעסקאות נדל״ן בע״מ" (The Center for Real Estate Transactions Ltd.), trading as "ווינרס נדל״ן בע״מ" (Winners Real Estate Ltd.), company number 516910775, of 3 Totzeret HaAretz Street, Petah Tikva, Israel.
For any question about this policy, or about personal information we hold, write to us at privacy@sunday-os.com.
2. Our role
Businesses use Sunday OS to manage their own customers and prospects. That gives us two different roles, and which one applies determines who you should approach about your information.
- For the staff accounts of a business that uses Sunday OS — the people who sign in to the system — we are the controller of that account data.
- For the leads, prospects and customers a business manages inside Sunday OS, we act as a processor on that business's behalf. The business decides why the information was collected and how it is used. If a business using Sunday OS contacted you and you want your details removed, that business is your first point of contact — though you can also write to us and we will pass the request on.
One qualification, stated plainly rather than buried: several parts of the service run automatically as standard product behaviour rather than being enabled business by business. In particular, calls are recorded, transcribed and analysed by AI automatically, and advertising-measurement events are sent to Meta automatically. Sections 5, 6, 11 and 12 describe these.
3. Information we process
Depending on how you interact with a business that uses Sunday OS, we may process:
- Account and user data — for people with a Sunday OS login: name, email address, phone number, profile photo, role and permissions, sign-in and presence timestamps, and an internal telephone extension identifier.
- Lead and prospect data — name, phone number, email address, city, free-text notes, the source and advertising campaign a record arrived from, and its status and classification. Where a business's forms ask for it, this also includes self-declared financial and personal information such as monthly income, monthly savings, available capital, budget, employment status and family status — together with any other answer a person chooses to enter into a form.
- Call recordings and transcripts — audio of calls made and received through the platform, the full text transcript of those calls, per-word timings with speaker separation, both parties' phone numbers, and call timing and duration.
- WhatsApp message content — the full text of messages sent and received, both phone numbers, direction and timestamps, and references to media exchanged. When a business connects an existing WhatsApp account, earlier conversation history from that account may be imported, including conversations with people who are not otherwise records in the system.
- Lead-form data — every answer submitted through a lead form, including answers to custom questions a business added to its own form. A verbatim copy of each submission is retained separately.
- Signed documents — where a business uses the document-signing feature, whichever fields that document requires. Depending on the template that can include a national identity number and a home address, together with the signature image and the IP address and browser user-agent of the person signing. This is the only place in the platform where an IP address is recorded.
- Automated assessments — scores, summaries, extracted needs and objections, and suggested classifications that our systems generate about a person from their form answers and call content. We also generate performance and coaching scores about the staff members who handle those calls, derived from recordings of their calls.
- Job-applicant data — where a business uses the recruitment features, applicant details and interview assessments. Applicants reach us through a separate Facebook lead-form flow.
- Uploaded files — documents and images attached to a record, including the original file name.
4. Where the information comes from
- Directly from you — when you fill in a lead form, book a meeting, sign a document, or send a WhatsApp message to a business using the platform.
- From Meta — when you submit a lead form on Facebook or Instagram. Section 12 covers this in detail.
- From telephony — when you call, or are called by, a business using the platform. A call from a number we do not already hold does not by itself create a record.
- Entered manually by a business's staff.
- Imported in bulk by a business from its own lists and spreadsheets. In that case your details reach us from the business rather than from you, and we had no relationship with you before that import.
- Through automation and integration tools that a business connects to the platform, which may forward form submissions and call records to us.
5. Why we process it
- To provide the platform — storing and organising records, telephony, messaging, calendars and documents.
- To transcribe and analyse calls automatically, producing summaries, sentiment, topics, follow-up items and quality scores.
- To score and prioritise leads automatically, and to suggest classifications, from form answers and call content.
- To evaluate and coach staff performance from recordings of their calls.
- To measure advertising results, by sending conversion events to Meta (section 12).
- To place outbound calls automatically through the platform's dialler.
- To operate, secure and debug the service, including diagnosing errors (section 13).
7. Transfers outside Israel
Personal data is processed by service providers located outside Israel, including in the European Union and the United States.
8. How long we keep it
We retain personal information for as long as the business's account with us is active, and after that until we are asked to remove it and are able to do so.
We do not state a fixed retention period, because we do not operate automated deletion schedules and have not measured a period we could stand behind. Call recordings, transcripts, messages and records accumulate for the life of the account. Backups, and data held by the service providers in section 6, are retained under those providers' own arrangements rather than ours.
9. Your rights, and how to request deletion of your data
You can ask us to access, correct or delete the personal information we hold about you, or to stop using it. This section is also the data-deletion instructions for our Facebook application.
Where your details sit inside the account of a business that uses Sunday OS, that business decides what happens to its own records, so please approach it directly as well. You can always write to us and we will pass the request on.
How to request deletion
- Email privacy@sunday-os.com with the subject line "Data deletion request".
- Include the phone number, and if you have one the email address, that you used. These are how records are identified in the system — without at least one of them we cannot locate you.
- Tell us which business you were in contact with, and roughly when. If you submitted a form on Facebook or Instagram, naming the page or the advertisement helps us find the submission.
- Please do not attach identity documents, payment details or other sensitive information. We do not need them, and sending them only creates another copy of your data.
What happens next
We will respond within 30 days of receiving your request and tell you exactly what we were able to remove and what we were not. Requests are reviewed and carried out by a person — there is no automated deletion process and removal is not instantaneous. If we need more detail to identify your records we will ask, and the 30 days runs from the point at which we have enough information to act.
What we retain even after a deletion request, and why
We would rather set these exceptions out plainly than imply an erasure we cannot perform. The following is not removed:
- Usage and billing records — records of the automated processing carried out on your data, such as transcription and AI analysis, are retained as usage and billing records. They have to survive independently of the record they relate to.
- Telephony records — call detail records and the technical event logs of calls are retained as infrastructure records. They are not attached to the customer record and cannot be removed together with it.
- Training and quality records — where a call was used for staff coaching, shadowing or training material, that material is retained.
- Records that carry history — a record with associated calls, meetings, messages or transactions is retained rather than removed. When we last measured this it applied to roughly a third of lead records.
- Copies held by service providers — we cannot delete on your behalf the copies held by the providers listed in section 6, including recordings held by a previous telephony provider.
We do not have a facility that strips the personal details out of a record while keeping the operational data attached to it. Where a record cannot be deleted, we will say so explicitly and tell you which of the reasons above applies.
Removing the application from Facebook
Removing Sunday OS from your Facebook account stops new lead submissions from reaching us. It does not delete submissions we have already received — for those, follow the steps above.
10. Security
What we do
- Sign-in is handled by a managed authentication provider, using a password or a one-time email link. We do not store platform passwords ourselves.
- Access inside a business's account is role-based. Sales users see only the records assigned to them; managers, administrators and account owners see all records in that account. Only administrators and owners can connect or disconnect the Meta integration.
- Each business's data is separated by account on every query, with database row-level access rules as an additional layer.
- Stored files and call recordings are reached through time-limited signed links rather than permanent public addresses. Two exceptions: profile photos and business branding images are served from permanent public addresses, and some historical call recordings sit with a previous provider whose access controls we do not operate.
- Inbound webhook requests from Meta are cryptographically verified before they are processed.
- The public lead-submission endpoint is rate-limited.
What we do not claim
We do not claim that every credential and access token we hold is encrypted at rest — some integration access tokens are stored in our database as ordinary text. We hold no security certifications, and we do not claim compliance with any particular security standard or framework.
11. WhatsApp
Where a business uses WhatsApp through Sunday OS:
- Message content travels through WhatsApp's own infrastructure, which is operated by Meta, and through a messaging connector operated on the business's behalf. Messages are sent from the business's own WhatsApp account.
- The full text of every message sent and received is stored in our database and is visible to the staff of that business.
- WhatsApp's platform rules include a 24-hour window: once 24 hours have passed since a person's last message, a business may generally send only pre-approved template messages rather than free-form ones.
- Automated messages are suppressed during a configured weekly quiet period. Messages a staff member sends by hand are not subject to that suppression.
- Outbound documents and files are sent as a link inside a text message. Files you send over WhatsApp are received and recorded.
- Consent and opting out: we do not currently record consent, or process opt-out instructions, as an automated function of the platform. To stop receiving WhatsApp messages, contact the business that is messaging you, or write to privacy@sunday-os.com, and we will act on the request manually.
12. Facebook (Meta) lead-form data
This section describes what happens when you submit a lead form on Facebook or Instagram belonging to a business that uses Sunday OS.
Which fields we receive
- The answers you gave on the form. Standard fields — full name, phone number, email address, city — are stored in the corresponding fields on your record. Answers to any custom question the business added to its form are retained verbatim, as free text, on that same record.
- The identifiers Meta supplies with the submission: Meta's own lead identifier, plus the form, ad, ad-set and campaign identifiers and names.
- A verbatim copy of the full submission, retained as a separate record for each submission — including repeat submissions.
In practice most lead submissions reach us through an automation provider that a business connects between Meta and Sunday OS, rather than arriving directly from Meta to us.
Where it is stored
On our servers, in a managed database hosted in the European Union, together with the verbatim submission copies described above. Repeat submissions from the same phone number are matched to a single record, so a person's separate submissions are linked together into one profile.
Who can see it
- Staff of the business whose form you submitted, subject to that business's own role settings — sales users see only records assigned to them, while managers, administrators and owners see all of that business's records.
- Our own personnel, for support and operation of the platform.
- The AI providers described in section 6, where your record becomes associated with a call that is transcribed and analysed.
What we send back to Meta
When a meeting is scheduled or attended, we send Meta a conversion event so the business can measure its advertising. That event contains the lead identifier Meta itself generated for your submission; your email address and phone number, each irreversibly hashed (SHA-256) before it leaves our servers; the event name and timestamp; and, where a sale is recorded, its value. Your email address and phone number are not sent to Meta in readable form.
We do not run a Meta Pixel or any other advertising tracker inside the Sunday OS application, and we do not send Meta your IP address, browser information or advertising cookies from it.
Permissions we request
When a business connects its Facebook account we request: pages_show_list, pages_read_engagement, leads_retrieval, business_management, pages_manage_ads, ads_management, ads_read and pages_manage_metadata. This is broader than lead retrieval alone — it includes permissions to read and manage advertising.
Deletion
We do not currently operate an automated data-deletion callback for Facebook, so deletion is handled as a request to us. Removing the Sunday OS app from your Facebook account stops new leads from reaching us, but does not by itself delete leads we have already received. Section 9 is our data-deletion instructions page: it sets out exactly what to send us, when we will respond, and which records are retained regardless and why.
14. Changes to this policy
We will update this page when our practices change, and we will change the "last updated" date at the top when we do. Where a change materially affects how we handle personal information, we will say so on this page.
15. Contact
privacy@sunday-os.com — "המרכז לעסקאות נדל״ן בע״מ" (trading as "ווינרס נדל״ן בע״מ"), company number 516910775, 3 Totzeret HaAretz Street, Petah Tikva, Israel.