Legal

Privacy Policy

Last updated: March 23, 2026

Questions? privacy@oshri.dev

O.Dev (“we”, “us”), incorporated in Israel, operates the Marv.inbox platform (“Service”). This Privacy Policy explains what personal data we collect, why, how we use and share it, how long we retain it, and what rights you have. It complies with the Israeli Protection of Privacy Law, 5741-1981 (PPL) and its Amendment No. 13 (effective August 14, 2025).

1. Data Controller

O.Dev is the data controller for personal data processed in connection with operating the Service and managing customer accounts.

For personal data that our clients submit about their own customers (“End Users”), our clients are the data controllers and we act as a data processor under their instructions.

Data Protection Contact: privacy@oshri.dev
O.DevHaBarzel 38, Tel Aviv, Israel

2. What Personal Data We Collect

2.1 Data You Provide Directly

CategoryExamples
AccountFull name, email address, phone number, company name, job title
AuthenticationPassword (hashed — never stored in plain text), session tokens
BillingCard details (processed by Stripe — we never store raw card numbers), billing address, VAT number
CommunicationsSupport messages, survey responses

2.2 Data Collected Automatically

CategoryExamplesRetention
Usage dataFeatures accessed, pages visited, session duration90 days
Technical dataIP address, browser type, OS, device type30 days
Server logsAccess logs, error logs30 days
CookiesSession cookies, preference cookiesSee Section 9

2.3 End User Data (Processor Role)

When clients use the Service to manage their customer communications, End User data passes through our platform. We process it solely under the client's instructions and never use it for our own purposes.

CategoryExamples
IdentifiersPhone numbers, WhatsApp/Messenger/Telegram IDs, email addresses
ProfileNames, profile photos (from messaging platforms)
Conversation contentMessages, attachments (images, documents, voice notes) across all connected channels
Contact metadataLabels, notes, conversation history, assigned agent or team

3. Legal Basis for Processing

BasisWhen We Rely On It
ConsentNewsletter subscriptions, optional analytics cookies, marketing communications
Contract performanceProviding the Service, processing payments, managing your account
Legal obligationTax records, regulatory compliance, court orders
Legitimate interestsService security, fraud prevention, platform improvement using aggregated data

4. How We Use Personal Data

  • Service delivery — create and manage your account, process payments, provide all platform features.
  • Communication — service notifications, invoices, product updates.
  • Security — detect and prevent fraud, unauthorised access, and abuse.
  • Platform improvement — analyse aggregated, anonymised usage patterns.
  • Legal compliance — meet obligations under Israeli law and applicable regulations.
We do not sell your personal data. We do not use it for targeted advertising.

5. Data Retention

Data TypeRetention PeriodReason
Account dataSubscription duration + 12 monthsAccount management, disputes
Billing records7 yearsIsraeli tax law (Income Tax Ordinance)
End User data (processor)Subscription duration + 30 daysService delivery; export grace period
Server / access logs30 daysSecurity monitoring
Backup snapshotsUp to 90 daysDisaster recovery
Support records3 years from resolutionQuality assurance

6. Third-Party Data Processors

We share data only as necessary to operate the Service. All processors are bound by data processing agreements.

Infrastructure

ProcessorRoleLocation
SupabaseDatabase hostingUS / EU
Google Cloud RunBackend application hostingUS (Iowa)
Fly.ioWorker process hostingSingapore
VercelFrontend hosting and CDNGlobal edge
Redis Labs (Redis Cloud)Real-time events and job queuesUS
CloudflareDNS, DDoS protection, TLS, CDNGlobal

Payments

ProcessorRoleLocation
StripePayment processing and invoicingUS / EU

Messaging Platforms

ProcessorRoleLocation
Meta PlatformsWhatsApp Business API, Messenger API, Instagram APIUS
TelegramTelegram Bot APIVarious
MicrosoftMicrosoft Teams APIUS / EU

7. International Data Transfers

Some processors listed above are located outside Israel. We ensure adequate protection through Standard Contractual Clauses (SCCs), Data Processing Agreements, and by transferring only to countries with an adequate level of protection. Israel has been recognised as providing adequate data protection under EU GDPR. Transfers are documented in accordance with Amendment 13.

8. Data Security

MeasureDetails
Encryption in transitTLS 1.2+ for all data transmission
Encryption at restAES-256 for sensitive configuration data and credentials
Access controlRole-based access control (RBAC); least-privilege principle
Network securityPrivate VPC networks; databases not exposed to public internet
Audit loggingAccess and activity logs for security-relevant operations

In the event of a personal data breach, we will notify the Israeli Privacy Protection Authority (PPA) within 72 hours and affected individuals without undue delay, as required by Amendment 13.

9. Cookies

TypePurposeCan Be Disabled?
EssentialAuthentication, CSRF protection — required for the Service to functionNo
FunctionalUser preferences (language, theme)Yes
AnalyticsAggregated, anonymised usage statisticsYes

Manage cookies through your browser settings or your account preferences. We do not use cookies for cross-site behavioural advertising.

10. Your Rights Under Israeli Law

Under the PPL and Amendment No. 13, you have the following rights:

RightDescription
AccessRequest a copy of your personal data in Hebrew, Arabic, or English.
CorrectionRequest correction of inaccurate or incomplete data.
DeletionRequest erasure where there is no legal basis for continued retention.
RestrictionRequest that we limit processing in certain circumstances.
ObjectObject to processing based on legitimate interests.
Data portabilityReceive your data in a structured, machine-readable format.
Withdraw consentWithdraw consent at any time without affecting prior processing.
To exercise your rights, email privacy@oshri.dev with subject “Privacy Rights Request.” We respond within 30 days.

To lodge a complaint: Israeli Privacy Protection Authority (PPA)

11. Children

The Service is for business use only. We do not knowingly collect personal data from individuals under 18. Contact us at privacy@oshri.dev if you believe we have inadvertently collected such data.

12. Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated by email or in-platform notice at least 14 days before taking effect. Continued use of the Service after the effective date constitutes acceptance.

O.DevHaBarzel 38, Tel Aviv, Israel — privacy@oshri.dev

Terms of Service