Skip to content
Petalעברית

Privacy Policy

Last updated: July 2, 2026

This policy explains what information we collect in the Petal app, how we use it, and — most importantly — what is shared with businesses when you send a service request. We've written it in plain language.

Who we are

Petal is a mobile app (iOS and Android) that connects consumers with beauty-service providers in real time, launching first in Tel Aviv, Israel. You broadcast an urgent service request, nearby businesses get notified and respond, and you choose the one that fits.

Data controller: Petal. For any privacy-related question, contact us at info@petal.cy.

The app is free to use, we do not show ads, and we do not sell personal data to third parties.

What we collect

  • Account details. You sign in with Google or with "Sign in with Apple" (Firebase Authentication). From the sign-in provider we receive your name, email address, and profile photo.
  • Phone number. Optional for general use of the app, but required to send a service request (so a booking can be coordinated with the business).
  • One-time location. When you create a request, we capture your device's location once, at that moment, to find nearby businesses. There is no background location tracking, and we do not track you when the app is closed.
  • Request content. The service type, your preferred timing, the search radius, and a free-text note you write (up to 150 characters).
  • Business profile (for business users). Business name, address, list of services and prices, photos, and contact links (WhatsApp, Instagram, phone). This information is intentionally visible to consumers — it is your public business card in the app.
  • Push tokens. To send notifications to your device, we store a technical device identifier used for notifications (Expo/FCM) on our server.
  • Diagnostics. To keep the service stable and reliable, our server collects error reports and performance data (via Sentry).
  • Terms acceptance record. We keep a record of your acceptance of the Terms of Service.

How we use it

  • To match your request with nearby businesses and to enable the booking and mutual-confirmation process.
  • To send relevant notifications (for example, a new request for a business, or a business's response to a consumer).
  • To operate, secure, and improve the service, and to prevent abuse.
  • To comply with the law and to handle inquiries and reports.

What is shared with businesses

Sharing your request details with nearby businesses is the core of Petal, so we want you to understand exactly what is revealed and when:

  • The moment you send a request, businesses within the search radius you chose receive: the service type, the timing, the free-text note you wrote, and your approximate distance from them. At this stage they do not receive your name, phone number, profile photo, or exact location.
  • Your name is revealed to the business you choose only after you select it and confirm the booking — so the business knows who they are hosting.
  • You initiate contact. You reach out to the business through the links on its public profile (for example, WhatsApp); we do not hand your phone number to the business.
  • Petal does not currently have a separate "anonymous request" mode — every request is linked to your account — but, as described above, your identity is not shown to businesses until you choose one and confirm.

Please note: your free-text note is sent to businesses exactly as you wrote it, so we recommend not including identifying details you don't want to reveal.

Service providers and sub-processors

We rely on trusted third-party providers to run the service. Each one processes data only for its defined purpose:

  • Google Firebase — sign-in (user authentication) and push notifications. We also use Google Maps for business-address autocomplete during business onboarding.
  • Supabase — the database (PostgreSQL), hosted in the European Union region.
  • Fly.io — application server hosting (Frankfurt, European Union).
  • Temporal Cloud — reliable orchestration of the real-time request and matching process.
  • Cloudflare R2 — photo storage (for example, business profile photos).
  • Sentry — server-side error monitoring.
  • Expo — push-notification delivery and app build services.

Data retention

We keep your information for as long as your account is active and as long as it is needed to operate the service. Your request and booking history is kept so you can track your activity. When you delete your account, we delete the associated information as described in the next section.

Exception: reports submitted about a user (see "Reports") may be retained even after that user's account is deleted, for safety reasons and our legitimate interest in protecting the community.

Account deletion

You can delete your account directly from within the app: Profile → Delete Account. Deletion removes your account, profile, requests, bookings, and push tokens.

If you prefer, you can also email us a deletion request at info@petal.cy.

For step-by-step instructions, see our Delete Account page.

Your rights

Under Israel's Protection of Privacy Law, 5741-1981, you have the right to access the information we hold about you, to request its correction, and to request its deletion.

If you are located in a region where the EU General Data Protection Regulation (GDPR) applies, you also have the rights it provides — including access, rectification, erasure, restriction of processing, data portability, and objection to processing. To exercise any right, contact us at info@petal.cy.

Reports

The app lets users report other users. To keep the community safe and to address abusive behavior, a report submitted about a user may be retained even after that user has deleted their account.

Children

Petal is not directed at children under the age of 16, and we do not knowingly collect information from children under that age.

Changes to this policy

We may update this policy from time to time. We will update the "Last updated" date at the top of the page, and in the case of a material change we will make reasonable efforts to notify you.

Contact

Petal · info@petal.cy

Governing law: the laws of the State of Israel.