Last Updated: August 2026
SporeSec ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website sporesec.com and use our services.
We comply with Israel's Privacy Protection Law, 5741-1981, including Amendment 13 (in force since August 2025). Our services are directed at customers in Israel and are not directed at residents of the EU or EEA: we have no establishment or representative in the EU and do not knowingly collect personal data of EU residents. Wherever you browse from, we keep collection minimal and honor the Global Privacy Control (GPC) signal.
Information You Provide - Contact Information: Name, email address, phone number when you submit a contact form or subscribe to our mailing list. - Business Information: Company name, website URL, account type (business/personal) when provided. - Communications: Content of messages you send through our contact form. - Free Website Audit tool: The URL you scan is processed through our server-side proxies: Google PageSpeed Insights for performance scores, our own edge scanner for security headers and DNS email records, Google Safe Browsing for malware status, and a passive read of the returned page for obvious exposure signals (for example an exposed key pattern or a CORS misconfiguration). The scan is read-only and is not a penetration test. We do not store the target's page content; only the URL and the computed result summary. If you request the emailed report, we store the scanned URL, the results, your email address, and your separate marketing opt-in choice.
Automatically Collected Information - Log Data: IP address, browser type, pages visited, timestamps. Processed by our hosting provider (Cloudflare) for performance and security. - Cookies: Essential and functional cookies only, by name: NEXT_LOCALE (language), the theme preference, sporesec_pending_claim / sporesec_pending_proposal / sporesec_pending_ref (short-lived, HTTP-only carriers that attach a saved scan, a saved proposal, or a referral to your new portal account; one day at most), the portal sign-in and two-step cookies (prefixed sporesec.), portal-locale and portal-sidebar-side (portal display preferences), the embedded Cal.com scheduler's cookies (only after functional consent), and the Cloudflare Turnstile bot check (operated under Cloudflare's Turnstile Privacy Addendum; it evaluates the browser without tracking you across sites). None of these are advertising cookies. - Analytics: First-party and cookieless by default: aggregate page and event counts. Your raw IP address is never stored; we keep only a salted, non-reversible hash of it (still personal data, which is why we minimize and protect it). Richer analytics run only if you opt in through the cookie banner (reopen it anytime via "Manage Cookies" in the footer) and include: referrer and UTM campaign tags, a random session id, coarse country (from Cloudflare, never your address), scroll depth, time on section, and interaction signals such as repeated or dead clicks and abandoned forms; Google Analytics 4 loads only under the same opt-in. Advertising attribution (a Meta/Facebook pixel) is wired but inactive, loads only under the separate marketing opt-in, and is disclosed here by name. We honor the Global Privacy Control (GPC) signal, keep everything non-essential off by default, and run no on-site ads or third-party ad tracking. - Client portal (app.sporesec.com): available as a free self-serve account or as a client account when we work together; it stores your account details (name, email, phone, business name and address, language), projects and milestones, documents you receive, contract signatures (signer name, time, a hashed IP, and the document fingerprint, per the Electronic Signature Law), invoices, messages with us, notification preferences, and a security access log (event type, hashed IP, browser). You can export all of it as a file or request deletion from Settings. On deletion we erase your portal data and the CRM contact, and irreversibly anonymize your earlier lead and scan records on the marketing site (identifiers and the scanned address removed). Signed agreements and tax records are retained after deletion only as, and for as long as, the law requires; see section 7 for the exact categories and periods.
We do not sell your personal data. We may share data with: - Cloudflare: Hosting, edge network, bot protection (Turnstile), and secure storage of form submissions (Cloudflare D1, server-side only) - Brevo: Transactional email and contact management - Cal.com: Meeting scheduling when you book a call through the embedded calendar - Google: PageSpeed Insights processes the URL you scan to produce the lab performance results; Google Analytics 4 runs only after you opt in to analytics cookies - Meta: the advertising pixel loads only after a separate marketing opt-in, for campaign attribution
Each provider processes data only to deliver its service to us, under its own data-processing agreement (for example Cloudflare's Customer DPA and Brevo's DPA). Some process data outside Israel; where they do, it is under contractual data-protection commitments consistent with Israeli law.
We may produce and share anonymized, aggregated statistics derived from the free security scans, for example how common a class of misconfiguration is across a sector or company-size band. These aggregates are stripped of anything that could identify you or your site: the scanned domain is removed, the figures are decoupled from any contact record, and a number is reported only for a group large enough that no single site can be singled out. We never publish a result, grade, or benchmark tied to an identifiable website, and we never sell or share identifiable lead or contact data. Because these statistics are truly anonymized, they fall outside the Privacy Protection Law; the de-identification method and the re-identification risk test we run before any release are documented in our anonymization standard, consistent with the Israeli Privacy Protection Authority's guidance on privacy-enhancing technologies. If you ask us to delete your data, it is excluded from any future aggregate.
We collect only what is needed to run the service, and we never sell your personal data.
Under Israel's Privacy Protection Law (as amended by Amendment 13) you have the right to: - Access the personal data we hold about you - Request correction or deletion of your data - Withdraw analytics or advertising consent at any time via "Manage Cookies" in the footer - Withdraw consent for marketing communications at any time (every marketing email also carries an unsubscribe link) - Request data portability - Lodge a complaint with the Israeli Privacy Protection Authority
To make a request, email contact@sporesec.com or use our contact form and select "Privacy / data request". We honor the Global Privacy Control (GPC) browser signal automatically.
We implement industry-standard security measures including encryption in transit (TLS), secure hosting infrastructure, and strict access controls. Security engineering is one of our services; we hold our own systems to the same standard.
We keep personal data only as long as it is needed for the purpose it was collected, then delete or anonymize it. The main periods: - Contact and lead records: while the enquiry is active plus a short follow-up window, then anonymized. - Free scan and configurator drafts: up to 90 days, then purged. - Analytics events: up to 400 days (aggregate, with a hashed IP). - Application and error logs: up to 30 days. - Portal notifications: up to 180 days once read (365 days otherwise); the activity feed up to 365 days; the security access log up to 730 days. - Marketing list: until you unsubscribe.
What we keep after you ask us to delete your account. When you delete your account we erase your profile, saved scans, messages, and marketing records, and confirm what was removed. Two categories are kept afterward, because the law requires it or entitles us to keep them, and only these: 1. Tax and accounting records. We are legally required to keep invoices, receipts, and their supporting documents for at least 7 years from the end of the relevant tax year (Income Tax (Keeping of Books) Instructions). We cannot delete these before that period ends. 2. Signed agreements and accepted proposals. Where you electronically accepted or signed a proposal or agreement, we keep the signed document and its signature record (your name, email, the time of signing, and a technical fingerprint proving the document was not altered) for the duration of the engagement and for up to 7 years after it ends, so either party can rely on or defend the agreement within the limitation period set by the Prescription Law, 5718-1958.
We keep only the records above, for at least the periods stated, and delete them once the law no longer requires them. If we retain anything after your deletion request, we tell you what and why. Marketing list subscribers can unsubscribe at any time.
For privacy-related inquiries or to exercise your rights: - Controller: SporeSec (Medy Gribkov) - Email: contact@sporesec.com - Security issues: security@sporesec.com - Location: Tel Aviv, Israel
SporeSec. Tel Aviv, Israel.