Privacy policy
This policy explains what information Makor collects, why, who it is shared with, how long it is kept, and what rights you have. It covers the website, the web app, the API and the Makor mobile app.
Who we are
Makor is an invoicing and receipts system for Israeli businesses, operated by Secure RO. For the information a business manages in Makor — its customers' details and the documents it issues — the business is responsible for that information, and Makor holds and processes it on the business's behalf and on its instructions.
What we collect
- Account details: full name, email address, preferred language, and a password that is stored only as a hash (Argon2), never in plain text. If you enable two-factor authentication, its secret is stored encrypted and its recovery codes as hashes. If you sign in with Google, we store your Google account identifier.
- Business details: registered name, VAT or company number, entity type, occupation, address, phone, email, logo and signature, and withholding-tax rate.
- Customers and documents: your customers' names, tax IDs, addresses, emails and phone numbers; items and prices; the documents you issue (invoices, receipts, credit notes) and their PDFs; and records of recipients' consent to receive computerized documents.
- Expenses and scans: supplier invoices and receipts you photograph or upload, and the fields read from them — supplier, tax ID, dates and amounts.
- Tax Authority connection: the access tokens the Israel Tax Authority issues when you connect your business (stored encrypted), and the allocation numbers it returns.
- Technical and security information: IP addresses and actions taken in the account, recorded in an audit log; for each signed-in mobile device, its platform (Android or iOS), device name, app version and last-used time; and for API keys, only a hash — never the key itself.
We do not use advertising or third-party analytics tools, and we do not sell information.
The Makor mobile app
- Camera: the app uses the camera only on the scanning screen, to photograph supplier invoices and receipts and file them in your business.
- Photos: photo-library access is used only to pick invoice photos you have already taken, and the app uploads only the photos you select.
- Photos you take or select are uploaded to your business's Makor account and are not used for anything else. The app does not access your location, contacts or microphone.
- Sign-in credentials are kept in the device's secure storage (Android Keystore or iOS Keychain) and erased when you sign out. Any device can be signed out remotely.
Why we use it
- To provide the service: issuing documents, gapless numbering, signed PDFs, reports and unified-format (מבנה אחיד) exports.
- To obtain allocation numbers from the Israel Tax Authority for tax invoices that require them.
- To email the documents you choose to send to your customers, and service messages such as an invitation to join a business.
- To read photos of supplier invoices, when automatic reading is enabled.
- To meet our legal bookkeeping obligations, secure your account, prevent misuse and provide support.
Who we share it with
We pass information on only as far as the service requires:
- Israel Tax Authority: an allocation-number request carries your tax ID, your customer's tax ID, the document type and number, dates and amounts.
- Brevo: the email delivery service that sends documents to your customers and our service messages. It processes the recipient's address and the message content.
- InvoiceOCR: when automatic reading of scans is enabled, the file is sent to the reading service, which runs on a separate server. It keeps the file for up to 72 hours — during which the service's operator may review requests for quality control — and then deletes it.
- Google: only if you choose to sign in with a Google account, and for identification only.
- Whoever you authorize: users you invite to your business (employees, and an accountant with read-only access), operators and systems you grant access or an API key, webhook endpoints you configure, and recipients of documents and share links you send.
- When required by law or by a competent authority.
How long we keep it
- Issued documents, their PDFs and the records behind them are kept for at least seven years from the end of the tax year they were issued in, and longer when a later annual-return filing date requires it, as Israeli bookkeeping rules (הוראות ניהול ספרים) demand.
- An issued document cannot be changed or deleted, and cancelling a document keeps its number. The law requires this, and the system enforces it.
- Photos of supplier invoices are kept for seven years. The audit log is never deleted.
- Account details are kept while the account is active, and afterwards only as far as the obligations above require.
Security
- All traffic to the website, the API and the app is encrypted with HTTPS.
- Passwords are stored as Argon2 hashes; Tax Authority tokens, signing keys and two-factor secrets are stored encrypted.
- Every issued document's PDF is digitally signed with a key unique to your business, and files are written once with an integrity hash, so any change to them can be detected.
- Two-factor authentication, signing out a single device, and signing out of every device at once.
Your rights
Under the Israeli Privacy Protection Law, 5741-1981, you may review the information held about you and ask us to correct or delete information that is inaccurate, incomplete, unclear or out of date. Much of it can be viewed and updated directly in your account and business settings; for anything else, write to us.
Information the law requires us to keep — issued documents and bookkeeping records — will not be deleted before its retention period ends.
If your details appear on a document a business issued to you through Makor, that business is responsible for the information. Please contact it first; we are glad to help.
Deleting your account
To delete your Makor account — whether you use the website or the app — email the address below from the address registered on the account, with the subject "Account deletion request". We will verify your identity and handle the request within 30 days.
- What is deleted: we deactivate the account, sign out every device and session, and delete the account details the law does not require us to keep.
- What is kept: documents the business issued, its bookkeeping records and the audit log are kept until the statutory retention period ends (at least seven years), and deleted after that.
- Signing out of the app or uninstalling it does not delete the account.
Children
Makor is built for businesses and is not intended for children. We do not knowingly collect information about anyone under 18.
Cookies
The website uses only strictly necessary cookies — to keep you signed in and to secure sign-in. We do not use advertising or tracking cookies.
Changes to this policy
When we change this policy we update the date at the bottom of the page. We will give advance notice of a material change in the app or by email.
Contact
For any privacy question or request, including a deletion request:
This policy was last updated in October 2026.