Skip to main content

Privacy Policy

This policy explains what information is collected on the site, the purposes for which it is used, with whom it may be shared, and how to contact us regarding personal information.

Privacy contact details

Business name
מנדין
Email
orders@mail.mendin.co.il
Phone
050-277-0566
Address
דרך המשחררים 29, באר שבע

Information collected

  • Contact details: name, phone, email and shipping address.
  • Order details: products, quantities, prices, shipping, payment and handling status.
  • Personalization details: text, colors, logos, files, images and production notes.
  • Account information: email address, sign-in methods, order history and customer profile.
  • Technical and security information: IP address, browser identifiers, logs and security action records.

Purposes of use

  • Contacting the customer, handling orders, quotes and post-purchase service.
  • Producing personalized items and passing required information to the production team or a relevant service provider.
  • Billing, payment processing, invoices, shipping and transaction-status updates.
  • Securing the site, preventing fraud, handling errors and improving service.
  • Meeting legal requirements, bookkeeping and document retention.

External services and information processing

Infrastructure, hosting, database, payment, email, Google Business, WhatsApp, delivery and security providers may operate as part of the site and service. Only information required for the service is shared with these providers, subject to appropriate agreements and security mechanisms.

Google Privacy Policy

Cookies and local storage

The site uses cookies and local storage required for operating the service: sign-in, security, cart storage, draft order storage and accessibility preferences. If non-essential measurement, marketing or advertising tools are added, they will be activated only after an appropriate consent mechanism and an update to this policy.

Mendin may retain limited operational records needed for security, reliability and troubleshooting, such as a request identifier, tool name, time, duration and error code. Do not enter personal or confidential information into ChatGPT when it is not needed for a public catalog question. Questions about OpenAI's retention and use of conversations are governed by OpenAI's policies and settings.

OpenAI Privacy Policy

Information retention

Information is retained for the period required for the purposes for which it was collected, including order handling, warranty, customer service, bookkeeping, security and legal compliance. Information that is no longer required will be deleted or minimized where possible.

The connection is intended for an authorized administrator's express operational requests, such as store management, customer service and security. On an individual ChatGPT account, including Free, Go, Plus or Pro, OpenAI processes the conversation and returned information under its own terms, privacy policy and account settings. If “Improve the model for everyone” is enabled, OpenAI states that information accessed from apps may be used to improve its models; administrators should turn this setting off before connecting administrative data.

Mendin does not retain a copy of the ChatGPT conversation. OAuth tokens and one-time codes are stored only as hashes: access tokens are valid for up to 10 minutes and refresh tokens for up to 7 days, and the connection can be revoked at any time. Hash rows, OAuth requests, client registrations and lifecycle events may remain after expiry or revocation as security records; they currently have no automatic deletion deadline.

An action proposal expires after 10 minutes. An expired pending proposal becomes eligible for deletion after 24 hours, while a denied, succeeded or failed proposal becomes eligible after 7 days; deletion occurs during scheduled cleanup. Completed tool-execution audit rows become eligible for deletion after 30 days and are removed by the daily cleanup. Business records created after approval, such as an order or note, follow the ordinary retention policy for that business record rather than the connector's retention periods.

Administrators must request only information needed for the task, avoid copying unnecessary sensitive information into the conversation, and disconnect the connection when it is no longer needed. Mendin enforces permissions, limited audit records, revocation, two-factor verification and on-site approval before any write.

OpenAI Privacy Policy · Privacy and data use for apps in ChatGPT · ChatGPT Data Controls

User rights

You may contact us to request access to personal information, correction of inaccurate information, deletion where possible under law, or withdrawal of consent for non-essential uses. To handle a request, we may ask for details required to identify the requester.

Information security

Mendin uses reasonable security measures, including access control, permissions, encrypted connections, secure infrastructure providers and operational logs. No internet security is absolute, but we work to reduce risks and handle security events according to law.

Transfers outside Israel

Some service providers may process information outside Israel. In those cases, providers and contractual mechanisms are used with the aim of protecting the information according to applicable law.

Information security

Mendin uses reasonable security measures, including access control, permissions, encrypted connections, secure infrastructure providers and operational logs. No internet security is absolute, but we work to reduce risks and handle security events according to law.

Transfers outside Israel

Some service providers may process information outside Israel. In those cases, providers and contractual mechanisms are used with the aim of protecting the information according to applicable law.

Last updated: July 2026.