Privacy Policy

How eg2 collects, uses, and protects personal data.

eg2 ("we", “us”) is operated by Efrat Galanti, a sole trader registered in Israel, business ID 056655061. This policy explains what personal data we handle, why, and what rights you have.

Questions or requests: [email protected].

1. Two different roles

eg2 turns a spreadsheet you already own into a private portal your own customers can log into. That creates two distinct relationships, and your rights differ depending on which applies to you.

When you are our customer (a portal administrator), we play two roles at once, and it matters which data we mean:

  • Your account information — the details we need to run your account (your email, name, portal settings, and activity records). For this, we are the data controller: we decide what we collect and why, and this policy governs it.
  • The files and spreadsheet content you connect — this is your data. It remains yours and belongs to you; connecting it to eg2 never transfers ownership to us. For this data we act only as a processor on your behalf, reading and storing it solely to run the service for you and following your instructions. You decide what it contains, who may see it, and when it is removed. We never claim ownership of it, sell it, or use it for any purpose other than providing the service to you.

When your customers are end users of your portal (“portal contacts”) — we are only a data processor. You, as the business that created the portal, are the controller: you chose what to put in the spreadsheet shown in the portal, and you decide who may see it. We process that data solely on your instructions. If one of your customers wants their data corrected or deleted, they should contact you directly — we cannot make those decisions on your behalf. If they reach us instead, we will forward their request to you.

2. What we collect

From portal administrators

  • Account details — email address and full name.
  • Portal configuration — your business name, portal URL slug, logo, brand colour, and the Google Drive file ID of the spreadsheet you connect.
  • Activity records — sign-ins and significant actions, with a timestamp.

From portal contacts (on your behalf, as our customer)

  • Contact identifier — the email address or mobile number used to sign in, taken from your spreadsheet as the portal administrator.
  • Spreadsheet content — whatever rows and columns you chose to publish. We do not control this and cannot predict it. It may include names, order histories, balances, documents, or images. You, as administrator, are responsible for ensuring you have a lawful basis to publish it.
  • One-time passcodes — the code sent to authenticate a sign-in, its expiry, and the number of failed attempts.
  • Access records — which portal was accessed and when.

From visitors to the eg2 website

Effectively nothing. The eg2 marketing website uses Google Analytics to understand how visitors use the site, which sets cookies on Google’s behalf; beyond that we run no advertising or tracking scripts of any kind. If you use the contact form, we receive what you type into it.

3. What we do not do

  • We do not sell personal data, and we never have.
  • We do not use your data, or your customers’ data, to train machine-learning models.
  • We do not send marketing email to portal contacts. They receive sign-in codes only.
  • We do not read your Google Drive at large. Access is limited to the specific files you explicitly select — see §5.
PurposeLegal basis (GDPR Art. 6)
Providing the service and maintaining your accountPerformance of a contract
Sending one-time passcodesPerformance of a contract
Security, fraud prevention, abuse investigationLegitimate interests
Keeping activity records for troubleshootingLegitimate interests
Billing and statutory bookkeepingLegal obligation
Responding to your enquiriesLegitimate interests

Where we rely on legitimate interests, we have weighed them against your rights and concluded they do not override your interests. You may object at any time — see §8.

5. Google Drive access

When you connect a spreadsheet, you authorise eg2 through Google’s own consent screen using the drive.file scope. This is deliberately the narrowest scope Google offers for this purpose.

Concretely, this means:

  • We can only access files you specifically pick using the Google file picker. We cannot browse, list, or open anything else in your Drive — the technical permission does not exist.
  • Selecting a file grants our service account read-only access to that file alone.
  • We read the file’s contents to sync it into your portal, and we automatically keep track, by technical means, of changes made to the file, so the portal updates when you edit the spreadsheet.
  • Revoking access at any time via your Google account permissions immediately stops all further reading. Data already synced into your eg2 portal remains unchanged and is not deleted automatically — it simply stops updating until you grant access again. Of course, you can delete the portal yourself, which removes the data from our server.

eg2’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Who else processes data

We keep the list of data-processing partners deliberately short:

ProviderPurposeLocation
Google LLCReading connected Drive/Sheets files; change notificationsEU / US
Our email (SMTP) providerDelivering sign-in codes and service emailEU / US
PaddlePayment processing as merchant of recordUK / US
Our hosting providerRunning the servers and databaseIsrael

Payments are handled entirely by Paddle, who act as merchant of record. We never receive or store your card details.

7. International transfers

Where your data is stored and how it’s protected in international transfers:

  • Main servers — your data is stored primarily on servers in Israel.
  • External providers — some of our services are run by providers outside Israel (Google, our email provider, and Paddle), mainly in the EU, the UK, and the US.
  • Transfers to the EU — the European Commission has formally recognised Israel’s data protection standards as adequate, so personal data can flow freely between the EEA and Israel without additional safeguards.
  • Transfers to the US — the US does not have comprehensive federal privacy regulation comparable to the EU’s or Israel’s. So when data is transferred to US-based providers, we make sure the transfer is protected by a recognised legal mechanism — typically Standard Contractual Clauses approved by the EU, which legally bind them to protect your data at a level equivalent to what the EU requires.

8. How long we keep data

DataRetention
One-time passcode records90 days
Activity and access records12 months
Portal data and synced spreadsheet contentDeleted immediately upon account closure or portal deletion
Account and billing recordsDuration of the account, then as tax law requires (7 years in Israel)

Deleting a portal removes its synced data. Note that deleting data from eg2 does not touch your original Google spreadsheet, which remains entirely yours.

9. Your rights

If you are in the EEA or UK, you have the right to access your data, correct it, erase it, restrict or object to processing, port it to another provider, and withdraw consent where processing relies on consent. Israeli law grants comparable rights of review and correction.

Exercise any of these by emailing [email protected]. We respond within 2–3 business days. There is no charge unless a request is manifestly unfounded or excessive.

Remember the distinction in §1: if you are a portal contact, we will pass your request to the business that runs the portal, because only they can act on it.

You may also complain to a supervisory authority — the Israeli Privacy Protection Authority, or your local EEA/UK data protection authority.

10. Security

Access to portal data requires a one-time passcode sent to an email address already present in the administrator’s spreadsheet. Each portal’s synced data is stored in its own isolated database. Traffic is encrypted in transit with TLS.

No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal data and poses a risk to your rights, we will notify you and the relevant authority without undue delay, as required by law.

11. Children

eg2 is a business tool and is not directed at children under 16. We do not knowingly collect their data. If you publish a spreadsheet containing children’s data, that is your responsibility as controller.

12. Changes

We may update this policy. Material changes will be announced to you by email at least 14 days before taking effect. The date at the top always reflects the current version.

13. Language

This policy is published in several languages for convenience. In the event of any conflict, the English version governs.