BaeemBack to home

Privacy Policy

Last updated: August 30, 2026

This Policy explains how Y.S. Software (י.ש תוכנה), Israeli exempt dealer no. 323881417 ("baeem", "we", "us", or the "Operator"), the controller of the Service's databases, collects, uses, retains, and discloses personal information in connection with the baeem website and service (the "Service"). It applies to event hosts, users, guests, website visitors, and people who contact us, and forms part of our Terms of Use.

1. Key Principles and Providing Information

You are not legally required to provide us with personal information; providing it is voluntary. However, without information marked as required, we may be unable to create an account, identify you, contact you, send invitations, collect RSVPs, process a payment, or provide another part of the Service. If you provide information about someone else, you must be entitled to do so and give them any notice required by law.

"Personal information" means information about an identified person or a person who can reasonably be identified. Aggregated or anonymous information that cannot identify a person is not personal information.

2. Information We Collect

  • User and account information: name, phone number, email address where supplied or received through Google sign-in, account identifiers, authentication methods, invited team members, and preferences.
  • Event and host information: event type; names, phone numbers, and details of partners or family members; date, time, venue, address, navigation and gift links, invitation image, message copy, custom questions, special requests, and seating information.
  • Guest information: name, phone number, household or group association, party size, RSVP status, dietary or accessibility preferences, answers to questions, table number, message content, WhatsApp or SMS correspondence, and phone-call results. Some information, such as dietary or accessibility preferences, may indirectly reveal sensitive information.
  • Contacts you choose to import: names and phone numbers from a file, device, or Google account. For WhatsApp import, contact and group discovery runs on your device; group names, memberships, and chat history are not sent to our servers, and only people you approve as guests are sent to the Service.
  • Enquiries, leads, and support: details you submit through a form, the onboarding chat, a demo, onboarding, correspondence, or a support call, including the enquiry and internal handling notes.
  • Payments and transactions: amount, currency, time, payment status, transaction identifiers, receipt, and campaign attribution. Full card details are processed by SUMIT and are not stored by us.
  • Technical and usage information: IP address, device type, operating system and browser, online identifiers, pages and actions in the Service, usage times, performance, errors, referrer, campaign parameters, and security data.
  • Recordings and transcripts: automated calls with guests may be recorded and transcribed, including the guest’s voice and statements, the automated agent’s responses, and the call result, to provide, review, troubleshoot, and improve the Service.

3. Sources of Information

  • Directly from you when you register, pay, upload an invitation or list, connect a service, answer a message or call, or contact us.
  • From an event host, partner, family member, or other user who adds you or your details to an event.
  • Automatically from your device, browser, and use of the Service through logs, local storage, cookies, and similar technologies.
  • From providers and services you connect or choose to use, such as Google, WhatsApp, SUMIT, and RSVP.

4. How We Use Information

  • To create and manage accounts and events, identify users, and grant access to partners, family, or team members.
  • To build and import guest lists, create invitations, send messages and reminders, place calls, collect and update RSVPs, and plan seating.
  • To extract details from invitation images, tailor greetings, understand free-form answers, and conduct conversations using automated and AI systems.
  • To process payments, issue records, prevent fraud, and handle cancellations, disputes, and service enquiries.
  • To provide support, communicate about the Service, and respond to enquiries. Marketing will be sent only as permitted by law and with any required consent, and you can ask us to stop at any time.
  • To secure the Service, detect misuse, maintain audit records, troubleshoot, measure performance, and improve the product and user experience.
  • To measure advertising and campaigns, understand how users found the Service, and report events such as registration or purchase to analytics and advertising platforms.
  • To comply with legal obligations, lawful authority requests, or legal proceedings, and protect rights, property, and safety.

5. Event Hosts and Guest Information

The event host decides which guests are included, which messages are sent, and which information is collected for the event. For that information, the host is responsible for lawful collection and use, accuracy, required notices, and guest rights; we process it to provide the Service under the host’s instructions. We may process limited information for our own purposes, such as security, fraud prevention, legal compliance, and Service administration.

A guest seeking to access, correct, or delete information supplied by an event host should first contact that host. The guest may also contact contact@baeem.co.il, and we will assist or route the request according to our role and applicable law.

6. Artificial Intelligence and Automated Calls

The Service uses automated tools and AI services, including Google Gemini and sometimes a telephony provider’s AI services, to read invitation details, tailor greetings, understand answers that ordinary rules cannot parse, and conduct RSVP calls. The relevant provider may receive an invitation image, guest name, event details, response text, conversational context, or audio only to the extent needed for the task.

An automated system may suggest or record an RSVP status, party size, or preference based on a guest’s response. The event host can review and correct the result. The Service does not make automated decisions that have legal or similarly significant effects on a person.

Calls may be recorded and transcribed by the telephony or AI provider. Guests should avoid sharing information not needed for the RSVP. Where law requires a specific recording notice or consent, the event host is responsible for ensuring that outreach is lawful.

7. Cookies, Analytics, and Advertising

We use cookies and local storage for authentication, security, language and preference storage, and attribution. We also use PostHog for usage analytics, performance, heatmaps, and session replay, and Meta Pixel and Meta Conversions API for advertising and conversion measurement. These tools may set or read identifiers such as _fbp and _fbc and receive information about pages, actions, devices, referrers, and campaigns.

We configure PostHog to mask text and input fields and filter sensitive properties before transmission; session replay is not intended to capture form content, guest lists, or messages. In conversion reports to Meta, an email address or phone number may be sent in cryptographically hashed form, together with browser identifiers, campaign information, and the event type.

You can restrict cookies through browser settings or blocking tools. Blocking essential technologies may impair the Service. Additional advertising controls are available through Meta account settings and tools offered by browsers and platforms.

8. Disclosures to Third Parties

We do not sell personal information. We disclose it only as needed for the purposes described in this Policy, including to:

  • Cloudflare — database, storage, hosting, security, and delivery of the website.
  • Meta and WhatsApp — authentication, message delivery, receiving replies, temporary media hosting, and advertising and conversion measurement.
  • ActiveTrail or Twilio — SMS delivery; Telnyx and related voice or AI providers — placing, recording, transcribing, and processing calls.
  • Google — sign-in, contact selection, and Gemini services for the content processing described above.
  • SUMIT — Service payment processing and fraud prevention.
  • PostHog and Sentry — analytics, error diagnosis, performance, and security.
  • Email, operational-messaging, and support providers, and professional advisers such as accountants, lawyers, and security providers, as needed and under appropriate obligations.
  • RSVP — the independent provider of card-gift registration, identity verification, compliance, processing, and settlement. Information is transferred only after a separate choice and approval and is subject to RSVP’s terms and privacy policy.
  • A competent authority, court, or other party where disclosure is legally required, necessary to protect rights or safety, or connected with a reorganization, transfer of operations, or business transaction, subject to law and appropriate safeguards.

9. International Transfers

Some providers operate outside Israel, so information may be stored or processed in other countries, including the United States and Europe. Privacy laws there may differ. Transfers will be made in accordance with applicable law using contractual commitments, transfer mechanisms, or other appropriate safeguards as relevant.

10. Retention

We retain information for as long as needed for the purpose for which it was collected: maintaining the account and event, providing support, security, transaction records, protecting rights, and legal compliance. Retention depends on the data type, sensitivity, event status, and legal obligations. Information is then deleted or anonymized unless further retention is permitted or required. You may send a deletion request to contact@baeem.co.il.

For transparency: WhatsApp conversation text retained for the automated agent and AI decision logs are generally deleted after 90 days; raw webhook bodies are generally deleted after 14 days; an unused anonymous account draft is generally deleted after 30 days; and an onboarding chat where no phone number was provided is generally deleted after 24 hours. Transaction, security, and backup records may be kept longer where needed or required by law.

For RSVP gift-service registration information, we act only as a transient technical conduit: bank details and compliance answers are cleared after transfer and no later than 60 minutes after collection begins; identity documents are deleted after the registration attempt with a scheduled deletion backstop within 60 minutes; and gift-giver and amount details are displayed to the verified event host in memory for under 15 minutes without storage in our database. RSVP’s own retention policy applies to the copy delivered to it.

11. Information Security

We use reasonable and customary technical and organizational measures, including access controls, encryption in transit, role separation, logging, data minimization, and scheduled deletion where appropriate. No system is completely secure, however, and we cannot promise that information will never be exposed, lost, or compromised. You must protect your sign-in methods and promptly notify us of suspected unauthorized use.

12. Your Rights

Subject to Israel’s Protection of Privacy Law, 1981 and applicable law, you may request access to personal information held about you. If it is inaccurate, incomplete, unclear, or outdated, you may ask us to correct or delete it. You may also request account closure, deletion, or an end to marketing; some rights may be limited by others’ rights, retention duties, fraud prevention, or the defense of claims.

Where another law such as the GDPR applies, you may have additional rights, including restriction, objection, portability, withdrawal of consent, and the right to complain to a supervisory authority. To exercise a right, email contact@baeem.co.il with enough detail to identify you and the requested information. We may verify your identity before responding.

A request concerning RSVP’s gift service—including gift-giver, transaction, processing, settlement, or refund information—should be sent directly to RSVP at rsvp@rsvpevents.co.il or WhatsApp +972 54-2512465. We will assist with routing where needed, but RSVP decides requests concerning information it controls.

13. Minors

Opening an account and using the Service as an event host are limited to people aged 18 and over. The Service is not directed to minors for account creation. An event host may nevertheless enter limited information about minor guests, such as a name, family association, and dietary preference, to manage the event. The person providing it must be entitled to do so and obtain parental or guardian consent where required. Contact us if you believe a minor’s information was provided unlawfully.

14. External Links and Services

The Service may link to or integrate with services we do not control, such as bit, PayBox, RSVP, Google, WhatsApp, and venue websites. Their terms and policies apply, and we recommend reviewing them. This Policy does not apply to processing by an independent third-party controller.

15. Changes to This Policy

We may update this Policy to reflect changes in the Service, providers, or law. The updated version will be posted here with a revised date. For a material change, we will take reasonable steps to notify users before it takes effect where required.

16. Contact

The controller of the Service's databases is Y.S. Software (י.ש תוכנה), Israeli exempt dealer no. 323881417. For privacy questions, requests, or complaints, email contact@baeem.co.il.