Privacy policy
Privacy Policy
- Version
- 1.0
- Last updated
Version: 1.0
Effective date: 29 August 2026
Last updated: 29 August 2026
This document describes what personal information the ARKEN site collects, why it is collected, who it is disclosed to, how long it is kept and how to contact us about it. It was written from an actual review of the site's code and data stores, not from a template. If you find a gap between what is described here and what actually happens, please tell us and we will correct it.
This policy forms an integral part of the site's terms of use.
This is a translation of the Hebrew policy, which is the operative version. Where the two differ, the Hebrew governs.
1. Who controls the information, and how to reach us
The controller of the personal-information database and the operator of the site is:
- ARKEN, licensed dealer (עוסק מורשה) no. 215615881
- Address: 2 Itamar Ben Avi Street, Netanya 4223762, Israel
- Email: orders.arken@gmail.com
- Telephone: 077-223-6623
- Hours: Sunday–Friday, 08:30–20:00. Closed Saturday.
ARKEN is a licensed dealer, not a limited company. Any privacy enquiry — including a request for access, a request for correction, or removal from marketing — should go to the email address or telephone number above. No separate data protection officer has been appointed, so requests are handled directly by ARKEN.
2. What information is collected
Information falls into two kinds: what you give us, and what is generated automatically as you use the site.
Information you give us
- Account creation and sign-in. Email address and name. If you sign in with a Google or Microsoft account, we also receive your profile picture and that provider's permanent user identifier. If you register with a password, only a hash of the password is stored — the password itself is never stored and cannot be recovered.
- Profile and addresses. Name, email address, telephone number and any delivery addresses saved to your account.
- Orders. Name, email, address, city, postcode and country, together with the items, quantities and amounts.
- Customer-service enquiries. Name, email, subject and the content of your message.
- Chat conversations. The content of the messages, and your name and email if you supply them in the conversation.
- Cancellation notices. Order reference, name, email, telephone (optional) and reason for cancelling (optional).
- Reseller applications. Business name, contact name, email, telephone and the business details you supply.
- Free text. Anything you choose to write in an open field — an enquiry, a chat message, a cancellation reason — is stored as written. Please do not include sensitive information that is not needed to handle your request.
Information generated automatically
- Cart identifier. A random identifier created in your browser to link your session to its cart, wishlist and guest profile. It contains no name or email address.
- Cart and wishlist contents. The items you added and when they were updated.
- Payment records. Transaction identifiers, payment status, the expected amount and currency, and attempt timestamps. See section 6 in full.
- Operational and security information. Error logs and request rate limits, used to keep the site stable and to prevent abuse.
- Gift cards. The email address a voucher was sent to, along with its code and balance.
What we do not collect
- We do not collect or store credit-card details — see section 6.
- We do not store visitors' IP addresses in our database, we do not store full browser user-agent strings, and we do not store full referring URLs.
- We do not run profile-based advertising, we do not carry out marketing profiling, and we do not sell personal information to anyone.
- Mailing list. The newsletter sign-up form on the site is not currently connected to any mailing system, so an address entered into it is not stored and is not sent to anyone. See section 8.
3. Is providing information mandatory
There is no general legal obligation to give us personal information. Some services, however, cannot work without it:
- Placing an order and delivery. Name, email, address, city, postcode and country are a condition of completing an order: without them the product cannot be delivered and you cannot be kept informed. They are needed for our contract with you, and an order cannot be placed without them.
- Payment. Completing a payment requires entering details on the payment provider's own page. Those details go to the provider, not to us. Without them, payment cannot be made.
- Creating an account. An email address is a condition of creating an account, because it identifies the account. You can also buy from the site without an account.
- Cancellation notice. An order reference, name and email are needed to identify the order and to send an acknowledgement. The reason for cancelling and the telephone number are optional — a notice with no reason is received and handled exactly like one with a reason.
- Contacting support or using chat. We need a way to reply. You can also call us without entering anything on the site.
- Marketing. Consent to marketing is entirely optional and separate. Withholding it does not affect your ability to buy, or the price, delivery or service you receive.
4. What the information is used for
Information is used only for the following purposes:
- Creating and administering user accounts and signing in.
- Receiving, fulfilling and updating you about orders.
- Taking and verifying payments, including reconciling our payment record against the provider's.
- Issuing invoices and receipts and maintaining accounting records, as required by law.
- Shipping and tracking deliveries.
- Handling cancellations, returns, warranty claims and support.
- Responding to enquiries and chat conversations.
- Service messages about an order, a cancellation or account security. These are not marketing and do not require separate consent.
- Preventing fraud, abuse and security incidents, and keeping the site sound.
- Maintaining and improving the site.
- Meeting the legal and regulatory obligations that apply to us.
- Establishing, exercising or defending legal claims.
Information is not used for any other purpose not listed above without telling you.
5. Who information is disclosed to
Running an online shop means using service providers. This is not a claim of "no disclosure": completing an order necessarily sends details to the payment provider, and delivering it necessarily sends details to the carrier. Providers receive only the information their function requires.
- Payment and clearing provider. Receives full name, telephone, email address, the transaction amount, its description and the order reference, in order to take the payment and issue an accounting document. Clearing is handled by Invoice4U (Israel).
- Alternative payment provider. If you choose to pay with PayPal, PayPal receives the transaction amount and the order reference only. We do not send it a delivery address.
- Delivery company. Name, address, city, postcode and contact details are passed on so the order can be delivered. Deliveries are carried out by HFD.
- Hosting and infrastructure providers. The site and its data file are stored with a server hosting provider. The provider makes no independent use of the information.
- Email. ARKEN's outgoing messages and customer-service mailbox run on a Gmail address, so the content of that correspondence also sits with Google.
- Sign-in providers. If you choose to sign in with a Google or Microsoft account, that provider verifies your identity and gives us an email address, name, profile picture and a permanent identifier. We never receive your password for that account.
- Professional advisers. An accountant, lawyer or other adviser, to the extent needed for the advice.
- Authorities. We will disclose information to a competent authority, a court or a law-enforcement body where we are legally required to, or where it is necessary to protect our rights in legal proceedings.
We do not sell personal information and we do not pass it to third parties for advertising.
The scope of our contractual arrangement with each provider is not set out in this document. If you need clarification about a particular provider, please ask us.
6. Payments and card details
This is the most important section in this document, and it was checked against the site's code.
- Credit-card details never reach ARKEN's servers and are not stored by us. The card number, its expiry and the security code (CVV) are entered directly on the payment provider's own hosted page. The ARKEN site has no input field for card details, and its code contains no field, variable or record intended for them.
- ARKEN asks the payment provider not to create or store a reusable card token.
- Apple Pay and Google Pay payments are also completed on the payment provider's page, in the same way.
- What we do keep: an internal transaction identifier, the provider's transaction identifier, a document or receipt number, the payment status (pending / paid / failed / cancelled / refunded), the expected amount and currency, the number of verification attempts and their timestamps, and a short description of the reason for any failure. These records contain no card number, no last four digits, no security code, no token and no authorisation code.
- Why it is kept: to match a payment to an order, to spot duplicate or missing payments, to handle queries and refunds, and to meet accounting record-keeping obligations.
7. Cookies and browser storage
The site uses a small number of cookies. There are no advertising cookies, no third-party tracking cookies and no marketing pixels of any kind. The site uses localStorage in exactly one place: the accessibility toolbar stores the display settings you choose. It is listed in the table below.
The table below is generated directly from the site's own code, so the names and durations shown are the ones actually sent to your browser:
| Name | Owner | Purpose | Category | Essential? | Duration | When set | Removal |
|---|---|---|---|---|---|---|---|
| arken_cart | ARKEN | A random identifier linking the browser to its shopping cart, wishlist and guest profile. It contains no name, email address or other identifying detail. | Functional | Yes | 1 year | Only on a first functional action — adding to the cart, opening a chat, entering checkout or using the account area. Browsing alone does not create it. | Clear cookies in the browser. Doing so disconnects the saved cart. |
| arken_user | ARKEN | Keeps you signed in to your customer account. Holds a cryptographically signed account id, so it cannot be forged. An authentication cookie, not a tracking cookie. | Essential | Yes | 1 year | When you sign in. | Sign out, or clear cookies in the browser. |
| arken_admin | ARKEN | A security cookie for ARKEN's internal admin console. It is created only for ARKEN staff signing in to that console and is never created for customers. It is not used to track visitors. | Essential | Yes | 12 hours | Only when a member of staff signs in to the admin console. | Sign out, expiry, or an admin password reset — which immediately invalidates every existing session. |
| arken_lang | ARKEN | Remembers the chosen interface language (Hebrew or English) so you are not asked on every visit. It holds the language code and nothing else. | Preference | No | 1 year | When you choose a language, or on first detection from browser settings. | Clear cookies in the browser. The language is then detected again. |
| _accessStatelocalStorage | ARKEN | Stores the accessibility toolbar settings you chose — text size, contrast, cursor type and highlighting — so you do not have to set them again on every page. It stays in your browser and is never sent to our server or to any third party. | Preference | No | Until cleared | Only if you change a setting in the accessibility toolbar. Simply showing the icon does not create it. | Reset the settings from within the toolbar, or clear site data in your browser. |
| msal.*sessionStorage | Microsoft | Microsoft's sign-in library keeps temporary sign-in state in the browser's sessionStorage during the sign-in flow only. It loads only if you choose to sign in with a Microsoft account. | Essential | Yes | Until the tab is closed | Only when you use the Microsoft sign-in button. | Close the tab, or clear site data in the browser. |
Third-party storage, only when you use the relevant service
- Google — Google's sign-in library (accounts.google.com) loads only on the sign-in page, and only if you choose to sign in with a Google account. Google may set its own cookies under its own policy.
- PayPal — PayPal's payment SDK loads only on the checkout page, and only when that option is configured. PayPal may set its own cookies under its own policy.
- Invoice4U — The secure payment page is hosted on the clearing provider's own site. It opens only when you choose to pay, and any cookie set there is the provider's, under its own policy.
An important clarification: the admin console cookie is a security cookie for ARKEN staff only. It is never created for customers and is not used to track visitors.
Can they be refused. Every cookie listed above is essential or functional, except the language preference. Because we currently run no analytics or marketing cookies, there is no refusal mechanism on the site — there is nothing to refuse. We do not display a consent banner that has no technical effect. If non-essential measurement is ever switched on, a real choice will be offered before it starts, and this document will be updated.
How to remove them. Every browser allows cookies to be deleted and blocked. Blocking the functional cookies will break the cart and the account area.
Third parties, when you use a particular feature. See section 5. The Google and Microsoft sign-in libraries and the PayPal payment SDK load only on the relevant pages and actions, not during ordinary browsing. Cookies those parties set are governed by their own privacy policies.
8. Marketing
- Signing up for marketing is entirely optional. The consent box on the form is not ticked by default, and ticking it is required to submit the form. Pre-ticked consent is not consent.
- Current position: the newsletter form on the site is not connected to any mailing system. An address entered into it is not stored in our database, is not sent to any provider, and creates no consent record. ARKEN does not currently operate a mailing list and does not send marketing from the site. The form itself says so.
- If and when a mailing system is introduced, we will record when consent was given and how, include a simple unsubscribe link in every message, and update this section before any message is sent.
- Service messages are not marketing. An order confirmation, a delivery update, an acknowledgement of a cancellation notice or a security alert are sent under our contract with you and need no marketing consent. They contain no promotional content.
- Unsubscribing. A request to be removed from marketing can be sent to orders.arken@gmail.com. To honour an objection over time, we will keep a minimal record of the objection itself — otherwise we would have no way of knowing not to contact you again.
9. Site-usage measurement (analytics)
As at the date of this document, analytics collection on the site is switched off.
The site contains an internal mechanism for counting page views for ARKEN's own operations screen. It is not active: the server refuses every page-view report and no new measurement record is written. It was disabled because this is measurement that is not essential to running the shop, and there is no mechanism on the site by which you were ever asked about it. We will not write that you consented to something you were never asked about.
For full transparency, when the mechanism was running it recorded — and if it is ever switched on again would record — only:
- The page path on the site, without the query string at the end of it.
- The host name of the referring site only, never the full URL.
- A coarse device category only: mobile, tablet, desktop or automated crawler.
- The interface language.
- A timestamp.
- The cart identifier, in order to group pages into a single visit.
In addition:
- No IP address was stored. An IP address exists transiently in the network request itself, as in any internet request, but it is neither read nor written to the database.
- No full user-agent string was stored. Only the device category was derived from it; the string itself was not kept.
- The information was never sent to any external party. There is no Google Analytics, advertising pixel or third-party measurement tool of any kind on the site.
- For a signed-in user, the visit identifier is the account identifier — meaning the record was linked to an account rather than anonymous. That is one of the reasons it was disabled.
- Records already collected in the past continue to be deleted automatically after 90 days.
It will be switched back on only after a real and enforceable choice is offered, and after this section is updated.
10. How long information is kept
We do not keep everything forever — but we also will not claim to delete information that we do not in fact delete. Here is the real position, by category:
Automatic deletion that exists and runs
- Site-usage measurement records: deleted automatically after 90 days, and capped in number. Deletion happens as new records are written.
- Admin password-reset codes: expire within 10 minutes and are deleted.
- Incomplete payment attempts: marked expired within 24 hours and no longer retried.
Kept as needed, with no automatic deletion at present
- Orders, invoices and payment records: kept for as long as needed for delivery, warranty, queries, bookkeeping and statutory reporting duties, and to defend claims within the limitation period. We deliberately do not state a number of years here while no documented business decision has been taken and no tax adviser has been consulted; we would rather state no number than state a wrong one.
- User accounts and profiles: kept for as long as the account exists.
- Carts and wishlists: kept for as long as the cart identifier exists in your browser, and at most one year, which is the cookie's lifetime.
- Customer-service enquiries and chats: kept so that a matter can be picked up again and repeat queries handled.
- Cancellation, return and warranty records: kept as evidence that a notice was given and of how it was handled. This record may be needed in your favour, as proof of when you gave notice.
- Marketing objection records: kept for as long as needed to honour the objection.
- Security and fault logs: kept for the short period needed for diagnosis and to prevent abuse.
- Backups: to the extent backups are taken, information deleted from the live database may persist in a backup copy until that copy is rotated.
Limits on deletion. Information needed for bookkeeping, for reporting to authorities, to resolve a claim or to prevent fraud will be kept after a deletion request, to the extent needed for that purpose alone. We cannot undertake to delete an accounting record we are required to keep.
11. Information security
We take reasonable measures to protect information. Here is what is actually implemented:
- Passwords are stored as a scrypt hash with a unique salt per password. The password itself is never stored and cannot be recovered, including by us.
- Authentication cookies are cryptographically signed and marked httpOnly, so they are not readable by JavaScript in the browser, and Secure in production, so they are only sent over an encrypted connection.
- Traffic to the site is encrypted with HTTPS.
- Separation between customer and staff access: the admin console requires an admin role and is protected by a separate, short-lived cookie (12 hours) with its own signing key.
- Resetting an admin password immediately invalidates every existing session for that account.
- Rate limiting on sensitive routes — sign-in, registration, password reset, checkout, chat and cancellation notices — to make guessing and abuse harder.
- Card details never pass through the system at all, so they cannot leak from it.
- Keys and secrets are configured on the server only, and are never exposed in the browser, in error messages or in logs.
What we do not claim. We do not claim encryption at rest, penetration testing, round-the-clock monitoring, ISO certification, PCI DSS certification or any other accreditation. We hold no such certifications and will not make a claim we cannot support.
No system is completely secure. We cannot guarantee absolute security and do not undertake to. If we become aware of a security incident affecting personal information, we will act to address it and to notify those affected as required by law.
12. Access, correction and other requests
- Self-service access. Account holders can view and update their own details directly on the site: account details, delivery addresses and order history. This is the fastest route and needs no request to us.
- Access request. You may ask to see the information we hold about you by writing to orders.arken@gmail.com.
- Correction request. If information we hold is wrong, incomplete, inaccurate or out of date, you may ask us to correct it.
- Removal from marketing. At any time, without giving a reason. See section 8.
- Deletion or restriction. We will consider each request on its merits. We do not promise blanket deletion of every record: information we are legally required to keep, or that is needed to resolve a claim or to prevent fraud, will be retained to the extent needed for that purpose. We will tell you what was deleted, what was not, and why.
Identifying the requester. So that we do not disclose your information to someone impersonating you, we will ask for details that link you to the information — for example the email address used on an order, and an order reference. We will ask for an identity document only if those details are not enough for reasonable identification, and not as a routine requirement.
Response time. We will respond within a reasonable time. If a request is complex and needs longer, we will tell you.
If you believe we have not handled your request properly, you retain the rights available to you under Israeli law, including approaching the competent authority.
13. International transfers
Some of the services we rely on are operated by international companies, so some information may be processed or stored outside Israel. We cannot say that all information stays in Israel, and we will not say so.
- The clearing provider we work with is Israeli and operates an Israeli interface.
- PayPal, Google and Microsoft are international providers. Information sent to them — an amount and order reference in PayPal's case, basic identity details in the case of sign-in, and email correspondence content in the case of the Gmail mailbox — may be processed outside Israel, under that provider's own policy.
- The location of the site's hosting servers was not verified in this review, so we do not state here where they are.
What we do not claim. We do not claim Standard Contractual Clauses, an adequacy decision or any equivalent transfer mechanism, because no agreement establishing such a claim has been produced to us. If such arrangements are put in place, this section will be updated.
14. Changes to this policy
This document may be updated — for example if a service is added, a provider is added, or the handling of information changes.
- The updated text will be published on this page, alongside a version number, an effective date and a last-updated date.
- For a material change — a new processing purpose, a new category of provider, or the start of non-essential measurement — we will display a prominent notice on the site before the change takes effect, or email account holders.
- A change to this policy does not apply retroactively to a completed transaction. Information given as part of an order already placed remains governed by the policy in force when that order was placed, unless the change is required by law.
15. Contact
- ARKEN — licensed dealer no. 215615881
- Address: 2 Itamar Ben Avi Street, Netanya 4223762, Israel
- Email: orders.arken@gmail.com
- Telephone: 077-223-6623
- Hours: Sunday–Friday, 08:30–20:00. Closed Saturday.
When writing about a privacy matter, please say so explicitly so that your message is routed correctly.
This document describes how the site actually behaves as at the date shown. Nothing in it reduces your rights under Israeli privacy and consumer law.