Legal
Privacy
Last updated: July 30, 2026
Draft. This is a first, plain-language pass written by the Home Sublet team. It will be replaced by a legally reviewed version before launch. Nothing here is legal advice. Translation, for convenience. The Hebrew version is the binding one. This translation is for understanding only, and where the two differ the Hebrew prevails.
What we collect
- Your phone number. It's how we identify you and sign you in. In most places it's stored hashed; in one place it's in the clear — the user record itself.
- Your email address, if you gave us one. Used for things like reference requests and booking confirmations. We don't sell it.
- Profile fields you fill in: about me, occupation, languages, preferences, privacy settings.
- Listings you create (as a host): photos, lease PDFs, address, price, what's in the flat.
- Bookings you make: dates, guests, how the keys change hands, and messages tied to the booking.
- Messages you send through Home Sublet: stored as written, and visible to you, to the other side, and to Home Sublet's operations team if a dispute is opened.
- References written about you: stored under your account and shown on your public profile once confirmed.
- Reviews you write: stored and published under the policy in the terms of use.
- Session data: when you signed in and from which browser. Used to keep you signed in across tabs.
- Logs. IP address, request paths, response codes. Kept briefly for debugging and abuse prevention.
What we don't collect
- No passport scans and no ID uploads. Identity is verified by phone only.
- No browsing-history trackers. Home Sublet carries no advertising identifiers.
- No payment data: we don't process payments.
Who sees what
- Other people on Home Sublet see what you chose to show on your public profile, and anything you sent them in a conversation or as part of a booking.
- Home Sublet's operations team may read messages and profile content while handling a dispute. We say so in the decision summary.
- Third parties get almost nothing. The SMS provider sees the phone number and the code. The email provider sees the address, subject and content of what we send you. The hosting provider sees the raw requests. That's the whole list.
Your rights (Israeli privacy law, and in the spirit of the GDPR)
- See your data. Write to us and within 30 days we'll gather what we hold and send it in a human-readable format.
- Correct it. Most fields are editable straight from your profile. For anything else, write to us.
- Delete your account. We remove personal fields, messages you sent, your references and your bookings. Some data stays (review summaries for finished stays, audit logs), because hosts and the operations team need it to work safely.
- Get a copy. JSON export on request.
- Object to particular uses. Email us and we'll sort it out.
How long we keep things
Messages and booking data are kept for as long as your account exists. Audit logs are kept up to 3 years for operational purposes. SMS codes are hashed, single-use, and expire within 10 minutes. Session records are deleted when you sign out.
Get in touch
Any question about this policy: [email protected].