The short version
- You can browse the map, places, zmanim and events without an account.
- If you sign up, we keep your email and a verified US phone number. The phone number is stored only as a one-way code plus its last two digits.
- Your location is used to show what is near you. Only an approximate area (about 100 meters) is sent to our servers, and it is not saved to your account.
- We do not sell your data, and we do not use your personal data to target ads.
- The app has no analytics or advertising trackers.
- You can delete your account in the app at any time, or ask us by email.
Who we are
Kehila Local ("we", "us") runs the Kehila Local mobile app, the website kehilalocal.com, and Kehila Local for Places, the part of the app where the people who run a place manage its listing. This policy covers all three. Questions about it go to support@kehilalocal.com.
What we collect
If you only browse
The app works without an account. To show you places, it asks our servers for the places in the area you are looking at (see Location). Like any web service, our hosting provider records basic request details, such as the time, the address requested and your network (IP) address, in short-lived server logs.
This website sets no cookies and has no analytics. Its fonts are served from this site, not from a third party.
Your account
- Email address. Used to sign in, either with a six-digit code we email you or with a password. Passwords are stored only as a scrypt hash. Sign-in codes are stored only as a hash and expire after 10 minutes.
- Name and city, if you add them. Your name appears on reviews you write as your first name and last initial, for example "Sara K."
- Google sign-in, if you use it. We receive the email address and name on your Google account, through Firebase Authentication. We keep the Firebase user ID that goes with your account, only so that deleting your account also deletes your Firebase sign-in record. See Google user data.
Your phone number (for verification only)
Members verify a US mobile number once, by a text-message code. This keeps the directory for real people and makes it hard for one person to open many accounts.
- The code is sent and checked by Google's Firebase Authentication. Firebase keeps a sign-in record of the verified number as part of that service. When you delete your account, we delete that record too.
- Our own database never stores the number itself. It stores a keyed one-way hash (a code that can't be turned back into the number without our server's secret key) and the last two digits, so the app can show you "ending 47".
- The number is never shown to other people, and there is no way to search or list members.
- To stop abuse, we keep a short record of each verification attempt: the hashed number, a hashed network address, and the time.
Your preferences and saved places
- Preferences: your nusach, the hechsherim and kashrus standards you follow, and your home community. These fill in your member card and help the app show what fits you.
- Settings, such as whether you want event reminders.
- Saved places, kept on your account so they follow you to another phone.
What you contribute
- Reviews (a star rating and text), shown in the app with your first name and last initial. Other members can mark a review helpful or report it.
- Updates and reports: suggested changes to times, hours and details, photos, answers to "Is it still open?", and reports of problems. These are stored with your account so our team can check them. Other people see only the result, never who sent it.
- Points and badges you earn for accepted contributions. The community leaderboard is opt-in and shows only your initials.
Tickets and events
- When you buy tickets we keep the order: your name and email, the names on the tickets, seats, amounts, and the last four digits of the card. Card numbers are entered into and processed by Stripe and never reach our servers. Payments currently run in Stripe's test mode only; no real charges are made.
- The event's organiser sees the names on the tickets, so they can check guests in. Shabbos and Yom Tov events use a door list instead of phones.
- If you host an event, we keep its details, the poster you choose and the messages you send to your guests.
Crash reports
If the app crashes, it sends us a report with the error message, the technical stack trace, the app version and build, and the phone's platform and system version. Reports carry no account, device ID or network address, and email addresses and long numbers are masked out before they are stored.
Device permissions
- Camera: only to scan tickets when you check guests in to an event you host.
- Photos: only the picture you choose, for example an event poster.
- Notifications: reminders are scheduled on your phone. We do not collect a push-notification token.
Location
If you allow it, the app uses your phone's location while the app is open, to show nearby places and work out zmanim. It never uses location in the background. If you would rather not share it, you can choose a community by hand and everything still works.
- What is sent to our server: to fetch nearby places, zmanim, events, area listings and local sponsor notices, the app sends the point or map area you are looking at, which may be your current position. Before anything leaves your phone, the app rounds these coordinates to three decimal places, which is about 110 meters (roughly a city block), so our server never receives your exact position. That precision is enough for nearby lists and zmanim.
- What stays on your phone: your exact position is used only on your device, to draw the map and your location dot and to sort places by distance.
- What is not kept: we do not save your location to your account, and we do not keep a history of where you have been. Like other request details, coordinates can appear in our hosting provider's short-lived server logs.
- On your phone: the app remembers your last area on your device so it opens there next time.
Place owners (Kehila Local for Places)
If you claim a shul, restaurant, school or other place, we collect what we need to confirm you really represent it and to keep a record of changes:
- Your claim: the place, your role, and how you verified: a code sent to the phone number on the listing, a code or link sent to an email address at the place's own website domain, a person you name who can confirm your role, approval from someone who already manages the place, or a document.
- Claim documents (such as a letter on letterhead, a licence or a utility bill) are seen only by Kehila Local staff reviewing the claim. The file is deleted 30 days after we decide on the claim. We keep a small record that a document was received (its name, type, size and a fingerprint) so the decision can be audited.
- Changes you make to a listing are kept in a history for the place, with who made them, for 7 years.
- Place statistics: owners see counts of how often their listing was viewed, called or opened for directions, and the search words people used to find it. These counts are not linked to any person.
Google user data
Google Business Profile
A place owner can choose to prove ownership by connecting the Google Business Profile that manages the place. If you do:
- We ask Google for the
https://www.googleapis.com/auth/business.managepermission, which is the permission Google requires for any access to Business Profile data. We use it only to read: the list of business locations your Google account manages, and each location's name, address, phone number, website and Google verification status. - We use that information only to check that the place you are claiming is one your Google account manages. We never create, change, post to or delete anything in your Business Profile.
- Google's access token is used once, for that check, and then discarded. We do not store it and we do not keep ongoing access to your account.
- We keep only the result of the check with your claim: that ownership was confirmed through Google, when, and which listing it matched.
- You can also remove Kehila Local's access at any time in your Google Account under Security, "Your connections to third-party apps and services".
Google sign-in
If you sign in with Google, we receive your Google account's email address and name, and use them only to create and sign in to your Kehila Local account.
Limited Use
Kehila Local's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, information from Google APIs is used only to provide the features described above. It is never sold, never used for advertising, never used to build a profile of you, and never used to train AI or machine-learning models. It is not transferred to anyone else except as needed to provide those features, to comply with the law, or as part of a merger or sale of the service with the same protections. People at Kehila Local do not read it, except the result of an ownership check when reviewing your claim, when you ask us to help, for security, or where the law requires.
How we use information
- To run the directory and your account: show places, save your places and preferences, sell and check tickets.
- To keep the directory accurate: check contributions and claims before they go live.
- To keep the community safe: verify members, limit how fast codes can be requested, and stop fake accounts, spam and abuse.
- To email you about your account, your claims, tickets you bought and events you are part of.
- To fix problems, using crash reports and server logs.
Kehila Local's Shabbos and Yom Tov rule applies to our systems too: ticket sales, reminders and messages are paused over Shabbos and Yom Tov.
Sponsored listings
Some screens can show a sponsored listing, always labelled "Sponsored". Which one appears depends only on the screen, the area being viewed and the kind of place, never on who you are or what you have done in the app. Sponsors never change the order of real results. We count how often a sponsored listing is shown or tapped, without recording who saw it.
Who we share information with
We do not sell personal information, and we do not share it for advertising. We share it only with the service providers that run Kehila Local for us, under their own security and privacy terms, and only as far as each one needs:
| Provider | What it does for us |
|---|---|
| Google Cloud and Firebase | Hosts our servers, database and this website (United States); Firebase Authentication sends and checks text-message codes and handles Google sign-in. |
| Cloudflare | Runs our domain's DNS and forwards email sent to our kehilalocal.com addresses. |
| Stripe | Takes card payments for tickets (test mode for now). Stripe receives your card details directly. |
| Gmail (Google) | Sends our outgoing email, such as sign-in codes. |
| Apple Maps and Google Maps | Draw the map in the app (Apple Maps on iPhone, Google Maps on Android). They receive the map area you view. |
We also share information:
- with an event's organiser, as described under Tickets and events;
- publicly, when you choose to publish it, such as a review;
- if the law requires it, or to protect the safety of our members and the community;
- with a buyer if the service is ever sold, under this policy.
Community safety and the data we publish
- Private mikvahs: the location of a private mikvah is never published in the app or on this site.
- Reviews from other sites: to keep listings accurate we may look at public ratings and reviews of places on other websites. That information is for our internal use only. It is never displayed in the app and never shared.
- There is no public list of members, and the app has no way to look up a member by phone number or email.
Security
The directory is information about a community that has real enemies, and we treat security seriously. All connections to the app and this site use HTTPS. Passwords, sign-in codes and phone numbers are stored only as hashes. Our database runs on Google Cloud, which encrypts stored data. Only a small number of staff can reach the admin tools, and changes made there are logged. No system is perfectly secure, and we will tell affected members promptly if their information is ever exposed.
How long we keep information
| Information | Kept for |
|---|---|
| Account, preferences, saved places, points | Until you delete your account. |
| Sign-in and phone codes | Expire after 10 minutes. |
| Claim documents | The file is deleted 30 days after the claim is decided. |
| Listing change history | 7 years. |
| Ticket orders: buyer name, email and ticket holder names | Cleared 90 days after the event. |
| Ticket orders: amounts, date, card last 4 digits, refunds | 7 years, for accounting, then deleted. |
| Security log of sign-ins and verification attempts | 180 days. |
| Crash reports | Only the most recent 2,000 reports are kept. |
| Server request logs | Deleted automatically by our hosting provider, normally within 30 days. |
| Database backups | 7 days, then replaced. |
Deleting your account
In the app, go to Profile → Account → Delete account. You can also email support@kehilalocal.com from the address on your account; see Delete your account. When you delete your account:
- your email, name, city and password are removed, and you are signed out everywhere;
- your phone verification, preferences, settings, saved places, points and badges are deleted;
- your reviews are taken down;
- updates you sent that were already accepted stay in the directory, without your name or email;
- your Firebase Authentication sign-in record (your verified phone number, and your Google email if you used Google sign-in) is deleted too. If Firebase can't be reached at that moment, we retry automatically every day until it is gone;
- ticket orders stay as business records for the periods above, and our security log of sign-ins keeps its entries for up to 180 days;
- copies in database backups disappear within 7 days.
Your choices
- You can use the app without an account, and without sharing your location.
- You can see and change your name, preferences and settings in the app.
- You can ask us for a copy of the information we hold about you, ask us to correct it, or ask us to delete it, by emailing support@kehilalocal.com. We answer every request, wherever in the United States you live. We may need to confirm the request comes from you.
Children
Kehila Local is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has given us personal information, email us and we will delete it.
United States only
Kehila Local is offered in the United States, and phone verification accepts US numbers only. Our servers are in the United States.
Changes and contact
If we change this policy, we will update the date at the top and, for important changes, tell members in the app or by email before the change takes effect.
Questions, requests or concerns: support@kehilalocal.com.