Privacy Policy

Effective 24 May 2026 · Last updated 24 May 2026

1. Who we are

CandyTask is a pre-launch productivity application operated by Maxim Shubin, based in Tel Aviv, Israel. You can reach us anytime at hello@candytask.com.

2. Scope

This Policy covers our marketing website at candytask.com and the waitlist sign-up. The CandyTask app itself is not yet released. When it launches, we will publish a separate, expanded policy and notify waitlist subscribers before any new data is collected.

3. What we collect

The only personal data we actively collect today is your email address, which you submit through the waitlist form.

We also receive limited technical data automatically — approximate country, device type, browser, referrer and pages visited. This is used only in aggregated, non-identifiable form to understand site usage.

4. Why we collect it, and our legal basis

We process your email based on your explicit consent (Section 11 of Israel's Protection of Privacy Law, 5741-1981, as amended by Amendment 13; and Art. 6(1)(a) GDPR where applicable). We use it to:

  • send you updates about the CandyTask launch and early-access invitations;
  • send transactional messages (confirmation of signup, account notifications).

5. Service providers we use

To run this site and the waitlist we rely on:

  • Lovable (lovable.dev) — website hosting, builder, and privacy-friendly aggregated usage statistics;
  • Supabase — the database where your email is stored;
  • Resend (resend.com) — sending you emails;
  • Cloudflare — content delivery and security for the site;
  • Google Fonts — serves the site's typefaces; loading them may set a Google cookie and transmits your IP address to Google;
  • Namecheap — domain registration and DNS.

6. International data transfers

Some of these providers store or process data outside Israel, primarily in the EU and the US. Where data leaves Israel, we rely on adequacy decisions, the EU Standard Contractual Clauses (SCCs), or equivalent safeguards required by Amendment 13.

7. How long we keep your data

We keep your email until the earlier of:

  • you ask us to delete it or unsubscribe; or
  • 24 months pass with no interaction from you, after which we delete it automatically.

8. Security

Your data is transmitted over HTTPS/TLS and stored encrypted at rest in our providers' systems. Our database tier is operated in line with Israel's Privacy Protection (Data Security) Regulations, 5777-2017, to the extent applicable. If a personal-data breach occurs that is likely to affect you, we will notify you and the Israeli Privacy Protection Authority without undue delay.

9. Your rights

You have the right to:

  • access the personal data we hold about you;
  • correct inaccurate data;
  • delete your data (“right to be forgotten”);
  • restrict or object to our use of your data;
  • withdraw your consent at any time (without affecting the lawfulness of processing already done);
  • receive a copy of your data in a portable format;
  • lodge a complaint with the Israeli Privacy Protection Authority (www.gov.il), or your local supervisory authority if you reside in the EU/UK.

To exercise any right, email hello@candytask.com. We will respond within 30 days.

10. Marketing emails and unsubscribe

Every marketing email we send includes a clear sender identification and a one-click unsubscribe link. Where Israel's “Spam Law” (Amendment 40 to the Communications Law, 5742-1982) applies, we mark promotional subjects accordingly and provide a Hebrew unsubscribe option.

11. Children

CandyTask is not intended for users under 16. We do not knowingly collect personal data from children. If you believe a minor has signed up, contact us and we will delete the data.

12. Cookies and similar technologies

This site uses only a small number of cookies — all of them either strictly necessary or for privacy-friendly, aggregated statistics:

  • security and load-balancing cookies set by our CDN (Cloudflare, e.g. __cf_bm);
  • a deployment cookie and a session cookie required for the site to function.

We use privacy-friendly, aggregated usage analytics provided by our hosting platform; these do not identify you individually and are never used for advertising. We also load web fonts from Google Fonts, which may set a Google cookie and transmit your IP address to Google. We do not use advertising or cross-site marketing cookies.

13. Changes to this Policy

We may update this Policy as the product evolves. For material changes, we will email everyone on the waitlist before the change takes effect. The “Last updated” date above always reflects the most recent revision.

14. Contact

Questions, requests or complaints — email hello@candytask.com. Operator: Maxim Shubin, Tel Aviv, Israel.