Makom
Privacy policy
Last updated: 13 September 2026
All Features
Makom
Last updated: 13 September 2026
This policy explains what personal information is collected when you use Makom or a studio app built on Makom, why it is collected, who it is shared with, how long it is kept, and the rights you have over it.
WitzLyne Ltd ("WitzLyne", "we", "us") operates the Makom platform. Makom runs as a family of apps and websites:
New studio apps are added over time. This policy applies to every one of them from the day it is released, whether or not it is listed anywhere here.
"Your studio" in this policy means the studio whose app you are using, or any studio whose classes, memberships or products you book or buy through the Makom marketplace app. Your studio is named inside the app, on its page on getmakom.com, and on every receipt and document it issues to you. You can be a member of more than one studio, and each of them is your studio for the part of your information that belongs to your relationship with it.
Two organisations are involved, and they are responsible for different things.
Your studio decides that it wants to know who its members are, who booked which class, who arrived, what each member bought and what health information it needs before letting someone train. In data protection terms the studio is an independent controller of the information that belongs to its own member relationship with you. Under the Israeli Protection of Privacy Law it is the controller of that database, the role that law calls בעל שליטה במאגר מידע. It sets its own class schedule, prices, cancellation rules, membership terms and health requirements. It is also the business you are paying.
WitzLyne builds and runs the software the studio uses. For most of your information we act as a processor for your studio: we hold and handle it on the studio's instructions so the studio can run its classes and serve its members. Israeli law calls that role the holder of the database, מחזיק במאגר מידע, and it carries its own duties of security and confidentiality that do not depend on what the studio asks of us.
We are an independent controller for a smaller set of things that are ours and not the studio's. That includes your platform account and sign-in credentials, the security and abuse-prevention records we keep across the whole platform, the diagnostic records we use to keep the service working, and the marketplace features that let you discover studios you are not yet a member of.
Where we act as processor and you want something done with information the studio controls, your studio is the right first contact. You can always write to us instead and we will pass the request to the studio and help it answer.
We collect only what the service needs. Not every item below applies to every member.
Your name, email address, phone number, date of birth, profile photo if you add one, your language preference, and an emergency contact name and relationship if you or your studio provide one. Your date of birth is used for age-restricted classes, for age-appropriate features, and to decide whether a profile belongs to a minor.
Your platform user identifier, your membership identifier at each studio, your sign-in method, and records of your sessions and sign-in attempts. If you sign in with Google or Apple, we receive the identifier and the basic profile details that provider returns. We never receive your password for those accounts.
The memberships, class packs, drop-ins, rentals and store products you buy, their prices, the credits and balances left on them, renewal and freeze history, payment attempts and their outcome, refunds, and the receipts, invoices and other tax documents issued to you. See section 5 for what we do and do not hold about your payment card.
Classes you book, waitlists you join, the position or spot assigned to you in a room, your arrival at the studio, check-ins made by scanning the studio's QR code or entered by staff at the desk, cancellations, late cancellations and no-shows, and the late passes or booking restrictions your studio's policy applies as a result.
Health declarations and any medical, injury, pregnancy or accessibility information you give your studio, and progress or performance figures where your studio uses them. This is treated as a special category of information and section 4 covers it separately.
Posts and replies on a class board, direct messages between you and your studio, form answers, reviews and feedback, and any report you file or member you block.
The push notification token your phone gives us, your notification and reminder preferences, the app version, operating system and device model needed to deliver a working build, and the crash and error diagnostics the app and our servers produce.
Request logs, IP addresses, rate-limit and abuse signals, and records of sensitive actions such as a password change, a device sign-out or an account deletion request. We keep these to protect your account, your studio and the platform.
No law obliges you to give us any of this. You give it because the service cannot be provided without it, and it is worth being plain about what happens if you decline. Without your name, your contact details and the health declaration your studio requires, the studio cannot register you as a member or let you book a class, and we cannot open an account for you. Other items are genuinely optional and cost you nothing to leave out: a profile photo, an emergency contact where your studio does not require one, your language preference, and every marketing preference. The app marks the optional fields as optional.
The member apps do not request your precise location, your contacts, your photo library, your microphone, Bluetooth, or the health data stored by Apple Health or Google Health Connect. The camera permission is used for one thing only: reading the studio's check-in QR code. The image is processed on your device to read the code and is not stored or uploaded.
There is no third-party advertising network in the member apps. We do not ask for an advertising identifier, we do not track you across other companies' apps or websites, and we do not sell your personal information or share it for cross-context behavioural advertising.
Studios on Makom are fitness, yoga, pilates and training businesses. Many of them require a health declaration before you may take a class, because physical exercise carries risk and the studio needs to know about conditions that affect what is safe for you.
Israeli law puts health information in its most protected category. The Protection of Privacy Law, as amended by Amendment 13, calls it data of especially sensitive nature, מידע בעל רגישות מיוחדת. Because we hold medical information, the platform's database falls at no lower than the medium security tier of the Privacy Protection (Data Security) Regulations, 5777-2017, and that is the tier we build and operate to. We handle health information accordingly:
Nothing in a Makom app is medical advice, a diagnosis or a treatment. The apps do not assess your fitness to exercise. Talk to a doctor before starting or changing an exercise programme.
Your studio, not WitzLyne, is the business selling you the class or the membership, and payments run through the studio's own merchant account with its own payment provider. Money for a studio's classes reaches that studio.
Full payment card numbers, expiry dates and security codes are entered on the payment provider's own secure page. They do not pass through the app and they are not stored on our servers. What we hold is what we need to show you and your studio what happened: the amount, the currency, the date, whether the charge succeeded or failed, the last digits and card brand, the provider's reference, and any refund or chargeback linked to it.
If you set up a recurring membership, the payment provider stores a token that lets the studio charge you again. We store the token reference, not the card.
The member apps are not directed at children. In Israel anyone under 18 is a minor, and the Legal Capacity and Guardianship Law, 5722-1962, leaves it to a parent or guardian to agree on a minor's behalf to anything beyond the everyday acts people of that age normally do alone. A membership contract, a recurring charge and a health declaration are not everyday acts. So an account of your own is for adults: you must be 18 to open one. Anyone under 18 uses the apps through a managed profile on a parent's or guardian's account.
Some studios run classes for children and teenagers. Where a studio does, a parent or legal guardian can hold the account and add a managed profile for each child. The child has their own bookings, their own credits and their own attendance record, while the account, the billing and the responsibility stay with the adult.
If you believe a child has given us information without a parent or guardian, write to isaac@getmakom.com and we will remove it.
A class board is a private space for the members of one studio. Posts are visible only to signed-in members of that studio, and never to the public or to members of another studio. Direct messages are between you and your studio.
You can report a post and you can block another member. A block hides that member's posts from you and hides yours from them. Reports go to your studio, which moderates its own board and can remove content and remove a member from it. We may also remove content and suspend accounts where content breaks the terms of use or the law.
A report and a block are records about both people involved, and we keep them so the block keeps working and so a pattern of behaviour can be acted on.
The purposes are the same for everyone. The legal ground for them is not, so both are set out.
The Protection of Privacy Law has no list of legal bases like the GDPR's. Processing rests on your informed consent, or on a specific authority in law such as the tax and accounting rules that make us keep financial records. Consent counts as informed only if you were told, before or at the moment you were asked, what this policy tells you: who is asking, why, whether you have to give it and what follows if you do not, who else receives it and why, and the rights you hold over it.
Israeli law has no equivalent of the GDPR's legitimate interests, so where a purpose below rests on that ground for a member in Europe, the Israeli ground for the same purpose is your consent, taken together with the duty section 17 of that law places on us to secure what we hold.
Israeli law is stricter than most about commercial messages. Section 30A of the Communications (Telecommunications and Broadcasts) Law, 5742-1982, requires your prior consent before a marketing message is sent to you by email, SMS, automated dialling or fax. Each message must say who sent it and must carry a simple way to stop the next one. Studio announcements and marketing are therefore off until you turn them on, and every one of them carries that opt-out. Where your studio runs a mailing list on the platform you may also write to the studio, or to us, and ask in writing to be removed from it.
Essential service messages about your account, a booking, a payment or a safety matter are not marketing, and are sent whatever your marketing preferences are.
We share personal information only in these situations.
We do not sell personal information and we do not share it for cross-context behavioural advertising.
The platform runs on cloud infrastructure that may store and process information outside Israel, including in the European Union and the United States. The European Commission reaffirmed on 15 January 2024 that Israel provides an adequate level of protection, so information can move from the European Economic Area to Israel without a further transfer mechanism. Information that reaches us from the European Economic Area carries extra duties on our side under the Privacy Protection Regulations (Provisions Regarding Data Transferred to Israel from the European Economic Area), 5783-2023, about its accuracy, how long it is kept and what you are told about it.
Sending information the other way, out of an Israeli database, has its own rule. The Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001, permit it only where the law of the receiving country, or a written undertaking from the recipient, holds the information to standards no weaker than Israeli law requires. Our contracts with providers outside Israel carry that undertaking.
Where information moves to a country without an adequacy decision, we rely on the European Commission's standard contractual clauses or another lawful transfer mechanism, together with the technical and organisational measures required for that transfer. You can ask us for details of the mechanism used for a given provider.
Access to member information is restricted by role, and a studio's data is isolated from every other studio's at the database level. Traffic is encrypted in transit and information is encrypted at rest. Sensitive actions require you to sign in again. We keep audit records of administrative access.
No system is perfectly secure. What the Privacy Protection (Data Security) Regulations, 5777-2017, call a severe security incident is reported to the Israeli Privacy Protection Authority immediately, along with what we did about it. The Authority may then direct that members who could be harmed be told, and we will tell you if it does. We will also tell you where any other law that applies to you requires it, including the seventy-two hour rule in Article 33 of the GDPR where the GDPR applies.
You can delete your account yourself. In the app, open Account & Data and choose to delete your account. If you cannot sign in, use the account deletion page.
Deletion starts a seven-day grace period, so an account is never lost to a mistaken tap or to someone with brief access to your phone. Signing in during those seven days cancels the deletion and nothing is lost. At the end of the grace period the account and the personal information attached to it are deleted or irreversibly anonymised, including your profile, bookings and attendance history, health declaration, messages and board posts, uploaded files and push tokens.
What survives, and why: financial and tax documents that the law requires to be kept; anonymised aggregate counts that can no longer identify you; and a minimal record of the deletion itself, so it can be proved that it happened. Where your studio holds its own separate copy of a record for its own legal duties, that copy is subject to the studio's retention obligations.
Depending on where you live, you have some or all of the following rights. We apply them to every member wherever we reasonably can.
The Protection of Privacy Law, 5741-1981, gives you the right to inspect the information held about you, and to demand that information which is incorrect, incomplete, unclear or out of date be corrected or deleted. If we refuse a correction we must tell you why, and you may ask a court to order it. If your details sit in a database used for direct mailing you may demand in writing to be taken out of it.
Amendment 13 to that law came into force on 14 August 2025. It widened what counts as personal information to include online identifiers, replaced the old category of sensitive information with the broader data of especially sensitive nature, expanded what must be told to you when information is collected, and turned the Privacy Protection Authority into a full enforcement body able to impose administrative fines, order processing to stop and open criminal investigations. A court may also award compensation of up to NIS 10,000 for certain breaches without your having to prove any damage.
You may complain to the Israeli Privacy Protection Authority (הרשות להגנת הפרטיות), part of the Ministry of Justice.
If the GDPR or the UK GDPR applies to you, you have the rights listed above under Articles 15 to 22, and the right to complain to the data protection authority in the country where you live or work. Our contact point for these requests is isaac@getmakom.com.
If you are a California resident, the California Consumer Privacy Act as amended gives you the right to know what personal information is collected about you and the categories of source, purpose and recipient; to obtain a copy of it; to have it corrected; to have it deleted; to limit the use of sensitive personal information; and to not be discriminated against for exercising any of these rights.
In the twelve months before this policy was published, we collected the categories described in section 3, for the purposes in section 8, and disclosed them for a business purpose only to the recipients in section 9. We have not sold personal information and have not shared it for cross-context behavioural advertising, including that of anyone under 16. The only sensitive personal information we handle is health information, and it is used solely to provide the service you asked for.
Start in the app: Account & Data holds your export, your deletion control and your privacy settings, and the profile screen lets you correct most of your details.
Otherwise, write to isaac@getmakom.com from the email address on your account, or from the phone number on it, and say what you want. We may ask for reasonable proof of identity before acting, and we will not act on a request that we cannot connect to the account it concerns. Never send us a password, a one-time code or a full card number.
We answer without undue delay and within the period the applicable law sets. There is no charge unless a request is manifestly unfounded or excessive, and we will say so before doing anything that would carry one. If your request concerns information your studio controls, we will tell you and pass it to the studio.
We update this policy when the service changes or the law does. The current version is always published here, with the date at the top. If a change materially affects your rights or how your information is used, we will tell you in the app or by email before it takes effect.
WitzLyne Ltd, 6 Vilna Street, Tel Aviv-Yafo, Israel, company number 517400826. Address for service in Israel: 6 Vilna Street, Tel Aviv-Yafo, Israel.
Privacy questions and requests: isaac@getmakom.com. Our privacy contact is the privacy inbox at isaac@getmakom.com.
For a question about your membership, a class, a charge or a health declaration, your studio is the fastest answer. Its contact details are in the app and on its page on getmakom.com.