PRIVACY POLICY

22 September 2026

This Policy explains what personal data we collect when providing the money transfer service, why we need it, whom we share it with and what rights you have.

1. Who we are

1.1. The moneysend.co.il money transfer service is provided by Albercom Ltd, company no. 51-232918-6, address: 3 Daniel Frisch St., Tel Aviv (hereinafter — the “Company”, “we”). The Company holds an extended financial asset service provider licence no. 62711.

1.2. For any questions about the processing of your data you may write to [email protected] or call 03-5103301.

1.3. This Policy applies to the Website, the mobile application and communications with customer support. It also applies where the Sender has started arranging a Transaction but has not completed it.

1.4. Terms capitalised in this Policy (Sender, Recipient, Transaction, Website and others) have the same meaning as in the Terms of Use. If any term differs between the two documents, the meaning given in the Terms prevails.

2. What data we collect

2.1. Sender’s data — first and last name, Israeli identity card number, phone number, email address. For certain destinations and payout methods we may additionally require date of birth, address and identity document expiry date, where this is required by the rules of the payment system or the payout partner.

2.2. Recipient’s data provided by the Sender: name, card or account number, phone number, and any other details required by the law of the payout country (for example, the Chinese national identity card number for transfers to China).

2.3. Payment data. The Sender’s payment card data is processed by a PCI DSS certified payment service provider.

2.4. Transaction data. Amount, currency, date and time, payout country and method, transfer status, and the purpose of the transfer.

2.5. Identification documents. Copies of identity documents and other information the Company requests when checking a Transaction or handling an enquiry.

2.6. Enquiries to customer support and correspondence with it, including via messengers.

2.7. Technical data. IP address, device and browser type, operating system, the pages of the Website visited and actions taken on them, server log data.

3. Where we obtain data

3.1. From the Sender — when arranging a Transaction and when contacting support.

3.2. Automatically — when the Website is used (section 10).

3.3. From third parties — from official sanctions lists and registers that we download and screen against, and from Payout Institutions and the card issuer — to the extent necessary to execute the transfer and comply with the law.

3.4. By providing the Recipient’s data, the Sender confirms that they are entitled to share it and that the Recipient has been informed accordingly.

4. Why we process data and on what basis

4.1. By registering for the Service and accepting the Terms of Use, you give your explicit informed consent to the collection and processing of your data for the purposes set out below. Where applicable, processing also relies on statutory requirements or our legitimate business interests:

  • Executing the Transaction and supporting the customer — performance of the contract with the Sender.
  • Customer identification, sanctions screening and regulatory reporting — requirements of anti-money laundering and counter-terrorist financing legislation and the conditions of our licence.
  • Fraud prevention, handling of disputes and chargebacks — protecting the security of our customers, statutory requirements.
  • Operation and security of the Website, analytics in aggregated form — the Company’s legitimate interest.
  • Analytics and marketing measurement — assessing Website traffic and advertising effectiveness — the Company’s legitimate interest.

4.2. Providing data is not a statutory obligation, but without the data listed in clauses 2.1–2.5 we cannot execute the transfer.

4.3. Decisions to decline or suspend a Transaction may be taken by automated anti-fraud checks. The Sender is entitled to contact customer support so that the decision is reviewed by a member of the Company’s staff.

4.4. We do not sell personal data to third parties.

5. Whom we share data with

5.1. Sharing data is a necessary part of a transfer: the payout is made not by the Company but by partner institutions in the Recipient’s country. We share only the data needed for the specific purpose:

  • Payout Institutions and international transfer systems, payment systems (including Visa and UnionPay), banks and financial companies — execution of the transfer and payout to the Recipient.
  • The payment service provider and the card issuer — accepting payment, refunds and disputes.
  • IT infrastructure providers (hosting, cloud services, protection against attacks), as well as telecom operators and SMS providers — operation of the Service; the phone number is shared in order to deliver the one-time code and the transfer Reference Number.
  • The Company’s auditors, accountants and lawyers — compliance with the law and protection of rights.
  • Government authorities of Israel and of the payout country — in the cases provided for by law or upon a court order.

5.2. In the event of a reorganisation or sale of the business, data may pass to an acquiring third party or to an entity stepping into the Company’s shoes, provided that it assumes obligations no lower than those set out in this Policy.

6. Transfers of data abroad

6.1. A transfer abroad is impossible without sharing data — at a minimum, with the Recipient’s country. By arranging a Transaction, the Sender gives their explicit consent to the sharing of their own data and the Recipient’s data with the payout country, as well as with international payment and money transfer systems (Visa Direct, RIA and others), whose infrastructure may be located in third countries.

6.2. In some countries the level of data protection is lower than in Israel. We share with them only the minimum needed for the payout and required by local law.

6.3. Some of the service providers we use to operate the Website are located outside Israel. To send SMS and WhatsApp messages containing the one-time code and the transfer Reference Number we use Twilio Inc. (USA) — only the phone number and the message text are shared with it. Data is stored and processed in the Microsoft Azure cloud infrastructure in the Israel Central region, that is, within the territory of Israel. To protect the Website against attacks and bots we use Cloudflare, Inc. (USA), through whose network the Website’s traffic passes, including the visitor’s IP address.

7. How long we keep data

7.1. Transaction data, scans of documents and correspondence with customers are kept for 7 years from the date of the Transaction — this is required by anti-money laundering legislation.

7.2. Data relating to uncompleted and declined Transactions is kept on the same grounds: it is needed for fraud prevention and regulatory reporting.

7.3. Once the retention period expires, data is deleted or anonymised.

8. How we protect data

8.1. We apply technical and organisational security measures in accordance with the Protection of Privacy Regulations (Data Security), 2017, as well as the international PCI DSS standard.

8.2. No system is absolutely secure. We notify affected individuals and the competent authorities of security incidents in the manner prescribed by law.

8.3. One-time codes sent via WhatsApp and SMS, the Reference Number and card details must not be disclosed to third parties. The Company never requests them in its own outgoing communications. If you suspect that a one-time password or transfer details have become known to outsiders, you must notify us immediately.

9. Your rights

9.1. Under the Israeli Protection of Privacy Law (חוק הגנת הפרטיות, התשמ״א-1981) you have the right to:

  • obtain access to the data about you held in our databases;
  • request correction of data that is inaccurate, incomplete or out of date;
  • request deletion of data — to the extent that we are not required to retain it by law (see section 7);
  • withdraw consent to marketing communications at any time;
  • request human review of a decision taken by automated means (see clause 4.3);
  • lodge a complaint with the Privacy Protection Authority (הרשות להגנת הפרטיות) at the Israeli Ministry of Justice.

9.2. Please send your request to [email protected] from the email address or phone number provided at registration. We may request additional proof of identity — this protects you against disclosure of your data to an outsider.

9.3. We respond to requests within the period prescribed by law. If we refuse a request, we state the reason for the refusal.

9.4. Contacting us is free of charge, except in the cases where the law permits a fee to be charged for providing a copy of the data.

10. Cookies and analytics

10.1. Cookies and similar technologies are used only on the Website; they are not used in the mobile application. We divide them into three groups:

  • Essential — operation of the Website and session persistence. These cannot be disabled: without them the Website does not work.
  • Analytics — Google Analytics 4, Google Tag Manager: how people use the Website and where errors occur. These can be disabled in your browser settings or with the Google Analytics Opt-out browser add-on (see clause 10.2).
  • Advertising — measuring advertising effectiveness and displaying advertising on third-party platforms. These can be disabled in your browser settings or in the advertising settings of the relevant services (see clause 10.2).

10.2. Analytics and advertising cookies are set when you visit the Website. You can refuse them in your browser settings — by blocking third-party cookies or deleting those already stored — and by means of the services themselves (for example, the Google Analytics Opt-out browser add-on and the advertising settings in your Meta account).

10.3. Browser settings allow cookies to be blocked entirely, but the transfer form may then not work correctly.

10.4. The analytics and advertising services we use may collect data independently and under their own rules. Google’s policy — policies.google.com/privacy.

11. Marketing communications

11.1. As at the date of this version we do not send marketing communications. Should we decide to send them in the future, this will be done solely subject to obtaining your prior explicit consent (opt-in), as required by section 30A of the Communications Law. In any event, you will be able to withdraw your consent and unsubscribe at any time: via the link in the email, by replying to the message or by writing to [email protected]. Opting out of marketing does not affect service messages — transfer confirmations, status notifications and verification codes.

12. Changes to this Policy

12.1. We may amend this Policy — for example, following changes in legislation or the addition of new destinations or providers.

12.2. The version in force is always published on this page together with the date of update.

13. How to contact us

Albercom Ltd, company no. 51-232918-6

3 Daniel Frisch St., Tel Aviv, Israel

Email: [email protected]

For any questions about the processing of personal data, and to exercise the rights set out in section 9, please write to [email protected] marking your message “Personal data”.