Data & Privacy Policy
Version: 2.5 |
Last Updated: August 2026
Entity: Aaron Belkar ("BE" / "Belkar Business Engineering")
At Belkar Engineering, we enforce strict data sovereignty and security engineering. This policy explains how we process personal data, authenticate user sessions, manage cross-domain cookies across *.aaronbelkar.com, utilize Supabase databases, deploy AI operational tools, process third-party payments, and evaluate analytics.
1. Data Collection & Authentication
We collect and process minimal data strictly necessary for client engagements, system access, and automated tool operations:
- User Authentication & Profiles: When you register or sign in (via Supabase Auth), we store your email address, name, encrypted credentials, and token ledger balance.
- Operational Diagnostics & Tool Inputs: Data entered into our diagnostic benchmarks (AiQ, Operational Audit, RFQ Normalizer, Inventory Analyzer) is processed to compute friction scores, normalize datasets, and render custom outputs.
- Payment & Transaction Records: When purchasing token packages, transaction metadata (payment provider reference, transaction IDs, token pack size, and amounts) is recorded to maintain immutable accounting ledgers.
2. Cookies & Cross-Domain Session Architecture
We implement functional and analytical cookies under strict privacy parameters:
- Single Sign-On (SSO) Cookies: We utilize secure cross-subdomain cookies scoped to
.aaronbelkar.com (with SameSite=Lax and Secure flags) so authenticated users can seamlessly access all engineering tools across all *.aaronbelkar.com subdomains without repeated logins.
- Google Analytics Cookies: We use Google tag (gtag.js / G-C548GV8P38) to analyze anonymous aggregated visitor interaction metrics. You can opt out or disable analytics cookies in your browser settings at any time without affecting application performance.
- {{{privacy.sec2_item3}}}
3. Infrastructure, Databases & AI Tool Processing
To provide high-availability systems, we work with enterprise-grade data processors adhering to strict security protocols:
- Database & Authentication Infrastructure (Supabase): User accounts, token balances, and immutable transaction ledgers are managed on isolated Supabase cloud databases with Row-Level Security (RLS) policies.
- Third-Party Payment Gateways: Payments are processed via PCI-DSS Level 1 compliant third-party payment providers (such as Stripe / Meshulam / Tranzila). Belkar Engineering never stores or transmits raw credit card numbers on our servers.
- AI Models & Privacy Guardrails: Operational tools utilizing Artificial Intelligence (e.g. LLM extraction, invoice parsing, RFQ normalization) process operational text solely for user-requested execution. Your proprietary business data is never used to train public AI foundation models.
4. Your Privacy Rights & Data Sovereignty
- No Data Brokering: We will never sell, rent, or trade your personal or business data to third-party advertisers or data brokers.
- Right of Erasure & Export: You hold the right to request a full export or permanent deletion of your profile and operational history. Contact us at aaron@aaronbelkar.com to initiate a data wipe.
- {{{privacy.sec4_item3}}}
5. Regulatory Compliance
This policy complies with:
- The Israeli Privacy Protection Law, 5741-1981 and Amendment 13 regulations
- EU General Data Protection Regulation (GDPR)
- CAN-SPAM Act & International Data Transfer Standards
6. Contact Information
For all data-related inquiries, audits, or privacy requests:
Data Controller: Aaron Belkar
Email: aaron@aaronbelkar.com
Phone/WhatsApp: +972 54-5858486
Location: Tel Aviv, Israel
This policy is updated periodically to match evolving AI security guardrails and legal requirements.
← RETURN TO SOVEREIGN ROOT