Legal
Privacy Policy
Last updated: August 31, 2026
1. Who we are
StemMap ("StemMap", "we", "us", "our") is operated by Shay Ben Tolila, Osek Patur, business registration number 026487967, of Snir 39, Pardes Hanna-Karkur, Israel.
The service is provided at https://stem-map.com (the "Service").
Privacy enquiries: shaybento@mmpguru.com
2. What this policy covers
This policy explains what personal information we collect, why, how we use it, who we share it with, and the rights you have. It applies to visitors to our website and to registered account holders.
It is an integral part of our Terms of Service.
3. The most important thing to understand: our two different roles
StemMap handles two very different categories of information, and our legal responsibility differs between them. Please read this section carefully.
3.1 Your account information — we are the controller
For information about you, the practitioner or visitor — your email address, clinic name, plan, payment records — we are the data controller. We decide why and how it is processed, and this policy governs it.
3.2 Your patients' information — we are only the processor
If you save a patient record, you provide us with information about a third party who is not our user: their name, their date of birth, and any clinical notes you write.
For that information:
- You are the data controller. It is your patient, your clinical relationship, and your professional and legal duty.
- We are the data processor. We store and display that information on your instructions and for no other purpose.
This means you are responsible for:
- having a lawful basis to collect and store your patients' information;
- informing your patients that you use third-party software to hold their records;
- obtaining any consent your professional body, or the law in your country, requires;
- the accuracy of what you enter;
- responding to your patients if they ask to see, correct or delete their records.
We will never use patient information to contact patients, market to anyone, train models, sell to third parties, or for any purpose other than providing the Service to you.
If you are subject to the GDPR, the UK GDPR, HIPAA, or an equivalent regime, you may need a written data processing agreement with us. Contact us at shaybento@mmpguru.com and we will provide one.
4. Information we collect
4.1 Information you give us when you create an account
| What | Why |
|---|---|
| Email address | To identify your account, sign you in, and send service messages |
| Password | To secure your account. Stored hashed — we never see or store it in readable form |
| Google account identifier (if you sign in with Google) | To authenticate you without a separate password |
| Clinic or practice name (optional) | To brand your printed maps and PDF exports |
| Clinic logo (optional) | Same |
| Language preference | To display the Service in your language |
4.2 Information about your subscription
Plan type, plan start and expiry dates, an identifier from our payment provider, order references, and your record of past payments.
We do not receive, see or store your card number, CVV or expiry date. Card details are entered directly on our payment provider's systems (see §6).
4.3 Patient records you create — you are the controller
If you use the patient library, we store on your behalf: patient name, date of birth, the map identifier resolved from that date, your clinical notes, visit dates, visit notes, and any adjustments you make to the map layout.
A note on sensitivity. A patient's name and date of birth, recorded in a clinical context alongside treatment notes, may constitute health-related or "especially sensitive" personal information under the Israeli Protection of Privacy Law (as amended by Amendment No. 13), and special category data under Article 9 of the GDPR. We treat it accordingly. You should too.
You do not have to use the patient library at all. You can build maps without saving anything.
4.4 Information you give us when you contact us
If you use a contact or enquiry form, we store your name, email address, your message, and which form you used.
4.5 Information collected automatically
When you use the Service we and our infrastructure providers may collect: IP address, browser type and version, device type, operating system, pages viewed, referring page, and timestamps.
Under Amendment No. 13 to the Israeli Protection of Privacy Law, and under the GDPR, IP addresses and similar online identifiers are treated as personal information.
4.6 What we do not collect
We do not collect: your card details, your national identity number, your patients' contact details, biometric data, genetic data, or location data beyond what an IP address implies. We do not use tracking pixels or advertising cookies. We do not buy personal information from third parties.
5. Why we process your information, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and running your account | Performance of a contract |
| Providing the map calculator and patient library | Performance of a contract |
| Taking payment and managing your subscription | Performance of a contract |
| Sending service messages (receipts, expiry notices, security alerts) | Performance of a contract |
| Keeping the Service secure and preventing abuse | Legitimate interests |
| Diagnosing faults and improving the Service | Legitimate interests |
| Meeting accounting, tax and legal obligations | Legal obligation |
| Sending marketing emails | Consent — and you may withdraw it at any time |
We do not use your information for automated decision-making that produces legal or similarly significant effects.
6. Who we share information with
We do not sell personal information. We do not share it for anyone else's marketing.
We use the following service providers, who process information on our behalf under contract:
| Provider | What they do | What they receive |
|---|---|---|
| Base44 | Hosting, database, authentication | All Service data, including account and patient records |
| Allpay (allpay.co.il) | Payment processing | Your name, email, and payment details, which you enter directly on their systems |
| Optional "Sign in with Google" | Your email address and Google account identifier, only if you choose this option |
We may also disclose information where we are legally required to: in response to a binding court order or lawful request from a competent authority; to establish, exercise or defend legal claims; or to prevent harm or investigate suspected fraud or abuse.
If StemMap is sold, merged or transferred, information may transfer with it. Any acquirer will be bound by commitments no less protective than these, and we will notify you in advance where the law requires.
7. International transfers
We are based in Israel. Our providers may store or process information outside Israel and outside your country, including in the European Union and the United States.
Where we transfer personal information out of Israel we do so in accordance with the Protection of Privacy Regulations (Transfer of Data to Databases Outside the State Borders), 5761-2001. Where we transfer personal information out of the European Economic Area or the United Kingdom, we rely on an adequacy decision where one applies, or on Standard Contractual Clauses.
Israel benefits from a European Commission adequacy decision, which permits transfers from the EEA to Israel without additional safeguards.
8. Cookies and similar technologies
We use the minimum necessary.
Strictly necessary — required for the Service to work. These keep you signed in, protect against fraud and abuse, and remember your cookie choices. They cannot be switched off, and we do not ask consent for them.
Preferences — remember choices such as your language.
Analytics — if and when we enable analytics, it will be used only to understand how the Service is used so we can improve it. We will ask for your consent first where the law requires it.
We do not use advertising or marketing cookies, and we do not allow third parties to track you across other websites.
You can control cookies through your browser settings, but disabling strictly necessary cookies will prevent you from signing in.
9. How we protect your information
We maintain security measures appropriate to the sensitivity of the information, including: encryption in transit (HTTPS/TLS); hashed passwords; access controls so each account can reach only its own records; row-level database rules preventing one practitioner from reading another's patients; server-side permission checks rather than checks in the browser; and restricted administrative access.
We act in accordance with the Protection of Privacy Regulations (Data Security), 5777-2017.
We must be honest with you: no system is completely secure. These measures substantially reduce risk but cannot eliminate it, and we do not warrant that the Service will be immune to unauthorised access. You must keep your password confidential and tell us promptly if you suspect your account has been compromised.
10. Data breaches
If a security incident occurs that is likely to result in a risk to your rights, we will notify the Israeli Privacy Protection Authority and affected individuals as required by law and within the timeframes the law sets.
Where the incident affects patient records, we will notify you without undue delay so that you, as the controller of that information, can meet your own notification obligations.
11. How long we keep information
| What | How long |
|---|---|
| Account information | While your account is open, then up to 12 months after closure |
| Patient records | While your account is open. Deleted when you delete them, or on account closure |
| Payment and invoice records | 7 years, as Israeli tax law requires |
| Contact and enquiry messages | Up to 24 months |
| Server logs | Up to 12 months |
If you downgrade from a paid plan to the free plan, your patient records are not deleted. You keep access to what you have already saved.
You may delete individual patient records at any time, and deletion is permanent. Backups may retain deleted information for a short period before being overwritten.
12. Your rights
Depending on where you live, you may have the right to: access the information we hold about you; correct it; delete it; restrict or object to processing; receive it in a portable format; withdraw consent; and object to direct marketing at any time.
Under Israeli law, the Protection of Privacy Law, 5741-1981 (including Amendment No. 13) gives you rights of access and correction, and the right to demand removal of your information from a direct-mailing database.
Under the GDPR and UK GDPR, you have the rights in Articles 15–22, and the right to complain to your local supervisory authority.
Under the California Consumer Privacy Act, you have the right to know, delete, correct, and not be discriminated against for exercising those rights. We do not sell or share personal information as the CCPA defines those terms.
To exercise any right, email shaybento@mmpguru.com. We will respond within the period the law requires — normally 30 days. We may need to verify your identity first.
If your request concerns a patient record, we will direct you to the practitioner who holds it. They are the controller of that information and we cannot act on it without their instruction.
13. Children
The Service is intended for qualified practitioners and students of Chinese medicine. It is not directed at anyone under 18, and we do not knowingly collect information from children. If you believe a child has created an account, contact us and we will delete it.
This does not restrict a practitioner from recording an adult or child patient's date of birth in their own records — that information is under the practitioner's control and their professional duty of care.
14. Direct marketing
We will only send you marketing email if you have consented. Every marketing message contains an unsubscribe link, and you may also email us to opt out. We comply with Amendment No. 40 to the Communications (Telecommunications and Broadcasts) Law, 5742-1982.
Service messages — receipts, expiry notices, security alerts and material changes to these terms — are not marketing, and you cannot opt out of them while you hold an account.
15. Third-party websites
The Service may link to sites we do not operate. We are not responsible for their content or their privacy practices, and this policy does not apply to them.
16. Changes to this policy
We may update this policy. If we make a material change we will post a notice on the website and, where the change significantly affects how we use information you have already given us, email you before it takes effect. The "Last updated" date at the top always reflects the current version.
17. Contact and complaints
Shay Ben Tolila Snir 39, Pardes Hanna-Karkur, Israel Email: shaybento@mmpguru.com
If you are not satisfied with our response, you may complain to the Israeli Privacy Protection Authority (www.gov.il/en/departments/the_privacy_protection_authority), or to your local supervisory authority if you are in the EEA or the UK.