(function () {
try {
// AQ-r2 (2026-06-09): respect the explicit-denial sentinel
// written by cookie-consent-harden.js writeATR() on any
// marketing-axis denial (payload.marketing === false; cycle-3 F1).
// Without this gate, the next page navigation re-creates
// gmx_first_touch from the current URL+referrer+utm_*+click_ids,
// silently undoing the reject-all deletion (sweep finding #1).
// The sentinel is cleared the moment the visitor grants
// marketing in the banner (analytics-only grant does NOT
// clear), restoring the writer path on the very next
// page load. Page-cache-safe: the sentinel is a
// browser-resident cookie checked in the inline script, so
// varnish/breeze-served HTML still hits this gate.
if (/(?:^|;\s*)gmx_consent_denied=1(?:;|$)/.test(document.cookie || '')) return;
var CLICK_IDS = ['gclid','fbclid','msclkid','ttclid','wbraid','gbraid','li_fat_id'];
var qs = new URLSearchParams(window.location.search);
var urlClickIdKey = null;
for (var i = 0; i < CLICK_IDS.length; i++) {
if (qs.get(CLICK_IDS[i])) { urlClickIdKey = CLICK_IDS[i]; break; }
}// Parse existing cookie.
var existing = null;
var match = document.cookie.match(/(?:^|;\s*)gmx_first_touch=([^;]+)/);
if (match) {
try { existing = JSON.parse(decodeURIComponent(match[1])); } catch (e) { existing = null; }
}// GWP-273 — referrer-enrichment branch.
// Keep existing unless either (a) URL carries a new click id
// the stored payload lacks (paid click is a higher-value
// signal and upgrades direct/organic), OR (b) the stored
// payload has empty referrer AND the current document.referrer
// is non-empty + external (Safari/ITP/policy-quirk catch:
// first-hit may have missed the referrer; later same-session
// page-loads can recover it).
var existingHasRef = !!(existing && existing.referrer && existing.referrer !== '');
var docRef = document.referrer || '';
var refHost = '';
if (docRef) {
try {
refHost = new URL(docRef).hostname.replace(/^www\./, '').toLowerCase();
} catch (e) { refHost = ''; }
}
var ownHost = (location.host || '').replace(/^www\./, '').toLowerCase();
var currentExternalRef = !!(refHost && refHost !== ownHost);
var canEnrichRef = !!existing && !existingHasRef && currentExternalRef;if (existing) {
if (!urlClickIdKey && !canEnrichRef) return;
if (urlClickIdKey && existing[urlClickIdKey] && !canEnrichRef) return;
}var utm_keys = [
'utm_source','utm_medium','utm_campaign','utm_content','utm_term',
'utm_adgroup','utm_matchtype','utm_network','utm_device','utm_placement'
];
// GWP-273 — merge-preserving base. When enriching an existing
// payload, retain its landing_url + ts + prior click ids /
// utms; only overlay referrer (and any click id appended below
// via the forEach). Branches with/without urlClickIdKey were
// collapsed — both produced the identical Object.assign — the
// click id is added uniformly later.
//
// GWP-273 design choice: "latest external referrer wins" —
// accepted edge case where a user opens a new external tab
// post-empty-first-touch and returns; low-volume, simple, no
// sentinel flag needed.
var data;
if (existing && canEnrichRef) {
data = Object.assign({}, existing, { referrer: docRef });
} else {
data = { landing_url: window.location.href, referrer: docRef, ts: Date.now() };
}
utm_keys.concat(CLICK_IDS).forEach(function (k) {
var v = qs.get(k);
if (v) data[k] = v;
});
// GWP-208 — carry Meta's first-party click-linker cookies (_fbc
// = fb.1.<ts>.<fbclid>, _fbp) into the captured payload so they
// ride the persistent gmx_first_touch cookie cross-page (LP X →
// LP Y) the same way the URL click-ids do. The CF7 hidden-field
// populator copies the whole payload verbatim, so fbc/fbp reach
// the lead even when the form lives on a page without ?fbclid.
var fbcMatch = document.cookie.match(/(?:^|;\s*)_fbc=([^;]+)/);
if (fbcMatch && fbcMatch[1]) data.fbc = decodeURIComponent(fbcMatch[1]);
var fbpMatch = document.cookie.match(/(?:^|;\s*)_fbp=([^;]+)/);
if (fbpMatch && fbpMatch[1]) data.fbp = decodeURIComponent(fbpMatch[1]);
var encoded = encodeURIComponent(JSON.stringify(data));
if (encoded.length > 3800) return;
var expires = new Date(Date.now() + 90 * 864e5).toUTCString(); // GWP-143 C1: match Google Ads 90-day attribution window
var secure = window.location.protocol === 'https:' ? '; Secure' : '';
document.cookie = 'gmx_first_touch=' + encoded + '; Path=/; Expires=' + expires + '; SameSite=Lax' + secure;
} catch (e) {}
})();
/* Meta Pixel base — inline in wp_head so Breeze Delay-All-JS does not defer it; fbevents.js is async-injected (optimizer-invisible). */
!function(f,b,e,v,n,t,s){if(f.fbq)return;n=f.fbq=function(){n.callMethod?
n.callMethod.apply(n,arguments):n.queue.push(arguments)};if(!f._fbq)f._fbq=n;
n.push=n;n.loaded=!0;n.version='2.0';n.queue=[];t=b.createElement(e);t.async=!0;
t.src=v;s=b.getElementsByTagName(e)[0];s.parentNode.insertBefore(t,s)}(window,document,'script',
'https://connect.facebook.net/en_US/fbevents.js');/* Symmetric with server GMX_Consent: revoke BEFORE init; cookies/sends held until grant. */
fbq('consent', 'revoke');
fbq('init', '1857131551802431');
fbq('track', 'PageView'); /* queued; flushed to Meta only after consent grant *//* Grant bridge — reads the SAME ATR marketing signal as GMX_Consent.applyConsent(). */
(function () {
function read(name){var m=document.cookie.match('(?:^|; )'+name.replace(/([.*+?^${}()|[\]\\])/g,'\\$1')+'=([^;]*)');return m?decodeURIComponent(m[1]):'';}
function marketingGranted(){
try {
var given = read('atr_cookie_notice_consent_given');
if (!given) return false; // undecided -> stay revoked
var c = JSON.parse(read('atr_cookie_notice_consent') || '{}');
return !!(c.marketing || c.ad_storage === 'granted');
} catch (e) { return false; } // NO-SILENT-OK: parse/read failure degrades gracefully to revoked (consent stays held; no marketing send) — not an error to report.
}
function apply(){ if (marketingGranted()) fbq('consent', 'grant'); }
apply();
document.addEventListener('click', function(ev){
if (ev.target && ev.target.closest && ev.target.closest('[class*="atr-cookie"], #atr-cookie-notice')) setTimeout(apply, 50);
}, true);
window.addEventListener('storage', apply);
})();
var breeze_prefetch = {"local_url":"https://gomixapp.com","ignore_remote_prefetch":"1","ignore_list":["/cart/","/checkout/","/my-account/","https://gomixapp.co.il/(.)/u05d4u05d8u05d5u05e4u05e1-u05e0u05e9u05dcu05d7-u05d1u05d4u05e6u05dcu05d7u05d4/","wp-admin","wp-login.php"]};
//# sourceURL=breeze-prefetch-js-extra
CCTV Surveillance Sign for Your Business — Free Printable
Looking for a CCTV surveillance sign for your business? Here is a ready-made “this area is under camera surveillance” notice — copy it with one click, print it for the entrance, or download it as a Word file to edit. Fill in the business name and phone in the square brackets — and the sign is ready to hang in a minute. In Israel, a visible sign is how a business meets its duty to inform under privacy law.
Please Note — This Area Is Under Camera Surveillance
Security cameras operate on these premises 24 hours a day.
Recording is intended to protect the safety of customers, employees and property.
Recordings are kept for a limited period only and are deleted in accordance with business policy.
For questions about the recording, contact: [Business name], tel. [Phone].
Thank you for your cooperation
Fill in the details — the notice updates automatically:
CCTV signage duty in Israel — what the Privacy Protection Law says
A business that installs security cameras films people — and therefore operates inside the scope of Israel’s Privacy Protection Law. Under the Privacy Protection Authority’s guidelines on surveillance cameras, whoever places cameras in a public space or business premises must inform the people being filmed clearly — first and foremost with a prominent sign at the entrance to the filmed area, announcing both the fact of the filming and its purpose. Since Amendment 13 to the law took effect (2025), enforcement powers and fines have expanded significantly — so a small sign at the entrance is the simplest piece of compliance there is.
What should the sign say? The fact of filming (“this area is under camera surveillance”), the purpose of filming (security and protecting the safety of customers, employees and property) and a contact for questions about the filming. The wording on this page covers all three. Place the sign at every entrance to the filmed area, at eye level, before a person enters camera range — not deep inside the shop. Several entrances? A sign at each one.
Beyond the sign, the basic principles in the Authority’s guidelines are simple: film only what is needed for the purpose (don’t point cameras at the neighbor’s property or at spots where employees have an expectation of privacy), keep recordings for a limited period and delete them accordingly, and restrict viewing access to designated role-holders only. A business that settles these three together with clear signage is covered on the basic layer of its duties.
Frequently Asked Questions
Is a CCTV sign mandatory for businesses in Israel?
Yes. Under the Privacy Protection Authority’s guidelines, issued under the Privacy Protection Law, whoever places security cameras in business premises must inform the people being filmed — and the principal way is a prominent sign at the entrance to the filmed area. This page is general information, not legal advice.
What must appear on a CCTV surveillance sign?
Three components: the fact of filming (“this area is under camera surveillance”), the purpose of the filming (for example security and protecting customers and property) and a contact for questions. The free wording on this page covers all three.
Where should the sign be placed?
At every entrance to the filmed area, at eye level, so a person sees it before entering camera range. A business with several entrances needs a sign at each. A sign by the parking area or yard is recommended if they are filmed too.
Are employees allowed to be filmed as well?
Filming employees is a more sensitive matter: full transparency toward employees about the cameras and their purpose is required, and cameras must not be placed where there is a heightened expectation of privacy. Before filming work areas, read the Privacy Protection Authority’s guidelines on cameras in the workplace.
How long may recordings be kept?
The law sets no single number — the principle is purpose-bound retention: keep footage only as long as it is needed for the security purpose the camera was installed for, and delete it under a fixed routine. In most businesses that means days to weeks, not months.
Key Takeaways
A business that films must inform — a prominent sign at every entrance to the filmed area
On the sign: the fact of filming, its purpose, and a contact for questions
Amendment 13 to Israel’s Privacy Protection Law (2025) expanded enforcement — don’t postpone the sign
Keep recordings for a limited period only; viewing access for designated role-holders only
The template here is free — copy, print, or download as Word
A printed sign settles the duty to inform — but a digital signage screen at the entrance does much more: it shows the security notice, your opening hours and promotions in one place, and updates remotely in seconds without ever printing a page.
var atrCookieNoticeSettings = {"cookieName":"atr_cookie_notice_consent","decisionCookieName":"atr_cookie_notice_consent_given","expiryDays":"365","autoHideDelay":"0","enableDebug":"","siteName":"GoMixApp","isPrivacyPage":"","privacyPolicyUrl":"https://gomixapp.com/privacy-policy/","privacyNoteText":"\ud83d\udca1 You can read this page while deciding about cookies","mode":"simple"};
//# sourceURL=atr-cookie-notice-simple-js-extra