Last updated: July 3, 2026
Commission data is payroll data, and we treat privacy accordingly. This policy explains what we collect, why, where it lives, and how to get it back or get it deleted — in plain language, because a privacy policy you can’t read protects nobody.
The Commish service (getcommish.com and the Commish application) is operated by Commish Tech Inc., a Delaware corporation (“Commish”, “we”, “us”). You can reach us about anything in this policy at ricki@getcommish.com.
Customer organisations (the companies that sign up) upload commission data — deals, rates, plans, payout history — including information about their sales representatives. For that data, the customer organisation is the data controller and we process it on their behalf, under our agreement with them.
Individual users(admins, managers, and reps invited by a customer organisation) have accounts with us directly. If you’re a rep with a question about the commission data your employer put into Commish, your employer controls that data — but we’ll always help you route the question.
Account information: name, work email, role, and authentication data (including two-factor enrollment status if you use it).
Customer data: the commission-related data your organisation uploads or connects — deals, products, rates, plans, payout results, statements. You own it; we calculate with it.
Usage and log data: standard server logs and in-app events used for security, debugging, and making the product better. Our error-monitoring masks all text and input content by default — we can see that something broke, not your numbers.
What we don’t collect: we run no advertising trackers, no third-party analytics cookies, and no social pixels. The only cookies we set are the ones that keep you signed in.
To provide and secure the service, calculate commissions, generate statements, send service notifications (like run approvals or statement availability), provide support, and improve the product. We do not sell your data. We do not use it for advertising. We do not use your data to train AI models — AI features run server-side through our API agreement with our provider, whose API terms exclude training on submitted data.
Production application compute and databases run in Canadian regions (Montréal and Canada Central) — end to end. Enterprise plans can choose their data residency. Data is encrypted in transit (TLS) and at rest (AES-256), with integration credentials additionally encrypted before storage.
Four vendors, each with one job:
If this list changes, existing customers hear about it from us first.
We keep customer data while the organisation’s account is active — commission history is an audit trail, and audit trails are the point. When an organisation leaves, it can export its data, and we delete it on request. Individual users can request access, correction, export, or deletion of their personal information at ricki@getcommish.com; where the data is controlled by your employer, we’ll coordinate with them.
Role-based access enforced in the database (reps see only their own earnings), org-enforceable two-factor authentication for admins, encryption throughout, and recurring internal security audits. The full, honest picture — including what certifications we don’t have yet — is on our Security & Trust page.
Commish is a workplace tool for businesses and is not directed to children. We don’t knowingly collect information from anyone under 16.
If we change this policy in a way that matters, we’ll notify customer organisations through the service or by email before the change takes effect — and the “last updated” date above changes only when the content does.
Commish Tech Inc. · ricki@getcommish.com. A human reads it.
Customers operating under a signed Master Services Agreement or data-processing addendum: those agreements take precedence over this policy where they differ.