Last updated: March 31, 2026

Privacy Policy

This Privacy Policy explains what data CommissionFlow collects, why we collect it, and how we protect it. We keep this plain and specific — no vague assurances.

Who We Are

CommissionFlow is operated by LJY Financial Consulting Inc. We build software for commission plan management, deal imports, payout calculations, and rep statements.

Questions? privacy@commissionflow.dev

Data We Collect

  • Account data: name, email address, password hash (managed by our auth provider), organization membership.
  • Company data: company name, team size, billing and workspace settings.
  • CRM integration data: deal records synced via API from connected CRMs (e.g., HubSpot), including deal values, close dates, stages, and owner fields.
  • Commission data: plan configurations, rules, rates, thresholds, payout periods, calculated payout data, statements, adjustments, and dispute notes.
  • Employee data: names, roles, data identifiers, plan assignments, and performance inputs imported from CRM or CSV.
  • Usage data: login times, feature usage, basic logs, page views, and performance telemetry.

How We Use Data

  • Authenticate users and enforce organization access controls.
  • Calculate commissions, generate statements, and display calculation details.
  • Process AI-based extraction of uploaded commission plan documents.
  • Support onboarding, customer support, and product reliability.
  • Meet legal, tax, and compliance obligations.

We do not sell your data or use it for advertising.

Data from Third-Party Integrations

When you connect a CRM (such as HubSpot), we pull deal records via their API. We store this data to calculate commissions. We do not share your CRM data with third parties.

You may disconnect a CRM integration at any time. Upon disconnection, previously synced data remains available for historical payout records unless you request deletion.

Third-Party Processors

We use vetted providers to operate the service. Each receives only the data necessary for its function:

  • Supabase: authentication and database storage.
  • Vercel: application hosting and delivery.
  • AI providers: analysis and structured extraction of uploaded commission plan documents. Documents sent to AI providers are processed per their data processing agreements and are not used to train public models.

Cookies

We use essential cookies only — authentication/session cookies and security-related cookies required to run the app. We do not use tracking or advertising cookies.

Data Retention

Commission data and calculation history are retained for the duration of your service agreement plus 12 months. After account closure, we delete or anonymize personal data within 90 days, except where we are required to retain it for legal, tax, or fraud-prevention purposes.

You may request data export or deletion at any time by emailing privacy@commissionflow.dev.

Your Rights

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request export of your data in a usable format.
  • Request deletion of your data, subject to legal obligations.

CommissionFlow is subject to Canadian privacy law (PIPEDA). We support data rights requests from users in the United States, European Union, and elsewhere. To submit a request, email privacy@commissionflow.dev.

Security

We use industry-standard safeguards: encrypted transport (TLS), role-based access controls, and operational monitoring. No system is perfectly secure, but we take reasonable and ongoing steps to protect your data.

Changes To This Policy

We may update this policy from time to time. Material changes will be posted on this page with an updated effective date. Continued use of the service after a material change constitutes acceptance of the updated policy.