Last updated: {DATUM VOR LAUNCH EINSETZEN}
The controller responsible for data processing on commi.io is the service provider named in the Imprint. For privacy inquiries contact: {PRIVACY-EMAIL}.
Account data. Email address and password (stored as a cryptographic hash) when you register, managed through our authentication provider Supabase. Legal basis: performance of contract (Art. 6(1)(b) GDPR).
Profile data. Name, avatar, bio and role (developer or sales rep) that you provide. Visible to other platform members. Legal basis: performance of contract.
Payment and payout data. We connect your Stripe account via Stripe Connect and store Stripe identifiers (account ID, customer ID). Card details are held exclusively by Stripe, never by us. Legal basis: performance of contract.
Commission and billing records. Sale amounts, commission splits, invoices and payout records. Retained for 10 years under German tax law (§147 AO). Legal basis: legal obligation (Art. 6(1)(c) GDPR).
Referral link analytics.When someone opens a rep's tracking link, we store a hashed (not reversible) IP address and browser user agent to count clicks and prevent abuse. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
Developers' customer data.To attribute sales, we receive events from the developer's Stripe account which can include a customer's email address and subscription details. We process this data on behalf of the developer solely for sale attribution and commission accounting, and do not use it for any other purpose.
commi.io uses strictly necessary cookies (session authentication). If you open an invite link, a first-party cookie stores the referral code for 30 days so we can credit the person who referred you; it is deleted once you sign up and is never shared with third parties. No advertising or cross-site tracking cookies are set on this site. Referral attribution on a developer's own website is governed by that developer's privacy policy.
We use the following processors under data processing agreements: Supabase (database and authentication), Stripe (payments and payouts), and{HOSTING-ANBIETER, z. B. Vercel — nach Deployment eintragen} (hosting). Stripe may process data outside the EU; transfers are safeguarded by the EU Standard Contractual Clauses and the EU–US Data Privacy Framework.
Account and profile data are kept until you delete your account. Commission, invoice and payout records are kept for 10 years (statutory retention). Click analytics are kept no longer than {AUFBEWAHRUNGSDAUER FESTLEGEN, z. B. 12 Monate}.
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21). To exercise any right, email {PRIVACY-EMAIL}. We respond within 30 days. Note that records subject to statutory retention (e.g. invoices) are excluded from erasure until the retention period ends. You also have the right to lodge a complaint with a supervisory authority (Art. 77).
To delete your account, email {PRIVACY-EMAIL}. Open payouts are settled first, then your profile is anonymized and your login removed. Financial records are retained in anonymized form as required by law.