Privacy Policy

Privacy Policy

Effective 25 August 2026.

CommishPulse is commission-tracking software for commission-based agencies, operated by Commish Pulse LLC (“we”, “us”). This policy explains what we collect, why, who else sees it, and what you can ask us to do about it.

It is written to be read. Where a section is unusual, or works in your favor, it says so rather than burying it.

1. Two kinds of data, and they are not the same

This distinction runs through everything below, so it comes first.

Data about you. If you are an agency owner, a producer, or a visitor to our website, the information about you is ours to explain and yours to control. We decide what to collect and why. This policy governs it.

Data your agency uploads about its clients. When an agency records a policy, the client’s name and policy number belong to that agency’s relationship with that client — not to us. We store and process it on the agency’s instructions and for no purpose of our own. We do not decide what goes in, we do not use it for anything except showing it back to that agency, and we never combine it with another agency’s data except through the anonymous benchmark in section 6.

In the language of privacy law: for your own information, we are the controller (or “business”); for your clients’ information, we are a processor (“service provider”), and your agency is the controller. If you are a client of an agency that uses CommishPulse and want to exercise a right over your information, contact that agency — they hold the relationship, and we will support whatever they ask us to do.

2. What we collect about you

If you visit commishpulse.com

Standard server and traffic information: IP address, browser type, pages requested, and the referring page. We use it to keep the site running and to understand which pages get read.

If you buy a subscription

Your name, email address, agency name, and home state, which you type into the signup form. Stripe collects and processes the payment itself.

We never receive your card number. Payment happens on Stripe’s own pages. We store a Stripe customer identifier, the plan you bought, and whether the subscription is current. If we were asked to produce your card number, we could not.

If you use the app

  • Name, email address, role, and profile photo if you upload one
  • Your commission rates and splits
  • Your salary and burden percentage, if your agency enters them
  • Hire date and employment type, if your agency enters them
  • Commission earned per policy, and your totals
  • Performance scores and grades the software calculates
  • The date and time you last signed in
  • Support session records, when our staff view an agency (see section 5)

Some of this is employment and income information, which is more sensitive than a name and an email. We hold it because calculating what a producer is owed requires it. It stays inside your agency: producers see only their own figures, owners see the whole agency, and nobody sees another agency’s.

3. What we do not collect at all

There is no field anywhere in our database for:

  • Social Security or tax identification numbers
  • Dates of birth
  • Home or mailing addresses
  • Phone numbers
  • Driver’s license or government identification numbers
  • Bank account details
  • Payment card numbers
  • Health, biometric, genetic, or precise location data

These are not optional fields left empty. They do not exist, and there is nowhere to put one. If you upload a spreadsheet containing columns we do not recognize, those columns are ignored rather than stored.

One qualification, stated because it is true: a policy has a free-text notes field. What goes in it is whatever your agency types. We do not read it, and we do not police it, so we cannot promise it contains nothing beyond the list above — that is within your agency’s control, not ours.

4. Why we use it

Purpose What it covers
Providing the service Calculating commissions, showing your book, sending sign-in links
Billing Charging the subscription, counting seats
Support Answering questions, diagnosing a problem you report
Security Detecting misuse, keeping an access record
Communication Onboarding email, service notices, and — only if you agree — occasional product news
Legal Meeting obligations we are actually subject to

We do not build advertising profiles, and we do not make automated decisions that produce legal effects about you. The performance grades the software calculates are a reporting feature shown to you and your agency owner; no decision about anyone’s employment is made by the software.

We do not use your data, or your clients’ data, to train machine-learning models.

5. Support access

Our staff can open a read-only view of an agency as one of its users, in order to see what a person reporting a problem is actually seeing.

  • It is read-only, enforced by the database. A support session physically cannot change a policy, a rate, or a commission figure.
  • Every session is recorded — who opened it, which agency, viewed as whom, when it started and ended, and the reason given.
  • That record is permanent and cannot be deleted from the interface.

We describe this in detail because a capability like it exists in most business software and is rarely disclosed. Ours is bounded and logged.

6. Cross-agency benchmarks

Off unless your agency owner turns it on.

When it is on, your agency’s producer totals become part of an anonymous distribution — a median, a top quartile — shared with other agencies in the same state. What leaves your agency is a set of numbers with no names, no client information, no carriers and no agency attached. Other agencies see where their own people sit against the spread; they never see a row of yours.

A cohort is only reported once at least three agencies and ten producers are in it, so no figure can be traced back to one agency or one person. An owner can also exclude individual producers.

7. Who else we share with

We do not sell personal information, and have not in the preceding twelve months. We do not share it for cross-context behavioral advertising. We share it only with providers who need it to run the service:

Provider Role What it receives
Supabase Database, authentication, file storage All application data
Stripe Payment processing Buyer name, email, agency name, and payment details you give Stripe directly
Resend Transactional email delivery Recipient address, message contents
HighLevel Onboarding email for new customers Buyer name, email, agency name, plan, state
SmarterASP.NET Application hosting Traffic in transit

No client policy data reaches any of these except Supabase, which is the database itself. Stripe, Resend and HighLevel receive information about the person who bought a subscription — never a book of business.

We may also disclose information if compelled by law, and we will tell you unless we are legally prohibited from doing so. If the business is sold, data moves with it, and you will be told before it does.

8. Security

  • Access rules are enforced in the database, not in the screens. Every table carries row-level security, so the rules separating one agency from another, and a producer from their colleagues, apply to every query, whatever code makes it. A bug in a page cannot leak another agency’s numbers.
  • Passwords are stored only as a salted hash by our authentication provider. We cannot see them, which is why a reset sends a one-time link rather than a password.
  • Uploaded photos are isolated per person; nobody can overwrite another’s.
  • Data is encrypted in transit and at rest, hosted in [SUPABASE_REGION].
  • Backups: [BACKUP_POLICY].

No system is perfectly secure, and anyone who says otherwise is selling something. If we discover a breach affecting your information, we will notify you, and any regulator we are required to notify, without undue delay.

9. How long we keep it

  • While your subscription is active: as long as you use the service.
  • After cancellation: 90 days, then deletion.
  • Support session records and billing records: kept longer — an access log you can delete is not an access log, and tax law requires the other. Neither contains client policy data.
  • Before you leave: ask, and we will export your full book to CSV within [EXPORT_DAYS] business days, at no charge.

10. SMS Communications & Mobile Information

Collection of Mobile Information

When you opt in to receive SMS messages, we collect your mobile phone number and any information you provide in connection with SMS communications.

Use of Mobile Information

Your mobile number may be used to send:

  • Appointment confirmations and reminders
  • Order confirmations and updates
  • Account-related notifications
  • Customer support responses
  • Promotional and marketing messages (if you opt in)
  • Service alerts and updates

Message frequency may vary.

SMS Consent & TCPA Compliance

We only send SMS messages to users who have provided prior express consent in compliance with the Telephone Consumer Protection Act (TCPA) and applicable regulations.

  • Consent to receive marketing text messages is not a condition of purchase.
  • We maintain records of opt-in consent in accordance with regulatory requirements.
  • You may withdraw consent at any time.

Wireless carriers are not liable for delayed or undelivered messages.

Opt-In Consent

By providing your mobile number and opting in via Contact form on our website you consent to receive SMS/text messages from CommishPulse. Consent is not a condition of purchase.

Opt-Out Instructions

You may opt out of receiving SMS messages at any time by replying:

STOP to any SMS message you receive from us.

After you send “STOP,” you will receive a confirmation message, and you will no longer receive SMS messages unless you opt back in.

For assistance, reply HELP or contact us at [Contact Email] or [Phone Number].

Message & Data Rates

Message frequency and data rates may apply depending on your wireless carrier and plan.

Carrier Disclaimer

Wireless carriers are not liable for delayed or undelivered messages.

No Sharing of Mobile Information

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.
All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

11. Your rights

Depending on where you live, you may have the right to know what we hold, receive a copy, correct it, delete it, restrict its use, or object to it. Where a right applies, we will honor it, and we will not treat you differently for asking.

Where to ask. If you are an agency user, write to info@commishpulse.com. If you are a client of an agency that uses CommishPulse, ask that agency — the data is theirs, and we act on their instructions.

We will confirm your identity before acting, and respond within the time the applicable law allows (45 days in California, one month under the UK and EU GDPR). If we decline, we will say why, and how to appeal.

12. Insurance-specific note

Client information handled through CommishPulse is likely to be nonpublic personal information under the Gramm-Leach-Bliley Act. We treat it as such, and use it for no purpose other than providing the service to the agency that entered it.

Where an agency is a licensee under a state adoption of the NAIC Insurance Data Security Model Law, we are a third-party service provider. Our terms of service are written to serve as the contract that law requires you to have with us, and we will sign an agency’s own vendor agreement or data processing addendum on request.

13. Cookies

We use cookies that are necessary for the service to work — keeping you signed in, and remembering whether you prefer the light or dark theme. We do not use advertising cookies or third-party tracking pixels inside the application.

14. Children

CommishPulse is business software and is not directed to anyone under 18. We do not knowingly collect information from children. If we learn that we have, we will delete it.

15. Changes

If we change this policy in a way that materially affects you, we will email account owners and update the date at the top. Continuing to use CommishPulse after that means you accept the revised policy.

16. Contact


 

CommishPulse

Track Sales. Track Commissions.
Know Your Profit.

Industries

Company

© 2026 CommishPulse. All rights reserved.