Privacy Policy
What we collect, what we read from your connections, why, who we share it with, and your rights.
Version 1.0 · Last updated 6 October 2026
1. Who is responsible
ThreeCommas Ltd, Registered office address, London, United Kingdom, is the controller of personal data processed through the Service. Contact our privacy team at privacy@threecommas.example.
2. What we collect, by role
Everyone: name, email, sign-in details (handled by Clerk), country, time zone, language, display currency, notification preferences, messages, reports, device and log data (IP address, browser) for security.
Founders: business details, website, logo, billing details, payment method details held by Stripe (we store only the brand and last four digits), and data read from connections (below).
Partners: public profile, track record, links, leads you register (company, domain, and a one-way hash and masked version of the contact email), payout details (encrypted) and tax details (encrypted).
3. Data read from Stripe
With a restricted, read-only key, we read customers, subscriptions, invoices, charges and refunds, products, prices, coupons, promotion codes, disputes and basic account details. We store: invoice and charge amounts, tax, currency, dates, refunds, promotion codes and product ids; customer Stripe ids, creation dates, billing and card country, email domain and a one-way hash of the email. We do not store customer names or street addresses. We never write to your Stripe account.
4. Data read from Google, and Limited Use
If you connect Google Search Console (scope webmasters.readonly) or Google Analytics (scope analytics.readonly), we read daily totals and top countries, pages, queries, channels and devices for the property you choose, to show traffic on your profile.
ThreeCommas’ use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the traffic features you see; we do not use it for advertising, do not sell it, do not let humans read it except with your consent, for security, or where the law requires, and do not use it to train AI models.
5. Why we use it, and legal bases
- To provide the Service and perform our contract with you (accounts, listings, partnerships, statements, payouts).
- To meet legal obligations (tax, accounting, sanctions checks, responding to authorities).
- For legitimate interests: security, fraud prevention, preventing abuse, improving the Service, and telling you about features related to what you use.
- With your consent, where we ask for it (for example optional cookies, if we ever use them).
7. International transfers
Our providers may process data outside the UK and EEA, including in the United States. Where they do, we rely on adequacy decisions, the UK International Data Transfer Agreement or the EU Standard Contractual Clauses.
8. How long we keep it
- Account data: while your account is open, then deleted within 30 days of closure.
- Financial records (statements, commission lines, payouts, audit log): 7 years, as required for accounting and tax.
- Data read from connections: while connected; credentials are deleted immediately on disconnect, synced data within 30 days unless needed for financial records.
- Logs: 90 days.
9. Your rights
You can access, correct, export and delete your data, object to or restrict some processing, and withdraw consent. In the app: download your data as JSON or CSV from Account settings, change details there, and delete your account (financial records we must keep are retained but detached). Otherwise email privacy@threecommas.example. We reply within one month.
UK and EU: you may complain to the ICO or your local authority. California (CCPA/CPRA): you have rights to know, delete, correct and opt out of sale or sharing; we do not sell or share personal information for cross-context advertising, and we will not discriminate against you for using your rights. Elsewhere: we honour equivalent rights under your local law.
10. Security
We encrypt credentials and payout details with AES-256-GCM, use read-only access to your Stripe account, restrict admin access and log every money, permission and admin action. See Security.
12. Children
The Service is not for anyone under 18 and we do not knowingly collect their data.
13. Changes and contact
We will notify you of material changes in the app and by email. Questions: privacy@threecommas.example.