Commish

Privacy Policy

Last updated September 3, 2026

1. The short version

Commish stores what running your pool requires — who you are, which pools you are in, and what you picked — and nothing aimed at advertising. We do not sell your data, we do not run ads, and we have no feature that handles money between players, so there is no financial data of yours to hold beyond what our payment processor reports about a pool’s software fee.

2. What we collect

Your account: an email address and the display name you choose. That display name is shown to other members of your pools; your email address is visible to the commissioner of a pool you join, because that is what lets them run it.

Your pool activity: pools, memberships, picks, and the standings derived from them. Commissioner actions that affect others — result overrides, roster changes, reminders — are recorded in that pool’s audit log.

Payments: checkout is processed by Stripe. We record which tier a pool bought, the amount, and the payment status. Card numbers never touch our servers.

Pick reminders: if you turn on pre-kickoff notifications, we store the push subscription your browser creates. Turning them off removes it.

3. Signing in with Google

If you use “Continue with Google”, Google sends us your name, email address, and profile picture reference. We use them for exactly one thing: creating and signing you into your Commish account. Your name is offered as a starting point for your display name, which you confirm or change before it is saved. We do not post anything to your Google account, and Google data is never shared, sold, or used for advertising.

Commish’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You can also sign in with an emailed code instead — Google is never required.

4. Cookies, analytics, and error reporting

Cookies keep you signed in. That is their only job here — there are no advertising or cross-site tracking cookies.

We use Vercel Analytics to count page visits in aggregate and Sentry to report errors when something breaks, so we can fix it. Error reports can include technical details about the request that failed; neither service is used to build profiles of you.

5. Who we share data with

Only the services that run the product: Supabase (accounts and database), Vercel (hosting and analytics), Stripe (payments), Brevo (transactional email such as sign-in codes and reminders), Sentry (error reporting), and Google (only if you sign in with it). Each receives what its job requires and nothing more. We do not sell personal data, and we do not share it with advertisers — there aren’t any.

We would disclose data if the law compelled us to, and would tell you unless we were legally barred from doing so.

6. Retention and deletion

Pool data is kept for the life of the pool, because standings are a shared record — other members’ seasons depend on the picks in them.

You can delete your account yourself from the Account page. That removes your email address, your display name, and any pick-reminder subscriptions, and closes your sign-in for good. Your picks stay in the pools you played in, attributed to “Deleted player”, because other members’ standings are computed from them. If you are the only commissioner of a pool that is still running, make someone else a commissioner first — a pool cannot be left with nobody to run it. A pool with nobody in it but you closes with your account.

You can also email support@commishpools.com from the address on the account and we will do the same by hand.

7. Children

Commish is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.

8. Changes and contact

If this policy changes, the date above changes with it, and material changes will be flagged in the product. Questions go to support@commishpools.com. Commish is operated from Washington State, United States.