Privacy Policy
Last Updated: September 23, 2026
This Privacy Policy explains how CommsOpen (“CommsOpen,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you access or use our websites, applications, dashboards, artist pages, software, and related services (collectively, the “Service”).
This Privacy Policy does not govern the privacy practices of third-party websites, platforms, or services that you may access through or connect to the Service.
1. Scope and Our Role
CommsOpen processes personal information in different contexts.
1.1 Information About Users
When you create an account, purchase a subscription, contact CommsOpen, or otherwise interact directly with the Service, CommsOpen generally determines why and how that personal information is processed.
This Privacy Policy describes how we process that information.
1.2 Client Data
The Service also allows Users and Organizations to store information about their own clients, customers, collaborators, referrals, and other contacts (“Client Data”).
For Client Data, the User or Organization that entered the information generally determines why the information is collected and how it is used.
CommsOpen processes Client Data to provide the Service on behalf of that User or Organization.
If a User or Organization has stored personal information about you and you want to exercise privacy rights regarding that information, you should generally contact that User or Organization first.
Where required by applicable law, we will assist Users and Organizations with legally valid privacy requests relating to Client Data.
2. Information We Collect
The information we collect depends on how you use the Service.
2.1 Account Information
We may collect:
- name;
- email address;
- username;
- profile information;
- authentication identifiers;
- account preferences;
- timezone;
- language; and
- other information associated with your account.
If you sign in using a third-party identity provider, we may receive information from that provider according to the authorization you grant.
2.2 Organization Information
If you create or join an Organization, we may collect:
- Organization name;
- Organization identifiers;
- membership information;
- roles and permissions;
- invitations;
- subscription and billing information;
- Organization settings; and
- activity associated with the Organization.
2.3 Artist Profile Information
You may provide information used to create or manage an artist profile, including:
- artist or studio name;
- profile image;
- artwork;
- biography or description;
- genres, disciplines, or labels;
- social media accounts;
- usernames and handles;
- portfolio links;
- websites;
- commission information; and
- other profile information.
Some artist profile information may be made public if you choose to publish it.
2.4 Client Data
Users may enter Client Data such as:
- names and preferred names;
- usernames and platform identities;
- contact information;
- preferred contact methods;
- pronouns;
- timezone;
- language;
- dates or dates of birth;
- referral relationships;
- commission history;
- payment records;
- notes;
- labels or flags; and
- relationship or communication information.
Client Data is generally provided to CommsOpen by a User or Organization rather than directly by the individual described in the record.
2.5 Commission and Business Information
The Service may process information relating to:
- commissions;
- project status;
- products and services;
- pricing;
- due dates;
- priorities;
- checklists;
- labels;
- payments;
- transaction amounts;
- transaction types;
- fees;
- currencies;
- expenses;
- discounts;
- time tracking;
- revenue;
- profitability;
- calendar events; and
- other business records you choose to maintain.
2.6 Subscription and Billing Information
If you purchase a paid subscription, CommsOpen and our payment processor may process:
- subscription plan;
- billing interval;
- seat count;
- payment status;
- transaction identifiers;
- billing address where required;
- payment method type;
- limited payment method details supplied by the payment processor; and
- other billing information.
Complete payment card information is generally collected and processed directly by our payment processor rather than stored by CommsOpen.
2.7 User Content
We may process information and files that you choose to submit, upload, publish, or create through the Service, including:
- images;
- artwork;
- notes;
- descriptions;
- documents;
- URLs;
- custom fields; and
- other content.
You control the information that you choose to place in free-form fields.
2.8 Communications and Feedback
If you contact us or submit feedback, we may collect:
- your message;
- your email address;
- account identifiers;
- Organization identifiers;
- artist profile identifiers;
- the page of the Service you were using;
- application version information;
- diagnostic information that you provide; and
- other information included in your communication.
2.9 Technical and Usage Information
When you use the Service, we may automatically receive technical information such as:
- IP address;
- browser type and version;
- operating system;
- device type;
- request timestamps;
- pages or features accessed;
- referring pages;
- network information;
- diagnostic information;
- security events;
- error information; and
- other server logs.
We use this information primarily to operate, secure, maintain, debug, and improve the Service.
2.10 Cookies and Similar Technologies
We may use cookies, local storage, session storage, and similar technologies for:
- authentication;
- maintaining sessions;
- remembering preferences;
- security;
- preventing abuse;
- application functionality; and
- analytics.
We do not currently sell personal information or use personal information for cross-context behavioral advertising.
3. How We Use Personal Information
We may use personal information to:
- provide, operate, and maintain the Service;
- create and manage accounts;
- authenticate Users;
- provide Organization and collaboration features;
- store and organize information at your direction;
- process subscriptions and billing;
- generate reports and analytics;
- publish information you choose to make public;
- provide third-party integrations you request;
- provide support;
- respond to inquiries and feedback;
- communicate important account or Service information;
- send marketing communications where permitted by applicable law;
- detect, prevent, and investigate fraud, abuse, and security incidents;
- monitor reliability and performance;
- diagnose and correct errors;
- develop and improve features;
- enforce our Terms of Service;
- establish, exercise, or defend legal claims;
- comply with applicable law and lawful requests; and
- protect CommsOpen, our Users, and other people.
We may also use aggregated or de-identified information that can no longer reasonably identify an individual for analytics, research, product development, and other business purposes.
4. Legal Bases for Processing
Where applicable law requires a legal basis for processing personal information, we may rely on:
- Performance of a contract: where processing is necessary to provide the Service you requested;
- Legitimate interests: where processing is reasonably necessary to operate, secure, maintain, improve, and support the Service;
- Consent: where you have given consent for a particular use;
- Legal obligations: where processing is necessary to comply with applicable law; and
- Protection of rights and safety: where processing is necessary to protect CommsOpen, our Users, or other people.
The applicable legal basis may depend on the type of information and the circumstances in which it is processed.
5. How We Disclose Personal Information
We do not sell or rent personal information.
We do not currently share personal information for cross-context behavioral advertising.
We may disclose personal information in the circumstances described below.
5.1 Service Providers
We use third-party service providers to operate and support the Service.
These providers may process personal information on our behalf as necessary to provide their services.
Service providers may include providers of:
- authentication and identity management;
- hosting, databases, networking, and cloud infrastructure;
- payment processing;
- email and communications;
- application monitoring and error reporting;
- analytics;
- customer support; and
- other operational services.
We currently use WorkOS to provide authentication and identity management functionality. WorkOS may process information on our behalf in connection with authentication and account management. You can review the WorkOS Privacy Policy.
We currently use Cloudflare for infrastructure, networking, security, content delivery, and related services. You can review the Cloudflare Privacy Policy.
If paid subscriptions are offered, we may use Stripe to process payments and subscription billing. Stripe may receive payment and billing information directly from you. You can review the Stripe Privacy Policy.
We may add, remove, or replace service providers as the Service evolves.
5.2 Organizations
If you use the Service through an Organization, authorized Organization owners, administrators, and members may access information associated with that Organization according to their permissions.
An Organization may retain or control certain information after a member joins or leaves the Organization.
5.3 Integrations You Request
If you connect the Service to a third-party service, you authorize CommsOpen to exchange information with that service as necessary to provide the integration you request.
Information provided to a third-party service may also be subject to that service’s privacy policy.
5.4 Public Information
Information you intentionally publish through an artist page or otherwise designate as public may be accessible to anyone.
Public information may also be indexed, cached, copied, or redistributed by search engines and other third parties.
5.5 Legal and Safety Reasons
We may disclose personal information where we reasonably believe disclosure is necessary to:
- comply with applicable law, regulation, legal process, or a valid governmental request;
- enforce our agreements;
- investigate fraud, abuse, or security incidents;
- protect the rights, property, or safety of CommsOpen, our Users, or other people; or
- establish, exercise, or defend legal claims.
Where legally permitted and appropriate, we may attempt to notify affected Users of requests for their information.
5.6 Business Transfers
If CommsOpen is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, personal information may be disclosed or transferred as part of that transaction.
Any successor’s use of personal information will remain subject to this Privacy Policy unless Users are notified otherwise as required by applicable law.
6. Public Information
You should carefully consider what information you choose to make public.
Information displayed through public artist pages may be accessible without a CommsOpen account.
After public information is removed from the Service, copies may continue to exist temporarily in:
- search engine caches;
- web archives;
- third-party websites;
- browser caches; or
- copies previously made by other people.
CommsOpen generally cannot control copies made by independent third parties.
7. Your Privacy Rights
Depending on where you live and applicable law, you may have rights relating to your personal information.
These rights may include the right to:
- request access to personal information we hold about you;
- request correction of inaccurate personal information;
- request deletion of personal information;
- obtain a portable copy of certain personal information;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent; and
- complain to an applicable data protection authority.
We may need to verify your identity before processing a request.
Certain information may be exempt from a request where applicable law permits or requires us to retain it, including information required for:
- security;
- fraud prevention;
- legal compliance;
- billing records;
- dispute resolution; or
- enforcement of agreements.
You may submit a privacy request by contacting privacy@commsopen.app.
We will not discriminate against you for exercising a privacy right protected by applicable law.
8. Accessing and Updating Information
You may be able to review or update certain account and profile information directly through the Service.
For information that cannot be changed through the Service, you may contact us at privacy@commsopen.app.
If you are seeking access to or correction of Client Data entered about you by a User or Organization, you should generally contact that User or Organization directly.
9. Account and Data Deletion
You may request deletion of your CommsOpen account and associated personal information.
Deletion requests are subject to information that we are permitted or required to retain for purposes such as:
- legal compliance;
- transaction and billing records;
- fraud prevention;
- security;
- dispute resolution; and
- enforcement of agreements.
Deleted information may remain temporarily in backups until those backups expire or are overwritten through our normal backup processes.
Aggregated or de-identified information may be retained where it can no longer reasonably identify you.
10. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Retention periods may depend on:
- the type of information;
- why the information was collected;
- whether your account remains active;
- applicable legal requirements;
- security and fraud prevention needs; and
- applicable limitation periods.
Client Data is generally retained while the relevant account or Organization remains active or until the User or Organization deletes it, subject to backup processes and legal retention requirements.
11. Security
We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, destruction, or loss.
These safeguards may include:
- access controls;
- authentication mechanisms;
- network security controls;
- encryption where appropriate;
- system monitoring; and
- separation of systems and environments.
No method of transmitting information over the Internet or storing information electronically is completely secure.
You are responsible for maintaining the security of your own account credentials and devices.
If you believe your account or information has been compromised, contact us promptly at security@commsopen.app.
12. Marketing Communications
You may opt out of marketing emails by using the unsubscribe mechanism provided in those messages or by contacting us.
Even if you opt out of marketing communications, we may continue sending non-promotional communications relating to:
- your account;
- security;
- billing;
- changes to the Service;
- legal notices; or
- other transactional matters.
13. California Privacy Disclosures
13.1 California Online Privacy Protection Act
California law requires operators of certain commercial websites and online services to disclose information about their online privacy practices.
The categories of personal information we collect and the categories of third parties with whom we may disclose personal information are described throughout this Privacy Policy.
You may review, update, or request changes to certain personal information as described in this Privacy Policy.
13.2 Do Not Track
Some web browsers provide a “Do Not Track” (“DNT”) signal.
Because there is not currently a universally accepted standard for interpreting DNT signals, the Service does not currently respond differently based solely on a browser’s DNT setting.
We do not currently sell personal information or use personal information for cross-context behavioral advertising.
13.3 Third-Party Tracking
Our service providers may collect technical information through the Service on our behalf for purposes such as infrastructure, authentication, security, diagnostics, and analytics.
We do not knowingly permit third parties to collect personal information about your activities across unaffiliated websites and services through CommsOpen for their own targeted advertising purposes.
13.4 California Consumer Privacy Act
The California Consumer Privacy Act (“CCPA”) applies to businesses that meet specific statutory requirements.
Where the CCPA or another California privacy law applies to our processing of personal information, we will provide and honor the rights and disclosures required by applicable law.
Regardless of whether the CCPA applies to a particular request, CommsOpen provides the access, correction, deletion, and portability mechanisms described in this Privacy Policy where reasonably practicable.
14. Minors
The Service is intended for Users who are at least 13 years old.
Users under 13 may not create or use a CommsOpen account.
If you are under the age of majority where you live, you may use the Service only with the permission of your parent or legal guardian.
If you are under 18, you may purchase a paid subscription only with the permission of your parent or legal guardian and using a payment method that you are authorized to use.
CommsOpen is not directed to children under 13, and we do not knowingly collect personal information directly from children under 13.
If we learn that a child under 13 has created an account or provided personal information directly to CommsOpen, we will take reasonable steps to delete the account and associated personal information.
If you believe a child under 13 has provided personal information to CommsOpen, contact us at privacy@commsopen.app.
15. International Users
CommsOpen is operated from the United States.
Personal information may be stored and processed in the United States and other countries where CommsOpen or our service providers operate.
Those countries may have privacy laws that differ from the laws where you live.
Where applicable law requires safeguards for international transfers of personal information, we will use legally recognized transfer mechanisms or other appropriate safeguards.
16. Third-Party Services
The Service may contain links to or integrations with third-party websites, applications, and services.
This Privacy Policy does not govern independent third parties.
We encourage you to review the privacy policies of third-party services before providing information to or connecting your account with them.
17. Changes to This Privacy Policy
We may update this Privacy Policy as the Service, our practices, or applicable law changes.
When we update this Privacy Policy, we will change the “Last Updated” date at the top of this document.
If changes materially affect how we use personal information, we may provide additional notice through the Service, by email, or through another reasonable method where required by applicable law.
18. Contact
Questions, privacy requests, or concerns about this Privacy Policy may be sent to: