Who we are and what this covers
Payout Atlas is a private commission calculation service operated by Webtune Agency. This policy covers the public website at payoutatlas.com and the signed-in workspaces behind it.
Payout Atlas is built for organizations, not consumers. There is no public sign-up form: every account is created through a private invitation issued by an organization owner or administrator, so most information we hold arrives through the organization you work with.
Information we collect
We collect only what the service needs to operate:
- Account details. Your display name, email address, username, and a salted one-way hash of your password. We never store the password itself.
- Membership records. Which organizations your account belongs to and the role you hold in each, because every request is authorized against them.
- Organization content. Carrier statements, parsed policy rows, payout snapshots, and calculation history uploaded by your organization. This content belongs to the organization and is stored inside its own boundary.
- Session records. Hashes of session and invitation tokens, so a stolen database record cannot be replayed as a sign-in.
Manual estimates are calculated on the server and returned to your workspace without being saved. We do not collect payment details, and the public site runs no advertising or third-party analytics trackers.
How we use information
Information is used to run the service and nothing else:
- Verifying who you are when you sign in.
- Routing your account to the organization workspaces it is assigned to.
- Running payout and chargeback calculations against your organization's private rules.
- Letting owners and administrators manage members and invitations.
- Protecting accounts, including rate limiting sign-in attempts.
We do not sell personal information or use it for advertising.
How data is stored and protected
All private configuration and organization content lives in server-side storage scoped to a single organization. The browser receives only the authorized options and results needed for the current screen. Team names, hierarchy, compensation rules, and results are never placed in public pages, client bundles, or source maps.
- Passwords are stored as salted PBKDF2 hashes and are never recoverable as plaintext.
- Application secrets are configured only on the server and are excluded from browser bundles and source control.
- Every parse, calculation, save, and history request re-checks the account's organization membership on the server.
- Missing, malformed, or mismatched records fail closed: when something cannot be verified, no data is returned.
Retention and deletion
Account records are kept while your membership is active. Organization content, including statements and calculation history, is kept for as long as the organization uses the service, because it is part of that organization's working records.
To correct or remove your account information, start with your organization administrator, who controls membership. You can also contact us directly and we will handle the request with the organization that owns the workspace.
Your choices
You can update your password at any time from your account, and signing out ends the session everywhere the button says it does. Changing your password also closes every other active session. For access, correction, or deletion requests, contact your organization administrator or email us at webtune.agency@yahoo.com.
Changes to this policy
If this policy changes, the effective date at the top of this page changes with it. Meaningful changes will be visible here before they apply, and continued use of the service after the effective date means the updated policy applies.
Contact
Questions about privacy or this policy can be sent to webtune.agency@yahoo.com. For questions about the rules of using the service, read the Terms and Conditions.