Privacy Policy

Private by structure, clear by default.

Payout Atlas exists to keep commission data inside the organization it belongs to. This policy explains what we collect, why we collect it, and the boundaries that keep it private.

Effective July 17, 2026Operated by Webtune Agency

Who we are and what this covers

Payout Atlas is a private commission calculation service operated by Webtune Agency. This policy covers the public website at payoutatlas.com and the signed-in workspaces behind it.

Payout Atlas is built for organizations, not consumers. There is no public sign-up form: every account is created through a private invitation issued by an organization owner or administrator, so most information we hold arrives through the organization you work with.

Information we collect

We collect only what the service needs to operate:

  • Account details. Your display name, email address, username, and a salted one-way hash of your password. We never store the password itself.
  • Membership records. Which organizations your account belongs to and the role you hold in each, because every request is authorized against them.
  • Organization content. Carrier statements, parsed policy rows, payout snapshots, and calculation history uploaded by your organization. This content belongs to the organization and is stored inside its own boundary.
  • Session records. Hashes of session and invitation tokens, so a stolen database record cannot be replayed as a sign-in.

Manual estimates are calculated on the server and returned to your workspace without being saved. We do not collect payment details, and the public site runs no advertising or third-party analytics trackers.

How we use information

Information is used to run the service and nothing else:

  • Verifying who you are when you sign in.
  • Routing your account to the organization workspaces it is assigned to.
  • Running payout and chargeback calculations against your organization's private rules.
  • Letting owners and administrators manage members and invitations.
  • Protecting accounts, including rate limiting sign-in attempts.

We do not sell personal information or use it for advertising.

Cookies and sessions

Payout Atlas uses cookies only to keep you signed in. The session cookie is HTTP-only, secure, and same-site, which means scripts on the page cannot read it and other sites cannot send it. Account activation uses a separate short-lived cookie that exists only long enough to set your first password.

There are no advertising, analytics, or cross-site cookies.

How data is stored and protected

All private configuration and organization content lives in server-side storage scoped to a single organization. The browser receives only the authorized options and results needed for the current screen. Team names, hierarchy, compensation rules, and results are never placed in public pages, client bundles, or source maps.

  • Passwords are stored as salted PBKDF2 hashes and are never recoverable as plaintext.
  • Application secrets are configured only on the server and are excluded from browser bundles and source control.
  • Every parse, calculation, save, and history request re-checks the account's organization membership on the server.
  • Missing, malformed, or mismatched records fail closed: when something cannot be verified, no data is returned.

When information is shared

We share information in only three situations:

  • Inside your organization. Owners and administrators can see the membership details of their own organization, such as names, emails, roles, and account status.
  • Infrastructure providers. The service runs on hosted infrastructure (currently Cloudflare) that processes data on our behalf to serve the application.
  • Legal requirements. If the law genuinely requires disclosure, we comply while sharing the minimum necessary.

One organization's data is never shared with another organization. Cross-organization requests are denied on the server.

Retention and deletion

Account records are kept while your membership is active. Organization content, including statements and calculation history, is kept for as long as the organization uses the service, because it is part of that organization's working records.

To correct or remove your account information, start with your organization administrator, who controls membership. You can also contact us directly and we will handle the request with the organization that owns the workspace.

Your choices

You can update your password at any time from your account, and signing out ends the session everywhere the button says it does. Changing your password also closes every other active session. For access, correction, or deletion requests, contact your organization administrator or email us at webtune.agency@yahoo.com.

Changes to this policy

If this policy changes, the effective date at the top of this page changes with it. Meaningful changes will be visible here before they apply, and continued use of the service after the effective date means the updated policy applies.

Contact

Questions about privacy or this policy can be sent to webtune.agency@yahoo.com. For questions about the rules of using the service, read the Terms and Conditions.