← Repstub

Repstub privacy policy

Last updated: October 3, 2026

Repstub is made by Great Work LLC, 651 N Broad St, Suite 206, Middletown, DE 19709, USA ("we"). This policy covers the Repstub app for your CRM's app marketplace and the pages at hl.greatwork.company/commissions, including reps' statement pages, approval pages and the leaderboard TV screen.

What we collect

When you install Repstub on a business account, your CRM gives us access tokens for the permissions you approve. With them, for that business account only, we read and store:

  • Your team: each user's id, name, email, phone and role, a monthly goal if you set one, and the teams you create.
  • Your plans and settings: rates, tiers, splits, clawback windows, draws, approvers.
  • Sales: for each won deal, paid invoice, paid order or subscription payment, its id, amount, refunds, date, the deal or invoice title, the client's contact id and name, the deal's pipeline, the product ids on it, and who was credited.
  • The commission ledger: every line credited, reversed, clawed back or adjusted, with its amount, note and who made it; period statements (earned, draws, balances, payout); and the approval history.

From payments we read only amounts, refunds, product and subscription ids, the contact id and name and whether the payment was live or a test. We never receive card or bank details. We read a contact's owner and won deals only when crediting a payment from that contact, and we do not read conversations, notes or other contact fields.

When you open Repstub inside your CRM, your CRM shares a signed record of who you are (user id, name, email, role and business account id). We use it to confirm you are signed in and to decide what you may see: admins see the team, everyone else only their own earnings. When someone opens a statement page, an approval page or the TV screen, our server sees their IP address, which we use only to limit repeated requests and do not store.

Why we use it

Only to work out commissions under your plans, keep the ledger, produce statements, get them approved, show each rep their own earnings and statements, show your leaderboard, and email statement and approval links. We do not sell data, use it for advertising, or train models on it.

Where it goes

  • Your CRM. To email a team member we create one contact for them, tagged as you choose (default "team statements"), and send the email through your business account's own conversations.
  • Your team. Each rep's private link shows their own earnings and statements; approvers' links show the period's totals per rep; the TV link shows names, sales and deal counts (commission amounts only if you turn that on).
  • No one else. We use no subprocessors besides our host: a DigitalOcean server in New York, USA.

How it is protected

Access tokens, names, emails, deal and invoice titles, client names, notes, plan definitions, settings and approval history are encrypted at rest with AES-256-GCM. Amounts are stored next to random ids. All traffic uses HTTPS. Statement links, approval links (which expire) and the TV link are signed; a rep's link and the TV link can be replaced at any time and the old one stops working. The TV link is kept in the part of the address that browsers never send to a server. Requests from your CRM are checked: webhooks by their digital signature, the app page by your CRM's signed user record, the workflow action by a secret key.

How long we keep it

Open and recent periods are kept while the app is installed. Approved periods, with their ledger lines, statements and approval history, are deleted 3 years after they end (pay records). When you uninstall Repstub, or click Disconnect inside the app, we delete the access tokens and everything we keep for that business account right away. When a contact is deleted in your CRM, we remove that client's id and name from our sale records; the amounts stay as pay records. Contacts and emails we created in your CRM stay there, under your control. Server logs that may contain IP addresses are kept for up to 14 days.

Your rights

You can see every plan, ledger line and statement inside the app and delete everything by uninstalling. For access, correction or deletion requests under GDPR, UK GDPR or CCPA, email hello@greatwork.company. If you are a member of one of our customers' teams, contact that business first; we act on their instructions as a processor.

Changes

We will post changes here and update the date above. Material changes are announced in the app.

Contact

hello@greatwork.company. We reply within one business day.