Commonities
Privacy Policy
Last updated: 3 October 2026
Who is responsible for your data
Commonities is currently operated by Alperen Turan Yuksel, who is the data controller for the normal Commonities service described in this policy.
For privacy questions or requests, contact our monitored public privacy contact at info@commonities.com.
The university-research data use and opt-out terms are stated in the University Research section of the Terms.
Privacy at a glance
- Your verified school account opens only the campus spaces you are allowed to use.
- We use account data, content and limited activity data to operate, secure and improve Commonities.
- We do not sell personal data, show targeted advertising or track you across other companies' apps and websites.
- Academic research runs only when the in-app status is On for an approved final build. The current Terms and your in-app opt-out control always apply.
- You can manage notifications, contact support and delete your account from the app.
Information we process
- Account and campus access: account ID, verified school email, school membership, nickname and optional avatar.
- Content and conversations: joined communities, posts, comments, event information, direct and event-chat messages, reports, blocks and support messages.
- Preferences: notification settings, saved items, onboarding choices, language choices and optional answers used to personalise recommendations. These product preferences are not thesis-research records.
- Search activity: When you join a course community or check or request a missing course on the web, we store the related search words, result and match details, time, campus and account ID. These action records stay linked to your account until you delete the account. Programme and course terms sent to search services from the web or native app may also appear temporarily in server-function logs under the provider's operational log schedule.
- Notifications: a device push token and delivery status when you enable device notifications.
- Service activity: limited events such as completing onboarding, joining a community, creating a first post or comment, sending a first chat, responding to an event, or submitting a report or suggestion.
- Safety, support and reliability: reports, blocks, support correspondence, moderation actions, app version, device platform, timestamps, error and security logs. Hosting and security providers may also process network information such as an IP address.
If you add a Commonities event to your device calendar, the chosen event is written locally by your device. Commonities does not upload the contents of your calendar.
Free-form posts, messages and community choices can reveal information that you consider sensitive. We use that information only to provide and protect the service, not for advertising or to infer a commercial profile about you. Please do not share another person's sensitive information without permission.
Why we use data and our legal bases
- To provide the service you request (GDPR Article 6(1)(b)): authentication, campus access, profiles, communities, catalogue search, posts, events, conversations, saved items, personalisation, support and notifications you enable.
- For our legitimate interests (GDPR Article 6(1)(f)): preventing abuse, enforcing blocks, investigating reports, securing the service, diagnosing failures and using limited product and search activity to understand whether core features work. We balance these interests against your rights and you may object.
- To meet legal obligations (GDPR Article 6(1)(c)): responding to valid legal requests and meeting applicable safety, accounting or regulatory duties.
- With consent where we specifically ask for it (GDPR Article 6(1)(a)): optional device permissions or any future processing that legally requires consent. You can withdraw consent without affecting earlier lawful processing.
Commonities does not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
Brochure links and daily totals
Each brochure link identifies a brochure placement. Opening it takes you to a Commonities page where you can continue to the web app. Public store links are shown only when available. When public store links are enabled, they may include a brochure campaign code so the stores can report aggregate campaign results under their own policies. A link open or store click does not establish an installation, signup or unique visitor.
Brochure link measurement. When enabled, this counter stores hourly totals by brochure code and action in a separate campaign schema in Commonities' existing Supabase database in Ireland. Aggregate totals are retained for historical campaign comparisons until Commonities removes them; reports can filter recent dates without deleting earlier totals. Link openings and web or store exits are separate counts; they are not unique people, registrations or confirmed installations. Vercel hosts the link pages and Supabase stores the totals. These providers may process technical connection data under their own policies; this counter does not add personal identifiers to the stored totals. See Vercel's privacy policy and Supabase's privacy policy. The link page states whether counting is currently enabled.
The counter uses hourly totals for each brochure code and separate web, App Store and Google Play exits. A random identifier for each counter request prevents duplicate writes; it is not a persistent visitor or account identifier and is also removed after approximately 90 days. The counter does not use cookies, account identifiers, device fingerprints or individual browsing profiles, and does not store IP addresses or user agents in its campaign tables. It skips counting when a Do Not Track or Global Privacy Control signal is sent. For those requests, brochure campaign tags are also omitted from store links. Known bots and previews are excluded where possible; repeated opens and unknown bots may still affect totals. This counter does not connect brochure visits to Commonities accounts or collect product-use analytics.
Hosting providers may process network metadata to deliver and secure the page under the provider arrangements described below. Ordinary account and app processing remains subject to the rest of this policy. For questions or objections, contact info@commonities.com.
University research control
Global research collection is controlled by a remote release switch, and the app shows its current status. It stays off during release preparation and cannot collect from an old or unapproved app build. The complete explanation is in the University Research section of the Terms.
When approved research is On, eligible users can see that status and turn it off at any time in Profile → Account & Privacy → Terms and Services.
Who receives data
Content is visible only in the campus, community or conversation context selected in the product. Direct messages are visible to their participants. Reports are available only to authorised reviewers or platform staff. Platform-support conversations are private between the requester and authorised Commonities platform staff.
We use service providers only to operate Commonities:
- Supabase for authentication, database storage and server functions.
- Vercel for the public web service and security delivery.
- Expo, Apple Push Notification service and Firebase Cloud Messaging for app delivery and optional push notifications.
- Apple App Store and Google Play for app distribution.
- Resend for service and account email.
These providers process data under their service terms and data-protection commitments. We do not give them permission to use Commonities data for their own advertising.
International transfers
Some providers may process data in the European Economic Area, the United States or other countries where they operate. When personal data is transferred outside the EEA, we rely on an applicable adequacy decision or contractual and technical safeguards such as the European Commission's Standard Contractual Clauses. Contact us if you want more information about the safeguards relevant to your data.
Retention and deletion
- Account, profile, membership, content and conversation data is kept while your account or the relevant content is active, then deleted when the account or content is validly deleted unless a limited record must be retained for a legal or safety reason.
- Push tokens are removed or invalidated when you disable notifications, sign out, delete the account or the provider reports that the token is no longer valid.
- Reports, support records and security logs are kept only for as long as reasonably needed to investigate the issue, protect users, prevent abuse, establish legal claims or meet a legal duty. Their need is reviewed rather than kept indefinitely.
- Web records created when you join a course community or check or request a missing course stay linked to the account until account deletion because no shorter automatic expiry is currently applied. Programme and course terms that appear in server-function logs follow the hosting provider's operational log schedule.
- Operational logs are minimised and follow the relevant provider's security and expiry schedules.
- Backup copies are isolated from normal product use and expire through provider backup cycles. Deleted account data is not restored for ordinary use; if disaster recovery temporarily restores an older backup, deletion controls must be reapplied.
- When research collection is On, the approved retention and opt-out rules stated in the University Research section of the Terms apply. When it is Off, no new research events are collected.
You can permanently delete your account in Profile → Account & Privacy → Delete account, or start from the web deletion page. Deletion signs you out and removes account-linked active service data, including stored course-search records. We may retain only narrowly limited records where necessary for security, fraud prevention, legal obligations or legal claims, and only for that purpose.
Your rights
Depending on the law and the circumstances, you may ask us to:
- provide a copy of your personal data;
- correct inaccurate or incomplete data;
- delete data;
- restrict processing;
- provide portable data you supplied to us;
- stop processing based on legitimate interests; or
- withdraw consent where consent is the legal basis.
Send a request to info@commonities.com. We may need to verify that the request concerns your account. You can also complain to the Dutch Data Protection Authority or the authority where you live or work.
Security
We use encryption in transit, campus-scoped access controls, restricted administrative roles, audit controls and data minimisation. No online service can promise perfect security. We investigate suspected incidents and notify affected people and authorities when the law requires it.
Age and eligibility
Commonities is designed for eligible students and staff and is not directed to children under 16. If you believe a child has provided personal data without the authority required by applicable law, contact us so we can investigate and take appropriate action.
Changes and contact
We may update this policy when Commonities, our providers or applicable law changes. We will update the date above and provide a more prominent notice if a change materially affects how personal data is used.
Privacy contact: info@commonities.com.