Commolyn Privacy Policy

Last updated: 2026-09-28

1. Who we are and how to contact us

Commolyn is owned and operated by Ilya Tsipelshteyn, a VAT-registered sole proprietor (Osek Murshe) in Israel. Contact us about privacy at [email protected].

We decide how personal data is used to operate the Commolyn platform, manage accounts, secure the service, and provide support. Community organizers decide what information their communities and events ask members to provide, who on their team can use it, and how they use it to run their activities. Where an organizer determines these purposes and instructs us to process the information, Commolyn provides the platform on the organizer's behalf. The organizer is responsible for informing participants about its own purposes and legal basis for community or event questions. You can contact us if you need help identifying the relevant organizer.

2. What this policy covers

This policy covers your use of the Commolyn website and application, event pages, and the Commolyn Telegram bot. It applies to organizers, team members, participants, and people whom a participant adds to an event. A separate notice covers details sent through the pilot request form on our marketing website. This policy does not cover a separately operated Russian service. Google provides sign-in and hosts the mailbox that receives messages sent to our contact address. Telegram provides the messaging service through which people interact with our bot and community chats. Google and Telegram also process information under their own privacy policies; those policies do not replace this one for information Commolyn receives and uses.

3. Information we handle

Depending on how you use Commolyn, we handle:

  • Account and contact details: your name or display name, email address, phone number, profile photo, preferred language, and identifiers associated with a connected Google or Telegram account. An email address and phone number are required before you can register for an event.
  • Community information: communities you belong to, your role and membership status, profile answers requested by a community, and your notification preferences.
  • Event information: registrations, waitlist and attendance status, answers to event-specific questions, companion or dependent details supplied by a registrant, and messages or photos connected with an event.
  • Communications: messages and actions sent to our bot, notifications sent through connected channels, delivery status, and support requests you send us.
  • Technical information: IP address, device and browser information, request and error logs, security events, and audit records of access attempts to protected personal data needed to run and protect the service. The web application stores information on your device, including sign-in state and interface preferences. This storage is strictly necessary for the service to work. We do not use analytics, advertising, or tracking cookies.

Organizers must not request health information, other special categories of personal data under the GDPR, or highly sensitive information under Israeli privacy law, such as financial, location, or personality-assessment data, in community or event questions. Please do not include such information in free-text answers. If you believe an answer contains sensitive information, contact us so that we can help the organizer review and remove it as appropriate. Acceptance of event rules is separate from this policy.

We receive information from you, from organizers or participants who register someone else, and from Google or Telegram when you choose to sign in or interact through those services. Google sign-in can provide us with your Google account identifier, verified email address, name, and profile photo. Our Telegram bot receives your Telegram identifiers, the messages or actions you send to it, and, where available, your Telegram profile photo, which we use as your profile picture; it uses them to carry out requests such as joining a community or registering for an event. If someone adds you as a companion, the registrant may provide your name and contact details before you interact with Commolyn yourself.

4. Why we use information

The following explains Commolyn's purposes and, where the EU GDPR applies, the legal bases for processing that we determine. An organizer is responsible for explaining its own purposes and legal bases for community-specific questions and event operations.

PurposeInformation involvedGDPR legal basis
Create and maintain your account and let you sign inAccount identifiers and account profilePerformance of a contract with you, or steps you request before entering one (Article 6(1)(b))
Maintain your identity across communities and let organizers of communities you join contact you about their eventsEmail address and phone numberPerformance of a contract with you (Article 6(1)(b))
Operate the platform for an organizer, including RSVP, attendance, and event communicationsCommunity and event informationThe organizer determines the applicable basis; Commolyn processes this information to provide the service on its behalf
Protect accounts and the platform, prevent abuse, diagnose failures, and keep necessary operational recordsSign-in, technical, security, and delivery dataOur legitimate interests in service security and reliability (Article 6(1)(f)); legal obligation where applicable (Article 6(1)(c))
Respond to requests and provide supportContact details and the contents of your requestPerformance of a contract or our legitimate interest in responding and resolving problems (Article 6(1)(b) or (f), as applicable)

Where we rely on legitimate interests, we consider the effect on people and their rights. We do not sell personal data or use event registration answers for advertising. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

Commolyn does not itself require you by law to provide personal information. An organizer must tell you if a law requires any information it requests for its event. Providing details marked as required in an account, community, or event flow is necessary to complete that flow. Optional fields can be left blank. If you do not provide required information, you may be unable to sign in, join a community, or register for that event.

5. Who can see information

Authorized organizers and team members can see member and event information needed for their community roles, including registration answers and attendance. Other participants may see information you or an organizer put on a public event page or in a shared channel. Before posting names, photos, or other personal details publicly, consider who can access or forward them.

We share information with MVPS, the provider of our VPS in Cyprus and its disaster-recovery snapshots, and Cloudflare for R2 media and encrypted database backup storage. Cloudflare also provides DNS for our domain and forwards email sent to [email protected] to a mailbox hosted by Google, where we read and answer it. Google handles sign-in and that mailbox; it is not used to host Commolyn's event or community records. Messages and actions sent through Telegram are handled by Telegram under its own privacy policy and by Commolyn when received by our bot. We may disclose information if required by law or necessary to protect rights, safety, or the service. We do not give organizers access to your profile answers from an unrelated community merely because you use the same account.

6. International transfers

Commolyn's application and primary database run on a VPS located in Cyprus, in the European Union. MVPS also makes disaster-recovery snapshots of the VPS on separate storage at that location. Media, such as event photos and profile images, is stored separately in a Cloudflare R2 bucket configured with the European Union (EU) jurisdiction restriction. Encrypted database backups are stored in a separate private Cloudflare R2 bucket with the same EU jurisdiction restriction. These R2 restrictions keep the stored objects within the EU. Commolyn is operated from Israel, so information on the VPS or in R2 may also be accessed from Israel. The European Commission has recognized Israel as providing an adequate level of protection for transfers of personal data from the EU. Google, Telegram, Cloudflare, and MVPS may process some information in other countries when you use their services or when they provide services to us. Where GDPR transfer rules apply and no adequacy decision covers a transfer, an applicable transfer mechanism and safeguards are required. Contact us for information about transfers that apply to your data.

This policy does not cover the separate Russian instance.

7. How long we keep information

We keep account information while your account is active and as needed to operate the service. Community profile data is kept while the relevant community is active and the organizer needs it for community purposes, subject to applicable law and deletion requests. Event registration answers and attendance records are kept for up to five years after the event ends so that participants can view their event history and organizers can review past events and develop their communities. An organizer should remove particular answers sooner when they are no longer needed for these purposes. If an organizer deletes a community, its community and event data is retained in the active system for up to 30 days for recovery, then deleted or anonymized, unless a longer period is required by law or needed to establish, exercise, or defend legal claims. Routine diagnostic logs and message delivery records are kept for no longer than one month. The platform's activity log, which records actions taken in the service, is kept for no longer than one year. We keep separate, restricted records of access attempts to protected personal data and relevant security events for at least 24 months as required by Israeli data-security rules. These records do not contain the accessed personal data itself. When information is no longer needed, we delete or anonymize it.

We retain the five most recent daily, two most recent weekly, and two most recent monthly encrypted database backups in R2. Older R2 backups are deleted as new ones replace them. Separately, MVPS makes automated snapshots of the entire VPS for disaster recovery and overwrites older snapshots under its own rotation. MVPS states that residual backup copies after service termination typically remain for no more than 90 days; this is its published practice, not a guaranteed maximum. Data removed from the active system may remain in either kind of backup until the relevant copy expires. Backups are used only to restore the service; if a backup is restored, we reapply applicable deletion requests before making the restored data available for ordinary use.

You may request deletion of your account information. Where an organizer controls event or community data, we will direct the request to the organizer or assist it in responding. Deleting an account does not necessarily remove an organizer's lawful event records; where possible, information retained for event history will be anonymized.

8. Your choices and rights

You can update some account, community profile, and notification settings in the service. You can also contact [email protected] to ask about the information we hold, request access or correction, request deletion, or raise a concern. We may need to verify your identity before acting. If an organizer controls the relevant information, we will help route your request to that organizer.

If the GDPR applies to you, you may also have rights to restrict processing, object to processing based on legitimate interests, receive portable data where applicable, and withdraw consent without affecting earlier lawful processing. You may complain to a data protection authority in the EU country where you live or work, or where you believe an infringement occurred. In Israel, you may contact the Privacy Protection Authority. Rights can be subject to legal exceptions.

9. Children and people registered by others

Commolyn accounts are for people aged 18 or over. If you register a child for an event, you must be the child's parent or legal guardian. You provide the information needed for that registration on the child's behalf. We rely on the information the registrant supplies and do not independently verify the parent or guardian relationship. A participant may also add another adult as a companion. Anyone providing another person's details should have authority to do so and should make this policy and any relevant organizer notice available to that person. Contact us if you believe information about you or a child was supplied without appropriate authority.

10. Security and changes

We use access controls and other technical and organizational measures intended to protect personal data. No online service can guarantee absolute security. Please contact us if you suspect unauthorized use of your account.

We may update this policy when our services or legal obligations change. The date at the top identifies the latest version. If a change materially affects how we use your information, we will provide additional notice where required.