Commission information
When you start a commission, 10NECTAR collects the selected tier and add-ons, your project brief, optional reference files and filenames, customer name and email from Stripe, payment and order identifiers, approval or revision choices, change requests, project status, and delivery records.
Before Stripe Checkout opens, the brief and reference details are placed in a protected, temporary Cloudflare R2 intake record. Stripe receives an opaque intake identifier, the Commission deposit description and amount, and the payment information it needs; the brief, filenames, and protected R2 object keys are not copied into Stripe metadata. Completed intake details become the authoritative D1 Commission record. Abandoned temporary intake records and their references are scheduled for deletion after seven days.
Reference, concept, and final files are stored in protected Cloudflare R2. Commission state, payment identifiers, authorization tokens, delivery dates, check-in state, and the durable notification outbox are stored in Cloudflare D1. Unique review and studio links function like passwords; keep them private. Do not include medical, financial, government-identification, password, or other unnecessary sensitive information in a brief or reference file.
After final delivery, Brevo may hold the customer name, email, PAST_CUSTOMER status, top_of_funnel stage, and last-delivery date for operational customer history and service communication. This does not add the customer to the Through Time list. One non-promotional customer-service check-in is scheduled 30 days after final delivery; it asks about the completed Commission and does not advertise another product or create a marketing subscription.