You're on dev (v1.1 integration) - not for real elections.

Legal

Privacy Notice

SIMPLEVOTE LTD (Company No. 17251484), registered in England and Wales · Last updated 2026-07-17 · info@simplevote.org

This notice explains how SIMPLEVOTE LTD (Company No. 17251484), registered in England and Wales processes personal data through simplevote.org and the SimpleVote service. Contact info@simplevote.org. ICO registration: ZC162594.

1. Our roles

  • Controller: for account, sales, billing, website usage, support and security data used for our own purposes.
  • Processor: for voter lists, candidate and election content, ballots and related records processed on instructions from the organisation running an election.

If you are a voter or candidate, that organisation is normally your controller and should be your first contact for rights requests.

2. Voters, candidates and election participants

We may process name, email, eligibility and turnout status, invitation delivery status, candidate content, nomination information, authentication metadata and election audit events. Cast ballot rankings are stored separately from voter name and email.

Elections involving political parties, trade unions or campaigning bodies can reveal political opinions or trade-union membership. The organisation must identify and document its Article 6 basis, any Article 9 condition, transparency information and applicable election law before upload. SimpleVote does not determine those grounds.

3. Account, website and business data

We process account identity and role, authentication and security events, organisation and plan details, support correspondence, contracts, invoices and payment status, device/request information, and cookieless aggregate website usage and performance measurements. Payment card details are handled by Stripe and are not stored by SimpleVote.

4. Lawful bases and purposes

  • Contract: accounts, service delivery, support and billing.
  • Legitimate interests: security, fraud prevention, service reliability, aggregate product measurement and B2B administration, balanced against individual rights.
  • Legal obligation: accounting, lawful requests and regulatory compliance.
  • Consent: optional product marketing and loading optional third-party embeds where consent is the appropriate basis; consent may be withdrawn.
  • Controller instructions: election data under the DPA; the customer supplies its own lawful basis.

We do not sell personal data or use voter lists for SimpleVote marketing.

5. Election email and aggregate engagement

Resend sends invitations, reminders and results messages. Delivery status is available to organisers so they can diagnose failures and suppressions. Where open or click measurement is used, SimpleVote stores only short-lived aggregate counts by election and email type - not named-voter or per-recipient reading history. Opens are approximate. Organisers should consider PECR and their transparency duties before relying on engagement measurement.

Organisation-scoped suppression records prevent further election email until a controller records a lawful re-subscription. Uploading a list does not itself remove suppression.

6. Technologies, recipients and transfers

We use Vercel for hosting, edge delivery and cookieless usage/performance analytics; Supabase for database, authentication and storage; Resend for transactional email; Stripe for billing; and optional TidyCal, YouTube and customer-configured font services after relevant user or customer action. See the data-flow page and Cookies and technologies notice.

Primary database and application processing are configured in the UK or EEA. Edge delivery, support, recipient mail systems and optional services may process data elsewhere under provider terms and applicable transfer safeguards.

7. Retention

Data / purposeArticle 6Article 9Absolute periodTrigger / disposal
Voter names, email addresses, eligibility, invite tokens and turnout links
Eligibility, invitation, authentication and duplicate-vote prevention
Controller-determined basis; processed on documented instructionsController must document an applicable Article 9 condition where political opinion, trade-union membership or another special category is revealed or inferred30 days after close; inactive drafts: 180 days from creationCanonical close (terminal status / closed_at); in_progress elections are never purged until closed. Automated deletion of invitees, voter/token links and recipient metadata. Open elections past their scheduled end are closed before the retention clock starts. Anonymous cast ballots and result totals are kept after identity links are removed.
Saved voter registers and sync/import rows
Reuse and synchronisation of controller-supplied electoral lists
Controller-determined basis; processed on documented instructionsSame controller-determined condition as the underlying list, where applicable30 daysCreation, upload, or successful sync. Expiry; renewed by upload or sync. Active imports are allowed to finish before deletion; restrictions and suppressions remain effective.
Recipient-level delivery, bounce, complaint and send-failure events
Deliverability, suppression, troubleshooting and abuse prevention
Controller-determined basis; Processor legitimate interests for service security and reliability where acting as controllerNo special-category content is required; election association can create an inference, governed by the Controller's condition90 days maximum, or the election identity purge if earlierEvent creation or election retention deadline. Automated row deletion. Open and click events are excluded from recipient-level storage.
De-identified hourly open/click aggregate counters
Approximate aggregate engagement measurement
Controller-determined basis and PECR assessmentNo recipient identifier is retained; the Controller must still assess low-volume political inference risk90 daysHourly bucket start. Automated aggregate-bucket deletion. No recipient email, token, provider message identifier or unique-person count is stored.
Organisation-scoped unsubscribe, objection and restriction records
Honour objections, restrictions and do-not-contact instructions
Legal obligation and legitimate interests; Controller instructionsNot intentionally recorded; organisation association may create an inferenceOrganisation service term plus 30 daysOrganisation deletion or documented lifting by the Controller. Deletion after contact data and active sending capability are removed. Kept while needed to prevent unlawful re-contact; not used for marketing.
Nominations, proposer names/emails, nomination tokens, biographies and rejection reasons
Administer nominations and approve ballot candidates
Controller-determined basis; processed on documented instructionsController must document an Article 9 condition where candidacy or affiliation reveals special-category data30 days after election close/scheduled end; inactive drafts: 180 daysElection retention deadline. Proposer rows and unaccepted nominations deleted; accepted candidate record minimised. Approved candidate name and result may remain as the election record; proposer email is never exposed publicly.
Candidate photos and other nomination media
Display controller-approved candidate information
Controller-determined basisController-determined condition where media reveals political opinion or other special-category dataImmediate queueing on replacement, rejection or deletion; otherwise 30 days after election close/scheduled endObject replacement, candidate/election deletion, rejection, abandoned upload expiry, or election retention deadline. Files removed from storage when candidates or elections are deleted, or after the retention period. Abandoned uploads are removed after 24 hours.
De-identified post-vote star rating, optional text, and optional coarse platform class (iOS / Android / desktop)
Product quality measurement, including whether UX complaints disproportionately come from a platform class
Legitimate interests, subject to balancing and minimisationUsers must not submit special-category data; free text is optional12 monthsDate-only submission date. Automated deletion. Stored without voter id, token hash, email, IP address, full user-agent, device model, browser fingerprint or precise submission time. Platform class is a coarse bucket only (iOS / Android / desktop) and must not be joinable to a voter record.
Login-attempt security records
Authentication security, rate limiting and incident investigation
Legitimate interests and legal obligations concerning securityNot intended90 daysRecord creation. Scheduled deletion. Longer preservation requires a documented legal hold or incident record.
Security audit events
Detect, investigate and evidence misuse or compromise
Legitimate interests and legal obligationNot intended24 monthsEvent creation. Controlled append-only retention cleanup. The cleanup route cannot alter newer records.
Account and organisation membership data
Contract administration, access control and customer service
Contract and legitimate interestsNot intendedAccount term plus 30 daysAccount closure or verified deletion request. Primary-system deletion and audit-record redaction. Billing and security records follow their separate periods; legal holds are documented and access-restricted.
Orders, invoices, payment status and accounting records
Billing, tax, accounting, fraud prevention and financial audit
Contract and legal obligationNot intended7 years from the transactionTransaction or invoice date. Deletion/anonymisation in SimpleVote systems; Stripe follows its controller/processor obligations. SimpleVote does not store full payment-card numbers.
Support requests, correspondence and diagnostic attachments
Resolve requests, maintain service quality and evidence instructions
Contract and legitimate interestsNot requested; users should not include unnecessary special-category data24 monthsTicket or request closure. Deletion from active support systems. A documented dispute or legal hold may suspend deletion only for the material required.
Cast ballots and published count records
Count votes, verify results and preserve election integrity
Controller-determined basisController-determined condition where ballot content constitutes political opinions or trade-union dataCustomer term, then 30 days, unless earlier deletion is instructedElection completion or service termination. Deletion, return, or retention in anonymised form. Ballot rows are not stored with voter name or email; retention may be necessary for result integrity.
Lawful-basis attestation version, actor and timestamp
Demonstrate accountable voter-list ingestion and controller instruction
Legal obligation and legitimate interestsThe attestation records a condition selected by the Controller, not the underlying voter attributes24 months after the related election closesElection close/scheduled end. Deletion or actor de-identification. The attestation wording/version is retained separately from the uploaded list.
Encrypted database backups and point-in-time recovery copies
Resilience, disaster recovery and integrity
Same basis as the protected source dataSame condition as the protected source data, where applicableProvider-configured recovery window, targeted maximum 30 days after primary deletionPrimary-system deletion and backup rotation. Automatic expiry; no restoration to ordinary processing. A deleted record may remain in an inaccessible backup until rotation and must be re-deleted if a backup is restored.
Hosting, database, and email provider logs
Security, delivery, availability and platform diagnostics
Legitimate interests, legal obligation and Controller instructions as applicableNot intended; request/election context may create an inference30 days maximum (production approval gate)Log creation. Provider expiry or deletion. Production approval is blocked until live provider configuration/terms evidence this ceiling or this matrix is corrected to the actual lawful maximum.

8. Rights and complaints

Depending on circumstances, you may have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent. We may need to verify identity. For election data, contact the organising controller; we assist it under the DPA. We cannot produce an identity-linked ballot ranking that the service does not store. You may complain to the ICO or your relevant supervisory authority.

9. Security, children and changes

Our current measures and limitations are described in the Trust Centre. The service is for organisations; a customer using it for children must establish lawful authority and appropriate notices. Material notice changes are shown by the date above and may require renewed organisational acceptance.

Privacy Notice | SimpleVote | SimpleVote