California privacy rights (CCPA / CPRA)
When the California Consumer Privacy Act or California Privacy Rights Act applies, California residents may have rights to know, delete, or correct personal information, opt out of sale or sharing, limit certain uses of sensitive personal information, and avoid discrimination for exercising applicable rights.
VoterFile also uses the request channel below for privacy questions even when a statutory right does not apply.
VoterFile does not share personal information for cross-context behavioral advertising and does not resell or pool a shared voter file. California Nonbusiness and Unknown customer workspaces default to authorized official-field processing without VoterFile-created voter-level models.
If a future accepted order activates California's data-broker/DROP lane for a customer-specific modeled field, California may treat the paid output as a sale or license. Before processing, VoterFile must activate required DROP access, payment, deletion/suppression, risk-assessment, disclosure, and opt-out controls; complete required annual registration; and update this notice.
To submit a privacy rights request, email hello@cavoter.io with the subject line "Privacy rights request."
Include the right you are exercising and enough detail to verify the request, typically the email address or identifier you used with the service.
We aim to respond within 45 days or the period required by applicable law and will explain a permitted extension, inability to verify, exception, or denial.
If a request concerns voter-registration data in a campaign workspace, identify the customer, state, and source if known. Election-law, agency, protected-person, and campaign-processor rules may require a different response or routing through the customer that controls the workspace.
- When applicable: know what personal information we collect, use, disclose, sell, or share
- When applicable: delete personal information we collected from you
- When applicable: correct inaccurate personal information
- When applicable: opt out of sale or sharing, including any activated broker-lane processing
- When applicable: exercise privacy rights without discrimination
- An authorized agent may submit an applicable request with proof of authorization
Access-request information
When someone requests access, we collect the name, email, role, and campaign or race information they submit. We use that information to verify the request, follow up, and decide whether the beta is a fit.
We do not sell access-request submissions. We use them to operate the beta and communicate about VoterFile.
We keep access-request and onboarding information only as long as needed for beta qualification, follow-up, product operations, and necessary operational records. Campaign contacts can request removal through VoterFile contact channels.
Campaign and voter data
In a BYO workspace, a qualified customer supplies voter data it is authorized to use. In an approved data-included workspace, VoterFile may obtain an approved official-source file solely for one named customer after access review, quotation, customer authorization, and source approval.
Handling may include acquisition support, secure transfer, file loading, validation, normalization, deduplication, deterministic address cleanup and mapping, source-field filtering, campaign CRM activity, exports, support, security logging, and offboarding. Voter-level scoring or another modeled inference is included only when the accepted order's customer classification and activation record permit it.
VoterFile does not sell or license a shared voter file, make voter records publicly searchable, pool files across customers, reuse one customer's voter data for another customer, or use workspace voter data for unrelated commercial marketing or shared model training.
The customer controls its campaign purpose, authorized users, universes, outreach, and exports. The signed order, data-processing terms, source restrictions, and state-specific care clause can impose additional limits.
Retention, return, and deletion
We retain voter-level source and workspace data for the service term and documented offboarding period, subject to the signed order, source rules, legal holds, suppression duties, and technical backup cycles.
On an authorized request or termination, we stop ordinary processing and return or delete the source file and voter-level workspace data as the agreement and applicable law require. We may retain limited billing, contract, security, access, suppression, and compliance records, but not a reusable voter file for another purpose.
Campaign contacts can request workspace offboarding through the order's support channel. Individual voter or protected-person requests may be routed through the customer or a state-specific process so the legally responsible party can verify and complete them.
Analytics
We use Vercel Web Analytics, Vercel Speed Insights, and Google Analytics 4 on public, non-protected pages to understand page traffic, access-request conversion, site interactions, and Core Web Vitals performance.
These tools may collect page URL, referrer, browser and device information, approximate location derived from IP address, event data, conversion events, performance metrics, and may set or read cookies or similar identifiers.
We do not mount these analytics tools on protected voter/workspace routes, and we do not use analytics data to sell personal information or share it for cross-context behavioral advertising.
We also collect Core Web Vitals performance metrics ourselves, sent directly to VoterFile. That beacon carries only the page route, the metric name and value, and a coarse device type. It sets no cookies and includes no identifiers.
Error and performance monitoring
We use Sentry for error monitoring, crash reporting, and performance diagnostics in deployed service environments. When an error or monitored performance event occurs, Sentry may receive technical diagnostic information such as page route or URL, browser and device details, stack traces, error messages, timestamps, and non-PII workspace or account identifiers used for debugging.
We configure Sentry not to attach default request personal information and use a scrubber to reduce sensitive fields before events are sent. We use Sentry data for security, reliability, debugging, and product operations, and we do not use it to sell personal information or share it for cross-context behavioral advertising.
On public pages we also use Sentry Session Replay to debug UI problems. It records a small sample of sessions, plus sessions where an error occurs. All text is masked and media is blocked before anything leaves your browser. Protected voter and workspace routes are never recorded. Replay data is used only for debugging and reliability.
Payments
If you buy a workspace or accept a quoted service order, payments are processed by Stripe. VoterFile sends Stripe the information needed to create and reconcile checkout, such as customer email, order identifiers, payment amount, package or race description, return URL, and transaction metadata.
A data-included order may separately record an approved official-source cost or deposit, source agency, maximum approved amount, agency receipt, unspent balance, and refund status. VoterFile does not silently treat an unknown or material agency charge as included in a flat software price.
Card details are entered in Stripe Checkout and handled by Stripe; VoterFile does not receive or store full card numbers.
AI features
Optional AI features may use Anthropic models, directly or through Vercel AI Gateway, to generate filter suggestions, campaign briefings, outreach drafts, canvassing scripts, or chat responses.
When a user runs those features, the prompt and context needed for the response may be sent to the AI provider. Depending on the feature, that context can include user-entered instructions, campaign or race details, filter criteria, aggregate voter statistics, or CRM and outreach context. Voter-level fields are not sent to an AI provider unless a separately disclosed feature and customer scope expressly authorize that processing.
SMS and text messaging
When a voter, volunteer, or campaign user opts in to text messages through cavoter.io or a campaign-specific signup flow, we collect the phone number they provide along with the consent record (timestamp, source URL, and the consent text shown).
We do not share or sell SMS opt-in data, mobile phone numbers, or consent records to third parties for marketing purposes. Phone numbers and consent records are used only to send the messages the user opted in to receive, to honor STOP and HELP requests, and to keep records required by carrier and platform rules.
Message frequency varies by campaign and election cycle. Most subscribers receive 2 to 4 messages per week, with higher volume in the final two weeks before an election. Message and data rates may apply per the recipient's mobile carrier plan.
Recipients can opt out at any time by replying STOP to any message, which immediately removes the number from the sending list and stops future sends. Replying HELP returns instructions for getting in touch and confirms the messaging program the number is subscribed to.
Need California voter-file software for a real campaign?
Request beta access for eligibility review, pricing, and onboarding for qualified California campaigns that bring an authorized voter file.
Questions
Do you sell access-request data?
No. Access-request data is used for beta qualification, follow-up, and product operations.
Can campaigns request deletion?
Yes. Campaign contacts can ask for access-request or onboarding information to be removed through VoterFile contact channels.
Do you share SMS opt-in data with third parties?
No. SMS opt-in data, phone numbers, and consent records are never shared or sold to third parties for marketing. They are used only to send the messages the user opted in to, honor STOP and HELP requests, and meet carrier recordkeeping rules.