™ Sign in
DRAFT — not final, for legal review. Last updated 2026-09-24. This page describes how RosterVote handles data. It is a draft, checked against the code, for our lawyer to review and approve before it is published. It is not a binding legal document. Items marked COUNSEL or CONFIRM are still under review.
Privacy

RosterVote Privacy Policy

RosterVote LLC ("RosterVote," "we," "us") provides RosterVote, a service for running membership meetings and conventions: check-in, voting and independent verification. This policy explains what data we handle, why, who can see it, and how long we keep it.

Draft — last updated 2026-09-24.

1. Who controls your data

RosterVote is used by organizations (parties, associations, HOAs, and similar) to run their meetings. COUNSEL — confirm this controller/processor split; it is the standard SaaS framing and matches how the system actually works, and it determines whether organizations need a data-processing agreement from us:

  • Your organization is the controller of its own roster, its member and delegate records, and its meeting data. It decides what to collect and how to use it. Send requests about the roster to your organization.
  • RosterVote is the processor acting on the organization's behalf for that data, and the controller of account, authentication, and operational data (logins, sessions, audit logs) needed to run the service.

2. What we collect and why

Account & authentication (RosterVote as controller)

Your sign-in email. Session records, including your IP address, browser type, and timestamps. COUNSEL If you turn on two-factor sign-in, its secret and backup codes. We use these to sign you in, keep you signed in, show you your active sessions, and protect your account.

Roster & contact information (your organization as controller)

Names, postal address, email, phone, status, tags, and notes your organization maintains for its members and delegates, plus a record of who created or changed each field. This is your organization's own directory; it persists until the organization changes or removes it.

Driver's-license scan at check-in

A scanned license is read on the device at check-in and never uploaded. Staff can save the name and address from it to your organization's roster, exactly as if they had typed them in. Nothing else from the license is kept.

Voting data

For secret ballots, we store who voted separately from what they chose, and the two cannot be linked back together. Each voter gets a private tracking code to confirm their vote was counted. Roll-call and other recorded votes are open by design. The meeting's record, which can only be added to and shows any later change, logs check-ins, credentials, motions, votes and certifications so that results can be independently verified. COUNSEL

Email communications

Meeting notices and related emails, and their delivery, acknowledgement, and unsubscribe status.

Operational records

Audit logs of privileged actions, including data exports. Support-access grants, which are time-limited, revocable, and logged each time they are used. Organization snapshots: periodic full copies of an organization's data, including roster personal information and uploaded images, used for backup and restore. Snapshots expire on a timer, and the most recent one is kept.

3. How data is shared

  • Between organizations: each organization's data is kept separate. The one exception is a county-to-state delegation submission. A county organization submits required delegate details, including addresses, to its state organization. We do not yet trim that submission to the minimum needed, so we make no claim that it is minimized.
  • Service providers we use to run RosterVote: Fly.io (application hosting), Neon (database), Cloudflare (DNS, proxy, security, and cookieless Cloudflare Web Analytics, which observes visitor traffic at the edge without cookies), and SMTP2GO for sending email.
  • No third-party advertising or tracking SDKs are embedded in the application, and no AI/LLM provider processes your data today. The one third-party analytics service is Cloudflare Web Analytics, described above, which is cookieless and does not track individuals across sites.
  • We do not sell personal data.
  • RosterVote Support can see an organization's data only when the organization grants access. Each grant is time-limited and logged, and the organization can revoke it.

4. How long we keep it

The table below describes how RosterVote behaves today. It is not a promise. COUNSEL — confirm which of these should be stated as commitments.

DataRetention
Roster / contact personal informationKept as your organization's directory until it changes or removes it (not removed by a meeting purge)
Imported delegate personal information (state conventions)Purgeable — removed when an archived meeting's data is purged
License-derived fields (name, address)Kept with the contact; removed on purge
Ballots & the meeting's recordKept permanently. The lasting record is the point of the service. COUNSEL
Account email / sessions / two-factor sign-inSessions end on expiry or revoke; account data while the account exists
Email communicationsWith the associated meeting
Audit logsDurable
Organization snapshotsExpire on a timer; the most recent is kept. Purging a meeting does not remove personal information from snapshots taken before the purge. COUNSEL Those copies stay until the snapshot expires.

5. Security

Each organization's data is kept separate. Traffic is encrypted in transit. Two-factor sign-in is available. Privileged actions are logged. The meeting's record shows any change made after the fact.

6. Cookies and local storage

We set only cookies your visit needs: to sign you in, or to keep your ballot tied to your device during a meeting. We don't use cookies for advertising, and we don't use them to follow you around other sites. Because of that, we don't show a cookie-consent banner: everything below is necessary for the page you asked for to work. COUNSEL — confirm this "strictly necessary, no banner" position.

Cookies

NameSet byWhat it's forHow long it lasts
cv_sessionRosterVoteKeeps you signed in.Ends after 24 hours with no activity, or 30 days after you signed in, whichever comes first. Even if you keep using it, you'll be asked to sign in again after 30 days.
rv_ballotRosterVoteTies an open ballot to your device for one meeting, so you can reopen the voting page and it's still you. It does not record which way you voted. When a vote is secret, we store who voted separately from what they chose, and nothing, including this cookie, links the two back together.Ends 24 hours after your last vote or check of the page. Refreshed each time you use it, so it won't expire mid-meeting.
A security cookie (e.g. __cf_bm)Cloudflare, which fronts our site for securityTells real visitors apart from automated traffic, so the site stays up under abuse.Set and controlled by Cloudflare, not by our code, so we can't state an exact value here. CONFIRM which Cloudflare features are switched on for our zone.

That's the complete list. No advertising cookie, analytics cookie or cross-site tracking cookie is ever set. Our one analytics service, Cloudflare Web Analytics (described in section 3), doesn't use cookies at all.

Local storage

Your browser also keeps a few small settings on your own device, never sent to our servers. Clearing your browser's site data removes these:

KeyWhat it's for
rv-themeRemembers whether you chose light or dark mode.
rv-dismiss-*Remembers which one-time notices or prompts you've already dismissed, so they don't keep reappearing.
rv-had-sessionRemembers that this browser was recently signed in, so if your session ends we can tell you that you were signed out instead of just showing a blank sign-in page.
rv-chair-script-pxRemembers your preferred text size on the chair's running script.
rv-timer-presetRemembers the last countdown length you set on the meeting timer.
rv-receipts-<meeting>Saves your vote tracking codes on your device so you can look up a past vote. This copy is for your convenience only. The meeting's record is the one that counts, and clearing it does not change your vote. Clearing your browser's data loses these saved codes.
rv-redeem-tokenHolds a one-time sign-in link's token for the moment it takes to use it. Cleared right after, and never saved between browser tabs or visits.

In the mobile app, there are no cookies. Instead your device's own secure storage (the same place it keeps other apps' passwords) holds the same kind of thing: your sign-in token, your theme choice, which screens you last opened, your label-printer setup, and which prompts you've dismissed. None of it leaves your device except your sign-in token, which the app sends with each request the same way a browser sends a cookie, so the app can tell our servers who's asking.

We use no advertising SDKs, no session-replay or analytics SDKs, and no third-party embeds anywhere in the app or the site. If we ever add a new pixel, embed, or a cookie that isn't strictly necessary, we'll add a consent banner and update this section first. An automated check in our codebase holds us to that.

7. Your choices and rights

Your organization controls its roster. To see, correct or delete your member or delegate record, ask your organization. It can make the change in RosterVote. For your own account, you can view and sign out of sessions and manage two-factor sign-in on your account page. Every email has an unsubscribe link.

COUNSEL — jurisdictional rights sections (GDPR, CCPA, and any other applicable regimes) go here. Placeholder pending counsel; no jurisdiction-specific claims are made until this section is written.

8. Children

RosterVote is intended for organizational and meeting administration and is not directed to children. CONFIRM

9. Changes to this policy

When our data practices change, we will update this page and its "last updated" date. We will tell you about important changes in an appropriate way. COUNSEL

10. Contact

Questions about this policy: [email protected]. For data your organization controls, contact that organization directly.