Privacy Policy
Last updated: 2026-08-13
This policy explains what Competitive Campaigns collects, where it comes from, who else sees it, how long it is kept, and what you can do about it.
It is written to be read by a campaign manager, not by a lawyer. Where something is unfinished or imperfect, this policy says so rather than describing a system we do not have.
1. Who runs this service
Competitive Campaigns ("the Service") is operated by Competitive Campaigns ("we", "us"), a sole operator based in North Carolina. There is no support team, no data protection officer, and no third party administering the Service on our behalf. One person can read every record described in this policy.
Contact: support@competitivecampaigns.com. Postal address: We do not publish a postal address. The Service is run by one person in North Carolina and has no business premises to list. Write to support@competitivecampaigns.com and a person will answer. If you need a postal address to serve a legal notice or to exercise a right under a privacy law, ask at that address and we will give you one.
2. There are two very different groups of people in this system
Almost every privacy question about this Service turns on which of these two groups you are in.
Campaign users. These are the people who create an account and sign in: candidates, campaign managers, and their staff. You gave us your information directly, you agreed to our Terms of Service, and you can ask us to change or delete what we hold.
North Carolina voters. These are the roughly 8.4 million people in the North Carolina voter registration file. They never signed up for anything here and never agreed to anything. We did not collect their information from them. We copied it from public files published by the North Carolina State Board of Elections ("NCSBE"), which North Carolina law makes a public record under N.C.G.S. section 163-82.10.
Sections 3 and 4 below cover campaign users. Section 5 covers voters.
3. What we collect about campaign users
Account and identity
- Email address, which is your login.
- Display name.
- A bcrypt hash of your password. We never store the password itself and cannot recover it.
- The state your account works in, chosen at signup. Today that is North Carolina.
- Your role (user, admin, or owner) and account status (active or suspended).
- Your access level (locked, trial, or comped), when it was granted, and when it expires.
- The date your account was created.
- Whether you have opted out of notification email.
- If you have asked us to delete your account: the date you asked, the date it is erased, and whether we have sent you the warning email. All three are cleared if you reactivate.
Sign-in and sessions
- A server-side session record holding an opaque session id, its expiry, and when it was created. Signing out deletes the record, which immediately invalidates the cookie.
- A session cookie (
cm.session) in your browser. It is HTTP-only, Secure, and SameSite=Lax, and it carries only a signed reference to the session record, never your identity or password. - If you sign in with Google or Apple: the provider's permanent account identifier, the email address the provider asserted, and the first and most recent sign-in times. We store the provider's identifier rather than the email, so changing your email at Google does not detach your account.
- Short-lived records for a sign-in attempt in progress, holding hashed values only (a hashed state parameter, a hashed browser-binding secret, and the PKCE verifier and nonce). These are single-use, expire in minutes, and are deleted about an hour after they expire.
- If you request a password reset: a SHA-256 hash of the reset token, its expiry, and whether it was used. The token itself only ever exists in the emailed link. A completed reset revokes every session on the account.
Security and abuse prevention
- Rate-limit counters keyed by IP address or account id, for example
login:ip:203.0.113.7. These hold a key, a count, and a window, and they are deleted after they expire (opportunistically, so a row can outlive its window by a while). - Administrative audit records. Every privileged action taken in the admin console writes one permanent record containing the administrator's id and email, the action, the target, a one-line summary, structured details about what changed, the administrator's IP address, and the time. These records are append-only. There is no way to edit or delete them, by design.
Billing
- If you start a paid subscription: your Stripe customer id, Stripe subscription id, plan, subscription status, current period end, and whether a cancellation is scheduled.
- We do not receive or store card numbers, expiry dates, or CVCs. Those go directly to Stripe.
- No one is being charged today. Stripe is running in test mode. Paid plans exist in the software and are not switched on.
Notification records
- One record per notification email we send you: the kind, the subject line, the provider, the provider's message id, whether it succeeded, any error, and the time.
What you create in the product
- Campaigns: campaign name, candidate name, party, and the race you selected.
- Saved lists: the list name and either the saved filter settings or a snapshot of which voters were on the list.
- Saved win-number scenarios: the full projection result at the time you saved it.
- Tags you create and apply to voters.
- Outreach records: for each voter you target, the campaign, the voter's state id number, the channel, the outcome, the message text you entered, and the time. See section 6 on what outreach does and does not do today.
What we do not collect
We do not use analytics, advertising trackers, session recording, heat maps, or any third-party JavaScript. There are no cookies other than the sign-in cookies described above and the short-lived cookie that binds an external sign-in to your browser. We do not track you across other websites and there is no "Do Not Track" behavior to configure, because there is nothing doing the tracking.
4. Why we use campaign user information
- To let you sign in and stay signed in.
- To decide what your account may reach, which is what the locked, trial, and comped access levels do.
- To operate the product features you use: campaigns, lists, exports, projections, and AI queries.
- To bill you, if and when paid plans are switched on.
- To send you service email: a welcome message, password resets, notices that your data is stale or a sync failed, new candidate filings in your race, election countdowns, and the two account deletion notices described in section 8. You can turn off everything except password resets and the deletion notices, which are about losing access to your account and to your data.
- To stop abuse: rate limits on sign-in, signup, password changes, access-code redemption, AI queries, exports, outreach, and billing.
- To keep an accountable record of administrative actions.
We do not sell information about you, we do not share it for advertising, and we do not use it to train any machine learning model.
5. What we hold about North Carolina voters
Where it comes from
Every voter record in the Service is derived from public files published by NCSBE and, for a subset of derived statistics, from public precinct-level election results, public campaign finance filings, and the public candidate filing list. We do not buy voter data from vendors, we do not merge in consumer data, and we do not add anything a campaign tells us about a voter except the tags and outreach records that campaign creates itself.
North Carolina law makes voter registration records public. The same law makes certain fields confidential and they are not in the published files: full or partial Social Security numbers, full dates of birth, driver's license numbers, and signature images. We do not have those fields and cannot obtain them here.
What we store per voter
- Names: first, middle, last, and suffix.
- Residential address, city, state, and ZIP code.
- Mailing address lines, city, state, and ZIP code.
- Telephone number, where the source file contains one.
- Registration status and the reason for that status.
- Registration date.
- Party affiliation.
- Race code, ethnicity code, and gender code.
- Birth year and age. We store no day or month of birth, and the AI feature is instructed never to expose birth dates.
- State of birth.
- County, precinct, municipality, ward, and every district assignment in the file: congressional, NC House, NC Senate, judicial, superior court, county commission, township, school, fire, water, sewer, sanitation, rescue, municipal, and voting tabulation district.
- The statewide voter identifier (NCID) and the county registration number.
- The confidentiality flag described in section 7.
- The date we loaded the record, and the date it disappeared from the source file if it has.
- A vote propensity score we compute (how many of the qualifying elections we have loaded the voter has a history record for) and the list of elections that score was computed from, which is also its denominator.
We also hold, linked to a voter by their NCID:
- Vote history. One record per ballot cast per election: the election date and description, the voting method, the party ballot taken in a primary, and the precinct and county. Whether a person voted is public record in North Carolina. How they voted is not, is not in the source file, and is not here.
- Absentee and early ballot requests. Request type, request date, send date, return date, and return status, from NCSBE's cumulative absentee export.
- A change journal. When a nightly sync sees a field change on a voter, we record which fields changed and their old and new values.
Why we hold it
To let a campaign see the electorate in its own district, build targeted lists, estimate turnout and a win number, and produce canvassing and mail lists. This is the entire purpose of the Service.
The legal basis, stated plainly
We process this data because it is a public record that North Carolina publishes for exactly this kind of use, and because campaigns have a legitimate interest in contacting the voters they seek to represent. Voters did not consent to this and we do not claim they did.
6. Who else receives data, and exactly what they receive
These are every third party that receives anything. Each one is listed with what actually crosses the boundary, because the difference matters.
Anthropic (the Claude API)
Used for two features, and only two.
Natural-language voter queries. When you type a question on the AI page, we send Anthropic:
- A generated description of our database structure: table names and column names only, with no data in it.
- A glossary of North Carolina code values, for example what each party and status code means.
- The question you typed.
Anthropic returns a SQL query. We do not send any voter data to Anthropic. The returned query is executed on our own database, under a restricted read-only role, against a view already narrowed to your campaign's district and already excluding confidential voters. The results go straight from our database to your browser. They are never sent back to Anthropic.
If you type personal information into the question box, that text is sent to Anthropic as part of your question. Do not type a voter's name, address, or phone number into the AI query box.
Campaign finance narratives. For the race money page, we send Anthropic the contest name, the report date, and for each committee in the race the candidate name, committee name, and total raised, total spent, and cash on hand rounded to the nearest hundred dollars. All of that is public campaign finance disclosure data. No voter data is included.
Anthropic is not permitted to use this data to train its models under its commercial API terms. If no Anthropic API key is configured, nothing at all is sent to Anthropic and the AI features return a "not configured" notice.
Resend (email delivery)
Resend delivers notification email to campaign users only. It receives the recipient's email address, the subject line, and the message body. The message bodies are: a welcome message, a password reset link, a data-staleness or sync-failure notice, a list of newly filed candidates in your race (public candidate filing information), an election countdown, and the two account deletion notices.
No voter records are sent to Resend. If no Resend key is configured, these messages are written to our server log instead of being delivered.
Stripe (payments)
When you start a checkout, we create a Stripe customer using your email address and display name, tagged with your internal account id, and a checkout session tagged with the same id. Stripe collects and holds your payment details directly; they never reach our servers. Stripe tells us your subscription status, plan, and period end. Stripe is currently in test mode and no real payments are being processed.
Render (hosting and database)
The application and the Postgres database both run on Render in the virginia region, which is in the United States. Everything in this policy is stored there. Render is our hosting provider and has the access to infrastructure that any hosting provider has.
Google and Apple (optional sign-in)
Only if you choose to sign in with Google or Apple. They learn that you are signing in to this Service. We receive the account identifier, email address, and display name they assert.
NCSBE and other public sources
We fetch public files from NCSBE. We send them nothing about you or about any voter.
Everyone else
No one. There are no data brokers, no advertising networks, no analytics vendors, and no marketing platforms in this system.
A note on outreach
The Service has an outreach feature that can target a saved list by SMS, phone, email, mail, or canvass. Today it sends nothing. Every channel is wired to a logging provider that writes a record of the attempt and performs no external communication at all. No voter has ever been contacted through this Service. If that changes, this policy will be updated with the provider's name and what it receives, and the version marker at the top of this document will change.
7. Voters with confidential addresses are excluded
North Carolina protects the address of certain voters. Under N.C.G.S. section 163-82.10(e), a registered voter's address is kept confidential if they give their county board of elections a domestic violence protective order, a restraining order, or a valid authorization card from the state Address Confidentiality Program, together with a statement that publishing their address would endanger them or their family.
The Address Confidentiality Program is established by Chapter 15C of the North Carolina General Statutes and administered by the North Carolina Attorney General. It exists so that victims of domestic violence, sexual offenses, stalking, and human trafficking can be reachable by government without their real address becoming a public record. Participants are given a substitute address, and disclosing or obtaining a participant's real address without authorization is a criminal offense under Chapter 15C.
NCSBE marks these voters in the published file with a confidentiality indicator. Wherever that indicator is set, the Service excludes the voter from every place a campaign could see or use them: the voter browser, every CSV export, the printable walk list, the AI query results, and outreach targeting. The exclusion is enforced twice, once in the ordinary database layer and once in the SQL view the AI feature queries, so a query cannot reach around it.
To be exact about what this does and does not mean:
- These voters are still stored in our database, because they are in the file we load. They are filtered out of every read path, not omitted from the copy.
- The exclusion depends on the flag being set correctly in the NCSBE file. If a voter has protection that is not reflected in the published file, we cannot know about it.
- Excluding a voter here does not affect their status anywhere else. Only the county board of elections can set or change the flag.
If you believe you should be excluded and are not, contact your county board of elections, and contact us at support@competitivecampaigns.com so we can check what our copy of the file says.
8. How long we keep things
We would rather tell you the truth than quote a retention period we do not enforce.
| What | How long |
|---|---|
| Voter registration records | Indefinitely. Records are never hard deleted. When a voter leaves the source file we mark the date they disappeared and keep the record, because saved lists and history may reference it. |
| Vote history records | Indefinitely. These are append-only. NCSBE's file covers a rolling ten-year window; records we loaded are kept after they age out of that window. |
| Absentee ballot records | Replaced in full each time the source file is reloaded for an election. |
| The voter field-change journal | Indefinitely. Nothing deletes these. |
| Your account and everything attached to it | Until you delete it. Deleting soft deletes immediately and hard deletes three months later. See below. |
| Sessions | Until they expire, you sign out, you change your password, or a password reset completes. Any of those removes them immediately. |
| Password reset tokens | 60 minutes, single use, and all outstanding tokens are deleted when a reset completes. |
| Sign-in attempt records for Google and Apple | Minutes, then deleted about an hour after expiry. |
| Rate-limit counters | Until the window expires, then removed opportunistically. |
| Notification delivery records | Until the account is deleted. |
| Administrative audit records | Indefinitely, including after the account they refer to is deleted. This is deliberate: an accountability log that can be erased is not an accountability log. These records contain the affected user's email, display name, and role. |
| Stripe records | Governed by Stripe's retention, and by the record-keeping obligations that apply to payment records. |
What "delete my account" does.
There is a delete button in your account settings, and it works in two stages.
Immediately, when you press it:
- You are signed out on every device.
- Your account can no longer reach any part of the product.
- Any paid subscription is cancelled outright in Stripe, so you are not charged again during the three months that follow. We do not leave billing running through a grace period.
- We email you to confirm, and the email names the exact date your data is erased.
- Nothing is erased yet. Every record listed below is still here, untouched.
Three months later, by a scheduled job:
Everything is permanently erased. We email you a warning a week beforehand, so a deletion you regret and forgot about is not silently final. That email goes out whether or not you have turned off notification email, because it is a notice about permanent data loss rather than a digest.
During those three months, you can change your mind.
Sign in with the same email address and password, or the same Google or Apple account, and we offer to bring the account back. Everything returns exactly as you left it. There is no link to click and nothing to ask us for. An administrator can also restore it for you if you would rather ask.
Your email address stays reserved for the whole three months, so signing up again with it will not work until either you reactivate or the account is erased. This is deliberate: releasing the address would make the account you can still recover unreachable, and would hand your identity to whoever claimed it first.
Exactly what is erased at the end of the three months:
your account record, your sessions, your linked Google and Apple accounts, your password reset tokens, your notification delivery records, your subscription record, your access code redemptions, your legal acceptance records, your campaigns, the races you created for them, your saved lists and their members, your saved win scenarios, your tags and every voter you applied them to, and your outreach records.
Exactly what is not erased, and why:
- The North Carolina voter file, vote history, and the voter change journal. These are the public records described in section 5. They are not yours and they are not about you: one copy is shared by every campaign using this Service, and deleting it would break every other campaign's product while doing nothing about the file NCSBE publishes. If you are a voter who wants to be excluded, section 9 explains the mechanism that actually works, and deleting a campaign account here is not it.
- Administrative audit records, as described above. They record that an account was deleted, and by whom, and they survive the deletion. An accountability log that can be erased is not an accountability log. These records contain the affected user's email address, display name, and role.
- Anything already delivered. Emails Resend has sent, and any CSV your campaign already downloaded, are outside our control.
- Records Stripe keeps. Cancelling a subscription does not erase Stripe's own record of the payments, which they retain under their own terms and under the record-keeping rules that apply to payment records.
There is no way to delete a single campaign. Campaigns can be archived, which hides them, and the record stays until the account is deleted.
9. Your rights, and how to use them
If you are a campaign user
You can:
- See and correct your account details. Your name, email, and password are editable in settings.
- Get a copy of your data. Email us and we will export your account record, campaigns, lists, scenarios, and outreach records.
- Delete your account. There is a button in your account settings. It closes the account at once and erases everything three months later, and you can undo it at any point in between by signing in. Section 8 sets out exactly what is erased and what is not.
- Turn off notification email. There is a single switch in the product. Password reset email is not covered by it, because you need it to get back into a locked account.
- Complain. Email us first. If you are unsatisfied you may contact the North Carolina Attorney General's Consumer Protection Division.
We will respond to any of these within 30 days. We will verify that a request comes from the account holder before acting on it.
If you are a North Carolina voter
You can ask us:
- What we hold about you. Email support@competitivecampaigns.com with your name and county and we will tell you what our copy of the public file contains for you.
- To confirm your exclusion status. If you have a protective order or are enrolled in the Address Confidentiality Program, we will confirm whether our copy shows the confidentiality flag.
We cannot do the following, and we want to be straightforward about why:
- We cannot correct your registration record. Our copy is a mirror of the NCSBE file. If a field is wrong, it is wrong at the source, and correcting it here would be overwritten by the next sync. Contact your county board of elections.
- We cannot make you private by deleting our copy. A deletion here does nothing about the public file, other copies of it held by every other campaign and vendor in the state, or the next sync, which would reload you. The mechanism that actually works is the one North Carolina built for this: a protective order or the Address Confidentiality Program, filed with your county board of elections. Once the flag is set in the published file, this Service excludes you automatically.
- We cannot tell you who contacted you. Campaigns using this Service contact voters using data they export. We do not see or control what they do afterwards.
If a campaign contacted you and you want it to stop, tell that campaign. If you tell us which campaign, we will pass the request on, and repeated failure to honor opt-outs is grounds for us to terminate their account under our Terms of Service.
State privacy laws
North Carolina has not enacted a comprehensive consumer data privacy law. Bills have been introduced and none had passed as of this policy's date. We nonetheless offer the access, correction, and deletion rights described above to anyone who asks.
10. Security, described as it actually is
What is in place:
- All traffic is served over HTTPS, with HTTP Strict Transport Security, clickjacking protection, MIME-sniffing protection, and a restrictive referrer policy.
- Passwords are hashed with bcrypt at cost factor 12 and must be at least 10 characters. Sign-in failures run a dummy hash comparison so a response time cannot reveal whether an account exists.
- Sessions are server-side and revocable. The cookie is HTTP-only, Secure, and SameSite=Lax, and it carries only a signed reference to a session record.
- Every state-changing request must prove it came from our own site. Webhook endpoints are exempt and instead authenticate by cryptographic signature.
- Rate limits on sign-in (three separate layers), signup, password changes, access-code redemption, AI queries, both CSV export paths, outreach, and billing.
- The AI feature runs as a separate Postgres role that can only read a short list of tables and cannot write anything. Each AI query runs inside a transaction that is always rolled back, against a view scoped to that one campaign, with a five-second statement timeout.
- Every voter read is scoped to the campaign's own district, and voters with confidential addresses are excluded at both the application and SQL layers.
- Database network access is restricted to an IP allowlist.
- Administrative actions are recorded in an append-only audit log.
- Anthropic, Resend, and Stripe are each optional. With no key configured, the corresponding data never leaves at all.
What is not in place, so you are not misled:
- No SOC 2, ISO 27001, or any other security certification or audit.
- No third-party penetration test and no bug bounty.
- No security monitoring, intrusion detection, or alerting.
- No multi-factor authentication for user accounts.
- No email address verification. Nothing currently proves that a signup address belongs to the person who typed it.
- No application-level encryption of individual fields. Data at rest is protected by whatever the Render managed platform provides and nothing more.
- No formal incident response plan or tested backup restoration procedure.
This is a one-person operation and its security posture is the security posture of a one-person operation. Do not put anything into this Service that you would not put into a system with those properties.
If there is a breach. If we discover unauthorized access to personal information about North Carolina residents, we will notify affected people and the North Carolina Attorney General's Consumer Protection Division as required by N.C.G.S. section 75-65, without unreasonable delay.
11. Children
The Service is for adults running political campaigns. We do not knowingly create accounts for anyone under 18. North Carolina lets 16 and 17 year olds preregister to vote under N.C.G.S. section 163-82.1, so the published file may contain a small number of records describing minors. Those records come from the public file and are handled exactly like every other record in it. We do not seek them out and we have no relationship with the people they describe.
12. Where data lives
Everything is stored in the United States, in Render's virginia region. We do not transfer data outside the United States. Our subprocessors may operate globally; their own policies govern their internal infrastructure.
13. Changes to this policy
The version marker at the top of this document changes whenever the policy does. If the change is material, you will be asked to review and accept it the next time you sign in. Continuing to use the Service after a change means you accept the current version.
14. Contact
Competitive Campaigns support@competitivecampaigns.com
We do not publish a postal address. The Service is run by one person in North Carolina and has no business premises to list. Write to support@competitivecampaigns.com and a person will answer. If you need a postal address to serve a legal notice or to exercise a right under a privacy law, ask at that address and we will give you one.
For anything about a voter record, include your name and county so we can find the right record.