Version 2, effective 2026-09-18.
Privacy Policy
Ballot is operated by Yost Group LLC. This policy explains what we collect, why, who else touches it, how long we keep it, and what you can ask of us. It applies to the marketing site at runballot.com and the application at app.runballot.com.
1. Two kinds of people
Associations are our customers. Their administrators create accounts and upload rosters. Members of those associations are voters. We hold voter data on behalf of the association, which decides who is on the roster and what the election is for. If you are a voter with a question about why you received a notice, the association that sent it is the right first contact; its support address is on every notice.
2. What we collect
- Administrator accounts. Name, email address, a salted hash of the password, an authenticator-app secret for multi-factor authentication, roles, and session records.
- Rosters uploaded by associations. Member id, name, email address, membership category, status, and optional group or office fields the association chooses to include. We do not enrich, verify, or merge this data on our own.
- Voter access records. When a member requests a code or link we record the hashed credential, its expiry, the number of attempts, and a throttling key derived from the email address and source address. When a ballot is accepted we record that the member participated, with a random receipt code. Voter sessions are held in a secure cookie for the duration of the vote.
- Ballots. The selections made and the date. A ballot row does not contain a member id, email, IP address, access token, or any key that links it to a participation record.
- Notice delivery. For each notice we send: recipient, template, and the status reported by our email provider (queued, accepted, delivered, bounced, suppressed).
- Billing records. For a paying association: the billing contact's name and email, the billing address and any tax identifier given at checkout, the tax-exempt status we have recorded, and the ledger of charges, credits, and refunds. Card numbers are entered on Stripe's pages and never reach us; we hold only Stripe's references.
- Audit trail. Administrative actions and approvals with the acting administrator, time, and the change made. Never credentials or ballot choices.
- Operational logs. Request logs for security and debugging, kept briefly, without credentials or ballot choices.
The marketing site collects nothing beyond standard server request logs. It sets no cookies and loads no third-party scripts.
3. Why we use it
To run the elections an association configures: verify eligibility, send notices, accept one ballot per eligible member, tally, certify, and produce the audit record. To secure the service: detect abuse, throttle enumeration attempts, and investigate incidents. To bill associations and to answer support requests. We do not sell data, share it with advertisers, or use it to train models.
4. Who else processes it
These are our subprocessors. Each acts on our instructions under written terms and its own security and privacy commitments. We keep this list current and notify account owners before adding to it.
- Railway (United States) hosts the application and its managed PostgreSQL database, including backups. It holds everything listed above.
- Resend (United States) delivers email notices and receives delivery, bounce, and suppression signals. It sees recipient addresses and the content of the notices sent.
- Stripe (United States) processes payments. It holds the billing contact's name and email, the billing address, any tax identifier, tax-exempt status, and payment-method details that it collects on its own pages. Stripe's privacy policy governs its use of that data; it also acts as an independent controller for fraud prevention and regulatory purposes.
No subprocessor receives ballots or voter access records except Railway, which stores them.
5. How long we keep it
- Election records, including rosters, participation, and ballots, are kept for the retention period the association's owner approves. The default is 24 months after certification.
- Voter credentials expire within minutes and cannot be used afterwards. Voter sessions expire within an hour.
- Administrator accounts persist for the life of the association's account.
- When an association closes its account we provide a final export on request and delete its data from the live system within 30 days. Backups are retained for no more than 90 days after that, then expire; we do not restore a closed association's data from a backup except to recover from a failure of the service.
- Billing records are kept for as long as tax and accounting rules require, which is generally seven years, even after an account closes.
6. Your rights
Administrators can view and correct their own account details in the application. Associations can export everything they own at any time. Members may ask their association to correct or remove their roster record; because ballots are not linked to members, an accepted ballot cannot be identified or withdrawn. Depending on where you live you may have additional rights to access, correct, delete, or restrict the use of your personal data. Write to info@yost.group and we will respond within 30 days. If we hold your data on behalf of an association we may need to refer the request to it.
7. Cookies
The application sets session cookies only: one for an administrator session and one for a voter session, both marked secure and HttpOnly. There are no analytics, advertising, or tracking cookies, and no third-party cookies of any kind. The marketing site sets none.
8. Security
Traffic is encrypted in transit, data is encrypted at rest, credentials are stored as hashes, and administrator access is protected by multi-factor authentication. The security overview describes the controls in detail. If you find a vulnerability, please tell info@yost.group.
If something goes wrong. If we confirm a security incident affecting an association's data, we notify that association's account owner without unreasonable delay and in no case later than 72 hours after confirming it, with what we know, what we have done, and what we recommend, so the association can meet its own notice duties to members.
9. Children
The service is directed at membership organizations and their adult members. It is not directed to anyone under 16, and we do not knowingly collect personal data from children. Associations should not include minors on a voting roster.
10. Changes
We will post any change to this policy with a new version number and effective date, and notify account owners by email of material changes.
11. Contact
Yost Group LLC. Privacy questions: info@yost.group. See also the terms of service.