Action Precinct

Privacy Policy

Last updated: July 22, 2026

This Privacy Policy explains how Action Precinct handles information when you visit actionprecinct.com or use our campaign-management platform (the "Service"). It works together with our Terms of Service.

Who we are and how this policy works

Action Precinct ("Action Precinct," "we," "us," "our") is a campaign-management platform operated by Precinct Technologies, Inc. This Privacy Policy explains what information we handle and how, for visitors to actionprecinct.com and for the campaigns, committees, party organizations, and their authorized staff ("Customers") who use the Service.

We act in two different roles. For information about our Customers and their staff — the accounts you create with us and how you use the Service — we are the "controller" and this policy governs. For the information a Customer loads into the Service about other people (for example, voter files, donors, and contacts), the Customer decides why and how that information is used; there, we act as a "processor" that handles the information on the Customer's behalf and under our Terms of Service. If you are a voter, donor, or other individual whose information a campaign has loaded into the Service, please direct requests to that campaign (see "Information about voters, donors, and other individuals" below).

Information we collect

Account and profile information

When a Customer's staff member is added to the Service, we collect their name, email address, role and permissions, and authentication identifiers. Sign-in is handled by our authentication provider (Auth0 by Okta); we do not see or store your password. We record which sign-in method you use (e.g., email/password or Google) so administrators can manage the team.

Information you load into the Service ("Campaign Data")

Customers use the Service to manage the data of a political campaign. Depending on which features a Customer uses, this can include:

  • Voter and constituent records — names, addresses, phone numbers, email addresses, party and turnout indicators, district assignments, and vote-history and modeled scores that Customers import from voter-file providers or state sources.
  • Donor and contribution records — names, addresses, contribution amounts and dates, employer/occupation, and processor references, together with the compliance information required for campaign-finance reporting (e.g., FEC or state filings).
  • Contacts and supporters — names, contact details, tags, and interaction notes.
  • Communications and content — press releases, mailings, talking points, media contacts, calendar events, tasks, media-buy records, and files.
  • Documents and photos you choose to connect from a third-party service (see "Google Drive integration").

We handle Campaign Data on the Customer's instructions to provide the Service. The Customer is responsible for having the right to collect and use it (see "Customer responsibilities").

Information from connected integrations

A Customer may connect optional third-party services to their own account — such as ActBlue (contributions), Mailchimp (email), or Google Drive (files). When they do, we receive the specific data those services return for the connection (for example, contribution records, mailing-list membership, or the files a user picks), and we store the connection's access credentials in encrypted form. We only access what is needed to provide the connected feature, and only for the Customer that connected it.

Billing information

If a Customer subscribes to a paid plan, payment is processed by our payment provider (Stripe). We receive limited billing details (such as plan and subscription status) and do not collect or store payment-card numbers — card details go directly to Stripe.

Information collected automatically

To operate and secure the Service we log technical and usage information — IP address, browser and device type, pages and features used, timestamps, and audit records of actions taken in an account. We use strictly necessary cookies to keep you signed in and to secure the session. We do not use third-party advertising cookies, and we do not use third-party analytics or ad-tech trackers.

How we use information

  • To provide, maintain, and secure the Service and its features.
  • To authenticate users, enforce roles and permissions, and keep audit records.
  • To provide customer support and respond to requests.
  • To send service and transactional messages (for example, invitations, password resets, and important notices).
  • To process subscriptions and billing.
  • To monitor, debug, prevent abuse, and protect the safety and integrity of the Service.
  • To comply with law and enforce our Terms of Service.

We do not sell personal information, and we do not use Campaign Data for advertising or to build advertising profiles.

Artificial-intelligence features

Some optional features use a third-party AI provider (Anthropic) to assist Customers — for example, suggesting how the columns of an uploaded file map to our fields, or answering questions about a Customer's own data. These features are designed to minimize what is sent to the model. For the import-mapping feature, only column headers and de-identified, masked samples of the shape of the data are sent — not the underlying personal records. When a Customer uses the AI assistant to ask about their own data, the specific records needed to answer (for example, donor names and giving totals for a "top donors" question) are shared with the AI provider for that request. AI output is a suggestion that a person reviews and applies; it is not legal, financial, or compliance advice. We do not permit our AI provider to use Customer data to train generalized models.

Google Drive integration

Action Precinct offers an optional integration that lets a Customer connect its own Google Drive to browse, preview, and attach documents and photos inside the Customer's workspace. Our use of information received from Google APIs adheres to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

When you connect Google Drive, we request access only to the specific files you select using the Google file picker (the "drive.file" scope) plus your Google account email address (to show which account is connected). We do not request access to your entire Drive and cannot see files you do not explicitly choose.

We store an encrypted access credential for the connected account, references to the files you pick (Google file ID, name, type, size, thumbnail, and "open in Drive" link), and your account email. A file's contents pass through our servers only when you preview it or choose to save a copy into your workspace; if you do not save a copy, we do not retain the file's contents. Google Drive data is used solely to provide this feature. We do not sell it, do not use it for advertising, and do not use it to train generalized AI/ML models. You can disconnect at any time from the Files settings (which deletes the stored credential) and can revoke access directly with Google at myaccount.google.com/permissions.

How we disclose information

We share information only as needed to run the Service and as described here. We do not sell personal information.

  • Within a Customer account — with the Customer and its authorized users, according to the roles and permissions the Customer sets. Data is isolated per Customer account; one Customer cannot access another Customer’s data.
  • Service providers (subprocessors) — vendors that host and support the Service and act on our instructions, including: Amazon Web Services (cloud hosting, database, storage, and secrets, in the United States); Vercel (front-end hosting/CDN); Auth0 by Okta (authentication); Anthropic (AI features); Resend and Amazon SES (transactional email); Stripe (billing); and Mapbox and the U.S. Census Bureau geocoder (maps and address geocoding, used to place records on a map).
  • Customer-connected integrations — ActBlue, Mailchimp, Google, and similar services that a Customer chooses to connect to their own account.
  • Legal and safety — to comply with law, legal process, or lawful requests; to enforce our terms; or to protect the rights, property, or safety of Action Precinct, our Customers, or others.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.

How long we keep information

We keep account and Campaign Data for as long as the Customer’s account is active and as needed to provide the Service. A Customer can delete records within the Service, and can request export or deletion of their account data on termination, subject to a short period to complete deletion from backups and to any legal-retention obligations (for example, campaign-finance records the Customer must retain). Connected-integration credentials are deleted when the integration is disconnected.

How we protect information

We use administrative, technical, and organizational safeguards designed to protect information, including: encryption of data in transit; encryption of sensitive credentials at rest; tenant isolation enforced at the database layer so each account’s data is fenced from others; role- and permission-based access controls; optional multi-factor authentication for sensitive actions; audit logging; and least-privilege access for our systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we learn of a security incident affecting personal information, we will notify affected Customers and applicable regulators as required by law.

Your choices and rights

Depending on your role and where you live, you may have rights to access, correct, delete, or receive a copy of personal information we hold about you, and to object to or restrict certain processing. If you are a Customer or an authorized user, you can access and update much of your information within the Service, or contact us using the details below. Where we act as a processor for Campaign Data, we will refer your request to, or act on the instructions of, the relevant Customer.

You can control cookies through your browser, but disabling strictly necessary cookies may prevent you from signing in.

Information about voters, donors, and other individuals

If you are a voter, donor, constituent, or other individual whose information a campaign has loaded into the Service, that campaign — not Action Precinct — determines how your information is used. Please direct requests to access, correct, or delete your information to the campaign or committee that holds it. If you are unsure who that is, you may contact us and we will make reasonable efforts to route your request to the appropriate Customer.

Customer responsibilities

Customers are responsible for the lawfulness of the Campaign Data they load and the messages they send using the Service — including complying with applicable election and campaign-finance laws, voter-file use restrictions, and communications laws (for example, laws governing calls, texts, and email). The Service provides tools to help, but does not guarantee compliance and does not provide legal advice.

Where we operate

The Service is operated from and hosted in the United States and is intended for use by U.S. political campaigns and organizations. If you access it from outside the United States, you understand that your information will be processed in the United States.

Children

The Service is not directed to children under 16 and is intended for use by authorized campaign staff. We do not knowingly collect personal information directly from children. (Voter or constituent records a Customer uploads are governed by the Customer’s own obligations.)

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.

Contact us

Questions about this policy or your information? Contact us at legal@precincttechnologies.com (or contact@precincttechnologies.com for general inquiries), or by mail at Precinct Technologies, Inc., 2809 E Hamilton Ave #4048, Eau Claire, WI 54701.