Privacy Policy
At Polity (“Polity,” “we,” “us,” or “our”), we believe financial and civic transparency must coexist with strict personal privacy. This Privacy Policy details the limited data we collect, how anti-Sybil fingerprinting protects equal-voice governance, and how public ledger entries are handled.
Last Updated: September 4, 2026
Our Core Privacy Principles
1. Information We Collect
We collect only the minimum necessary information required to verify democratic participation, maintain financial custody, and coordinate campaign execution:
- Account & Contact Data: When you contribute or sign in, we collect your email address. We use this exclusively to authenticate you via magic links, send contribution receipts, and notify you of campaign milestone updates (such as when creative voting opens).
- Pseudonym or Public Display Name: During checkout, you may provide a public display name or pseudonym to be displayed alongside your contribution on our Public Ledger. If left blank or selected as anonymous, you appear as “Anonymous Civic Backer.”
- Creative Submissions & Ballots: When you exercise your Submission Right, we collect the graphic artwork and title you upload. When you cast a ranked-choice ballot, we record your candidate ranking preferences linked to your verified backer session.
- Technical Logs: Minimal standard server metadata (IP addresses, browser type, and timestamps) are collected temporarily for security auditing, DDoS mitigation, and rate limiting.
2. Payment Information & Sybil-Resistant Fingerprinting
All financial transactions are processed securely through Stripe, Inc., an audited PCI-DSS Level 1 Service Provider. Polity never collects, logs, or has access to your full credit card number, CVV code, or bank account credentials.
How Anti-Sybil Payment Fingerprinting Works
In digital governance, a “Sybil attack” occurs when an adversary generates dozens of fake identities to manipulate an election. Rather than forcing users through intrusive facial biometric scans or government identity uploads, Polity leverages Stripe’s institutional payment rails. Stripe provides a cryptographic, one-way payment method fingerprint. This mathematically confirms that multiple contributions are not secretly stemming from the same financial instrument, allowing us to enforce 1-person, 1-voice integrity without having to know or expose your legal identity.
3. Public Ledger & Transparency Disclosures
To prevent fraud and maintain public trust, Polity publishes a real-time, tamper-resistant Public Ledger. Here is what is publicly visible and what is kept strictly private:
| Data Field | Public Status | Purpose |
|---|---|---|
| Display Name / Pseudonym | Public | Community recognition on the ledger (customizable or anonymous). |
| Contribution Amount & Timestamp | Public | Verifiable escrow accounting and funding progress tracking. |
| Campaign ID & Transaction ID | Public | Cryptographic audit trail connecting fiat payments to on-chain escrows. |
| Email Address | Private (Never Public) | Used exclusively for magic link sign-in and campaign notifications. |
| Payment Card & Billing Info | Private (Never Handled by Polity) | Processed exclusively by Stripe via tokenized HTTPS endpoints. |
4. How We Use and Share Information
We process your information strictly for the following operational purposes:
- Campaign Execution: Verifying eligibility to vote, allocating voting ballots, and tallying ranked-choice elections.
- Escrow Reconciliation: Verifying funds against billboard vendor media invoices and issuing automatic 100% refunds if an MLT is not reached.
- Service Providers: We share necessary transactional data with trusted infrastructure providers: Supabase (database & auth hosting) and Stripe (payment processing). Each provider is bound by strict confidentiality and data protection obligations.
- Legal Compliance: We may disclose information if required by law, subpoena, or to protect the safety, security, and integrity of the platform and public billboard inventory.
5. Data Security & Storage
We implement industry-standard security safeguards to protect your personal information:
- All network traffic is encrypted in transit using modern Transport Layer Security (TLS 1.3 / HTTPS).
- Application databases enforce Row Level Security (RLS), ensuring backer records cannot be read or tampered with by unauthenticated actors.
- Internal API endpoints and automated cron workers communicate using cryptographically signed secrets and zero-trust service roles.
6. Your Rights & Choices
Depending on your jurisdiction (including GDPR, CCPA, and similar consumer privacy regulations), you may have the following rights:
- Access & Portability: You may request a copy of the personal information we hold about you.
- Pseudonymity: You can change your public ledger display name to an alias or request complete anonymous masking at any time.
- Deletion: You may request deletion of your user account. Please note that confirmed financial transaction records and aggregated election tallies must be retained to maintain legal accounting compliance and mathematical integrity of completed elections.
7. Contact Our Privacy Team
For privacy inquiries, data export requests, or questions regarding our anti-Sybil architecture, please reach out to:
Email: privacy@polity.vote
Subject: Privacy Rights Inquiry