Privacy policy
Privacy
What we collect, why we collect it, every company that receives it, and how to get your data out or deleted. Written from the code, not from a template.
Last updated 12 August 2026
ClubPolls.io is decision software for university clubs. This policy covers clubpolls.io, dash.clubpolls.io (the officer console), user.clubpolls.io (the member surface), and the emails we send on a club’s behalf.
Two kinds of people appear in this policy. Officers create an account, run a club workspace, and pay for it. Members are on a club’s roster, answer polls, vote, and RSVP — usually without ever creating an account. Most member data reaches us because an officer put it there. Section 8 is about exactly that.
1. What we collect
From officers who create an account
- Email address and password. Authentication is handled by Supabase Auth; we never see or store a plaintext password.
- Display name, and an avatar URL if one is set.
- Club details you enter: name, URL slug, description, university, category, time zone, and an estimated member count.
From officers, about their members
Officers add members by pasting a list, importing a CSV, or sharing a join code. The roster stores, per member:
- Email address (required — it is how a member is identified).
- Name, if supplied.
- Role (owner, admin, officer, member, advisor), an optional officer title, and status (invited, pending, active, inactive, alumni, suspended, removed).
- Graduation year, if the officer imported or entered one.
- Dues status, if the officer records it.
- Whether the member is eligible to vote.
- Tags and segments an officer assigns (for example “committee” or “first-year”), used to decide who a poll goes to.
- When they joined, and when they were last active.
From members, as they use the product
- Poll answers: selected options, rankings, ratings, numbers, dates, and free-text written answers.
- Election nominations, candidate records, and ballots, including ranked-choice ballots.
- Event RSVPs: yes / no / maybe, guest count, when you responded, whether you checked in, when, and by which method (manual, QR code, RSVP confirmation, or CSV import).
- Whether an invitation was opened and completed, and how many reminders were sent.
- Notification preferences, including whether you unsubscribed.
Records the system creates
- A delivery record for every email we send: the recipient address, the subject, the message type, whether it sent or failed, any error, the provider’s message id, and timestamps.
- Audit log entries for officer actions: who acted, what they did, on what, and when.
- Decision records: the outcome an officer recorded, the reasoning they wrote, and whether it differed from the poll result.
- Billing records for a paying club: the Stripe customer and subscription identifiers, plan, status, and the current period end.
What we do not collect
- Card numbers. Card details are typed into a form served and rendered by Stripe. They never reach a ClubPolls server. See section 4.
- No advertising identifiers, no cross-site tracking, no data brokers, no selling or sharing of personal data for advertising.
- We do not ask for a date of birth, a student ID number, a government ID, a home address, or a phone number.
2. Anonymous polls stay anonymous
A poll set to anonymous stores no link between a response and the member who submitted it: the response row carries no member id at all, and nothing else in the record points back to one.
The fact that you took part is recorded separately, on your invitation rather than on your answers — which is how a club can show a member voted without being able to show what they voted for. On an anonymous poll that completion time is rounded to the hour, and CSV exports write “anonymous” in the identity columns and round submission times the same way, so a timestamp cannot be used to match a ballot to a person.
Polls that are not set to anonymous are identified, and officers can see who said what. The poll tells you which it is before you answer.
3. Why we use it, and on what basis
- To run the club’s polls, elections, and events. This is the service itself: sending invitations, counting responses, enforcing eligibility and quorum, tracking RSVPs and check-ins. Necessary to perform our contract with the club, and in the legitimate interest of the club and its members in having the club actually function.
- To send transactional email — invitations, reminders, closing notices, result announcements, RSVP confirmations. Same basis. Members can turn these off; see section 9.
- To take payment from clubs on a paid plan. Necessary to perform our contract with that club, and to meet our own tax and accounting obligations.
- To keep the service secure and accountable — audit logs, rate limiting, signed one-time links. Our legitimate interest in preventing abuse and in letting a club prove what happened in its own election.
We do not use member data to train any machine-learning model, our own or anyone else’s.
4. Payments
Paid plans are billed through Stripe. Checkout is rendered inside our page, but the fields you type your card into belong to Stripe and are served from Stripe’s own frame. Card numbers, CVCs, and expiry dates never touch a ClubPolls server and are never stored by us.
What we send Stripe when a club starts checkout:
- The identifier of the plan being purchased and the billing interval.
- The club’s internal id, as a reference so we can match the payment back.
Stripe collects the billing name, email, card details, and country directly from the person paying, under Stripe’s own privacy policy. What comes back to us is a customer id, a subscription id, the plan, the status, and the period end date. Nothing else.
5. AI features
Some officer-facing features are AI-assisted: drafting poll questions from a plain-language goal, checking draft questions for leading wording, grouping free-text answers into themes, and writing a plain-English narrative or a draft announcement from results that have already been counted. Every one is labelled in the interface.
These run on fal.ai, which routes the request to a model through OpenRouter. The model in use today is DeepSeek v4 Flash; it is a configuration value and may change.
What is sent to that provider:
- Poll and question titles.
- Already-computed vote counts and percentages — numbers, not ballots.
- The goal an officer typed when asking for draft questions.
- The literal text of free-text answers, when an officer asks for theme grouping. If a member writes their own name or anything else identifying into a written answer, that text goes with it. Nothing strips it.
What is not sent:
- Member names, email addresses, roster records, or any respondent identity. Free-text answers are sent as an unattributed list.
- Ballots, individual response rows, or election records.
- Payment data.
AI never counts a vote, decides eligibility, changes an election rule, alters a ballot, or publishes a result. It writes drafts an officer reads and edits. Turning the provider off disables every AI feature and leaves the rest of the product working.
6. Who else receives your data
This is the complete list of companies that process personal data on our behalf.
- Supabase — the database and authentication system. Everything in section 1 that we store, is stored there.
- Cloudflare — hosts and serves both this site and the application, and processes request metadata such as IP addresses as part of delivering and protecting them. Cloudflare also provides the cookieless Web Analytics on this marketing site; see section 7.
- Resend — delivers our email. Receives the recipient’s address, the subject, and the message body, which typically contains the member’s name, the club name, the poll or event title, and a one-time link.
- Stripe — payments. See section 4.
- fal.ai, and through it OpenRouter and the model provider it routes to — AI features. See section 5.
Integrations a club chooses to turn on
These are off by default. An officer connects them per club, and can disconnect them at any time.
- Slack — we request permission to post messages and to list channels. We post poll announcements, reminders, result announcements, and event announcements: a title, a short body, and a link. We do not read your Slack messages.
- Discord — a bot is added to the server with permission to send messages, and nothing else. Same content as Slack. We do not read your Discord messages.
- Google Calendar — we request permission to manage calendar events and to read the email address of the connecting Google account, which we store as a label so an officer can tell which account is connected. When an officer syncs an event we send Google the event title, description, location, start and end times, a link back to ClubPolls, and any attendee email addresses that officer typed into the invite field. We do not read your calendar.
Once data reaches Slack, Discord, or Google it is governed by that company’s own privacy policy, not this one.
7. Cookies, sessions, and analytics
Nothing on this site or in the product sets a tracking cookie. There are no advertising cookies, no third-party trackers, and nothing that follows you to another website.
This marketing site runs Cloudflare Web Analytics — how we know whether anyone reads these pages. We picked it because it is the least invasive option we could find. It sets no cookies and stores nothing on your device, and Cloudflare does not fingerprint you: it does not identify you by IP address, user agent, or any other fixed attribute, and it cannot follow you to another website.
What it reports, in aggregate: page views, which page was visited, the referring site, and your country, device type, browser, and operating system. There is no profile, no visitor id, and no way for us to tie any of it to a named person.
It runs for every visitor to this marketing site, wherever in the world you are. It does not run inside the application, and it does not run on the poll, RSVP, check-in, or unsubscribe links we email to members — there is no analytics of any kind on the pages where a member answers a poll or casts a ballot.
The application sets session cookies when an officer or member signs in. They are issued by Supabase Auth, are strictly necessary to keep you signed in, and are scoped to the host that set them — being signed in as a member on user.clubpolls.io does not sign you into the officer console on dash.clubpolls.io. There are no advertising or cross-site tracking cookies anywhere in the product.
Members who answer a poll from an emailed link are not signed in at all. The link carries a one-time token; we store only a SHA-256 hash of it, never the token itself, so a copy of our database cannot be used to reconstruct a working link. The same applies to RSVP links, event check-in codes, and unsubscribe links.
8. If you were added by someone else
Officers import rosters, which means your name and email can be added to ClubPolls by a club officer rather than by you. We think you should hear that plainly.
In that arrangement the club is the party that decides what member data to collect and why; we process it on the club’s instructions. That does not leave you without recourse. If you were added to a club and would rather not be:
- Every email we send on a club’s behalf carries an unsubscribe link that works without an account and without a login.
- Ask the club’s officers to remove you from the roster. They can do it themselves, immediately.
- Or write to [email protected] and we will act on it, and tell the club we did.
9. Getting your data, or getting rid of it
Write to [email protected] from the address the data is held under. We will respond within 30 days. There is no charge.
- A copy of your data. We will send you everything we hold that is linked to you, in a machine-readable format. Officers on a paid plan can also export a poll’s results to CSV themselves at any time.
- Correction. Officers can edit roster fields directly. Ask us if the club cannot fix it.
- Deletion. We will delete your roster record and the personal data attached to it. Two honest limits: answers to a poll that was run anonymously carry no link to you, so there is nothing to find and delete; and where deleting a ballot would invalidate a completed election another club’s members relied on, we will tell you so rather than silently do half of it.
- Stop the email. Use the unsubscribe link in any message. You can switch off reminders, results, and event mail separately, or all of it at once. Unsubscribing does not remove you from the roster; ask for deletion if that is what you want.
- Objection and restriction. If you are in a jurisdiction that grants those rights, you have them here. Write to us.
- Deleting an officer account or a whole club. Email us and we will remove the workspace and everything in it.
If you are in the UK or EEA and think we have handled this badly, you can complain to your national data protection authority. We would rather you told us first.
10. How long we keep it
A club’s decision record is the point of the product — results are meant to outlast the officers who ran them — so we keep club data for as long as the club workspace exists, and we do not automatically expire old polls.
- Roster records are kept until an officer removes the member or the club asks us to delete the workspace.
- Poll responses, ballots, RSVPs, and decision records are kept for the life of the workspace, so a club can look back at what it decided and why.
- Email delivery records (recipient, subject, status) are kept as the club’s proof that a notice went out.
- Billing records are kept for as long as tax and accounting law requires, which is longer than the subscription.
- Deleted workspaces are removed from live systems on request; encrypted backups roll off on our providers’ own schedules.
Ask us to delete something sooner and we will, subject to section 9.
11. Security
Data is encrypted in transit and at rest by our hosting providers. Access to a club’s data is enforced in the database itself, not only in the interface. One-time links are stored as hashes. Payment webhooks are rejected unless they carry a valid signature. Integration access tokens are held in a table with no read path for any signed-in user.
No system is perfect. If we discover a breach affecting your personal data, we will notify affected clubs and, where the law requires it, the relevant regulator.
12. Where your data is processed
ClubPolls is operated from the United States, and our providers — Supabase, Cloudflare, Resend, Stripe, and fal.ai — process data on infrastructure that includes the United States. If you use ClubPolls from outside the US, your data is transferred there.
13. Age
ClubPolls is built for university clubs, whose members are mostly but not exclusively adults. It is not directed at children under 13 and we do not knowingly collect their data. If you believe a club has added a child under 13 to a roster, tell us at [email protected] and we will remove the record.
14. Changes to this policy
The “last updated” date at the top of this page always reflects the current version. If we make a change that materially affects what we collect, who receives it, or what we do with it, we will email the account address of every club owner at least 14 days before it takes effect, and note the change here.
15. Contact
Questions, requests, and complaints: [email protected]. A real person reads it.