Privacy notice
What we collect, why we need it, where it lives, and how to have it removed.
Last updated 6 August 2026
What we collect
About members of your district: name, email address, club, member number, and the role that decides their vote. A phone number only if they give one for text reminders.
About people who sign in: email address and sign-in history.
For security: the IP address a voting link is opened from, so we can spot a link being shared or attacked.
We do not use tracking cookies or advertising trackers.
How votes are recorded
When your meeting chooses an anonymous ballot, the vote is stored without any link back to the person who cast it. We have deliberately built it so that we cannot reconstruct that link either.
When your meeting chooses a recorded vote, the ballot names the voter — because that is what your meeting decided it should do.
Why we are allowed to hold it
We hold it to run the service your district asked us to run. Your district decides what goes in; we process it on your instructions.
Who else touches it
We use a small number of suppliers to run Red Vote: Supabase (database), Google Cloud (servers), Paddle (payments), Resend (email), Twilio (text messages), Upstash (rate limiting), Sentry (error reports), and OpenAI and DeepL for the optional document-assistant and translation features.
We do not sell your data, and we never share it with advertisers.
Where it is kept
Your district’s data is stored in a database in Canada. The application that reads it runs on servers in the United States, so data is processed there in the course of serving your pages, and some suppliers above operate outside Canada.
How long we keep it
While your district is active, we keep it. When a district closes, we delete its data thirty days later.
One thing survives on purpose: for each certified meeting we keep a record that the meeting happened, when it was certified, who signed it, and a cryptographic fingerprint of its audit trail. That record contains no member names, no contact details and no votes. It exists so anyone holding an exported audit bundle can still prove it has not been altered.
Seeing or removing your data
Ask us at vote@taverns.red and we will tell you what we hold about you, correct it, or remove it. Your district’s administrators can also remove a member’s details directly.
When we remove someone, we clear their name, email, phone number and any contact details we copied elsewhere. One thing we cannot remove is the audit trail of the meetings themselves. It is built to be tamper-evident, which means entries cannot be altered or deleted without destroying the proof that the results are genuine. So the trail keeps a note that a removal took place and which fields were cleared — but not the name, the address or anything else that was cleared.
Complaints
Write to us first at vote@taverns.red. If we cannot sort it out, you can complain to the Office of the Privacy Commissioner of Canada, or to your province’s privacy regulator.
Questions about any of this? vote@taverns.red.