Privacy Center

How supporter, location, and photo data is handled

SignCommand 360 handles the addresses of people who ask for a yard sign, the coordinates where signs are installed, and photographs taken in residential neighborhoods. This page explains what is collected, why, who can see it, how long it is kept, and how to ask for it to be deleted. This page describes the platform's controls. It is not legal advice, and it does not replace the privacy notice each campaign publishes for its own supporters.

What data is collected and why

  • Supporter details

    Collected: Name, address, email, phone, preferred contact method, and the signs requested.

    Purpose: To deliver a yard sign to the right household, contact the resident before installation, and recover the sign afterwards.

  • Sign location

    Collected: GPS coordinates and accuracy captured when a sign is installed or recovered.

    Purpose: To find the sign again for maintenance and post-election recovery, and to confirm it was placed where it was authorized.

  • Placement photographs

    Collected: A photo of the installed sign, its timestamp, and the device accuracy reading.

    Purpose: To verify the work was completed correctly and to document damage, theft, or compliance questions.

  • Volunteer records

    Collected: Contact details, availability, training status, assigned routes, and completed work.

    Purpose: To schedule crews, confirm required training, and account for campaign inventory.

  • Operational records

    Collected: Inventory movements, routes, incidents, and security events such as sign-in failures and role changes.

    Purpose: To keep an accurate, auditable record of who did what with campaign property and campaign data.

Who can access it

Access is enforced in the database, not just in the interface. Every record belongs to a single campaign inside a single organization, and every read and write is checked server-side against the signed-in person's role in that campaign. A person who is not a member of a campaign cannot reach any of its records, no matter what link they follow.

  • Campaign administrators

    Full access to supporter records, exact addresses, photographs, exports, settings, and the security event log for their own campaign.

  • Campaign and warehouse managers

    Operational access to requests, inventory, routes, and placements. Access to exact addresses and exports follows the campaign's privacy settings.

  • Field captains

    Team, route, and verification access for the crews they lead.

  • Volunteers and contractors

    Addresses and supporter contact details only for the stops on a route assigned to them. Campaigns can switch off that access as soon as the route is completed.

  • Read-only and consultant roles

    Dashboards, maps, and reports with residential coordinates reduced in precision.

  • The public

    No access to supporter records, exact coordinates, photographs, or exports. The public request portal can accept a submission but can never read one back.

Location-data practices

  • Exact residential coordinates are visible only to roles a campaign has cleared for them. Everyone else sees coordinates rounded to street level or neighborhood level.
  • Volunteers see the address of a stop only while it is on a route assigned to them. Campaigns can revoke that access automatically the moment the route is completed.
  • Volunteer location is off by default. When a campaign turns it on, the app explains what will be recorded before a field session starts, and location is captured only during a session the volunteer chose to start.
  • Location data is never sold, shared with data brokers, or used for advertising.
  • Public maps, when a campaign enables one, show approximate or street-level points only. Exact coordinates are never published.

Photo practices

  • Placement and recovery photographs are stored in a private bucket. They are never publicly readable.
  • Photos are shown through short-lived signed links that expire, so a copied link stops working.
  • Uploads are limited by file type and file size, and are filed under the campaign that owns them so no other campaign can reach them.
  • Field guidance is to photograph the sign, not people. Photos should be tightly framed on the sign and its immediate surroundings.

How long it is retained

Each campaign sets its own retention periods in Settings → Data Retention: supporter records, placement photographs, location data, incident records, and audit logs each have their own window. When automatic purging is enabled, records older than the configured window are removed on a nightly schedule.

Security events and audit logs are append-only. They cannot be edited or deleted by campaign staff, and they are removed only when their retention window expires.

How to request deletion

A supporter can ask a campaign to delete their record at any time. Use the deletion request form on that campaign's yard-sign request portal, or contact the campaign directly. Requests arrive in the campaign's Security & Privacy console, where an administrator reviews and completes them.

Where a record must be kept for a legal or compliance reason, the campaign is expected to say so in its response rather than silently ignore the request.

Exports and administrator access

Data exports are limited to the roles each campaign authorizes, and every export is recorded in the security event log with who ran it and how many records it contained. Unusually large exports are flagged for administrator review.

What we never do

  • We do not sell supporter data or location data to anyone.
  • We do not use supporter addresses for advertising or ad targeting.
  • We do not publish supporter political preferences or make them publicly searchable.
  • We do not expose exact residential coordinates to roles that are not cleared for them.
  • We do not continuously track volunteers. Location is off by default and, when a campaign enables it, is recorded only during an active field session the volunteer starts.

Campaign and platform responsibility

The campaign is responsible for

  • What it collects and what it tells supporters when collecting it
  • Who it invites and the role it grants each person
  • Its privacy, retention, and export settings
  • Answering deletion and access requests from its supporters
  • Following the election and sign rules of its jurisdictions

The platform is responsible for

  • Keeping each organization's and campaign's data isolated
  • Enforcing role-based access in the database, not only the interface
  • Private photo storage with expiring links
  • Append-only audit and security event logging
  • Honoring configured retention periods and deletion workflows

This page describes product behavior. It is not a certification, an audit result, or legal advice. Campaigns should have their own counsel review their privacy notice and data practices.