Legal
Privacy Policy
What we collect, why we collect it, and how we keep ballots unlinkable to the people who cast them.
Who we are
Fast Elections is a product of Votivigy LLC. Throughout this policy, "we", "us", and "our" mean Votivigy LLC. If you have any question about this policy or about your data, write to us at jason@fastelections.com — a person reads and answers that address.
What we collect
Organizer accounts. When you sign up to organize elections, we collect your email address and name through Amazon Cognito, our authentication provider. If you sign in with Google, Cognito receives the basic profile information Google shares for sign-in — your name and email — and nothing more.
Voter data. Organizers supply the roster for their own election: each voter's name and email address. We use that information only to deliver a voting link and, on elections with email delivery, reminder emails. We do not collect voter data ourselves and we do not ask voters to create accounts.
Payment information. Paid elections are processed through Stripe's hosted checkout. Your card number and billing details go directly to Stripe — they never pass through or touch our servers. We receive confirmation that a payment succeeded and a reference to the transaction, nothing more.
Analytics, only with consent. We use Google Analytics to understand overall traffic to our pages, and a consent banner asks before it stores anything: analytics cookies are set only if you choose "Accept all". Choosing "Essential only" — or ignoring the banner — keeps analytics in a cookieless mode that stores nothing in your browser. Either way, voting links are never shared with analytics: pages report only their generic route (for example "/vote"), never the secret token in a voter's link, and analytics never receives names, emails, or ballot contents. Your consent choice itself is remembered in your browser's local storage so we don't ask again.
What we don't collect. We run no advertising trackers and show no ads. Beyond the consent-gated analytics above, the only browser storage we use is the session token that keeps an organizer signed in, a voter's one-time voting-link token while their ballot is open, and your consent choice. There is no tracking pixel and no cross-site advertising cookie anywhere on Fast Elections.
How voting data works
Ballots are stored unlinkably. When a ballot is cast, nothing on it identifies who cast it — no name, no email, no account reference. The time a ballot was cast is rounded to the hour, so ballot order and timing can't be used to guess who voted which way. Each cast ballot generates a random receipt code that is not derived from, or tied to, the voter's identity in any way.
Organizers see who participated. Never how anyone voted. An organizer can see the turnout roster — which invited voters have cast a ballot and which haven't — because that's how they know an election is complete. What they can never see, and what we can never show them, is the connection between a specific voter and a specific set of choices. Once a ballot is cast, it is anonymous even to us.
Retention
Voting-link tokens automatically expire 180 days after they're issued, whether or not the voter used them, closing off any long-lived link into an old election.
Election data — the roster, the ballots, and the published results — is kept for as long as the organizer's account or organization remains active, so results stay available for reference. If an organizer asks us to delete their account or organization, we delete the associated election data. See "Voter and organizer rights" below for how to make that request.
Voter and organizer rights
Voters can unsubscribe from reminder emails at any time using the link included in every reminder — that stops future reminders without affecting their ability to vote using their original voting link.
Voters and organizers can request deletion of their personal data by emailing jason@fastelections.com. For an organizer, that means their account and their organizations' data; for a voter, that means removing their name and email from an organizer's roster once the request is confirmed with the organizer. Because ballots are already stored unlinkably, there is no voter identity attached to a cast ballot to delete in the first place.
Changes & contact
If we change this policy in a way that materially affects how we handle your data, we'll update the date below and, where practical, let active organizers know. Questions about anything in this policy can go to jason@fastelections.com.
Last updated: 2026-08-30. This policy was prepared without legal counsel, by the people who built the product. If anything here is unclear, ask us at jason@fastelections.com — we'd rather explain it plainly than leave it vague.