Campaigns trust Votera with some of the most sensitive information in local politics — who their supporters are and what was said at the door. This page explains, in plain language, how that information is protected: where it lives, who can see it, and what happens to it when the election is over.
Votera is built and operated by ThreeDay Digital / BIZIBIZI INC. It is a multi-tenant platform: every campaign gets its own logins and its own isolated data, on infrastructure hosted in Canada. For the full legal detail, see our Privacy Policy.
The short version. Your campaign's data is stored in Canada, isolated from every other campaign, encrypted in transit and at rest, and backed up daily. It is never sold and never used for advertising. When the election is over, you can take all of it with you — or have us delete it — with a single request to info@votera.ca.
On this page
1. Built around Canadian privacy law
Votera is made for Canadian municipal campaigns, and our practices are aligned with the principles of PIPEDA — the Personal Information Protection and Electronic Documents Act — including accountability, consent, limiting collection and use, safeguards, and individual access. PIPEDA has no certification program, so we won't wave a badge at you; instead, here is what alignment looks like in practice:
- Consent-based collection at the door. Canvassing data is recorded from what residents choose to share in conversation with your volunteers. The campaign directs what is collected and why.
- Purpose limitation. Data collected for your campaign is used only to run your campaign's field program. We never sell it, mine it, or use it for advertising — and no other campaign can see it.
- Access, correction & deletion. Residents can ask what information a campaign holds about them and have it corrected or deleted. Requests are honoured through the campaign that collected the data, and we help route and fulfil them.
2. Canadian data residency
Campaign, volunteer, and voter contact data is stored in our database infrastructure hosted in the Canada Central region (ca-central-1). Data at rest stays in Canada — it is not mirrored to servers in other countries. For campaigns that get asked "where does our voter data live?", the answer is one word: Canada.
3. Per-campaign isolation
Votera is multi-tenant by design. Every campaign is its own tenant with its own logins, and every query is scoped to that tenant — there is no shared pool of voter data. Your volunteers see your campaign and nothing else. If your opponent also uses Votera, neither of you can see the other's data, full stop.
4. Encryption in transit and at rest
- In transit: every connection to Votera — mobile apps, web app, and API — is encrypted with TLS 1.2 or higher. There are no unencrypted endpoints.
- At rest: the database and its backups are encrypted on disk using industry-standard AES-256 encryption.
5. Role-based access: admins vs. volunteers
Access inside a campaign follows the campaign's own chain of command:
- Administrators get the full command center — voter file imports, exports, team management, turf assignment, and reporting.
- Volunteers get what they need to knock doors — their turf, their doors, and the ability to log conversations. No exports, no bulk views, no account management.
The same principle applies inside our own company: production access is limited to the small number of people who operate the service, and only for operating it.
6. Account security
- Every team member signs in with their own account under the campaign's tenant — no shared passwords.
- Passwords are stored only as salted bcrypt hashes; they can never be read back, not even by us.
- Two-factor authentication via SMS one-time codes is supported to protect sign-ins.
- Administrators can remove a team member's access instantly when someone leaves the campaign.
7. Daily backups & disaster recovery
The database is backed up automatically every day, and backups are encrypted and kept in the same Canadian region as the live data. In the unlikely event of an infrastructure failure, we restore from the most recent backup — an election has hard deadlines, and our recovery planning is built around never costing a campaign its ground game.
8. Retention, export & deletion
Your data stays available for as long as your campaign keeps its account. You are never locked in:
- Full export on request. A campaign administrator can request a complete export of the campaign's data in standard, portable formats at any time — before, during, or after the election.
- Deletion on request. When a campaign wraps up, we delete or de-identify its data on request within a reasonable period, except for records we are required by law to retain.
9. Subprocessors
We keep the list of providers that touch service data short, and each one processes data only to help us run Votera:
- Supabase — database, authentication, and storage hosting in the Canada Central region.
- Netlify — hosting and delivery of the votera.ca website.
- Google Maps — mapping and geocoding inside the canvassing app.
- Twilio — delivery of SMS verification codes for two-factor authentication.
10. Reporting a vulnerability
Responsible disclosure. If you believe you've found a security vulnerability in Votera, email info@votera.ca with "Security" in the subject line. We read these promptly, we'll keep you informed as we investigate and fix, and we will not pursue legal action against good-faith security research.
Candidates, campaign managers, and clerks doing due diligence are equally welcome at the same address — we're happy to walk your team through any of the above. Email info@votera.ca.