Legal

Platform Privacy Policy

How Electbase — the platform at app.electbase.com — collects, uses, and protects account, campaign, and supporter data.

Effective August 31, 2026

Three different documents

This policy covers the Electbase platform itself. It's separate from the electbase.com marketing-site Privacy Policy (email signups on this site) and from each campaign's own generated Privacy Policy, published automatically at /privacy/ on every Electbase site — that page is the campaign's disclosure to its own supporters, in its own voice. Every campaign site names Electbase as its website provider and links here. See also our Data Processing Terms, which govern how we process Campaign Data on a campaign's behalf.

Who we are

Electbase is a service of BlueList AI LLC, an Arizona limited liability company. In this policy, "Electbase," "we," "us," and "our" refer to BlueList AI LLC.

Scope of this policy

This policy explains how Electbase collects, uses, discloses, stores, and protects information in connection with the Electbase platform and websites published through it. It applies to account owners and other authorized platform users; campaign, committee, and organization websites hosted through Electbase; supporter, volunteer, and donor information processed through those websites; payment and transaction records for subscriptions and donations; third-party accounts and services a campaign connects; and technical, security, support, and AI-drafting information generated through use of the platform.

Our roles

Our role depends on the information involved and why it's processed.

Campaign-directed processing. When a campaign uses Electbase to collect, host, organize, export, or transmit campaign content or supporter, volunteer, donor, or connector data for the campaign's own purposes, the campaign determines why that information is processed. In that context, the campaign acts as the controller or business, and Electbase acts as its processor, service provider, or contractor — see our Data Processing Terms for the specifics.

Electbase-directed processing. Electbase determines the purposes of processing needed to create and administer accounts and subscriptions; authenticate users and control access; secure, debug, and monitor the Service; administer billing, refunds, disputes, and fraud prevention; provide customer support; maintain tax, accounting, and legal records; and enforce our agreements. For these activities, Electbase acts as a controller or business.

Payment providers and connected services. Stripe and services a campaign connects may process information as our service providers or as independent controllers under their own terms and privacy notices. Campaigns should review those notices before enabling a service.

What we collect

Account and subscription information

Name, email address, phone number, account role, and authentication data; subscription status, invoices, payment status, refunds, disputes, and related Stripe identifiers; and communications with support. Stripe collects payment-card or bank-account details through its own payment interfaces — Electbase does not receive or store full card numbers or security codes. We do receive the transaction information needed to administer subscriptions and donations: amount, date, status, campaign identifier, Stripe identifiers, refunds, and disputes.

Campaign content and configuration

Content and settings supplied by account users to build and operate a site — text, images, disclaimers, domains, forms, integrations, and publishing settings.

Supporter, volunteer, and donor information

Whatever a campaign's forms collect — typically name, email, mailing address, phone number, volunteer interests, event responses, and (on donation forms) contribution amount, date, status, and transaction identifiers. Where a form includes the texting-consent checkbox, we store the checkbox state, a timestamp, and the page URL where consent was given — the record a campaign may need to prove consent to a carrier or texting vendor. Campaigns determine which fields they enable and are responsible for ensuring their own collection and use of them is lawful.

Connector and integration information

When a campaign connects a third-party account (Mailchimp, Google Sheets, Google Calendar, Google Analytics, Microsoft 365, NGP VAN, Slack, Notion, Calendly, and similar), Electbase holds the credential needed to sync data between the campaign's Electbase account and that connected account, at the campaign's direction and for that purpose only. When a campaign disconnects a connector, we delete the stored credential immediately — for Google-family connectors (Sheets, Calendar, Analytics) we also call Google's own revocation endpoint; for other connectors, the credential is deleted on our side and we recommend also revoking access from that provider's own account settings.

Google API information

Electbase's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Our Google Sheets connector requests only the restrictive drive.file scope (files the app itself created), and our Google Calendar connector requests only calendar.app.created (events the app itself created) — access is limited to what the campaign's configured sync needs. We use information from connected Google accounts only to provide and secure the function a campaign configures; we do not use it for advertising, and we do not use it to train a generalized machine-learning or AI model.

Technical information and cookies

Standard request logs from our hosting infrastructure (Google Cloud) — IP address, browser type, timestamps — kept for security and reliability. Our platform's own site analytics are cookieless and collect no personal information: they record only a page path, referring hostname, and campaign-tracking parameter, with no visitor identifier. We do not currently operate any third-party analytics, advertising, or session-tracking tools on the platform. We do not currently respond to browser Do Not Track or Global Privacy Control signals.

AI-assisted drafting

When an account user chooses an AI-assisted drafting feature, Electbase sends the text that user submits to Google Cloud Vertex AI (our production configuration uses Google's enterprise Vertex AI service, not the consumer Gemini app or AI Studio) and returns the generated draft. We don't use Campaign Data, including prompts or outputs, to train generalized AI models. For AI-assisted copy drafting specifically, we don't separately log your prompt or the generated text — only the draft you choose to keep is saved to your site. Other AI-assisted features work differently: for example, AI-generated logo concepts are stored, along with the prompt used to create them, so you can review and choose one before it's applied — that's a feature of how logo concepts work, not incidental logging. Campaign users shouldn't submit supporter or donor personal information to an AI drafting feature unless doing so is necessary, authorized by the campaign, and accurately disclosed to the individual.

How we use information

To create and administer accounts; host, publish, and secure campaign sites; receive and record supporter, volunteer, and donation submissions; administer subscriptions, donations, refunds, and disputes; operate campaign-configured connectors; provide support; generate drafts when a user selects an AI-assisted feature; detect and prevent security incidents and misuse; maintain backups; comply with legal and tax obligations; enforce our agreements; and evaluate aggregated, de-identified platform usage patterns to improve the product. When we use de-identified information, we take reasonable measures to keep it from being re-associated with an individual and don't attempt to re-identify it. Electbase does not sell personal information, does not share it for cross-context behavioral advertising, and does not use campaign or supporter data for our own advertising or to advertise to supporters on any campaign's behalf.

Who we disclose it to

We disclose information to: the campaign's own authorized account users; the infrastructure and service providers below; Stripe and other payment partners; the connectors and destinations a campaign selects; our professional advisers (legal, accounting, security); law enforcement or regulators when required by law; and, in a corporate transaction, a buyer or successor, subject to the commitments in this policy. Our vendors may use information only to provide their contracted service to us, and none is authorized to use it for its own purposes.

  • Google Cloud Platform — hosting, databases, file storage, authentication, and AI-assisted drafting (Vertex AI).
  • Cloudflare — DNS, domain registration, and bot-mitigation (Turnstile) on public forms.
  • Backblaze — secondary disaster-recovery backup, alongside Google Cloud Storage.
  • Stripe — subscription and donation payment processing.
  • Resend — transactional email (login links, notifications).
  • GitHub — source code hosting and deployment automation (does not process live Campaign Data).
  • The connectors a campaign configures — only the accounts a campaign connects, and only the data its configured sync sends there.

How long we keep it

  • Campaign content and supporter/donor records stay available in our active systems for up to 60 days after paid service ends, per the Billing Policy, so a campaign can resubscribe or export its data. After that, we delete or de-identify it unless a legal hold, dispute, or legal obligation requires otherwise.
  • Account and authentication information is retained while the account is active and deleted or de-identified after closure, except for limited security and legal records.
  • Connector credentials are deleted immediately when a connector is disconnected or an account closes, with provider-side revocation requested where supported (see "Connector and integration information" above).
  • Texting-consent and similar consent/revocation evidence records — the checkbox state, timestamp, and page URL, not your full contact record — are retained for four years after consent is given or, if later, revoked, since a campaign may need this evidence to demonstrate consent for that long. After four years, we delete or de-identify it.
  • Payment, transaction, and dispute records are kept for the periods reasonably necessary to meet our legal, accounting, fraud-prevention, and payment-network obligations. Stripe retains its own records under its own policies.
  • Technical and security logs follow Google Cloud's standard logging retention — ordinarily 30 days, and up to 400 days for the administrative-activity audit log category Google Cloud retains separately — unless a security investigation or legal obligation requires longer.
  • Backups are deleted on a rolling schedule — our Google Cloud Storage backups roughly every 30 days, our database backups on a 7-backup cycle — after which deleted information no longer persists there.

Electbase is not a campaign's campaign-finance system of record. Campaigns are responsible for their own recordkeeping obligations and should export required donation, consent, and supporter records before their subscription ends.

Security

Access to production data is controlled through IAM and service-account impersonation — we don't use long-lived service-account key files. Secrets are stored in Google Secret Manager, not in code. Data is encrypted in transit and at rest using our cloud provider's standard encryption. No security measure eliminates all risk, and we can't guarantee against every possible breach — this is the baseline we hold our own infrastructure to. If we discover a security incident affecting Campaign Data, we'll notify and assist the affected campaign as described in our Data Processing Terms.

Where information is processed

Electbase is based in the United States. Our primary hosting, database, and file-storage systems are configured in United States regions. Our AI-assisted drafting feature uses Google Cloud Vertex AI's global endpoint, which Google may serve from infrastructure in more than one region. We don't currently represent participation in the EU-U.S. Data Privacy Framework, Standard Contractual Clauses, or another international-transfer mechanism. The platform is presently intended for campaigns and organizations operating in the United States; a campaign shouldn't use Electbase to intentionally target individuals in a jurisdiction that requires additional data-protection safeguards unless we've first put those in place together.

Privacy choices and requests

Account users can review and update their account information and export Campaign Data through the dashboard, and may request correction or deletion of their Electbase-controlled account information. If a request concerns information a campaign controls — a supporter's or donor's own data — the requester should contact that campaign directly using its own site's Privacy Policy; if they reach us instead, we'll verify and forward the request to the campaign and assist as described in our Data Processing Terms. We won't disclose Campaign Data to a requester unless the campaign authorizes it or law requires it. Depending on where you live, you may have rights to access, correct, delete, or receive a portable copy of information Electbase controls, and to object to certain processing — we won't discriminate against you for exercising those rights. Submit a request through our contact form or email hello@electbase.com. We may ask for information reasonably necessary to verify your identity and the account or campaign involved.

Children's privacy

Electbase accounts aren't intended for children under 13, and children under 13 may not create an Electbase account. Campaigns must not use the Service to knowingly collect personal information from a child in violation of applicable law. If you believe a child submitted personal information through a campaign site, contact that campaign and us so it can be reviewed and, where appropriate, deleted.

Changes to this policy

We may update this policy as the Service and applicable requirements evolve. We'll update the effective date above and take reasonable steps to notify active account holders before a material change takes effect.

Contact

BlueList AI LLC, operator of Electbase. Questions about this policy or how Electbase handles data: contact us or email hello@electbase.com.

Not legal advice

This page describes our actual current practices in plain language. It isn't a substitute for legal counsel, and campaigns with their own compliance obligations should confirm requirements with their own counsel.