Privacy
Ehlect privacy information
This page explains the information Ehlect uses to provide private campaign workspaces and related services.
Effective · Version 2026-08-13
Contacting Ehlect
Questions about this page or information handled through Ehlect can be sent to hello@ehlect.ca.
Information handled by the service
Ehlect handles account information needed for sign-in, email confirmation, multi-factor authentication, campaign membership, and subscription administration.
Campaign workspaces can hold campaign-provided records such as contacts, contact details, volunteer information, support levels, consent and suppression details, canvassing and phonebank assignments, interaction results, tasks, events and shifts, survey responses, public intake, lawn-sign requests, imports, privacy requests, and audit activity.
For individually reviewed business outreach, Ehlect may assign a message variant and use an opaque signup link to count best-effort link visits and connect a resulting account, campaign, and trial to the outreach record. The public link does not contain a recipient email, lead identifier, or account identifier.
Stripe handles payment details for Ehlect subscriptions. Ehlect stores the Stripe customer, subscription, price, status, and billing-period information needed to provide and manage workspace access; Ehlect does not collect card numbers through its own forms.
How information is used
Information is used to authenticate users, enforce campaign-specific permissions, provide requested campaign operations, process public submissions for the selected campaign, deliver transactional messages, manage subscriptions, respond to support requests, and record security or operational activity.
Outreach attribution is used to compare message variants and understand trial conversion. A first-party, HTTP-only attribution cookie can remain on the Ehlect application for up to 30 days so the connection can survive email confirmation, multi-factor authentication, campaign setup, and Stripe Checkout.
Ehlect does not offer campaign donations, mass SMS, or AI targeting as part of the current service.
Service providers
- Vercel hosts and delivers the Ehlect application.
- Supabase provides the database, authentication, storage, and related hosted services. Supabase Auth email uses provider-native Custom SMTP through Resend.
- Twilio Email delivers application-generated transactional email and campaign marketing email from authenticated campaign-owned domains.
- Microsoft 365 is used by the operator to send individually reviewed platform outreach from Outlook.
- Stripe provides subscription Checkout, billing, invoices, and the customer billing portal.
These providers process information needed to perform their part of the service. Ehlect does not claim that campaign information stays exclusively in Canada.
Campaign boundaries and access
Each campaign is a separate workspace. Protected access uses Supabase authentication, verified multi-factor authentication, live campaign membership, fixed role permissions, and campaign-scoped database controls. Volunteers receive only the limited information needed for their current assignments.
Campaign owners and authorized administrators decide who belongs to their campaign and are responsible for the campaign information they enter or connect to Ehlect.
Public forms and campaign websites
A campaign may connect reviewed public contact or lawn-sign forms to its Ehlect workspace. Those forms identify the campaign receiving the submission and ask for the applicable consent before storing the request.
Ehlect publishes an included editable one-page campaign site at the campaign's Ehlect subdomain. The private operations workspace remains separate from the public site, and the site's own published privacy information may also apply.
Retention, security, and requests
Ehlect includes campaign controls for privacy requests, retention processing, account access, and campaign lifecycle. The period for keeping a specific record depends on the campaign context, configured controls, and applicable obligations; this page does not promise a single fixed retention period.
Ehlect records email delivery and estimated open events for up to 90 days, then retains campaign-level aggregates.
For manually sent platform outreach, Ehlect records best-effort click counts and trial conversion, but does not use a tracking pixel and does not store a raw IP address or device fingerprint for this attribution. Automated email-security scanners can follow links, so a recorded click may not represent a person; trial conversion is the primary measure.
No online service can promise absolute security. Ehlect uses access controls, multi-factor authentication, campaign isolation, private application tables, audit records, and restricted runtime roles to protect private campaign information.
To ask about access, correction, deletion, a campaign submission, or an Ehlect account, contact hello@ehlect.ca. Ehlect may need to confirm the requester and coordinate with the campaign responsible for the record.
