Privacy policy
NetaTrack collects the minimum data needed to run the platform, and publishes as little of it as possible.
What is collected
- Account — name, email address, password hash, role and account status.
- Participation — your ratings, poll votes and submitted issues.
- Security — session records, login timestamps and a hashed form of your IP address for abuse detection.
- Audit — a record of privileged administrative actions, for accountability.
What is never public
- Your email address, phone number and account details.
- Your identity as the reporter of a citizen issue.
- Your identity as the author of an individual candidate rating.
- Internal staff notes on any issue.
- Any raw IP address.
Passwords and credentials
Passwords are stored only as a bcrypt hash and are never recoverable, logged or displayed. Email verification and password reset links are stored as SHA-256 hashes, expire, and can be used once. SMTP credentials live only in server environment variables and are never sent to a browser or mobile app.
Your controls
- Update or delete your rating on any candidate at any time.
- Revoke every active session from your account security page.
- Enable multi-factor authentication on your account.
- Request account deletion; published aggregate figures are recomputed without your data.
Retention
Sessions expire after 7 days. Verification and reset tokens expire within 24 hours and 60 minutes respectively. Audit records are retained for accountability and are not editable through the application.