Privacy policy

NetaTrack collects the minimum data needed to run the platform, and publishes as little of it as possible.

What is collected

  • Account — name, email address, password hash, role and account status.
  • Participation — your ratings, poll votes and submitted issues.
  • Security — session records, login timestamps and a hashed form of your IP address for abuse detection.
  • Audit — a record of privileged administrative actions, for accountability.

What is never public

  • Your email address, phone number and account details.
  • Your identity as the reporter of a citizen issue.
  • Your identity as the author of an individual candidate rating.
  • Internal staff notes on any issue.
  • Any raw IP address.

Passwords and credentials

Passwords are stored only as a bcrypt hash and are never recoverable, logged or displayed. Email verification and password reset links are stored as SHA-256 hashes, expire, and can be used once. SMTP credentials live only in server environment variables and are never sent to a browser or mobile app.

Your controls

  • Update or delete your rating on any candidate at any time.
  • Revoke every active session from your account security page.
  • Enable multi-factor authentication on your account.
  • Request account deletion; published aggregate figures are recomputed without your data.

Retention

Sessions expire after 7 days. Verification and reset tokens expire within 24 hours and 60 minutes respectively. Audit records are retained for accountability and are not editable through the application.