Skip to content
Web Ballot

Legal

Privacy policy

What Web Ballot collects, why, who can see it, and what your choices are.

Last updated 25 September 2026

1. Overview

This policy explains what personal information Web Ballot collects, why, who can see it, and what your choices are. In short: we collect what is needed to run a fair, auditable election, we show voters only totals and never how an individual voted, we do not sell your information, and we do not use advertising trackers. We use Google Analytics on our public pages only, never on sign-in pages or once you are signed in (see “Cookies”).

2. Who is responsible

Web Ballot is provided by Lync Systems. Each election is run by an election organiser (for example a school, association or company) which decides who is on the voter list and why. The organiser is responsible for its election data; Lync Systems runs the platform on its behalf and handles the data only to provide the service.

For questions about a specific election, contact its election officers. For anything about the platform itself, see “Contact” below.

3. What we collect

Your account

  • Your name, email address and role (voter, commissioner or administrator).
  • Your password, stored only in scrambled (hashed) form. If you turn on two-factor authentication, its secret is stored encrypted, plus hashed recovery codes.
  • For commissioners, a designation and contact phone number.

Your part in an election

  • Which elections you belong to, and whether you have voted.
  • Your ballot choices, and the time you voted.
  • Your receipt code, and whether you were registered as present in person.

Technical details

  • When you vote: your IP address, browser, operating system and device type, and an approximate location (country, region, city and time zone) worked out from the IP address.
  • When you sign in, open pages or make changes: your IP address and browser details, in the audit trail.
  • Emails we send you, such as your login details or a password reset link, and in-app notifications.

4. What is shown about your vote

Web Ballot never shows any user how an individual voted: results are shown only as totals per candidate. Your receipt, the badge and the public receipt check confirm that a vote was recorded, and when, but never who you voted for. The badge shows the election, the date and your initials only.

5. Why we use it

  • To let eligible people sign in, vote once, and receive proof that their vote was recorded.
  • To count votes and publish results for the election organiser.
  • To keep elections secure and to detect problems such as shared devices, repeated failed sign-ins or unusual voting locations.
  • To keep an audit trail, so an election can be checked afterwards.
  • To send you the emails you need, and to give you help when you ask.

6. Who can see it

  • Administrators can see accounts, voter lists, the audit trail and the voting audit (who voted, when, and from where).
  • Commissioners can see the details of the elections they run, including the voter roster and results.
  • Voters see their own account, their own receipt, and results only for elections they belong to, once published.
  • Anyone with a receipt code can check that it is genuine. That page shows the election and the time, not who voted.

7. Other companies involved

  • Location lookup. Unless the operator has switched it off, the IP address of a vote is sent to a third-party lookup service (currently ipwho.is) to estimate where it came from. Private and local addresses are never sent, and the lookup happens after your vote is confirmed.
  • Bot check. The sign-in form and the “Set up an election” request form may use Cloudflare Turnstile to tell people from automated programs. When it is on, your browser talks to Cloudflare while the form loads, and Cloudflare receives your IP address and some browser signals to decide whether you are a person.
  • Analytics. Our public pages (the home page, the voting tutorial, the “Set up an election” form, and the terms and privacy pages) use Google Analytics to count visits and see which pages are read. Google receives your IP address and details about the page and your browser, and sets cookies. It is not used on the sign-in and password-reset pages, and not anywhere once you are signed in, so it never sees your ballot or your activity in an election.
  • Fonts. Your browser loads the site’s font from Google Fonts, which means Google can see your IP address when a page loads.
  • Hosting and email. The service runs on hosting and email providers chosen by the operator, which handle data only to deliver the service.

We do not sell personal information, and we do not use it for advertising.

8. Cookies

The service itself uses only the cookies it needs to work: a session cookie that keeps you signed in, and a security cookie that protects forms against forgery. We do not use advertising cookies.

Our public pages (see “Other companies involved”) also use Google Analytics, which sets its own cookies to tell visitors apart and count visits. You can block these in your browser settings, or use Google’s opt-out add-on (tools.google.com/dlpage/gaoptout). The service works the same if you do.

9. How long we keep it

Election records, including votes, receipts and the audit trail, are kept for as long as the election organiser needs them to run, verify and, if necessary, defend the election. Accounts can be removed by an administrator. Removing an account does not change votes already cast in an election.

10. Security

We protect your information with measures such as hashed passwords, optional or required two-factor authentication, role-based access, and an audit trail of who did what. No system is perfectly secure, so please keep your login details private and sign out on shared devices.

11. Your choices

You can ask to see the personal information held about you, to have it corrected, or to have your account removed, and you may object to how it is used. Ask your election officers, or use the contact below. We may have to decline or limit a request where it would compromise the integrity of an election or where the law requires us to keep a record. You can change your password, and set up two-factor authentication, under Settings once you are signed in.

12. Changes to this policy

We may update this policy as the service changes, and will change the “last updated” date above when we do.

13. Contact

For questions about this policy or your information, submit a support ticket at support.lyncsystems.tech, or contact your election officers. See also our Terms of use.

Questions about this page? Submit a support ticket at support.lyncsystems.tech.