KnockListCampaign field operations Product

Privacy and data use

Privacy Policy

This policy explains how KnockList handles information across its website, manager portal, and iOS and Android field apps. It also explains the separate responsibilities of KnockList and the campaign or organization that supplies field records.
Effective August 3, 2026

1. Scope and roles

KnockList is operated by Seaside Security LLC. We provide field-operations software to campaigns, committees, civic organizations, and their authorized teams.

For campaign-supplied records, the customer organization decides why the records are used and who may access them. KnockList handles those records as a contracted service provider or processor under the customer's instructions. For website visits, support, security, and our own account administration, KnockList determines the limited processing described here.

2. Information we handle

  • Account and organization data: name, work email, role, organization, campaign memberships, invitations, authentication and account status.
  • Authorized campaign records: fields supplied by the organization under its source license or lawful public-record request, such as source identifiers, names, addresses, household links, and manager-approved operational flags. The first release does not accept voter participation history.
  • Field activity: turf assignments, doorstep outcomes, approved questionnaire responses, operational notes, follow-ups, opt-outs, timestamps, and synchronization status.
  • Map and route data: campaign-assigned stop coordinates and road-route endpoints. The first mobile release does not request or transmit the operator's device location and does not request background location.
  • Device, security, and audit data: device grants, app version, sign-in and revocation events, idempotency keys, error categories, access changes, imports, exports, and deletion actions.
  • Billing administration: organization plan, customer and subscription identifiers, invoice status, and billing contacts. A hosted payment provider collects card details; KnockList does not receive or store full card numbers.
  • Support communications: messages and information a person chooses to provide when asking for help or exercising a privacy right.

3. How information is used

We use information to authenticate authorized users; import and validate approved files; prevent duplicates; create, assign, and route turf; support offline work and synchronization; record neutral field outcomes and surveys; enforce opt-outs and permissions; provide aggregate operational reporting; administer organization subscriptions; protect the service; support users; and satisfy documented retention, audit, and legal obligations.

We do not use campaign records for advertising, sell them, combine them into a cross-campaign person graph, or use them to build a consumer data marketplace.

4. Political-data boundaries

Voter participation history is not vote choice. KnockList never claims a ballot selection is public. The first release rejects participation-history fields. Any future support would require an approved source-license and jurisdiction-specific policy before import is enabled.

The product does not generate individualized political persuasion based on sensitive personal traits and does not infer ideology, protected characteristics, or a person's secret ballot. Customers may use only fields and purposes permitted by their source, jurisdiction, contract, and campaign compliance obligations. KnockList may quarantine, reject, suspend, or delete data that fails those controls.

5. When information is disclosed

Information is available only to authorized members of the customer organization according to their roles and assignments. A volunteer should receive only the active field packet assigned to that person.

We may use vetted infrastructure, storage, security, support, mapping, and payment providers under contract. Mapping providers may receive the minimum map area or route endpoints needed to load a road map or calculate a route, but KnockList is designed not to send names, survey answers, or notes with that request. When the Mapbox road map is enabled on Android, Mapbox may also receive unidentified map-usage telemetry under its settings and privacy terms; the map's attribution control includes Mapbox's telemetry choice. We may also disclose information when legally required, to protect people or the service, or during a business transaction subject to appropriate safeguards.

KnockList does not share campaign records with unrelated campaigns or political beneficiaries without documented customer authority.

6. Maps, mobile storage, and offline work

The first mobile release displays assigned campaign coordinates but does not request the operator's device location or background location. The in-app road map may contact its mapping provider to load the visible area. A user may also choose to open a stop in the device platform's external mapping app; that separate mapping service applies its own settings and privacy terms. Assigned campaign records and pending operations may be stored on a device to support offline work. Production deployments use encrypted device storage, short-lived assignments, backup exclusions, revocation, and purge controls.

7. Retention and deletion

Retention depends on the customer's source license, campaign purpose, election cycle, contract, legal obligations, and closeout schedule. Staged source files are designed to expire or be destroyed after an approved import. Assigned device packets expire or are removed when access ends.

A user may request deletion of the KnockList account and personal profile. Campaign-owned field events or audit evidence may need to remain with the customer organization for contract, security, dispute, election-law, or other legal reasons. When retained, those records are separated from the deleted sign-in profile where feasible and are not reused for advertising or unrelated campaigns.

8. Security

KnockList uses access controls, tenant and campaign scoping, encrypted transport, protected storage, expiring assignments, duplicate-safe operations, audit evidence, backup restrictions, and incident procedures appropriate to the deployment. No service can promise absolute security. Customers and users must protect invitations, credentials, devices, exports, and source files and report suspected misuse promptly.

9. Choices and rights

Depending on location and relationship to the customer organization, a person may have rights to access, correct, delete, restrict, object to, or obtain certain personal information. A field-record request may need to be handled by the campaign or organization that controls the record. KnockList will route or assist with a valid request and will not retaliate for exercising a privacy right.

Users can leave a campaign, sign out, and request account deletion. Doorstep opt-outs are recorded as suppression instructions for the relevant campaign workflow. If a later KnockList release adds device location, it will require a separate just-in-time disclosure, permission, and policy update before activation.

10. Children and changes

KnockList is an organization-directed professional tool and is not designed for children under 13. Organizations are responsible for confirming that their users and field operations comply with applicable age, labor, campaign, and consent rules.

We may update this policy as the service, vendors, or legal requirements change. Material changes will be dated and communicated through the service or customer organization when appropriate.

11. Contact

For privacy questions, rights requests, or security concerns, contact support@knocklistapp.com. Include “KnockList privacy” in the subject and identify the relevant organization or campaign without emailing voter-file rows or sensitive field records.