1. Scope and roles
KnockList is an independently operated field-operations service for campaigns, committees, civic organizations, and their authorized teams. The final operating legal entity will be identified here before store submission and production account activation.
For campaign-supplied records, the customer organization decides why the records are used and who may access them. KnockList handles those records as a contracted service provider or processor under the customer's instructions. For website visits, support, security, and our own account administration, KnockList determines the limited processing described here.
2. Information we handle
- Account and organization data: name, work email, role, organization, campaign memberships, invitations, authentication and account status.
- Authorized campaign records: fields supplied by the organization under its source license or lawful public-record request, such as source identifiers, names, addresses, household links, and manager-approved operational flags. The first release does not accept voter participation history.
- Field activity: turf assignments, doorstep outcomes, operational notes, opt-outs, timestamps, and synchronization status.
- Map and route data: campaign-assigned stop coordinates and road-route endpoints. The first mobile release does not request or transmit the operator's device location and does not request background location.
- Device, security, and audit data: device grants, app version, sign-in and revocation events, idempotency keys, error categories, access changes, assignment changes, and deletion actions.
- Android crash diagnostics: release builds may automatically send Firebase Crashlytics stack traces, relevant app and device state, app version, and installation or session identifiers so we can diagnose crashes and app-not-responding events. KnockList does not enable Firebase Analytics or deliberately attach names, campaign records, field notes, custom user IDs, custom keys, custom logs, or developer-recorded non-fatal events to these reports.
- Support communications: messages and information a person chooses to provide when asking for help or exercising a privacy right.
3. How information is used
We use information to authenticate invited users; provision and route authorized assignments; prevent duplicate field operations; support offline work and synchronization; record neutral doorstep outcomes, operational notes, and opt-outs; enforce permissions; protect the service; support users; and satisfy documented retention, audit, and legal obligations. The first mobile release does not offer file import, organization administration, surveys, dashboards, or subscription billing.
We do not use campaign records for advertising, sell them, combine them into a cross-campaign person graph, or use them to build a consumer data marketplace.
4. Political-data boundaries
Voter participation history is not vote choice. KnockList never claims a ballot selection is public. The first release rejects participation-history fields. Any future support would require an approved source-license and jurisdiction-specific policy before import is enabled.
The product does not generate individualized political persuasion based on sensitive personal traits and does not infer ideology, protected characteristics, or a person's secret ballot. Customers may use only fields and purposes permitted by their source, jurisdiction, contract, and campaign compliance obligations. KnockList may quarantine, reject, suspend, or delete data that fails those controls.
5. When information is disclosed
Information is available only to authorized members of the customer organization according to their roles and assignments. A volunteer should receive only the active field packet assigned to that person.
We may use vetted infrastructure, storage, security, support, and mapping providers under contract. Mapping providers may receive the minimum map area or route endpoints needed to load a road map or calculate a route, but KnockList is designed not to send names, doorstep outcomes, or notes with that request. When the Mapbox road map is enabled on Android, Mapbox may also receive unidentified map-usage telemetry under its settings and privacy terms; the map's attribution control includes Mapbox's telemetry choice. Configured Android release builds use Google Firebase Crashlytics as a reliability processor for the limited crash diagnostics described above. Google states that Crashlytics crash traces and their associated identifiers are retained for 90 days before removal begins. We may also disclose information when legally required, to protect people or the service, or during a business transaction subject to appropriate safeguards.
KnockList does not share campaign records with unrelated campaigns or political beneficiaries without documented customer authority.
6. Maps, mobile storage, and offline work
The first mobile release displays assigned campaign coordinates but does not request the operator's device location or background location. The in-app road map may contact its mapping provider to load the visible area. A user may also choose to open a stop in the device platform's external mapping app; that separate mapping service applies its own settings and privacy terms. Assigned campaign records and pending operations may be stored on a device to support offline work. Production deployments use encrypted device storage, short-lived assignments, backup exclusions, revocation, and purge controls.
7. Retention and deletion
Retention depends on the customer's source license, campaign purpose, election cycle, contract, legal obligations, and closeout schedule. Staged source files are designed to expire or be destroyed after an approved import. Assigned device packets expire or are removed when access ends.
A user may request deletion of the KnockList account and personal profile. Campaign-owned field events or audit evidence may need to remain with the customer organization for contract, security, dispute, election-law, or other legal reasons. When retained, those records are separated from the deleted sign-in profile where feasible and are not reused for advertising or unrelated campaigns.
8. Security
KnockList uses access controls, tenant and campaign scoping, encrypted transport, protected storage, expiring assignments, duplicate-safe operations, audit evidence, backup restrictions, and incident procedures appropriate to the deployment. No service can promise absolute security. Customers and users must protect invitations, credentials, devices, exports, and source files and report suspected misuse promptly.
9. Choices and rights
Depending on location and relationship to the customer organization, a person may have rights to access, correct, delete, restrict, object to, or obtain certain personal information. A field-record request may need to be handled by the campaign or organization that controls the record. KnockList will route or assist with a valid request and will not retaliate for exercising a privacy right.
Users can leave a campaign, sign out, and request account deletion. Doorstep opt-outs are recorded as suppression instructions for the relevant campaign workflow. If a later KnockList release adds device location, it will require a separate just-in-time disclosure, permission, and policy update before activation.
10. Children and changes
KnockList is an organization-directed professional tool and is not designed for children under 13. Organizations are responsible for confirming that their users and field operations comply with applicable age, labor, campaign, and consent rules.
We may update this policy as the service, vendors, or legal requirements change. Material changes will be dated and communicated through the service or customer organization when appropriate.
11. Contact
For privacy questions, rights requests, or security concerns, contact support@knocklistapp.com. Include “KnockList privacy” in the subject and identify the relevant organization or campaign without emailing voter-file rows or sensitive field records.
