Skip to content

Legal

Privacy policy

Last updated 27 August 2026

Membership of a political organisation is sensitive information. UK law treats it as a special category of personal data, and so do we. This page sets out exactly what we hold, why, for how long, and what you can make us do about it.

Who is responsible

Patriots Unite is operated by Digital Platforms Limited, the data controller, a company registered in England and Wales under number 17087275, registered office 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE. We are registered with the Information Commissioner's Office under reference ZC201671.

Contact us about anything on this page through our contact form.

What we collect

Your account
Your email address. Optionally a name, only if you choose to add one.
The email you upload
The original membership or sign-in email you provide, stored complete so a verification can be re-checked if it is ever challenged.
Verification records
Which organisation, what our checks concluded, and the evidence behind that conclusion. This includes the recipient address covered by the email's seal, and the date it was sent.
Technical information
A one-way salted hash of your IP address — never the address itself — and your browser's user-agent string, kept to detect abuse. Session records so you stay signed in.
Analytics
We use Google Analytics to count visits and see which pages people use. Nothing is stored on your device unless you accept— until then Google records the page address without any cookie or identifier, so visits cannot be linked to each other or to you. If you accept, it sets cookies that recognise a returning browser. You can change your mind at any time from the link in the footer. Your verification pages are reported as “Verification badge” only — the name on a badge is never sent to an analytics provider.

We do not use advertising trackers, we do not sell data to anybody, and we do not build profiles for marketing.

Our lawful basis

Verifying membership means processing data revealing political opinions — special category data under Article 9 of the UK GDPR. We rely on your explicit consent (Article 9(2)(a)), given when you upload an email for verification. You may withdraw it at any time by deleting your account, which removes the data.

For running your account and preventing abuse we rely on legitimate interests (Article 6(1)(f)) — operating a service you asked for, and keeping it from being misused.

What is public, and what is not

  • Your email address is never published and is never passed to the organisation you verify against.
  • Your name appears on a badge only if you add one and switch it on, and you decide that separately for each badge. The default is off.
  • Verification pages carry instructions telling search engines not to index them. They are meant to be shared by you, not found by someone searching your name.
  • A badge set to private cannot be resolved by anyone, including by someone holding the link.

How long we keep it

  • Uploaded emails: 12 months, then deleted automatically.
  • Your account and verifications: until you delete them.There is a delete button on your account page. It is immediate and permanent, and it removes your stored emails as well as your records.
  • Sessions and sign-in links expire on their own — links within fifteen minutes, sessions within thirty days.

Who processes data for us

We use a small number of suppliers, each bound by contract to process data only on our instructions:

  • Neon — database hosting (United States)
  • Cloudflare — file storage for uploaded emails (Western Europe), and site delivery
  • Resend — sending sign-in links and notifications (European Union)
  • Google Analytics — visitor statistics (United States), only if you accept cookies

International transfer. Our database and our visitor statistics are currently handled in the United States. Those transfers are covered by the UK International Data Transfer Addendum and Standard Contractual Clauses. We intend to move the database to a UK or EU region, and will update this page when we do.

Your rights

Under UK GDPR you may ask us to:

  • give you a copy of the data we hold about you
  • correct anything inaccurate
  • erase your data — the delete button on your account does this immediately
  • restrict or object to how we use it
  • provide it in a portable form
  • stop relying on your consent, by withdrawing it

Ask us and we will respond within one month. If you are unhappy with how we have handled it you can complain to the Information Commissioner's Office at ico.org.uk, or call 0303 123 1113. We would rather you told us first.

Security

Traffic is encrypted in transit. Sign-in links and session tokens are stored only as one-way hashes, so a database leak yields nothing usable to sign in with. There are no passwords to steal because we do not use any. Access to production systems is limited to those who need it.

No service can promise perfect security. If a breach ever affects your rights we will tell you, and the ICO, as the law requires.

Changes

If we change this policy we will update the date at the top. Where a change materially affects you, we will email you about it.