Elektor Pro · Legal
Privacy Policy
Last updated: August 4, 2026
1. Introduction
Elektor Pro is an electronic voting platform that organizations - unions, universities, associations and similar bodies - use to run their elections. This policy explains plainly what data the platform handles, how ballot secrecy is protected, and how to reach us about any of it.
By using the platform you agree to the practices described here.
2. Who runs the platform
- Developer: Nurudeen Abdul-Majeed
- Website: manuru.dev
- Email: abdulmajeednurudeen48@gmail.com
When an organization runs its election on Elektor Pro, that organization decides who is on the voter roll and which staff accounts exist; the platform processes that data to run the election on the organization's behalf.
3. Information the platform collects
3.1 Staff accounts. Administrators, agents, candidates and accreditation staff have accounts with a name, an email address and/or phone number, an optional profile photo, and a password stored only as a one-way bcrypt hash - the platform never sees or stores a password in readable form.
3.2 Voter records. The organization running an election loads its voter roll: a name, a voter ID, and a phone number and/or email address used to sign in with one-time codes. Group memberships (for example a department or college) may be attached so the right elections are shown to the right voters.
3.3 One-time codes. Sign-in and verification codes are sent to the contact details on record, stored only as hashes, expire quickly, and are single-use.
3.4 Security records. The platform keeps an append-only audit log of sensitive actions (sign-ins, changes to election data, certifications) which records the acting account, the action, and the IP address and browser identification of the request. Active sessions are recorded per device so you can review and revoke them.
3.5 Nothing else. There are no analytics trackers, no advertising cookies, and no profiling of any kind.
4. Your ballot is not linked to you
This is the heart of the platform's design: a cast ballot is stored with no reference to the voter. The system records separately that you voted in an election (so nobody can vote twice) and what was voted (the anonymous ballot), and the two cannot be joined - not by administrators, not by the developer. Your receipt code proves your ballot entered the count without revealing how it was cast.
5. How your data is used
Data is used for exactly one purpose: running elections - signing you in, showing you the elections you belong to, delivering one-time codes, counting ballots, publishing certified results, and keeping the security records above. It is never sold, shared, rented, used for advertising, or used to train models.
6. Cookies
The platform sets only strictly necessary cookies: httpOnly access and refresh tokens that keep you signed in, and a simple non-identifying marker that tells the website a session exists. There are no analytics, advertising, or cross-site tracking cookies.
7. Security
The platform is built to production security standards: bcrypt password hashing, short-lived session tokens in httpOnly cookies with refresh-token rotation and replay detection, optional two-factor authentication, account lockout, rate limiting, hashed single-use codes, hash-chained ballots and audit logs whose integrity can be re-verified, and encrypted connections throughout. Still, no online system is completely secure; report any concern to the contact below.
8. Retention and deletion
Election records are kept so that past results remain checkable - that permanence is a feature organizations rely on. Voter and staff records are kept while the organization uses the platform and are removed when the organization asks or ends its use. To have your own details corrected or removed, contact the organization that runs your election, or email the address below.
9. Infrastructure and processors
The platform runs on ordinary cloud infrastructure: a website host, an API host, a managed PostgreSQL database, and Cloudinary for profile photos. Email and SMS providers deliver one-time codes and notifications. These providers process data only to run the application; no third party receives your data for its own purposes.
10. Children
The platform is used by organizations whose electorates are adults or students of voting age within those organizations; no data is knowingly collected from children outside that context.
11. Changes to this policy
If the platform's data practices change, this document will be updated with a new date at the top. Continued use after a change means you accept the updated policy.
12. Contact
Questions, correction or deletion requests, or security reports: abdulmajeednurudeen48@gmail.com. See also the Terms of Service.
See also the Terms of Service, or return to the landing page.