Security, Privacy & Data Handling
This page is maintained by the Madalsan Party team to answer common security and privacy questions about the Madalsan platform. It describes practices currently in place — it is not an independent certification or third-party audit. Last updated: June 2026.
Shared responsibility. The Madalsan platform is hosted on the Lovable platform, which provides underlying infrastructure, database, authentication, and storage capabilities. Madalsan Party is responsible for the application configuration, content moderation, member data handling, and the practices described below. Members and visitors are responsible for keeping their account credentials confidential and submitting accurate information.
Accounts & Authentication
- Member and administrator sign-in uses email and password backed by the platform's managed authentication service.
- Passwords are stored as one-way hashes by the auth provider; the application does not see plaintext passwords.
- Administrative actions are gated by role checks and recorded in an internal audit log.
- Role assignments are stored separately from user profiles and require an existing administrator to grant.
Data in Transit & At Rest
- All traffic to
getmadalsan.comis served over HTTPS. - The application database enforces row-level security policies so that records are only readable by the intended role (public content, member, or administrator).
- Uploaded identity documents and signatures are stored in a private storage bucket that is not publicly readable. Administrators access them via short-lived signed URLs.
What We Collect
- Membership applications: name, contact details, geographic location, and supporting documents you choose to upload.
- Engagement: event registrations, volunteer interest, donation pledges, and contact-form messages.
- Account activity: sign-in timestamps and administrative actions for security auditing.
- We do not knowingly collect data from children. Submissions should be made by adults eligible for party membership.
How We Use It
- To review and process membership applications, candidate nominations, and volunteer registrations.
- To issue digital membership cards and to verify membership status.
- To communicate party news, event invitations, and campaign updates to people who registered for those communications.
- To meet legal and organisational record-keeping obligations.
Retention & Deletion
- Active member records are retained for the duration of membership and a reasonable archival period afterwards.
- Operational logs (sign-in activity, notifications) are kept for a limited window and then aggregated into anonymous statistics.
- Backups are taken on a regular schedule and are retained for disaster recovery.
- You can request deletion of your personal data by contacting us at the address below; we will confirm what can be removed and what must be retained for legal or organisational reasons.
Cookies & Analytics
- Essential cookies and local storage are used to keep you signed in and to remember your language preference.
- The site does not embed third-party advertising trackers.
- If analytics are enabled in the future, this page will be updated to describe what is collected.
Your Rights
- Request a copy of the personal information we hold about you.
- Ask us to correct information that is inaccurate or out of date.
- Request deletion of your data, subject to the retention notes above.
- Withdraw consent for non-essential communications at any time.
Send requests to privacy@madalsan.so.
Reporting a Security Issue
If you believe you've discovered a vulnerability in the Madalsan platform, please contact us privately first so we can investigate and remediate before any public disclosure. Include steps to reproduce and any supporting screenshots.
Subprocessors
The platform relies on the Lovable hosting platform (which provides the underlying application runtime, database, authentication, and storage) and on standard email delivery infrastructure for transactional messages. Additional integrations will be listed here when introduced.