Privacy Policy
Effective Date: January 1, 2025
Last Updated: September 17, 2026
SAFE SAPCR Texas ("we," "us," or "our") operates the website safesapcrtx.org. This Privacy Policy explains how we collect, use, and protect your information when you visit our site.
What happens when you visit today
- The pages are static files. There is no account to create, no login, and no advertising or social-media pixel. Netlify serves the HTML and keeps standard server logs.
- The tools run on your device, not ours. The deadline calculator and the Bill of Review eligibility checker do every calculation in your browser. The dates and answers you enter are never transmitted, never stored, and we never see them.
- Two measurement tools do run, and both can be blocked. Google Analytics counts pages and approximate location. Microsoft Clarity records pointer movement, clicks and scrolling so we can see which long pages people give up on — with what you type into any form masked before it leaves your browser. Blocking
google-analytics.comandclarity.msstops both, and the site works normally without them. - One measurement property is not ours. The Google Analytics tag also reports to a second property attached at Google’s end that we did not add and cannot remove. We disclose it rather than leave it unsaid; the opt-out under Your Rights blocks it too.
- We do not fingerprint your browser, sell your information, or take payment.
That is the whole of what happens now. Everything below is the detail behind it, and it also keeps the account of two things that were once true and are not any more: a Meta Pixel that ran for five days in August 2026, and fingerprinting software that ran from January to April 2026 whose records are still held. Those accounts are kept rather than deleted, and begin under Information Collected Automatically.
Information We Collect
Information You Provide
- Contact forms: If you contact us via email or a contact form, we collect your name, email address, and message content.
- Petition signatures: If you sign our petition, we collect your name, email, and optional location.
- Membership: If you join as a member, we collect your name, email, and any information you voluntarily provide.
- Newsletter: If you subscribe to our newsletter, we collect your email address.
- Email we send you: Messages we send to a list you opted into contain a single invisible 1x1 image unique to your copy. When your mail program loads that image, we record that the message was opened, when, and how many times. We do this to judge whether an update was worth sending. It tells us nothing about what you read or clicked inside the message, and nothing about you when you are not reading our mail. Many mail programs -- Apple Mail and Gmail among them -- load or block that image on their own, so the record is approximate by nature. If you would rather not be counted, turn off remote or external images in your mail program and the request is never made.
Information Collected Automatically
- Analytics: We use Google Analytics to collect anonymous usage data such as pages visited, time on site, browser type, and general geographic location. This data is aggregated and does not personally identify you.
- Server logs: Our hosting provider (Netlify) may collect standard server log data including IP addresses, browser type, and pages requested.
- Session recording — Microsoft Clarity, added 8 September 2026.
This is more than page counts and you should know what it is. Clarity
records your visit and lets us play it back: where you moved the pointer,
what you clicked, how far you scrolled, and how the page looked to you as
you read it. It also builds heatmaps showing which parts of a page
visitors use, and it sets two first-party cookies (
_clckand_clsk) so a returning browser is recognised as the same one.
We added it to find out which pages people give up on, because the pages here are long and we would rather fix the ones that fail than guess. Text you type into a form is masked before it leaves your browser — the recording shows that a field was filled, not what you put in it. That is Clarity’s behaviour for every input box and drop-down in all of its masking modes; since 9 September 2026 this site additionally marks its free-text boxes, the chat transcript, and the results panels of the deadline calculator and the eligibility checker as masked in the page itself, so their contents are withheld whatever the Clarity project’s own settings say. Ordinary page text is not masked — the words of the page you are reading are part of the recording, because that is what makes a replay legible.
It does not fingerprint your device: it identifies a browser by cookie, so clearing cookies or using private browsing separates one visit from the next, which is not true of the canvas and audio fingerprinting described further down this page.
Recordings are held by Microsoft, not by us, under Microsoft’s privacy statement. If you would rather not be recorded, blockingclarity.msin a content blocker stops it, and the rest of this site works normally without it. - A second analytics property we do not control. The Google Analytics tag served to this site also reports to a second measurement property that is not ours and that we did not add. It is not referenced anywhere in this site's code; it is attached at Google's end, so it loads for every visitor regardless of what we publish, and we cannot remove it from here. We are disclosing it rather than leaving it undisclosed. It receives the same category of data described above — pages viewed, approximate location, browser — and it is not covered by the assurances we give elsewhere on this page, because we do not control it. The Google Analytics opt-out linked under Your Rights blocks that property as well as ours.
- Meta (Facebook) Pixel — removed 27 August 2026.
Nothing on this site sends anything to Meta today. A Meta
Pixel ran here from 22 to 27 August 2026, five days. It is
described here rather than deleted because during those five days it
collected, and that data is held by Meta, not by us.
While it ran, on every page that carried it, it reported to Meta that a browser had loaded that page, together with the page address, the referring page, your IP address and your browser details — which Meta can match against a Facebook or Instagram account and combine with what it knows about you from other sites. It did not run on the eight translated homepages or on /perjury, and it did not load at all for browsers sending a Global Privacy Control signal.
It was removed because there was no advertising campaign consuming it: it was collecting into a named identity graph with nothing on the other side of the scale. The code is gone from this site’s JavaScript and both Meta origins are out of the Content-Security-Policy, so it cannot load even if a page asked for it. We cannot delete what Meta already received. If you visited between those dates, you can review and adjust what Meta holds through your Meta ad preferences. The full account is in the corrections log.
Data this site collected in early 2026, and still holds
Between 7 January and 12 April 2026 this site ran software that recorded technical details of visits to its own database, separate from the hosting provider’s logs described above. It recorded IP address, user agent, referring and visited page, screen resolution, timezone, HTTP headers, scroll depth, time on page, form interaction, and browser fingerprints including canvas and audio fingerprints. A companion table recorded requests to decoy paths, including IP address, user agent and the raw request body.
Canvas and audio fingerprints identify a browser by properties of the device rather than by cookies, which means they can work when private browsing or Tor is in use. Given who reads this site, that should not have been done without saying so, and this policy did not say so at the time.
Collection stopped on 12 April 2026 and the software that performed it was removed. Nothing on this site collects fingerprints today, and no code in it is capable of doing so.
The records are retained. They are restricted to server-side access; the public key used by this site’s own pages cannot read them, which was verified from outside on 26 August 2026. They are not deleted because the operator is a party to pending litigation and is subject to a duty to preserve records that may be relevant to it — a duty he has himself invoked against an opposing party in one of those cases. If you believe a record of your visit is among them and you want to know what it contains, write to info@safesapcrtx.org.
A fuller account, including the period during which one of these tables was readable by anyone holding this site’s public key, is in the corrections log.
How We Use Your Information
- To respond to your inquiries and communications
- To process petition signatures and membership requests
- To send newsletters and updates (only if you opt in)
- To measure whether the emails we send are opened, so we can send fewer and better ones
- To improve our website and understand how visitors use it
- To support our legislative advocacy efforts with aggregate data (e.g., total petition signatures by region)
Information We Do Not Collect
- We do not sell, rent, or trade your personal information to third parties
- We do not collect payment or financial information
- We do not fingerprint your browser. This was not true between January and April 2026 — see “Data this site collected in early 2026” above.
Third-Party Services
We use the following third-party services:
- Netlify: Website hosting and serverless functions
- Google Analytics: Anonymous website usage analytics
- Microsoft Clarity: Session replay and heatmaps — see Information Collected Automatically
- Supabase: Database services for petition signatures and membership data
Each of these services has its own privacy policy governing how they handle data.
That list covers the services we chose. It is not the complete set of parties receiving data about your visit — see the second analytics property described under Information Collected Automatically, which we did not add and cannot remove.
Data Security
We take reasonable measures to protect your information, including:
- HTTPS encryption on all pages
- Database access controls, reviewed 26 August 2026. Every table is restricted to server-side access except where a public form must write to it.
- Limited access to personal data
Your Rights
You have the right to:
- Request a copy of any personal information we hold about you
- Request correction or deletion of your personal information
- Unsubscribe from our newsletter at any time
- Opt out of Google Analytics by using the Google Analytics Opt-out Browser Add-on
Children's Privacy
Our website is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us so we can remove it.
Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date.
Contact Us
If you have questions about this Privacy Policy, contact us at:
info@safesapcrtx.org