Privacy

What player.vote pages share

This note applies to player.vote public pages, the partner ballot at /embed/c/:slug, and its result page.

The embed does not send participant details to the partner page.

The parent receives only state and size events. It does not receive the email, voter id, token, choice, score, result rows, or response body.

Participant browser state

Email mode verifies the one-time code before the ballot. player.vote then stores one participant bearer and one campaign cast proof on the player.vote origin, with an in-memory fallback when browser storage is unavailable.

The final cast sends the bearer in the Authorization header and the cast proof and choice in the request body. The flow does not depend on a participant cookie, and it does not read or write a ballot receipt cookie.

Partner assertions

A partner can call setVoterToken(token) after it loads the player.vote script. The loader keeps the token in memory only.

Parent messages

The frame can send only ready, submitted, closed, and resize. Each message uses a versioned envelope. Unknown message types are ignored.

Images and source text

A client-bound ballot does not load a partner logo or an option image. This rule prevents a partner image host from receiving the participant's IP address through the ballot.

The page can show source_url and snapshot_text. It shows them as escaped text. It does not fetch the source URL.

Public-page fonts

Public pages request font styles and files from Google Fonts at fonts.googleapis.com and fonts.gstatic.com. Google receives the network information needed to serve those files, including the visitor's IP address and browser request metadata. Partner embeds and this privacy page do not load Google Fonts.

Fallback

The loader adds an “Open this decision on player.vote” link to the parent page. The strict frame cannot open a popup or navigate the top page.

Verification limit

The scoped embed has been exercised in Chrome and Firefox with third-party cookies blocked, proving the request, storage, and message rules. Safari and a production sibling-domain deployment are not yet verified.