Every part of Rallly is built to protect your data, on trusted infrastructure with a codebase anyone can audit. Your schedule is nobody's business but yours.
people voted on polls in the last 30 days
Rallly is built in the open. The source code is public, uptime is independently measured, and this page lists exactly where your data lives.
The full source code is public and auditable on GitHub. Anyone can review exactly how data is handled.
Browse source codeMeasured uptime above 99.9%, published in real time on an independent status page. Not self-reported.
View live statusPrefer full control? Run Rallly on your own infrastructure and your data never reaches us.
Learn moreTLS 1.2 or higher for all traffic, AES-256 encryption at rest, and HTTPS enforced across the platform.
We collect the minimum needed to run the service. No sensitive personal information, no advertising trackers, and we never sell data.
Data is scoped to its owner at the access layer, with the architecture rules enforced by static analysis in the codebase.
Rallly runs on the world's leading infrastructure providers, giving you the security and performance you should expect. Here is the complete list, and where your data lives.
| Provider | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Vercel | Application hosting | United States | EU-US DPF + UK Extension SCCs fallback |
| Neon | Managed PostgreSQL database | United States | EU-US DPF + UK Extension Certified under Databricks, Inc. · SCCs fallback |
| Upstash | Session data, rate limiting | United States | EU-US DPF + UK Extension SCCs + UK Addendum fallback |
| Amazon Web Services | Transactional email, object storage | United States | EU-US DPF + UK Extension Certified under Amazon.com, Inc. · SCCs fallback |
| Stripe | Payment processing (billing contact data only) | United States | EU-US DPF + UK Extension SCCs + UK Addendum fallback |
| PostHog (EU) | Product analytics | European Union | EU data residency No US transfer |
| Sentry | Error monitoring | United States | EU-US DPF + UK Extension SCCs + UK Addendum fallback |
The answers we give when organizations evaluate Rallly. If your review needs something not covered here, we are happy to complete your security questionnaire.
Very little by design. Account holders provide a name, email address, and timezone preference. Poll participants provide a name and optionally an email address, and vote as guests without needing accounts. We collect no sensitive personal information, no government identifiers, and no financial account details.
Data is retained while your account is active. You can delete polls and your account at any time. Account deletion starts a 7 day recovery window, after which your data is permanently erased and remaining backup copies expire on our database provider's retention schedule. Inactive polls are automatically scheduled for deletion with a 30 day grace period and advance notice. On request, we delete an organization's data and confirm deletion in writing.
Not currently. Our infrastructure providers are SOC 2 Type 2 and/or ISO 27001 certified, and their attestations are available from each provider. In place of certification we offer what most certified vendors cannot: fully auditable source code, public real-time uptime monitoring, and direct access to the people who build the product.
Yes. Our GDPR Article 28 Data Processing Agreement is published openly and incorporated into our terms of use, so it applies automatically without paperwork. It includes our technical and organizational measures and the full subprocessor list, and we countersign an execution copy on request.
Sign in works with email verification codes, Google, or Microsoft accounts. All inputs are schema-validated, database access goes through a typed ORM with parameterized queries, and dependencies are monitored for vulnerabilities with automated security updates. Every production change goes through version control, code review, automated tests, and staged deployment with instant rollback.
Monitoring and alerting route directly to the engineering team. If a security incident affects your data, we will notify you within 72 hours of becoming aware of it. Rallly has had no data breaches.
Members can sign in with their Google or Microsoft accounts today. Organization-wide SSO enforcement is on our roadmap as part of upcoming organization features.
The production database is backed up continuously with point-in-time recovery, managed by our database provider. The application runs on globally distributed serverless infrastructure and can be redeployed rapidly.
Yes. We complete security and privacy questionnaires for organizational customers, and most answers map directly to the information on this page. Send it to support@rallly.co.
We are happy to answer questions, complete your security review, or talk through deployment options, including self-hosting on your own infrastructure.