Privacy Policy
Last updated: 15 June 2026
GPS Network operates The Jewish Activist and is the data controller for the personal data described on this page. You can reach us about anything to do with your data at office@gpsnet.org. We are based in the United Kingdom and handle your data in line with the UK GDPR and the Data Protection Act 2018.
Who we are
The Jewish Activist is a UK grassroots advocacy group, operated by GPS Network. This website lets you take action against antisemitism — most often by sending an email to your MP or local councillor — and lets you sign up for alerts or apply to join our community. This policy explains what personal data we collect when you do those things, why, and what your rights are.
What we collect, and why
1. Sending a campaign email to your MP or councillor
When you use an Action Alert to email your MP or councillor, we ask for a few details so the message reaches the right person and reads as coming from one of their constituents:
- Your postcode — used to look up your MP, local council and ward. It is also placed into the email so the recipient's office can confirm you are a constituent.
- Your name and full postal address — placed into the email body. UK MPs and councillors only act for people in their own area, and their offices verify this by full address.
Your name, address and postcode for a campaign email are not stored by us. They are put together in your browser and handed to your own email app — they live only in the email you send from your own account. We do not write them to our database and we do not log them.
Each Action Alert includes a unique blind-copy (BCC) address on a domain we operate. When your email goes out, a copy of that BCC comes back to us so we can confirm a send actually happened. From that copy we record that a send occurred and the constituency area it relates to. We do not store your name, your address, or the wording of your message.
The email address you send from. Because the BCC is a copy of the message you sent, it shows the From address of your own email account. We see and store that address and use it to attribute the action to you — for example to credit you as an active supporter and to keep a record of the campaigns you have taken part in — even if you did not tick the optional "email me a reminder" box. The lawful basis for confirming the send and crediting your action is our legitimate interest in measuring the reach of our campaigns and recognising the people who take part; you also knowingly include our BCC address and choose to send the message. We do not use this address to email you unless you separately opted in to alerts, and you can ask us to erase it at any time through the data rights process.
2. Email alerts and supporters
If you sign up to receive alerts, we collect and store:
- Your email address and name — so we can send you the updates you asked for.
- Your postcode (optional) — if you give it, we resolve it once to your local council, ward and Westminster constituency and store those, so we can see where our support is across the country. You don't have to provide it.
The lawful basis is your consent, given when you sign up. Every email we send includes a one-click unsubscribe link, and you can opt out at any time.
3. Applying to join
Our membership application form collects more, because joining involves vetting and ongoing administration:
- your full name and email address;
- your mobile / WhatsApp number;
- your town or city and your country;
- whether you are Jewish or a non-Jewish ally (see the note below);
- the name and contact details of a referee;
- why you want to join, and your alert preferences.
Special-category data. Telling us whether you are Jewish is information about your religion, which UK GDPR treats as special-category data. We collect and store it only with your explicit consent, which the application form asks for, and we use it solely to vet applications and run our community. The lawful bases are your explicit consent (Article 9) for this religious-belief information, and your consent together with our legitimate interest in running a membership organisation (Article 6) for the rest of the application. You can withdraw your consent at any time by contacting us.
We keep applications so we can vet and administer membership. If you withdraw or ask to be forgotten, we delete your application.
4. Team sign-ins
Members of our team who sign in to administer the site have an account holding their email address and a securely hashed password. The lawful basis is our legitimate interest in running the site securely.
Analytics and cookies
Our analytics are privacy-friendly: cookieless, first-party only, with no third-party trackers and no advertising cookies. The only cookies we set are strictly necessary ones (a sign-in session for our team and a short-lived sign-in preference cookie) plus an optional "remember me" cookie that, if you leave it ticked on a lookup campaign, stores your name, postcode and email on your own device to pre-fill the form next time. See our Cookie Policy for the detail.
What we do NOT collect
- The wording of the email you send. It is composed in your own email app and sent from your own address — we never see it.
- Advertising or cross-site tracking data. No third-party ad trackers, no retargeting.
Who we share data with
We don't sell your data and we share it only with the suppliers we need to run the site, who act on our instructions:
- Cloudflare — hosts the website, the database, and the inbound mail handler that receives the send confirmations.
- UK Parliament Members API — your postcode is sent to members-api.parliament.uk to look up your MP. Your name is not sent.
- mySociety MapIt — your postcode is sent to mapit.mysociety.org to find your council and ward. No identifier is attached.
- Amazon Web Services (SES) — delivers our outbound email, such as alerts and sign-in messages.
- A third-party AI provider (currently Anthropic, OpenAI or Google) — when our team uses the optional AI features to draft or refine campaign wording, the relevant campaign text is sent to the configured provider, which acts as a sub-processor on our instructions. This does not include your name, address or the email you send to your MP.
Retention
We keep personal data only as long as we need it for the purpose we collected it for. Supporter records are kept until you unsubscribe; applications are kept while we vet and administer membership. Asking us to forget you, or unsubscribing, removes your records. The full picture is on our data rights page.
Security
We apply appropriate technical and organisational measures to protect your data (UK GDPR Article 32):
- Multi-factor authentication (MFA) is required on every team sign-in to this site, so a leaked password alone cannot reach supporter data. Supporters themselves sign in passwordlessly, via a one-time link.
- The site is served through Cloudflare — encrypted (HTTPS) connections, DDoS protection and a hardened edge network in front of everything we serve.
- Outbound email is sent through Amazon Web Services (SES), with SPF and DKIM authentication on our sending domain.
- Passwords and one-time sign-in codes are stored only as salted hashes, never in plain text.
Your rights (UK GDPR)
You can ask us to give you a copy of your data, correct it, or delete it, and you can withdraw any consent you've given. If you've signed up, you can see and export your data and ask to be forgotten yourself in your account at /my. For anything else, email office@gpsnet.org. Your full rights and how to use them are set out on our data rights page.
If you're unhappy with how we've handled your data, you can complain to the Information Commissioner's Office (the UK's data-protection regulator) at ico.org.uk.
Changes
We'll update this page when anything material changes and update the "last updated" date at the top.