TargetSmart Data Use Addendum
Supplement to the ActBlue Account Use Policy
Last Updated: 7/28/26
This addendum supplements the ActBlue Account Use Policy ("AUP") and applies to any entity that receives data from TargetSmart Communications LLC ("TargetSmart") through ActBlue's platform, including the TargetSmart Cellbase product and related database, analytics, and append services (collectively, "TargetSmart Data"). It describes the additional requirements that apply to entities approved to receive TargetSmart Data, on top of the general requirements of the AUP. Where this addendum and the AUP both address the use of TargetSmart Data, this addendum controls; the AUP continues to govern all other matters of platform eligibility and conduct.
ActBlue reserves the right to alter this addendum, or an entity's access to TargetSmart Data, on a discretionary basis, consistent with the AUP.
1. Eligibility and Approval• Access to TargetSmart Data requires TargetSmart's prior approval as an Authorized End User ("AEU"), granted or withheld at TargetSmart's discretion, in addition to and independent of an entity's standing under the AUP.
• TargetSmart or ActBlue may suspend or revoke an entity's AEU approval at any time. Revocation of AEU approval does not, by itself, affect an entity's standing under the AUP, and an AUP violation does not, by itself, affect AEU approval — though conduct described in Section 3 below will typically trigger review under both.
• AEU approval does not modify, waive, or substitute for any requirement of the AUP.
2. Restrictions on UseEntities receiving TargetSmart Data must not:
• sell, resell, license, sublicense, transfer, or otherwise disclose TargetSmart Data to any third party, including any data reseller, credit bureau, data compiler, or people/background-search company;
• copy, modify, or create derivative works from TargetSmart Data except as necessary for backup or security purposes, or combine TargetSmart Data with a third-party file without ActBlue's and TargetSmart's prior written consent;
• use TargetSmart Data to develop "look-alike" segments or user profiles, or to enable generative artificial intelligence or large language models to produce similar or substantially similar data;
• use TargetSmart Data as a factor in determining any individual's eligibility for credit, insurance, or employment;
• display TargetSmart Data in a non-secured or publicly accessible manner; or
• use TargetSmart Data in connection with credit repair, payday or short-term lending, malware or other harmful code, hate, illegal weapons, pornography, violence, or any other purpose that violates applicable law
3. Prohibited Political Uses
ActBlue's ability to distribute TargetSmart Data is itself conditioned on that data not being used to support the defeat of any Democratic candidate in a general election, to oppose a candidate whom the local, state, or national Democratic Party has publicly endorsed in a primary, or to support or oppose an issue or ballot measure in a manner a reasonable person would consider contrary to the Democratic Party's position. Using TargetSmart Data for any such purpose is a violation of this addendum and independently violates AUP Sections 1 and 2, and will result in prompt revocation of AEU approval in addition to any action taken under the AUP.
4. Voter Registration and FEC-Sourced Data• Entities are solely responsible for their own compliance with applicable state laws governing the use of voter registration records, and must complete any state-required certifications promptly upon request. Neither ActBlue nor TargetSmart provides legal advice or guidance on such compliance.
• Entities must not use data sourced from reports filed with the Federal Election Commission for commercial purposes, or for any purpose not permitted under the Federal Election Campaign Act and applicable FEC guidance, including solicitation of contributions beyond what such data may lawfully support.
5. Data Retention and Destruction• Entities must delete and destroy all TargetSmart Data in their possession within thirty (30) days of the earlier of: (i) revocation or expiration of AEU approval, or (ii) a request from ActBlue or TargetSmart.
• Absent separate written agreement, entities must not retain TargetSmart Data for longer than one (1) year following receipt.
• Entities must certify deletion and destruction of TargetSmart Data in writing upon request.
6. Security RequirementsEntities receiving TargetSmart Data must, at a minimum:
• implement multi-factor authentication on any email system or online service with access to TargetSmart Data;
• maintain at-rest encryption and password protection on systems storing TargetSmart Data, and encryption on network communications transmitting it;
• avoid storing TargetSmart Data on removable media (e.g., USB drives) unless the media is encryption-enabled; and
• restrict access to TargetSmart Data to personnel with a need to know, authenticated onto the entity's network.
7. Security Incident NotificationEntities must notify ActBlue within twenty-four (24) hours of discovering, or having reason to believe, that TargetSmart Data has been subject to unauthorized access, use, or disclosure (a "Security Incident"), and must reasonably cooperate with ActBlue's and TargetSmart's investigation and remediation efforts, including by preserving relevant logs and providing information about the scope of the incident.
8. Geographic and Access RestrictionsTargetSmart Data may be accessed and stored only within the United States or its territories. Entities must not access or permit access to TargetSmart Data from outside the United States without ActBlue's and TargetSmart's prior written approval, and any approved access must occur over a secure, encrypted connection.
9. Audit and CooperationEntities must cooperate with reasonable requests by ActBlue or TargetSmart to review compliance with this addendum, including by providing access to relevant records and personnel on no less than five (5) business days' written notice. Absent a good-faith belief that an entity has violated this addendum or experienced a Security Incident, such reviews will occur no more than once in any twelve (12)-month period.
10. Consequences of Non-ComplianceA violation of this addendum may result, at ActBlue's or TargetSmart's discretion, in immediate suspension or revocation of an entity's AEU approval and access to TargetSmart Data, independent of and in addition to any action taken under the AUP. ActBlue may disclose the nature of a suspected violation to TargetSmart as necessary to comply with ActBlue's own data agreements. Entities remain responsible for the acts and omissions of their own officers, employees, contractors, and agents under this addendum.
This addendum applies for as long as an entity retains AEU approval or possesses TargetSmart Data, whichever is later. If you have questions about this addendum, please contact ActBlue.