Consent & privacy

Ballot Signal + OneTrust

Live Native — API key Nonpartisan n/a (client-side signal)

What is OneTrust?

The enterprise CMP — where a state party or large advocacy organization has a privacy office, this is usually what they bought.

It sits in the Consent & privacy category of a campaign stack. Signals we consume, never signals we override.

Who uses it

Nonpartisan. Used across both parties and by nonpartisan organizations.

How the Ballot Signal + OneTrust integration works

A signal we consume. Ballot Signal reads OneTrust's active consent groups and its consent-changed callback, and maps the groups you designate onto our marketing and statistics requirements.

What syncs

  • Consent groups
  • Consent change callbacks

Field mapping

The supporter record is the same shape everywhere. What changes is where each field lands. The full record is documented on what you get.

Supporter record field mapping
Supporter record Consent signal Notes
— (inbound) Consent category state Read from this platform, not written to it.
consentCategories Normalized internal consent object Their category names mapped onto ours.
consentTimestamp Captured at the moment of the affirmative act Stored on every supporter record produced afterwards.
consentVersion Your configured policy version string A version bump re-asks the visitor.
consentSource Page URL where the consent event fired Exact URL, not just the domain.

How to set it up

  1. 1

    Confirm which OneTrust consent group corresponds to marketing on your site.

  2. 2

    Register the Ballot Signal snippet under that group so OneTrust's auto-blocking gates it.

  3. 3

    Install the snippet.

  4. 4

    Map the group in Ballot Signal settings.

  5. 5

    Test decline, accept, and withdrawal.

Why it matters

The enterprise CMP — where a state party or large advocacy organization has a privacy office, this is usually what they bought.

Ballot Signal + OneTrust: questions

Is the OneTrust integration available today?

Live. Built, tested and available to every customer today. You can turn this on yourself without talking to us.

What authentication does the OneTrust integration use?

n/a (client-side signal). Credentials are stored encrypted and are never rendered back into the interface after entry.

Will this create duplicate records in OneTrust?

No, assuming you leave deduplication on. We match on the lowercased-email hash first, then phone, then name plus address. On a match we update rather than create, and only the fields you have marked overwritable.

Does the consent record travel into OneTrust?

Yes. Consent timestamp, consent version, consent source URL and granted categories are included in every push, by default, and there is no configuration that strips them. That is the point of the product.

See what your own website already knows.

Book a 20-minute walkthrough. We will look at your site's current consent posture first — that part is useful whether or not you buy anything.