Privacy Policy

Last updated: 23 July 2026

Confetti is a Slack application operated by TinyPoll ("we", "us"). This policy explains what we collect when your workspace installs Confetti, how we secure and retain it, and the choices and rights you have. For your members' information we act as a processor on behalf of your workspace, which is the controller of that data.

What we collect

What we process but never store

What we don't collect

How we secure your data

Confetti runs as a single least-privilege service in AWS's Sydney region. In transit, all traffic uses TLS 1.2 or higher. At rest, our databases are encrypted with AWS-managed keys. The most sensitive secrets — the Slack bot token and any Google refresh token — receive an additional layer of field-level encryption using a dedicated customer-managed AWS KMS key with automatic annual rotation. Every request is authenticated: Slack requests are verified by HMAC signature with replay protection and a constant-time comparison, the install flow carries a signed anti-CSRF state parameter, Stripe webhooks are signature-verified, and browser billing links use short-lived (one-hour) signed tokens. Each workspace's data is strictly isolated by its tenant ID on every query, and admin actions are re-authorized server-side. A fuller account is in our Security statement.

Sub-processors

We use a small set of third-party providers to run Confetti — for hosting, payments, the Slack platform itself, and the optional Google, KLIPY and AI features. Each is listed with its purpose and region on our Sub-processors page. We do not sell your data or share it with anyone beyond these providers.

Google API Limited Use

Confetti's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request read-only Google Workspace directory access solely to sync birthdays and hire dates onto your celebration roster; we do not transfer or sell this data to third parties except as needed to provide that feature, and raw or derived Google Workspace data is never used to develop, improve, or train generalized AI or machine-learning models.

Cookies and tracking

This website sets no cookies and runs no analytics, advertising or third-party trackers. The only embedded data is JSON-LD structured markup that helps search engines describe the page. Confetti itself runs inside Slack, not in your browser.

Retention and deletion

Personal data is retained while Confetti is installed. A few specifics:

Your controls: opt out and delete

These are two different things:

You can also email us for access, export or deletion requests and we'll respond within 30 days.

International transfers

Confetti is hosted in Australia. If your workspace includes people in the EU, UK or elsewhere, their personal data is transferred to and processed in Australia. Where the law requires a transfer mechanism — for example for EU- or UK-origin personal data — we rely on an appropriate basis such as the European Commission's Standard Contractual Clauses (and the equivalent UK provisions), together with the safeguards described above. We do not claim any certification or adequacy status we don't hold.

Your rights

Depending on where you live, you have rights over your personal data — including under the EU and UK GDPR, the Australian Privacy Act, and US state privacy laws such as the California Consumer Privacy Act (CCPA, as amended by the CPRA). These can include the right to access, correct, export (data portability), and delete your data, and to opt out of its sale or "sharing" for targeted advertising. Confetti does not sell or share personal data and does not use it for targeted advertising, so there is nothing to opt out of on that front. To exercise a right, use the in-app controls above or contact us; because your workspace is the controller of its members' data, we may route certain requests through your workspace admin. We do not discriminate against anyone for exercising these rights.

Data breach notification

If we become aware of a personal-data breach affecting your workspace, we will notify the affected workspace's admins without undue delay, describe what we know and what we're doing about it, and cooperate with any notifications required under applicable law (including the Australian Notifiable Data Breaches scheme and Articles 33–34 of the GDPR).

Contact

For privacy questions or to exercise a right, contact our privacy team at privacy@tinypoll.io. For general help, email support@tinypoll.io. TinyPoll is based in Victoria, Australia.