Privacy Policy
Last updated: 23 July 2026
Confetti is a Slack application operated by TinyPoll ("we", "us"). This policy explains what we collect when your workspace installs Confetti, how we secure and retain it, and the choices and rights you have. For your members' information we act as a processor on behalf of your workspace, which is the controller of that data.
What we collect
- Workspace data: your Slack workspace (or organization) ID and name, the identity of the installer and the people you designate as Confetti admins, the bot access token Slack issues on install (stored encrypted — see Security), a periodic snapshot of member IDs used to size the roster and count seats, and your configuration (channels, timezone, posting hour, message templates).
- Member directory basics: Slack user IDs, display names (real names) and timezone for the people on your celebration roster.
- Celebration dates: birthdays (month and day; the birth year only if the individual voluntarily provides it to have their age shown — a piece of sensitive data we treat accordingly) and hire dates, entered by individuals, admins, CSV import, or Google Workspace sync.
- Reporting relationships: where an admin enables manager advance alerts, the manager assigned to a person (their Slack user ID), so the right manager can be given a private heads-up before a celebration.
- Preferences: each person's opt-out flag.
- Card and event content: the messages teammates write when signing group cards, and the text of any custom events an admin creates.
- Billing data: handled by Stripe. We store only Stripe customer and subscription identifiers and your plan, trial and billing state — never card numbers.
- AI-consent record: if an admin turns on AI-written messages, we keep an audit record of that consent (who agreed, and when).
- Google Workspace (optional): if an admin connects Google sync, we store an OAuth refresh token (stored encrypted — see Security) and read directory names, emails and date fields weekly. We request read-only directory access and nothing else.
What we process but never store
- Email addresses. Where your Slack plan or Google directory exposes them, email addresses are used only in the moment — to match an imported spreadsheet row or a directory entry to the right Slack account. They are never written to our database. Billable seats are counted from your live Slack member list, not from stored emails.
- Job titles. If AI-written messages are on, a person's Slack job title (when set) may be sent to the AI model at posting time to colour the message, but we do not retain it.
- What we send to the AI model. The celebrant's display name, the occasion, their job title (if set), your workspace name and the years or age being celebrated are sent to write that one message and are not stored by us — see our Sub-processors page for how the AI service handles them.
What we don't collect
- We cannot read your channels' message history — Confetti's Slack permissions don't allow it.
- Birth years are never required, and ages are never displayed unless the individual opts in.
- We do not sell or "share" personal data, run ads, or disclose data to third parties beyond the sub-processors below.
How we secure your data
Confetti runs as a single least-privilege service in AWS's Sydney region. In transit, all traffic uses TLS 1.2 or higher. At rest, our databases are encrypted with AWS-managed keys. The most sensitive secrets — the Slack bot token and any Google refresh token — receive an additional layer of field-level encryption using a dedicated customer-managed AWS KMS key with automatic annual rotation. Every request is authenticated: Slack requests are verified by HMAC signature with replay protection and a constant-time comparison, the install flow carries a signed anti-CSRF state parameter, Stripe webhooks are signature-verified, and browser billing links use short-lived (one-hour) signed tokens. Each workspace's data is strictly isolated by its tenant ID on every query, and admin actions are re-authorized server-side. A fuller account is in our Security statement.
Sub-processors
We use a small set of third-party providers to run Confetti — for hosting, payments, the Slack platform itself, and the optional Google, KLIPY and AI features. Each is listed with its purpose and region on our Sub-processors page. We do not sell your data or share it with anyone beyond these providers.
Google API Limited Use
Confetti's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request read-only Google Workspace directory access solely to sync birthdays and hire dates onto your celebration roster; we do not transfer or sell this data to third parties except as needed to provide that feature, and raw or derived Google Workspace data is never used to develop, improve, or train generalized AI or machine-learning models.
Cookies and tracking
This website sets no cookies and runs no analytics, advertising or third-party trackers. The only embedded data is JSON-LD structured markup that helps search engines describe the page. Confetti itself runs inside Slack, not in your browser.
Retention and deletion
Personal data is retained while Confetti is installed. A few specifics:
- On uninstall. When you uninstall Confetti — or when the bot token is revoked — we delete your workspace's personal data promptly as part of handling that event, and a daily job re-checks and clears anything missed, so personal data is always removed within 30 days of uninstall. Because our database keeps point-in-time-recovery backups for operational safety, residual copies in those backups age out automatically within about 35 days.
- What we keep after uninstall. We retain a minimal record so billing stays correct and a reinstall behaves sensibly: your workspace/organization ID and name, Stripe customer and subscription identifiers, plan and billing state, and a flag noting the free trial was already used. This tombstone carries no roster, dates or card content — all personal data is purged.
- Announcement log. To avoid posting the same celebration twice, we keep a small log keyed by user ID; entries expire automatically after roughly 400 days.
- AI-consent record. The audit record of an admin enabling AI-written messages is kept even if the feature is later switched off or the plan lapses, so we retain proof of the consent that applied at the time.
- Card messages and custom events remain on your roster until the card or event is removed, the person is erased, or the workspace uninstalls.
- Billing records held by Stripe follow Stripe's own retention and any legal record-keeping obligations.
Your controls: opt out and delete
These are two different things:
- Opt out. Any individual can opt out of celebrations at any time from the Confetti Home tab. This immediately stops their dates being used, without asking an admin — but keeps their record so they can opt back in later.
- Delete my data. The Confetti Home tab also offers a "Delete my data" control that erases an individual's roster record outright. A Confetti admin can likewise erase any person from the roster. Deletion is permanent, subject only to the backup ageing-out window noted above.
You can also email us for access, export or deletion requests and we'll respond within 30 days.
International transfers
Confetti is hosted in Australia. If your workspace includes people in the EU, UK or elsewhere, their personal data is transferred to and processed in Australia. Where the law requires a transfer mechanism — for example for EU- or UK-origin personal data — we rely on an appropriate basis such as the European Commission's Standard Contractual Clauses (and the equivalent UK provisions), together with the safeguards described above. We do not claim any certification or adequacy status we don't hold.
Your rights
Depending on where you live, you have rights over your personal data — including under the EU and UK GDPR, the Australian Privacy Act, and US state privacy laws such as the California Consumer Privacy Act (CCPA, as amended by the CPRA). These can include the right to access, correct, export (data portability), and delete your data, and to opt out of its sale or "sharing" for targeted advertising. Confetti does not sell or share personal data and does not use it for targeted advertising, so there is nothing to opt out of on that front. To exercise a right, use the in-app controls above or contact us; because your workspace is the controller of its members' data, we may route certain requests through your workspace admin. We do not discriminate against anyone for exercising these rights.
Data breach notification
If we become aware of a personal-data breach affecting your workspace, we will notify the affected workspace's admins without undue delay, describe what we know and what we're doing about it, and cooperate with any notifications required under applicable law (including the Australian Notifiable Data Breaches scheme and Articles 33–34 of the GDPR).
Contact
For privacy questions or to exercise a right, contact our privacy team at privacy@tinypoll.io. For general help, email support@tinypoll.io. TinyPoll is based in Victoria, Australia.