Sub-processors
Last updated: 23 July 2026
To run Confetti we rely on a small set of third-party service providers ("sub-processors"). Each processes your workspace's data only to provide the function listed below, under its own security and privacy commitments. Several are used only when your workspace turns on an optional feature. We do not sell your data or share it with anyone beyond these providers.
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services | Core hosting, database (DynamoDB), encryption keys (KMS) and AI inference (Bedrock). This is where Confetti and your roster data live. | Sydney, Australia (ap-southeast-2). AI inference runs only in AWS Australian regions. |
| Stripe | Payment processing and subscription billing. Card details go directly to Stripe; we never see or store them. | United States and global (Stripe's own infrastructure). |
| Slack | The messaging platform Confetti runs on. We read your member directory and post announcements through Slack's API. | Slack's (Salesforce's) own infrastructure. |
| Workspace directory sync — Pro, admin opt-in only. Read-only access to directory names and date fields to sync birthdays and hire dates. | Google's own infrastructure. | |
| KLIPY | Meme GIF search — per-team opt-in only. We send generic search terms like "happy birthday" (never names, dates or personal data); GIFs reach your members through Slack's image proxy. | KLIPY's own infrastructure. |
| Anthropic (via AWS Bedrock) | AI-written celebration text — admin opt-in only. At posting time we send the celebrant's display name, the occasion, their Slack job title if set, your workspace name and the years or age being celebrated (age only if that person shows it), solely to write that one message. Nothing sent or generated is stored, logged, retained or used to train any model. | AWS Australian regions only (ap-southeast-2 / ap-southeast-4). |
We review our sub-processors and will update this page when we add or change one. For the full picture of what we collect and how we protect it, see our Privacy Policy. A Data Processing Addendum listing these sub-processors is available on request — privacy@tinypoll.io.