← Back to Home

Privacy Policy

Last updated: October 5, 2026

Our Privacy Promise

TinyPoll is designed with privacy first. We minimise the data we collect — the service doesn't store phone numbers or people's names from Slack. The web app reads your name and avatar from Slack each time it loads, voter names on non-anonymous polls are read from Slack and held only briefly in memory, and anything you type into a poll is kept as poll content. We do store the Slack workspace name for limited operational purposes such as identifying your installation and supporting billing. We only keep the minimum data necessary to make polling work, and we automatically delete poll data based on your plan (Free: 7 days, Pro: 30 days). Email you send us is separate: we keep what you write to us, as Section 1 explains.

The web app at app.tinypoll.io adds a sign-in, so it keeps a session for you. It never asks Slack for your email address, and it carries no analytics or advertising code. See Section 11.

1. Information We Collect

What We Do Collect:

What We Collect When You Use the Web App:

TinyPoll on the web (app.tinypoll.io) has to know who you are, so it stores a little more than the Slack app does. Section 11 explains how signing in works.

What We Collect When You Email Us:

If you write to any @tinypoll.io address (support, privacy, security, legal or enterprise), we keep what you send: your email address and name as they appear on the message, the message and any attachments, when it was sent, the technical headers your mail provider adds, and anything else you choose to include, such as a signature or details of your workspace or polls. We use it only to deal with your message. It is held by Google Workspace, our email provider (see Section 4), and is not copied into the TinyPoll service.

Important Note About Poll Content: We collect and store the poll questions and answer options you create. If you include personal information (PII) in your poll questions or options, that is your responsibility. We will still delete all this data according to your plan's retention period (Free: 7 days, Pro: 30 days) as part of our automatic deletion policy.

What We DON'T Store:

This list is about the TinyPoll service — the Slack app and the web app. Email you send us is different: it holds whatever you put in it (see What We Collect When You Email Us, above).

Note: We do collect your email address if you provide one during Stripe checkout for billing purposes. See the Payment and Billing section below for details. We also have your email address, and whatever else you include, when you email us (see above).

2. How We Use Your Information

We use the limited information we collect only to:

Legal Basis for Processing (GDPR)

If you are in the EEA, UK, or Switzerland, our legal bases for processing your data are:

3. Data Retention and Deletion

Automatic Data Deletion

All poll data is automatically deleted based on your plan:

  • Free Plan: Data deleted after 7 days
  • Pro Plan and Pro trial: Data deleted after 30 days
  • Enterprise Plan: Custom retention periods available

This includes poll questions, options, votes, and any associated metadata.

Pro retention applies while your subscription is active or your workspace is on its trial. When a trial or subscription ends, or while a subscription payment is outstanding, the Free plan period applies from the next scheduled cleanup.

What Gets Deleted Based on Your Plan:

What We Retain (For Service Operations):

Web App Sessions and Sign-in Data:

Audit Records:

Email You Send Us:

Retention Exceptions:

Even after deletion of active poll data, we may retain certain information where required:

4. Data Sharing and Third Parties

We Do NOT:

We Only Share Data With:

For more detail on subprocessors, see our Data Processing Agreement.

Payment and Billing Data:

If you subscribe to a paid plan, we store:

We do not store credit card numbers, CVVs, or other payment card details. All payment processing is handled by Stripe, a PCI Level 1 certified payment processor.

Admin Identification:

For billing notifications, grace period alerts, and to decide who may manage a poll or the plan, we identify workspace administrators using the Slack users.list and users.info APIs (via our existing users:read permission). Admin status is never written to our database — it is read from Slack and cached in memory for up to six hours. In the web app it is cached with your session and re-checked with Slack at least every six hours, so losing admin rights in Slack takes effect in TinyPoll within six hours.

5. Security

We implement industry-standard security measures:

6. Your Rights

You have the right to:

To exercise any of these rights, contact us at privacy@tinypoll.io. We aim to respond within 30 days.

Note on deletion: If you request deletion, we delete active service data (polls, votes, settings) within 30 days, and email you have sent us as Section 3 describes. Uninstalling TinyPoll removes it from your Slack workspace, but does not by itself constitute a separate deletion request. Data is otherwise handled in accordance with our retention practices, and some data may be retained where required by law or for legitimate purposes — see the Retention Exceptions in Section 3.

7. Children's Privacy

TinyPoll is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete such information.

8. International Users and Data Transfers

TinyPoll is hosted on AWS infrastructure in Australia (ap-southeast-2, Sydney). If you are using TinyPoll from outside Australia, your data will be transferred to and processed in Australia.

Australia does not have an adequacy decision from the European Commission, the UK or Switzerland. When a customer sends us personal data that is subject to the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection, to process on its behalf, the safeguard is the European Commission's Standard Contractual Clauses, with the UK Addendum and the Swiss adaptations; our Data Processing Agreement incorporates them (Section 6).

Some of our subprocessors are in the United States. For those onward transfers we rely on the subprocessors' own transfer mechanisms (e.g., EU-US Data Privacy Framework, Standard Contractual Clauses) as applicable.

Email you send us is not held on our AWS infrastructure. It is stored by Google Workspace, which may hold it in data centres outside Australia, including in the United States.

For more detail, see our Data Processing Agreement.

Controller and Processor Roles

Under data protection law, your organisation (the Slack workspace administrator) is the data controller for Personal Data processed through TinyPoll's polling service. TinyPoll acts as a data processor on your behalf.

For data we process for our own purposes (billing, website analytics, account management, and answering email you send us — apart from any data from your workspace you include, which we handle as your processor under our DPA), TinyPoll is an independent data controller as described in this Privacy Policy.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

10. Slack-Specific Information

Slack Permissions We Request:

TinyPoll requests the following OAuth scopes when installed. Each is explained below:

Sign in with Slack (Web App):

Signing in to the web app with Slack uses Slack's OpenID Connect flow, which asks you — not your workspace admin — for two user scopes:

We do not request the email scope, so Slack never sends us your email address. These scopes are only requested when you personally sign in — installing TinyPoll does not grant them, and workspaces that installed TinyPoll before the web app existed don't need to reinstall.

How We Use the Bot Token:

The bot token allows TinyPoll to interact with your Slack workspace. We use it only to:

11. TinyPoll on the Web (app.tinypoll.io)

TinyPoll also runs on the web at app.tinypoll.io, where you can watch results update live, vote, create polls that post to Slack, manage your polls, and export results. This section describes how it handles your data.

How You Sign In:

Your Session:

Signing in creates a session record on our servers and sets two cookies on api.tinypoll.io: one that keeps you signed in, and one that stops another site acting on your behalf. Sign in with Slack sets a third for the 10 minutes that sign-in takes, and clears it straight after. Our Cookie Policy lists all three. The session identifier is random and we store only a hash of it, so a copy of our database contains nothing anyone could sign in with. Sessions expire 30 days after you last use them, signing out deletes the session immediately, and you can sign out of every device at once.

What Other People Can See:

No Tracking in the Web App:

app.tinypoll.io carries no analytics, advertising, or support-chat scripts, and no third-party code at all. The only cookies it uses are the ones that sign you in and keep the app secure, and those need no consent because the app cannot work without them.

12. Website Analytics and Tracking

Our marketing website (tinypoll.io) uses the following third-party services. These apply only to visitors of that site — the Slack app uses no cookies at all, and the web app uses only the sign-in cookies described in Section 11.

Google Tag Manager / Google Analytics

We use Google Analytics to understand how visitors find and use our website (page views, traffic sources, button clicks). Google may collect your IP address (anonymised), pages visited, browser type, and referral source. See Google's Privacy Policy.

Zoho SalesIQ

We use Zoho SalesIQ to provide live chat support on our website. If you start a chat, Zoho may collect the messages you send and any information you voluntarily provide. If you leave a message when no one is online, or ask for a copy of the chat, it may also reach us by email, where it is handled like any other email you send us (see Section 1). See Zoho's Privacy Policy.

For full details on cookies and how to manage them, see our Cookie Policy.

Questions or Concerns?

If you have any questions about this Privacy Policy or our privacy practices, please contact us:

Email: privacy@tinypoll.io

Response time: We aim to respond within 30 days

See also: Terms of Service · Cookie Policy · Data Processing Agreement