Privacy Policy
Last updated: October 5, 2026
Our Privacy Promise
TinyPoll is designed with privacy first. We minimise the data we collect — the service doesn't store phone numbers or people's names from Slack. The web app reads your name and avatar from Slack each time it loads, voter names on non-anonymous polls are read from Slack and held only briefly in memory, and anything you type into a poll is kept as poll content. We do store the Slack workspace name for limited operational purposes such as identifying your installation and supporting billing. We only keep the minimum data necessary to make polling work, and we automatically delete poll data based on your plan (Free: 7 days, Pro: 30 days). Email you send us is separate: we keep what you write to us, as Section 1 explains.
The web app at app.tinypoll.io adds a sign-in, so it keeps a session for you. It never asks Slack for your email address, and it carries no analytics or advertising code. See Section 11.
1. Information We Collect
What We Do Collect:
- Slack User IDs: Anonymous identifiers from Slack (like "U1234567") to track votes and poll ownership
- Slack Team IDs: Anonymous workspace identifiers (like "T1234567") for multi-workspace support
- Slack Channel IDs: Anonymous channel identifiers (like "C1234567") to display polls in the correct channel
- Channel Name and Privacy: When you create a poll in the web app, the name of its channel and whether the channel is private, stored with the poll so the app can label it and work out who may see it. Deleted with the poll
- Poll Content: Poll questions and answer options that you create (including any text or content you choose to include)
- Voting Data: Records of votes cast on polls
- Bot Tokens: Encrypted Slack bot tokens to enable functionality (stored securely)
- Basic Metadata: Poll creation time, settings (anonymous/public), and voting statistics
- Workspace Name: The name of your Slack workspace, used to identify your installation and for billing and customer records
- Audit Records: When a poll is created, voted on, edited, closed, reopened, or deleted, we record which Slack user did it, whether they were a workspace admin, whether it happened in Slack or the web app, the poll ID, and the time. Audit records never contain the poll question, the options, or which option anyone chose — for an anonymous poll, the record shows only that you voted
What We Collect When You Use the Web App:
TinyPoll on the web (app.tinypoll.io) has to know who you are, so it stores a little more than the Slack app does. Section 11 explains how signing in works.
- Session Records: a random session identifier (stored only as a SHA-256 hash), your Slack user ID and team ID, whether Slack reports you as a workspace admin, how you signed in (a link from Slack, or Sign in with Slack), and when the session was created and last used
- Sign-in Records: short-lived one-time values that stop a sign-in link being reused and stop a Sign in with Slack response being tampered with
- Your Slack Display Name and Avatar: read from Slack each time the web app loads, so it can show who is signed in. Neither is stored
- Access Logs: IP address, user agent, request path and timestamp, recorded by our CDN and API gateway across our website, our API, and the web app, for security and abuse investigation
What We Collect When You Email Us:
If you write to any @tinypoll.io address (support, privacy, security, legal or enterprise), we keep what you send: your email address and name as they appear on the message, the message and any attachments, when it was sent, the technical headers your mail provider adds, and anything else you choose to include, such as a signature or details of your workspace or polls. We use it only to deal with your message. It is held by Google Workspace, our email provider (see Section 4), and is not copied into the TinyPoll service.
Important Note About Poll Content: We collect and store the poll questions and answer options you create. If you include personal information (PII) in your poll questions or options, that is your responsibility. We will still delete all this data according to your plan's retention period (Free: 7 days, Pro: 30 days) as part of our automatic deletion policy.
What We DON'T Store:
This list is about the TinyPoll service — the Slack app and the web app. Email you send us is different: it holds whatever you put in it (see What We Collect When You Email Us, above).
- Real names or display names — for non-anonymous polls we read them from Slack when a poll is displayed and hold them only briefly in memory, and the web app reads your own name from Slack each time it loads
- Email addresses from Slack — Sign in with Slack asks for the
openidandprofilescopes only, neveremail - Passwords — there is nothing to set, because you sign in through Slack
- Phone numbers
- Profile pictures — the web app shows your Slack avatar from Slack each time it loads, and keeps neither the image nor its URL
- Slack message content outside of polls
- Your Slack conversations or DMs
- Credit card numbers or payment details (handled entirely by Stripe)
Note: We do collect your email address if you provide one during Stripe checkout for billing purposes. See the Payment and Billing section below for details. We also have your email address, and whatever else you include, when you email us (see above).
2. How We Use Your Information
We use the limited information we collect only to:
- Provide the polling service: Create polls, track votes, display results
- Authenticate requests: Verify that requests are coming from Slack
- Prevent duplicate voting: Ensure users can only vote once per poll (when not anonymous)
- Enable poll management: Allow poll creators, and workspace admins, to edit and close polls
- Sign you in to the web app: Keep you signed in at app.tinypoll.io and work out which polls you may see and manage
- Calculate billing: Determine workspace size for plan limits and subscription management
- Improve the service: Website analytics to understand how people find and use our site (see Section 12)
- Answer your email: Reply to what you send us, and keep a record of what was asked and agreed
Legal Basis for Processing (GDPR)
If you are in the EEA, UK, or Switzerland, our legal bases for processing your data are:
- Contract performance: Processing necessary to provide the polling service you've requested (poll data, votes, workspace integration, web app sessions, and support for your workspace)
- Legitimate interests: Security logging, fraud prevention, service improvement, and answering email you send us and keeping a record of it — balanced against your privacy rights
- Contract performance: Billing and subscription management for paid plans
- Consent: Website analytics and support chat cookies (where required by law)
- Legal obligation: Handling a request to exercise your data protection rights, and keeping billing and tax records
3. Data Retention and Deletion
Automatic Data Deletion
All poll data is automatically deleted based on your plan:
- Free Plan: Data deleted after 7 days
- Pro Plan and Pro trial: Data deleted after 30 days
- Enterprise Plan: Custom retention periods available
This includes poll questions, options, votes, and any associated metadata.
Pro retention applies while your subscription is active or your workspace is on its trial. When a trial or subscription ends, or while a subscription payment is outstanding, the Free plan period applies from the next scheduled cleanup.
What Gets Deleted Based on Your Plan:
- Free Plan (7 days): Poll questions, answer options, votes, voters, and most metadata
- Pro Plan (30 days): Poll questions, answer options, votes, voters, and most metadata
- Enterprise Plan: Custom retention periods as configured
What We Retain (For Service Operations):
- Slack workspace ID (for billing and access control)
- Basic usage statistics (when polls were created, how many votes cast - no content)
- The Slack user ID of the poll creator (for poll management)
- Bot installation records (to maintain service access)
Web App Sessions and Sign-in Data:
- Sessions: deleted 30 days after you last use them. The 30 days start again each time you use the app, and signing out deletes the session straight away
- Sign-in links: valid for 10 minutes and usable once; the record that marks a link as used expires a few minutes after the link itself
- Sign in with Slack records: deleted as soon as you finish signing in, and in any case within 10 minutes
- Access logs: kept as security logs (see below)
Audit Records:
- Kept for 400 days, then deleted automatically. They outlive the polls they describe so that "who deleted that poll?" can still be answered after the poll is gone.
Email You Send Us:
- Kept for as long as we need it to deal with your message and to keep a record of what was asked and agreed, such as a refund or a deletion request. It is not on the automatic schedules above, because it is held in our email rather than in the TinyPoll service. If you ask us to delete it, we delete it from our mailbox and from the group that receives our mail, unless we have to keep it to meet a legal obligation (a refund email is a billing record, for example) or to establish or defend a legal claim. Our email provider may then take up to 180 days to remove it from its own systems.
Retention Exceptions:
Even after deletion of active poll data, we may retain certain information where required:
- Billing records: Subscription and payment records retained for tax and accounting purposes (up to 7 years as required by Australian law)
- Security logs: Operational and security logs retained for 90 days, for investigation and abuse prevention purposes, then deleted automatically
- Legal compliance: Any data subject to a legal hold or required to comply with legal obligations
- Backups: Our database keeps continuous point-in-time backups for 35 days, used only to recover from a fault. Data deleted from the live database can remain in those backups until they roll over, up to 35 days later
- Archived metadata: When a poll is deleted under your plan's retention period, we keep a small archive record for service analytics: the workspace ID, channel ID, the creator's Slack user ID, when the poll was created and archived, how many options it had, how long the question was, the total number of votes, and whether it was anonymous. It contains no question or option text and no record of who voted for what. We keep these records for 400 days, or until you ask us to delete them
4. Data Sharing and Third Parties
We Do NOT:
- Sell your data to anyone
- Share data with advertisers
- Use data for marketing purposes
- Provide data to data brokers
- Share polls or votes outside your Slack workspace
We Only Share Data With:
- Slack (Salesforce): When making API requests to display polls and manage the app (required for functionality). Slack's Privacy Policy.
- AWS (Amazon): Our hosting provider (Sydney, Australia region). AWS Privacy Policy.
- Stripe: Our payment processor, for handling subscription billing. Stripe processes payment details directly — TinyPoll never stores credit card numbers. Stripe's Privacy Policy.
- Google: Website analytics via Google Tag Manager/Analytics (website visitors only, not Slack app users). Google's Privacy Policy.
- Google (Google Workspace): Our email provider. Every message sent to a
@tinypoll.ioaddress is delivered to and stored in Google Workspace, and our replies are sent from there. Google Cloud Privacy Notice. - Zoho: Customer support chat widget on our website (website visitors only). Zoho's Privacy Policy.
- When Required by Law: Only if compelled by valid legal process (we will notify you if legally permitted)
For more detail on subprocessors, see our Data Processing Agreement.
Payment and Billing Data:
If you subscribe to a paid plan, we store:
- Your Stripe customer ID (to link your workspace to your subscription)
- Subscription status and billing period
- Billing email address (if provided during checkout)
We do not store credit card numbers, CVVs, or other payment card details. All payment processing is handled by Stripe, a PCI Level 1 certified payment processor.
Admin Identification:
For billing notifications, grace period alerts, and to decide who may manage a poll or the plan, we identify workspace administrators using the Slack users.list and users.info APIs (via our existing users:read permission). Admin status is never written to our database — it is read from Slack and cached in memory for up to six hours. In the web app it is cached with your session and re-checked with Slack at least every six hours, so losing admin rights in Slack takes effect in TinyPoll within six hours.
5. Security
We implement industry-standard security measures:
- Encryption: All data is encrypted at rest and in transit
- Access Controls: Strict access controls and authentication
- Infrastructure Security: Built on AWS with enterprise-grade security
- Request Verification: All Slack requests are cryptographically verified
- Minimal Permissions: We only request the minimum Slack permissions needed
6. Your Rights
You have the right to:
- Access: Request information about data we have about your workspace
- Deletion: Request deletion of your active service data (we'll process requests within 30 days)
- Correction: Request correction of any inaccurate data
- Restriction: Request that we restrict processing of your data in certain circumstances
- Objection: Object to processing based on legitimate interests
- Uninstall: Remove TinyPoll from your Slack workspace at any time
- Data Portability: Request a copy of your poll data before automatic deletion
- Complaint: Lodge a complaint with your local data protection authority (e.g., the OAIC in Australia, or your EEA/UK supervisory authority)
To exercise any of these rights, contact us at privacy@tinypoll.io. We aim to respond within 30 days.
Note on deletion: If you request deletion, we delete active service data (polls, votes, settings) within 30 days, and email you have sent us as Section 3 describes. Uninstalling TinyPoll removes it from your Slack workspace, but does not by itself constitute a separate deletion request. Data is otherwise handled in accordance with our retention practices, and some data may be retained where required by law or for legitimate purposes — see the Retention Exceptions in Section 3.
7. Children's Privacy
TinyPoll is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete such information.
8. International Users and Data Transfers
TinyPoll is hosted on AWS infrastructure in Australia (ap-southeast-2, Sydney). If you are using TinyPoll from outside Australia, your data will be transferred to and processed in Australia.
Australia does not have an adequacy decision from the European Commission, the UK or Switzerland. When a customer sends us personal data that is subject to the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection, to process on its behalf, the safeguard is the European Commission's Standard Contractual Clauses, with the UK Addendum and the Swiss adaptations; our Data Processing Agreement incorporates them (Section 6).
Some of our subprocessors are in the United States. For those onward transfers we rely on the subprocessors' own transfer mechanisms (e.g., EU-US Data Privacy Framework, Standard Contractual Clauses) as applicable.
Email you send us is not held on our AWS infrastructure. It is stored by Google Workspace, which may hold it in data centres outside Australia, including in the United States.
For more detail, see our Data Processing Agreement.
Controller and Processor Roles
Under data protection law, your organisation (the Slack workspace administrator) is the data controller for Personal Data processed through TinyPoll's polling service. TinyPoll acts as a data processor on your behalf.
For data we process for our own purposes (billing, website analytics, account management, and answering email you send us — apart from any data from your workspace you include, which we handle as your processor under our DPA), TinyPoll is an independent data controller as described in this Privacy Policy.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last updated" date
- For significant changes, sending a notification in Slack workspaces using TinyPoll
10. Slack-Specific Information
Slack Permissions We Request:
TinyPoll requests the following OAuth scopes when installed. Each is explained below:
- commands: To enable the
/tinypollslash command - chat:write: To post poll messages to channels where TinyPoll is invited
- chat:write.public: To post polls to public channels without needing an invite
- channels:read: To determine which channel a poll should be posted in
- groups:read: To support polls in private channels
- im:write: To send direct messages for billing notifications and upgrade prompts
- team:read: To determine workspace size for plan limits and billing
- users:read: To display user names for non-anonymous polls and to identify workspace administrators for billing notifications
Sign in with Slack (Web App):
Signing in to the web app with Slack uses Slack's OpenID Connect flow, which asks you — not your workspace admin — for two user scopes:
- openid: To confirm your Slack identity
- profile: needed for Slack to send your workspace ID. Slack also sends your name and picture with it; we use only your Slack user ID and workspace ID, and discard the rest
We do not request the email scope, so Slack never sends us your email address. These scopes are only requested when you personally sign in — installing TinyPoll does not grant them, and workspaces that installed TinyPoll before the web app existed don't need to reinstall.
How We Use the Bot Token:
The bot token allows TinyPoll to interact with your Slack workspace. We use it only to:
- Post poll messages to channels
- Update poll results in real-time
- Retrieve user display names for non-anonymous polls (when enabled)
- Verify that requests are coming from your workspace
- Send direct messages for billing and account notifications
- Check whether you are a workspace admin, and which channels you belong to, so the web app shows you only the polls you may see
11. TinyPoll on the Web (app.tinypoll.io)
TinyPoll also runs on the web at app.tinypoll.io, where you can watch results update live, vote, create polls that post to Slack, manage your polls, and export results. This section describes how it handles your data.
How You Sign In:
- From a link Slack shows only to you (the App Home tab, a direct message, a message only you can see): the link carries a signed sign-in token that lasts 10 minutes and works once. It sits in the part of the URL after the
#, which browsers never send to us or to anyone else, and the app clears it from the address bar as soon as you arrive. Treat those links as personal — anyone you forward one to could sign in as you until it expires or is used. - Sign in with Slack: links that a whole channel can see carry no token. If you don't have a session, you sign in with Slack's OpenID Connect flow (scopes
openidandprofileonly) and land back on the poll.
Your Session:
Signing in creates a session record on our servers and sets two cookies on api.tinypoll.io: one that keeps you signed in, and one that stops another site acting on your behalf. Sign in with Slack sets a third for the 10 minutes that sign-in takes, and clears it straight after. Our Cookie Policy lists all three. The session identifier is random and we store only a hash of it, so a copy of our database contains nothing anyone could sign in with. Sessions expire 30 days after you last use them, signing out deletes the session immediately, and you can sign out of every device at once.
What Other People Can See:
- You see polls from your own Slack workspace only: polls in public channels, plus private channels you belong to. A poll you may not see is indistinguishable from one that doesn't exist.
- Anonymous polls never reveal who voted — not on the web, not in Slack, not to the poll creator, not to workspace admins, and not in an exported CSV file, which contains counts only.
- Poll creators and workspace admins can edit, close, reopen, and delete the polls they manage, and export their results from the web — the same permission rules the Slack app follows.
- A CSV export has two parts: a count and percentage for each option, and — for a non-anonymous poll only — a list of which option each voter chose, by their Slack display name. It does not contain Slack user IDs or voting timestamps, and for an anonymous poll it contains the counts and nothing else.
No Tracking in the Web App:
app.tinypoll.io carries no analytics, advertising, or support-chat scripts, and no third-party code at all. The only cookies it uses are the ones that sign you in and keep the app secure, and those need no consent because the app cannot work without them.
12. Website Analytics and Tracking
Our marketing website (tinypoll.io) uses the following third-party services. These apply only to visitors of that site — the Slack app uses no cookies at all, and the web app uses only the sign-in cookies described in Section 11.
Google Tag Manager / Google Analytics
We use Google Analytics to understand how visitors find and use our website (page views, traffic sources, button clicks). Google may collect your IP address (anonymised), pages visited, browser type, and referral source. See Google's Privacy Policy.
Zoho SalesIQ
We use Zoho SalesIQ to provide live chat support on our website. If you start a chat, Zoho may collect the messages you send and any information you voluntarily provide. If you leave a message when no one is online, or ask for a copy of the chat, it may also reach us by email, where it is handled like any other email you send us (see Section 1). See Zoho's Privacy Policy.
For full details on cookies and how to manage them, see our Cookie Policy.
Questions or Concerns?
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
Email: privacy@tinypoll.io
Response time: We aim to respond within 30 days
See also: Terms of Service · Cookie Policy · Data Processing Agreement