Privacy Policy

Effective date: September 1, 2026

ABOUT THIS POLICY

This Privacy Policy explains how MegaVote Network ("MegaVote", "we", "us", or "our"), operated from Vietnam, collects and uses personal data through the MegaVote website, Slack app, licensing dashboard, and related services (collectively, the "Service").

MegaVote is designed for Slack workspaces. Your organization controls its Slack workspace and may also control data submitted through that workspace. Slack and Paddle process data under their own privacy notices.

DATA WE COLLECT

Slack workspace and installation data

When MegaVote is installed or used in Slack, we may receive and store:

  • Slack workspace ID, name, domain, current Slack plan, installation status, granted scopes, and app authorization data;
  • Slack member ID, display name, profile image, timezone, and other profile fields made available under the granted Slack permissions;
  • channel, group, direct-message, Slack message, and permalink identifiers needed to publish and manage votes; and
  • installation, authorization, and activity timestamps.

MegaVote does not read Slack message history. It receives commands, interactions, and information that Slack sends when a user directly uses the app.

Poll and vote data

We process poll questions, options, settings, schedules, destinations, responses, participation identifiers, and related timestamps. This information is needed to create polls, count responses, publish results, prevent duplicate voting, and let authorized users manage their votes.

An anonymous response hides the voter's identity from the poll audience. MegaVote still processes an internal member identifier to count and update that response. A confidential response may be visible to the poll owner as indicated in the Slack interface.

Authentication data

The licensing dashboard uses Sign in with Slack. We process the Slack workspace and member identifiers returned by Slack and set essential, HTTP-only cookies. MegaVote does not create or store a separate user password.

Billing and licensing data

Paddle is the authorized reseller and Merchant of Record for MegaVote purchases. Paddle collects payment and billing information at checkout. MegaVote receives limited information needed to provide and support licensing, including Paddle customer, subscription, transaction, price, refund, chargeback, and event identifiers; subscription status and dates; currency and transaction amounts; the paying Slack member; and the workspace that receives the license time.

MegaVote does not receive or store full payment-card numbers or card security codes. Paddle and MegaVote act as independent controllers for the buyer data each party processes. See the Paddle Privacy Policy for Paddle's practices and privacy rights.

Technical and support data

When you use the website or contact us, our hosting, network, and error-monitoring systems may process IP address, browser or device information, request timestamps, diagnostic data, and the information you include in a support request. We use this information to operate, secure, troubleshoot, and support the Service.

HOW WE USE DATA

We use personal data only as reasonably necessary to:

  • provide, authenticate, and maintain the Service;
  • create, publish, schedule, count, and manage votes and polls;
  • display information to the intended Slack workspace audience;
  • determine the Slack plan, trial, license state, pricing, and billing history of a workspace;
  • create Paddle checkout and customer-portal sessions and apply completed payments, refunds, and chargebacks to license time;
  • prevent abuse, investigate failures, secure the Service, and comply with law; and
  • respond to support, privacy, and legal requests.

Depending on applicable law, we rely on performance of a contract, legitimate interests in operating and securing the Service, compliance with legal obligations, or consent where consent is required.

We do not sell personal data, use Slack data for advertising, or use Slack data to train artificial intelligence or machine-learning models.

WHEN DATA IS SHARED

We share data only where needed for the Service:

  • Slack: to authenticate users and publish or update votes in the destinations selected by users;
  • Paddle: to process purchases, subscriptions, taxes, invoices, cancellations, refunds, fraud, and buyer support;
  • Service providers: with hosting, database, content-delivery, security, and error-monitoring providers acting under appropriate contractual and security obligations;
  • Workspace users: poll content and results are shown according to the selected visibility settings. Workspace billing screens may show payer name, subscription status, and the license effect of payments, refunds, or chargebacks to members of the same workspace; and
  • Legal and safety: where disclosure is required by law or reasonably necessary to protect users, the Service, or legal rights.

We may transfer data as part of a merger, acquisition, reorganization, or sale of the Service, subject to this Policy and applicable law.

COOKIES

MegaVote uses essential cookies only:

  • a short-lived Slack OAuth transaction cookie, normally expiring after 10 minutes; and
  • an authenticated dashboard session cookie, normally expiring after 30 days or when you sign out.

These cookies are HTTP-only and are used for authentication and security. Paddle may use its own cookies during checkout or customer-portal use under the Paddle Privacy Policy.

DATA RETENTION AND DELETION

We retain workspace, member, and poll data while the Slack app is installed or until the vote owner or workspace requests deletion. When MegaVote is uninstalled, associated Slack data is deleted within 14 business days, except for limited information that must be retained for billing, fraud prevention, security, dispute resolution, or legal compliance.

Authentication transaction data expires after approximately 10 minutes, and dashboard sessions expire after approximately 30 days. Raw webhook delivery and deduplication data is maintained within a rolling operational window and removed through regular cleanup. Billing and transaction records are retained for as long as reasonably necessary to provide licensing and meet legal, accounting, tax, fraud-prevention, and dispute obligations.

Deleted information may remain temporarily in protected backups until those backups expire under normal retention cycles.

YOUR CHOICES AND RIGHTS

Depending on your location, you may have rights to access, correct, export, restrict, object to, or delete personal data. You may submit a request through our Help Center or email [email protected]. We may need to verify your Slack identity and workspace relationship before completing a request.

Because workspace data belongs to a shared organizational environment, some requests may need to be handled by or coordinated with the Slack workspace owner or administrator. You can also:

  • delete votes you own using available MegaVote controls;
  • sign out to end the current dashboard session;
  • ask a workspace administrator to uninstall MegaVote; and
  • manage your own Paddle subscription through Manage billing.

For payment data controlled by Paddle, submit a request directly through the Paddle Privacy Policy.

INTERNATIONAL DATA TRANSFERS

MegaVote operates from Vietnam and uses service providers that may process data in other countries. Where required, we use appropriate contractual, organizational, and technical safeguards for international transfers. Local laws in those countries may differ from the laws where you live.

SECURITY

We use reasonable administrative, technical, and organizational measures intended to protect personal data. No internet transmission or storage system is completely secure, so we cannot guarantee absolute security.

CHILDREN

The Service is intended for workplace use and is not directed to children. We do not knowingly collect personal data from children in violation of applicable law. If you believe a child has provided personal data improperly, contact us so we can investigate and delete it where required.

CHANGES TO THIS POLICY

We may update this Policy to reflect changes to the Service, law, or our data practices. We will update the effective date and provide additional notice where required by law.

CONTACT US

For privacy questions or requests, use our Help Center or email [email protected].

APPENDIX 1 - SLACK PERMISSION SCOPES

MegaVote requests only Slack scopes used by the current Service. Slack explains how permissions work in Understand app permissions in Slack and its OAuth scopes reference.

Sign in with Slack scopes

  • openid: identifies the Slack user and workspace signing in to the dashboard.
  • profile: provides the user's basic Slack profile for authentication and display.

Bot scopes

  • channels:join: lets the MegaVote bot join a public channel when needed to publish a vote.
  • channels:read, groups:read, im:read, mpim:read: reads basic conversation information needed to identify and validate vote destinations; these scopes do not grant message-history access.
  • chat:write: posts and updates MegaVote messages.
  • commands: handles the /vote, /poll, and /megavote Slack commands.
  • team:read: reads basic Slack workspace information.
  • users:read: reads basic member information needed for poll display and interaction.
  • team.billing:read: reads the workspace's Slack plan to determine MegaVote pricing and licensing.