Spark Sales AIReturn to Spark

DRAFT — REQUIRES COMMUNICATIONS-COUNSEL APPROVAL BEFORE PRODUCTION PUBLICATION

SPARK SALES AI

Privacy Policy

Draft version: spark-privacy-2026-08-20-draft-2
Counsel review required.

This draft is provided for review and implementation testing only. It is not approved for production publication and is not legal advice.

1. Scope and privacy roles

This Privacy Policy explains how Spark collects, uses, discloses, retains, and protects personal information when people visit Spark’s sites, create or administer an account, purchase or use the Services, communicate with Spark, or interact with a Spark customer’s digital employee.

For account, billing, website, security, and support information, Spark generally determines why and how information is processed. For contacts, communications, recordings, transcripts, business content, and instructions a customer submits to the Services, Spark generally acts on the customer’s documented instructions as its service provider or processor. The customer remains responsible for its own privacy notices, legal bases, consents, and responses to individuals.

Privacy counsel must confirm these role allocations for every production workflow and jurisdiction before publication.

2. Information Spark collects

Account and identity information

Name, business email, telephone number, organization, job role, account identifiers, user role, authentication evidence, preferences, and account status.

Business and configuration information

Business identity, locations, websites, products, services, hours, FAQs, policies, brand guidance, workflows, qualification criteria, escalation paths, employee configurations, and approved operating instructions.

Customer-provided contacts and communications

Contact details, list and source information, consent and suppression records, communication content, call or message metadata, recordings where enabled, transcripts, summaries, dispositions, opt-outs, Do Not Call requests, appointments, and outcome evidence.

Integration information

Connection identifiers, authorization tokens or references, configuration settings, synchronization status, and data exchanged with customer-selected CRMs, calendars, communications providers, email services, and other integrations.

Payment and commercial information

Plan, order, subscription, invoice, payment status, transaction references, usage, credits, caps, and billing contact information. Payment-card details are processed by Spark’s payment provider rather than intentionally stored by Spark in full.

Device, usage, and security information

IP address, browser and device information, timestamps, pages or features used, diagnostic events, audit records, authentication events, error data, approximate location derived from IP, and information used to detect abuse or protect the Services.

Support and feedback

Messages, attachments, call notes, survey responses, feedback, and other information provided when a person requests support or communicates with Spark.

Derived information

Readiness states, classifications, summaries, suggested dispositions, usage projections, risk indicators, and other inferences generated to operate, secure, and govern the Services. Customers must review material automated outputs before relying on them.

3. Sources of information

Spark may obtain information directly from customers, authorized users, and people who communicate with a customer’s digital employee; from customer-selected integrations and service providers; from payment, identity, communications, hosting, security, and support providers; from public business sources a customer asks Spark to review; and automatically through use of the Services.

Customers must not provide information obtained unlawfully or beyond the scope of their authority. Spark’s ability to technically receive information does not establish that the customer may lawfully provide or use it.

4. How Spark uses information

  • Provide, configure, personalize, maintain, and support the Services.
  • Authenticate users, administer organizations, and enforce role-based access.
  • Execute customer-approved communications and workflows subject to governance controls.
  • Synchronize customer-selected integrations and maintain service continuity.
  • Process orders, subscriptions, usage, credits, invoices, and payment status.
  • Capture opt-outs, suppress restricted contacts, apply calling-hour and recording controls, and enforce authorization and campaign caps.
  • Monitor reliability, troubleshoot errors, prevent fraud and abuse, and protect customers, providers, recipients, and Spark.
  • Maintain audit, acceptance, authorization, readiness, communication, and outcome evidence.
  • Respond to support, privacy, legal, and security requests.
  • Comply with law, enforce agreements, and establish or defend legal claims.
  • Improve the Services using information that Spark is permitted to use, subject to contractual, privacy, and security restrictions.

5. Automated and AI-assisted processing

The Services may use automated and AI-assisted systems to understand business information, generate or classify communications, summarize interactions, recommend actions, and support digital employees. These systems may produce inaccurate or incomplete results. Spark applies governance controls, and customers are responsible for approving material instructions and maintaining appropriate human oversight.

Before publication, privacy counsel and engineering must verify and state Spark’s production practices concerning model-provider retention, provider training, human review, sensitive data, and any legally significant automated decision-making.

6. How Spark discloses information

Spark may disclose personal information only as reasonably necessary for the purposes described in this Policy:

  • Service providers and subprocessors. Hosting, communications, model, storage, authentication, payment, analytics, security, support, and integration providers that process information under contractual restrictions.
  • Customer-authorized integrations. CRMs, calendars, email systems, communications providers, and other services the customer directs Spark to connect.
  • Customer organizations. Authorized account users may access information associated with their organization and its communications.
  • Legal and safety recipients. Government authorities, courts, advisers, affected parties, or providers when reasonably necessary to comply with law, protect rights or safety, investigate misuse, or preserve the integrity of the Services.
  • Corporate transactions. Parties to a financing, merger, acquisition, reorganization, or sale, subject to appropriate confidentiality and continued protection.

Spark does not disclose one customer’s Customer Materials to another customer except at the first customer’s direction or as legally required.

7. Selling, sharing, and targeted advertising

Spark does not sell Customer Materials for money. Spark’s production website, cookie, analytics, and advertising practices must be assessed under applicable state definitions of “sale,” “sharing,” and targeted advertising.

Before publication, privacy counsel and engineering must confirm whether any production activity constitutes sale, sharing, or targeted advertising and add the required opt-out links, preference-signal handling, and category disclosures. This draft does not waive any applicable privacy right.

8. Cookies and similar technologies

Spark may use cookies and similar technologies that are necessary for authentication, security, preferences, service operation, diagnostics, and approved analytics. The production notice must identify the categories actually in use and provide consent or opt-out controls where required.

Spark will honor legally required browser-based opt-out preference signals when they apply to Spark’s practices. Account authentication and strictly necessary security technologies may continue where permitted.

9. Communications recipients and customer responsibility

When Spark processes information about a person contacted on behalf of a customer, that customer determines the communication’s purpose, audience, content, legal basis, and instructions. Privacy requests, consent revocations, opt-outs, and Do Not Call requests received during a communication may be recorded and relayed to the customer and applied to Spark’s suppression controls.

Recipients may contact the identified business or support@sparksalesai.com if they believe Spark processed information for that business. Spark may need information identifying the customer or communication to route and verify the request.

10. Data retention

Spark retains information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain account and transaction records, preserve consent, suppression, authorization, acceptance, communication, security, and outcome evidence, resolve disputes, enforce agreements, and comply with law.

Retention periods vary by information type, customer configuration, legal requirements, contractual commitments, sensitivity, and the need to prevent repeated contact or misuse. Some suppression and audit records may be retained after account closure so Spark can continue honoring opt-outs, demonstrate compliance, and protect the Services.

Counsel and engineering must approve a production retention schedule and ensure this disclosure matches implemented deletion and backup behavior.

11. Security

Spark uses administrative, technical, and organizational safeguards designed to protect information, including access controls, tenant separation, credential protections, audit logging, deployment governance, provider restrictions, and incident-response procedures appropriate to the Services. No system can guarantee absolute security.

Customers are responsible for securing their accounts, devices, integrations, and authorized users and for promptly reporting suspected compromise to support@sparksalesai.com. Additional information is available on Spark’s Security page.

12. Privacy rights and requests

Depending on location and applicable law, individuals may have rights to know or access personal information, correct inaccuracies, delete information, obtain a portable copy, opt out of certain sale, sharing, targeted advertising, or profiling, restrict or object to processing, withdraw consent, appeal a decision, or receive equal service without unlawful discrimination.

Requests may be submitted to support@sparksalesai.com. The requester should describe the relationship with Spark and the relevant customer organization. Spark will request only the information reasonably necessary to verify and process the request. Authorized agents may submit requests where permitted, subject to verification of their authority.

Where Spark processes information solely for a customer, Spark may direct the request to that customer or assist the customer in responding. Spark may deny or limit a request where an exception applies, including when information must be retained for security, suppression, legal compliance, or claims, and will provide an explanation and appeal path where required.

13. U.S. state privacy disclosures

Where applicable state privacy laws require additional disclosures, the categories described in Section 2 are collected for the purposes in Section 4 and disclosed to the recipient categories in Section 6. Spark’s production policy must include the legally required lookback period, sensitive-information treatment, rights metrics or jurisdiction-specific supplements, and sale/sharing determinations based on verified production practices.

Privacy counsel must determine which state laws apply to Spark and finalize all California and other state-specific notices before publication.

14. International data transfers

Spark and its providers may process information in the United States and other locations where they operate. Where required, Spark will use approved contractual or other transfer safeguards. The Data Processing Addendum will identify the applicable transfer mechanism for covered customer processing.

15. Children’s information

The Services are designed for businesses and are not directed to children. Customers must not use Spark to intentionally collect or communicate with children in violation of law or without Spark’s express written approval and all required safeguards. If Spark learns that prohibited children’s information was submitted, it may restrict the account and delete or isolate the information as legally permitted.

16. Changes to this Policy

Spark may update this Policy to reflect changes in law, providers, security, or the Services. Spark will post the current version and provide additional notice appropriate to the materiality of the change. When a change materially alters the governing customer agreement, Spark will require a new account-level acceptance before the applicable checkout or first activation can be completed.

17. Contact and unresolved items

Privacy questions and requests may be sent to support@sparksalesai.com.

Before publication, counsel must insert Spark’s complete legal entity, postal address, privacy contact, any required appeal channel or toll-free method, and the policy’s effective date.

Legal & Compliance
Terms of ServicePrivacy PolicyAcceptable Use PolicyCommunications Compliance PolicyData Processing AddendumSecurityContact Support

Spark provides governed communications technology. Customers are responsible for the contacts, consent, content, and instructions they provide. Spark does not provide legal advice.