Last Updated: July 29, 2026
Introduction
Sparko ("Sparko," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information. And because Sparko plays two different roles depending on whose data it is, Section 1 explains which role applies before anything else.
1. Sparko’s Two Roles
Depending on what data is involved, Sparko acts in one of two distinct roles under data protection law:
- As Controller: for data about you as a website visitor, a prospective customer, or an administrator/billing contact on a Sparko account. Here, Sparko decides why and how that data is used, same as any SaaS vendor’s own marketing and billing data.
- As Processor: for Employee Data, Applicant Data, Payroll Data, and Performance Data that a Customer inputs about their own employees and candidates. Here, Sparko only processes that data on the Customer’s documented instructions, under the Data Processing Agreement. Sparko doesn’t decide why that data exists or what it’s used for.
Throughout this Policy, each data category is labeled [Controller] or [Processor] so it’s clear which role applies.
2. Information We Collect
2.1 Information You Provide
- Account Information [Controller]: Name, email, company name, job title
- Employee Data [Processor; see Section 1]: Data you input about your employees
- Payment Information [Controller; processed by our payment subprocessor]: Billing details processed by our payment provider
- Communications [Controller]: Messages you send to us
2.2 Information Collected Automatically
- Usage Data [Controller]: Features used, pages visited, actions taken
- Device Information [Controller]: Browser type, IP address, device identifiers
- Cookies [Controller]: Session cookies and analytics cookies
3. How We Use Your Information
We use collected information to:
- Provide and maintain the Services
- Process transactions and send related information
- Send administrative communications
- Respond to inquiries and provide support
- Improve and personalize the Services
- Monitor usage and analyze trends
- Detect and prevent fraud or abuse
- Comply with legal obligations
4. AI and Your Data
Our Services include AI-powered features. Here's how we handle your data in relation to AI:
- No Cross-Customer Training: We do not use your data to train AI models that benefit other customers
- Data Isolation: Your data is logically separated from other customers' data
- Transparency: AI features are clearly identified in the product
- Human Oversight: AI suggestions can always be reviewed and overridden by users
- AI Infrastructure: AI features are powered by third-party AI infrastructure providers bound by data-protection obligations; see the sub-processor list in our Data Processing Agreement. Your data is not used to train their models
4a. AI Processing Data Flow
Here is what data reaches our AI providers for each AI-powered feature, and what is excluded:
| AI feature | Data sent to provider | Purpose | Excluded / minimized |
|---|
| Performance review drafting | Role, department, tenure, review inputs | Draft for human review | Name, SSN, DOB, home address excluded by design |
| Career / development plans | Role, skills, goals | Draft for human review | Name, SSN, DOB excluded by design |
| Resume screening & parsing | Resume text | Parsing, scoring against role | Candidate name / direct contact info anonymized before scoring |
| Ask Sparko assistant | Employee’s own permitted data (leave balances, OKRs, team summaries) | Conversational assistant, drafts & actions | Sensitive identifiers excluded by design |
5. Information Sharing
We may share your information with:
- Service Providers: Third parties who help us operate the Services (hosting, AI processing, payment processing, email delivery, analytics)
- Legal Requirements: When required by law or to protect rights
- Business Transfers: In connection with a merger or acquisition
- With Your Consent: When you direct us to share information
We do not sell your personal information to third parties.
6. Data Retention
How long we keep information depends on its category:
| Category | Role | Retention |
|---|
| Employee, Applicant, Payroll & Performance Data | Processor | Exportable for 30 days after account termination; deleted within 90 days; backup copies purged within 180 days, per the Data Processing Agreement |
| Candidate résumés (unprogressed applications) | Processor | Deleted 365 days after upload. Once an application reaches interviewing, offer, or hired, the résumé is kept as part of the hiring record |
| Account & billing records | Controller | 7 years, for tax and accounting purposes |
| Marketing & prospect contact data | Controller | Until you unsubscribe, or after 24 months of inactivity |
| Product usage & analytics data | Controller | 14 months |
| Support communications | Controller | 24 months after resolution |
Some data may be retained longer where required by law.
7. Data Security
We implement industry-standard security measures including:
- AES-256 encryption at rest
- TLS 1.2+ encryption in transit
- Regular security assessments using industry-standard tools
- Access controls and audit logging
- AWS infrastructure with enterprise-grade security
For more details, see our Security page.
8. Your Rights
Depending on your location, you may have rights to:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data
- Portability: Receive your data in a portable format
- Objection: Object to certain processing activities
- Restriction: Request restriction of processing
To exercise these rights, contact us at [email protected].
9. GDPR Compliance
For users in the European Economic Area (EEA), we comply with GDPR requirements:
- We process data under legitimate interest or contract performance
- We offer Data Processing Agreements (DPA) for customers
- We support data subject access requests
- We maintain records of processing activities
See our Data Processing Agreement for more details.
10. CCPA Compliance
For California residents, we comply with CCPA requirements:
- We disclose categories of personal information collected
- We do not sell personal information
- We honor requests to know, delete, and opt-out
- We do not discriminate against users who exercise their rights
11. Cookies
When you visit sparko.app, a cookie banner lets you choose which categories of cookies to allow:
- Necessary: Required for the site to function: session handling and security. These cannot be turned off.
- Analytics: Helps us understand which pages are useful, via anonymized traffic and engagement data. Only set if you opt in.
- Marketing: Used for ad conversion tracking and remarketing. Only set if you opt in.
You can change your choices at any time using the “Cookie Preferences” link in the site footer, or through your browser settings. Declining Analytics or Marketing cookies does not affect core site functionality.
12. Children's Privacy
Our Services are not intended for children under 16. We do not knowingly collect personal information from children. If we learn we have collected such information, we will delete it promptly.
13. International Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including Standard Contractual Clauses where required. See the Data Processing Agreement for the specific transfer mechanism that applies.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Services. Your continued use after changes constitutes acceptance.
15. Contact Us
For privacy-related questions or to exercise your rights:
Email: [email protected]