Spark Studio Ltd
Privacy Policy
Last updated: 5 September 2026 · Effective date: 4 September 2026
1. Who we are
Spark Studio Ltd, trading as Spark Loyalty ("Spark", "we", "us", "our"), is a company registered in England and Wales, company number 17267086. Our registered office is 48 Crowestones, Buxton, England, SK17 6NZ.
We provide digital loyalty cards that live inside Apple Wallet and Google Wallet. Independent businesses create a card, their customers add it to their phone, and the card keeps count.
We are the controller of the personal data described in sections 3 and 5, and a processor for the data described in section 4. Section 2 explains which applies to you.
If you have a question about this policy or about how we handle personal data, email support@sparkloyalty.co.uk.
2. Who this policy is for, and who is responsible for what
This policy covers three groups of people. It matters which one you are, because it changes who is responsible for your data.
Merchants. Business owners and their team who create a Spark account and use our dashboard. For your data, Spark is the controller.
Website visitors. Anyone who visits sparkloyalty.co.uk. For your data, Spark is the controller.
Members. Customers of a business that uses Spark, who hold one of that business's loyalty cards. For your data, the business is the controller and Spark is its processor. We only process your data on that business's instructions, to run their loyalty card. If you want to know how a particular business uses your data, or you want your data deleted, contact that business directly and their own privacy notice applies. If you contact us instead, we will pass your request to them and tell you we have done so.
Spark never contacts members on its own initiative, and never uses member data for Spark's own marketing.
Merchants should read this policy alongside our Data Processing Agreement at sparkloyalty.co.uk/dpa. That agreement, not this policy, governs how we handle member data on a merchant's behalf, and it forms part of our Terms of Service.
Throughout this policy, "the service" means the Spark dashboard at app.sparkloyalty.co.uk, the loyalty cards we issue to Apple Wallet and Google Wallet, and our website.
3. Merchants: what we collect
When you create an account and use the service, we collect:
About you. Your first name, and your email address. If you sign in with Google, we receive your name, email address and Google account identifier from Google, in line with the permissions you grant.
About your business. Business name, business category, your logo, and the address and postcode of each location you operate. Addresses and postcodes are optional, and are used to set the neighbourhood your card can appear in, never to display your exact address to anyone. If your business trades from more than one location, we hold the address and postcode of each one you tell us about.
Your account. Your password, stored only as a salted hash so that nobody at Spark can read it, your plan, and your account preferences. If your plan includes team accounts, the same applies to each team member you invite.
Billing. Your plan, billing history, and the last four digits and expiry date of your payment card. We never see or store your full card number. Card details are entered directly into our payment processor's systems.
How you use the service. Which screens and features you use, cards you create, messages you send, and technical logs. We use this to keep the service working and to make it better. If you agree to it, we also record how you move around the dashboard, as section 11 describes.
What you send us. Emails and support messages, and anything you attach to them.
Technical data. IP address, browser and device type, and cookie data. Section 11 covers cookies.
We do not ask for a phone number, a date of birth, or anything about your finances beyond what is needed to take payment.
4. Members: what we process for a merchant
When someone scans a merchant's join code and adds a card to Apple Wallet or Google Wallet, we process the following on that merchant's behalf:
- A random, unguessable identifier for the card. It is not derived from a name, an email address or a device ID, and it cannot be reversed into one.
- The identifier Apple or Google gives us for the card, so we can keep it up to date.
- Stamps, visits or points collected, rewards earned and rewards claimed, and the date of the most recent visit.
- A first name and an email address, where the merchant has these and has chosen to use them. Neither is required to hold a card.
Location. We do not collect, receive or store any member's location. When a merchant chooses to switch on lock screen relevance, we include the merchant's own trading locations in the card, up to the number their plan allows. Apple or Google then decide, on the phone itself, whether to show the card on the lock screen. That decision happens on the device. Spark is never told where anyone is.
Payments. Spark is not a payment system. We never see what a member spent, what they bought, or how they paid. Where a merchant runs a points card, the merchant or their team enter the amount, and we store only the resulting points figure.
Our full obligations to merchants in respect of this data, including security, sub-processors, breach notification and deletion, are set out in our Data Processing Agreement at sparkloyalty.co.uk/dpa.
5. Website visitors: what we collect
If you visit sparkloyalty.co.uk we collect technical and analytics data as described in sections 3 and 11. If you subscribe to our newsletter we collect your email address, and you can unsubscribe from any email we send.
6. How we collect it
We collect personal data:
- Directly from you, when you sign up, fill in a form, or contact us.
- Automatically, when you use the service or visit our website, through cookies and technical logs.
- From merchants, in the case of member data.
- From our service providers, such as our payment processor and our analytics tool.
7. Why we use it, and our lawful basis
Create and run your Spark account
- Why
- To give you the service you signed up for
- Lawful basis
- Performance of a contract
Issue and update loyalty cards
- Why
- Same
- Lawful basis
- Performance of a contract
Take payment and keep billing records
- Why
- To charge for the service and meet our accounting duties
- Lawful basis
- Performance of a contract, and legal obligation
Answer your support messages
- Why
- To help you
- Lawful basis
- Performance of a contract, and legitimate interests
Send you service emails, such as billing notices, trial reminders and important changes
- Why
- So you are not caught out by something about your own account
- Lawful basis
- Performance of a contract, and legitimate interests
Send you marketing about Spark
- Why
- To tell you about the product
- Lawful basis
- Consent, or legitimate interests where you are already a customer. You can opt out at any time and every email carries an unsubscribe link
Understand how the service is used, and improve it
- Why
- To make Spark better. We use aggregated or anonymised data wherever it will do the job
- Lawful basis
- Legitimate interests
Record how you use the dashboard
- Why
- To find where the dashboard is confusing or slow, and fix it
- Lawful basis
- Consent. You are asked the first time you open the dashboard, and you can change your answer in Settings at any time
Keep the service secure, and prevent fraud and abuse
- Why
- To protect merchants and members
- Lawful basis
- Legitimate interests
Meet legal, tax and regulatory obligations
- Why
- Because we have to
- Lawful basis
- Legal obligation
| What we do | Why | Lawful basis |
|---|---|---|
| Create and run your Spark account | To give you the service you signed up for | Performance of a contract |
| Issue and update loyalty cards | Same | Performance of a contract |
| Take payment and keep billing records | To charge for the service and meet our accounting duties | Performance of a contract, and legal obligation |
| Answer your support messages | To help you | Performance of a contract, and legitimate interests |
| Send you service emails, such as billing notices, trial reminders and important changes | So you are not caught out by something about your own account | Performance of a contract, and legitimate interests |
| Send you marketing about Spark | To tell you about the product | Consent, or legitimate interests where you are already a customer. You can opt out at any time and every email carries an unsubscribe link |
| Understand how the service is used, and improve it | To make Spark better. We use aggregated or anonymised data wherever it will do the job | Legitimate interests |
| Record how you use the dashboard | To find where the dashboard is confusing or slow, and fix it | Consent. You are asked the first time you open the dashboard, and you can change your answer in Settings at any time |
| Keep the service secure, and prevent fraud and abuse | To protect merchants and members | Legitimate interests |
| Meet legal, tax and regulatory obligations | Because we have to | Legal obligation |
Where we rely on legitimate interests, we have considered your rights and reached the view that our interest does not override them. Ask us at support@sparkloyalty.co.uk if you would like more detail on any of these.
Where we rely on consent, you can withdraw it at any time. That does not affect anything we did lawfully before you withdrew it.
For member data, the lawful basis is the merchant's to establish, not ours. Merchants are responsible for having a lawful basis for the messages they send.
8. Push Agent, and automated processing
Push Agent is the messaging tool inside the Spark dashboard. A merchant describes what they want to say in plain language, and Push Agent drafts a message and suggests which of their members to send it to. It can also run standing reminders, for example when a member is one stamp from a reward.
How this works, in terms of data:
- Push Agent uses member data held for that merchant, such as stamps collected and the date of the last visit, to group members and to draft copy.
- The merchant chooses the group, sees the message, and decides whether to send it. Push Agent never sends anything on its own initiative.
- To draft copy we send the merchant's instruction, their chosen tone and the relevant business details to Anthropic, acting as our processor. We do not send Anthropic member records, member names or member email addresses.
- We do not use merchant data or member data to train AI models. Not ours, and not anyone else's. Anthropic does not train models on anything we send it, and that is a contractual commitment rather than a setting.
We do not make solely automated decisions about anyone that have a legal effect or a similarly significant effect on them. Nothing in Push Agent decides whether you get an account, a price, or access to anything.
Turning messages off. A member can turn off notifications for a card inside Apple Wallet or Google Wallet, or remove the card from their wallet, at any time. Removing the card stops all messages relating to it.
9. Who we share it with
We do not sell personal data, and we never will.
We use a small number of service providers to run Spark. Each of them acts as our processor under a written data processing agreement, and each is only allowed to use the data to provide their service to us.
Every one of them is named at sparkloyalty.co.uk/subprocessors, along with what it does, where it processes data, and the safeguard that covers any transfer outside the UK. That page is the current list, we keep it up to date, and it is the same list our Data Processing Agreement refers to.
As at the date of this policy, the providers who handle member data on a merchant's behalf are:
- Vercel, for hosting our website and dashboard.
- Supabase, for our database and for signing you in.
- Anthropic, for drafting Push Agent message copy, on the limited basis described in section 8.
The providers who handle our own data, meaning data about merchants and website visitors rather than members, are:
- Stripe, for taking payment and managing subscriptions.
- Resend, for sending service and marketing email to merchants. We do not send email to members.
- Google, for website analytics through Google Analytics, on our website only. Section 11 explains what this collects and how to decline it.
- Microsoft, for website analytics and session recording through Microsoft Clarity, on our website and, only if you agree, in the merchant dashboard. It never runs on the pages where a member adds a card. Section 11 explains what this records and how to decline it. Microsoft also uses this data for its own purposes, so it acts as a controller in its own right as well as our processor.
Before we add a provider who will handle member data, or replace one, we give merchants at least 30 days' notice by updating that page and by email. Clause 6.3 of our Data Processing Agreement sets out how to object.
We also share data with:
Apple and Google, to the extent needed to deliver a card to Apple Wallet or Google Wallet and keep it up to date. They act as independent controllers for what happens on the device, including whether a card appears on a lock screen, and their own privacy policies apply.
Law enforcement, regulators, courts or professional advisers, where we are required to by law or where we need advice on a legal claim.
A buyer or successor, if Spark is sold or merged. We will tell merchants before this happens.
10. International transfers
Some of our providers process personal data outside the UK, including in the United States. Where that happens we put appropriate safeguards in place, normally the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, along with an assessment of the risks of that particular transfer.
The safeguard that applies to each provider is shown at sparkloyalty.co.uk/subprocessors. For a copy of the safeguard itself, or of the transfer risk assessment behind it, email support@sparkloyalty.co.uk.
11. Cookies and similar technologies
Cookies are small files stored on your device. The same rules cover similar things like local storage and tracking pixels, so where this section says cookies, it means all of them.
There is no separate cookie policy, because the list below is the whole of it.
Sign-in and session cookies
- What it does
- Keep you signed in to the dashboard and keep your session secure
- Type
- Strictly necessary
- How long
- Until you sign out, or your session expires
Cookie preference
- What it does
- Remembers what you chose about the cookies below, on the website and in the dashboard
- Type
- Strictly necessary
- How long
- 12 months
Stripe (__stripe_mid, __stripe_sid)
- What it does
- Prevents fraud when you pay. Only set on our billing pages
- Type
- Strictly necessary
- How long
- Up to 1 year
Google Analytics (_ga, _ga_*)
- What it does
- Counts visitors to our website and tells us which pages they visit and what brought them here. Website only. Google does not store your IP address, but it does use this data for its own purposes
- Type
- Analytics
- How long
- Up to 2 years
Microsoft Clarity (_clck, _clsk, CLID, MUID and related)
- What it does
- Records how visitors move around our website and, if you agree, how merchants move around the dashboard, including clicks, scrolling and session recordings, so we can see where people get stuck. Microsoft also uses this data for its own purposes, including advertising
- Type
- Analytics and advertising
- How long
- Up to 1 year
| What we set | What it does | Type | How long |
|---|---|---|---|
| Sign-in and session cookies | Keep you signed in to the dashboard and keep your session secure | Strictly necessary | Until you sign out, or your session expires |
| Cookie preference | Remembers what you chose about the cookies below, on the website and in the dashboard | Strictly necessary | 12 months |
Stripe (__stripe_mid, __stripe_sid) | Prevents fraud when you pay. Only set on our billing pages | Strictly necessary | Up to 1 year |
Google Analytics (_ga, _ga_*) | Counts visitors to our website and tells us which pages they visit and what brought them here. Website only. Google does not store your IP address, but it does use this data for its own purposes | Analytics | Up to 2 years |
Microsoft Clarity (_clck, _clsk, CLID, MUID and related) | Records how visitors move around our website and, if you agree, how merchants move around the dashboard, including clicks, scrolling and session recordings, so we can see where people get stuck. Microsoft also uses this data for its own purposes, including advertising | Analytics and advertising | Up to 1 year |
Strictly necessary cookies cannot be switched off, because the site and dashboard do not work without them.
Everything else is only set if you agree. Nothing in the bottom two rows of that table is set before you say yes. On the website you are asked through the cookie settings in the footer. In the dashboard you are asked once, the first time you open it, and you can change your answer at any time in Settings under Legal and data. Blocking cookies through your browser works too, though it may stop parts of the service working.
The pages where a member adds a card, and the cards themselves, set only strictly necessary cookies. No analytics and no session recording ever run on a join page or in a wallet card, which is why a member is never asked about cookies. That is a promise to merchants as much as to members: nothing we do to understand our own product ever touches your customers.
About session recording. Microsoft Clarity records mouse movement, clicks, scrolling and the pages you visit, and plays them back to us as a session. On the website it runs if you accept analytics and advertising cookies. In the dashboard it runs only if you say yes when we ask, and it is off until you do. Wherever it runs, everything you type is masked, and in the dashboard your members' names and details on screen are masked too, so a recording shows us how you moved through a screen, not who your regulars are. We use it to find usability problems, not to identify individuals.
If you would rather not be recorded, decline on the website or say no in the dashboard, and nothing is captured. You can change your mind either way at any time.
12. How long we keep it
Merchant account data
- How long
- For as long as your account is open, then 6 years after closure for legal and accounting reasons
Billing and transaction records
- How long
- 6 years, in line with HMRC requirements
Member data held for a merchant
- How long
- For as long as that merchant's account is open, then 90 days, then we delete it
Support messages
- How long
- 3 years from the last message
Marketing data
- How long
- Until you unsubscribe or withdraw consent, then we keep a minimal record so we do not email you again
Website and dashboard analytics
- How long
- 14 months
Session recordings
- How long
- 30 days, then deleted by Microsoft
Technical and security logs
- How long
- 12 months
| Data | How long |
|---|---|
| Merchant account data | For as long as your account is open, then 6 years after closure for legal and accounting reasons |
| Billing and transaction records | 6 years, in line with HMRC requirements |
| Member data held for a merchant | For as long as that merchant's account is open, then 90 days, then we delete it |
| Support messages | 3 years from the last message |
| Marketing data | Until you unsubscribe or withdraw consent, then we keep a minimal record so we do not email you again |
| Website and dashboard analytics | 14 months |
| Session recordings | 30 days, then deleted by Microsoft |
| Technical and security logs | 12 months |
If a merchant's free trial or subscription ends, we do not delete their cards or their member data straight away. We keep both for 90 days so the merchant can pick up where they left off, and we delete them after that. This is deliberate: a loyalty card that vanishes overnight looks like a broken promise from the business, not from us.
Deleted data may persist in encrypted backups for up to 90 days after it leaves our live systems, and is deleted in the ordinary course of our backup rotation. It is not restored or used for anything in the meantime.
13. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Rectification, to have inaccurate data corrected.
- Erasure, to have data deleted in certain circumstances.
- Restriction, to limit how we use your data.
- Portability, to receive your data in a structured, machine-readable format.
- Object to processing based on legitimate interests, and to object to direct marketing at any time, which we will always honour.
- Withdraw consent, where consent is what we relied on.
To use any of these rights, email support@sparkloyalty.co.uk. We will reply within one calendar month. We may need to check who you are first. There is no charge, unless a request is excessive or repetitive.
If you are a member, exercise these rights with the business whose card you hold. They are the controller of your data. If you come to us, we will forward your request to them within five working days and confirm to you that we have done it.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you spoke to us first so we can put it right.
14. Security
We protect personal data with appropriate technical and organisational measures, including encryption in transit and at rest, hashed passwords, access controls on a need to know basis, separation of each merchant's data from every other merchant's, and regular reviews.
Card identifiers are random and unguessable, and hold no personal data in themselves.
The measures that apply to member data are set out in full in Annex III of our Data Processing Agreement at sparkloyalty.co.uk/dpa.
No system is completely secure. If there is a breach that is likely to affect your rights and freedoms, we will tell the ICO within 72 hours and tell you without undue delay, as UK GDPR requires. Where the breach affects member data, we tell the merchant within 48 hours of becoming aware of it, as our Data Processing Agreement requires.
15. Children and young people
The Spark dashboard is for businesses. You must be 18 or over to create a Spark account, and we do not knowingly collect data from anyone under 18 as a merchant.
Loyalty cards are a different matter. A merchant's customers may include people under 18, and a young person can add a card to their phone. We keep member data to the minimum needed to make a card work, we never profile members for Spark's own purposes, and we never use member data for advertising. Merchants are responsible for their own obligations towards younger customers.
If you believe we hold data about a child that should not be there, email support@sparkloyalty.co.uk and we will look into it and delete it if we should.
16. Changes to this policy
We update this policy as the product changes. Where a change is material, we will tell merchants by email or in the dashboard before it takes effect. The date at the top always shows the current version.
17. Contact us
Spark Studio Ltd, trading as Spark Loyalty
48 Crowestones, Buxton, England, SK17 6NZ
We have not appointed a Data Protection Officer, as we are not required to. Data protection questions go to the address above.