Spark

Spark Studio Ltd

Privacy Policy

Last updated: 5 September 2026 · Effective date: 4 September 2026

1. Who we are

Spark Studio Ltd, trading as Spark Loyalty ("Spark", "we", "us", "our"), is a company registered in England and Wales, company number 17267086. Our registered office is 48 Crowestones, Buxton, England, SK17 6NZ.

We provide digital loyalty cards that live inside Apple Wallet and Google Wallet. Independent businesses create a card, their customers add it to their phone, and the card keeps count.

We are the controller of the personal data described in sections 3 and 5, and a processor for the data described in section 4. Section 2 explains which applies to you.

If you have a question about this policy or about how we handle personal data, email support@sparkloyalty.co.uk.

2. Who this policy is for, and who is responsible for what

This policy covers three groups of people. It matters which one you are, because it changes who is responsible for your data.

Merchants. Business owners and their team who create a Spark account and use our dashboard. For your data, Spark is the controller.

Website visitors. Anyone who visits sparkloyalty.co.uk. For your data, Spark is the controller.

Members. Customers of a business that uses Spark, who hold one of that business's loyalty cards. For your data, the business is the controller and Spark is its processor. We only process your data on that business's instructions, to run their loyalty card. If you want to know how a particular business uses your data, or you want your data deleted, contact that business directly and their own privacy notice applies. If you contact us instead, we will pass your request to them and tell you we have done so.

Spark never contacts members on its own initiative, and never uses member data for Spark's own marketing.

Merchants should read this policy alongside our Data Processing Agreement at sparkloyalty.co.uk/dpa. That agreement, not this policy, governs how we handle member data on a merchant's behalf, and it forms part of our Terms of Service.

Throughout this policy, "the service" means the Spark dashboard at app.sparkloyalty.co.uk, the loyalty cards we issue to Apple Wallet and Google Wallet, and our website.

3. Merchants: what we collect

When you create an account and use the service, we collect:

About you. Your first name, and your email address. If you sign in with Google, we receive your name, email address and Google account identifier from Google, in line with the permissions you grant.

About your business. Business name, business category, your logo, and the address and postcode of each location you operate. Addresses and postcodes are optional, and are used to set the neighbourhood your card can appear in, never to display your exact address to anyone. If your business trades from more than one location, we hold the address and postcode of each one you tell us about.

Your account. Your password, stored only as a salted hash so that nobody at Spark can read it, your plan, and your account preferences. If your plan includes team accounts, the same applies to each team member you invite.

Billing. Your plan, billing history, and the last four digits and expiry date of your payment card. We never see or store your full card number. Card details are entered directly into our payment processor's systems.

How you use the service. Which screens and features you use, cards you create, messages you send, and technical logs. We use this to keep the service working and to make it better. If you agree to it, we also record how you move around the dashboard, as section 11 describes.

What you send us. Emails and support messages, and anything you attach to them.

Technical data. IP address, browser and device type, and cookie data. Section 11 covers cookies.

We do not ask for a phone number, a date of birth, or anything about your finances beyond what is needed to take payment.

4. Members: what we process for a merchant

When someone scans a merchant's join code and adds a card to Apple Wallet or Google Wallet, we process the following on that merchant's behalf:

  • A random, unguessable identifier for the card. It is not derived from a name, an email address or a device ID, and it cannot be reversed into one.
  • The identifier Apple or Google gives us for the card, so we can keep it up to date.
  • Stamps, visits or points collected, rewards earned and rewards claimed, and the date of the most recent visit.
  • A first name and an email address, where the merchant has these and has chosen to use them. Neither is required to hold a card.

Location. We do not collect, receive or store any member's location. When a merchant chooses to switch on lock screen relevance, we include the merchant's own trading locations in the card, up to the number their plan allows. Apple or Google then decide, on the phone itself, whether to show the card on the lock screen. That decision happens on the device. Spark is never told where anyone is.

Payments. Spark is not a payment system. We never see what a member spent, what they bought, or how they paid. Where a merchant runs a points card, the merchant or their team enter the amount, and we store only the resulting points figure.

Our full obligations to merchants in respect of this data, including security, sub-processors, breach notification and deletion, are set out in our Data Processing Agreement at sparkloyalty.co.uk/dpa.

5. Website visitors: what we collect

If you visit sparkloyalty.co.uk we collect technical and analytics data as described in sections 3 and 11. If you subscribe to our newsletter we collect your email address, and you can unsubscribe from any email we send.

6. How we collect it

We collect personal data:

  • Directly from you, when you sign up, fill in a form, or contact us.
  • Automatically, when you use the service or visit our website, through cookies and technical logs.
  • From merchants, in the case of member data.
  • From our service providers, such as our payment processor and our analytics tool.

7. Why we use it, and our lawful basis

Create and run your Spark account

Why
To give you the service you signed up for
Lawful basis
Performance of a contract

Issue and update loyalty cards

Why
Same
Lawful basis
Performance of a contract

Take payment and keep billing records

Why
To charge for the service and meet our accounting duties
Lawful basis
Performance of a contract, and legal obligation

Answer your support messages

Why
To help you
Lawful basis
Performance of a contract, and legitimate interests

Send you service emails, such as billing notices, trial reminders and important changes

Why
So you are not caught out by something about your own account
Lawful basis
Performance of a contract, and legitimate interests

Send you marketing about Spark

Why
To tell you about the product
Lawful basis
Consent, or legitimate interests where you are already a customer. You can opt out at any time and every email carries an unsubscribe link

Understand how the service is used, and improve it

Why
To make Spark better. We use aggregated or anonymised data wherever it will do the job
Lawful basis
Legitimate interests

Record how you use the dashboard

Why
To find where the dashboard is confusing or slow, and fix it
Lawful basis
Consent. You are asked the first time you open the dashboard, and you can change your answer in Settings at any time

Keep the service secure, and prevent fraud and abuse

Why
To protect merchants and members
Lawful basis
Legitimate interests

Meet legal, tax and regulatory obligations

Why
Because we have to
Lawful basis
Legal obligation

Where we rely on legitimate interests, we have considered your rights and reached the view that our interest does not override them. Ask us at support@sparkloyalty.co.uk if you would like more detail on any of these.

Where we rely on consent, you can withdraw it at any time. That does not affect anything we did lawfully before you withdrew it.

For member data, the lawful basis is the merchant's to establish, not ours. Merchants are responsible for having a lawful basis for the messages they send.

8. Push Agent, and automated processing

Push Agent is the messaging tool inside the Spark dashboard. A merchant describes what they want to say in plain language, and Push Agent drafts a message and suggests which of their members to send it to. It can also run standing reminders, for example when a member is one stamp from a reward.

How this works, in terms of data:

  • Push Agent uses member data held for that merchant, such as stamps collected and the date of the last visit, to group members and to draft copy.
  • The merchant chooses the group, sees the message, and decides whether to send it. Push Agent never sends anything on its own initiative.
  • To draft copy we send the merchant's instruction, their chosen tone and the relevant business details to Anthropic, acting as our processor. We do not send Anthropic member records, member names or member email addresses.
  • We do not use merchant data or member data to train AI models. Not ours, and not anyone else's. Anthropic does not train models on anything we send it, and that is a contractual commitment rather than a setting.

We do not make solely automated decisions about anyone that have a legal effect or a similarly significant effect on them. Nothing in Push Agent decides whether you get an account, a price, or access to anything.

Turning messages off. A member can turn off notifications for a card inside Apple Wallet or Google Wallet, or remove the card from their wallet, at any time. Removing the card stops all messages relating to it.

9. Who we share it with

We do not sell personal data, and we never will.

We use a small number of service providers to run Spark. Each of them acts as our processor under a written data processing agreement, and each is only allowed to use the data to provide their service to us.

Every one of them is named at sparkloyalty.co.uk/subprocessors, along with what it does, where it processes data, and the safeguard that covers any transfer outside the UK. That page is the current list, we keep it up to date, and it is the same list our Data Processing Agreement refers to.

As at the date of this policy, the providers who handle member data on a merchant's behalf are:

  • Vercel, for hosting our website and dashboard.
  • Supabase, for our database and for signing you in.
  • Anthropic, for drafting Push Agent message copy, on the limited basis described in section 8.

The providers who handle our own data, meaning data about merchants and website visitors rather than members, are:

  • Stripe, for taking payment and managing subscriptions.
  • Resend, for sending service and marketing email to merchants. We do not send email to members.
  • Google, for website analytics through Google Analytics, on our website only. Section 11 explains what this collects and how to decline it.
  • Microsoft, for website analytics and session recording through Microsoft Clarity, on our website and, only if you agree, in the merchant dashboard. It never runs on the pages where a member adds a card. Section 11 explains what this records and how to decline it. Microsoft also uses this data for its own purposes, so it acts as a controller in its own right as well as our processor.

Before we add a provider who will handle member data, or replace one, we give merchants at least 30 days' notice by updating that page and by email. Clause 6.3 of our Data Processing Agreement sets out how to object.

We also share data with:

Apple and Google, to the extent needed to deliver a card to Apple Wallet or Google Wallet and keep it up to date. They act as independent controllers for what happens on the device, including whether a card appears on a lock screen, and their own privacy policies apply.

Law enforcement, regulators, courts or professional advisers, where we are required to by law or where we need advice on a legal claim.

A buyer or successor, if Spark is sold or merged. We will tell merchants before this happens.

10. International transfers

Some of our providers process personal data outside the UK, including in the United States. Where that happens we put appropriate safeguards in place, normally the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, along with an assessment of the risks of that particular transfer.

The safeguard that applies to each provider is shown at sparkloyalty.co.uk/subprocessors. For a copy of the safeguard itself, or of the transfer risk assessment behind it, email support@sparkloyalty.co.uk.

11. Cookies and similar technologies

Cookies are small files stored on your device. The same rules cover similar things like local storage and tracking pixels, so where this section says cookies, it means all of them.

There is no separate cookie policy, because the list below is the whole of it.

Sign-in and session cookies

What it does
Keep you signed in to the dashboard and keep your session secure
Type
Strictly necessary
How long
Until you sign out, or your session expires

Cookie preference

What it does
Remembers what you chose about the cookies below, on the website and in the dashboard
Type
Strictly necessary
How long
12 months

Stripe (__stripe_mid, __stripe_sid)

What it does
Prevents fraud when you pay. Only set on our billing pages
Type
Strictly necessary
How long
Up to 1 year

Google Analytics (_ga, _ga_*)

What it does
Counts visitors to our website and tells us which pages they visit and what brought them here. Website only. Google does not store your IP address, but it does use this data for its own purposes
Type
Analytics
How long
Up to 2 years

Microsoft Clarity (_clck, _clsk, CLID, MUID and related)

What it does
Records how visitors move around our website and, if you agree, how merchants move around the dashboard, including clicks, scrolling and session recordings, so we can see where people get stuck. Microsoft also uses this data for its own purposes, including advertising
Type
Analytics and advertising
How long
Up to 1 year

Strictly necessary cookies cannot be switched off, because the site and dashboard do not work without them.

Everything else is only set if you agree. Nothing in the bottom two rows of that table is set before you say yes. On the website you are asked through the cookie settings in the footer. In the dashboard you are asked once, the first time you open it, and you can change your answer at any time in Settings under Legal and data. Blocking cookies through your browser works too, though it may stop parts of the service working.

The pages where a member adds a card, and the cards themselves, set only strictly necessary cookies. No analytics and no session recording ever run on a join page or in a wallet card, which is why a member is never asked about cookies. That is a promise to merchants as much as to members: nothing we do to understand our own product ever touches your customers.

About session recording. Microsoft Clarity records mouse movement, clicks, scrolling and the pages you visit, and plays them back to us as a session. On the website it runs if you accept analytics and advertising cookies. In the dashboard it runs only if you say yes when we ask, and it is off until you do. Wherever it runs, everything you type is masked, and in the dashboard your members' names and details on screen are masked too, so a recording shows us how you moved through a screen, not who your regulars are. We use it to find usability problems, not to identify individuals.

If you would rather not be recorded, decline on the website or say no in the dashboard, and nothing is captured. You can change your mind either way at any time.

12. How long we keep it

Merchant account data

How long
For as long as your account is open, then 6 years after closure for legal and accounting reasons

Billing and transaction records

How long
6 years, in line with HMRC requirements

Member data held for a merchant

How long
For as long as that merchant's account is open, then 90 days, then we delete it

Support messages

How long
3 years from the last message

Marketing data

How long
Until you unsubscribe or withdraw consent, then we keep a minimal record so we do not email you again

Website and dashboard analytics

How long
14 months

Session recordings

How long
30 days, then deleted by Microsoft

Technical and security logs

How long
12 months

If a merchant's free trial or subscription ends, we do not delete their cards or their member data straight away. We keep both for 90 days so the merchant can pick up where they left off, and we delete them after that. This is deliberate: a loyalty card that vanishes overnight looks like a broken promise from the business, not from us.

Deleted data may persist in encrypted backups for up to 90 days after it leaves our live systems, and is deleted in the ordinary course of our backup rotation. It is not restored or used for anything in the meantime.

13. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectification, to have inaccurate data corrected.
  • Erasure, to have data deleted in certain circumstances.
  • Restriction, to limit how we use your data.
  • Portability, to receive your data in a structured, machine-readable format.
  • Object to processing based on legitimate interests, and to object to direct marketing at any time, which we will always honour.
  • Withdraw consent, where consent is what we relied on.

To use any of these rights, email support@sparkloyalty.co.uk. We will reply within one calendar month. We may need to check who you are first. There is no charge, unless a request is excessive or repetitive.

If you are a member, exercise these rights with the business whose card you hold. They are the controller of your data. If you come to us, we will forward your request to them within five working days and confirm to you that we have done it.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you spoke to us first so we can put it right.

14. Security

We protect personal data with appropriate technical and organisational measures, including encryption in transit and at rest, hashed passwords, access controls on a need to know basis, separation of each merchant's data from every other merchant's, and regular reviews.

Card identifiers are random and unguessable, and hold no personal data in themselves.

The measures that apply to member data are set out in full in Annex III of our Data Processing Agreement at sparkloyalty.co.uk/dpa.

No system is completely secure. If there is a breach that is likely to affect your rights and freedoms, we will tell the ICO within 72 hours and tell you without undue delay, as UK GDPR requires. Where the breach affects member data, we tell the merchant within 48 hours of becoming aware of it, as our Data Processing Agreement requires.

15. Children and young people

The Spark dashboard is for businesses. You must be 18 or over to create a Spark account, and we do not knowingly collect data from anyone under 18 as a merchant.

Loyalty cards are a different matter. A merchant's customers may include people under 18, and a young person can add a card to their phone. We keep member data to the minimum needed to make a card work, we never profile members for Spark's own purposes, and we never use member data for advertising. Merchants are responsible for their own obligations towards younger customers.

If you believe we hold data about a child that should not be there, email support@sparkloyalty.co.uk and we will look into it and delete it if we should.

16. Changes to this policy

We update this policy as the product changes. Where a change is material, we will tell merchants by email or in the dashboard before it takes effect. The date at the top always shows the current version.

17. Contact us

Spark Studio Ltd, trading as Spark Loyalty

48 Crowestones, Buxton, England, SK17 6NZ

support@sparkloyalty.co.uk

We have not appointed a Data Protection Officer, as we are not required to. Data protection questions go to the address above.