Spark Loyalty Ltd
Privacy Policy
Last updated: 16 March 2026 · Effective date: 16 March 2026
1. Who We Are
Spark Loyalty Ltd ("Spark", "we", "us", "our") is registered in England and Wales (company number [COMPANY NUMBER]). We are the controller of personal data we collect when you visit our website or create a merchant account. We are registered with the Information Commissioner's Office (ICO). Our ICO registration number is [ICO REGISTRATION NUMBER].
For questions about this policy or our data practices, contact us at support@sparkloyalty.co.uk.
2. Who This Policy Covers
This Privacy Policy explains how we collect and use personal data relating to:
- Merchants: business owners and their staff who create a Spark account and use our platform.
- Website visitors: anyone who visits sparkloyalty.co.uk.
If you are a customer of a business that uses Spark (i.e. you have scanned a loyalty card), your personal data is processed by that business as the data controller. Spark processes it only on their behalf, as a data processor. Please refer to that business's own privacy policy for information about how your data is used.
3. What Personal Data We Collect
3.1 Merchants
When you create a Spark account or use our platform, we may collect:
- Identity data: your name, business name, and job title.
- Contact data: email address, phone number, and business address.
- Account data: login credentials (passwords are stored in encrypted form), plan type, and account preferences.
- Payment data: billing information. Note: we do not store full payment card details. Card processing is handled by our payment processor, subject to their own privacy policy.
- Usage data: how you interact with the dashboard, features used, and campaign activity.
- Communications: messages you send to us via email or support channels.
- Technical data: IP address, browser type, device information, and cookies. See Section 8 for more on cookies.
3.2 End Customers (via Merchants)
When a customer adds a loyalty card through a Spark merchant's QR code or NFC point, we may process on the merchant's behalf:
- A unique device identifier or wallet pass ID.
- Stamp count and reward redemption history.
- Location data used to surface the loyalty card on the customer's lock screen when they are near the merchant's location (this is processed by Apple or Google, not Spark directly).
- Any personal data provided by the merchant about their customers, such as first name if used in notifications.
Spark does not independently contact end customers or use their data for its own marketing purposes.
3.3 Website Visitors
When you visit our website, we collect standard technical and analytics data as described in Sections 3.1 and 8.
4. How We Collect Personal Data
We collect personal data:
- Directly from you when you register, fill in forms, or contact us.
- Automatically when you use the Service or visit our website (via cookies and tracking technologies).
- From third-party sources such as payment processors and analytics providers.
5. Why We Use Your Data (Lawful Bases)
We only process personal data where we have a lawful basis to do so. The following summarises our main processing activities:
Creating and managing your account
Lawful basis: Performance of a contract. We need this to provide the Service.
Processing payments
Lawful basis: Performance of a contract.
Providing customer support
Lawful basis: Performance of a contract and legitimate interests.
Sending service-related communications (e.g. billing alerts, product updates)
Lawful basis: Performance of a contract and legitimate interests.
Sending marketing communications about Spark
Lawful basis: Consent (where required by PECR) or legitimate interests for existing customers. You may opt out at any time.
Improving the Service through usage analytics
Lawful basis: Legitimate interests. We use aggregated and anonymised data where possible.
Complying with legal obligations
Lawful basis: Legal obligation.
6. How We Share Your Data
We do not sell your personal data. We may share it with:
- Service providers who process data on our behalf, including our hosting provider, database provider, wallet pass infrastructure, payment processor, and email and analytics tools. Each provider is subject to a data processing agreement with us.
- Apple and Google, to the extent necessary to deliver wallet passes. Their processing is subject to their own privacy policies.
- Law enforcement or regulatory bodies where we are required to do so by law, court order, or regulatory requirement.
- A purchaser or successor entity in the event of a sale, merger, or acquisition of Spark, in which case we will notify you in advance.
7. International Transfers
Some of our service providers may process data outside the UK or European Economic Area. Where this occurs, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.
For details of the safeguards applicable to any specific transfer, please contact us at support@sparkloyalty.co.uk.
8. Cookies and Tracking
We use cookies and similar tracking technologies on our website. Cookies are small text files stored on your device that help us understand how the site is used and improve your experience.
The types of cookies we use:
- Strictly necessary cookies: required for the website and dashboard to function. These cannot be switched off.
- Analytics cookies: help us understand how visitors use our website. We anonymise data where possible.
- Marketing cookies: used to deliver relevant advertising where applicable.
You can manage your cookie preferences via our cookie banner or your browser settings. Blocking certain cookies may affect the functionality of the Service.
For more detail on the specific cookies we use, please see our Cookie Policy at sparkloyalty.co.uk/cookies.
9. Data Retention
We keep your personal data only for as long as necessary for the purposes described in this policy, or as required by law.
- Merchant account data: retained for the duration of your account and for 6 years after closure for legal and accounting purposes.
- Transaction and billing records: retained for 6 years in line with HMRC requirements.
- Marketing data: retained until you unsubscribe or withdraw consent.
- Website analytics data: retained for 26 months.
10. Your Rights
Under UK GDPR, you have the following rights in relation to your personal data:
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to request that inaccurate data is corrected.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restrict processing: to request that we limit how we use your data.
- Right to data portability: to receive your data in a structured, machine-readable format.
- Right to object: to object to processing based on legitimate interests or for direct marketing.
- Rights relating to automated decision-making: to not be subject to solely automated decisions that have a legal or similarly significant effect on you.
To exercise any of these rights, contact us at support@sparkloyalty.co.uk. We will respond within one calendar month. We may need to verify your identity before processing your request.
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
11. Security
We take the security of your personal data seriously. We implement appropriate technical and organisational measures to protect it against unauthorised access, loss, or destruction, including encryption in transit and at rest, access controls, and regular security reviews.
No method of transmission over the internet is completely secure. In the event of a personal data breach that is likely to affect your rights and freedoms, we will notify you and the ICO as required by UK GDPR.
12. Children
The Service is not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at support@sparkloyalty.co.uk and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Where we make material changes, we will notify you by email or via the dashboard. The updated policy will take effect from the date shown at the top of this page.
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, please get in touch:
Spark Loyalty Ltd