atSpark
  • Home
  • AI Assist
  • What you get
  • Pricing
  • LeadershipFor CEOs & foundersBoard-ready answers, no data teamFor CFOsBoard-ready SaaS financeFor investors & boardsLive metrics, not PDF decks
    Finance & OpsFor FP&A & controllersForecasting, waterfall, the closeFor finance teamsThe reporting you own day-to-dayFor RevOps & salesPipeline, expansion, NRR
    • vs spreadsheets
    • vs Power BI
    • vs Looker
    • vs Tableau
    • vs Mode
    • Blog
    • SaaS glossary
    • Free calculators
    • Embed Portal
Get started
Doc · 001 · Privacy

Privacy policy.

In effect Last updated: June 3, 2026 Version 1.0
CONTENTS
  1. 01Scope & introduction
  2. 02Information we collect
  3. 03How we use information
  4. 04Legal bases for processing
  5. 05Data sharing & third parties
  6. 06International transfers
  7. 07Data retention
  8. 08Data security
  9. 09Your rights
  10. 10Cookies & tracking
  11. 11Children's privacy
  12. 12Changes to this policy
  13. 13Contact us

This Privacy Policy describes how atSpark ("we," "us," or "our") collects, uses, shares, and protects information when you access our website, create an account, connect your data sources, and use the atSpark analytics platform (collectively, the "Service").

01

Scope & introduction

We respect your privacy and are committed to handling personal information transparently and responsibly. This policy applies to information we collect directly from you, information generated through your use of the Service, and information we receive from third-party services you choose to connect.

Capitalized terms not defined here have the meaning given in our Terms of Service. If you do not agree with this policy, please do not use the Service.

02

Information we collect

We collect the following categories of information:

Account information

  • Identity — your name, email address, job title, and company name provided at registration.
  • Authentication — password hashes, multi-factor authentication secrets, and session tokens required to keep your account secure.
  • Billing — if you become a paying customer, our payment processor collects billing contact and payment method details; we store only the last four digits of your card and the billing descriptor.

Connected data sources

  • OAuth tokens — encrypted access and refresh tokens from services you connect (for example Stripe, HubSpot, QuickBooks, Zoho) used to retrieve data on your behalf.
  • Business data — customer records, invoices, subscription records, CRM objects, and similar data pulled from connected sources and stored in your dedicated warehouse schemas.

Usage & technical data

  • Product telemetry — pages viewed, queries run, dashboards opened, buttons clicked, and feature adoption signals.
  • Device data — browser type and version, operating system, screen size, and locale.
  • Network data — IP address, approximate geolocation derived from IP, and request timestamps.
  • Logs — diagnostic logs, error stacks, and performance traces that help us operate and improve the Service.
03

How we use information

We use the information we collect for the following purposes:

  • Deliver the Service — authenticate you, sync data from connected sources, compute metrics, render dashboards, and power AI Assist responses.
  • Secure the Service — detect and prevent fraud, abuse, credential stuffing, and unauthorized access; investigate and respond to incidents.
  • Support — answer your questions, troubleshoot issues, and communicate service notices.
  • Improve the product — analyze aggregate usage to prioritize features, fix bugs, and evaluate performance. We do not train third-party AI models on your business data.
  • Billing & compliance — issue invoices, meet tax and accounting obligations, and comply with applicable laws.
04

Legal bases for processing

Where the GDPR or similar laws apply, we process personal data under one or more of the following legal bases:

  • Contractual necessity — processing required to provide the Service you have requested.
  • Legitimate interests — improving, securing, and promoting our Service, balanced against your rights and expectations.
  • Consent — where you have given explicit permission, for example for optional analytics or marketing communications. You can withdraw consent at any time.
  • Legal obligation — compliance with tax, accounting, and law-enforcement requests.
05

Data sharing & third parties

We do not sell or rent your personal information. We share information only in these limited cases:

  • Subprocessors — reputable vendors bound by data-protection agreements who help us deliver the Service (cloud hosting, email, error monitoring, analytics, customer support). We maintain a current list on request.
  • Connected services — when you connect a third-party source, atSpark sends authentication tokens to that service and receives data back. Your use of those services is governed by their own terms and privacy policies.
  • Business transfers — if atSpark is involved in a merger, acquisition, or asset sale, information may transfer to the successor entity subject to this policy.
  • Legal requests — when we believe in good faith that disclosure is required by law, to protect the rights and safety of users, or to respond to valid legal process.
  • With your direction — for example when you share a dashboard link or invite a teammate to your workspace.
06

International transfers

atSpark primarily hosts data in AWS regions in the United States. If you are located outside the United States, your information may be transferred to, stored in, and processed in jurisdictions where data-protection laws may differ from those in your country.

For transfers from the European Economic Area, United Kingdom, or Switzerland, we rely on appropriate safeguards such as the Standard Contractual Clauses approved by the European Commission, supplemented with technical and organizational measures as needed.

07

Data retention

We keep personal information only as long as needed to deliver the Service and meet the purposes described in this policy:

  • Account data — retained for the life of your account plus up to 30 days after deletion to support recovery.
  • Connected source data — retained in your warehouse schemas while the connection is active; purged within 30 days after disconnection unless you export it first.
  • Usage logs — retained for up to 13 months, then aggregated or deleted.
  • Billing records — retained for up to 7 years to meet tax and accounting obligations.

You can request earlier deletion of data you control; see "Your rights" below.

08

Data security

We apply industry-standard safeguards to protect your information:

  • Encryption — AES-256-GCM at rest and TLS 1.2+ in transit.
  • Access control — least-privilege role-based access, multi-factor authentication, and scoped OAuth tokens.
  • Isolation — multi-tenant workspaces with row-level security and per-organization schema boundaries in the warehouse.
  • Audit logging — every sensitive action is recorded with actor, time, and context.
  • Monitoring — continuous anomaly detection, vulnerability scanning, and a formal incident-response process.

No system is perfectly secure. We encourage strong passwords, use of MFA, and prompt reporting of suspicious activity to security@atspark.com.

09

Your rights

Depending on your jurisdiction, you may have the following rights over your personal information:

  • Access — request a copy of the personal information we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — request deletion of your personal information, subject to our lawful retention obligations.
  • Restriction — limit how we process your information in specific circumstances.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests or direct marketing.
  • Withdraw consent — where processing is based on consent, withdraw it at any time.
  • Complain — lodge a complaint with your local supervisory authority.

To exercise any right, email privacy@atspark.com. We respond within 30 days and may ask you to verify your identity before disclosing personal data.

10

Cookies & tracking

We use a small number of cookies and similar technologies on the atSpark marketing website (atspark.com). They fall into two categories:

Essential cookies

  • Session & preferences — keep your session active, remember your consent choice, and preserve UI preferences such as theme. These cookies are required for the site to function and are always set.

Analytics cookies (with your consent)

  • Aggregate site analytics — we use one or more third-party analytics providers to measure aggregate site traffic, page views, and how visitors reach our content. Cookies set by these providers carry anonymized identifiers; no advertising or personalization data is collected. Disabled by default until you accept.
  • Behavioral insight tools — when enabled, we may use a third-party tool to record anonymized interaction heatmaps and session replays of the marketing site to help us improve usability. Disabled by default until you accept.

A current list of analytics subprocessors is available on request to privacy@atspark.com.

Your choice

On your first visit you will see a cookie banner with Accept and Decline options. We use a consent framework that defaults all analytics, advertising, and personalization storage signals to denied until you explicitly accept. Your choice is stored in your browser (localStorage plus a one-year cookie) so the banner does not reappear on later visits.

You can change your decision at any time by clearing site data for atspark.com in your browser, which will show the banner again on your next visit, or by emailing privacy@atspark.com.

Do Not Track & Global Privacy Control

We respect the DNT and Global Privacy Control signals. If your browser sends either, we automatically treat your visit as a Decline and do not display the banner.

The atSpark application

The atSpark product (when you sign in to your workspace) uses only first-party essential cookies needed to operate the application.

11

Children's privacy

atSpark is a B2B analytics platform intended for business users. The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it promptly.

12

Changes to this policy

We may update this Privacy Policy as the Service evolves or as laws change. When we make material changes, we will notify you by email or through a prominent notice in the Service at least 14 days before they take effect. The "Last updated" date at the top of this page always reflects the current version.

13

Contact us

For questions, requests, or complaints about this Privacy Policy or our handling of your data, contact our privacy team at privacy@atspark.com. For general inquiries, email contact@atspark.com.

END · PRIVACY POLICY ◦ Continue to terms of service →
atSpark

The AI analyst for SaaS revenue & finance. Unified billing, CRM & subscriptions, plain-English answers.

Product

  • AI Assist
  • What you get
  • How it works
  • Integrations
  • Pricing

Solutions

  • For CFOs
  • For RevOps
  • For finance teams

Compare

  • vs spreadsheets
  • vs Looker
  • vs Mode
  • vs Power BI
  • vs Tableau

Resources

  • Blog
  • SaaS glossary
  • Free calculators
  • Security
  • Embed Portal
© 2026 atSpark. Made with care.
SecurityPrivacyTermsContact
Cookies & analytics

We use a small amount of analytics to understand which posts help most. No ads, no profile-building. See our privacy policy for details.