Privacy
Privacy Policy
Sparks Support Pty Ltd (ABN 93 669 152 103) provides Sparks Provider. This policy explains what information the service handles, why it is needed and the choices available to you.
Last updated
Who this policy covers
Sparks Provider is business software for support providers. An organisation controls the records its authorised owners, admins and workers enter. Sparks Support processes those records to provide and protect the service.
The app is not directed to children as account holders. A provider may record information about a person receiving support, including a child, only where the provider has the authority and notices needed to do so.
Information we handle
- Account and identity information: name, email address, user identifier, membership role and security or sign-in state. Supabase Auth handles passwords and sessions.
- Business and team information: business identity, ABN, contact details, address, invoice and bank settings, staff profiles, employment details, availability, emergency contacts, photos and compliance documents.
- Support and service records: participant identity and contact details, date of birth, emergency contacts, support and health information, photos, documents, schedules, attendance, travel, notes, tasks, incidents, agreements, rates and invoices.
- Communications and integrations: invitation, sign-in, reminder and support messages, plus the information an authorised user chooses to send to Xero.
- Purchase information: product, customer, transaction and subscription identifiers and status. We do not receive full payment card details.
- Technical and support information: request and device information needed to operate the service, limited error diagnostics and anything you include in a support request.
Camera and file access is used only when you choose a photo or document to upload. Do not enter information that your organisation does not need or is not authorised to hold.
How we use information
- Authenticate users and keep organisation records separated.
- Provide rostering, worker, document, incident, agreement, invoice, export and reminder features.
- Send service messages and complete actions an authorised user requests.
- Process purchases, show subscription status and provide purchase restoration.
- Protect accounts, investigate faults, prevent misuse and meet legal obligations.
- Answer support, access, correction and deletion requests.
We do not sell personal information or send participant and worker records to advertising platforms. No Meta advertising script runs inside the signed-in app.
Optional website advertising measurement
If you allow advertising measurement on sparksprovider.app, technical browser and ad-click identifiers can connect that website visit to a new trial workspace, its first shift and its first recorded payment. Our server reports only those generic milestones to Meta. It does not send account names, emails, calculator answers, participant or worker records, notes, health information, or signed-in page URLs.
This choice is separate from optional marketing emails and does not affect your access to the service. You can withdraw it using Advertising preferences on the website. Identifiers expire after 90 days. Meta may process advertising information overseas. Events already received by Meta cannot be recalled by changing this choice. See the website privacy policy for the full measurement and retention details.
Service providers and disclosures
We disclose only the information needed for the service involved:
- Supabase for authentication, database and private file storage.
- Vercel for web application and API hosting.
- Resend for email delivery, and Twilio when an organisation enables SMS reminders.
- Xero only when an authorised owner connects Xero and chooses to send records.
- Stripe for separate web subscription and SMS-credit purchases.
- Apple and Google to process iOS and Android purchases, and RevenueCat to receive an organisation-scoped pseudonymous identifier and app-store purchase or subscription status. RevenueCat does not receive the organisation login email for this purpose and does not decide app roles or authorisation.
App-store purchases are not connected to the separate Stripe account. Some providers may process information in countries outside Australia under their own privacy and security terms.
We may also disclose information where required by law, to protect a person or the service, or as part of a business transfer subject to appropriate confidentiality and notice.
Security and access
Sparks Provider uses encrypted network connections, private storage, role-based access and organisation-scoped database policies. Access is based on the authoritative membership role for the signed-in account. Security events are logged without intentionally placing participant details in diagnostic messages.
Encrypted recovery backups are access-restricted and held separately from the live service. No system can be completely secure, so please report suspected unauthorised access promptly.
Retention and deletion
We keep active organisation records while needed to provide the service and for the organisation’s operational and legal needs. Short-lived sign-in, invitation and diagnostic records are removed on defined schedules. An organisation should export records it is legally required to keep before closing its account.
When the organisation founder requests closure, uploaded documents and photos are removed from the active service straight away. Other active organisation records are scheduled for permanent deletion after 30 days and the founder can cancel during that period. Deleted information may remain in restricted encrypted recovery backups until those snapshots expire, no later than 56 days after deletion from the active service. Backups are used only for disaster recovery, not to restore an individual deleted account.
Removing a worker from an organisation is different from deleting the worker’s sign-in. See our account deletion instructions for both paths.
Your choices and requests
You can ask to access or correct your personal information, delete an individual sign-in, close an organisation account or make a privacy complaint. We may need to verify your identity and your authority for an organisation before acting. We will explain if information cannot be changed or deleted because of another person’s rights or an applicable legal requirement.
Email hello@sparksprovider.app. Please do not include passwords, sign-in codes or sensitive support records in an ordinary email.
Changes to this policy
We may update this policy when the service, providers or legal requirements change. The latest version and its update date will stay available at this address.