Back to home

Privacy Policy

Effective date: 08/24/2026

This Privacy Policy describes how Spark Inventory, INC ("Spark Inventory", "we", "us", or "our") collects, uses, and shares information when you use the Spark Inventory mobile and web applications (the "App") and related services (together, the "Service"). By using the Service, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

1.1 Information you provide

  • Account information. When you sign in, we collect your email address and authentication credentials.
  • Workspace data. Inventory items, locations, sales orders, purchase orders, packing records, and other operational data you or your organization enter into the App.
  • Support communications. Messages, screenshots, or attachments you send to our support team.

1.2 Information collected automatically

  • Device information. Device model, operating system version, unique device identifiers, app version, and language settings.
  • Usage data. Screens viewed, features used, crash logs, and performance metrics, used to diagnose problems and improve the App.
  • Log data. IP address, access times, and request metadata when the App communicates with our servers.

1.3 Camera and barcode scanning

The App uses your device's camera only to scan barcodes and QR codes for inventory operations. Camera frames are processed on-device in real time and are not stored, recorded, or transmitted to our servers or any third party. The decoded barcode value (a short string of text) is sent to our servers only when needed to look up or update inventory.

1.4 Hardware barcode scanners

If you connect a hardware barcode scanner via Bluetooth or USB, the App receives the decoded text values from that device. We do not access any other Bluetooth or peripheral data.

1.5 Information we do not collect

  • We do not collect your contacts, photos, microphone audio, precise location, or biometric data.
  • We do not sell personal information. Our public website uses analytics and marketing technologies as described in Section 14. Shopify protected customer data and authenticated customer workspace data are not provided to these marketing vendors or used for advertising.

2. How We Use Information

We use the information we collect to:

  • Provide, maintain, and improve the Service;
  • Authenticate you and secure your account;
  • Synchronize your workspace data across devices;
  • Provide AI-assisted chat features (see Section 5);
  • Diagnose and fix bugs, crashes, and performance issues;
  • Communicate with you about service updates, security alerts, and support requests;
  • Comply with legal obligations and enforce our terms.

3. How We Share Information

We share information only as described below:

  • With your organization. Data you enter into a workspace is visible to other authorized members of that workspace.
  • With service providers. We use trusted third parties to host infrastructure, deliver push notifications, monitor errors, and process AI requests. These providers may only use your data to perform services for us.
  • For legal reasons. We may disclose information if required by law, subpoena, or to protect the rights, property, or safety of our users or others.
  • In a business transfer. If we are involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction.

We do not sell your personal information.

4. Shopify Integration

When a merchant installs or connects Spark Inventory through Shopify, we receive the merchant's shop domain and shop profile information, including shop name, account email, owner name, country, time zone, and currency. Depending on the features the merchant enables, we also receive product and variant information, SKUs, barcodes, prices, images, metafields, costs, locations, inventory quantities, customer names and contact information, order details, shipping addresses, fulfillment information, and refund or cancellation information.

We use Shopify data only to provision and secure the merchant's Spark account; import and synchronize products, inventory, customers, and orders; manage inventory and fulfillment workflows; provide support; and comply with legal and privacy obligations. We do not sell Shopify protected customer data, share it with advertising providers, or use it for unrelated marketing.

For Shopify merchant and customer data processed on a merchant's behalf, Spark Inventory acts as a service provider or data processor. Spark Inventory may act as a data controller for information used to administer Spark accounts, provide support, secure the service, meet legal obligations, and maintain compliance records.

Retention and deletion

Processed Shopify webhook payload content is normally removed within 7 days, and completed webhook records are removed within 30 days. Failed or pending webhook records may be retained for up to 90 days so they can be retried and investigated.

When Shopify sends a customer deletion request, we delete the customer's Shopify linkage, remove linked contact and address records, erase stored export snapshots, and anonymize identity fields in business records that must be retained. When Shopify sends a shop deletion request following uninstall, we delete stored Shopify credentials, raw Shopify payloads, location mappings, and Shopify linkage records.

If a merchant independently activates and uses Spark Inventory outside Shopify, we may retain non-personal operational or accounting records as necessary to provide the merchant's Spark service, meet legal obligations, or preserve legitimate business records. Personal identity, contact, and address information associated with deleted Shopify data is removed or anonymized. Accounts created through the Shopify App Store that were never activated or used are anonymized.

We retain pseudonymous deletion receipts for up to seven years for compliance auditing. These receipts contain identifiers such as a hashed shop reference and timestamps, but not the shop domain or raw Shopify payload.

Security

Shopify data is encrypted in transit and at rest, including application-level protection of Shopify access and refresh tokens. Access is restricted to authorized personnel and subject to logging and access controls.

Disconnection and contact

Merchants can disconnect Shopify from Spark Inventory or request deletion by contacting support@sparkinventory.com. Customers whose information originated from a Shopify merchant can also exercise their privacy rights by contacting that merchant.

5. AI Features

The App includes an AI chat assistant. When you interact with it, your messages and relevant workspace context are sent to our AI processing provider to generate a response. We do not use your data to train third-party foundation models. You can avoid using AI features by not opening the chat tab.

6. Google Account Integration (Gmail)

Spark Inventory offers an optional integration with your Gmail account so you can send replies to suppliers and customers directly from the address they know you by. This section describes how we handle data accessed via Google's APIs.

What we access. When you choose to connect a Gmail account in Spark Inventory, we request a single Google OAuth scope: gmail.send (described to you on Google's consent screen as "Send email on your behalf"). This is the narrowest Gmail scope that permits sending.

What we do not access. With this scope, we cannot read, search, modify, label, archive, delete, or otherwise interact with any messages in your Gmail mailbox. We do not have access to your inbox, contacts, drafts, or any other Gmail data.

How we use it. We send a message via Gmail only when you explicitly click "Send" on a reply or follow-up you have composed inside Spark Inventory. We do not send autonomous, bulk, or marketing email through this integration.

How we store the data. Spark Inventory stores an encrypted OAuth refresh token tied to your Spark Inventory account so the integration continues to work without re-authentication. Outgoing messages and the events that triggered them are recorded in our internal logs for diagnostic and audit purposes.

Third parties. Outgoing messages are transmitted only between Spark Inventory's servers and Google's Gmail API. No other third party receives data obtained via Google's APIs.

How to revoke access. You can disconnect your Gmail account at any time from Spark Inventory's Email accounts page (Profile → Email accounts). You can also revoke Spark Inventory's access directly from your Google Account at myaccount.google.com/permissions. Disconnection deletes the stored refresh token within 30 days.

Limited Use compliance. Spark Inventory's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer, use, or store Google user data for serving advertisements, and we do not allow humans to read Google user data except (a) with your explicit consent, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) for limited internal operations where the data has been aggregated and anonymized.

7. SMS / Text Message Communications

This section describes how we collect, use, and protect the information you provide when you opt in to receive SMS text messages from Spark Inventory.

What we collect when you opt in to SMS

When you enable SMS notifications from your Spark Inventory account settings, we collect and store:

  • The mobile phone number you provide
  • The date and time you opted in
  • The IP address and user-agent string of the device used to opt in
  • The exact version identifier of the consent statement you agreed to
  • Your per-notification-type preferences (which message categories you've enabled or disabled)

We also retain a per-message delivery log (timestamp, carrier-reported status, and provider message identifier) so that we can troubleshoot delivery problems and honor opt-out requests reliably.

How we use this information

Mobile phone numbers collected through the SMS opt-in are used solely to deliver the transactional operational notifications you have subscribed to (inventory alerts, order updates, and similar operational events in your Spark account), and to support opt-out (STOP) and help (HELP) requests. We do not use SMS opt-in data for marketing or promotional outreach. We do not send marketing SMS.

How we protect and share this information

No mobile information will be sold or shared with third parties for promotional or marketing purposes. We do not rent, sell, or otherwise make available any mobile phone numbers, opt-in records, or related data to third parties for advertising or marketing.

We share mobile phone numbers only with the SMS service provider that delivers the messages on our behalf (currently Twilio), strictly for the purpose of sending the message and receiving delivery status confirmations. Our SMS service provider is bound by their own contractual confidentiality and data-handling obligations.

How to revoke consent

You can revoke your consent to receive SMS at any time by either:

  • Replying STOP to any Spark Inventory SMS: your opt-out is recorded immediately, and you will not receive further messages.
  • Visiting Profile → SMS notifications inside your Spark Inventory account and clicking "Turn off SMS".

Replying HELP to any Spark Inventory SMS will return a brief description of the program and our support contact (support@sparkinventory.com).

For full details about the SMS program, including the verbatim consent statement, frequency expectations, and sample message content, see sparkinventory.com/sms-program.

8. Data Retention

We retain your account and workspace data for as long as your account is active. If you or your organization delete your account, we delete associated data within 30 days, except where we are required to retain it for legal, tax, or audit purposes.

Shopify-sourced information is retained and deleted according to the Shopify Integration section above. Certain non-personal business records and pseudonymous compliance receipts may be retained for the periods described there.

9. Data Security

We use industry-standard measures to protect your information, including encryption in transit (TLS) and at rest, role-based access controls, and audit logging. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify you in accordance with applicable law.

10. Your Rights

Depending on where you live, you may have rights to:

  • Access the personal data we hold about you;
  • Correct or update inaccurate data;
  • Delete your data;
  • Object to or restrict certain processing;
  • Receive a copy of your data in a portable format;
  • Withdraw consent (where processing is based on consent);
  • Lodge a complaint with a supervisory authority.

To exercise any of these rights, contact us at support@sparkinventory.com. We will respond within the time required by applicable law.

10.1 California residents (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect and the right not to be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising.

10.2 European Economic Area, UK, and Switzerland (GDPR)

If you are in the EEA, UK, or Switzerland, our legal bases for processing are: performance of a contract (providing the Service), legitimate interests (improving and securing the Service), and consent (where applicable). Data may be transferred to and processed in countries outside your jurisdiction; where required, we use Standard Contractual Clauses or equivalent safeguards.

11. Children

The Service is not directed to children under 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact support@sparkinventory.com and we will delete it.

12. International Users

The Service is operated from the State of New York. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the new policy here and update the "Effective date" at the top. Material changes will be communicated via email or in-app notice.

14. Third-Party Data Collection and Marketing

When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email addresses. You may opt out of receiving this advertising by visiting https://app.retention.com/optout. You also have the option to opt out of the collection of your personal data in compliance with GDPR by visiting https://www.rb2b.com/rb2b-gdpr-opt-out.

These website marketing technologies are not applied to Shopify protected customer data or data stored inside authenticated Spark Inventory workspaces.

15. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Spark Inventory, INC
30 Rockefeller Plaza, Suite 2060
New York, NY 10112
Email: support@sparkinventory.com