Home

Privacy Policy

Last updated: June 21, 2026

Respark places great importance on protecting your personal data. This policy explains what data we process, why, with whom, for how long, and what your rights are, in accordance with the General Data Protection Regulation (GDPR).

1. Data controller

The data controller is Respark, publisher of the Service. Full contact details are shown on the site and are to be completed by the publisher before going live.

2. Data we process

  • Account: your email address, used for magic-link authentication and Service-related communications.
  • Business: name, category, brand tone, signature and Google review link that you provide.
  • Reviews and requests: imported or collected reviews, customer name and contact details (email or phone) you enter to request a review.
  • Billing: subscription identifiers managed by Stripe. We never store your card numbers.
  • Technical data: security logs and data strictly necessary for proper operation (session cookies, see section 7).

3. Purposes and legal bases

We process this data to: provide the Service and perform the contract (Article 6.1.b GDPR); ensure security, prevent fraud and improve the Service under our legitimate interest (Article 6.1.f); and comply with our legal and accounting obligations (Article 6.1.c). Sending review requests to your customers is your responsibility as the controller of your own customer files; Respark then acts as a processor.

4. Processors

To provide the Service we rely on carefully selected providers acting as processors: Supabase (database and authentication, hosted in the European Union), Stripe (payments), Resend (email delivery), and an AI provider (Anthropic or OpenAI depending on configuration) for generating replies. Content sent to the AI provider is limited to the review text and the context needed to draft the reply.

5. Transfers outside the EU

Some processors may handle data outside the European Union. In that case, such transfers are framed by appropriate safeguards (the European Commission’s standard contractual clauses or equivalent mechanisms).

6. Retention periods

Account and business data are kept for as long as your account is active, then deleted or anonymized within a reasonable time after closure. Billing data is kept for the applicable legal period. You can request deletion of your account at any time.

7. Cookies

The Service uses only cookies strictly necessary for its operation: a session cookie to keep you authenticated, and local storage to remember your theme preference (light/dark). These essential cookies do not require prior consent. We do not use advertising cookies or third-party trackers for profiling.

8. Your rights

Under the GDPR, you have the right to access, rectify, erase, restrict, object to and port your data. You can exercise these rights by contacting us at the address shown on the site. You also have the right to lodge a complaint with your supervisory authority (in France, the CNIL — www.cnil.fr).

9. Security

We implement appropriate technical and organizational measures: data isolation per account via row-level security policies (RLS), encryption of communications, access limitation and logging. As no system is infallible, we cannot guarantee absolute security.

10. Changes

This policy may be updated. In the event of a material change, we will inform you. The last updated date is shown at the top of the page.

To read the terms of service, see our Terms.