SSpark
← Back to Spark

Privacy policy

Spark Finance · last updated 9 September 2026

What we collect

What you type into the application: your business details, its address, how much you need and what for, and your name, email and role. If you create an account, your password is stored only as a hash — we never see it.

What you upload: bank statements, company registration documents, and identity documents.

What we already held: if you came to us from our existing customer file, we already hold your trading history and current exposure. That is the point of the offer we make you.

What your browser tells us: pages you visited, roughly where you are from your IP address, and what device you used. We use PostHog and Amplitude for this.

Identity verification

We use a third-party provider to verify identity documents. They receive the document and selfie you provide and return a result to us. We keep the result and the reference, not the raw images.

Why we use it

To decide whether we can fund you, to verify you are who you say you are, to meet anti-money-laundering and record-keeping obligations, and to contact you about your application.

We do not sell your personal information. We do not use it to advertise to you.

Who else sees it

Our staff, on a need-to-know basis — a salesperson working your file sees what they need to talk to you and no more.

Funding partners, if we place your application with one, and only then.

Service providers who run parts of this for us: our hosting, our email sender, our identity checker, and our analytics.

Anyone the law requires.

Credit reports

If you authorised a credit check when you applied, we may obtain business and personal credit reports and share the outcome with a funding partner considering your application.

How long we keep it

For as long as we are required to, which for financial records is typically seven years after a file closes. Applications that go nowhere are kept for long enough to recognise you if you come back, then removed.

Your choices

You can ask us what we hold about you, ask us to correct it, or ask us to delete it where we are not legally required to keep it. Email us and we will tell you what we can and cannot do, and why.

Security

Everything is encrypted in transit and at rest. Access to the internal tools is restricted by role, and what a salesperson can see is limited in the database itself, not just hidden in the interface.

Questions about this? Email [email protected].