Introduction
SparkleTree AB, a Swedish company operating the SparkleTree platform ("SparkleTree", "we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our marketing platform and related services. Your use of the platform is also governed by our Terms of Service.
Information We Collect
We may collect the following types of information:
- Account information (name, email address, organization details)
- Usage data and analytics
- Content you create and upload to the platform
- Device and browser information
- Location data (when contextual marketing features are enabled)
- Requests that an AI assistant you have connected makes on your behalf (see "AI Assistants and Connectors" below)
How We Use Your Information
We use the information we collect to:
- Provide and maintain our services
- Improve and personalize your experience
- Process transactions and send related information
- Send promotional communications (with your consent)
- Analyze usage trends and optimize our platform
- Protect against unauthorized access and abuse
Data Security
We implement appropriate technical and organizational security measures to protect your personal information. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
Your Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Opt out of marketing communications
- Data portability
Shopify Integration
If you install the SparkleTree app for Shopify, we process the following data from your store on your behalf (you remain the controller; SparkleTree acts as your processor):
- Your product catalog (titles, descriptions, images, prices, inventory levels, currency) and store domain
- Order references limited to order identifiers, totals, and currency — used solely to attribute conversions and revenue to your own campaigns
We do not collect or store your customers' names, email addresses, phone numbers, or addresses. API access tokens are stored encrypted. We honor Shopify's data deletion webhooks: customer redaction requests remove matched order references, store redaction removes the store's data after uninstall, and customer data requests are fulfilled within Shopify's 30-day window. Uninstalling the app deactivates the connection immediately.
Cookies and Tracking
We use cookies and similar tracking technologies to enhance your experience, analyze trends, and gather demographic information. You can control cookie preferences through your browser settings.
Data Retention
We keep personal data for as long as your account or workspace is active and as needed to provide the service. When a workspace is deleted, or when we receive a verified deletion request, we delete or anonymise the personal data we hold within 30 days, unless we must keep it longer to meet legal, tax or accounting obligations, to resolve disputes, or to enforce our agreements.
- Account and workspace data: for the life of the account, then deleted within 30 days.
- Campaigns, products, brand content and media you create: for the life of the workspace. You can delete individual items at any time.
- Campaign analytics (impressions, reach, interactions): daily aggregates for the life of the workspace; raw events for the life of the workspace today, with a shorter window once we introduce one, announced here first.
- Live-session metrics from screens and kiosks: 7 days.
- Hourly counts of AI crawler and agent reads of a workspace's machine-readable pages (bot family and page type only, no addresses or identifiers): 400 days.
- Server, security and access logs: up to 90 days.
- Shopify data: as described above; removed on uninstall and through Shopify's redaction webhooks.
- Encrypted backups: roll off within 30 days of a deletion.
Sub-processors and Third-Party Sharing
We do not sell personal data. We share it with the service providers below, who process it on our behalf and under contract, only to the extent needed for the purpose listed. We may also disclose data when the law requires it.
- Clerk: sign-in, accounts, workspace membership, and the OAuth flow used by AI connectors.
- Vercel: hosting of the application, file storage for uploaded and generated media, request logs.
- Neon: the PostgreSQL database that stores your workspace data.
- Upstash: Redis cache, rate limiting and short-lived job state.
- UploadThing: upload handling for media you add to the platform.
- PostHog: product analytics on how the dashboard is used.
- OpenAI: text and image generation for campaigns and product analysis.
- Google (Gemini): text and image generation, goal parsing and image analysis.
- Replicate: media generation for commissioned films (Open Studio).
- Remotion Lambda on Amazon Web Services: rendering campaign videos and stills.
AI providers receive only the inputs needed for the request you make (for example your brief, product and brand information, and images you supply). They process them under their API terms, and we do not use your content to train models of our own.
Our platform may also contain links to third-party websites or integrate with third-party services you choose to connect, such as Shopify or social media accounts. We are not responsible for the privacy practices of those services; please review their privacy policies.
AI Assistants and Connectors
You can connect an AI assistant (for example Claude, ChatGPT, Cursor or another MCP client) to your SparkleTree workspace. When you do:
- The assistant acts as you. It has your role and can only reach the workspace you sign in to. Cross-workspace access is refused.
- Each tool call the assistant makes sends us its inputs (the request and any content it includes) and returns outputs drawn from your workspace data. We process both to fulfil the request and keep the same request logs we keep for dashboard use: who acted, which tool, when, and the outcome.
- We do not receive, collect or store your conversation with the assistant. We only see the tool calls it sends us. What the assistant provider keeps is governed by that provider's privacy policy.
- Tools that generate content or render video spend your workspace credits in the same way as the dashboard does.
- You can revoke access at any time by removing the connector in the assistant's settings or by disabling the API key in Settings → API keys. The token stops working immediately.
AI-Generated Media
Some features create content with AI models: campaign copy and images, brand voice suggestions, product image analysis, rendered videos and commissioned films. Where a published campaign contains AI-generated content created on or after 2 August 2026, it carries a visible "AI-generated content" disclosure on the surface it is shown on, in line with Article 50 of the EU AI Act. Images generated through OpenAI carry C2PA Content Credentials and images generated through Google carry a SynthID watermark, so the origin stays machine-readable.
Generated content can be inaccurate or unsuitable. You review it before publishing and remain responsible for what you publish.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact our support team:
support@sparkletree.io