SPRK logo

Switchboard

by SPRK

All legal documents

Privacy Policy

Version 1.0

Effective date: August 31, 2026

This Privacy Policy explains how SPRK Technologies LLC ("SPRK", "we", "us" or "our") collects, uses, discloses, and protects personal information in connection with Switchboard by SPRK and related websites, applications and services (the "Services").

Switchboard is a business communications platform. When an organization uses the Services, that organization is the controller of the call, contact, and user data it processes, and we act as its processor or service provider. For our own website visitors, account holders, and billing relationships, we act as the controller.

1. Information we collect

Account information. Name, business email address, phone number, extension, job role, organization, profile photo, authentication credentials, and account settings.

Communications data. Call metadata (date, time, duration, direction, caller and called numbers, disposition, outcome), call recordings and transcripts where enabled, voicemail messages, notes, dispositions, ratings, and chat or support messages.

Contact and lead data. Information your organization uploads or creates about its own contacts and leads, including names, phone numbers, email addresses, addresses, tags, and notes.

Billing information. Purchase history, subscription tier, invoices, and transaction records. Card details are collected and stored by our payment processor; we do not store full card numbers.

Usage and device data. IP address, browser and device type, operating system, pages viewed, features used, timestamps, presence and availability status, session duration, error reports, and diagnostic logs.

Consent records. When you accept our terms or a purchase disclosure, we record the acceptance, the document version, the timestamp, the page URL, the IP address, and the browser user agent.

Cookies and similar technologies. We use strictly necessary cookies and local storage for authentication and session management, and limited analytics storage to understand product usage. We do not use third-party advertising cookies.

2. How we use information

- Provide, operate, maintain, and secure the Services, including placing, receiving, routing, recording, and transcribing calls. - Authenticate users, enforce roles and permissions, and prevent fraud, abuse, and unauthorized access. - Process payments, manage subscriptions, and send billing communications. - Generate reporting, analytics, and AI-assisted summaries for the organization that owns the data. - Provide customer support and respond to requests. - Send service, security, and transactional messages, and — where permitted — product updates you can unsubscribe from. - Comply with legal obligations, enforce our terms, and establish or defend legal claims.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.

3. Legal bases (where applicable)

Where data protection law requires a legal basis, we rely on: performance of a contract (providing the Services); legitimate interests (securing and improving the Services, preventing abuse); consent (optional communications and certain recordings, where required); and legal obligation (tax, accounting, lawful requests).

4. Call recording and transcription

Recording and transcription are configurable by each organization. The organization that operates the account is responsible for providing notices and obtaining consents required by law in the jurisdictions where its calls occur. Recordings and transcripts are stored in encrypted storage and are accessible to authorized users of the owning organization according to their role.

5. How we share information

- Service providers that support the Services under contract, including telephony carriers, cloud hosting and storage providers, payment processors, email delivery providers, transcription and AI providers, and analytics providers. Each is permitted to process data only to provide services to us. - Within your organization. Administrators and supervisors can view user activity, call records, recordings, transcripts, and reporting for their organization. - Integrations you enable, such as CRM webhooks or exports, which transmit data to systems you control and designate. - Legal and safety disclosures when required by law, subpoena, or lawful request, or to protect rights, safety, and property. - Business transfers in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

6. Data retention

We keep account and billing records for as long as the account is active and thereafter as required for legal, tax, and audit purposes. Call metadata, recordings, and transcripts are retained according to the organization's configured retention settings and are deleted after the retention period or on request. Consent and compliance records are retained for the period required to demonstrate compliance. Backups are purged on a rolling schedule.

7. Security

We use industry-standard safeguards including encryption in transit (TLS) and at rest, role-based access control enforced in the database, row-level security, least-privilege service credentials, audit logging, secret management, and monitoring. No system is perfectly secure; you are responsible for maintaining strong credentials and for managing who in your organization has access.

8. International transfers

We operate in the United States and may process data in other countries where we or our providers operate. Where required, we use appropriate safeguards such as standard contractual clauses for cross-border transfers.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to certain processing, and to withdraw consent. Residents of California and other U.S. states with comprehensive privacy laws may request disclosure of the categories of information collected and the right to opt out of sale or sharing — which we do not engage in. You will not be discriminated against for exercising a right.

If your data was provided to us by an organization using the Services, please direct your request to that organization; we will assist them in responding. You may also contact us at privacy@sprktechnologies.com and we will respond within the timeframe required by law. We may need to verify your identity before acting on a request.

10. Children's privacy

The Services are intended for business use and are not directed to individuals under 18. We do not knowingly collect personal information from children. If we learn that we have, we will delete it.

11. Third-party links

The Services may link to third-party sites and tools that we do not control. Their privacy practices are governed by their own policies.

12. Changes to this Policy

We may update this Policy. When we make material changes we will update the effective date and, where appropriate, notify you in the product or by email. Continued use of the Services after the effective date constitutes acceptance.

13. Contact us

SPRK Technologies LLC — privacy@sprktechnologies.com