Skip to content
SparkMRR

Legal

Privacy notice

Version 2026-10-10.2, in effect from

This notice explains how we handle personal data when you visit sparkmrr.com and when you join the SparkMRR waitlist. It follows the EU General Data Protection Regulation (GDPR) and also covers the privacy laws of other places our visitors live in.

1. Who is responsible for your data

The controller of your personal data is Rafał Darłak, doing business as Software Development - Rafał Darłak, Gnojnica 59, 39-105 Gnojnica, Poland, NIP 8181728292. SparkMRR is our trading name.

Write to support@sparkmrr.com or to the postal address above with any question about your data. We have not appointed a data protection officer, because the GDPR does not require one for the processing we do.

2. What we collect

We collect only what you give us when you join, and what we need to keep the service safe:

Email address
Required to join. Without it we cannot run the waitlist or send you your confirmation link.
Your product's web address
Optional. You decide whether to give it to us.
Signup records
When you joined and confirmed, which versions of the Terms and of this notice you accepted, and a random signup ID.
Confirmation link
We keep only a one-way hash of the secret in your link, never the link itself, and remove it once it has expired.
Abuse-prevention counters
A keyed one-way hash of your IP address (for IPv6, of its /64 network) and of your email address, with the number of recent attempts. We never store the IP address itself, and we delete the counters after 1 day.
Technical logs
Records of what our application did and when, with a random request ID and, if an email fails to send, the signup ID. Our logs do not contain your email address or IP address.

Like every website, our hosting infrastructure receives your IP address and the technical details your browser sends, so that it can deliver pages to you. Apart from the hashed counters above, our application does not store them.

3. Why we use it and on what legal basis

Running the waitlist
Confirming your address, keeping your place, applying the launch offer and sending you emails about the launch and your invitation. Legal basis: performance of our contract with you under the Terms (Article 6(1)(b) GDPR). Because launch and invitation emails are commercial information, we also rely on the consent you give by joining, as required by Article 398 of the Polish Electronic Communications Law. You can withdraw it at any time by leaving the waitlist.
Understanding your product
We use your product's web address to understand what you have built and prepare your onboarding. Legal basis: our legitimate interest (Article 6(1)(f) GDPR). You can object at any time and we will delete it.
Preventing abuse and keeping the service secure
Rate-limit counters and technical logs. Legal basis: our legitimate interest in protecting the service and its users from spam and attacks (Article 6(1)(f) GDPR).
Showing what you agreed to
Records of the versions you accepted and when. Legal basis: our legal obligation to demonstrate compliance (Article 6(1)(c) together with Articles 5(2) and 7(1) GDPR).
Answering your requests and complaints, and legal claims
Legal basis: our legal obligations (Article 6(1)(c) GDPR) and our legitimate interest in establishing, exercising or defending legal claims (Article 6(1)(f) GDPR).

We do not sell your personal data, use it for advertising or share it for cross-context behavioural advertising. We do not profile you or make decisions about you by automated means that have legal or similarly significant effects.

4. Who receives your data

We use two service providers, who process data only on our instructions under data processing agreements:

  • Microsoft Ireland Operations Limited (Microsoft Azure). Hosts the website, the database and the logs in the West Europe region (the Netherlands).
  • Resend, Inc.. Sends our emails. It receives your email address and the content of the emails we send you, stores data in the United States and keeps email logs for 30 days.

We may also disclose data to public authorities when the law requires it, and to professional advisers bound by confidentiality, such as lawyers or accountants, when they need it to advise us.

5. Transfers outside the European Economic Area

Resend, Inc. is based in the United States. Transfers to it rely on the European Commission's Standard Contractual Clauses included in its data processing agreement, and additionally on its certification under the EU-U.S. Data Privacy Framework and its UK Extension, which the European Commission has recognised as adequate.

Microsoft Ireland Operations Limited stores our data in the European Union. Where its staff or subprocessors may access data from outside the EEA, for example for support or security, Microsoft relies on the Standard Contractual Clauses and its Data Privacy Framework certification.

You can ask us for a copy of these safeguards at support@sparkmrr.com.

6. How long we keep it

  • Unconfirmed signups: deleted after 7 days.
  • Confirmed signups: until you leave the waitlist, and at the latest 24 months after you confirmed. Once we send your invitation, we keep your signup for 30 more days, or until you create an account, which is covered by its own privacy terms.
  • Confirmation link hashes: removed once the link has expired.
  • Abuse-prevention counters: deleted after 1 day.
  • Technical logs: deleted after 30 days.
  • Database backups: data we delete can remain in encrypted backups for up to 7 more days, after which the backups expire.
  • Email logs at Resend, Inc.: deleted after 30 days.
  • Your messages to us, such as requests and complaints: as long as we need them to handle the matter, and then until any related claims become time-barred.

7. Your rights

You have the right to:

  • access your data and get a copy of it (Article 15 GDPR);
  • have inaccurate data corrected (Article 16);
  • have your data deleted (Article 17);
  • restrict how we use it (Article 18);
  • receive the data you gave us in a machine-readable format (Article 20);
  • object to processing based on our legitimate interests (Article 21); and
  • withdraw your consent at any time, without affecting what we did before you withdrew it.

The quickest way to delete your signup is the "Leave the waitlist" link in any of our emails. For anything else, write to support@sparkmrr.com. We answer within one month, which we can extend by two more months for complex requests, and we will tell you if we do. Exercising your rights is free. We may ask you to confirm that you control the email address before we act.

You can complain to the President of the Personal Data Protection Office (Prezes UODO), ul. Stawki 2, 00-193 Warszawa, Poland, uodo.gov.pl, or to the data protection authority in the EU or EEA country where you live or work, or where you think the problem happened.

8. Cookies and storage on your device

We do not use cookies. We do not use analytics, advertising, tracking pixels, fingerprinting or third-party scripts, and our fonts are served from our own domain. Our emails contain no tracking pixels and no tracked links.

The website stores two settings in your browser's local storage, and only when you choose them:

sparkmrr:theme
Remembers the colour theme you picked.
sparkmrr:motion
Remembers that you paused animations.

These settings stay on your device and are never sent to us. They are strictly necessary to provide a feature you asked for, so they do not need consent under Article 5(3) of the ePrivacy Directive and Article 399 of the Polish Electronic Communications Law. You can delete them at any time in your browser settings.

9. How we protect it

The whole website uses HTTPS. Data is encrypted at rest. The database sits on a private network with no public access and accepts only Microsoft Entra identities, secrets are kept in a key vault, confirmation links and abuse counters are stored only as one-way hashes, and every component gets only the access it needs. If a personal data breach puts your rights at risk, we will notify the supervisory authority and, where required, you.

10. Children

SparkMRR is for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has joined the waitlist, write to support@sparkmrr.com and we will delete the signup.

11. Information for specific places

United Kingdom
The UK GDPR and the Data Protection Act 2018 give you the rights in section 7. You can complain to the Information Commissioner's Office at ico.org.uk. Transfers to the United States rely on the UK Extension to the EU-U.S. Data Privacy Framework and the safeguards in our providers' data processing agreements.
Switzerland
The Federal Act on Data Protection gives you the same rights. You can contact the Federal Data Protection and Information Commissioner at edoeb.admin.ch.
United States
We do not sell or share personal information, use it for targeted advertising or collect sensitive personal information. If a US state privacy law applies to you, such as the California Consumer Privacy Act, you can ask to know, access, correct or delete your personal information, and appeal our decision by replying to it. We will not treat you differently for using these rights, and we accept requests from authorised agents. We honour Global Privacy Control signals, although there is nothing for them to switch off.
Canada
We handle your data in line with PIPEDA. You can complain to the Office of the Privacy Commissioner of Canada.
Brazil
You have the rights under Article 18 of the LGPD, and you can complain to the ANPD.
Australia
We follow the Australian Privacy Principles. You can complain to the Office of the Australian Information Commissioner.
Everywhere else
Wherever you live, including India and other countries with data protection laws, you can use the rights described in section 7.

12. Changes to this notice

We will publish any change on this page with a new version number. If a change matters to people on the waitlist, we will email them before it takes effect.