arrow_back Back

Privacy Policy for onSpark AI

      Last Updated: October 1, 2026

Thank you for choosing onSpark AI (also called onSpark or The Deal Room), operated by Deal Room Group, Inc. ("Company," "we," "us," or "our"). This Privacy Policy outlines how we collect, use, and protect your information when you use our platform.

This policy describes our privacy practices when you access or use onSpark.

1. Information We Collect

1.1 Personal Information

Name and Contact Details: We collect your name, email, and contact information to personalize your experience and facilitate partner matching.

Voice Intake Data: During the AI-guided intake call (which uses Deepgram for speech-to-text and OpenAI for speech and language processing), we collect information about your business, goals, partnership preferences, and relevant professional details.

Profile Information: You may upload pitch decks, media kits, and other business assets to your profile.

Payment Information: We process payments securely through Fort Point Payments. We do not store your complete payment information on our servers.

1.2 Device, Usage, and Cookie Data

We use cookies and similar technologies to collect information such as IP address, browser type, device information, and usage patterns to improve our services and user experience.

How optional analytics defaults depend on where you are: we determine your country from your IP address using a locally stored copy of the DB-IP country database (IP Geolocation by DB-IP), falling back to your browser's time zone. We do not store the country or use it for anything else. If you are in the United States, first-party product analytics (which areas of onSpark you visit and how long you are active) is on by default, and you can opt out at any time from the notice, Cookie settings, or Settings → Privacy. Everywhere else, including the European Economic Area, the United Kingdom, Switzerland, and whenever we cannot determine your location, optional analytics stays off until you allow it. Session replay, behavioural signals, Google analytics storage, and Marketing cookies are off by default everywhere and require your explicit choice. If your browser sends a Global Privacy Control signal, we treat it as an opt-out of optional analytics and Marketing. When you are signed in, your analytics choice is saved to your account so it applies on your other devices.

1.3 Google Ads Conversion Measurement

We use the Google tag and Google Ads conversion tracking to measure whether advertising leads to account registrations and purchases. We use Google Consent Mode v2. Before you make a choice, or when you reject marketing cookies, advertising storage, advertising user data, advertising personalization, and analytics storage default to denied. In that state, Google may receive cookieless, redacted measurement pings, but our site does not grant permission for advertising cookies or personalized advertising.

If you grant Marketing consent, the Google tag receives granted advertising consent signals and may use advertising storage and advertising data for campaign attribution. A confirmed purchase conversion includes the amount paid, currency, and a unique payment transaction identifier. It does not include complete card details.

When an advertising link contains a Google click identifier (gclid, gbraid, or wbraid), we retain only that identifier for up to 90 days in session storage, not the complete landing URL. We may send it with the same consent state and transaction identifier through Google's Data Manager API as a retryable server-side supplement. Browser and server reports use the same transaction identifier so Google can deduplicate them. These identifiers are forwarded only to our owned qualification service and Google for conversion measurement; they are not included in our error telemetry.

You can grant, reject, or customize optional Analytics and Marketing consent from the consent banner or notice and can change or withdraw that choice at any time using the Cookie settings control.

1.4 Reddit Conversion Measurement

With Marketing consent, we load the Reddit Pixel to measure page visits, completed email registrations, and confirmed purchases. Reddit may receive the page URL, referrer, browser and device information, its cookie and advertising click identifiers, and public page metadata according to the pixel's settings. A purchase event includes the amount paid, currency, item count, and a conversion identifier. Our integration does not supply email addresses, phone numbers, or payment card details as matching fields.

The Reddit Pixel does not load before Marketing consent. If you withdraw that consent, we stop sending events through our integration, disable the pixel's first-party cookies, and reload the page to remove its active tracking code. Links tagged with campaign parameters may separately identify visits from Reddit conversations; a pixel event alone does not identify which organic conversation led to a visit.

2. How We Use Your Information

We use your data to:
- Provide AI-powered partner matching services
- Connect you with relevant members from our database
- Facilitate communication and networking
- Provide access to community resources and tools
- Process payments and manage your membership
- Send important updates about matches, events, and platform features
- Improve our AI matching algorithms and services

2.1 Authorized Account Access

Authorized onSpark personnel may temporarily access or act within an account for account setup, member-requested or contracted concierge management, customer support and troubleshooting, fraud prevention, and platform security. Depending on the account and task, the legal basis is performance of our service contract or our legitimate interests in delivering, protecting, and supporting the service. We do not treat acceptance of our Terms as GDPR consent to unrelated processing.

We limit access to administrators with a dedicated permission and enrolled multi-factor authentication. Each impersonation session records the acting administrator, affected account, date and time, and a required specific reason. Sessions start read-only by default; dry-run and live modes are available only when needed for the documented task. Personnel are required to use the least intrusive access appropriate to that purpose.

Authentication and impersonation audit records are retained for 24 months so we can investigate access, demonstrate accountability, resolve disputes, and meet legal obligations, then deleted automatically. A specific record may be isolated for longer when required by a documented legal hold. Account content remains subject to the retention periods applicable to that content.

Where we rely on legitimate interests, you may object to that processing. We will stop unless we demonstrate compelling legitimate grounds or need the processing to establish, exercise, or defend legal claims. Limiting operational access may affect our ability to provide setup, concierge, or support services that require it.

3. Data Sharing

We share your profile information with matched partners within the platform to facilitate connections.

We do not sell your personal information to third parties.

We disclose data only as necessary to providers that host our application and database, store files, deliver email and communications, process payments, provide AI, speech, meeting, scheduling, CRM, analytics, security, and error-monitoring functions, or support member-connected integrations. Those providers receive only the data needed for the enabled function and are subject to the contractual role and safeguards applicable to that service.

SMS Privacy: We use your mobile number and SMS consent to provide the onSpark text services you request, including partnership intake, requested signup links, and security codes. Intake message frequency varies with your conversation; signup links are one text per request, and security codes are one code per request, with additional messages only when you request another code. Message and data rates may apply. We do not sell or share mobile information with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with third parties for their own use. We provide only the information necessary to service providers that deliver these messages on our behalf. You can stop texts by replying STOP and request help by replying HELP or emailing kyle@onspark.com.

3.1 International Transfers

Some providers process data outside the European Economic Area, United Kingdom, or Switzerland. Where an adequacy decision does not cover the destination, we use an approved transfer safeguard, such as the European Commission's Standard Contractual Clauses and the United Kingdom addendum, together with appropriate supplementary security measures. You may contact us for information about the safeguard applicable to a particular transfer.

3.2 Google and Microsoft User Data

Connecting Google Workspace is optional and separate from signing in with Google. The connection requests access for the following features:

Contacts: We import names, email addresses, organizations, job titles, and available photos from your Google contacts into your onSpark network for contact management and warm introductions. We do not need permission to edit your Google address book.

Gmail: With your optional connection, we send outreach messages you review and submit using Gmail send-only permission. We store the outreach recipient, subject, body, send status and follow-up activity in onSpark. Provider acceptance does not prove delivery or a reply. We do not request Gmail inbox-reading permission for this feature. You read incoming replies in your email app and can record replies in onSpark. Without a connection, we can open a prefilled message in your email app; we ask you to confirm whether you sent it because opening that app does not prove a send.

Calendar: We read events from your primary Google calendar, including titles, descriptions, times, attendees, and meeting links, to display meetings and track partnership interactions. When you schedule a meeting, we create an event on that calendar, optionally with a Google Meet link, and send invitations to the attendees you select. We use provider notifications where configured to keep events current.

Relationship memory: Relationship interactions and information you provide can be processed into searchable representations using Pinecone inference and vector storage. Relevant context may be supplied to the AI service providers supporting the assistance you use. The retired mailbox-sync feature previously imported email threads and generated relationship memory from them. Disconnecting a provider or changing requested permissions does not by itself delete previously imported data; that data remains subject to our deletion and retention practices below.

Microsoft connections support Outlook send-only outreach, contacts, and calendar features. Provider tokens are stored encrypted. You can disconnect a provider in Settings. Disconnecting access is distinct from deleting data already imported into onSpark. Account deletion and retention are described below.

The Deal Room's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

3.3 How Long We Keep Data

We retain account data while the account is active and for only as long afterward as needed to complete deletion, meet a stated service purpose, comply with tax, accounting, payment, security, or other legal obligations, resolve disputes, or enforce agreements. Users can permanently delete their account from Settings. Backup copies are removed through our ordinary backup lifecycle unless preservation is required by law. More specific periods disclosed in this policy, including the 24-month account-access audit period and 90-day advertising-click identifier period, control for those records.

4. Data Security

We implement industry-standard security measures to protect your information. However, no method of transmission over the internet is 100% secure.

5. Your Rights

You have the right to:
- Access your personal data
- Update or correct your information
- Request deletion of your account and data
- Opt-out of non-essential communications
- Change or withdraw optional cookie and advertising consent at any time
- Object to processing based on legitimate interests
- Request restriction of processing and data portability where applicable
- Lodge a complaint with the supervisory authority in your country of residence, work, or the place of an alleged GDPR infringement

You are required to provide the identity, contact, account configuration, and payment information needed to create and perform a paid account. Without it, we cannot provide the relevant service. Optional profile, integration, cookie, advertising, and outreach information is identified as optional at collection or in the applicable settings.

Our AI features generate recommendations, summaries, and assistance. We do not use them to make decisions based solely on automated processing that produce legal or similarly significant effects about you.

6. Children's Privacy

The Deal Room is intended for business professionals. We do not knowingly collect information from individuals under 18.

7. Updates to Privacy Policy

We may update this Privacy Policy to reflect changes in our practices. We will notify you of significant changes via email.

8. Contact Information

For privacy-related questions or requests, contact us at:

Email: kyle@onspark.com