arrow_back Back

Privacy Policy for onSpark AI

      Last Updated: August 18, 2026

Thank you for choosing The Deal Room, operated by Deal Room Group, Inc. ("Company," "we," "us," or "our"). This Privacy Policy outlines how we collect, use, and protect your information when you use our platform.

This policy describes our privacy practices when you access or use The Deal Room.

1. Information We Collect

1.1 Personal Information

Name and Contact Details: We collect your name, email, and contact information to personalize your experience and facilitate partner matching.

Voice Intake Data: During the AI-guided intake call (which uses Deepgram for speech-to-text and OpenAI for speech and language processing), we collect information about your business, goals, partnership preferences, and relevant professional details.

Profile Information: You may upload pitch decks, media kits, and other business assets to your profile.

Payment Information: We process payments securely through Fort Point Payments. We do not store your complete payment information on our servers.

1.2 Device, Usage, and Cookie Data

We use cookies and similar technologies to collect information such as IP address, browser type, device information, and usage patterns to improve our services and user experience.

1.3 Google Ads Conversion Measurement

We use the Google tag and Google Ads conversion tracking to measure whether advertising leads to account registrations and purchases. We use Google Consent Mode v2. Before you make a choice, or when you reject marketing cookies, advertising storage, advertising user data, advertising personalization, and analytics storage default to denied. In that state, Google may receive cookieless, redacted measurement pings, but our site does not grant permission for advertising cookies or personalized advertising.

If you grant Marketing consent, the Google tag receives granted advertising consent signals and may use advertising storage and advertising data for campaign attribution. A confirmed purchase conversion includes the amount paid, currency, and a unique payment transaction identifier. It does not include complete card details.

When an advertising link contains a Google click identifier (gclid, gbraid, or wbraid), we retain only that identifier for up to 90 days in session storage, not the complete landing URL. We may send it with the same consent state and transaction identifier through Google's Data Manager API as a retryable server-side supplement. Browser and server reports use the same transaction identifier so Google can deduplicate them. These identifiers are forwarded only to our owned qualification service and Google for conversion measurement; they are not included in our error telemetry.

You can grant, reject, or customize optional Analytics and Marketing consent from the consent banner and can change or withdraw that choice at any time using the Cookie settings control.

2. How We Use Your Information

We use your data to:
- Provide AI-powered partner matching services
- Connect you with relevant members from our database
- Facilitate communication and networking
- Provide access to community resources and tools
- Process payments and manage your membership
- Send important updates about matches, events, and platform features
- Improve our AI matching algorithms and services

2.1 Authorized Account Access

Authorized onSpark personnel may temporarily access or act within an account for account setup, member-requested or contracted concierge management, customer support and troubleshooting, fraud prevention, and platform security. Depending on the account and task, the legal basis is performance of our service contract or our legitimate interests in delivering, protecting, and supporting the service. We do not treat acceptance of our Terms as GDPR consent to unrelated processing.

We limit access to administrators with a dedicated permission and enrolled multi-factor authentication. Each impersonation session records the acting administrator, affected account, date and time, and a required specific reason. Sessions start read-only by default; dry-run and live modes are available only when needed for the documented task. Personnel are required to use the least intrusive access appropriate to that purpose.

Authentication and impersonation audit records are retained for 24 months so we can investigate access, demonstrate accountability, resolve disputes, and meet legal obligations, then deleted automatically. A specific record may be isolated for longer when required by a documented legal hold. Account content remains subject to the retention periods applicable to that content.

Where we rely on legitimate interests, you may object to that processing. We will stop unless we demonstrate compelling legitimate grounds or need the processing to establish, exercise, or defend legal claims. Limiting operational access may affect our ability to provide setup, concierge, or support services that require it.

3. Data Sharing

We share your profile information with matched partners within the platform to facilitate connections.

We do not sell your personal information to third parties.

We disclose data only as necessary to providers that host our application and database, store files, deliver email and communications, process payments, provide AI, speech, meeting, scheduling, CRM, analytics, security, and error-monitoring functions, or support member-connected integrations. Those providers receive only the data needed for the enabled function and are subject to the contractual role and safeguards applicable to that service.

3.1 International Transfers

Some providers process data outside the European Economic Area, United Kingdom, or Switzerland. Where an adequacy decision does not cover the destination, we use an approved transfer safeguard, such as the European Commission's Standard Contractual Clauses and the United Kingdom addendum, together with appropriate supplementary security measures. You may contact us for information about the safeguard applicable to a particular transfer.

3.2 Google and Microsoft User Data

If you choose to connect your Google or Microsoft account, The Deal Room requests only the mail permissions needed for the features you enable: sending partnership outreach you explicitly compose, reading deal-related inbox threads when Partnership inbox sync is turned on, and keeping those threads current through provider change notifications. We filter out unrelated mailbox noise such as bulk, automated, promotional, and personal mail where possible, and store only messages that appear related to partner, deal, or meeting workflows. Your provider tokens are stored encrypted, used only for the connected features, and you can disconnect your account at any time, which revokes our access.

The Deal Room's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

3.3 How Long We Keep Data

We retain account data while the account is active and for only as long afterward as needed to complete deletion, meet a stated service purpose, comply with tax, accounting, payment, security, or other legal obligations, resolve disputes, or enforce agreements. Users can permanently delete their account from Settings. Backup copies are removed through our ordinary backup lifecycle unless preservation is required by law. More specific periods disclosed in this policy, including the 24-month account-access audit period and 90-day advertising-click identifier period, control for those records.

4. Data Security

We implement industry-standard security measures to protect your information. However, no method of transmission over the internet is 100% secure.

5. Your Rights

You have the right to:
- Access your personal data
- Update or correct your information
- Request deletion of your account and data
- Opt-out of non-essential communications
- Change or withdraw optional cookie and advertising consent at any time
- Object to processing based on legitimate interests
- Request restriction of processing and data portability where applicable
- Lodge a complaint with the supervisory authority in your country of residence, work, or the place of an alleged GDPR infringement

You are required to provide the identity, contact, account configuration, and payment information needed to create and perform a paid account. Without it, we cannot provide the relevant service. Optional profile, integration, cookie, advertising, and outreach information is identified as optional at collection or in the applicable settings.

Our AI features generate recommendations, summaries, and assistance. We do not use them to make decisions based solely on automated processing that produce legal or similarly significant effects about you.

6. Children's Privacy

The Deal Room is intended for business professionals. We do not knowingly collect information from individuals under 18.

7. Updates to Privacy Policy

We may update this Privacy Policy to reflect changes in our practices. We will notify you of significant changes via email.

8. Contact Information

For privacy-related questions or requests, contact us at:

Email: kyle@onspark.com