Privacy Policy

Last updated: July 26, 2026

How SparkSocialHq collects, uses and protects your data.

1. Who we are

SparkSocialHq ("we", "us") operates sparksocialhq.com, a social media publishing platform that lets you create, customize and schedule posts to social networks you choose to connect (LinkedIn, YouTube, Reddit, TikTok and others as they become available).

This Privacy Policy explains what data we collect, why we collect it, how long we keep it, and the choices you have. Network-specific details are on the dedicated pages linked at the bottom of this policy.

2. Data we collect

Account data: username, email address, display name and a salted bcrypt hash of your password (never the password itself). If you sign in with Google, we receive your name, email and profile picture from Google.

Connected-channel data: when you connect a social account we store the account's public identifier, display name, avatar, and the OAuth access/refresh tokens the network issues. Tokens are encrypted at rest with AES-256-GCM.

Content you create: post captions, media files you upload, schedules, ideas-board cards and posting presets.

Technical data: standard server logs (IP address, browser type, timestamps) used for security and debugging.

3. How we use your data

To operate the service: authenticate you, publish the posts you compose to the channels you select, run your schedule, and show you the results.

We only publish content when you explicitly click Publish or set a schedule — never on our own initiative.

We do not sell your personal data, and we do not use your content or connected-account data for advertising.

4. Sharing

Your post content and media are transmitted to the social networks you select, under their own terms and privacy policies.

We use infrastructure providers (hosting, storage, database) to run the service; they process data on our behalf under contract.

We may disclose data if required by law or to protect the security of the service.

5. Retention & deletion

Account and content data are kept while your account is active.

Disconnecting a social channel immediately deletes its stored tokens. Deleting a post removes it from our systems (it does not remove content already published to a network — delete that on the network itself).

To delete your entire account and associated data, email helpdesk.smartrixlabs@gmail.com — we complete deletion within 30 days.

6. Security

All traffic is encrypted in transit (HTTPS). Social tokens are encrypted at rest with AES-256-GCM using a key held outside the database. Passwords are hashed with bcrypt.

No system is perfectly secure; if a breach affecting your data occurs we will notify you without undue delay.

7. Your rights

Depending on your location (e.g. GDPR, CCPA) you may have rights to access, correct, export or delete your personal data, and to object to or restrict processing.

Exercise any of these by emailing helpdesk.smartrixlabs@gmail.com.

8. Children

The service is not directed to children under 13 (or the minimum age required by your jurisdiction) and we do not knowingly collect their data.

9. Changes

We will post any changes to this policy on this page and update the date above. Material changes will be announced in the app or by email.

Network-specific privacy details