Last updated: July 26, 2026
How SparkSocialHq collects, uses and protects your data.
SparkSocialHq ("we", "us") operates sparksocialhq.com, a social media publishing platform that lets you create, customize and schedule posts to social networks you choose to connect (LinkedIn, YouTube, Reddit, TikTok and others as they become available).
This Privacy Policy explains what data we collect, why we collect it, how long we keep it, and the choices you have. Network-specific details are on the dedicated pages linked at the bottom of this policy.
Account data: username, email address, display name and a salted bcrypt hash of your password (never the password itself). If you sign in with Google, we receive your name, email and profile picture from Google.
Connected-channel data: when you connect a social account we store the account's public identifier, display name, avatar, and the OAuth access/refresh tokens the network issues. Tokens are encrypted at rest with AES-256-GCM.
Content you create: post captions, media files you upload, schedules, ideas-board cards and posting presets.
Technical data: standard server logs (IP address, browser type, timestamps) used for security and debugging.
To operate the service: authenticate you, publish the posts you compose to the channels you select, run your schedule, and show you the results.
We only publish content when you explicitly click Publish or set a schedule — never on our own initiative.
We do not sell your personal data, and we do not use your content or connected-account data for advertising.
Your post content and media are transmitted to the social networks you select, under their own terms and privacy policies.
We use infrastructure providers (hosting, storage, database) to run the service; they process data on our behalf under contract.
We may disclose data if required by law or to protect the security of the service.
Account and content data are kept while your account is active.
Disconnecting a social channel immediately deletes its stored tokens. Deleting a post removes it from our systems (it does not remove content already published to a network — delete that on the network itself).
To delete your entire account and associated data, email helpdesk.smartrixlabs@gmail.com — we complete deletion within 30 days.
All traffic is encrypted in transit (HTTPS). Social tokens are encrypted at rest with AES-256-GCM using a key held outside the database. Passwords are hashed with bcrypt.
No system is perfectly secure; if a breach affecting your data occurs we will notify you without undue delay.
Depending on your location (e.g. GDPR, CCPA) you may have rights to access, correct, export or delete your personal data, and to object to or restrict processing.
Exercise any of these by emailing helpdesk.smartrixlabs@gmail.com.
The service is not directed to children under 13 (or the minimum age required by your jurisdiction) and we do not knowingly collect their data.
We will post any changes to this policy on this page and update the date above. Material changes will be announced in the app or by email.