Sparkboard Privacy Policy
Version: 1.0 Effective date: 5 September 2026 Applies to: the Sparkboard hackathon platform at sparkboard.com and the event sites hosted on it ("Sparkboard", "the Platform"). It does not cover other products or prototypes operated under the Sparkboard name, which carry their own notices.
1. Who we are
Sparkboard is operated by Matthew Huebert, a sole proprietor established in Berlin, Germany:
Matthew Huebert (Sparkboard) Erich-Weinert-Str. 11 10439 Berlin, Germany VAT ID: DE303517320
Contact for all data protection matters: privacy@sparkboard.com. Matthew Huebert is the person responsible for data protection at Sparkboard, including in the role the Singapore Personal Data Protection Act 2012 ("PDPA") requires an organisation to designate.
The incorporation of Sparkboard Sàrl (Geneva, Switzerland) has been agreed and is in progress. Upon incorporation, operation of the Platform and the commitments in this policy will transfer to the company, and this policy will be updated with its registered details. Under both the EU General Data Protection Regulation ("GDPR") and the PDPA, a natural person carrying on a business can act as a data controller or data processor; the absence of a company does not reduce our obligations to you, and nothing in this policy depends on the incorporation being complete.
The legal notice required under German law is at sparkboard.com/imprint.
2. How Sparkboard is used, and who is responsible for your data
Sparkboard is a multi-tenant platform: each hackathon or event runs on its own "board", created and administered by an event organizer (for example, a university, foundation, or company). Your account and profile on Sparkboard exist per board: signing up for two events creates two separate participant records.
Because of this structure, responsibility for your personal data is split:
- For a board you join, the event organizer is the data controller (GDPR) and the organisation primarily accountable for the collection and use of your data (PDPA). The organizer decides why participant data is collected (running the event, forming teams, judging, issuing certificates, contacting participants), what profile fields you are asked to fill in, and how long event data is kept. Organizer-specific privacy terms, where provided, are shown to you when you register for that board and take precedence for that board's data.
- Sparkboard acts as a data processor (GDPR) and data intermediary (PDPA) for that board: we host and process participant data on the organizer's behalf and on its instructions, and we do not use it for our own purposes.
- Sparkboard acts as a controller in its own right only for a narrow layer needed to run the Platform itself: operating and securing the service, technical logs and error diagnostics, and the mechanics of service communications such as notification emails. We do not sell personal data and we do not use participant data for advertising.
If you have a question or request about your data on a specific event board, you can direct it either to that event's organizer or to us; we forward requests to the responsible party and assist the organizer in answering them.
3. Personal data we collect
Account and profile data (provided by you at sign-up and in your profile):
- Name and email address (required to create an account)
- Profile picture, if you upload one or sign in with a Google account that has one. If you have none, a generic placeholder image is shown; we do not derive images from your email address.
- Profile fields defined by the event organizer, typically a short introduction and a description of your skills and interests, plus any custom fields the organizer configures; tags; links you add to your profile
- Sign-in credentials: authentication is provided by Google Firebase Authentication (Google sign-in or email/password). If you use a password, only a cryptographic hash is stored, never the password itself.
- Notification preferences (email frequency, unsubscribe status) and language preference
Content you create on the Platform:
- Projects: titles, descriptions, team membership, tags, links, demo video links
- Discussion posts and comments
- Direct messages between participants (stored so that both parties can read the conversation; not end-to-end encrypted, see Section 8)
- Votes and feedback you submit
- Images and files you upload (stored in Google Firebase Storage)
Website contact form: if you request a Sparkboard through the form at sparkboard.com, we receive the name, email address, organisation and message you enter. The form sends them to us by email so we can reply; we keep that correspondence in our mailboxes for as long as the conversation is relevant, and do not add you to any list.
Notifications and email: we generate in-app notifications and, depending on your email preferences, send digest emails to your email address containing recent activity relevant to you (new messages, posts, comments, team members). Every such email contains an unsubscribe link.
Technical data:
- Session data: a session cookie identifying your logged-in session (see Section 11)
- Server logs and error reports, which can include IP address, browser user-agent, and pages visited, processed for security and to diagnose faults
- If you vote on a project through a public (not logged-in) voting page, we record your IP address, browser user-agent, and referring page together with the vote, to detect duplicate or fraudulent votes
- Aggregate, cookieless web analytics provided by Cloudflare (page views and performance timings, without cookies or cross-site identifiers). This measurement is not collected for visitors in the European Union.
We do not knowingly collect special categories of data (health, religion, political opinions, etc.). Free-text fields (profiles, projects, messages) are under your control; please do not put sensitive information in them.
4. Purposes and legal bases
Where Sparkboard processes data as processor for an event organizer, the legal basis is determined by that organizer (commonly: your consent given at registration, or the organizer's legitimate interest or performance of its arrangement with you). The organizer's own notice applies.
Where Sparkboard processes data as controller, we rely on:
| Purpose | GDPR legal basis | PDPA basis |
|---|---|---|
| Creating and operating your account; providing the Platform's features (projects, teams, messaging, notifications) | Performance of a contract, Art. 6(1)(b) | Consent given at sign-up; purposes notified at or before collection |
| Sending notification digest emails at your chosen frequency | Performance of a contract, Art. 6(1)(b); you can switch these off at any time | Consent; withdrawal honoured via unsubscribe |
| Security, abuse and fraud prevention (including IP logging on public votes), service diagnostics and error reporting | Legitimate interests, Art. 6(1)(f): keeping the service secure and working | Legitimate interests exception; purposes a reasonable person would consider appropriate in the circumstances |
| Aggregate, cookieless web analytics (not collected for EU visitors) | Legitimate interests, Art. 6(1)(f): understanding overall usage | Purposes a reasonable person would consider appropriate |
| Answering a request sent through the website form | Steps at your request prior to a contract, Art. 6(1)(b) | Consent given by sending the form |
| Newsletter (only if you opt in; off by default) | Consent, Art. 6(1)(a) | Consent |
You can withdraw any consent at any time (see Section 9); this does not affect processing already carried out.
5. Sharing and subprocessors
We do not sell personal data. We share it only with (a) the event organizer of each board you join, who is the controller for that board; organizers can view and export participant lists for their own event, including participant email addresses, for event administration; (b) other users, to the extent you make information visible on the Platform (your profile and projects are visible to other participants of your board; some boards make project pages publicly visible, which your organizer's settings control); and (c) the service providers ("subprocessors") below, who process data on our behalf under their standard data processing terms:
| Provider | Role | Data involved | Location |
|---|---|---|---|
| Salesforce, Inc. (Heroku) | Application hosting | All platform data in transit through the application | United States |
| MongoDB, Inc. (Atlas) | Primary database | Accounts, profiles, projects, messages, votes, notifications | United States (AWS us-east-1) |
| Google LLC (Firebase Authentication, Realtime Database, Firestore, Cloud Storage; App Engine; Cloud Pub/Sub) | Sign-in, board settings, invitations, file and image storage and serving, internal events | Identity data (name, email, photo), uploaded files, board configuration | United States (us-central1) |
| Mailgun Technologies, Inc. | Email delivery | Name, email address, notification content | United States |
| Functional Software, Inc. (Sentry) | Error reporting | Technical error context; may include IP address and user-agent | United States |
| SolarWinds (Papertrail) | Application log aggregation | Server logs; may include IP addresses and request paths | United States |
| Cloudflare, Inc. | DNS, CDN, cookieless web analytics | Traffic metadata (IP addresses); aggregate page-view statistics | Global network |
| Algolia, Inc. | Legacy search index. The Platform no longer queries it; the index is being decommissioned. | Names and profile/project text indexed before September 2026 | United States (US-East) |
| Filestack (legacy Filepicker.io) | Historic image hosting for images uploaded before the move to Firebase Storage | Legacy profile and project images | United States |
| Slack Technologies | Optional per-project chat channels, only on boards where the organizer enables the Slack integration | Name and email as needed to join the workspace | Only for boards that use it |
Some features are served by a companion Sparkboard service hosted in Heroku's European region; it receives only a signed, short-lived token identifying your account and board. Some pages load JavaScript libraries from Google's static-content CDN, which technically receives your IP address when your browser fetches the files.
We will update this table when providers change. Organizers acting as controllers are informed of subprocessor changes as described in our processing arrangement with them.
6. International transfers
Sparkboard's primary data stores are located in the United States: the application (Heroku), the MongoDB Atlas database (AWS us-east-1), the Firebase project (us-central1), and email delivery via Mailgun.
- From the EU/EEA and Switzerland: where personal data is transferred to providers outside the EEA (notably to the US), the transfer is protected by the European Commission's Standard Contractual Clauses incorporated in each provider's data processing agreement, and, where the provider is certified, by the EU-US Data Privacy Framework. All providers listed in Section 5 publish data processing terms that incorporate these safeguards and that apply to our accounts with them.
- From Singapore: where personal data of individuals in Singapore is transferred outside Singapore, we ensure, through contractual arrangements with our providers and with event organizers, a standard of protection comparable to the PDPA, as required by the PDPA's Transfer Limitation Obligation (section 26).
7. Retention
- Account and event data are retained for as long as the event board remains active, and thereafter according to the event organizer's instructions (organizers frequently keep boards accessible as an archive of the event). Independently of organizer instructions, we review boards that have had no activity for three years and archive or delete them, unless the organizer asks us to keep a board longer.
- Deactivated accounts: when an account is deleted on the Platform, the profile is deactivated and masked (displayed as "Deleted User", with picture, tags and links removed) and login is disabled. Underlying records are then removed in line with the retention rules above, or earlier on request (see Section 9). If you want your data fully erased rather than deactivated, ask us.
- Notification emails include activity from the last 14 days only.
- Server logs and error reports are retained by the respective provider for up to 90 days.
- We may retain limited data longer where required to comply with legal obligations or to establish, exercise or defend legal claims.
8. Security
We take measures appropriate to the nature of the data, including: TLS encryption in transit; encryption at rest and certified security programmes (ISO 27001, SOC 2) at the cloud providers that hold the data (Google Cloud, Salesforce/Heroku, MongoDB Atlas); password storage using bcrypt hashing; role-based access (organizer and admin functions separated from participant functions); production access restricted to the operator, with multi-factor authentication on provider accounts; and daily database backups managed by the database provider. No internet service can guarantee absolute security. Direct messages are stored in the database in readable form and are accessible to the operator for support and legal compliance, so treat them as private but not confidential.
If a data breach occurs that is likely to result in a risk to you, we will notify the competent authorities and affected controllers and users as required: under the GDPR within 72 hours of becoming aware (Art. 33), and under the PDPA by notifying the Personal Data Protection Commission as soon as practicable and no later than 3 calendar days after assessing that a breach is notifiable, and by assisting the responsible event organizer with its own notification duties.
9. Your rights
Under the GDPR (if you are in the EU/EEA; equivalent rights apply under Swiss and UK law), you have the right to: access your data; rectify inaccurate data; erasure ("right to be forgotten"); restriction of processing; data portability; object to processing based on legitimate interests; withdraw consent at any time; and lodge a complaint with a supervisory authority. The authority responsible for Sparkboard is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit, datenschutz-berlin.de); you may also complain to the authority of your own country of residence.
Under the PDPA (if your data was collected in Singapore), you have the right to: request access to your personal data and information about how it has been used or disclosed within the past year; request correction of errors or omissions; and withdraw consent (which we will action within a reasonable time, after informing you of the likely consequences). Complaints may be made to the Personal Data Protection Commission of Singapore (pdpc.gov.sg).
How to exercise your rights:
- In-product: edit your profile at any time; change or stop notification emails via your settings or the unsubscribe link in any email.
- By email: write to privacy@sparkboard.com. Because responsibility for event data sits with the event organizer (Section 2), we will either fulfil your request directly (for data we control) or forward it to the organizer and assist them (for their board's data); we will tell you which, and you will not need to resubmit. We aim to respond within 30 days.
- Erasure requests: full deletion of your account and content from a board is performed on request; where you have contributed to shared content (for example, comments in a discussion), we remove or anonymise your identity from it.
We may need to verify your identity (normally by corresponding via the email address on the account) before acting on a request.
10. Children
Sparkboard is not directed at children under 13, and accounts require the user to be old enough to consent to data processing in their country (16 in Germany and most EU member states unless the event organizer has obtained parental consent; 13 in Singapore, where the PDPC recognises that minors aged 13 or older may typically give valid consent). Events aimed at younger participants are the responsibility of the organizer, who must ensure appropriate consent is in place.
11. Cookies and local storage
Sparkboard uses no advertising cookies and no analytics cookies, and therefore shows no cookie banner. What is stored in your browser:
- Strictly necessary: a session cookie (
connect.sid) that keeps you logged in and remembers your language choice for the session. Local storage is used briefly during email sign-in to return you to the right page. These do not require consent. - Sign-in: Google Firebase Authentication stores the tokens needed to keep you signed in.
- Embedded videos: if a participant adds a video link to a project, the page embeds a player from the video provider (for example YouTube), which may set its own cookies when you play the video.
You can delete cookies in your browser at any time; doing so signs you out.
12. Changes to this policy
We may update this policy from time to time, for example upon incorporation of Sparkboard Sàrl or when subprocessors change. The current version is always available at sparkboard.com/privacy, with its effective date at the top. For material changes we will provide notice on the Platform or by email.
Previous version: the policy hosted at iubenda (policy 7930385), last updated 27 February 2023, which this policy replaces.