Security, privacy and reliability at SparkLayer.
SparkLayer handles business and customer data for thousands of brands. This Trust Center brings together the policies, processes and terms that explain how we protect that data, keep the service available and respond.
-
01
Privacy Policy
What personal data we collect, why we collect it, the legal bases we rely on and the rights available to individuals.
Updated 15 Sep 2026 -
02
Terms of Service
The contractual terms that govern use of SparkLayer, including accounts, fees, cancellation, liability and governing law.
Updated 15 Sep 2026 -
03
Data Processing Agreement
The terms that apply when SparkLayer processes personal data on your behalf, including sub-processors, international transfers, security, breach notification, deletion and audit rights.
Updated 15 Sep 2026 -
04
Security Policy
How we secure SparkLayer, protect customer data, manage access, maintain our systems and back up data.
Updated 15 Sep 2026 -
05
Business Continuity Planning
How we prepare for disruption, restore service and keep customers informed if a major incident affects SparkLayer.
Updated 15 Sep 2026 -
06
Incident Management Policy
How security and service incidents are identified, assessed, contained and resolved, including how to report a concern to us.
Updated 15 Sep 2026
At a glance.
- Hosted on Google Cloud, in London - Customer data is held in the United Kingdom, in Google Cloud's europe-west2 (London) region.
- Encrypted in transit and at rest - Data is encrypted in transit using TLS and encrypted at rest within Google Cloud.
- Multi-factor authentication - Multi-factor authentication is required for access to production systems. Staff are issued FIDO security keys for supported services.
- Least-privilege access - Access is limited to what each person needs for their role, reviewed periodically and removed when no longer required.
- Automated daily backups - Customer data is backed up automatically every day, with backups encrypted at rest. Point-in-time recovery is enabled for supported systems.
- Regular review and testing - Our security policies are reviewed at least twice a year. Business continuity and incident response procedures are reviewed and tested periodically.
- UK GDPR and EU GDPR - Our Data Processing Agreement includes the Article 28 terms required when SparkLayer acts as your processor.
- Published sub-processors - We publish the third parties that process Customer Personal Data on our behalf, together with their processing purpose, location and applicable transfer mechanism.
Report a security concern
If you believe you have identified a vulnerability or security incident affecting SparkLayer or your data, email support@sparklayer.io with URGENT - Security in the subject line.
Please send the report only to that address so it can be routed directly through our incident-response process.
For Trust Center questions, security questionnaires or requests for a countersigned Data Processing Agreement, contact contact@sparklayer.io.
Our details
- Legal entity
- Spark Layer Ltd
- Registered
- England and Wales, company no. 12881913
- Office
- Trimbridge House, First Floor, Trim Street, Bath, BA1 1HB, United Kingdom
- ICO registration
- ZB074246
- Help docs
- docs.sparklayer.io