1. Who We Are and Scope of This Policy
This policy is issued by Goods Software, Inc ("Sparrow," "we," "us," or "our"), a Delaware corporation providing AI-powered workflow automation services", with its principal office at 1353 Riverstone Pkwy Suite 120-335 Canton GA 30114 United States.
This policy applies to:
- Information collected through sparrow.ai and its subdomains (the "Website"), including the marketing site, account registration, and the Sparrow platform; and
- Marketing and sales communications we send to prospective and current customers.
This policy does not apply to:
- Customer Content — data, text, files, or other content you upload to or process through the Sparrow platform. We process that content as a data processor acting on your instructions under our Data Processing Agreement. See Section 13 for details.
- Personal data of Sparrow employees and job candidates (governed by separate HR notices).
- Third-party websites we link to but do not operate.
1.1 Data Controller
For information collected through the Website and platform accounts, the data controller is:
Goods Software, Inc
- 1353 Riverstone Pkwy
- Suite 120-335
- Canton GA 30114
- United States
- Phone: 1-800-735-3710
- Email: privacy@sparrow.ai
For visitors in the European Economic Area or the United Kingdom, we are the data controller under GDPR and UK GDPR. See Section 17 for region-specific information.
Email: privacy@sparrow.ai
Mail:
Sparrow Software, Inc
1353 Riverstone Pkwy
Suite 120-335
Canton GA 30114
United States
Phone: 1-800-735-3710
privacy@sparrow.ai
We collect information in three ways: (a) directly from you when you provide it; (b) automatically when you use the Website or platform; and (c) through third-party technology partners described in Section 4.
Marketing site and contact/demo request forms:
- Identifiers — name, work email address, telephone number, company name, job title;
- Communication content — the contents of your inquiry or demo request.
Account registration:
- Account identifiers — name, work email address, password (stored as a salted hash, never in plaintext), company name, job title, account role;
- Billing information — payment method type and billing address, processed by our payment processor (J.P. Morgan Chase) on our behalf. We do not store full card numbers.
Platform use:
- Configuration and settings — workspace names, integration credentials (API keys you connect), and feature preferences;
- Support communications — messages, attachments, and metadata exchanged with our support team.
Website visitors:
- Server logs — IP address, browser type and version, operating system, referring URL, pages viewed, and time of visit;
- Approximate geolocation — city or region derived from IP address;
- Cookie and tracking data — as described in Section 4.
Authenticated platform users:
- Usage data — features accessed, actions taken, API call logs, error events, and session timing;
- Device and session identifiers — browser type, operating system, session tokens, and IP address.
We use Google Tag Manager to load and manage site technologies. GTM loads on every page before consent is obtained, as required to deliver Google Consent Mode v2 signals to Google before any tag fires. This contacts www.googletagmanager.com on page load and involves your IP address being processed by Google for script delivery. Google Analytics 4 (GA4) is configured within GTM and is consent-gated — it activates only after you accept the Statistics cookie category.
2.3 Categories under California Law
For California residents, categories of personal information collected during the past 12 months:
(A) Identifiers
- Examples: Name, work email, IP address, cookie IDs (GA4, HubSpot), account ID
- Collected?: Yes
(B) Customer records (Cal. Civ. Code §1798.80)
- Examples: Name, email, phone from forms and account registration; billing address
- Collected?: Yes
(C) Protected classification characteristics
- Examples: Not collected
- Collected?: No
- Examples: Subscription plan, billing history, services purchased or inquired about
- Collected?: Yes — account holders
- Examples: Not collected
- Collected?: No
(F) Internet activity
- Examples: Server logs; GA4 analytics (consent-gated); platform usage logs
- Collected?: Yes
(G) Geolocation (precise)
- Examples: Not collected. Approximate city/region from IP only.
- Collected?: No (precise)
(H) Sensory data
- Examples: Not collected
- Collected?: No
- Examples: Employer name, job title from forms and account
- Collected?: Yes
- Examples: Not collected
- Collected?: No
(K) Inferences
- Examples: Usage patterns derived from platform activity; GA4 inferences (consent-gated)
- Collected?: Limited
- Examples: See Section 2.4
- Collected?: See 2.4
We do not intentionally collect sensitive personal information (as defined under CCPA/CPRA or GDPR special categories) through the Website or account registration. If you submit a free-form message that incidentally includes sensitive information, we use it only to respond to your inquiry and do not retain it beyond that purpose.
Customer Content note: If data you upload to the Sparrow platform contains sensitive personal information about third parties, we process it as a data processor on your behalf under our Data Processing Agreement. See Section 13.
Operate, maintain, and secure the Website and platform
- GDPR Legal Basis: Legitimate interests (Art. 6(1)(f))
- GDPR Legal Basis: Performance of contract (Art. 6(1)(b))
Process account registration and authentication
- GDPR Legal Basis: Performance of contract (Art. 6(1)(b))
Process billing and payments
- GDPR Legal Basis: Performance of contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
- GDPR Legal Basis: Pre-contractual measures (Art. 6(1)(b)) or legitimate interests
Deliver site technologies via Google Tag Manager (loads unconditionally for Consent Mode v2 delivery)
- GDPR Legal Basis: Legitimate interests (Art. 6(1)(f)) — technically required for consent signal delivery
Website analytics — Google Analytics 4 — activated only after Statistics consent
- GDPR Legal Basis: Consent (Art. 6(1)(a))
CRM and lead management — HubSpot — tracking activated only after Statistics consent
- GDPR Legal Basis: Consent (Art. 6(1)(a)); legitimate interests for B2B follow-up (Art. 6(1)(f))
- GDPR Legal Basis: Legitimate interests (Art. 6(1)(f)) — product improvement and reliability
Customer support
- GDPR Legal Basis: Performance of contract (Art. 6(1)(b)) or legitimate interests
Security monitoring, fraud prevention, and abuse detection
- GDPR Legal Basis: Legitimate interests (Art. 6(1)(f))
Send product and account notifications
- GDPR Legal Basis: Performance of contract (Art. 6(1)(b))
Send marketing communications (email)
- GDPR Legal Basis: Consent (Art. 6(1)(a)) for individuals; legitimate interests for B2B contacts (Art. 6(1)(f)); unsubscribe in every email
Comply with legal obligations
- GDPR Legal Basis: Legal obligation (Art. 6(1)(c))
Establish, exercise, or defend legal claims
- GDPR Legal Basis: Legitimate interests (Art. 6(1)(f))
4. Cookies and Tracking Technologies
4.1 What Cookies Are
A cookie is a small data file stored in your browser. We also use related technologies including HTML local storage and session storage. We refer to all of these collectively as "cookies" in this policy.
4.2 Consent Management — Cookiebot
We use Cookiebot by Usercentrics as our consent management platform (CMP). On your first visit to the Website, Cookiebot presents an Accept All / Reject All / Customize choice. You may change your preferences at any time via the "Cookie Settings" link in the Website footer. Your consent choice is stored in the CookieConsent cookie for 12 months.
Non-essential cookies (Statistics category) are blocked until you give consent. Strictly necessary cookies load immediately as required for the Website to function.
When we detect a Global Privacy Control (GPC) browser signal, we treat it as a "Do Not Sell or Share" preference and suppress non-essential cookie categories accordingly.
4.3 Cookie Inventory
This inventory reflects the standard cookie deployment on www.sparrow.ai. Verify all entries against a live Cookiebot scan before publication and update any placeholders marked [TBD].
CookieConsent
- Provider: sparrow.ai (Cookiebot)
- Type: HTTP
- Duration: 1 year
- Purpose: Stores your cookie consent choices for sparrow.ai
auth session token
- Provider: sparrow.ai
- Type: HTTP / Secure
- Duration: Session or rolling expiry
- Purpose: Authenticated session management for platform users
CSRF token(s)
- Provider: sparrow.ai
- Type: HTTP / Secure
- Duration: Session
- Purpose: Cross-site request forgery protection on forms
Google Tag Manager — Loads unconditionally on every page (Legitimate Interests — Consent Mode v2 delivery).
www.googletagmanager.com/gtag/js loads on every page of sparrow.ai before user consent is obtained. This is required to deliver Google Consent Mode v2 signals to Google before any tag fires — the mechanism by which Cookiebot instructs GTM to block or allow Analytics tags. This script delivery contacts Google's servers and involves your IP address being processed by Google. GTM itself does not set a cookie or collect personal data beyond this script-delivery request. All tags within the GTM container that require consent are gated by Cookiebot consent signals.
Statistics — Requires consent. Blocked until you accept the Statistics category.
_ga
- Provider: Google LLC (GA4)
- Type: HTTP
- Duration: 2 years
- Purpose: Google Analytics 4 — distinguishes unique visitors; enables aggregate website traffic analysis
_ga_1ZMB60LL5L
- Provider: Google LLC (GA4)
- Type: HTTP
- Duration: 2 years
- Purpose: GA4 session and campaign persistence for this property
_gid
- Provider: Google LLC (GA4)
- Type: HTTP
- Duration: 24 hours
- Purpose: GA4 — distinguishes users within a 24-hour period
hubspotutk
- Provider: HubSpot, Inc.
- Type: HTTP
- Duration: 13 months
- Purpose: Visitor identity tracking — links contact form submissions to prior site visits for CRM attribution
__hstc
- Provider: HubSpot, Inc.
- Type: HTTP
- Duration: 13 months
- Purpose: Session tracking — records first visit, most recent visit, and current session start time
__hssc
- Provider: HubSpot, Inc.
- Type: HTTP
- Duration: 30 minutes
- Purpose: Session state — determines whether to increment session count in CRM
__hsfp
- Provider: HubSpot, Inc.
- Type: HTTP
- Duration: 13 months
- Purpose: Browser fingerprint — identifies a browser instance independently of login state
__hs_opt_out
- Provider: HubSpot, Inc.
- Type: HTTP
- Duration: 13 months
- Purpose: Stores HubSpot opt-out preference when a visitor declines tracking
4.4 Your Cookie Choices
Cookiebot banner. On first visit and at any time via "Cookie Settings" in the Website footer: Accept All, Reject All, or customize by category. Rejecting Statistics blocks all GA4 and HubSpot tracking cookies listed above.
Global Privacy Control (GPC). A GPC signal in your browser is honored as a Do Not Sell or Share preference. Non-essential cookies are suppressed when GPC is detected.
Browser controls. All major browsers allow you to block or delete cookies. Standard cookie deletion clears the Statistics cookies listed above.
HubSpot opt-out. You may opt out of HubSpot tracking at hubspot.com/data-privacy/gdpr-faq, or by clicking the unsubscribe link in any marketing email we send.
Google Analytics opt-out. You may install the Google Analytics Opt-out Browser Add-on (tools.google.com/dlpage/gaoptout) or adjust your Google data settings at myaccount.google.com/data-and-privacy.
We disclose information only in the circumstances described below.
5.1 Third-Party Technology Partners
The following third parties receive information through the technologies described in Section 4 and through our platform operations. Where noted, they act as independent data controllers subject to their own privacy policies.
Google LLC
- Data Received: IP address (script delivery)
- Purpose: GTM script delivery (loads unconditionally for Consent Mode v2)
- Role: Independent controller
- Location: United States
Google LLC
- Data Received: Session, traffic, and behavioral data (consent-gated)
- Purpose: Google Analytics 4 website analytics
- Role: Independent controller
- Location: United States
HubSpot, Inc.
- Data Received: Contact form submissions, visitor identity (consent-gated)
- Purpose: CRM and lead management
- Role: Processor (under DPA)
- Location: United States / EU
Cookiebot / Usercentrics A/S
- Data Received: Consent choices, anonymized IP, browser type
- Purpose: Consent management and audit log
- Role: Processor (under DPA)
- Location: Denmark / EU
AWS
- Data Received: Web traffic, platform data, application logs, CDN
- Purpose: Website and application hosting
- Role: Processor (under DPA)
- Location: United States
5.2 Legal and Compliance
We may disclose information when required by law, lawful court order, or governmental request; to enforce our Terms of Service; or to protect the rights, property, or safety of Sparrow, our users, or others.
5.3 Business Transactions
In the event of a merger, acquisition, financing, or sale of all or part of our business, information may be transferred to the counterparty subject to confidentiality protections and continued application of equivalent protections.
5.4 With Your Consent
We share information for any other purpose only with your explicit consent.
6. Sale and Sharing Disclosure
We do not sell your personal information for monetary or other valuable consideration. We have not sold personal information of any consumer in the preceding 12 months.
We do not share your personal information for cross-context behavioral advertising as that term is defined in Cal. Civ. Code §1798.140(ah). We do not participate in advertising networks or data broker programs.
Notwithstanding the above, you may register a "Do Not Sell or Share" preference at any time by:
- Selecting Reject All or disabling Statistics in our "Cookie Settings" footer link;
- Setting the Global Privacy Control (GPC) signal in your browser;
- Emailing [privacy@sparrow.ai] with subject: "Do Not Sell or Share."
We do not knowingly sell or share personal information of consumers under 16.
7. International Data Transfers
Our Website, primary infrastructure, and personnel are in the United States. If you visit from the European Economic Area, the United Kingdom, or another jurisdiction with cross-border data transfer requirements, your information may be transferred to and processed in the United States.
7.1 Transfer Mechanisms — EU/EEA
For transfers of personal data from the EEA to the United States, we rely on the following mechanisms:
Google LLC (GTM, GA4)
HubSpot, Inc.
Cookiebot / Usercentrics A/S
- Transfer Mechanism: Processed within EU (Denmark) — no cross-border transfer to US
AWS
All transfers are supplemented by TLS 1.2+ encryption in transit.
7.2 Transfer Mechanisms — United Kingdom
For transfers from the United Kingdom, we rely on the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses with the UK Addendum, as published by each partner above.
7.3 Other Jurisdictions
For visitors from Canada, Brazil, Australia, Japan, and other jurisdictions with cross-border transfer rules, we rely on the legal mechanisms recognized by applicable law — typically contractual safeguards equivalent to SCCs — with each service provider.
8. Data Retention
- Retention: Up to 7 years
- Rationale: Sales-cycle and statute-of-limitations alignment
- Retention: Duration of subscription
- Rationale: Platform operation
- Retention: 30 days, then deleted or anonymized
- Rationale: Grace period for reactivation; customer instruction; legal hold exceptions apply
Customer Content
- Retention: Per your account settings and Data Processing Agreement
- Rationale: Controlled by customer; deletion available on request or upon account closure
- Retention: 12 months rolling
- Rationale: Product improvement, security investigation, billing disputes
Server access logs (IP, referrer, user-agent)
- Retention: 90 days
- Rationale: Security investigation and abuse prevention
Cookiebot consent logs
- Retention: 3 years
- Rationale: Audit trail for demonstrating valid consent
GA4 analytics data
- Retention: Default 14 months (Google Signals) — adjustable in GA4 property settings
- Rationale: Controlled by Google as independent controller; adjust data retention in GA4 admin if shorter period is required
HubSpot CRM data
- Retention: Duration of our HubSpot subscription
- Rationale: Processor; deletion available on written request
Billing and payment records
- Retention: 7 years
- Rationale: Tax, accounting, and legal compliance
Marketing email engagement data
- Retention: Until unsubscribe + 30 days
- Rationale: Suppression list maintenance
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction, including:
- TLS 1.2+ encryption for all data in transit;
- Encryption at rest for stored Customer Content and account data;
- Role-based access controls and the principle of least privilege;
- Separation of production and development environments;
- Regular security reviews [and penetration testing — confirm if applicable];
- DDoS and edge security protection via [infrastructure provider — TBD].
No method of transmission or storage is perfectly secure. If we become aware of a personal data breach affecting your information, we will notify you and the relevant supervisory authorities as required by applicable law and within required timeframes — 72 hours under GDPR; as required under applicable US state breach notification laws.
10. Children's Privacy
The Sparrow platform is a business tool intended for use by adults in a professional capacity. It is not directed to children under 16. We do not knowingly collect personal information from children under 16. Contact [privacy@sparrow.ai] if you believe a child has provided us with information and we will delete it promptly.
11. Your Privacy Rights
Your rights depend on where you live.
California
- Rights: Know, access, delete, correct, portability, opt out of sale/sharing, limit use of sensitive PI, non-discrimination
- Governing Law: CCPA / CPRA
Virginia
- Rights: Access, delete, correct, portability, opt out of sale/targeted advertising/profiling, appeal
- Governing Law: VCDPA
Colorado
- Rights: Access, delete, correct, portability, opt out of sale/targeted advertising/profiling, appeal
- Governing Law: CPA
Connecticut
- Rights: Access, delete, correct, portability, opt out of sale/targeted advertising/profiling, appeal
- Governing Law: CTDPA
Texas
- Rights: Access, delete, correct, portability, opt out of sale/targeted advertising/profiling
- Governing Law: TDPSA
Tennessee
- Rights: Access, delete, correct, portability, opt out of sale/targeted advertising/profiling
- Governing Law: TIPPA
Florida
- Rights: Access, delete, correct, portability, opt out of sale/targeted advertising/profiling
- Governing Law: FDBR
Oregon
- Rights: Access, delete, correct, portability, opt out of sale/targeted advertising/profiling
- Governing Law: OCPA
Montana, Iowa, Indiana, Delaware, New Jersey, New Hampshire, Minnesota, Maryland, Kentucky, Rhode Island
- Rights: Access, delete, correct, portability, opt out of sale/targeted advertising/profiling
- Governing Law: State-specific CDPA/equivalent
EU / EEA
- Rights: Access, rectification, erasure, restriction, portability, object, withdraw consent, lodge complaint
- Governing Law: GDPR Art. 15–22
United Kingdom
- Rights: Same as EU/EEA
- Governing Law: UK GDPR / DPA 2018
Canada
- Rights: Access, correction, withdrawal of consent
- Governing Law: PIPEDA; Quebec Law 25
Brazil
- Rights: Confirmation, access, correction, anonymization, portability, deletion, information on sharing, revoke consent
- Governing Law: LGPD Art. 18
Other jurisdictions
- Rights: Rights granted by your local law — contact us and we will respond consistent with applicable law
- Governing Law: Various
11.1 California (CCPA/CPRA)
California residents have the right to non-discrimination for exercising any privacy right. We will not deny services, charge different prices, or provide a different level of service because you exercised a right.
Because we do not sell or share personal information for cross-context behavioral advertising (Section 6), the "Do Not Sell or Share" link is not legally mandatory — but we provide an opt-out mechanism voluntarily and honor all requests.
Authorized agents. California residents may designate an authorized agent to make requests on their behalf. Written proof of authorization is required before we act on the request.
11.2 EU / UK
Right to object (Art. 21 GDPR). You may object to processing based on legitimate interests — including product usage analytics and B2B marketing outreach — by contacting [privacy@sparrow.ai] with subject line "Right to Object." We will assess and respond within one month.
Right to withdraw consent. Withdraw cookie consent at any time via "Cookie Settings." Withdraw marketing email consent via the unsubscribe link in any marketing email. Withdrawal does not affect the lawfulness of processing that took place before withdrawal.
UK supervisory authority: Information Commissioner's Office (ICO) — ico.org.uk
EU/EEA supervisory authority: The data protection authority in your member state of residence, place of work, or place of the alleged infringement.
11.3 Brazil (LGPD)
Brazilian data subjects may exercise rights under LGPD Art. 18 by contacting [privacy@sparrow.ai]. We will respond within 15 days as required under LGPD.
11.4 GPC and Do Not Track
We honor the Global Privacy Control (GPC) browser signal as a Do Not Sell or Share preference (Section 4.2). We do not respond to the older Do Not Track (DNT) signal, which is a separate and non-standardized mechanism.
11.5 How to Exercise Your Rights
Mail: Sparrow Software, Inc. 1353 Riverstone Pkwy Suite 120-335 Canton GA 30114 United States
Phone: 1-800-735-3710
privacy@sparrow.ai
Cookie preferences: "Cookie Settings" link in the Website footer
Response times: 45 days for CCPA (one 45-day extension available); 30 days for most other US state laws; one month for GDPR/UK GDPR (up to two additional months for complex requests); 15 days for LGPD. We may need to verify your identity before fulfilling a request. We do not require account creation.
Appeals. If we deny your request in whole or in part, you may appeal under applicable US state laws by resubmitting to the same contact with subject: "Privacy Appeal."
12. Automated Processing and AI
We do not engage in automated decision-making based on Website visitor data that produces legal effects or similarly significant effects on you.
The Sparrow platform uses AI and machine learning to process inputs and generate outputs according to your instructions and subscription plan. This constitutes automated processing of Customer Content. You control what content you submit and what actions you take based on Sparrow's outputs. Sparrow does not use the outputs of your AI sessions to make autonomous decisions about you without your direction.
See Section 13 for AI model provider disclosure and Customer Content processing.
13. Customer Content and Our Role as Processor
13.1 Controller/Processor Distinction
When you use the Sparrow platform, you may upload, submit, or otherwise provide data, text, files, or other content ("Customer Content"). We process Customer Content as a data processor acting strictly on your instructions, as documented in our Data Processing Agreement (DPA) and Terms of Service.
Our DPA governs:
- Sub-processors used in delivering the platform (e.g., AI model providers, cloud hosting);
- Responding to data subject rights requests relating to Customer Content;
- Data breach notification timelines for Customer Content incidents;
- Cross-border transfer mechanisms for Customer Content;
- Retention and deletion of Customer Content upon contract termination.
If your Customer Content includes personal data of third parties — such as your own customers' data — you are responsible as the data controller for having a lawful basis to provide that data to us for processing. Our DPA satisfies the Article 28 GDPR processor contract requirement.
To request a copy of our DPA, contact [privacy@sparrow.ai] with subject: "DPA Request."
13.2 AI Model Processing
N/A
13.3 No Use of Customer Content for Our Marketing
We do not use Customer Content for our own marketing, advertising, or product development purposes (beyond aggregate, de-identified analytics) without your separate written consent.
14. Third-Party Links and Services
The Website and platform may contain links to, or integrations with, third-party websites and services. This policy does not apply to those third parties. We encourage you to read their privacy notices before sharing personal information with them.
15. Changes to This Policy
We update this policy when our practices change or when required by law. Material changes will be announced with a prominent notice on the Website at least 14 days before taking effect; where required by law, we will obtain renewed consent. The "Last Updated" date at the top reflects the most recent revision.
Important: If we add new tracking technologies — including analytics, advertising, or any non-essential cookies — we will update this policy and our Cookiebot configuration before those technologies are activated.
Data subject rights requests
Do Not Sell / Share requests
GDPR / UK GDPR requests
LGPD requests
Data Processing Agreement
Mailing address
- **Contact:**Sparrow Software, Inc
1353 Riverstone Pkwy
Suite 120-335
Canton GA 30114
United States
Phone: 1-800-735-3710
privacy@sparrow.ai
UK supervisory authority
- Contact: Information Commissioner's Office · ico.org.uk
EU supervisory authority
- Contact: Your local EU member state data protection authority
Brazil supervisory authority
- Contact: Autoridade Nacional de Proteção de Dados (ANPD) · gov.br/anpd
17. Region-Specific Notices
17.1 California Notice at Collection
This policy serves as our "Notice at Collection" under Cal. Civ. Code §1798.100. Categories of personal information collected are in Section 2.3. Purposes are in Section 3. We do not sell or share personal information for cross-context behavioral advertising. Retention periods are in Section 8.
Legal bases for all processing are in Section 3. For non-essential cookies (Statistics category), the legal basis is consent (Art. 6(1)(a) GDPR), obtained through Cookiebot before those cookies load. For GTM script delivery, the legal basis is legitimate interests (Art. 6(1)(f)) as required for Consent Mode v2 delivery. International transfer mechanisms are in Section 7. You have the right to lodge a complaint with your local supervisory authority (Sections 11.2 and 16).
The .ai top-level domain is global. Visitors from the EU and UK are fully protected by GDPR and UK GDPR. We do not rely on contractual waivers to exclude or limit your rights under EU or UK data protection law.
The processing described in this policy is carried out by Goods, Software, Inc as the data controller (controlador) under LGPD. Personal data collected from Brazilian data subjects is transferred to the United States under contractual safeguards (Art. 33, LGPD). Brazilian data subjects may exercise rights under Art. 18 LGPD by contacting privacy@sparrow.ai.
We process personal information of Canadian residents in accordance with PIPEDA and, for Quebec residents, in accordance with Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25). Consent for non-essential cookies is obtained through Cookiebot. You may withdraw consent at any time via "Cookie Settings" in the Website footer.
18. Definitions
- Definition: Information that identifies, relates to, or could reasonably be linked to a particular consumer or household (CCPA/CPRA); information relating to an identified or identifiable natural person (GDPR/UK GDPR/LGPD).
Customer Content
- Definition: Data, text, files, or other content submitted to or processed through the Sparrow platform by you or users acting under your account.
Sale
- Definition: Disclosure of personal information to a third party for monetary or other valuable consideration. We do not sell.
Share
- Definition: Disclosure of personal information to a third party for cross-context behavioral advertising (Cal. Civ. Code §1798.140(ah)). We do not share.
Service provider / processor
- Definition: An entity processing personal information on our behalf under a written contract limiting use to specified purposes.
Independent controller
- Definition: A third party that determines its own purposes and means of processing. Google LLC (for GTM script delivery and GA4 analytics) acts as an independent controller for data it collects through its technologies on our Website.
Cookie
- Definition: A small data file stored in your browser. Includes HTML local storage, session storage, and similar client-side technologies.
- Definition: A tool that presents cookie consent choices to visitors and enforces those choices by blocking non-essential technologies until consent is obtained. We use Cookiebot by Usercentrics.
Global Privacy Control (GPC)
- Definition: A browser-level signal communicating a consumer's opt-out of sale and sharing of personal information. We honor GPC wherever applicable law recognizes it.
Cross-context behavioral advertising
- Definition: Targeted advertising based on personal information from a consumer's activity across businesses or sites other than the one directly interacted with. We do not engage in this.
Data Processing Agreement (DPA)
- Definition: A written agreement under GDPR Art. 28 governing the terms on which a data processor (Sparrow) processes personal data on behalf of a data controller (customer).
Consent Mode v2
- Definition: Google's framework for communicating consent signals to Google tags via GTM before those tags fire, allowing GA4 and Google Ads to operate in a consent-respecting mode. Requires GTM to load unconditionally before consent is obtained.
Questions? Contact privacy@sparrow.ai.