TrailSpark Privacy Policy
Last updated: August 2025
Who we are: TrailSpark, LLC ("TrailSpark," "we," "us," or "our").
Contact: privacy@trailspark.ai
Scope
This Privacy Policy explains how TrailSpark, LLC collects, uses, and shares personal data when you use our marketing website and our software-as-a-service application (the "Service").
This Policy does not change the role TrailSpark plays with respect to personal data we process on behalf of our business customers. Where we process personal data submitted to the Service by or at the direction of a business customer ("Customer Data"), we generally act as a processor (also called a service provider). Our customers are responsible for their own privacy notices covering their end users and systems.
We act as a controller for personal data that we determine the purposes and means of processing for—such as our website visitors, account administrators, and our own business operations.
Key definitions
- Customer: A company or organization that has a contractual relationship with TrailSpark to use the Service.
- Customer Data: Personal data in systems a Customer connects to the Service (e.g., CRM, marketing and sales tools, product event streams, webhooks) that we process on behalf of the Customer.
- Service: The TrailSpark SaaS application and related functionality made available to Customers.
Personal data we collect (as controller)
We collect the following categories of personal data when we act as controller:
- Account & admin data: name, work email, role, and company.
- Product telemetry: user events and feature usage generated by your use of the Service. (See also the Cookies & Tracking section.)
- Support communications: any personal data you include when you email us (e.g., from an admin or support contact).
- Payments: payments for subscriptions are handled by Stripe; Stripe may collect personal and payment information directly. (TrailSpark does not run its own payment processing.)
We do not intentionally collect sensitive personal data (such as health, biometric, or precise geolocation data) and our Service is for B2B use.
Customer Data we process (as processor)
When Customers connect systems like Salesforce, HubSpot, Marketo, Segment, Gong, or custom webhooks, we process Customer Data to provide the Service (e.g., ingesting signals, evaluating lead activity, returning results to the Customer's chosen systems). For this processing, TrailSpark acts as a processor/service provider and the Customer acts as the controller. The Customer's privacy notices govern their end users and data flows.
Sources of personal data
- Directly from you (e.g., account setup, support emails).
- Automatically via your use of the Service (e.g., telemetry, logs).
- From Customers and their connected systems (for Customer Data where we act as processor).
- From service providers we use to operate our website and Service (see Sharing & disclosure).
Cookies & Tracking
We use Google Analytics and Segment on our website and/or in the Service to understand usage and improve performance. Today we use:
- Strictly necessary/functional technologies (to operate the Service).
- Analytics (to understand usage and improve the Service).
We do not currently use advertising/retargeting cookies. If we add them in the future, we will update this Policy and, where required, provide appropriate notice and controls.
You can control cookies via your browser settings. Disabling certain cookies may affect Service functionality.
How we use personal data (as controller)
We use personal data for:
- Service delivery and account administration (contract).
- Security, abuse prevention, and reliability (legitimate interests).
- Product analytics and improvement (legitimate interests).
- Compliance with law and recordkeeping (legal obligations, e.g., tax/invoices via our payment processor).
- Communications related to the Service (e.g., operational or legal notices). We do not currently send marketing emails. If we do in the future, we will include unsubscribe options consistent with applicable anti-spam laws.
AI/ML use of data
TrailSpark provides AI-driven evaluations of lead activity:
- Customer-specific modeling only: We use Customer Data only for that Customer's own models and outcomes.
- PII minimization: We make strong efforts to avoid sending end-user PII to AI models (e.g., referencing leads by internal IDs instead of email addresses).
- Human review: Customers can review scored outcomes and provide feedback to improve models and reevaluate leads.
TrailSpark does not use Customer Data to train generalized models across customers.
Sharing & disclosure
We share personal data with:
- Service providers/subprocessors that support hosting, analytics, error monitoring, customer communications, and payments.
- Professional advisors (e.g., legal, accounting) as necessary.
- Authorities where required by law (see Law enforcement & safety below).
We may update our service providers over time. We do not currently provide individual notices for subprocessor changes. We do not sell or share personal information for cross-context behavioral advertising.
International data transfers
TrailSpark uses global/cloud hosting and service providers, and data may be processed in various countries. We do not currently participate in the EU-U.S. or UK-U.S. Data Privacy Framework and we have not implemented EU/UK Standard Contractual Clauses.
If TrailSpark begins to process personal data subject to EEA/UK transfer requirements, we will implement appropriate transfer mechanisms and update this Policy accordingly.
Data retention
- Customer signal data: retained up to 1 year depending on the Customer's plan tier.
- Other categories (e.g., site analytics, app telemetry, support communications, audit logs, invoices/records, backups): retention periods vary by category and purpose. Where specific retention schedules are adopted, TrailSpark will update this Policy or provide notice in the Service.
Customers may instruct deletion of Customer Data consistent with their agreements and applicable law.
Security
We employ administrative, technical, and organizational measures appropriate to the risk, including:
- Role-based access controls (RBAC) and least-privilege access.
- Encrypted transport and storage for end-user personal data we handle.
- CSRF protections in the web application and secure, authenticated API endpoints.
- PII minimization for AI models, as noted above.
No system is perfectly secure; we continually work to improve our safeguards.
Your privacy rights
Your rights depend on where you live.
GDPR/UK GDPR (EEA/UK)
If applicable to you, you may have the right to access, correct, delete, restrict or object to certain processing, and port your personal data. You may also have the right to lodge a complaint with a supervisory authority.
California (CPRA)
California residents may have rights to know/access, correct, and delete personal information, and to opt out of sale or sharing for cross-context behavioral advertising. TrailSpark does not sell or share personal information for cross-context behavioral advertising. We do not use sensitive personal information for purposes requiring a right to limit under CPRA.
Other U.S. states
Residents of certain U.S. states may have similar rights. We will respond to rights requests as required by applicable law.
Exercising your rights
To exercise rights or submit a request, contact privacy@trailspark.ai. We may take reasonable steps to verify your identity before responding. We will respond within timeframes required by applicable law.
For Customer end users, please direct your request to the relevant Customer (your organization); we will assist the Customer upon their request as a processor.
Law enforcement & safety disclosures
We may disclose personal data if we believe it is reasonably necessary to: (i) comply with applicable law, regulation, legal process, or governmental request; (ii) protect the security or integrity of the Service; (iii) protect TrailSpark, our Customers, or the public from harm or illegal activities; or (iv) respond to an emergency. Where legally permitted, we will attempt to notify the relevant Customer before disclosing Customer Data.
Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated Policy with a new "Last updated" date. For material changes, we may also provide additional notice (e.g., in-app notice or email to account administrators).
Contact
If you have questions or requests about this Policy or our practices, contact us at privacy@trailspark.ai.
