Sparkboard Privacy Policy

Version: 1.0 Effective date: 5 September 2026 Applies to: the Sparkboard hackathon platform at sparkboard.com and the event sites hosted on it ("Sparkboard", "the Platform"). It does not cover other products or prototypes operated under the Sparkboard name, which carry their own notices.


1. Who we are

Sparkboard is operated by Matthew Huebert, a sole proprietor established in Berlin, Germany:

Matthew Huebert (Sparkboard) Erich-Weinert-Str. 11 10439 Berlin, Germany VAT ID: DE303517320

Contact for all data protection matters: privacy@sparkboard.com. Matthew Huebert is the person responsible for data protection at Sparkboard, including in the role the Singapore Personal Data Protection Act 2012 ("PDPA") requires an organisation to designate.

The incorporation of Sparkboard Sàrl (Geneva, Switzerland) has been agreed and is in progress. Upon incorporation, operation of the Platform and the commitments in this policy will transfer to the company, and this policy will be updated with its registered details. Under both the EU General Data Protection Regulation ("GDPR") and the PDPA, a natural person carrying on a business can act as a data controller or data processor; the absence of a company does not reduce our obligations to you, and nothing in this policy depends on the incorporation being complete.

The legal notice required under German law is at sparkboard.com/imprint.

2. How Sparkboard is used, and who is responsible for your data

Sparkboard is a multi-tenant platform: each hackathon or event runs on its own "board", created and administered by an event organizer (for example, a university, foundation, or company). Your account and profile on Sparkboard exist per board: signing up for two events creates two separate participant records.

Because of this structure, responsibility for your personal data is split:

If you have a question or request about your data on a specific event board, you can direct it either to that event's organizer or to us; we forward requests to the responsible party and assist the organizer in answering them.

3. Personal data we collect

Account and profile data (provided by you at sign-up and in your profile):

Content you create on the Platform:

Website contact form: if you request a Sparkboard through the form at sparkboard.com, we receive the name, email address, organisation and message you enter. The form sends them to us by email so we can reply; we keep that correspondence in our mailboxes for as long as the conversation is relevant, and do not add you to any list.

Notifications and email: we generate in-app notifications and, depending on your email preferences, send digest emails to your email address containing recent activity relevant to you (new messages, posts, comments, team members). Every such email contains an unsubscribe link.

Technical data:

We do not knowingly collect special categories of data (health, religion, political opinions, etc.). Free-text fields (profiles, projects, messages) are under your control; please do not put sensitive information in them.

4. Purposes and legal bases

Where Sparkboard processes data as processor for an event organizer, the legal basis is determined by that organizer (commonly: your consent given at registration, or the organizer's legitimate interest or performance of its arrangement with you). The organizer's own notice applies.

Where Sparkboard processes data as controller, we rely on:

Purpose GDPR legal basis PDPA basis
Creating and operating your account; providing the Platform's features (projects, teams, messaging, notifications) Performance of a contract, Art. 6(1)(b) Consent given at sign-up; purposes notified at or before collection
Sending notification digest emails at your chosen frequency Performance of a contract, Art. 6(1)(b); you can switch these off at any time Consent; withdrawal honoured via unsubscribe
Security, abuse and fraud prevention (including IP logging on public votes), service diagnostics and error reporting Legitimate interests, Art. 6(1)(f): keeping the service secure and working Legitimate interests exception; purposes a reasonable person would consider appropriate in the circumstances
Aggregate, cookieless web analytics (not collected for EU visitors) Legitimate interests, Art. 6(1)(f): understanding overall usage Purposes a reasonable person would consider appropriate
Answering a request sent through the website form Steps at your request prior to a contract, Art. 6(1)(b) Consent given by sending the form
Newsletter (only if you opt in; off by default) Consent, Art. 6(1)(a) Consent

You can withdraw any consent at any time (see Section 9); this does not affect processing already carried out.

5. Sharing and subprocessors

We do not sell personal data. We share it only with (a) the event organizer of each board you join, who is the controller for that board; organizers can view and export participant lists for their own event, including participant email addresses, for event administration; (b) other users, to the extent you make information visible on the Platform (your profile and projects are visible to other participants of your board; some boards make project pages publicly visible, which your organizer's settings control); and (c) the service providers ("subprocessors") below, who process data on our behalf under their standard data processing terms:

Provider Role Data involved Location
Salesforce, Inc. (Heroku) Application hosting All platform data in transit through the application United States
MongoDB, Inc. (Atlas) Primary database Accounts, profiles, projects, messages, votes, notifications United States (AWS us-east-1)
Google LLC (Firebase Authentication, Realtime Database, Firestore, Cloud Storage; App Engine; Cloud Pub/Sub) Sign-in, board settings, invitations, file and image storage and serving, internal events Identity data (name, email, photo), uploaded files, board configuration United States (us-central1)
Mailgun Technologies, Inc. Email delivery Name, email address, notification content United States
Functional Software, Inc. (Sentry) Error reporting Technical error context; may include IP address and user-agent United States
SolarWinds (Papertrail) Application log aggregation Server logs; may include IP addresses and request paths United States
Cloudflare, Inc. DNS, CDN, cookieless web analytics Traffic metadata (IP addresses); aggregate page-view statistics Global network
Algolia, Inc. Legacy search index. The Platform no longer queries it; the index is being decommissioned. Names and profile/project text indexed before September 2026 United States (US-East)
Filestack (legacy Filepicker.io) Historic image hosting for images uploaded before the move to Firebase Storage Legacy profile and project images United States
Slack Technologies Optional per-project chat channels, only on boards where the organizer enables the Slack integration Name and email as needed to join the workspace Only for boards that use it

Some features are served by a companion Sparkboard service hosted in Heroku's European region; it receives only a signed, short-lived token identifying your account and board. Some pages load JavaScript libraries from Google's static-content CDN, which technically receives your IP address when your browser fetches the files.

We will update this table when providers change. Organizers acting as controllers are informed of subprocessor changes as described in our processing arrangement with them.

6. International transfers

Sparkboard's primary data stores are located in the United States: the application (Heroku), the MongoDB Atlas database (AWS us-east-1), the Firebase project (us-central1), and email delivery via Mailgun.

7. Retention

8. Security

We take measures appropriate to the nature of the data, including: TLS encryption in transit; encryption at rest and certified security programmes (ISO 27001, SOC 2) at the cloud providers that hold the data (Google Cloud, Salesforce/Heroku, MongoDB Atlas); password storage using bcrypt hashing; role-based access (organizer and admin functions separated from participant functions); production access restricted to the operator, with multi-factor authentication on provider accounts; and daily database backups managed by the database provider. No internet service can guarantee absolute security. Direct messages are stored in the database in readable form and are accessible to the operator for support and legal compliance, so treat them as private but not confidential.

If a data breach occurs that is likely to result in a risk to you, we will notify the competent authorities and affected controllers and users as required: under the GDPR within 72 hours of becoming aware (Art. 33), and under the PDPA by notifying the Personal Data Protection Commission as soon as practicable and no later than 3 calendar days after assessing that a breach is notifiable, and by assisting the responsible event organizer with its own notification duties.

9. Your rights

Under the GDPR (if you are in the EU/EEA; equivalent rights apply under Swiss and UK law), you have the right to: access your data; rectify inaccurate data; erasure ("right to be forgotten"); restriction of processing; data portability; object to processing based on legitimate interests; withdraw consent at any time; and lodge a complaint with a supervisory authority. The authority responsible for Sparkboard is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit, datenschutz-berlin.de); you may also complain to the authority of your own country of residence.

Under the PDPA (if your data was collected in Singapore), you have the right to: request access to your personal data and information about how it has been used or disclosed within the past year; request correction of errors or omissions; and withdraw consent (which we will action within a reasonable time, after informing you of the likely consequences). Complaints may be made to the Personal Data Protection Commission of Singapore (pdpc.gov.sg).

How to exercise your rights:

We may need to verify your identity (normally by corresponding via the email address on the account) before acting on a request.

10. Children

Sparkboard is not directed at children under 13, and accounts require the user to be old enough to consent to data processing in their country (16 in Germany and most EU member states unless the event organizer has obtained parental consent; 13 in Singapore, where the PDPC recognises that minors aged 13 or older may typically give valid consent). Events aimed at younger participants are the responsibility of the organizer, who must ensure appropriate consent is in place.

11. Cookies and local storage

Sparkboard uses no advertising cookies and no analytics cookies, and therefore shows no cookie banner. What is stored in your browser:

You can delete cookies in your browser at any time; doing so signs you out.

12. Changes to this policy

We may update this policy from time to time, for example upon incorporation of Sparkboard Sàrl or when subprocessors change. The current version is always available at sparkboard.com/privacy, with its effective date at the top. For material changes we will provide notice on the Platform or by email.


Previous version: the policy hosted at iubenda (policy 7930385), last updated 27 February 2023, which this policy replaces.