Privacy Policy
What we collect, why we collect it, who else can see it, and how to get it deleted.
Last updated: 11 September 2026
This policy explains how GHL Spark(“we”, “us”) handles personal data. It covers ghlspark.com, the strategy calls and forms on it, the snapshots and workflow packs we sell, and the client work we do inside GoHighLevel and Google Ads. We are a small team and we do not sell data to anyone, ever.
1. Who we are
GHL Spark builds GoHighLevel SaaS setups for agencies. We are the data controller for the data described in this policy. You can reach us at [email protected] or by phone on +1 240-759-2915. For anything privacy-related, email is the fastest route and reaches the people who actually hold the data.
When we work inside a client’s own GoHighLevel or Google Ads account, the client is the controller of the data in that account and we act as a processor on their instructions.
2. What we collect
We collect four kinds of data, and no more than we need for each.
- What you send us. Your name, email address, phone number, company and whatever you type into a booking form or a message. This is data you choose to give us in order to start a conversation.
- Purchase data. If you buy a snapshot or a workflow pack, we receive your billing name, email and the fact of the purchase. Card details go to our payment processor and never reach our servers.
- Usage data. Pages viewed, approximate location from your IP address, referring site, browser and device type. This is aggregate and we use it to work out which pages are worth keeping.
- Client account data. When you engage us, the access you grant to your GoHighLevel sub-accounts, Google Ads accounts or connected services, and the data visible inside them while we do the work.
We do not ask for and do not want special-category data — health, biometrics, political opinions and the like. Please do not send it.
3. Why we use it, and our legal basis
- To answer you and run the call you booked. Basis: steps taken at your request before entering a contract.
- To deliver the work you have paid for, including building inside your accounts. Basis: performance of our contract with you.
- To take payment and keep the records tax law requires us to keep. Basis: contract, and legal obligation.
- To improve the site and understand which content is useful. Basis: our legitimate interest in running a business people can find.
- To send you things you asked for. Basis: your consent, which you can withdraw at any time.
We do not use your data to train machine learning models, and we do not build advertising profiles of you.
5. Google user data
Where a client connects a Google account to us, our application requests access through Google OAuth so that we can work on advertising accounts on their behalf. This section describes exactly what that access means.
- What we access. Read and, where the client has asked us to manage campaigns, write access to the Google Ads accounts the client selects. Campaign, ad group, keyword, budget and performance data within those accounts.
- Why. To report on performance, research keywords, and make the campaign changes the client has engaged us to make. Nothing else.
- How we store it.OAuth tokens are held in encrypted configuration on access-controlled machines, never in the browser and never in any public repository. We store the minimum account data needed to do the work, and we prefer reading live from Google’s API over keeping our own copy.
- Who we share it with. Nobody. Google user data is not passed to any third party, is not sold, and is not used for advertising.
- How to revoke. Disconnect us at any time from your Google Account permissions page, or email us and we will revoke our own access and confirm when it is done.
6. Limited Use commitment
Google API Services User Data Policy
GHL Spark’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms: we use Google user data only to provide the service the client asked for, we do not transfer it except as needed for that service or where required by law, we do not use it for advertising, and we do not let humans read it except with the client’s explicit permission, for security purposes, to comply with law, or on data that has been aggregated and anonymised.
8. Where it lives, and how long we keep it
We work with clients worldwide, so data may be processed outside your country, including in the United States. Where data leaves the UK or EEA we rely on the standard contractual clauses or an equivalent safeguard.
- Enquiries that never became clients: deleted within 24 months.
- Client records: kept for the engagement and 6 years after, which is what tax and accounting rules require.
- Access tokens and credentials: revoked and deleted at the end of the engagement, or immediately on request.
- Analytics: retained in aggregate only.
9. Your rights, including deletion
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to it entirely. You can withdraw consent at any time, and you can ask for your data in a portable format.
How to have your data deleted
Email [email protected] with the subject line “Data deletion request”. We will confirm receipt within 3 business days and complete the deletion within 30 days, then write to tell you it is done.
If your request covers Google user data, we revoke our OAuth access and delete any stored tokens and derived records as part of the same request. You can also revoke our access yourself at any time from your Google Account permissions page.
We do not charge for this and we will not ask you why. If you think we have handled your data badly, you are entitled to complain to your national data protection authority — though we would rather you told us first so we can fix it.
10. Security
The site is served over HTTPS. Credentials and access tokens are held in encrypted configuration, never committed to source control, and scoped to the narrowest permission that does the job. Access to client accounts is limited to the team members working on that engagement.
No system is perfectly secure. If a breach affects your data we will tell you and the relevant regulator within the timeframes the law sets.
11. Children
This is a business-to-business service and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, email us and we will delete it.
12. Changes to this policy
If we change this policy we will update the date at the top of this page. Where a change materially affects how we use data you have already given us, we will tell you directly rather than relying on you to re-read the page.
13. Contact
Privacy questions, access requests and deletion requests all go to [email protected]. For anything else, the contact page lists every way to reach us. Our terms of service govern the commercial side of the relationship.