Privacy Policy
Last updated: January 1, 2026
This Privacy Policy describes how SparkDBI ("SparkDBI," "we," "us," or "our") collects, uses, shares, and protects information in connection with our B2B and healthcare (HCP) contact data products, data licensing, data enrichment, email appending, and email marketing services (collectively, the "Services"), and when you visit our website. This Policy applies to business contact information we hold about you as a business professional, and to information collected from visitors to our website.
SparkDBI does not collect, process, or sell sensitive personal information such as Social Security numbers, financial account or payment card numbers, government identification numbers, health records, or biometric data. Our data products are limited to professional business contact and firmographic information.
1. Information We Collect
We compile and maintain business contact information from a range of vetted, compliant sources, including:
- Public sources, including regulatory registries such as the CMS NPPES NPI Registry and state professional licensing boards;
- Licensed, first-party data contributors and vetted third-party data partners;
- Professional associations, conference and event attendee lists (where opt-in was obtained), and company websites;
- Information you or your organization submit directly to us, such as through our website contact form, a sample data request, or an order form;
- Website usage information collected automatically, such as IP address, browser type, and pages visited, described further in Section 4 below.
The categories of business contact information we typically collect and license include: name, business email address, direct dial and mobile phone numbers, job title and seniority, employer and firmographic details (industry, company size, revenue range), technographic details (software and platforms in use), and, for healthcare providers, NPI number, medical specialty, licensing status, and practice or hospital affiliation. We do not collect or include patient data, protected health information (PHI), or clinical records in any of our data products.
2. How We Use Information
We use business contact information to build, verify, and license our data products, and to provide the Services, including:
- Compiling, verifying, and licensing B2B and healthcare contact datasets to our customers for marketing, sales, and research purposes;
- Validating active inbox, employment, and identity signals to maintain data accuracy;
- Operating managed email marketing campaigns on behalf of our customers, using appropriate suppression and compliance controls;
- Responding to inquiries, sample requests, and support requests submitted through our website;
- Complying with legal obligations, and detecting, investigating, and preventing fraudulent or unauthorized use of our Services.
3. How We Share Information
We license and deliver business contact data to customers who have agreed to our Terms and Conditions and any applicable order form governing their permitted use of the data. We do not sell or share Social Security numbers, financial information, or other sensitive personal information. We may share information with:
- Customers licensing our data products, subject to the usage restrictions in our Terms and Conditions;
- Service providers who perform functions on our behalf, such as email verification, hosting, and analytics, under confidentiality obligations;
- Regulators, law enforcement, or other parties when required by law or to protect our legal rights.
4. Cookies and Website Analytics
Our website uses cookies and similar technologies to operate core functionality, remember your preferences, and understand aggregate visitor behavior so we can improve our site. Most browsers let you refuse or delete cookies; doing so may make some parts of our website slower or less convenient to use. Where required by law, we present a cookie consent banner allowing you to accept or manage non-essential cookies before they are set.
5. Data Security
We maintain administrative, technical, and physical safeguards designed to protect business contact information against unauthorized access, alteration, or disclosure, consistent with our SOC 2 Type II-aligned controls. These include access limited to authorized personnel, encryption in transit, vendor due diligence for service providers who process data on our behalf, and ongoing monitoring of our systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Data Retention
We retain business contact information for as long as reasonably necessary to provide the Services, comply with legal obligations, and maintain the accuracy of our data products through periodic refresh and re-verification. Records that fail verification, are subject to a valid deletion or suppression request, or are no longer needed for these purposes are removed from active use.
7. International Data Transfers and Compliance
SparkDBI provides data and Services across North America, Europe, APAC, and other regions, and structures its sourcing and delivery practices to align with applicable regional frameworks, including GDPR (European Union and UK), CCPA (California), CASL (Canada), DPDP (India), and LGPD (Brazil). Where we transfer personal information across borders, we use appropriate safeguards consistent with the applicable law.
8. Your Rights
Depending on your location, you may have rights to access, correct, delete, or restrict the use of your business contact information, and to opt out of having your information included in our data products or used for marketing outreach. To make a request, contact us at [email protected] or through our Contact Us page. California residents can find additional detail on their rights under the CCPA in Section 9 below, and can submit an opt-out request directly through our Do Not Sell My Personal Information page. Individuals who wish to stop receiving telemarketing or email outreach sourced from SparkDBI data can refer to our Do Not Call Compliance Policy.
9. California Privacy Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act ("CCPA") gives you the right to: (a) know the categories and specific pieces of personal information we have collected about you and the categories of sources, purposes, and third parties involved; (b) request deletion of personal information we have collected, subject to certain exceptions such as completing a transaction, detecting security incidents, or complying with a legal obligation; (c) opt out of the "sale" or "sharing" of your personal information, as those terms are defined under California law; and (d) not be discriminated against for exercising these rights.
To submit a verifiable request to know, delete, or opt out, please use our Do Not Sell My Personal Information page or email [email protected]. We will confirm receipt of your request and respond within the timeframes required by law. We may need to verify your identity, or the identity of an authorized agent acting on your behalf, before completing your request.
10. Children's Privacy
Our Services are intended for business use by adults and are not directed to individuals under 18. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date.
12. Contact Us
If you have questions about this Privacy Policy or how we handle your information, please contact us at [email protected], or write to us at 447 Broadway, New York, NY 10013, USA.