Privacy Policy

Last updated: September 10, 2026

1. What this covers

This policy applies to SparkHours, available at sparkhours.com. SparkHours is a clinical hour tracking tool for pre-licensed therapists working toward licensure in California. We built this policy in plain language so you know exactly what happens with your data.

2. What we collect

We collect only what we need to provide the service.

Account information

Your name, email address, and password. Passwords are hashed with bcrypt before storage. We never store your password in plain text.

Training profile

Graduation status and date, graduate program or school, associate registration numbers and issue dates, and your chosen qualification tracks (AMFT, APCC, ASW).

Sites and supervisors

Names, addresses, phone numbers, email addresses, and license information (state, type, number) for your work sites and supervisors.

Hours and rollups

Dates, durations, category types, and status of your logged clinical hours. Rollups group hours by week, site, and supervisor.

Electronic signatures

When your supervisor signs a rollup, we store their signer information and a signed PDF of the weekly log.

Technical and advertising conversion data

IP address, browser user agent, a session cookie to keep you logged in, and a 30-day first-party origin cookie. The origin cookie stores the first marketing page path and query, which can include a voucher code or Google Ads click identifier.

3. What we don't collect

  • No client or patient data. SparkHours tracks your training hours, not your clients. We never collect protected health information (PHI).
  • No payment information stored. Payment processing is handled entirely by Stripe. We do not store your card details. We only store a Stripe customer identifier to manage your subscription.
  • No analytics or tracking scripts. We do not use Google Analytics, Facebook Pixel, or third-party tracking scripts. If you arrive through a Google ad and create an account, we may send Google Ads a server-side conversion using the click identifier from your origin and a hashed email address.
  • No third-party cookies. Our cookies are first-party session, CSRF, and origin cookies.

4. How we use your data

We use your data to provide SparkHours. That means:

  • Logging and organizing your clinical training hours
  • Generating weekly rollups grouped by site, supervisor, and week
  • Sending signature requests to your supervisors via email
  • Generating BBS-compliant PDF forms (37A-525, 37A-638)
  • Calculating your dashboard progress, weekly pace, and projected completion
  • Checking supervision ratios and sending you compliance notifications
  • Measuring Google Ads registrations when a marketing origin includes a Google Ads click identifier

5. Who sees your data

Your supervisors see only the rollups you submit to them. They access these through time-limited signed URLs sent via email. They do not have access to your full account or other supervisors' rollups.

Service providers help us run SparkHours. This includes hosting infrastructure, email delivery, and Google Ads conversion measurement. Google Ads receives a server-side registration conversion only when the origin includes its click identifier; that conversion includes the click identifier and a hashed email address.

We do not sell your data. We do not provide it to data brokers or use it to train AI models.

Legal obligations: We may disclose your data if required by law, such as a valid court order or subpoena. If this happens, we will notify you unless legally prohibited from doing so.

6. Track Your Hours import

SparkHours offers a one-time import from Track Your Hours. If you use this feature, your Track Your Hours credentials are sent directly to their servers to retrieve your data. We do not store your Track Your Hours username or password. The credentials are used only during the import request and are discarded immediately.

7. Security

We protect your data with the following measures:

  • TLS/HTTPS: All data in transit is encrypted
  • Bcrypt password hashing: Passwords are never stored in plain text
  • Time-limited signed URLs: Supervisor signature links expire and cannot be guessed or reused
  • Database access controls: Production database access is restricted to the application
  • CSRF protection: All form submissions are protected against cross-site request forgery

8. Data retention

We keep your data for as long as your account is active. Signed rollups are retained as official BBS documentation for your licensure records. If you delete your account, all data is permanently removed (see Account deletion below).

9. Account deletion

You can delete your account from your profile settings at any time. Deletion is permanent and immediate. It cascades to all your entries, rollups, signatures, sites, supervisors, and profile data. We do not retain backups of deleted accounts. We recommend exporting your signed rollups as PDFs before deleting your account.

10. Cookies

SparkHours sets first-party session and CSRF cookies for the application to function. It also sets a first-party origin cookie for 30 days after your first marketing visit. The origin cookie contains that page's path and query, which can include a voucher code or Google Ads click identifier, so your offer and advertising conversion can be attributed when you register. We do not set third-party cookies.

11. Your rights

You have the right to:

  • Access your data at any time through your account
  • Update your profile, sites, supervisors, and entries
  • Export your signed rollups as PDFs for your records
  • Delete your account and all associated data permanently

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA). Contact us at [email protected] to exercise these rights.

12. Children

SparkHours is designed for pre-licensed therapists who are at least 18 years old. We do not knowingly collect data from anyone under 18. If we learn that we have, we will delete it promptly.

13. Breach notification

If we discover a data breach that affects your personal information, we will notify you by email within 72 hours of confirming the breach. Our notification will describe what happened, what data was affected, and what steps we are taking to address it.

14. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and notify you by email. For non-material changes (clarifications, formatting), we will update the date without email notification.

15. Contact

If you have questions about this privacy policy or how we handle your data, email us at [email protected].