SparkyCert
Legal

Privacy Policy

Last updated: 5 August 2026

Overview

SparkyCert ("we", "our") is a trading name of Taylored Electrical Group Pty Ltd (ABN 49 689 808 633), based in New South Wales, Australia. This policy explains what information we collect, how we use it, and how we protect it. It covers both the SparkyCert mobile app and the SparkyCert web dashboard at sparkycert.com.au. By using either, you agree to this policy.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We built SparkyCert for NSW licensed electricians. Protecting your professional data — and your clients' data — is fundamental to what we do.

What we collect

Account information. Your email address and name, provided when you create your account via Clerk authentication. We use this to identify your account only.

Licence details. Your supervisor licence number and expiry date, entered during onboarding. This is used to pre-fill your certificates and is never shared with third parties outside of CCEW submission.

Certificate data. The contents of CCEWs you lodge — installation address, customer details, work type, equipment, and meter information. This data is transmitted to the NSW eCert system as required by law and stored in your account history. It also includes your own job or purchase-order reference, which is kept for your records and is never sent to Building Commission NSW.

Tester details. Where the testing was done by someone other than you, the certificate records that person's name, licence number, contact details and address, because Building Commission NSW requires them. If that person is not you, the same responsibility applies as for customer details below — see "Information about other people you enter".

Business and team information. If you run or join a business account, we store the business name, who is on the team, each person's role and seat status, and the email addresses you send invitations to.

Billing details you give us. If you enter them on the dashboard, we store the business name, ABN and billing address you want shown on your tax invoices, plus the invoices themselves. We store these because a tax invoice has to record who the purchase was for.

Technical diagnostics. When something goes wrong we record an error report containing the error message, the screen it happened on, the app or browser version, and the IP address the report was sent from. IP addresses are used only to investigate faults and abuse of the service, are not used to build a profile of you, and are not combined with your certificate data.

Push notification tokens. If you turn on notifications in the mobile app, we store the anonymous device token needed to send them — for example to tell a licence holder that a certificate is waiting for their sign-off. Delivery goes through Expo and, on Android, Google's Firebase Cloud Messaging. A token identifies a device installation, not you personally, and is deleted with your account.

Anonymous usage analytics. To understand how the app is used and improve it, we collect: app open counts, submission success/failure rates, device type, app version, and subscription tier. This analytics data is fully anonymous — it carries no identifier that could tie it back to you, and we never collect certificate content, customer details, your name, email, licence number, or location data through analytics. Because it is anonymous and used only by us (never linked with outside data or shared with a data broker), it is not used to track you across other companies’ apps or websites.

Subscription data. Where you bought your subscription decides who processes the payment: the Apple App Store on iPhone, Google Play on Android, or our web checkout (run by RevenueCat, with card processing by Stripe) on the dashboard. In every case we receive your subscription status (e.g. active, trialling, cancelled) and the identifiers needed to match it to your account — we never see, store or process payment card details.

Early-access list. If you enter your email address in the sign-up form on our website, we store that address so we can tell you when SparkyCert launches. Alongside it we keep a record of your consent — the date, the fact that it came from the website form, and the IP address it was submitted from — because Australian anti-spam law requires us to be able to show that you asked to hear from us. That IP is kept only as evidence of the sign-up; it is never read by any feature and is deleted with the record.

Every announcement we send carries an unsubscribe link, and you can use it at any time without signing in — see "Your rights" below. Joining this list is not the same as having an account, and the address is used for nothing else: no advertising, no profiling, and it is never given to anyone.

What we never collect

  • Credit card or banking details (handled by Apple, Google Play, or Stripe)
  • Location or GPS data
  • Contacts or phone book access
  • Photos or camera access beyond what you explicitly upload
  • Certificate content through analytics
  • Customer or client personal information through analytics

How we use your data

Certificate data is used solely to submit CCEWs to the NSW eCert system and to maintain your history within the app.

Anonymous analytics are used to understand which features are working and where users encounter problems, so we can improve the app.

We do not sell, share, or rent your data to any third party for marketing purposes.

Information about other people you enter

When you prepare a certificate, you enter details about your customer — such as their name, the installation address, and contact details — and you may attach site photos. Where the testing was done by another electrician you also enter that person's name, licence number, contact details and address. If you invite people onto a team, you give us their email addresses. All of this is personal information about someone other than you.

We handle that information on your behalf, only to lodge the certificate with the NSW eCert system and to keep it in your account history. We do not use your customers' details for our own marketing and never sell them.

You are responsible for having those people's agreement to provide their details and any photos to SparkyCert for this purpose — whether you are the licensed electrician or the office staff member typing it up. If one of them asks you to correct or remove their information, contact us at support@sparkycert.com.au and we will help.

Third-party services

SparkyCert uses the following third-party services:

  • Clerk — authentication and account management. clerk.com/privacy
  • Apple App Store — in-app purchase processing. Apple's privacy policy applies to all payment transactions. apple.com/legal/privacy
  • Google Play — in-app purchase processing on Android. Google's privacy policy applies to those transactions. policies.google.com/privacy
  • RevenueCat — subscription entitlement management, and the checkout used when you subscribe on the web dashboard. RevenueCat receives your store subscriber ID, your SparkyCert account identifier and your subscription status on our behalf. revenuecat.com/privacy
  • Stripe — processes card payments made through the web dashboard checkout, on RevenueCat's platform. Stripe receives your card and billing details directly; we never see them. stripe.com/au/privacy
  • NSW eCert API — the Building Commission NSW system that receives CCEW lodgements. Data sent to eCert is governed by NSW government privacy obligations.
  • Neon — the PostgreSQL database that stores your account, certificate history, and saved customers. Hosted in Sydney, Australia. neon.tech/privacy-policy
  • Railway — hosts the SparkyCert application server that processes your lodgements. Located in Singapore. railway.com/legal/privacy
  • Sentry — crash and error reporting. Sentry receives anonymised diagnostic information (stack traces, device type, app version). No personal data or certificate content is included.
  • Expo and Google Firebase Cloud Messaging — deliver push notifications to the mobile app (for example, that a certificate is waiting for your sign-off). They receive the device token and the notification text, which names the event but not certificate contents. Firebase is used on Android only. expo.dev/privacy
  • Resend — delivers every email the app sends (certificate confirmations, certificate copies, team invites). These emails can contain certificate and customer details. resend.com/legal/privacy-policy
  • Cloudflare R2 — stores certificate PDFs and site photos you attach to a lodgement. Files are private and only ever served via a temporary, signed link. cloudflare.com/privacypolicy
  • Vercel Analytics — collects anonymised page-view and interaction data on this website (sparkycert.com.au) to understand traffic and which pages and buttons are actually used. No account or certificate data is included. vercel.com/legal/privacy-policy

Data retention

Your certificate history and profile are retained while your account is active. You can delete your account in the app under Profile → Data & Privacy → Delete My Data, or on the web dashboard under Profile → Delete my account. All stored data — including profile, certificates, saved customers and push tokens — is permanently deleted from our servers within 30 days. If you have no account, or cannot sign in, you can request deletion from our support page.

Certificates already submitted to eCert are held by the NSW government under their own retention requirements and are not affected by deleting your SparkyCert account.

Security

All data is transmitted over HTTPS. Account credentials are managed by Clerk with industry-standard encryption. We do not store passwords.

Your rights under Australian Privacy Law

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to access, correct, or request deletion of your personal information. You can:

  • Update your profile details in the app or on the web dashboard at any time
  • Delete your account and all data — in the app under Profile → Data & Privacy, or on the web dashboard under Profile → Delete my account
  • Unsubscribe from our announcement emails using the link in any of them, or at sparkycert.com.au/unsubscribe — no account or sign-in needed. This is separate from your account: certificate confirmations, invoices and team invites are sent because of something you did and keep arriving.
  • Contact us at support@sparkycert.com.au with any access, correction, or complaint request

If you are not satisfied with our response to a privacy complaint, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Cross-border disclosure

Some of the service providers we use store or process data outside Australia. Under Australian Privacy Principle 8, we tell you where that is:

  • United States — Clerk (accounts), RevenueCat (subscriptions and web checkout), Stripe (card processing for web purchases), Apple and Google (app store purchases), Expo and Google Firebase (push notifications), Sentry (crash reporting), Resend (email delivery), and Vercel (this website and its analytics).
  • Singapore — Railway, which hosts the SparkyCert application server that processes your certificate data.
  • Global network — Cloudflare R2, which stores certificate PDFs and any site photos you attach.
  • Australia — our main database (Neon) is hosted in Sydney, so your account and certificate records are stored in Australia.

By using SparkyCert you consent to these transfers, which are made under appropriate safeguards consistent with the Australian Privacy Principles.

Changes to this policy

We may update this policy from time to time. Significant changes will be notified in-app. Continued use of SparkyCert after changes constitutes acceptance of the updated policy.

Contact

For privacy questions or requests: support@sparkycert.com.au

SparkyCert is a trading name of Taylored Electrical Group Pty Ltd, ABN 49 689 808 633, New South Wales, Australia.