This Privacy Policy explains how Sparrow Local Technologies Inc., doing business as Sparrow (“Sparrow,” “we,” “us,” or “our”), collects, uses, discloses, stores, and protects personal information when you use sparrowlocal.com and our related websites, applications, portals, communications, tools, and services (collectively, the “Platform”).
This Policy is intended to support compliance with Alberta’s Personal Information Protection Act (“PIPA”), the federal Personal Information Protection and Electronic Documents Act (“PIPEDA”) where applicable, Canada’s Anti-Spam Legislation (“CASL”), and other applicable privacy laws.
1. ACCOUNTABILITY AND PRIVACY CONTACT
Sparrow is responsible for personal information under its control.
Our Privacy Officer is:
Founder & Privacy Officer
Sparrow Local Technologies Inc.
Unit 2510, 90 Arbour Lake Hill NW
Calgary, Alberta, Canada
Email: privacy@sparrowlocal.com
Questions, access requests, correction requests, withdrawal-of-consent requests, complaints, and privacy concerns may be directed to the Privacy Officer.
2. SCOPE
This Policy applies to personal information handled by Sparrow through the Platform, customer and Service Provider onboarding, support, pilot participation, business operations, marketing, analytics, and related interactions.
This Policy does not govern:
- (a) personal information independently collected or controlled by a Service Provider outside Sparrow;
- (b) third-party websites, applications, or services that have their own privacy policies; or
- (c) employee personal information, which may be governed by a separate internal policy.
Service Providers may independently be responsible for personal information they collect through or outside the Platform. They must comply with applicable privacy laws and use information obtained through Sparrow only for legitimate service-related purposes.
3. PERSONAL INFORMATION WE COLLECT
Depending on how you use Sparrow, we may collect the following categories.
3.1 Account and identity information
- Name
- Email address
- Telephone number
- Login and authentication information
- Account role and permissions
- Email-confirmation status
- Profile photo
- Communication preferences
- Account status and activity
We do not store your plain-text password.
3.2 Customer and household information
- Customer profile details
- Household or organization members
- Saved businesses
- Service preferences
- Service history
- Reviews and feedback
- Support requests
- Information you choose to provide about pets, accessibility, household needs, or service preferences
Do not provide sensitive information unless it is reasonably necessary for the service.
3.3 Property and service-location information
- Street address, unit, city, province, and postal code
- Property or location type
- Parking information
- Access and entry instructions
- Gate, buzzer, concierge, or building information
- Preparation instructions
- Relevant hazards, pets, or restrictions
- Photos, files, measurements, or notes
- Service-location history
Access instructions are treated as sensitive operational information and should be visible only to authorized users who reasonably need them for the relevant service.
3.4 Service requests and transaction information
- Requested service
- Intake-question responses
- Preferred dates and times
- Scope, specifications, and notes
- Estimates, revisions, approvals, and declines
- Bookings, appointments, jobs, sessions, projects, and milestones
- Assigned personnel
- Checklists and completion details
- Before-and-after photos
- Materials, expenses, time entries, and change orders
- Invoices, taxes, deposits, balances, receipts, refunds, and payment status
- Transaction source, such as Sparrow marketplace, returning customer, referral, or business-created customer
- Reviews, ratings, business responses, and reports
3.5 Business and professional information
- Legal and public business names
- Owner and contact information
- Business address and service areas
- Website and social links
- Business structure and years operating
- Service descriptions, pricing, availability, policies, and media
- Team members, job titles, roles, permissions, skills, schedules, and assignments
- Business licence or registration details
- Trade or professional credentials
- Insurance information and expiry dates
- Verification claims, documents, statuses, and review history
- Tax settings
- Connected payment-account status
- Payout status and payment-provider identifiers
- Support and administrative notes
Private verification documents are not intended to be displayed publicly.
3.6 Communications and content
- In-app messages
- Attachments and photos
- Internal business notes
- Customer-visible notes
- Email and notification records
- Support communications
- Surveys, interviews, and pilot feedback
- Product suggestions and bug reports
Private internal notes should not be disclosed to customers unless required by law or intentionally converted into customer-visible content.
3.7 Payment information
If online payments are enabled, payment processing may be provided by a third party such as Stripe.
Sparrow may receive:
- Payment-provider customer and account identifiers
- Connected-account identifiers and status
- Payment amount, currency, taxes, fees, and net amount
- Payment, refund, dispute, transfer, and payout status
- Limited card information such as brand and last four digits
- Billing contact information
- Fraud or risk indicators made available by the provider
Sparrow does not intend to collect or store full card numbers, bank login credentials, or complete banking details. Those are handled by the payment provider.
3.8 Device, technical, and usage information
- IP address
- Browser, device, operating system, and language
- Login, session, and security events
- Pages, buttons, and features used
- Referral URL
- Date, time, and approximate location derived from IP address
- Error logs, crash information, and performance data
- Cookie and similar-technology identifiers
3.9 Marketing and consent information
- Newsletter or promotional preferences
- Source and date of consent
- Unsubscribe requests
- Campaign engagement where lawfully enabled
- Waitlist, referral, or event participation
3.10 Information from third parties
We may receive information from:
- Service Providers or customers involved in the same service relationship
- Team members and organization administrators
- Authentication, hosting, storage, email, analytics, and payment providers
- Public business registries or professional sources
- Referral partners
- Fraud-prevention and security services
- Other sources with your consent or as permitted by law
4. HOW WE COLLECT INFORMATION
We collect personal information:
- (a) directly from you;
- (b) from another authorized user, such as a household member, business owner, manager, or customer;
- (c) automatically through your use of the Platform;
- (d) from service providers that support Platform operations;
- (e) through public or professional sources used for verification; and
- (f) as otherwise permitted or required by law.
5. PURPOSES FOR COLLECTION, USE, AND DISCLOSURE
We may collect, use, or disclose personal information for reasonable purposes including:
5.1 Providing the Platform
- Create, verify, secure, and manage accounts
- Authenticate users
- Provide role-based access
- Onboard and review businesses
- Publish approved business profiles
- Match customers with relevant businesses
- Process requests, messages, estimates, bookings, jobs, projects, invoices, payments, receipts, and reviews
- Support recurring services and rebooking
- Provide dashboards, reports, workflows, and business tools
5.2 Enabling service relationships
- Share request details with businesses selected by or responding to the customer
- Share necessary customer, location, scheduling, and access information with authorized business users
- Enable communications and file sharing
- Document agreements, approvals, changes, completion, payments, and disputes
- Maintain service and property history
5.3 Trust, safety, verification, and fraud prevention
- Review applications and verification claims
- Confirm eligibility and account authority
- Detect unauthorized access, abuse, fraud, spam, manipulation, and security incidents
- Enforce Platform rules
- Investigate disputes and reports
- Maintain audit logs
- Protect users, Sparrow, and the public
5.4 Payments and financial operations
- Facilitate and reconcile payments
- Calculate disclosed Platform fees
- Record external payments
- Process refunds and disputes
- Support connected-business payouts
- Prevent duplicate or fraudulent transactions
- Produce invoices, receipts, and financial reports
- Meet accounting, tax, and legal obligations
5.5 Communications
- Send account, security, confirmation, support, service-request, estimate, booking, payment, review, policy, and administrative communications
- Respond to questions and support requests
- Send marketing communications where permitted by law
- Maintain records of consent and unsubscribe requests
5.6 Improving Sparrow
- Monitor performance and reliability
- Diagnose errors
- Understand feature usage
- Conduct product research
- Improve design, workflows, safety, support, and accessibility
- Develop new features
- Use aggregated or de-identified information for analysis
5.7 Legal and corporate purposes
- Comply with law, court orders, regulatory obligations, and lawful requests
- Establish, exercise, or defend legal claims
- Complete audits, financing, insurance, due diligence, corporate reorganization, merger, acquisition, or sale
- Protect Sparrow’s legal rights and intellectual property
We will not use personal information for a materially different purpose without additional notice or consent where required.
6. CONSENT AND CHOICES
6.1 Meaningful consent. We seek consent in a form appropriate to the sensitivity of the information and the reasonable expectations of the individual.
6.2 Essential processing. Some information is necessary to create an account, provide requested features, secure the Platform, complete transactions, or comply with law. If you do not provide it, the relevant feature may be unavailable.
6.3 Optional information. Optional fields should be identified where practical. You may choose not to provide them.
6.4 Withdrawal. You may withdraw consent to optional collection, use, or disclosure by contacting privacy@sparrowlocal.com, subject to legal or contractual restrictions and reasonable notice. We will explain material consequences of withdrawal.
6.5 Marketing. You may unsubscribe from marketing communications using the unsubscribe mechanism or by contacting us. You may still receive transactional or legally required communications.
6.6 Notifications. You may manage certain notification preferences in your account. Security, legal, payment, and essential service notices may not be optional.
7. WHEN WE DISCLOSE INFORMATION
We may disclose personal information as follows.
7.1 Between customers and Service Providers
We disclose information reasonably required to request, quote, schedule, deliver, document, invoice, pay for, review, support, or resolve a service.
The amount disclosed depends on the stage of the transaction, the user’s role, and the need for the information.
7.2 Within a business or household
Organization owners and authorized managers may access information associated with their organization. Assigned workers may receive only the information reasonably needed for their role and assignments. Authorized household or organization members may access shared records according to their permissions.
7.3 Public profiles and reviews
Approved public business information may include:
- Public business name
- Logo and cover image
- Business description
- Categories and services
- Service areas
- Public policies and pricing language
- Years operating
- Public contact methods
- Approved gallery images
- Trust or verification labels
- Verified-service reviews and business responses
We do not intend to publicly display private addresses, payment-account identifiers, private verification documents, internal notes, or sensitive access instructions.
7.4 Service providers
We may use service providers for:
- Application development and hosting
- Databases, authentication, and file storage
- Domain and content delivery
- Transactional email and communications
- Analytics and error monitoring
- Customer support
- Payment processing
- Security, fraud prevention, and verification
- Legal, accounting, insurance, and professional services
Current or expected providers may include:
- Lovable — application platform, hosting, deployment, and managed transactional email delivery
- Supabase — database, authentication, and file storage
- Stripe, if payments are enabled
- Managed transactional email delivery through Lovable, sent from the notify.sparrowlocal.com sending domain
- No third-party analytics provider is currently enabled
- Platform error and performance monitoring provided through Lovable
- No other material service providers are currently engaged. This list will be updated before any new material provider is introduced
Service providers may process information only for authorized purposes and are subject to contractual, technical, or legal safeguards.
7.5 Legal, safety, and enforcement
We may disclose information where we reasonably believe it is necessary to:
- Comply with law, a warrant, subpoena, court order, or lawful government request
- Protect life, health, safety, property, or security
- Investigate fraud, abuse, threats, or illegal conduct
- Enforce agreements
- Establish, exercise, or defend legal claims
- Report suspected offences or professional misconduct where permitted or required
7.6 Business transactions
Information may be disclosed in connection with financing, insurance, due diligence, reorganization, merger, acquisition, sale, insolvency, or transfer of some or all of Sparrow’s business, subject to confidentiality and applicable law.
7.7 With consent
We may disclose information for another purpose with your consent.
8. CROSS-BORDER PROCESSING
Sparrow is based in Alberta, Canada, but service providers may process or store personal information in Canada, the United States, or other jurisdictions.
Information processed outside Canada may be subject to the laws of the foreign jurisdiction and may be accessible to courts, law enforcement, or national-security authorities in that jurisdiction.
Sparrow will use reasonable contractual, organizational, and technical safeguards appropriate to the sensitivity of the information.
Contact privacy@sparrowlocal.com for information about material service providers or jurisdictions, subject to legal and security limitations.
9. RETENTION
We retain personal information only as long as reasonably necessary for identified purposes, including to:
- Operate accounts and service relationships
- Preserve transaction and service history
- Support warranties, disputes, and reviews
- Meet legal, tax, accounting, insurance, and regulatory obligations
- Prevent fraud and abuse
- Maintain security and audit records
- Enforce agreements
- Resolve complaints
- Maintain backups and disaster recovery
Retention periods vary by record type.
Examples:
- Active account information: while the account is active and for a reasonable period afterward
- Estimates, invoices, payments, receipts, and tax records: for the period required by applicable tax and accounting laws
- Messages and service records: for the service relationship and a reasonable dispute, safety, and business-record period
- Verification documents: while required for verification and for a limited audit or dispute period
- Security and access logs: for a limited security and investigation period
- Marketing consent records: as needed to prove consent or honour unsubscribe requests
- Backups: until overwritten under backup schedules
We may de-identify information and retain it in a form that is not reasonably capable of identifying an individual.
Account closure does not always require immediate deletion of every record. Where deletion is not possible or appropriate, access will be restricted and information retained only for lawful purposes.
10. SECURITY
Sparrow uses administrative, technical, and physical safeguards appropriate to the sensitivity of the information, which may include:
- Role-based access controls
- Row-level database security
- Multi-tenant separation
- Authentication and email confirmation
- Encryption in transit
- Secure hosting and storage
- Private storage for verification documents
- Signed or time-limited file access
- Audit logs
- Input validation
- Security scanning
- Backups and recovery processes
- Restricted administrative access
- Incident monitoring and response
No system is completely secure. Users are responsible for protecting their credentials, using secure devices, and promptly reporting suspected unauthorized access.
11. PRIVACY BREACHES
Sparrow will investigate suspected privacy and security breaches and take reasonable containment, remediation, documentation, and notification steps.
Where required by Alberta PIPA, PIPEDA, or other applicable law, Sparrow will notify the appropriate privacy regulator and affected individuals where a breach creates the legally applicable risk threshold.
12. ACCESS AND CORRECTION
Subject to legal exceptions, you may request:
- Access to personal information Sparrow holds about you
- Information about how it has been used or disclosed
- Correction of inaccurate or incomplete information
Submit requests to privacy@sparrowlocal.com.
We may verify your identity before responding. We will respond within the period required by applicable law and may charge only a fee permitted by law.
Some information may not be provided where disclosure would reveal another person’s information, confidential commercial information, privileged information, security information, or information that law permits or requires us to withhold.
You may also update many account details directly in the Platform.
13. DELETION AND ACCOUNT CLOSURE
You may request account closure or deletion by emailing privacy@sparrowlocal.com or using the in-app Support page or by emailing privacy@sparrowlocal.com.
We will delete, anonymize, or restrict information where reasonably possible, subject to legal, security, dispute, transaction, tax, accounting, backup, and legitimate business-record requirements.
Closing a business account may not remove records from customers’ legitimate transaction histories.
14. COOKIES AND SIMILAR TECHNOLOGIES
Sparrow may use cookies, local storage, pixels, SDKs, and similar technologies for:
- Authentication and session management
- Security and fraud prevention
- Preferences
- Platform functionality
- Performance and error monitoring
- Analytics
- Marketing, only where lawfully enabled
Essential technologies are required for the Platform to function.
Before enabling non-essential analytics, advertising, or cross-site tracking, Sparrow should implement any notice and consent controls required by applicable law.
Browser settings may allow you to block some technologies, but doing so may impair Platform functions.
Technologies currently in use on the Platform:
- Authentication session storage (browser local storage) — essential. Keeps you signed in and stores your access token. Set by our authentication provider.
- Invitation and sign-in continuation values (browser session storage) — essential. Temporarily remembers an invitation code or the page you were heading to. Cleared when the tab closes.
- Interface preference cookie (sidebar_state) — functional. Remembers whether the navigation sidebar is expanded or collapsed.
- Portal personalization values (browser local storage) — functional. Remembers display preferences you choose for your portal home page.
No advertising pixels, cross-site trackers, third-party analytics tags, or marketing SDKs are enabled on the Platform. If any non-essential technology is introduced, this Policy will be updated and any legally required consent controls will be implemented first.
15. ANALYTICS AND DE-IDENTIFIED INFORMATION
Sparrow may create aggregated or de-identified information that does not reasonably identify an individual and use it to:
- Measure Platform activity
- Improve features
- Understand marketplace health
- Produce business or pilot reporting
- Conduct research
- Support planning and investment
Sparrow will not attempt to re-identify de-identified information except for security testing or as permitted by law.
16. ARTIFICIAL INTELLIGENCE AND AUTOMATION
Sparrow may introduce optional AI-assisted features such as summarizing requests, drafting communications, identifying missing information, suggesting next steps, or explaining reports.
Before such features process personal information, Sparrow will:
- Provide appropriate notice
- Limit information used to what is reasonably necessary
- Apply role and access controls
- Require human review for consequential actions where appropriate
- Avoid allowing AI to autonomously move money, issue refunds, suspend users, set binding prices, or send sensitive communications unless clearly configured and legally permitted
- Identify material third-party AI providers in this Policy or a related notice
Users must review AI-generated content for accuracy and suitability. Do not submit highly sensitive information to AI features unless expressly requested and protected for that purpose.
17. CHILDREN
The Platform is not directed to children under 18 for independent commercial use.
We do not knowingly allow a person under 18 to create an independent business or transaction account. A parent or legal guardian may manage a household account and submit information reasonably necessary for family services.
Contact privacy@sparrowlocal.com if you believe a minor has provided personal information without appropriate authorization.
18. COMMERCIAL ELECTRONIC MESSAGES
Where CASL applies, Sparrow will:
- Obtain express or implied consent as required
- Identify Sparrow and provide required contact information
- Include a functioning unsubscribe mechanism
- Process unsubscribe requests within the legally required period
- Maintain records of consent and unsubscribe requests
Transactional messages relating to an account, security, request, estimate, booking, invoice, payment, or existing service relationship may be sent where permitted by law.
19. THIRD-PARTY LINKS AND SERVICES
The Platform may link to third-party websites or services. Their privacy practices are governed by their own policies. Review them before providing personal information.
20. CHANGES TO THIS POLICY
Sparrow may update this Policy to reflect legal, operational, technical, or product changes.
We will post the revised Policy and update the “Last updated” date. We will provide additional notice or obtain consent where required for material changes.
21. COMPLAINTS
Contact the Privacy Officer first so we can investigate and respond.
You may also have the right to contact:
Office of the Information and Privacy Commissioner of Alberta
or
Office of the Privacy Commissioner of Canada
depending on the law and circumstances that apply.
22. CONTACT
Privacy Officer
Sparrow Local Technologies Inc.
Doing business as Sparrow
Unit 2510, 90 Arbour Lake Hill NW
Calgary, Alberta, Canada
Email: privacy@sparrowlocal.com
Support: support@sparrowlocal.com
Website: https://sparrowlocal.com
