Legal

Privacy Policy

Last updated: June 17, 2026  ·  Effective: June 17, 2026

Governed by the Individual Privacy Act, 2075 (2018) of Nepal and applicable international best practice.

1. Controller Identity and Contact Information

This Privacy Policy is issued by Black Snow, a company registered and operating under the laws of Nepal, with its principal place of business in Kathmandu, Nepal (website: www.blacksnow.com.np). Black Snow operates the digital platform Sparkd Social, accessible at sparkd.social(the “Platform”).

For the purposes of Nepal’s Individual Privacy Act, 2075 (2018) (“IPA 2075”) and comparable international frameworks, Black Snow is the data controller in respect of all personal information processed through the Platform.

Company: Black Snow

Platform: Sparkd Social (sparkd.social)

Address: Kathmandu, Nepal

Privacy contact: hello@sparkd.social

Response time: We aim to respond to all privacy enquiries within 5 Nepali business days.

2. Scope of This Policy

This policy applies to all personal information collected by Black Snow when you:

  • Visit or browse sparkd.social in any capacity
  • Register and maintain a user account on the Platform
  • Create, publish, or manage events as a Host
  • RSVP to, attend, or review events as a Guest
  • Submit a host verification application
  • Contact us by email or through any platform feature
  • Sign in with a third-party identity provider (Google OAuth)

This policy does not apply to third-party websites linked from the Platform. We encourage you to review the privacy policies of any third-party sites you visit.

3. Personal Information We Collect

We collect personal information in the following categories. For each category we identify the legal basis under the IPA 2075 and the practical reason for collection.

3.1 Account Registration Data

What: Full name, username, email address, date of birth, and (optionally at signup, required before creating a paid event) phone number. If you register via Google OAuth, we also receive your Google profile name and Google-linked email address.

Why: To create and maintain your account; to identify you within the Platform; to send transactional communications (booking confirmations, one-time passcodes, event reminders).

Legal basis (IPA 2075): Performance of a contract (your use of the Platform) and your explicit consent at the time of registration.

Is it mandatory? Yes for email, full name, username, and date of birth. Without these fields you cannot create an account. Phone number becomes mandatory only when you create your first paid event, because it is required for payment-related communications.

3.2 Date of Birth — Age Verification

Your date of birth is collected at signup and is permanently retained as a core platform safety measure. The Platform is strictly 18 years and older. We verify your age server-sideat every RSVP request, not only at account creation. Individual events may set a higher minimum age (e.g., 21 for age-restricted venues); the server checks your date of birth against the event’s configured minimum at RSVP time.

Date of birth is never displayed publicly. It is used only for age-gate enforcement and is accessible only to authorised administrative personnel.

Legal basis:Compliance with a legal obligation (Nepal’s Age of Majority and Minority Act; Children’s Act, 2075) and legitimate interest in preventing access by minors to adult-content venues.

3.3 Profile Photo

You may upload a profile photo. If you register via Google OAuth, your Google profile picture is imported as your default avatar. Profile photos are stored in a Cloudflare R2 bucket and served via a CDN. Your profile photo is visible to all users of the Platform.

Legal basis: Your explicit consent at the time of upload or OAuth authorisation.

3.4 Geolocation and Location History

When you first visit the Platform, your browser may prompt you to share your approximate location (city/district level). This requires your explicit browser permission. We use this to show you relevant nearby events.

We store your location data in a database table called user_location_history. Each entry records an approximate location associated with a visit or session.

Important Disclosure — Location History Retention

Even if you request deletion of your location history (for example, by deleting your account or submitting a data erasure request), location history records are soft-deleted only. This means the records are flagged as deleted and hidden from all user-facing features, but they are not permanently erased from our database. Administrators retain access to all location history records for the purposes of legal compliance, fraud prevention, and safety investigations. We disclose this limitation because we believe you deserve full transparency about how your data is handled. If you object to this retention, you may withdraw your location consent at any time in your browser settings — this stops future collection but does not remove existing records.

Legal basis: Your explicit consent (browser permission prompt). You may withdraw consent at any time via your browser settings.

Retention: Location entries are retained for a rolling 12-month period for active records. Soft-deleted records are retained indefinitely for administrative and legal purposes.

3.5 Event Content

When you create an event, you provide: event title, description (rich text), cover photo, event category, public neighbourhood/area, exact address and coordinates, date and time, ticket pricing, capacity, and any custom questions for guests. The exact address and coordinates are stored with heightened access controls (see Section 4 on location privacy). Event cover photos are stored in a Cloudflare R2 bucket.

Legal basis: Performance of your host contract with the Platform.

3.6 RSVP and Attendance Records

When you RSVP to an event, we record: the event ID, your user ID, RSVP status (pending / confirmed / cancelled), RSVP timestamp, your booking reference code (format: SPK-YYYY-XXXXXX), and check-in status. If payment was required, we record the payment reference and amount paid.

Legal basis: Performance of contract (the RSVP and ticketing transaction).

3.7 Payment Proof and Financial Records

For paid events using the manual QR payment method, guests upload a screenshot or photo of their payment confirmation. These payment proof images are stored in a private Cloudflare R2 bucket and are accessible only via time-limited signed URLs. They are never publicly accessible. Payment proof images are accessible only to the host of the event and Platform administrators.

We record transaction metadata including: amount paid, currency (NPR), payment timestamp, payment method identifier, booking code, and payout status. We do not store raw card numbers or bank account numbers.

Legal basis: Performance of contract; compliance with tax and financial record-keeping obligations.

Retention: Financial records are retained for 7 years from the date of the transaction in compliance with applicable Nepali financial record-keeping requirements.

3.8 Host Identity Verification Documents

To achieve Silver or Gold host verification tier, we require you to submit identity verification documents (e.g., government-issued photo ID). These documents are:

  • Uploaded directly to a private, encrypted Cloudflare R2 bucket
  • Never publicly accessible — served only via short-lived signed URLs to authorised administrators
  • Accessible only to Black Snow employees authorised for host verification review
  • Retained for the lifetime of your host account plus 2 years, to support dispute resolution
  • Destroyed (permanently deleted from storage) within 90 days of account closure, after applicable retention periods have elapsed

Legal basis: Your explicit consent at the time of submission; legitimate interest in preventing fraud and protecting event guests.

3.9 Reviews and Public Content

When you post a review of an event, we store: your user ID, the event ID, your star rating, your written review text, and the timestamp. Reviews are public. If your account is deleted, your reviews are anonymised to display as posted by “[Deleted Account]” — the review content itself remains visible to preserve the integrity of event records.

Legal basis: Your explicit consent at the time of posting; legitimate interest in maintaining reliable event quality records for the community.

3.10 Communications (Q&A, Inquiry Threads, Group Chat)

The Platform has three communication channels:

  • Event Q&A — questions and answers posted publicly on the event page
  • Private Inquiry Threads — direct messages between a guest and a host, visible only to those parties and Platform administrators
  • Event Group Chat — chat between confirmed attendees of an event, visible to all confirmed attendees and Platform administrators

You have no expectation of privacy from Platform administrators in any of these channels. All messages may be reviewed by administrators for safety, legal compliance, dispute resolution, and policy enforcement purposes.

Legal basis: Performance of contract; legitimate interest in maintaining platform safety.

3.11 Technical and Usage Data

We automatically collect certain technical data when you use the Platform, including: IP address (used for rate limiting and fraud detection, not stored long-term), browser type, device type, operating system, referring URL, pages visited, session duration, and error traces captured by our monitoring software (Sentry).

Legal basis: Legitimate interest in maintaining platform security, detecting abuse, and improving reliability.

3.12 Analytics Data (PostHog and Google Analytics 4)

We use PostHog and Google Analytics 4 to understand how users interact with the Platform — which features are used, where users encounter friction, and how traffic flows through the site. Both analytics tools are activated only after you provide explicit cookie consent. If you decline analytics cookies, neither PostHog nor GA4 will be initialised in your browser session. See our Cookie Policy for full details.

Legal basis: Your explicit consent via the cookie consent banner.

4. Event Location — Two-Tier Privacy System

Every event on the Platform operates a two-tier location disclosure system to protect both hosts and the character of private events:

Tier 1 — Public Location (Neighbourhood / Area)

A broad neighbourhood, ward, or area name (e.g., “Thamel, Kathmandu”) is shown to all visitors on the event discovery page. No street address is revealed at this stage.

Tier 2 — Exact Location (Confirmed Guests Only)

The exact street address, building name, and precise coordinates (location_exact_address, location_exact_lat, location_exact_lng) are stored in the database with Row Level Security (RLS) policies that prevent any query from returning these fields unless:

  • The requesting user has a confirmed (paid and verified) RSVP for that specific event, OR
  • The requesting user is the event’s host, OR
  • The requesting user is a Platform administrator

This restriction is enforced at the database layer — it cannot be bypassed by front-end code.

Hosts are instructed not to share the exact location with guests prior to RSVP confirmation. Unauthorised sharing of exact event location data by hosts or guests is a violation of our Terms of Service.

5. How We Share Your Personal Information

We do not sell, rent, or trade your personal information. We share it only as described below:

5.1 With Event Hosts (Limited)

When you RSVP to a host’s event, the host receives: your display name, profile photo, RSVP status, booking reference code, and (if you provided it) your phone number if required by the event. The host does not receive your email address, date of birth, location history, or payment proof images. Hosts are permitted to use your information only for managing their event and communicating with you about it. They may not use it for marketing or any other purpose.

5.2 With Infrastructure and Service Providers

We engage the following sub-processors who may handle your personal data in the course of providing their services to us. Each is bound by a data processing agreement or equivalent contractual obligation:

Supabase Inc.

Purpose: Database (PostgreSQL), authentication, real-time infrastructure

Data location: ap-northeast-1 (Tokyo, Japan)

Privacy policy: https://supabase.com/privacy

Cloudflare Inc.

Purpose: File storage (R2), CDN, DDoS protection

Data location: United States (globally distributed)

Privacy policy: https://www.cloudflare.com/privacypolicy/

Vercel Inc.

Purpose: Serverless hosting and deployment

Data location: United States (globally distributed edge)

Privacy policy: https://vercel.com/legal/privacy-policy

Resend Inc.

Purpose: Transactional email delivery

Data location: United States

Privacy policy: https://resend.com/privacy

PostHog Inc.

Purpose: Product analytics (consent-gated)

Data location: United States

Privacy policy: https://posthog.com/privacy

Google LLC (GA4)

Purpose: Traffic analytics (consent-gated)

Data location: United States

Privacy policy: https://policies.google.com/privacy

Functional Software Inc. (Sentry)

Purpose: Error monitoring and performance tracing

Data location: European Union

Privacy policy: https://sentry.io/privacy/

Upstash Inc.

Purpose: Rate limiting (Redis)

Data location: Singapore

Privacy policy: https://upstash.com/trust/privacy.pdf

5.3 With Law Enforcement and Regulators

We may disclose personal information when required by: (a) a valid court order, subpoena, or government demand under Nepal law; (b) compliance with any applicable statute or regulation; (c) protection of our legal rights; or (d) urgent need to prevent harm or protect public safety. We will notify affected users of any such disclosure where legally permitted to do so.

5.4 Business Transfers

If Black Snow undergoes a merger, acquisition, or sale of assets, your personal information may be transferred to the successor entity. We will notify you by email and via a notice on this page before your data is subject to a different privacy policy.

6. Cross-Border Data Transfers

The Platform is operated from Nepal, but our infrastructure providers are based in or route data through Japan, the United States, the European Union, and Singapore. By using the Platform, you acknowledge that your personal information may be transferred to and processed in these countries, which may have different data protection laws than Nepal.

Specifically:

  • Database (Supabase): Your account data, RSVPs, and event content are stored in the ap-northeast-1 region (Tokyo, Japan). Japan has robust data protection law (Act on the Protection of Personal Information — APPI) and is considered by the European Commission to provide adequate protection.
  • File Storage (Cloudflare R2): Profile photos, event covers, payment proof images, and host verification documents are stored in US-based infrastructure and served via Cloudflare’s global CDN.
  • Hosting (Vercel): Application code executes at Vercel edge nodes globally, including in the United States and Europe.
  • Error monitoring (Sentry): Error traces, which may include session identifiers or user context, are processed in the European Union.
  • Rate limiting (Upstash): IP-level rate limiting data is processed in Singapore.

We rely on contractual safeguards (data processing agreements with each provider) to protect your data in transit and at rest across borders.

7. Data Retention Periods

We retain personal information only for as long as necessary for the purposes set out in this policy or as required by applicable law.

Data TypeRetention Period
Account PII (name, email, DOB)Active account lifetime + 6-month deletion window, then anonymised
Date of birthRetained permanently for age-gate compliance (anonymised on account closure)
Profile photoDeleted from R2 within 30 days of account closure or photo replacement
Location history (active records)Rolling 12 months
Location history (soft-deleted records)Retained indefinitely — admin access only for legal/safety purposes
RSVP and attendance recordsRetained for 3 years after the event date for dispute resolution
Payment records and financial metadata7 years from transaction date (legal requirement)
Payment proof screenshots1 year after event, then permanently deleted
Host verification documentsAccount lifetime + 2 years, then permanently deleted
Event content (completed events)Permanent — for SEO and attendee records; host becomes "[Former Host]" on closure
ReviewsPermanent — anonymised to "[Deleted Account]" on account closure
Messages (Q&A, inquiries, group chat)1 year after the event date, then permanently deleted
Error monitoring (Sentry) traces90 days
Admin audit logsPermanent — immutable by policy and database design
Analytics data (PostHog / GA4)Per the respective provider's retention settings (max 13 months in GA4)

8. Your Rights Under Nepal’s Individual Privacy Act, 2075

Nepal’s Individual Privacy Act, 2075 (2018) recognises your right to control personal information about yourself. You have the following rights in relation to the personal information we hold about you:

8.1 Right of Access

You have the right to request a copy of all personal information we hold about you. To exercise this right, email hello@sparkd.social with the subject “Data Access Request” from the email address registered to your account. We will provide a machine-readable export (JSON or CSV) within 30 days.

8.2 Right of Correction

You may correct inaccurate personal information at any time via your account Settings page. If you need to correct your date of birth (which cannot be changed in Settings for security reasons), contact us with valid ID documentation.

8.3 Right of Deletion (with Important Limitations)

You may request deletion of your account from Settings > Account > Delete Account. When you initiate deletion:

  • Your account enters a 6-month grace period (status: deletion_requested). You may cancel the deletion during this window.
  • After 6 months, your account is moved to archived status: all PII fields (name, email, phone, DOB, photo) are irreversibly anonymised.
  • Reviews you posted become attributed to “[Deleted Account]” — the review text is retained.
  • If you hosted completed events (events with at least one confirmed attendee), those events remain live on the Platform with attribution as “[Former Host]” — they are never deleted, because guests have a legitimate interest in accessing records of events they attended.
  • Financial records (payment transactions) are retained for 7 years regardless of account deletion, as required by Nepali financial law.
  • Location history records are soft-deleted (hidden from all user-facing features) but retained by administrators — see Section 3.4.
  • Admin audit log entries recording actions you took are retained permanently.

8.4 Right to Data Portability

You may request a structured, machine-readable export of your personal data by emailing hello@sparkd.social. The export will include account data, RSVP history, event content (for hosts), and review history.

8.5 Right to Withdraw Consent

Where we process your data based on consent (analytics cookies, location data), you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal. To withdraw analytics consent, clear your browser cookies and decline when the consent banner reappears. To withdraw location consent, revoke the geolocation permission in your browser settings.

8.6 Right to Object to Processing

You may object to processing of your personal information where we rely on legitimate interest as the legal basis. Contact us at hello@sparkd.social to raise an objection. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.

8.7 Marketing Communications

Every marketing email we send includes a one-click unsubscribe link. Transactional emails (booking confirmations, OTP codes, event reminders) are essential to the service and cannot be disabled while your account is active.

9. Data Security Measures

We implement the following technical and organisational security measures in line with Nepal’s National Cybersecurity Policy, 2080 (2023) and industry best practice:

  • Encryption in transit: All data between your browser and our servers is encrypted via TLS 1.2 or higher. All data between our servers and database is encrypted in transit.
  • Encryption at rest: Database storage (Supabase) and file storage (Cloudflare R2) encrypt data at rest using AES-256.
  • Row Level Security (RLS): Every table in our PostgreSQL database has RLS policies. No query can access another user’s data without an explicit policy permitting it. This is a core architectural invariant — no table is accessible without an RLS policy.
  • Secrets management: All API keys, service-role keys, and payment secrets are stored as server-side environment variables. They are never exposed in client-side JavaScript bundles (NEXT_PUBLIC_ variables contain only non-sensitive configuration).
  • Signed URLs for sensitive files: Host verification documents and payment proof images are never publicly accessible. They are served only via short-lived, cryptographically signed URLs generated on-demand for authorised users.
  • XSS prevention: All rich text content (event descriptions) is sanitised with isomorphic-dompurify before storage and before rendering.
  • Rate limiting: All API routes are rate-limited via Upstash Redis to prevent brute-force attacks and abuse.
  • Admin audit log: All administrative actions are recorded in an immutable audit log. No entry can be updated or deleted — enforced at the database layer.
  • Error monitoring: Sentry captures application errors and performance traces. Sentry is configured to minimise capture of personally identifiable information in error payloads.

Despite these measures, no system is completely secure. If you become aware of a security vulnerability or suspected breach involving the Platform, please report it immediately to hello@sparkd.social.

10. Host Data Obligations

When a guest RSVPs to your event, you receive limited personal information about them (see Section 5.1). As a host, you are an independent data controller for the information you receive about your guests. You must:

  • Use guest information only for managing your event and communicating with guests about it
  • Not share guest information with third parties without guest consent
  • Not use guest information for marketing purposes unrelated to the event they RSVP’d to
  • Not retain guest information longer than reasonably necessary for the event
  • Not share the exact event location with guests before their RSVP is confirmed
  • Comply with applicable Nepal law (including IPA 2075) in your handling of guest data

Black Snow is not responsible for hosts’ independent data handling practices. If you have a complaint about how a host handled your data, contact us and we will take appropriate action under our Terms of Service.

11. Children and Minors

The Platform is strictly for persons aged 18 years and over. We do not knowingly collect personal information from anyone under the age of 18. In accordance with Nepal’s Children’s Act, 2075 (2018) and the international principle of child protection, we take the following measures:

  • Date of birth is collected and verified at signup, and server-side at every RSVP
  • Accounts that appear to belong to a person under 18 are immediately suspended pending verification
  • No event may be configured in a way that admits minors to an 18+ event

If you have reason to believe that a person under 18 has created an account on our Platform, please contact us immediately at hello@sparkd.social. We will investigate and remove the account promptly.

12. Google OAuth Sign-In

If you choose to sign in with Google, we receive from Google: your name, email address, and profile photo URL. We do not receive your Google password, payment methods, search history, or any other Google account data. The information received from Google is treated in accordance with this Privacy Policy.

Your use of Google Sign-In is additionally governed by Google’s Privacy Policy at policies.google.com/privacy. You may disconnect Google Sign-In from your account at any time in Settings.

13. Cookies and Similar Technologies

We use cookies and similar browser storage technologies for authentication and (with your consent) analytics. For a complete explanation of every cookie we use, its purpose, and how to control it, please read our Cookie Policy.

14. Complaints and Dispute Resolution

If you have a concern about how we handle your personal information:

  1. Step 1 — Contact us directly: Email hello@sparkd.social with the subject “Privacy Complaint”. We will acknowledge your complaint within 2 Nepali business days and aim to resolve it within 15 days.
  2. Step 2 — Escalate to regulatory authorities: If you are not satisfied with our response, you may file a complaint with the relevant Nepali authority responsible for privacy enforcement under the Individual Privacy Act, 2075. You may also seek remedies through the consumer protection mechanisms available under Nepal’s Consumer Protection Act, 2075 (2018).
  3. Step 3 — Legal proceedings: Nothing in this policy limits your right to bring a legal claim in the courts of Nepal.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the “Last updated” date at the top of this page
  • Send an email notification to all registered users at least 30 days before the changes take effect
  • Display a notice on the Platform for the 30-day notice period

Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree with material changes, you may delete your account before the effective date.

16. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of Nepal, including but not limited to:

  • Individual Privacy Act, 2075 (2018)
  • Electronic Transactions Act, 2063 (2006)
  • Consumer Protection Act, 2075 (2018)
  • Children’s Act, 2075 (2018)
  • National Cybersecurity Policy, 2080 (2023)

Any dispute arising under this policy shall be subject to the exclusive jurisdiction of the competent courts of Kathmandu, Nepal.

We use essential cookies for login and saving your preferences. With your consent, we also use analytics cookies (Google Analytics) to improve the website. Learn more