Updated 28 September 2026 · version public-2026-09-28
Privacy notice
Who is responsible
CommonSpark is operated by IT Finesse. IT Finesse is responsible for the personal information described in this notice. For privacy questions or requests, contact [email protected].
Information we use
We process your account email, password hash, birth date, consent history, profile details, interests and reactions, photos, videos, audio and memories, likes and connections, conversation messages and read state, meeting readiness and venue proposals. We also process blocks, reports, moderation decisions, session identifiers, network and browser information, security records and service diagnostics.
Optional profile details can reveal sensitive information, including ethnicity, religion, relationship preferences and exercise habits. Only provide information you want to include in your profile. You can edit or remove optional details.
Why it is used
We use account, profile and conversation information to provide the service you request: an adult account, shared-interest discovery, messaging and optional meetup planning. We use security and safety records to prevent abuse, moderate media, investigate reports and protect members, and service diagnostics to maintain and improve the app. We process information where needed to meet legal obligations.
Our basis for using information
We use information needed to create your account and deliver the features you request to perform our agreement with you. Our interests in preventing fraud, protecting members and keeping the service reliable support necessary security, moderation and diagnostic processing. Where a specific law requires us to retain or disclose information, we use it to meet that obligation. Optional website analytics and Meta measurement depend on your separate consent and are not a condition of using the app.
Location and external providers
Your hometown is part of your profile. If you grant location permission, the app can use precise device coordinates for nearby places and meetup planning. Device location permission is optional and can be withdrawn in your browser or device settings. Location features do not publish your live coordinates to other members.
Location searches and coordinates are sent to Photon/Komoot and OpenStreetMap-based Overpass services, currently maps.mail.ru and overpass-api.de, to return places. Map tiles load from OpenStreetMap, which receives your network address and the map area requested. These providers can process requests outside the UK. Hosting and email services also process information needed to operate your account. Optional Meta measurement is described separately below. Hosting, email and location providers receive the information needed for their part of the service, not access to every part of your account. International processing may occur; contact us for details about a provider or the safeguards applicable to your information.
Privacy controls
Discovery is on by default, but a profile appears only after it has at least three interests and an approved main photo. You can switch discovery off at any time. Exact birth dates, emails, and internal account identifiers are never public.
Optional website analytics
With your permission, Google Analytics uses cookies to measure visits throughout the website and signed-in app, plus successful email-verified registrations. Google Tag Manager loads these tags only after you accept analytics. This works independently of the Meta advertising choice. We send fixed page names, recognised campaign labels and the website origin of supported social or search referrals. Other query values, click identifiers and referrer paths are excluded from Google Analytics. Member, conversation and verification pages use fixed page labels without names, record identifiers, confirmation codes or message content. Advertising features and automatic form, search, link and video tracking are disabled.
Choose Reject optional to use the site without analytics. Privacy choices lets you withdraw consent and remove our analytics cookies at any time. Your choice is stored on this browser for up to 180 days. Google processes analytics data under its privacy policy; event data is retained for two months in our Analytics property.
Optional public-page performance
The same analytics choice also enables Cloudflare Web Analytics on our home and About pages to measure visits and loading performance. Its beacon receives public-page and referral information, browser performance measurements and network requests, without analytics cookies. We exclude private pages and unrecognised URL parameters, and check our internal-traffic exclusion before loading it. See Cloudflare’s Privacy Policy. Rejecting or withdrawing analytics prevents further Cloudflare measurement. Previously saved analytics permission must be renewed before this additional provider can load.
Optional masked session recordings
If you accept analytics, Microsoft Clarity records clicks, scrolling and masked session replays throughout the website and signed-in app, including profiles and chats. Personal text, form entries and images are masked before upload. Clarity receives interaction, device and network information and uses first-party cookies. Page URLs can contain opaque profile or conversation references, recognised campaign labels and Meta click identifiers; these are not emails or authentication credentials. Documents containing verification challenges, reset tokens or unrecognised URL parameters are excluded from replay. Google still counts those visits using a fixed, sanitised page label.
After successful email confirmation, a neutral completion page sends a verified-registration event to Clarity and Google Analytics. This can join your earlier consented session and does not depend on accepting Meta measurement. We do not send emails, names, message content or custom account identifiers to these services. Clarity advertising consent remains denied. The broader recording scope requires a new analytics choice from visitors whose previous permission covered public pages only; previous refusals remain respected.
Microsoft processes this information to provide website analytics. See the Microsoft Privacy Statement for its handling of this data. Reject optional prevents Google Analytics, Cloudflare and Clarity from loading. Withdrawing consent stops collection and clears their first-party cookies in this browser; it does not delete measurements already received.
Optional Meta signup measurement
This is a separate, optional choice in Privacy choices. If you opt in, after the server confirms your email we send Meta one completed-registration event. Meta receives the event time, a random event identifier, the neutral completion-page URL, any retained Meta ad-click identifier, cookie identifiers, and browser and network information (including your IP address). Meta can match these to its services to attribute signups and help optimise Facebook and Instagram advertising. This does not guarantee more signups. No email, name, birth date, account ID, profile fields, interests or messages are included in our event.
The Meta pixel runs only on the short completion page, never in signup or verification forms, profiles or messages. Automatic event detection and advanced matching are off. We retain an ad-click identifier in this tab for up to seven days after opt-in; the completion marker is used once and expires after five minutes. Meta may set first-party cookies, including _fbp and _fbc. Meta handles received information under its Privacy Policy and Business Tools Terms.
Both optional choices are off until selected and can be changed independently using the Privacy choices button on our About page. Reject optional or untick Meta signup measurement in Privacy choices to prevent future events and remove its first-party cookies from this browser. We honour browser Global Privacy Control for this purpose. Withdrawal does not erase events already received by Meta; contact us or use Meta's privacy controls for those requests. Your browser choices expire after 180 days. You can sign up and use CommonSpark without either optional choice.
Activity and discovery
Signed-in visits record your last visit and a history of visits, with a new visit after 30 minutes of inactivity. This history does not include visited URLs, IP addresses or device identifiers. Administrators can review activity to operate the service. Other members can see a broad Today or Recently label, not your precise visit times. Visit history is retained for the configured number of calendar months (six by default); last-visit and total-visit summaries remain while your account is active.
Discovery uses your profile choices, shared interests and filters to help people find common ground. It does not guarantee compatibility or a relationship. Uploaded media is processed and screened for safety, with moderation and reporting controls. Contact us if you want a moderation decision reviewed.
Storage and deletion
Account and profile information is retained while your account is active. Media is stored outside the public web root and served after an authorisation check. Closing an account removes its profile and interests, revokes sessions, anonymises its email and birth date, deletes its password hash and queues uploaded files for deletion. Conversations are closed. Restricted conversation, consent, report and audit records may remain to investigate abuse, resolve disputes and meet legal obligations.
Rejected photos are removed from profiles immediately. Authorised moderators can review them for 30 days after rejection, after which access expires and the deletion worker removes the stored file.
Retention of restricted records depends on the purpose, whether a report or dispute remains unresolved, and any applicable legal preservation requirement. You can ask us to erase remaining information; we will explain any reason that prevents deletion. Account and data deletion instructions are available without signing in.
Who can see your information
Other members see the profile and content you make available through the app, subject to discovery, visibility and blocking controls. Recipients can see messages you send. Authorised administrators and moderators can access information needed to support the service and investigate reports. We may disclose information where legally required or necessary to handle a safety incident. We do not publish your exact birth date or email.
Your rights
You can request access, correction, deletion or a copy of your information, and ask us to restrict or object to its use where these rights apply. Contact [email protected]. We may verify your identity before acting. You can also raise a concern with the UK Information Commissioner’s Office.
You may object to processing based on our legitimate interests. You may withdraw optional consent at any time, without affecting the lawfulness of earlier processing. You can also complain to your local data protection authority, including in Ireland or another EU country where you live or work. Rights and exceptions depend on the applicable law.
Adults only
CommonSpark is for adults aged 18 and over, including friendship and chat features. Report a suspected underage account in the app or contact us. See our community and child safety standards.