← Notaspark

Privacy Policy

Last updated: 11 August 2026

Notaspark manages Google Business Profiles for restaurant clients. This policy covers two separate kinds of data: data accessed through the Google Business Profile API on behalf of a client, and data recorded when a customer taps one of our NFC cards. They are described separately below because they involve different people and different obligations.

1. Google user data

How access is granted

Notaspark accesses a restaurant’s Google Business Profile only after the owner grants Notaspark manager-level access through Google’s standard user management. Notaspark never asks for a client’s Google password and never signs in as the client. Access exists only for profiles an owner has explicitly added Notaspark to.

Who decides: the restaurant is the controller

For data accessed through the Google Business Profile API, the restaurant is the controller and Notaspark is the operator. The data belongs to the restaurant’s profile, the restaurant decides that Notaspark may process it, and Notaspark acts on the restaurant’s instruction and only within the access the restaurant granted — access it can revoke at any time. Notaspark does not process this data for its own purposes.

Tap data from NFC cards works the other way around: there, Notaspark is the controller. That is described in Part 2.

What is accessed, and why

Reviews
Review text, ratings, and dates for the client’s managed locations. Used to consolidate reviews in one place and to reply to them.
Location details
Business name, address, hours, and category for each managed location. Used to keep listings accurate and to attribute reviews to the correct restaurant.
Performance metrics
Google’s profile performance data for the managed locations. Used to produce the owner’s monthly report.

Notaspark requests only the access needed to provide these functions, and uses the data only to deliver the service to the restaurant the data belongs to.

Human review of replies

Notaspark may draft a reply to a review, but a person writes or approves every reply before it is posted to Google. No reply is published automatically, and no content is posted to a client’s profile without human approval.

How it is stored

Data retrieved from the Google Business Profile API is transmitted over encrypted connections and stored on access-controlled infrastructure. Notaspark is operated by one person, who is the only individual with access to client data. No one else holds credentials for it. When a client revokes access, their data is deleted within 30 days, except where a record must be kept to meet a legal obligation.

Never sold, never shared

Notaspark does not sell Google user data, does not share it with third parties, and does not use it for advertising, for training machine learning models, or for any purpose other than providing this service to the client whose profile it came from. Data from one client is never combined with, or disclosed to, another client.

Notaspark’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

How a client revokes access

A client can remove Notaspark’s access at any time, without asking Notaspark first, from their own Google Business Profile settings: open the profile’s user management, find Notaspark, and remove it as a manager. Revocation takes effect immediately and ends Notaspark’s ability to read the profile or post to it.

On revocation, or on written request to [email protected], Notaspark deletes the client data it holds, except where a record must be kept to meet a legal obligation.

2. NFC card tap data

Notaspark places NFC cards on restaurant tables. Tapping a card opens a short link on notaspark.com, which immediately forwards the customer to that restaurant’s own Google review page. The purpose of recording a tap is to tell the restaurant how often its cards are being used.

What a tap records

What a tap does not record

Notaspark does not know who tapped a card. Tap data is reported to the restaurant only in aggregate. It is never sold and never shared with third parties.

This website itself sets no cookies and loads no analytics, advertising, or other third-party scripts.

How long tap data is kept

Raw tap records are kept for 90 days. After 90 days they are aggregated into daily per-card counts and the raw records are deleted. The aggregated counts carry no timestamp beyond the day, no location, no language, and no hashed IP address, and cannot be traced back to an individual tap.

Brazilian data protection (LGPD)

Notaspark’s client locations include restaurants in Brazil, so tap data is handled in line with the Lei Geral de Proteção de Dados (Law No. 13.709/2018). For tap data Notaspark is the controller (controlador): Notaspark decides what a tap records and why, and the restaurant has no say in it. This is the opposite of the arrangement in Part 1, where the restaurant is the controller of its own Business Profile data and Notaspark is the operator (operador). The contact point for data protection matters is [email protected].

The legal basis for this processing is the legitimate interest of the restaurant and of Notaspark in measuring how often the cards are used (Art. 7, IX). Processing is limited to what that purpose requires: the fields listed above, and nothing that identifies an individual by name. Raw records are deleted after 90 days, as described above.

Notaspark is operated from the United States, and tap data may be processed on infrastructure located outside Brazil, including in the United States.

Under the LGPD you may ask Notaspark to confirm whether your data is being processed, to give you access to it, to correct it, to anonymise, block, or delete data that is unnecessary or excessive, to tell you who your data has been shared with, and to delete it. Send any such request to [email protected].

Tap data is anonymized to the point that a record cannot be tied to an individual. Notaspark therefore cannot locate or delete the taps belonging to one person, because it has no way to tell which records those are. All raw tap records are deleted after 90 days regardless of whether anyone asks.

3. Changes and contact

If this policy changes, the “last updated” date at the top of this page will change with it, and the current version will always be published here.

Questions about this policy, requests about your data, and enquiries from Google’s review team can all be sent to [email protected].