How Spark & Spool handles site and Part Rescue information.

First-party measurements explain which pages and contact paths help visitors. Part Rescue information is separately collected only to review technical suitability, acknowledge the request, and manage the resulting business decision.

Name, company, business email, the part or problem, what the part does, and a rights/terms acknowledgment are required. Phone, approximate quantity, needed-by date, preferred response, and one private upload are optional. The version and time of the acknowledgment are retained with the inquiry. This information is not used for automated suitability decisions.

One JPG/JPEG, PNG, PDF, STL, STEP/STP, or OBJ file up to exactly 15,000,000 bytes may be stored in a private Spark-owned R2 boundary. It has no public object URL, is downloaded only through protected owner review, and is treated as untrusted. Engineering files receive bounded structural validation only; they are not rendered, executed, extracted, converted, or used to fetch referenced resources. Archives and every unlisted format are rejected.

Turnstile, same-origin and CSRF checks, a honeypot, limits, and short-lived HMAC source digests protect the form. Application code does not store raw IP addresses, full user agents, Turnstile tokens, or fingerprints.

Spark-owned D1 records track inquiry, upload, submission, notification, conversion, owner review, qualification, acknowledgment, transfer, rate-window, and deletion states. Inquiry contents, files, and contact details do not enter Signal Machine, DSWR, general analytics state, Google Ads, model prompts, public logs, or public proof.

A fixed owner notification may be attempted only after durable acceptance. Customers receive no automatic email. Sergey manually acknowledges the request and records that state after the external effect is observed.

Allowlisted UTM values, the canonical landing route, referring host only, and timestamps may be retained with the inquiry. First-party diagnostics and one deduplicated accepted-submit event contain no inquiry text or contact details.

Rate/invalid-attempt digests: 7 days. Unconverted inquiry metadata: 180 days. Unconverted uploads: 90 days. Failed staged uploads: reconciled after 15 minutes. Owner access: 7 days or earlier. Preview/test state: end of session or within 7 days.

After verified transfer, normal owner business-record policy applies and redundant Part Rescue state is deleted within 30 days. Content-free deletion evidence is retained for 400 days. Owner-requested deletion uses the same journaled private-object and D1 path.

No sale of data, advertising profile, cross-site identity, remarketing, customer-list upload, call recording or forwarding, enhanced conversion, customer auto-email, automatic quote/order/production, or automatic AI interpretation of submissions or files. Inquiry content is not sent to Google.

Google Ads conversion measurement is inactive unless real account identifiers and the separate runtime enable flag are approved and enabled. This page does not claim an advertising tag is active.

Allowlisted page views, meaningful email/telephone clicks, and 30-minute site sessions are measured without inquiry content, email addresses, or retained IP hashes. Raw events, sessions, and weekly browser digests are retained for 35 days; final daily and weekly aggregates are retained for 400 days.

Cloudflare separately provides aggregate visits, page views, performance information, Turnstile verification, and the bound application infrastructure. Cloudflare performance data is not used in the site’s first-party weekly reporting. Substantive customer communication remains human-reviewed and human-sent.

Estimated weekly unique browsers is an estimate of participating browsers, not people. Multiple devices or browsers, private windows, and cleared storage can increase the count; shared browsers can reduce it. A site-specific first-party random identifier is stored locally only for the current Eastern reporting week, rotates when the week changes, and is immediately converted server-side to a site-and-week-specific digest. The raw identifier is not retained server-side.