Privacy policy
First written: 5 July 2026 · Last updated: 10 October 2026
We collect as little as we can, and we tell you exactly what that is.
The short version
- We collect very little: only what you put in an email to us. Our web host sees the basic technical details every website needs to deliver a page, and we never see them.
- No cookies, no analytics, no advertising trackers, no accounts.
- We never sell your data or use it for advertising.
- You can ask to see, correct or delete what we hold at any time.
Who we are
ThinkSpark ("the lab", "we", "us") is an independent research lab based in Glasgow, Scotland. The lab is led by Poatri Uma Senthil, who is responsible for this website and for the personal data described in this policy. Under UK data protection law (the UK GDPR and the Data Protection Act 2018), that makes us the controller of this data.
Contact: hello@jointhinkspark.com. Please put "Privacy" in the subject line.
What this policy covers
This policy covers this website and the emails you exchange with us. Each tool the lab releases, including our flagship Rehumanize, has its own privacy policy, because each one handles different data.
What we collect
When you email us
Your name, your email address, and whatever you choose to include, such as your field, your research question or the tool you wish existed. Please do not send us sensitive personal information, for example about your health, that we do not need.
When you visit the site
Like every website, ours can only be delivered if the server sees your IP address, your browser type, the page you ask for and the time. Our hosting provider, Render Services, Inc. (United States), and its network partners process this information to deliver pages and protect the site from attacks. We do not receive or see these logs. Render does not publish a fixed retention period; see Render's privacy policy.
What we do not collect
We do not use cookies, analytics, advertising trackers or embedded social media. There are no accounts or forms on this site. Our fonts are served from our own website, so loading a page does not send your details to anyone else.
Why we use it, and our lawful basis
UK data protection law says we need a lawful basis for each way we use personal data. These are ours:
| What we do | Data involved | Lawful basis |
|---|---|---|
| Reply to your email and talk with you about joining the lab | Your name, email address and message | Legitimate interests: answering people who contact us |
| Run the membership if you join, including pairing you with a lab member | Your name, email address, field and project details | Legitimate interests: supporting members and their projects |
| Deliver the website and keep it secure | Server logs | Legitimate interests: keeping the site working and safe |
| Meet our legal obligations | Whatever the law requires | Legal obligation |
Where we rely on legitimate interests, you can object at any time (see Your rights).
Who sees your data
- Lab members, only where they need it. For example, if you ask to be paired with a member, we share your request with that member.
- Our service providers: Render Services, Inc. (United States) for website hosting and Tuta (Tutao GmbH, based in Germany) for email. They process data only to provide their service to us.
- Authorities, only if the law requires us to.
We never sell personal data, and we never use it for advertising.
Data outside the UK
Our email provider, Tuta, stores all data in Germany, which UK law recognises as providing adequate protection. Our website host, Render, is in the United States and is certified under the UK Extension to the EU-US Data Privacy Framework (the “UK-US data bridge”), which UK law also recognises.
How long we keep it
- Emails: for as long as we need them to reply to you and, if you join, for as long as you are a member, then 12 months.
- Server logs: we hold none. Render's own retention is set out in Render's privacy policy.
When we no longer need data, we delete it.
Your rights
Under UK data protection law you can ask us to:
- show you the personal data we hold about you;
- correct it;
- delete it;
- limit how we use it;
- stop using it, where we rely on legitimate interests;
- give you a copy in a portable format, where that right applies.
To use any of these rights, email hello@jointhinkspark.com. We will reply within one month, as the law requires, and there is normally no charge.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office (ICO), the UK's data protection regulator, at ico.org.uk/make-a-complaint. We would appreciate the chance to put things right first.
Keeping data safe
The site is served only over an encrypted connection (HTTPS). We keep personal data in as few places as possible and limit who can see it. No system is perfectly secure, so if you find a problem, please tell us through our security policy.
Children
This site is for researchers and is not aimed at children.
Changes to this policy
If we change this policy, we will update the date at the top of this page. If a change matters, we will say so here.
This policy is adapted from a privacy policy template by General Legal, PC, released under CC0 1.0.