Cookie Policy

This policy explains how Spark Network uses cookies and similar browser storage, and how you can control them. It supplements our Privacy Policy.

The controller is ISKRA ASSOCIATION, UIC 208183744, at 12 Doctor Piskulev Street, entrance A, apartment 25, Varna, Bulgaria. Contact us at office@spark-network.eu.

Your choices

Cookies are small values stored by your browser and sent with matching web requests. Local storage and IndexedDB keep information in your browser for the website to read. Persistent storage can remain after you close a tab; browser settings can limit or remove it.

You can browse without agreeing to analytics. Choose Reject all in the banner, or disable Analytics cookies and save in Cookie Preferences. Accept all enables Google Analytics. Essential functions, such as authentication and remembering your choice, remain available.

Reopen Cookie Preferences in the footer, the floating preferences button on pages without a footer, or the button on this page. You can withdraw analytics consent at any time. Withdrawal changes future analytics use; it does not undo processing that took place before withdrawal. Cookies already present may remain until expiry or browser deletion.

When you save a choice, we also send a consent record to our server: your choice, its version and timestamps, a consent reference, IP address, browser information and your account ID if signed in. This server record is separate from the 180-day preference cookie; deleting browser data does not delete server records. Contact us about your data rights.

Cookies and browser storage

The entries below describe our website integration. Names containing a user, app or session identifier vary by account or browser. Some entries appear only after signing in, choosing analytics, using the cart or opening an exercise. Storage lifetimes are separate from retention of information already received by a provider.

sn_consent

Technology
First-party cookie
Provider
Spark Network
Purpose
Remembers your analytics choice, a random consent reference, the choice date and the consent version.
Category
Essential — saving your privacy choice
Duration
180 days from your most recent choice.
Recipients
Spark Network and its Google Cloud / Firebase hosting provider.
Your controls
Change your choice using Cookie Preferences. Clearing this cookie makes the banner appear again.

__session

Technology
First-party, HttpOnly authentication cookie
Provider
Spark Network / Firebase Authentication (Google)
Purpose
Keeps you signed in and allows the server to check access to your account.
Category
Essential — used when you sign in
Duration
Up to 5 days; cleared when you sign out.
Recipients
Spark Network and Google, which provides authentication.
Your controls
Sign out or clear this site’s cookies. Blocking it prevents signed-in features from working.

firebaseLocalStorageDb / firebase:authUser:<app-key>:[DEFAULT]

Technology
IndexedDB authentication record; browser local storage may be used as a fallback
Provider
Firebase Authentication (Google)
Purpose
Persists the signed-in account and authentication tokens in this browser.
Category
Essential — used for authentication
Duration
No fixed browser expiry; persists across visits until sign-out or browser data removal. Tokens are refreshed or invalidated separately.
Recipients
The record is stored in your browser; authentication information is exchanged with Spark Network and Google.
Your controls
Sign out to remove the persisted account, or clear site data in your browser.

firebase-heartbeat-database

Technology
IndexedDB
Provider
Firebase (Google)
Purpose
Records the days on which the Firebase SDK was used in this browser so the SDK can report its usage to Google when it contacts Firebase services.
Category
Essential — technical SDK record
Duration
Rolling; the SDK keeps recent daily entries and removes older ones.
Recipients
Stored in your browser; a summary is sent to Google with Firebase requests.
Your controls
Clear site data in your browser.

spark-cart:guest / spark-cart:<user-id>

Technology
Local storage
Provider
Spark Network
Purpose
Remembers the courses in your shopping cart for a guest or signed-in account.
Category
Essential — shopping cart
Duration
No automatic time expiry; retained until removed by the cart flow or cleared in your browser.
Recipients
Stored locally and read by Spark Network. Cart selections are sent to our service when needed for checkout.
Your controls
Remove items from your cart or clear site data. Clearing browser data removes locally saved selections.

spark-course-homework-session:<session-id>

Technology
Local storage
Provider
Spark Network
Purpose
Saves an opened course assessment and your progress so the exercise can be resumed.
Category
Essential — requested course exercise
Duration
No automatic time expiry; retained until cleared by the course flow or in your browser.
Recipients
Stored locally and read by Spark Network. Submitted work is handled separately by the course service.
Your controls
Clear site data to remove saved exercise state. This can erase unfinished work.

__stripe_mid

Technology
First-party cookie set by Stripe.js
Provider
Stripe
Purpose
Recognises a browser to help detect fraudulent payment activity.
Category
Payment security / fraud prevention — outside the analytics preference
Duration
1 year; Stripe may refresh it.
Recipients
Stripe and its service providers; see the Stripe information below.
Your controls
Remove or block it through browser cookie settings. Payment and fraud checks may be affected.

__stripe_sid

Technology
First-party cookie set by Stripe.js
Provider
Stripe
Purpose
Associates browser activity with a session for payment fraud checks.
Category
Payment security / fraud prevention — outside the analytics preference
Duration
30 minutes; Stripe may refresh it.
Recipients
Stripe and its service providers; see the Stripe information below.
Your controls
Remove or block it through browser cookie settings. Payment and fraud checks may be affected.

m

Technology
Third-party cookie on m.stripe.com
Provider
Stripe
Purpose
Helps Stripe assess device and browser signals for fraud prevention.
Category
Payment security / fraud prevention — outside the analytics preference
Duration
400 days observed in our browser check. Provider updates and browser limits can change its lifetime.
Recipients
Stripe and its service providers; see the Stripe information below.
Your controls
Use browser settings to remove or block third-party cookies, including m.stripe.com.

_ga / _ga_5MYEWWNL3B

Technology
First-party cookies set by Google Analytics 4
Provider
Google Analytics
Purpose
Distinguishes browsers and maintains analytics session state for reports about visits and use of the website.
Category
Optional analytics — loaded after you allow analytics
Duration
Google’s default cookie lifetime is 2 years and may be renewed on use. Browser limits or Analytics settings may shorten or change this.
Recipients
Google and Spark Network, which receives analytics reports.
Your controls
Reject analytics or switch it off in Cookie Preferences. To remove cookies already stored, clear them in your browser.

Stripe.js loads only when a payment form is opened (donations, course purchase or billing). Its fraud-prevention cookies are set at that point regardless of your analytics choice, because they support the payment you requested. The analytics switch does not control Stripe. Stripe’s cookies are not used by us for advertising.

Providers and international processing

Google / Firebase: Spark Network uses Google infrastructure for hosting and authentication. Firebase Authentication processes data in the United States; an EU hosting location does not mean every Google service processes data only in the EU. Authentication entries above involve Google when signing in or checking your session. Our local cart and exercise records stay in your browser unless their contents are sent as part of the service you use. See Firebase privacy and processing locations and Firebase data-processing terms.

Google Analytics: with your consent, our Google tag sends visit and page-use information to Google, including page URLs, browser/device information and cookie identifiers. This may involve processing outside the EEA, including the United States. We use the direct Google tag for Analytics; the website does not include a separate Google Tag Manager container, Google Ads tag or Meta Pixel. See Google’s Analytics cookie information and Google’s Privacy Policy.

Stripe: payment-security signals are received by Stripe and its providers and may be processed outside the EEA, including in the United States. Stripe’s roles and purposes are explained in its Privacy Center and Privacy Policy. Its data-processing terms describe applicable transfer safeguards, including standard contractual clauses.

Adobe Fonts: the public website’s typefaces are delivered from Adobe’s servers (use.typekit.net and p.typekit.net). Each page load sends your IP address, the page address and browser information to Adobe, which records the font request for licensing and service purposes. No cookies are set and the analytics switch does not apply. This can involve processing in the United States; see Adobe Fonts privacy information and Adobe’s transfer safeguards. The Creators Hub uses fonts served from our own hosting.

Google, Stripe and Adobe publish information about their international transfer safeguards in the linked notices and terms. Contact us for information about safeguards applicable to your data or to exercise your rights. You may complain to the Bulgarian Commission for Personal Data Protection. This policy addresses our Bulgarian and EU/EEA website context.

Other services and embedded content

Some course and project pages can embed YouTube or Vimeo content. If such content is included and loaded, the provider receives a web request and may use its own storage. This is conditional content, not a statement that those providers load on every page. Their notices explain their technology and controls: YouTube / Google cookies and Vimeo cookies.

Signing in with Google or choosing an additional Stripe payment service can open provider-controlled pages with their own cookies and notices. Ordinary social links take you to the selected website; a social link alone does not install a tracking pixel on Spark Network.

You can remove cookies, local storage and IndexedDB using your browser’s site-data settings. This may sign you out or remove saved cart and exercise progress. For instructions, see Chrome cookie controls or your browser’s help. We will update this policy when the website’s use of these technologies changes.