Privacy Policy

What we collect, why we collect it, and what we will never do with it.

Effective 28 August 2026 · Gate Zero Wireless™, operated by Spark Fire Technologies

The short version. We collect what is needed to deliver and bill for your service, and nothing else. We do not sell your data. We do not sell your browsing history. Information about your use of our network — what the FCC calls Customer Proprietary Network Information, or CPNI — is used to run your service and bill you for it, and for nothing else unless you specifically opt in.

Information we collect

What we do not collect

CPNI and your consent

Federal law (47 C.F.R. § 64.2001 et seq.) governs how we may use CPNI. We use it without asking you for permission only where the law permits: to provision, deliver, maintain and bill for the service you purchased, and to respond to lawful legal process.

Any other use — marketing outside your existing service category, or disclosure to a third party — requires your express opt-in consent. Our systems enforce this: a request to access CPNI for a purpose that requires consent is refused outright when consent is not on file. Every access is written to a tamper-evident, hash-chained log.

Law enforcement

We disclose subscriber information to law enforcement only under valid legal process — a subpoena, court order or warrant appropriate to the information sought. Every such request is recorded, including the legal instrument relied upon. Our systems will not record a law enforcement disclosure without that reference.

Retention

RecordRetention
Billing and payment records7 years (tax and regulatory requirement)
Session accounting (times, volumes, assigned IP)12 months
Support tickets3 years after closure
Cloud Browser profileUntil you delete it or 90 days after service ends
Audit logRetained indefinitely; it is append-only by design

Your rights

You may request a copy of the personal information we hold about you, ask us to correct it, withdraw CPNI consent at any time, or ask us to delete your Cloud Browser profile. Contact us and we will respond within 30 days.

Security

Credentials are hashed with scrypt. Secrets are encrypted at rest with AES-256-GCM under a key that is not stored alongside the data. Access to subscriber records is role-based and enforced on the server, and every privileged action is recorded in an append-only audit log whose integrity can be verified independently.

Changes

If we change this policy in a way that materially affects how we treat your information, we will notify you before the change takes effect.