1. In transit
All traffic to GC SPARK is served over TLS 1.3. We use HSTS to prevent downgrade attacks.
Every card detail is encrypted in storage and masked in our dashboard. A reviewer can only briefly unmask a card while working your ticket — and every reveal is logged.
All traffic to GC SPARK is served over TLS 1.3. We use HSTS to prevent downgrade attacks.
Card numbers and PINs are encrypted at rest using AES-256. Keys are stored separately, rotated quarterly.
Card images are stored in a private object store with signed, time-limited URLs.
Every admin action is recorded. You can request the audit log for any submission by emailing support@gcspark.com.
Engineers do not have routine access to production card data.
Email security@gcspark.com. We respond within 48 hours.
GC SPARK operates independently from all gift card issuers. The brands featured on this website do not sponsor, authorize, or endorse GC SPARK's services. References to third-party trademarks are made solely for identification purposes.
Anything in this policy unclear? Get in touch.
support@gcspark.comWe use a few essential cookies to keep you signed in and protect your submission. Optional cookies help us measure traffic and improve the site. You can change this anytime in our cookie policy.