TREADSPARK

TREADSPARK INC.

TREADSPARK INC.

Privacy Policy

Effective Date: October 5, 2026 · Last Updated: October 5, 2026

1. Who we are and what this policy covers

TREADSPARK INC., a Delaware corporation with its principal business address at 163 SW Freeman Ave, Hillsboro, OR 97123, operates TreadSpark.com. In this policy, “TreadSpark,” “we,” “us,” and “our” refer to TREADSPARK INC. Contact us at Admin@Treadspark.com for privacy questions, requests, complaints, and appeals.

This policy describes personal information processed through our websites, accounts, software, partner and independent installer applications, territory checks, document and signature workflows, verification, training, mobile tire service operations, van inquiries and quotes, customer relationship management, billing, communications, and related services that link to it, collectively the “Services.” Personal information includes information that identifies, relates to, describes, or can reasonably be associated with a person or household, as defined by applicable law.

This policy applies to individuals throughout all 50 U.S. states, the District of Columbia, U.S. territories, and visitors from other countries. Particular legal rights depend on the law’s territorial scope, effective date, thresholds, exemptions, and our role in the processing. The international provisions below apply when the relevant foreign law governs the processing. Visiting a U.S. website does not, by itself, establish that every foreign privacy law applies.

This policy is a notice of our practices. Reading it, visiting the website, or accepting the Terms of Service is not blanket consent to advertising tracking, sensitive-data processing, background screening, or another activity requiring separate consent. A more specific notice supplements this policy for its stated processing and cannot diminish mandatory legal rights.

2. Our role and information supplied by business customers

For our own website, account administration, marketing, applications, sales, security, and business operations, we ordinarily decide why and how information is processed and act as a controller or business under applicable law.

For customer, employee, technician, appointment, and work-order information that a business uploads or manages using our software, we may act as that business’s processor, service provider, or contractor. The business determines the purposes and instructions, subject to its contract with us and applicable law. Its privacy notice applies to its own practices. Contact that business first for requests about records it controls; you may also contact us so we can identify the appropriate business and assist as legally required. We do not treat this referral as a reason to ignore requests about information we control ourselves.

Organizations may grant their owners, administrators, managers, technicians, or other users access based on their permissions. An administrator may access organization records, manage users, and change permissions. Organizational access is different from public disclosure. Other organizations do not receive unrestricted access merely because they participate in the same network or have a common owner.

3. Sources of personal information

We obtain information directly from you through forms, applications, accounts, uploads, orders, support, and communications; from your organization and authorized representatives; from customers and participating installers involved in a service; and automatically from devices and interactions with our Services.

We may also receive relevant information from screening and identity providers, references, licensing and registration sources, payment and financing providers, electronic signature and document vendors, service networks, retailer or dispatch partners, referral sources, and lawful public records. We use those sources only for an appropriate disclosed purpose. A source being publicly available does not automatically make all uses permissible.

If we receive personal information indirectly and applicable law requires additional notice, we provide that notice within the applicable period, subject to lawful exceptions. Providing another person’s information does not replace that person’s required consent or our own notice obligations.

4. Account identity and business information

Account information includes name, email, telephone number, login identifier, authentication records, verification status, organization membership, role, preferences, and account activity. Authentication records can include password hashes, session tokens, or authentication-provider identifiers depending on the method used. We use this information to create accounts, authenticate access, protect sessions, administer permissions, and communicate about the Services.

Business information includes legal name, DBA, entity type, EIN or other tax identifiers when required, business and mailing addresses, formation and registration details, operating hours, service capabilities, equipment, vehicle fleet, technician count, business contacts, ownership details when required, licenses, certifications, insurance, references, and financial or tax documentation. Business information can be personal information when it relates to an individual owner or representative.

A shared account or business record may support multiple TreadSpark workspaces. This supports authentication and legitimate administration; it does not authorize unrelated disclosure or use of sensitive documents across programs.

5. Applications screening and uploaded documents

Application records can include requested ZIP codes, service territories, qualifications, capacity, equipment photographs, compliance records, training completion, agreements, electronic signatures, signature timestamps and audit records, communications, verification results, and application or activation status.

Uploads may include certificates of insurance, licenses, tax forms, identity documents, contracts, vehicle documents, and other compliance materials. We process them to evaluate qualifications, verify requirements, maintain program records, and administer agreements. Provide only information requested for the relevant purpose. Where feasible, redact unrelated personal information before uploading. We may restrict or remove unnecessary sensitive content while preserving records required by law.

Screening may involve legal name, date of birth, address history, identity or driver’s-license information, Social Security information, criminal or driving records, professional credentials, screening reports, eligibility results, and dispute or review records, depending on the check. A screening provider may collect sensitive inputs directly and provide us with status or results. The exact data flow depends on the provider and program.

We initiate screening only with a lawful permissible purpose and any required separate disclosure, authorization, or consent. This policy is not a Fair Credit Reporting Act disclosure, authorization, liability release, or substitute for state screening notices. Required access, correction, pre-adverse-action, adverse-action, and other screening procedures are addressed separately. An applicant may contact the identified screening provider to dispute its report and contact us about our own records and decision review.

6. Location territory and vehicle information

Location information can include requested ZIP codes, service areas, business addresses, customer appointment locations, routing and delivery addresses, IP-derived approximate location, and technician or vehicle location where a feature is enabled. We use relevant location information for territory review, scheduling, dispatch, routing, safety, service fulfillment, and fraud prevention.

Precise location, including some real-time or historical device-location information, can be sensitive. We provide appropriate notices and obtain consent where required before processing it. Device permissions and program settings may allow you to turn location collection off; doing so may affect routing or dispatch features. The business operating a technician account may establish additional employment or workplace notices and requirements.

We do not authorize sale of precise geolocation or its use to infer health conditions or visits to sensitive locations through this policy. Those activities require a separate legal and operational assessment and must not occur where prohibited. Vehicle records can include VIN, make, model, year, tire specifications, DOT tire identifiers, fleet records, service photographs, and service history when relevant to the Services.

7. Van inquiries quotes and sales records

When you request a van quote or information, we process contact and business information, vehicle and equipment preferences, configuration selections, branding choices, quotes, discounts, deposits, order and build status, delivery details, correspondence, sales notes, and lead activity. We also record whether you express interest in becoming a partner or installer so personnel can follow up about that program.

A quote request can create a CRM lead and connect subsequent communications and sales activity. Providing information for a quote does not automatically enroll you in a partner program or authorize a background check. Separate financing applications are governed by the lender’s notices and any TreadSpark disclosures for the actual referral. We do not use this policy as permission to obtain a consumer credit report.

8. Customer transactions payments and support

Service records may include customer contact and address details, appointments, technician assignments, work orders, tire and vehicle information, inspection photographs, service notes, warranty records, customer messages, invoices, and payment status. Authorized installers, dispatch personnel, and the business responsible for the job receive information needed to perform and administer that service.

Billing and payment records may include billing contact information, amounts, invoices, deposits, refunds, subscriptions, payout status, transaction identifiers, and payment-method metadata. Payment processors may collect card, bank, or identity information directly. Their independent processing is subject to their own notices. The information available to TreadSpark and our internal access and storage depend on the payment method and integration.

Support and communications records include messages, attachments, associated contact information, and metadata. If calls are recorded, transcribed, or analyzed, we provide required notice and consent before doing so. We do not treat use of the website as consent to recording a later telephone call. The same requirements apply to session replay, chat monitoring, and third-party communications interception technologies where relevant law requires notice or consent.

9. Device usage cookies and advertising tracking

We use advertising tracking. The technologies deployed may include cookies, pixels, tags, local storage, advertising identifiers, and server-side integrations. They can process IP addresses, device and browser details, cookie identifiers, approximate location, referral URLs, pages visited, clicks, timestamps, interactions, and conversion events. Where implemented, account or contact identifiers may be matched with an advertising provider; hashing an email address does not necessarily make it anonymous.

Essential technologies support authentication, security, user choices, and requested functionality. Analytics measure usage and performance. Advertising technologies measure campaigns, build audiences, and help present relevant advertising on our Services or other services. Providers may combine advertising information with information obtained elsewhere according to their own roles and notices.

We obtain prior consent for nonessential tracking where required and provide opt-out choices where applicable. A cookie control must cover the relevant technologies, including server-side advertising disclosures; merely deleting a browser cookie may not stop all processing. We do not use the act of accepting the Terms as a substitute for a legally required tracking choice.

10. How information is used

We use account and business information to provide requested software, administer accounts and organizations, authenticate users, and maintain role permissions. We use application, document, screening, and territory information to evaluate qualifications, prevent conflicts, facilitate lawful verification, manage training, and administer activation or continued participation.

We use quote, CRM, order, and payment records to respond to inquiries, prepare quotes, administer van builds and delivery, process authorized payments and subscriptions, reconcile transactions, and address refunds or disputes. We use service and vehicle information to support scheduling, dispatch, fulfillment, invoicing, and business-customer workflows.

We use communications and technical information to provide support, send operational notices, troubleshoot, assess performance, develop features, and protect against fraud, misuse, and security incidents. We use permitted advertising and engagement information to measure and promote the Services, subject to choices and applicable consent requirements.

We also maintain records to meet contractual, legal, accounting, tax, insurance, safety, and compliance obligations; establish or defend legal claims; and respond to valid legal process. We limit collection and use to information reasonably necessary and proportionate to these purposes. A materially different or incompatible new purpose requires additional notice and consent where required by law.

11. Recipient and disclosure categories

Service providers and processors include hosting, storage, authentication, email, SMS, support, cybersecurity, document processing, electronic signature, and software vendors. They receive the account, technical, communications, document, or transaction information necessary for their function, subject to appropriate contractual restrictions and applicable law.

Screening and identity providers receive authorized application and identity information needed to perform checks. Payment processors and payout providers receive billing, transaction, and required verification information. Financing providers receive information needed for a referral or application you choose, subject to separate disclosure and authorization where required.

Participating retailer networks, dispatch or fulfillment partners, installers, and service businesses receive relevant customer contact, location, vehicle, appointment, work-order, and status information needed to coordinate and complete a job. Program administrators may receive application, territory, qualification, compliance, and status information necessary to administer a program. Sensitive underlying reports and tax or identity documents are limited to recipients with a legitimate need and lawful basis; a partnership does not justify access to every record.

Advertising and analytics providers receive the technical, activity, advertising, and permitted matching information described above. Some act as independent third parties rather than restricted service providers. Their receipt can constitute a sale, sharing, or targeted advertising under state law.

Professional advisers such as lawyers, accountants, auditors, insurers, and consultants receive information needed for their work. Government bodies, courts, and other recipients may receive information when required by law or reasonably necessary for lawful security, safety, fraud prevention, or legal-claim purposes. We assess requests and apply legal restrictions rather than promising unrestricted access to every requester.

In a proposed or completed merger, financing, restructuring, bankruptcy, or sale of assets, transaction participants may receive relevant information subject to appropriate safeguards and applicable law. A successor’s materially different use remains subject to required notices and choices. We also disclose information at your direction or with a valid separate consent when necessary.

12. Sale sharing and targeted advertising

Because we use advertising tracking, we may disclose online identifiers, IP addresses, browsing and interaction information, approximate location, and permitted advertising-matching identifiers to advertising partners in a way that constitutes “sale,” “sharing” for cross-context behavioral advertising, or “targeted advertising” under applicable state law. These definitions can apply even when no money is exchanged. We do not rely on a statement that we do not sell data for money to imply that advertising disclosures are exempt.

You may opt out by emailing Admin@Treadspark.com with the subject “Privacy Opt Out” and identifying the browser, account, or information involved without sending passwords or full government identifiers. You may also use any website privacy controls made available to manage these choices. Opting out of advertising does not prevent processing necessary to supply a requested service or other legally exempt processing.

We honor legally recognized universal opt-out preference signals, including qualifying Global Privacy Control signals, as required by applicable law. Depending on recognition and available account information, a signal applies to the browser or device and, when required and reasonably linked, the account. A signal does not opt you out of necessary communications or unrelated processing. Traditional Do Not Track signals are different and are not treated as a universal opt-out unless applicable law requires it.

We do not require an account, payment, or unnecessary identity verification to submit a sale, sharing, or targeted-advertising opt-out. We use only the information needed to implement the choice. Cookie settings and account-linked choices may need to be addressed together. Use separate browsers or devices consistently, and contact us if a control does not work.

13. Sensitive data biometric information and health information

Sensitive information can include government identifiers, login credentials, financial account information, precise location, and information contained in screening or compliance documents. State and foreign definitions vary. We process sensitive information for disclosed account, verification, fulfillment, security, legal, or compliance purposes with consent or another lawful condition where required.

We do not authorize disclosure of screening reports, Social Security numbers, identity documents, account credentials, tax forms, or payment account details to advertising partners. Tracking must be configured to exclude those fields, documents, and sensitive application or account pages. Sensitive information should not be placed in URLs or advertising-event payloads.

Photographs, signatures, or recordings are not always statutory biometric identifiers; technologies that derive identifying face geometry, fingerprints, voiceprints, or similar templates can trigger separate requirements. Before enabling biometric verification, we provide the specific notice, purpose, retention and destruction terms, consent or written release, and vendor disclosures required by the relevant law. This general policy is not a biometric consent or a complete biometric retention policy.

The Services are not intended for collecting health or medical information for advertising. Do not upload medical records unless a specifically authorized workflow requires them and provides the required notice. If a service processes legally protected consumer health data, we assess the applicable health-data laws and issue a dedicated notice and choices where required. A general prohibition in these Terms does not excuse our obligations for data actually collected.

14. Automation artificial intelligence and decision review

Where enabled, rules and AI may assist with document extraction, completeness checks, territory routing, inconsistency detection, fraud review, support, and workflow organization. Inputs may include application fields, uploaded records, territory information, and relevant account activity; outputs can include extracted fields, flags, scores, recommendations, or routing decisions. Automated output can be incomplete or incorrect.

When applicable law grants rights relating to significant automated decisions or profiling, we provide required advance notice, meaningful information, access, opt-out, and human-review or contest procedures, subject to lawful exceptions. Contact Admin@Treadspark.com with “Decision Review” to request review of a qualification or verification result. A review request does not replace a screening-report dispute with the reporting agency.

Uploading records is not blanket permission for unrelated general-purpose AI model training. Any such use requires a separately established lawful basis, appropriate notice, contractual authority, and consent where required. Processor data is used only as permitted by the customer’s instructions and applicable data-processing terms.

15. Retention deletion and backups

We retain information only for the period reasonably necessary for the applicable purpose and legal obligations. Relevant criteria include account activity, the application or program relationship, transaction completion, warranty administration, tax and accounting requirements, insurance, dispute periods, security investigations, statutory recordkeeping, and legal holds.

Account and business records are ordinarily needed during the account or contractual relationship and for justified follow-up records. Application and screening records are needed for qualification administration and any required review or defense period. Transaction, tax, contract, and signature records may require longer legal retention. Technical logs, advertising identifiers, rejected applications, and sensitive source documents should have separate, purpose-based periods rather than automatically inheriting the longest business-record period.

Deletion can include removing identifying content, permanently deleting records, or lawful deidentification. Backups may retain restricted copies until scheduled rotation; we do not restore deleted data for ordinary use and apply deletion instructions again if recovery requires restoration. Legal holds suspend ordinary deletion only for relevant records and are reviewed when the hold ends.

16. Security and incident response

We maintain safeguards appropriate to the nature of the personal information, our processing, and applicable law. Safeguards are intended to reduce unauthorized access, misuse, alteration, loss, and disclosure. Security practices must be proportionate to sensitivity and include appropriately restricted access, vendor oversight, and incident handling. No system is completely secure.

If an incident triggers a legal notification duty, we notify affected individuals, businesses, authorities, or other recipients in the time and manner required. We do not make access to statutory notices conditional on signing a release. Report a suspected account or data incident to Admin@Treadspark.com without sending passwords or unnecessary sensitive data.

17. Your choices and privacy rights

Depending on applicable law, you may have rights to confirm processing; access and receive a copy; obtain portability; correct inaccurate information; delete information; learn collection sources, purposes, disclosure categories, or specific recipients; opt out of sale, sharing, targeted advertising, or covered profiling; limit certain sensitive-data uses; withdraw consent; restrict processing; object to processing; or contest specified automated decisions.

These rights differ by jurisdiction and are subject to lawful exemptions. We explain a refusal or limitation where required rather than treating the existence of an exemption as a reason to reject an entire request. Withdrawing consent does not invalidate earlier lawful processing but stops future consent-based processing subject to applicable law. Some requested features cannot operate without necessary information.

We do not unlawfully discriminate or retaliate for exercising rights. Any legally permitted price or service difference tied to information must satisfy applicable requirements and disclosures. This policy does not announce a financial-incentive program or authorize one without a separate required notice.

18. How to submit requests and use an authorized agent

Email Admin@Treadspark.com with “Privacy Request” and describe the right you wish to exercise. You may also mail TREADSPARK INC., Attention Privacy, 163 SW Freeman Ave, Hillsboro, OR 97123, United States. Provide sufficient contact and account information for us to locate the relevant records, your jurisdiction where needed to determine rights, and your preferred response method. Do not submit full Social Security numbers, passwords, or complete payment numbers by ordinary email.

We verify access, deletion, and similar requests using information reasonably appropriate to the risk and applicable law. We do not require more information than reasonably necessary, charge for ordinary requests where prohibited, or require you to create an account when the law forbids it. Additional verification for disclosure of sensitive information may be necessary. Verification information is used only for request administration, security, and legally necessary records.

An authorized agent may submit a request with evidence of authority where required. A legally recognized power of attorney, parent, guardian, or representative is handled under applicable rules. We do not impose additional consumer verification on an opt-out where prohibited. If you cannot use email or need an accessible alternative, contact us by mail and explain the accommodation needed.

We respond within the applicable legal deadline. Many U.S. access, correction, and deletion regimes use a 45-day initial period with a permitted extension; some rights and jurisdictions require faster action. California sale/sharing and limitation requests have separate rules and deadlines. EEA and UK requests generally require action within one month, with legally allowed extensions. We notify you of permissible extensions and reasons. These examples do not replace a shorter governing deadline.

19. Appeals complaints and decision refusals

If we deny a request, you may appeal by emailing Admin@Treadspark.com with “Privacy Appeal,” identifying the original request and why you disagree. Send the appeal within the period stated in our response; we do not impose a shorter period than applicable law permits. We review and respond within the governing deadline, provide reasons, and include the legally required route to the relevant attorney general or regulator if the appeal is denied.

You may complain to a competent regulator or exercise another legal remedy without first completing a voluntary internal process where the law allows. Privacy requests and regulator complaints are not conditioned on the informal dispute process in the Terms. This policy does not waive a private right of action where one exists.

20. Email SMS and marketing choices

You can unsubscribe from promotional emails through the message’s link or by contacting Admin@Treadspark.com. We maintain the minimum suppression information needed to honor the choice. Operational messages, such as security, billing, application, or service updates, may remain necessary while you use the relevant feature; they are not used to disguise promotional campaigns.

Text messages are sent according to the permission and purpose applicable to that message. Marketing text consent is separately obtained when required and is not a condition of purchase. Reply STOP to opt out of texts and HELP for assistance where supported, or contact Admin@Treadspark.com. Carrier message and data rates may apply. Applicable SMS disclosures identify frequency and the relevant program.

We do not disclose mobile opt-in or consent records to third parties or affiliates for their own marketing. We may disclose them to communications providers and other authorized recipients as necessary to operate the messaging program, honor preferences, prevent misuse, or comply with law. This does not override the separate advertising disclosures about other information. Message consent can be revoked through legally recognized methods; STOP is not stated as the sole valid method.

21. Children and teenagers

The Services are designed for adults and business users. Accounts and program participation require the age stated in the Terms, ordinarily at least 18 and any higher applicable age of majority. We do not intentionally solicit information directly from children under 13. If we learn we processed children’s information unlawfully, we take required steps, including deletion or legally required parental involvement.

Teen privacy protections vary. We do not authorize sale, sharing, targeted advertising, or covered profiling of known minors where prohibited or without legally required consent. Age restrictions alone do not eliminate duties for minor data actually obtained. Parents or guardians may contact Admin@Treadspark.com about information relating to a child.

22. Nationwide United States rights

This policy’s request and contact procedures are available to residents of every U.S. state, the District of Columbia, and U.S. territories. Statutory rights apply when the governing law covers the person, activity, and entity. Some comprehensive state laws exempt business-to-business or employment contexts, while other laws, including California rules where applicable, can cover them. Security, breach notification, communications, consumer protection, screening, biometric, and specialized privacy laws can apply even when a comprehensive privacy statute’s thresholds are not met.

The nationwide framework covers Alabama, Alaska, Arizona, Arkansas, California, Colorado, Connecticut, Delaware, Florida, Georgia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Mississippi, Missouri, Montana, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, North Dakota, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, South Dakota, Tennessee, Texas, Utah, Vermont, Virginia, Washington, West Virginia, Wisconsin, and Wyoming. Listing a state does not mean it has a comprehensive privacy law or that its specific obligations are identical to another state’s.

Where applicable, Oregon residents may request the statutory list of specific third parties receiving information, and other jurisdictions may grant similar recipient transparency. Minnesota and other applicable laws may provide additional profiling explanation, correction, and contest rights. California rights and disclosures are addressed below. Nevada residents may request an opt-out of a covered sale. Sensitive-data consent and universal opt-out rules are applied according to the relevant state requirements.

Mandatory state rights control over conflicting Terms, contractual choice-of-law provisions, or language in this policy. Contact us even if your state is not associated with a particular right in this notice; we evaluate your request under applicable law.

23. California privacy rights and information categories

If the CCPA applies to TreadSpark and the relevant processing, California residents have rights to know and access, correct, delete, opt out of sale or sharing, and limit sensitive-information uses when the statutory limitation right applies, together with non-discrimination and other applicable protections. Covered business contacts and applicants may also have rights. California rights are subject to the statute’s permitted exemptions and verification requirements.

The table below summarizes the categories of personal information described in this Privacy Policy, their sources, purposes, recipient categories, and potential advertising disclosures. The categories processed depend on the Services used and the information provided. The collection, use, disclosure, and advertising practices described in this Policy apply to the relevant categories, subject to applicable law and your privacy choices.

CategorySourcesPurposesBusiness purpose recipientsAdvertising disclosures
Identifiers and account recordsYou, organization, authentication systemsAccounts, access, support, securityHosting, authentication, support, authorized organization usersAdvertising identifiers and permitted matching information.
Customer records and commercial informationYou, customers, service providers, payment systemsOrders, quotes, invoicing, CRM, service fulfillmentPayment, dispatch, installer, CRM/support providersConversion information only where permitted.
Internet and device activityDevices, website integrations, ad/analytics providersSecurity, performance, analytics, advertisingHosting/security, analytics and advertising providersOnline identifiers and advertising-related activity.
GeolocationYou, customer sites, devices where enabledTerritory, routing, dispatch, deliveryAuthorized dispatch, installer, maps and technical providersApproximate IP location may be included; precise location is excluded from advertising under this Policy.
Professional and business qualificationsYou, organization, references, licensing sourcesProgram eligibility and complianceAuthorized program administrators, screening, document vendorsPrivate screening and compliance records are not authorized for advertising.
Audio visual and signature recordsUploads, signature systems, noticed recordings if usedDocuments, service evidence, agreements, supportDocument/signature providers, authorized service or support usersPrivate records are not authorized for advertising.
Inferences and decision recordsService activity, permitted automation, advertising systemsWorkflow, fraud review, permitted audience analysisRelevant program/security providers; advertising partners for permitted ad inferencesPermitted advertising inferences may be shared; sensitive screening inferences are excluded.
Sensitive personal informationAuthorized forms, screening, financial or location providersVerification, required payment and fulfillment, security, legal complianceRestricted screening, payment, document and authorized program recipientsSensitive source records are not authorized to be sold or shared for advertising.

Retention periods or criteria are described in Section 15. Collection sources are described in Section 3. Business-purpose recipients are described in Section 11. The advertising categories and opt-outs appear in Sections 9 and 12. Where required, we provide an additional notice at or before collection that describes the relevant categories, purposes, sale or sharing practices, retention, and this Policy.

We provide the applicable privacy-request methods, agent process, and legally required opt-out and limitation links or lawful alternatives. You may submit a request using the contact methods described in Section 18.

Where applicable, California Shine the Light requests concerning personal-information disclosures to third parties for their direct marketing may be sent to Admin@Treadspark.com with “California Direct Marketing Request.” This is distinct from CCPA advertising opt-outs. We do not treat commercial activity as exempt solely because the information identifies a business contact.

24. European Economic Area United Kingdom and Switzerland

Where the GDPR, UK GDPR, or applicable Swiss law governs the processing, TREADSPARK INC. is the controller for its own purposes described here. A business customer may be the controller for processing we perform on its instructions. Our contact details appear in Section 1.

We identify a lawful basis for each purpose: contractual necessity for the account or transaction you request as an individual; legal obligations for required records and compliance; legitimate interests for proportionate security, administration, business-to-business contact, support, and improvement where those interests are not overridden; and consent for processing that legally requires it, including relevant tracking. We do not use contractual necessity to cover every marketing activity. Special-category information and criminal-offence data require additional lawful conditions and safeguards; an ordinary legitimate-interest statement is not sufficient.

Our legitimate interests include maintaining reliable Services, securing accounts, preventing fraud, responding to business inquiries, managing program operations, and establishing legal claims. We assess necessity and effects on individuals. You may request information about a relevant assessment and object where applicable. Objection to direct marketing is honored as required without requiring you to prove a special justification.

You may have rights to access, rectification, erasure, restriction, portability, objection, consent withdrawal, and safeguards for solely automated decisions with legal or similarly significant effects. We provide required information about decision logic, significance, consequences, human intervention, and contest rights for covered processing. Your rights depend on the basis and circumstances and are not limited to the U.S. list above.

Some information is required by law or needed to enter or perform a transaction; we explain the required fields and consequences of not providing them at collection. Optional marketing choices are separate. We provide additional indirect-collection information when required.

You may complain to your local data-protection supervisory authority, the UK Information Commissioner’s Office at ico.org.uk, or the Swiss Federal Data Protection and Information Commissioner at edoeb.admin.ch, as applicable. You do not need to waive that right or contact us first.

25. Canada and other international jurisdictions

Where Canadian federal or provincial privacy law applies, we use meaningful consent or another permitted basis for collection, use, and disclosure, provide access and correction and consent-withdrawal processes as required, and identify our privacy contact at Admin@Treadspark.com. Optional processing is not made a condition of a service beyond what is legitimately necessary. Applicable Quebec, Alberta, British Columbia, language, assessment, and cross-border requirements require additional measures where relevant.

Where Brazilian law applies, requests may include confirmation, access, correction, portability, deletion or anonymization or blocking of inappropriate processing, information about sharing and consent, withdrawal, and review of covered automated decisions, subject to applicable law. We establish the relevant legal basis and required transfer safeguards and provide a designated privacy contact where required. Where Australian or New Zealand privacy law applies, applicable access, correction, complaint, security, and overseas-disclosure protections also apply.

Visitors from other countries may contact us about the privacy rights available under governing law. This notice does not represent that we have audited or satisfied every country’s law. We assess additional local notice, language, consent, registration, localization, transfer, representative, and consumer requirements before actively offering regulated services in a new market. Mandatory local rights remain available notwithstanding U.S. operations or contractual venue provisions.

26. International processing and transfer safeguards

TreadSpark operates from the United States. Information may be processed in the United States and countries where relevant vendors or authorized personnel operate. These jurisdictions can have different privacy laws and government-access rules.

Where a restricted transfer requires safeguards, we use a legally available mechanism and necessary assessments or supplementary measures before the transfer, such as applicable adequacy arrangements, approved contractual clauses, or an appropriate UK transfer addendum or agreement. The appropriate mechanism depends on the exporter, importer, location, and governing law. Consent to this policy or mere website use is not our routine substitute for those requirements.

We do not claim participation or certification in the EU-U.S. Data Privacy Framework, UK extension, or Swiss-U.S. framework unless verified and separately disclosed. You may request information about relevant transfer safeguards and a copy where legally available, subject to protection of confidential information.

27. Third party services and related companies

Independent service providers, payment or financing businesses, screening agencies, retailer networks, and other linked sites can have their own privacy notices. Their independent purposes are governed by those notices and applicable law. We remain responsible for our own selection, disclosures, instructions, and legal obligations; linking to a third party does not eliminate those duties.

TREADSPARK INC. is the operator identified here. A relationship with GoMobile Tires or another business does not, by itself, grant that business unrestricted access to TreadSpark information. Any permitted disclosure must fit a disclosed purpose, required safeguards, and applicable choices. Review the particular service agreement to identify the business that actually provides an installation, van build, financing, or other transaction.

28. Deidentified and aggregated information

We may use aggregated or properly deidentified information for performance analysis, planning, benchmarking, product improvement, and other lawful business purposes. We apply required safeguards so it cannot reasonably be used to identify or link to an individual. Where required, we commit not to reidentify it except for legally permitted testing or other permitted purposes and impose corresponding obligations on recipients. Pseudonymous identifiers, hashed emails, and small identifiable groups are not automatically deidentified.

29. Changes to this policy

We update this policy when practices or legal requirements change and revise its last-updated date. We provide notice of material changes in the manner required, and seek renewed or additional consent where necessary. Posting a new notice does not retroactively authorize an incompatible use of previously collected information or remove a prior binding restriction. We retain version information needed to identify the notice that applied to a relevant period.

30. Contact and accessible alternatives

Privacy requests, appeals, consent withdrawals, advertising opt-outs, and questions: Admin@Treadspark.com.

Mail: TREADSPARK INC., Attention Privacy, 163 SW Freeman Ave, Hillsboro, OR 97123, United States.

Website: https://treadspark.com. If you need this notice or a request process in an accessible format or another legally required language, contact us and describe the assistance needed. Do not include passwords, full government identifiers, or unnecessary sensitive attachments in an ordinary email.