Future 42

Company information

How we protect your data, what has changed, and the terms of working with us.

Security

Our security practices cover access, encryption, incident response, and service providers. SOC 2 is in progress; no audit report has been issued. Report a concern to security@ftr42.com.

Read full security details

Last reviewed: 9 Sep 2026. Review cadence: quarterly. Owner: Security & Compliance.

Where we stand

Current compliance posture, stated plainly

We would rather tell you exactly where we are than imply more than we have earned. FTR42 is mid-programme on SOC 2 Type II. No audit report exists yet, and we do not claim one.

SOC 2In progressControls implemented and monitored in Vanta. No Type I or Type II report is issued. Do not treat this page as a certification.
Trust CenterSparsetrust.valspark.ai exists. It does not yet list subprocessors or FAQs. Do not treat it as an SLA. This page and the Terms are the public record.
Written policies16 approvedAll sixteen Vanta policies are approved and actively maintained.
Continuous monitoringVantaInfrastructure, identity and endpoint checks run automatically rather than at audit time only.

We hold no ISO 27001, HIPAA or PCI DSS attestation, and we do not represent ourselves as certified under any framework we have not completed.

01  /  Governance

Sixteen approved policies

Approved policies are version-controlled in Vanta and renewed on an annual cycle.

Access Control Policy
Asset Management Policy
Business Continuity & Disaster Recovery Plan
Code of Conduct
Cryptography Policy
Data Management Policy
Human Resource Security Policy
Incident Response Plan
Information Security Policy (AUP)
Information Security Roles and Responsibilities
Operations Security Policy
Physical Security Policy
Privacy Compliance Policy
Risk Management Policy
Secure Development Policy
Third-Party Management Policy

Risk management

We keep a risk register with inherent and residual scoring, and we run control self-assessments at least annually. Findings get an owner and a fix plan. We have no standing remediation SLA with customers unless a written SOW attaches one.

02  /  Data protection

Encryption, classification and retention

Data in transit

Confidential and sensitive data is encrypted with secure transport protocols whenever it crosses a public network. This applies to our own applications and to the interfaces we build for customers.

Data at rest

Customer data resides in managed cloud platforms, principally Supabase, AWS and Vercel, which encrypt at rest as a platform default. Privileged access to encryption keys is restricted to users with a documented business need.

Classification and retention

A data classification policy defines how information is categorised and handled, and documented retention procedures govern how long we keep it. We retain information for as long as needed to operate the service or to satisfy a legitimate business or legal requirement, and no longer.

Disposal

Electronic media holding confidential information is purged or destroyed in line with recognised practice, and a certificate of destruction is issued for each device destroyed.

Model training and AI processing

Are you training AI models on store or customer data? Outside model providers do not train on identifiable store, technician, or customer data. We run VAL through AWS Bedrock in us-west-2 under an enterprise agreement with Zero Data Retention (ZDR).

Inference calls are ephemeral. Prompts and completions are not stored on AWS. ValSpark may improve Val on de-identified, aggregated operational data inside our own systems. Identifiable records are not licensed to outside AI providers.

03  /  Infrastructure

Production is separated, restricted and logged

  • Production application access is restricted to authorised users only.
  • Production databases (Supabase) restrict privileged access to people with a business need, using unique credentials and provider MFA where we have turned it on.
  • Hosting is serverless on Vercel and managed cloud services. We do not run our own servers, SSH bastions, or a company-owned network firewall.
  • Logs come from those providers and from application logs we retain for security and operations.
  • Inventory of in-scope assets is tracked in Vanta. Some integrations (Google Workspace, Supabase) still need to be reconnected so that inventory stays complete.

Physical data centres are operated by our cloud providers. We do not claim their building access as a control we perform ourselves.

04  /  Access control

Least privilege, enforced by tooling

Access is granted on the basis of role and business need, and removed when the need ends. Identity is centralised in Google Workspace; credentials that cannot be federated are held in a managed password manager rather than in documents or chat.

  • Passwords for in-scope systems are configured according to our password policy.
  • Privileged access to production consoles, databases, and encryption-key settings is separately restricted and individually justified.
  • Access is reviewed on a defined cycle, and revoked as part of offboarding.

05  /  Secure development

How code reaches production

We run a documented development lifecycle: GitHub for source, pull-request review on main, and Vercel for production deploys. Emergency changes still go through that path unless a documented exception is recorded.

  • Vulnerability handling is an engineering duty. We do not currently publish a pentest of production or sell an intrusion-detection product to customers.
  • Control self-assessments are performed at least annually, with an owner on findings.

06  /  Incident response

What happens when something goes wrong

The Incident Response Plan is approved in Vanta. Security reports go to security@ftr42.com.

If we confirm a security incident affecting customer materials on systems we operate, we notify the affected customer without unreasonable delay. This page does not publish an uptime percentage or a breach-notification clock. Any service level lives in a written agreement.

A Business Continuity and Disaster Recovery plan is approved. It covers how we keep operating if key people are unavailable.

If you think you found a vulnerability in something we operate, write to the address below. We will acknowledge the report and keep you informed as we work it.

07  /  People

The smallest attack surface is a well-run team

FTR42 is a small, senior team, and our controls are built for that shape rather than borrowed from a larger one.

  • A Code of Conduct and Human Resource Security Policy are approved in Vanta, outlining clear standards and expectations across all personnel.
  • Security responsibilities are assigned to named individuals, not left implicit.

08  /  Subprocessors

Who else touches the data

We assess third parties before we adopt them and review them on a recurring basis under our Third-Party Management Policy. The providers below support delivery of our services.

Current subprocessors and infrastructure providers
ProviderPurposeRisk tier
Amazon Web ServicesCloud infrastructure, Bedrock us-west-2 model inference (Claude, Titan) under enterprise agreement with Zero Data Retention (ZDR). Outside providers do not train on identifiable shop data.Critical
SupabaseApplication database and authenticationCritical
Google WorkspaceIdentity, email, documentsCritical
GitHubSource controlCritical
VercelApplication hostingHigh
AnthropicIn-app assistant and coaching textHigh
Apple / GoogleApp distribution, push, device speech-to-textHigh
StripeShop billing when the owner connects paymentHigh
BitwardenCredential managementHigh
VantaCompliance monitoring (not a ValSpark data processor for shop records)High
ResendFTR42 transactional email-
TwilioFTR42 marketing/lead SMS only; not ValSpark staff SMS-
TangoDigital gift card and rewards procurement conduit for ValSpark employee recognitionHigh
OpenAIOptional Whisper fallback for call audio. In scope only if that production key is live.-

Risk tiers reflect our internal inherent-risk assessment. Where a tier is not shown, the provider is in scope of our register but not yet tiered. OpenAI Whisper is optional and only in scope if that production key is live. Tango receives employee name, delivery email or phone, and award amount. It does not receive repair-order data.

09  /  Documents

What is public, and what stays internal

These are the customer-facing papers. Vanta policy PDFs stay internal.

Public documents
DocumentWhereStatus
This security pageftr42.com/company#securityPublic
ValSpark staff privacyvalspark.ai/privacyPublic
Peer benchmarks noticevalspark.ai/privacy/peer-benchmarksSign-in required
ValSpark shop termsvalspark.ai/termsSign-in required
Future 42 Terms of Serviceftr42.com/company#termsPublic
Company privacyftr42.com/privacy-policyPublic
Vanta policies (16)Internal. Listed by name above.Internal

10  /  Contact

Reporting a vulnerability, or asking for more

Security reports: security@ftr42.com

Privacy and support: scale@ftr42.com (two business days, see valspark.ai/support)

Terms: ftr42.com/company#terms and valspark.ai/terms

Updates: ftr42.com/company#updates (public product change log)

Prospects, customers and auditors who need more than this page (control evidence, the policy set, a questionnaire, or an NDA first) should write to us. We will route it the same week.

This page is maintained by the Security & Compliance owner named above, reviewed quarterly, and re-confirmed whenever our practices, audits or policies change.

Updates

Product changes for shop crews and owners.

31 Aug 2026

VAL rename and chat fix

  • The in-app assistant is now VAL. It was previously called B.O.B.
  • VAL chat threads that failed to load for some users now open.
  • VAL no longer shows the model scratchpad while it thinks.

For help using ValSpark, visit the product guide or contact support.

Terms

Read the full Terms of Service for Future 42, including service scope, responsibilities, fees, and dispute resolution.

Read full terms details

Future 42, Inc. · Effective May 23, 2026

These Terms of Service (“Terms”) form a binding legal agreement between you, or the business you represent (“Client,” “you,” or “your”), and Future 42, Inc., doing business as FTR42 (“FTR42,” “we,” “us,” or “our”). They cover this website, ValSpark (hosted software for automotive service shops), and any other product or work we provide under an order form or statement of work (collectively, the “Services”). By accessing the Services, requesting a proposal, engaging FTR42, signing an order form or statement of work, paying an invoice, or otherwise using any deliverable provided by us, you agree to be bound by these Terms. If you do not agree, do not use the Services.

1. Who We Are and What We Do

Future 42, Inc. is a Utah software company. Our primary product is ValSpark, hosted workforce software for tire and auto service shops. Shop-facing terms for that product also appear at valspark.ai/terms. We may also build or operate other software, integrations, or marketing systems under a written order form or SOW. Those engagements are Services under these Terms. They are not the public description of the company. We are not the manufacturer, vendor, host, or operator of any underlying AI model, hyperscaler platform, advertising network, messaging provider, payment processor, data store, or other third-party technology that any Service may rely upon, and we make no representations on behalf of any such third party.

2. Definitions

  • “AI Output” means any text, image, audio, video, embedding, classification, decision, code, plan, recommendation, or other artifact produced in whole or in part by a machine-learning model, agent, or other automated system used in connection with the Services.
  • “Client Materials” means any data, content, brand assets, accounts, credentials, prompts, customer lists, documents, or other materials you provide, make accessible, or instruct us to use.
  • “Deliverables” means any tangible artifact, codebase, model configuration, prompt, agent, workflow, report, documentation, or recommendation produced for you under an SOW or engagement letter.
  • “SOW” means a statement of work, order form, engagement letter, or written proposal accepted by both parties.
  • “Third-Party Services” means any product, platform, model, API, application, hosting service, dataset, library, or other offering owned or operated by a party other than FTR42, including without limitation Anthropic, OpenAI, Google, Microsoft, Meta, Amazon Web Services, Vercel, Supabase, Twilio, Resend, Stripe, and any other vendor, model provider, platform, integration, or open-source project used in or alongside the Services.

3. Eligibility and Authority

You must be at least 18 years old and have full legal authority to bind the business on whose behalf you engage FTR42. You are responsible for keeping your account credentials confidential and for every action taken under your account. Notify us promptly of any suspected unauthorized access.

4. Engagement, Scope, and Changes

Each engagement is governed by these Terms together with the applicable SOW or ValSpark order form. Hosted ValSpark access is a Service even when there is no consulting SOW. The SOW or order form controls scope, fees, milestones, deliverables, timelines, and any service-specific obligations. In the event of a conflict between these Terms and an SOW, the SOW controls only for that engagement. Anything outside the SOW (additional features, new integrations, scope expansions, extra rounds of revision, emergency support, or work on systems we did not originally build) is out of scope and may be quoted separately. Verbal requests, chat messages, and emailed asks do not change the SOW unless reflected in a written amendment signed by both parties.

5. Fees, Invoicing, and Refunds

Fees are stated in your SOW. Unless your SOW says otherwise: (a) recurring retainer fees are billed monthly in advance and non-refundable once paid; (b) project fees are billed at signature and at milestone, and once a milestone is delivered the fee for that milestone is non-refundable; (c) usage-based fees (including third-party API spend, model inference costs, advertising spend, hosting, telephony, SMS, email, and other pass-through costs) are either invoiced separately or billed directly to you by the third-party provider; (d) overdue amounts accrue interest at the lesser of 1.5% per month or the maximum permitted by law and may result in suspension. You authorize us to act on your behalf with any provider you have connected to us solely to deliver the Services, and you are solely responsible for charges incurred on your own provider accounts.

6. Your Responsibilities and Human Oversight

  • Provide complete, accurate, and lawful Client Materials, credentials, instructions, and approvals on a timely basis.
  • Hold all rights, licenses, and consents necessary for us to process Client Materials and to deploy the Services for your stated purpose.
  • Designate qualified personnel to review, test, validate, and approve every AI Output and Deliverable before relying on it, publishing it, sending it to a customer, or using it to make any decision that affects a person, account, transaction, or regulated matter.
  • Maintain a human-in-the-loop for any consequential or customer-facing use of AI Outputs. You acknowledge that AI is a tool, not a decision-maker, and that final responsibility for any action taken in reliance on AI Output rests with you.
  • Comply with all laws, regulations, industry rules, and platform policies (including those of Third-Party Services) that apply to your business, your customers, your data, your jurisdiction, and your use of the Services.
  • Keep your own backups, exports, and copies of any Client Materials, Deliverables, leads, configurations, or logs that you cannot afford to lose. We do not warrant that any system we operate or integrate will retain data indefinitely.
  • Promptly respond to suspected security incidents, lead notices, opt-out requests, model misbehavior, or other operational issues that we surface to you.

7. Artificial-Intelligence Disclosures and Risk Acknowledgements

You acknowledge and accept that artificial intelligence and large-language-model systems are probabilistic, evolving, and imperfect technologies. In particular:

  • AI Outputs may be inaccurate, incomplete, outdated, biased, offensive, harmful, defamatory, or fabricated (commonly called “hallucinations”), and may appear confident or authoritative while being wrong.
  • The same prompt or input may produce different outputs at different times, on different models, or after a model update. Reproducibility is not guaranteed.
  • Model providers may deprecate, retrain, retire, rate-limit, or change the behavior, pricing, availability, or output of any model at any time without notice, which may degrade or break workflows built on those models.
  • AI systems can leak, memorize, or surface unexpected patterns from training data, prior conversations, or user input. Do not submit data to any AI system unless you are authorized to do so and are comfortable with the residual risk.
  • AI Outputs do not constitute legal, medical, financial, tax, engineering, psychological, or other professional advice, and must not be used as a substitute for advice from a licensed professional or for required human review under any applicable regulation.
  • We do not warrant any particular accuracy rate, latency, availability, conversion, lead volume, cost-per-lead, revenue, ROI, ranking, click-through rate, deliverability, or other business outcome from any AI System or Deliverable.

You assume sole responsibility for evaluating the fitness, accuracy, and appropriateness of AI Outputs for your use case and for any decision, communication, transaction, or content you publish or act on based on those outputs.

8. Third-Party Services and Dependencies

The Services rely on, integrate with, or are delivered through Third-Party Services. We are an integrator and operator on top of those systems; we do not control them and we are not their agent. By engaging FTR42 you understand and agree that:

  • Your use of any Third-Party Service is subject to that provider's terms of service, acceptable-use policy, privacy policy, and data-processing terms. You are responsible for reviewing and complying with those terms.
  • Third-Party Services may experience outages, errors, latency, data loss, security incidents, policy enforcement actions, account suspensions, ad disapprovals, page restrictions, model deprecations, API changes, breaking schema changes, rate limits, pricing changes, region restrictions, or unilateral termination, any of which may interrupt, degrade, or end your use of the Services. FTR42 is not liable for any such event.
  • We do not guarantee that any specific Third-Party Service will remain available, supported, compatible, or cost-effective, and we may need to migrate to, substitute, or remove a Third-Party Service in response to changes outside our control.
  • Where a Third-Party Service is unavailable, has a bug, makes a policy decision, suspends your account, throttles your usage, charges you, loses your data, or otherwise causes harm, your recourse is against that provider under its terms, not FTR42.

9. Acceptable Use

You will not, and you will not permit any user, employee, contractor, or downstream party to, use the Services to:

  • Violate any law, regulation, court order, sanctions regime, or export-control restriction, or infringe any intellectual property, privacy, publicity, or other right of any third party.
  • Generate, distribute, or facilitate child sexual abuse material, non-consensual intimate imagery, content that sexualizes minors, material that facilitates real-world violence or terrorism, instructions for weapons of mass destruction, or content promoting self-harm.
  • Conduct fraud, scams, phishing, spam, market manipulation, unauthorized data scraping, credential stuffing, deepfake impersonation, election interference, or any other deceptive or abusive activity.
  • Make consequential decisions about employment, housing, credit, insurance, benefits, immigration, criminal justice, healthcare treatment, or other regulated determinations using AI Output alone, without human review and without complying with the laws that govern those decisions.
  • Submit to any AI system protected health information, payment card data, government-identifier data, biometric identifiers, children's personal information, or any other category of sensitive personal data, unless we have agreed in writing to process such data and the underlying providers permit it.
  • Reverse-engineer, decompile, scrape, train competing models on, or extract underlying model weights, prompts, or proprietary methodology from the Services, except to the extent that this restriction is unenforceable under applicable law.

We may suspend or terminate the Services, remove content, or report activity to the relevant provider or authority if we reasonably believe a violation has occurred. Suspension or termination for a violation does not entitle you to any refund.

10. Regulated Industries and Compliance

Unless we have signed a separate written agreement that says otherwise: (a) the Services are not HIPAA-compliant and we are not a Business Associate; (b) the Services are not designed for processing data subject to GLBA, FERPA, COPPA, PCI-DSS, FedRAMP, ITAR/EAR, or other regulated regimes; (c) we make no representation that any Deliverable conforms to the EU AI Act, any U.S. executive order or state law on AI, the GDPR, the CCPA/CPRA, or any sector-specific rule; and (d) if you operate in a regulated industry or in a jurisdiction that imposes AI-specific obligations, you are solely responsible for identifying, complying with, and demonstrating compliance with those obligations. Tell us up front, in writing, before you submit regulated data or deploy a Deliverable for a regulated use case.

11. Data, Privacy, and Confidentiality

You retain all rights in Client Materials. You grant FTR42 a worldwide, non-exclusive, royalty-free license to host, copy, transmit, transform, analyze, and otherwise process Client Materials solely as necessary to provide the Services, maintain the Services, and improve the Services in a manner that does not identify you. We process personal data in accordance with our Privacy Policy. Each party will protect the other's non-public information with the same care it uses for its own confidential information, and at minimum reasonable care, and will not disclose it except as needed to perform under these Terms or as required by law. If FTR42 confirms a security incident affecting Client Materials on systems under our operational control, we will notify you without unreasonable delay. You acknowledge that AI provider terms vary on training-data use and that you are responsible for selecting providers whose data-handling commitments meet your requirements. We do not promise a numeric uptime target, an intrusion-detection product, or a penetration test of production unless a written SLA or SOW says otherwise.

12. Intellectual Property

FTR42 owns and retains all right, title, and interest in and to its pre-existing tools, methodology, frameworks, prompts, libraries, internal software, configurations, templates, training materials, know-how, and any improvements to the same, even when those items appear in Deliverables. Subject to your payment of all fees due, FTR42 grants you a non-exclusive, non-transferable, worldwide license to use the Deliverables for your internal business purposes. Where Deliverables include AI Outputs, you understand that AI Outputs may not be eligible for copyright protection in some jurisdictions, that ownership of such outputs may be governed by the originating model provider's terms, and that we make no warranty regarding their non-infringement, originality, or copyrightability. You retain all rights in Client Materials.

13. Service Levels and Availability

Unless a written SLA is attached to your SOW, the Services are provided on a commercially reasonable-efforts basis with no uptime, availability, response-time, throughput, accuracy, or performance guarantee. Scheduled maintenance, third-party outages, model deprecations, account-level enforcement actions, and force-majeure events are not breaches of these Terms or any SLA.

14. Disclaimer of Warranties

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE SERVICES, DELIVERABLES, AI OUTPUTS, AND ANY THIRD-PARTY SERVICES ACCESSED THROUGH US ARE PROVIDED “AS IS” AND “AS AVAILABLE,” WITH ALL FAULTS, AND WITHOUT WARRANTY OF ANY KIND. FTR42 DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING WITHOUT LIMITATION ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, COMPLETENESS, QUIET ENJOYMENT, OR ANY WARRANTY ARISING OUT OF COURSE OF DEALING OR USAGE OF TRADE. FTR42 MAKES NO WARRANTY THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, SECURE, FREE OF HARMFUL CODE, OR THAT ANY AI OUTPUT WILL BE ACCURATE, TRUTHFUL, NON-INFRINGING, OR FIT FOR ANY PURPOSE.

15. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW: (A) IN NO EVENT WILL FTR42, ITS AFFILIATES, OR ITS OR THEIR OFFICERS, DIRECTORS, EMPLOYEES, CONTRACTORS, OR AGENTS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF REVENUE, PROFITS, GOODWILL, USE, DATA, LEADS, CUSTOMERS, OR BUSINESS OPPORTUNITY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES; (B) FTR42'S AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS, THE SERVICES, OR ANY DELIVERABLE, WHETHER IN CONTRACT, TORT, STRICT LIABILITY, OR OTHERWISE, WILL NOT EXCEED THE GREATER OF (i) THE FEES ACTUALLY PAID BY YOU TO FTR42 UNDER THE APPLICABLE SOW IN THE THREE (3) MONTHS IMMEDIATELY PRECEDING THE FIRST EVENT GIVING RISE TO THE CLAIM, OR (ii) ONE HUNDRED U.S. DOLLARS ($100); AND (C) IN NO EVENT WILL FTR42 BE LIABLE FOR DAMAGES CAUSED BY THIRD-PARTY SERVICES, AI OUTPUTS, MODEL DEPRECATIONS, PROVIDER OUTAGES, POLICY ENFORCEMENT ACTIONS, ACCOUNT SUSPENSIONS, OR EVENTS OUTSIDE OUR REASONABLE CONTROL. THE FOREGOING LIMITATIONS APPLY EVEN IF ANY LIMITED REMEDY IS FOUND TO HAVE FAILED OF ITS ESSENTIAL PURPOSE.

16. Indemnification

You will defend, indemnify, and hold harmless FTR42, its affiliates, and its and their officers, directors, employees, contractors, and agents from and against any claim, demand, action, proceeding, loss, liability, damage, fine, penalty, cost, or expense (including reasonable attorneys' fees and costs) arising out of or related to: (a) Client Materials, including any allegation that they infringe, misappropriate, or violate the rights of any third party; (b) your use of the Services, AI Outputs, or any Deliverable, including any decision you make or content you publish in reliance on them; (c) your violation of these Terms, your SOW, any applicable law, or any Third-Party Service's terms; (d) any data, leads, customers, or end users you generate or interact with through the Services; and (e) your acts or omissions, including those of your personnel, vendors, and downstream users.

17. Term, Suspension, and Termination

These Terms apply for as long as you use the Services or have an active SOW with us, whichever is longer. Either party may terminate the Services in accordance with the notice period in the applicable SOW, or, if no notice period is specified, on thirty (30) days' written notice. Either party may terminate immediately for the other party's material breach that remains uncured ten (10) days after written notice. We may suspend or terminate the Services immediately and without refund if (a) you fail to pay a past-due invoice, (b) you violate Section 9 (Acceptable Use), (c) continued provision of the Services would create a security, legal, or compliance risk for us or a Third-Party Service, or (d) a Third-Party Service terminates access required to deliver the Services. Upon termination, all unpaid fees become due, your license to the Services and Deliverables ends except as the SOW expressly says otherwise, and we will provide a reasonable opportunity for you to export your data.

18. Force Majeure

Neither party will be liable for any failure or delay caused by events beyond its reasonable control, including acts of God, war, terrorism, civil unrest, government action, sanctions, pandemics, labor disputes, internet or telecommunications failures, cyber attacks, denial-of-service events, third-party-service outages, AI-model deprecations or behavior changes, supplier failures, and other events of force majeure.

19. Subcontractors and Subprocessors

We may use subcontractors and subprocessors (including Third-Party Services) to deliver the Services. We remain responsible for their performance of obligations we owe you under these Terms, but not for matters governed by their own terms with you.

20. Modifications to These Terms

We may update these Terms from time to time. When we do, we will update the “Effective” date at the top and, where changes are material, take reasonable steps to notify you through the Services, by email, or by another reasonable means. Your continued use of the Services after an update takes effect constitutes acceptance of the updated Terms. If you do not agree, stop using the Services.

21. Governing Law and Venue

These Terms are governed by the laws of the State of Utah, without regard to its conflict-of-laws principles, and excluding the U.N. Convention on Contracts for the International Sale of Goods. Subject to Section 22, any action arising out of or relating to these Terms will be brought exclusively in the state or federal courts located in Salt Lake County, Utah, and the parties consent to the personal jurisdiction of those courts and waive any objection based on venue or forum non-conveniens.

22. Dispute Resolution; Class Waiver

Before filing any claim, the parties will attempt in good faith to resolve the dispute through written notice and a 30-day negotiation period. If the dispute is not resolved, either party may, at its option, submit the dispute to binding, confidential arbitration administered by JAMS under its Streamlined Arbitration Rules, seated in Salt Lake County, Utah, before a single arbitrator. Judgment on the award may be entered in any court of competent jurisdiction. Notwithstanding the foregoing, either party may seek temporary or preliminary injunctive relief in court to protect intellectual property, confidential information, or to enjoin a violation of Section 9. THE PARTIES WAIVE ANY RIGHT TO BRING OR PARTICIPATE IN A CLASS, COLLECTIVE, OR REPRESENTATIVE ACTION.

23. Notices

Notices to FTR42 must be sent in writing to scale@ftr42.com. Notices to you may be sent to the email address on file with us or delivered through the Services. Notices are effective on delivery if by hand or recognized courier, on confirmed transmission if by email, or three (3) business days after dispatch if by certified mail.

24. Assignment

You may not assign or transfer these Terms or any SOW, by operation of law or otherwise, without our prior written consent. We may assign these Terms in connection with a financing, merger, acquisition, reorganization, or sale of all or substantially all of our assets. Any assignment in violation of this Section is void.

25. Independent Contractors; No Agency

The parties are independent contractors. Nothing in these Terms creates a partnership, joint venture, agency, fiduciary, or employment relationship. Neither party has authority to bind the other.

26. Publicity

You agree that we may identify you as a client and use your name and logo in factual references on our website, marketing materials, and proposals. Either party may revoke this consent by written notice for use going forward.

27. Survival

The provisions of these Terms that by their nature should survive termination will survive, including Sections 5, 7 through 16, and 17 through 28.

28. Miscellaneous

These Terms, together with the applicable SOW or ValSpark order form and any document they incorporate by reference, constitute the entire agreement between the parties and supersede all prior or contemporaneous agreements on the subject matter. If any provision is found unenforceable, the remaining provisions will remain in full force. A failure to enforce any provision is not a waiver. Any waiver must be in writing and signed by the waiving party. Headings are for convenience only. The English-language version of these Terms controls in case of translation.

29. Contact

Data deletion

Email scale@ftr42.com with the subject “Data Deletion Request.” Include your name and the email, phone number, or social profile associated with your data. We acknowledge requests within 5 business days and complete deletion within 30 days, subject to the retention exceptions below.

Read full data deletion details

FTR42 · Effective April 23, 2026

FTR42 (“FTR42,” “we,” “us”) respects your right to control the personal information we hold about you. This page explains how to request deletion of your data, including data associated with your Facebook or Instagram account that you connected to FTR42, and data we received through lead forms or SMS opt-ins.

What Data We Store

  • Contact information you submitted through a lead form or SMS opt-in (name, email, phone number, address, project details).
  • Meta ad account performance data, campaign configuration, and lead submissions collected on behalf of FTR42 clients who connected their Meta account to our platform.
  • Account information for FTR42 client users (name, email, business profile, login credentials).

How to Request Deletion

To request deletion of your personal data, send an email to scale@ftr42.com with the subject line “Data Deletion Request” and include:

  • Your full name.
  • The email address, phone number, or Facebook/Instagram profile associated with the data you want deleted.
  • Optionally, the business name or campaign you believe the data was submitted to, so we can locate it faster.

We will acknowledge your request within 5 business days and complete the deletion within 30 days. We will confirm by email when the deletion is complete.

Disconnecting FTR42 From Your Facebook Account

If you previously authorized the FTR42 app to access your Facebook or Instagram account and want to remove that authorization:

  1. Open Facebook and go to Settings & privacy → Settings.
  2. Click Apps and websites in the left sidebar.
  3. Find FTR42 in the list of active apps.
  4. Click Remove, and in the confirmation dialog, check the box to also delete all posts, photos, and videos associated with the app, then confirm.

Removing app authorization in Facebook revokes FTR42's access to your account going forward, but does not by itself delete data FTR42 already has. To delete that data, also email us using the instructions above.

What We May Retain

We may retain a limited record of your deletion request (e.g. email address and date) to confirm compliance, and we may retain information required to satisfy legal, tax, accounting, or fraud-prevention obligations. Any retained data will be kept only for as long as required and will not be used for marketing.

Contact

SMS opt-in

SMS notifications require your consent. Message and data rates may apply. Reply STOP to opt out or HELP for assistance. The details below explain consent, message types, frequency, and privacy.

Read full sms opt-in details

FTR42 · Effective April 21, 2026

FTR42 offers SMS text notifications to keep you updated on new leads, account activity, and service-related messages. This page explains what you are agreeing to when you opt in.

How to Opt In

You opt in to receive SMS messages from FTR42 by:

  • Submitting a form on this site or a FTR42 client site that includes an SMS consent checkbox, and checking that box.
  • Replying START or YES to a confirmation text from one of our phone numbers after initial form submission.
  • Providing your phone number directly to a FTR42 team member and confirming you would like SMS updates.

What You Will Receive

  • Transactional lead alerts— when a prospect submits a form that routes to your FTR42-managed account, we send you an SMS with the lead's contact information so you can respond promptly.
  • Account notifications — service confirmations, appointment reminders, or updates related to your engagement with FTR42.
  • Support messages — replies to support questions you have initiated with us.

We do not send promotional or marketing SMS messages. Our SMS program is limited to transactional and account-related notifications only.

Message Frequency

Message frequency varies based on your activity and the number of leads your account receives. You may receive several messages per day during high-activity periods, or no messages for extended periods when there is no activity. You are only texted in response to actions on your account.

Costs

Message and data rates may apply.Check with your mobile carrier for details about the rates applied to text messages. FTR42 does not charge any fee for receiving SMS; your carrier's standard rates are the only charges.

How to Opt Out

You can opt out at any time by replying STOP to any message you receive from us. You will receive a single confirmation that you have been unsubscribed, and you will not receive further SMS messages from that number. You may also email scale@ftr42.com to request removal from our SMS list.

Help

Reply HELP to any message from us and you will receive our contact information and instructions for managing your SMS preferences.

Privacy

Information you provide is handled according to our Privacy Policy. Your phone number and SMS consent are never sold or shared with third parties for marketing or promotional purposes.

Supported Carriers

FTR42 SMS is supported on all major US carriers (AT&T, T-Mobile, Verizon, US Cellular, and others). Delivery may vary based on carrier capability. Carriers are not liable for delayed or undelivered messages.

Contact

Questions about this SMS program can be sent to: