Legal and regulatory
Privacy Policy
How Northstar collects, uses, shares, protects, and retains personal information.
1. Who is responsible
The Northstar operating entity identified in your order form is accountable for personal information it controls. A property management customer is generally responsible for the applicant information it asks Northstar to process. Contact privacy@northstar.example to reach the Privacy Officer.
2. Information we collect
Identity and communication data include name, email, phone number, and messages. Financial data may include account-holder name, consented account summaries, deposit amounts, payment references, and settlement status. Technical and usage data include IP address, browser, device, session security events, pages visited, and actions taken.
- We do not ask for online-banking passwords.
- Plaid handles bank connection credentials in its interface.
- Report views intentionally exclude full account and transaction identifiers where they are not needed.
3. Purposes and authority
We use information to provide verification and deposit services, prevent abuse, secure accounts, support users, reconcile trust records, meet legal duties, and improve reliability. We rely on consent where required, contractual necessity for customer services, and legitimate operational or legal requirements where permitted.
4. How information arrives
Information comes directly from users, from the organization managing an application, from authorized integrations such as Plaid and payment providers, and automatically through security and service logs.
5. Service providers and transfers
We may use Supabase for databases and authentication, Vercel for application hosting, Plaid for bank connections, Resend or another configured provider for email, and Canadian payment-network participants for payment processing. Some providers may process information in the United States or other countries, where it can be subject to local law. The Security settings page shows configured residency controls.
6. Retention
We keep personal information only as long as needed for the stated purpose, contractual commitments, security, dispute handling, and legal obligations. Customer-configured retention applies where available; protected financial and audit records may be retained longer. Information is securely deleted or de-identified when no longer required.
7. Safeguards and incidents
Safeguards include encryption in transit, restricted service credentials, organization isolation, role-based access, MFA for sensitive actions, audit records, and monitoring. No system is risk-free. We investigate incidents and provide required notices.
8. Your choices and rights
Subject to applicable law, you may ask for access, correction, an explanation of use and disclosure, or withdrawal of consent. Withdrawal may prevent us from providing a requested feature. You may challenge our compliance with the Privacy Officer and complain to the Office of the Privacy Commissioner of Canada or the applicable provincial regulator.
9. Cookies, children, and changes
The Cookie Policy explains browser storage and optional analytics. The service is not intended for children under 18. We will post updates here and give appropriate notice of material changes.
Northstar