Legal and regulatory

Privacy Policy

How Northstar collects, uses, shares, protects, and retains personal information.

Effective: July 20, 2026Last updated: July 20, 2026Version 2026.07

1. Who is responsible

The Northstar operating entity identified in your order form is accountable for personal information it controls. A property management customer is generally responsible for the applicant information it asks Northstar to process. Contact privacy@northstar.example to reach the Privacy Officer.

2. Information we collect

Identity and communication data include name, email, phone number, and messages. Financial data may include account-holder name, consented account summaries, deposit amounts, payment references, and settlement status. Technical and usage data include IP address, browser, device, session security events, pages visited, and actions taken.

  • We do not ask for online-banking passwords.
  • Plaid handles bank connection credentials in its interface.
  • Report views intentionally exclude full account and transaction identifiers where they are not needed.

3. Purposes and authority

We use information to provide verification and deposit services, prevent abuse, secure accounts, support users, reconcile trust records, meet legal duties, and improve reliability. We rely on consent where required, contractual necessity for customer services, and legitimate operational or legal requirements where permitted.

4. How information arrives

Information comes directly from users, from the organization managing an application, from authorized integrations such as Plaid and payment providers, and automatically through security and service logs.

5. Service providers and transfers

We may use Supabase for databases and authentication, Vercel for application hosting, Plaid for bank connections, Resend or another configured provider for email, and Canadian payment-network participants for payment processing. Some providers may process information in the United States or other countries, where it can be subject to local law. The Security settings page shows configured residency controls.

6. Retention

We keep personal information only as long as needed for the stated purpose, contractual commitments, security, dispute handling, and legal obligations. Customer-configured retention applies where available; protected financial and audit records may be retained longer. Information is securely deleted or de-identified when no longer required.

7. Safeguards and incidents

Safeguards include encryption in transit, restricted service credentials, organization isolation, role-based access, MFA for sensitive actions, audit records, and monitoring. No system is risk-free. We investigate incidents and provide required notices.

8. Your choices and rights

Subject to applicable law, you may ask for access, correction, an explanation of use and disclosure, or withdrawal of consent. Withdrawal may prevent us from providing a requested feature. You may challenge our compliance with the Privacy Officer and complain to the Office of the Privacy Commissioner of Canada or the applicable provincial regulator.

9. Cookies, children, and changes

The Cookie Policy explains browser storage and optional analytics. The service is not intended for children under 18. We will post updates here and give appropriate notice of material changes.

These public terms describe the platform’s standard operating position. Signed order forms and negotiated agreements control where they differ.
Northstar | Applicant Verification & Deposit Operations