Privacy Policy
Effective: February 26, 2026
Northy ("we", "our", or "us") is committed to protecting your privacy. This policy explains how we collect, use, disclose, and safeguard your personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
1. Accountability
We are responsible for the personal information under our control. Questions or concerns about our privacy practices can be directed to privacy@northy.ca.
2. What We Collect
We collect the following personal information:
- Email address (via the waitlist signup form) for the purpose of sending product launch notifications.
- IP address (automatically collected during signup) for the purpose of rate limiting and abuse prevention. Retained for 30 days, then deleted.
We use Umami for website analytics, which is cookie-free and does not collect any personally identifiable information. We track page interactions such as calculator usage, tab selections, and sorting preferences to understand feature usage. No personal data is included in these analytics events.
3. Purpose of Collection
We collect personal information solely for the purposes identified at or before the time of collection:
- Email: to send product launch notifications and updates you requested
- IP address: to prevent abuse through rate limiting
4. Consent
We obtain your consent through a double opt-in process. When you submit your email, we send a confirmation email. Your subscription is only activated after you click the confirmation link, providing meaningful and explicit consent.
5. Limiting Collection
We only collect information that is necessary for the identified purposes. We do not collect names, phone numbers, physical addresses, or any other personal data beyond what is listed above.
6. Limiting Use, Disclosure, and Retention
Your personal information will not be used or disclosed for purposes other than:
- Sending the notifications you subscribed to
- Preventing abuse of our services
IP addresses are automatically deleted after 30 days. Email addresses are retained until you unsubscribe.
7. Accuracy
We keep your information as accurate as necessary for the purposes for which it is used. You may update your email preferences at any time through the unsubscribe link in our emails.
8. Safeguards
We protect your information with measures appropriate to the sensitivity of the data:
- Data is stored in Supabase (PostgreSQL) with row-level security enabled
- All connections use TLS encryption in transit
- Database access requires authenticated service keys
- We conduct regular reviews of our security practices
9. Third Parties
We share personal information with the following service providers:
- Resend (email delivery): receives your email address to deliver notifications on our behalf
- Supabase (database hosting): stores your email and IP address on servers in Canada (Canada Central region)
These providers are bound by their own privacy commitments and only process data as directed by us.
10. Openness
This privacy policy is publicly available at northy.ca/privacy. We will update this policy as our practices change and notify subscribers of material changes via email.
11. Your Rights
Under PIPEDA, you have the right to:
- Know what personal information we hold about you
- Request correction of inaccurate information
- Withdraw your consent (unsubscribe) at any time
- File a complaint with the Office of the Privacy Commissioner of Canada
To exercise any of these rights, contact us at privacy@northy.ca.
12. Challenging Compliance
If you believe we are not complying with this policy or with PIPEDA, you may contact us at privacy@northy.ca. We will investigate all complaints and respond within 30 days. You may also contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.