Last updated: June 18, 2026
This Privacy Policy explains how NorthernPlus Inc. ("NorthernPlus", "we", "us", or "our") collects, uses, discloses, and protects information when you visit our website, sign up for an account, or use our services. We take privacy seriously, and we structure our practices around the principle that intake data is sensitive and deserves a higher bar than typical SaaS. Your use of the service is also governed by our Master Subscription Agreement and Data Processing Addendum.
This policy applies to two distinct groups of people: Customers (the companies and staff who sign up and administer accounts) and end users (prospective and existing customers of those companies who interact with intake forms, magic-link portals, or AI voice intake calls). If you are an end user filling out a company's intake form, that company is the controller of your data. NorthernPlus processes that data on the company's behalf.
When you sign up for NorthernPlus as a customer, we collect your name, work email, company name, and phone number. When you create a workspace, we collect billing contact information (we do not store full payment card numbers; those are held by our payment processor).
When end users complete an intake form, NorthernPlus receives whatever your company has configured the form to collect. This typically includes contact information, demographic information, relevant facts, and uploaded documents. Sensitive categories may include health information, financial information, and information about minors. Where a customer's use involves protected health information subject to HIPAA, our processing of that information is also governed by a Business Associate Agreement.
We collect technical data when you use the service: IP address, browser type, device identifiers, pages viewed, time stamps, and similar telemetry. We use first-party cookies and similar technologies for session management, authentication, and core product functionality.
We also use Google Analytics (GA4) and Hotjar to understand how visitors use our marketing website. These tools may collect your IP address (anonymized), pages visited, session duration, scroll depth, clicks, and browser and device type. Analytics cookies are only loaded with your consent where required by applicable law. See Section 02 for details.
When AI voice intake is enabled by a customer, NorthernPlus (or our voice subprocessor) collects the audio of the call, the call transcript, and any structured data extracted from the conversation. Calls are recorded with prior consent disclosure to the end user, in accordance with applicable telephone consumer protection laws.
Essential cookies are required for the service to function. They manage your session, protect against cross-site request forgery, and maintain authentication state. These cookies cannot be disabled without breaking core functionality and do not require consent.
We use two analytics tools on our marketing website:
We do not use advertising cookies, retargeting pixels, or cross-site tracking technologies.
On your first visit, we detect your approximate location to determine which consent framework applies:
You can change or withdraw your consent at any time by clicking Cookie preferences in the footer of any page. Your choice is saved in your browser's local storage. You can also disable or delete cookies through your browser settings; note that disabling essential cookies will affect service functionality.
Additional opt-out tools: Google Analytics opt-out browser add-on (available at tools.google.com/dlpage/gaoptout); Hotjar opt-out at hotjar.com/legal/compliance/opt-out.
Google Analytics cookies persist for up to 24 months. Hotjar session cookies expire at the end of your browser session; Hotjar identification cookies persist for up to 365 days. Essential session cookies expire when you close your browser or log out.
We use information for the following purposes:
We do not sell personal information. We do not use identifiable intake data to train artificial intelligence models for the benefit of other customers. Where a customer enables AI features, we use that customer's intake data to serve that customer. We may use de-identified and aggregated data, usage data, and feedback to operate, secure, and improve the service and its models, as described in Sections 10 and 12 of our Master Subscription Agreement.
We share information with vendors that help us operate the service: hosting infrastructure, email delivery, authentication, payment processing, voice telephony, analytics (Google Analytics, Hotjar), and customer support. A current list of subprocessors is available on request from hello@northernplus.com. Each subprocessor is bound by contractual obligations to protect customer data.
We may disclose information when required by law, subpoena, court order, or other lawful process. Where legally permitted, we will notify the affected customer before disclosing their data.
If NorthernPlus is involved in a merger, acquisition, or sale of assets, customer information may be transferred as part of that transaction. We will provide notice before customer information is transferred and becomes subject to a different privacy policy.
We retain customer data for as long as the customer maintains an active account, plus a reasonable wind-down period after termination during which data can be exported. After that period, data is deleted from active systems on a defined schedule and from backups within ninety days.
End-user intake data (the data collected by a customer using NorthernPlus) is retained according to the customer's own retention configuration. Customers can delete or redact end-user records at any time using built-in privacy tools, subject to any recordkeeping requirements that apply to their industry and may require preservation of certain audit trails.
Telemetry and operational logs are retained for up to twelve months for security, debugging, and analytics, and then purged or anonymized.
We use commercially reasonable technical and organizational measures to protect personal information from loss, misuse, and unauthorized access. These measures include:
No system can be guaranteed perfectly secure. If we become aware of a personal data breach affecting a customer, we will notify the customer without undue delay, in accordance with applicable law and our Data Processing Addendum.
If you are located in the European Union, United Kingdom, or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR) or equivalent national law:
If you are an end user (someone who filled out an intake form for a company using NorthernPlus), direct requests to that company first. The company is the controller of your intake data. We will support the company in fulfilling them.
NorthernPlus customers may exercise rights by emailing hello@northernplus.com. We will respond within 30 days.
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with specific rights regarding your personal information.
Submit a verifiable consumer request to hello@northernplus.com with the subject line "California Privacy Request." We will respond within 45 days. If we need additional time (up to 90 days), we will notify you of the extension within the initial 45-day period.
You may designate an authorized agent to submit a request on your behalf. We may require the agent to provide written proof of authorization and may require you to verify your own identity directly.
California Civil Code Section 1798.83 permits California residents to request certain information about disclosure of personal information to third parties for direct marketing purposes. We do not disclose personal information for third-party direct marketing purposes.
NorthernPlus is not directed to children under the age of 13. We do not knowingly collect personal information directly from children under 13. Companies using NorthernPlus may collect information about minors as part of the services they provide; in those cases, the company is the controller and is responsible for applicable protections. If we become aware that we have inadvertently collected information directly from a child under 13 outside of a legitimate company-mediated intake, we will delete it.
NorthernPlus is operated from the United States, and our infrastructure is hosted primarily in the United States. If you access the service from outside the United States, your information will be transferred to and processed in the United States.
For transfers of personal data from the EU, UK, or EEA to the United States, we rely on lawful transfer mechanisms including the European Commission's Standard Contractual Clauses (SCCs), the UK Addendum to those SCCs for UK transfers, and equivalent measures for Switzerland, as set out in our Data Processing Addendum. A copy of the applicable transfer mechanism is available on request.
We may update this Privacy Policy from time to time. When we make material changes, we will notify customers by email and update the "Last updated" date at the top of this page. Continued use of the service after a material change constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or our privacy practices, contact us at:
NorthernPlus Inc.
Phone: (763) 272-7262
323 Washington Ave N, #200
Minneapolis, MN 55401
Email: hello@northernplus.com
Analytics stay off until you choose.
We use cookies to improve the site. Read our Privacy Policy to learn more.