Privacy Policy
Effective Date: March 1, 2026
NorthOS is operated by Apex North Enterprise, a sole proprietorship registered in Ontario, Canada.
1. Information We Collect
- Account Information — name and email via Google OAuth. We do not store your Google password.
- Business Data — transactions, revenue, expenses, business type, province, and GST/HST registration status you enter.
- Usage Data — anonymized analytics on the landing page only via Google Analytics. No tracking inside dashboard or ledger.
- Technical Data — session tokens for authentication, which expire automatically.
2. How We Use Your Information
We use your information to provide NorthOS services, calculate tax estimates and T2125 working papers, maintain your transaction history, improve the service, and communicate important updates. We never use your financial data for advertising purposes.
3. How We Store Your Information
Your data is stored in a secured cloud database with HTTPS encryption and session-based authentication. Servers are located in Canada or the United States.
4. Sharing Your Information
We do not sell or rent your personal or business data. We may share limited information only with:
- Service Providers — Google OAuth for authentication, cloud hosting providers.
- Legal Requirements — when required by law or to protect our rights.
- Business Transfer — in connection with a merger, acquisition, or sale of assets.
5. Your Rights Under PIPEDA
Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to:
- Access your personal information
- Correct inaccurate information
- Withdraw consent for data processing
- Request deletion of your data
Contact hello@northos.ca to exercise these rights. We respond within 30 days.
6. Data Retention
Your data is retained while your account is active. Upon account deletion, your data will be permanently deleted within 30 days, except where retention is required by law.
7. Children's Privacy
NorthOS is intended for adults aged 18 and older. If you believe a minor has created an account, please contact hello@northos.ca.
8. Third-Party Services
NorthOS uses the following third-party services:
- Google OAuth — for secure authentication.
- Google Analytics — landing page analytics only, not inside dashboard.
9. Third-Party AI Processing
NorthOS uses Google Gemini to power the Document Scanner and the North AI assistant. To provide these features, certain data — including receipt images, invoice content, and financial summaries relevant to your query — is transmitted to and processed by Google LLC, which may process this data outside of Canada, including in the United States. Google's processing is governed by their Privacy Policy and Terms of Service.
Your core business data, including transactions, GST records, and account information, is stored on servers located in Toronto, Canada (Microsoft Azure Canada Central) and does not leave Canada except as described above.
You may disable AI features individually at any time in Settings.
10. Changes to This Policy
We will notify you of material changes via email. The updated policy will be posted at northos.ca/privacy.