← Northbound

Privacy Policy

Last updated: March 16, 2026

This Privacy Policy describes how Northbound ("Northbound", "we", "us", or "our") collects, uses, discloses, and protects your personal information when you use our services at northbound.run. We are committed to complying with the Personal Information Protection and Electronic Documents Act (PIPEDA) and the British Columbia Personal Information Protection Act (BC PIPA).

1. Information We Collect

We collect the following categories of personal information:

Account Information: When you register, we collect your name, email address, and any other information you provide during account creation.

Email Data (Gmail): With your authorization via the Gmail API, we access your email content, metadata, labels, and attachments. This includes message bodies, subject lines, sender and recipient information, and timestamps. This data is used exclusively for AI-assisted productivity features visible within Northbound's interface. Emails are only sent or modified when you explicitly initiate the action within the app.

Calendar Data (Google Calendar): With your authorization via the Google Calendar API, we access your calendar event details, including event titles, descriptions, attendees, dates, times, and locations. This data is used exclusively for scheduling assistance features visible within Northbound's interface. Calendar events are only created or modified when you explicitly initiate the action within the app.

Usage Data: We collect information about how you interact with our services, including log data, device information, IP addresses, browser type, and pages visited.

Communications: If you contact us directly, we retain records of those communications.

2. Google API Services User Data

Northbound's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, data received from Google APIs is used only to provide and improve user-facing features that are visible within Northbound's interface. We do not use Google API data for any purpose unrelated to delivering and improving your experience in the app.

No sale of Google data: We do not sell, transfer, or share Google user data with third parties for any purpose other than operating and improving the Northbound service.

No advertising use: We do not use Google API data for advertising purposes of any kind, including retargeting, personalized advertising, or interest-based advertising.

Human access restrictions: No Northbound personnel or contractors will read, view, or otherwise access the content of your Google data except in the following limited circumstances:

  • You have given explicit, affirmative consent for a specific item (for example, sharing an email thread with our support team to investigate a reported issue);
  • It is necessary to investigate a security incident, abuse, or violation of these policies; or
  • We are required to do so by applicable law.

Aggregated or fully anonymized data that cannot be linked to an individual may be reviewed for product improvement purposes.

OAuth token security: OAuth tokens issued by Google are stored in encrypted form and are revoked immediately upon disconnection of your Google account or deletion of your Northbound account.

3. Purpose of Collection

We collect and use your personal information for the following purposes:

  • Providing, operating, and maintaining the services you have requested
  • Improving user-facing features within Northbound, including AI-assisted scheduling, email management, and productivity tools
  • Personalizing your experience and improving service quality
  • Communicating with you about your account, service updates, and support requests
  • Detecting and preventing fraud, security incidents, and abuse
  • Complying with legal obligations

We rely on your consent as the primary legal basis for collecting and processing your personal information, particularly for accessing email and calendar data. You provide consent when you authorize our application to connect to your email and calendar accounts.

You may withdraw your consent at any time by disconnecting integrations through your account settings or by contacting us at hello@northbound.run. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

Under PIPEDA and BC PIPA, we are also permitted to collect and use personal information without consent where required or permitted by law.

5. Third-Party Data Subjects

When you connect your Google account, the emails and calendar events we process may contain personal information belonging to your correspondents, colleagues, and other third parties. We handle this information as follows:

  • Correspondent and third-party data is processed only to the extent necessary to provide the Northbound service to you.
  • Correspondent data is not used independently of the service, profiled, or shared with third parties.
  • We do not use correspondent data for advertising or any purpose unrelated to delivering the service.

Individuals who believe their personal information has been processed through Northbound may contact us at hello@northbound.run to request information about how their data is handled or to request deletion of any data we hold about them.

6. Subprocessors

We work with third-party service providers ("subprocessors") to help us operate, store, and process data as part of delivering our services. These subprocessors may have access to your personal information to the extent necessary to perform their functions. We require all subprocessors to maintain appropriate security and privacy standards and to process data only on our instructions.

Categories of subprocessors we use include:

  • Cloud infrastructure and hosting providers
  • Data storage and database providers
  • AI and machine learning infrastructure providers
  • Analytics and monitoring providers
  • Customer support platforms

A current list of our subprocessors is available upon request at hello@northbound.run. We will notify you of any material changes to our subprocessor list.

7. Data Ownership and Portability

You retain ownership of all personal information you provide to us, including the content of your emails and calendar events. We do not claim ownership of your data.

You have the right to access a copy of the personal information we hold about you. To request a copy of your data in a portable format, contact us at hello@northbound.run. We will respond to such requests within 30 days.

8. Data Retention and Deletion

We retain your personal information for as long as your account is active or as needed to provide the services. We may also retain certain information as required by law or for legitimate business purposes such as dispute resolution and fraud prevention.

You may request deletion of your personal information at any time by contacting us at hello@northbound.run or through your account settings. We will process deletion requests within 30 days. Note that deletion of your data may affect your ability to use certain features of the services.

Google-sourced data: If you disconnect your Google account from Northbound, Google-sourced data associated with that connection will be deleted within 30 days, even if you retain your Northbound account. Backup copies of Google-sourced data are purged within 90 days of a deletion request. OAuth tokens are revoked immediately upon disconnection of your Google account or deletion of your Northbound account.

Some residual copies of non-Google data may remain in backup systems for a limited period following deletion requests, consistent with our backup and retention schedules.

9. Data Security

We implement reasonable technical and organizational measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These measures include encryption in transit and at rest, access controls, and regular security reviews.

No method of transmission over the internet or electronic storage is completely secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.

Breach notification: In the event of a breach involving your personal information, Northbound will notify affected users within 72 hours of confirming the breach, consistent with our obligations under PIPEDA and BC PIPA.

10. Cross-Border Data Transfers

Our subprocessors may be located outside of Canada, including in the United States and other jurisdictions. When your personal information is transferred outside of Canada, it may be subject to the laws of those jurisdictions, which may differ from Canadian privacy law.

We take steps to ensure that cross-border transfers are subject to appropriate safeguards, including contractual protections with subprocessors. By using our services, you acknowledge that your information may be transferred to and processed in countries outside of Canada.

11. Your Rights Under Canadian Privacy Law

Under PIPEDA and BC PIPA, you have the following rights with respect to your personal information:

  • Access: You have the right to request access to the personal information we hold about you.
  • Correction: You have the right to request correction of inaccurate or incomplete personal information.
  • Withdrawal of Consent: You have the right to withdraw consent to our collection and use of your personal information, subject to legal or contractual restrictions.
  • Deletion: You have the right to request deletion of your personal information, subject to our legal obligations.
  • Complaint: You have the right to lodge a complaint with the relevant privacy authority (see Section 15).

To exercise any of these rights, contact us at hello@northbound.run.

12. Children's Privacy

Our services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13 without verifiable parental consent, we will take steps to delete that information promptly. If you believe we may have collected information from a child under 13, please contact us at hello@northbound.run.

13. Cookies and Tracking Technologies

We may use cookies and similar tracking technologies to operate and improve our services, remember your preferences, and analyze usage patterns. You can control cookie settings through your browser, though disabling certain cookies may affect the functionality of the services.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by displaying a prominent notice within the services. The "Last updated" date at the top of this policy reflects when the most recent changes were made. Your continued use of the services after the effective date of the updated policy constitutes your acceptance of the changes.

15. Privacy Complaints

If you have concerns about our privacy practices, please contact us first at hello@northbound.run so we have an opportunity to address your concern.

If you are not satisfied with our response, you may file a complaint with the Office of the Information and Privacy Commissioner for British Columbia:

Office of the Information and Privacy Commissioner for British Columbia Website: www.oipc.bc.ca Telephone: 250-387-5629 Toll-free: 1-800-663-7867

You may also contact the Office of the Privacy Commissioner of Canada:

Office of the Privacy Commissioner of Canada Website: www.priv.gc.ca Telephone: 1-800-282-1376

16. Contact

If you have questions or concerns about this Privacy Policy or our privacy practices, please contact us at:

Northbound British Columbia, Canada hello@northbound.run