Northwind Labs
Cross-border SaaS handling team account data, processing payments, using common analytics + helpdesk integrations.
Privacy Policy
Effective date: January 1, 2026
Northwind Labs ("Northwind", "we", "us") provides a collaborative workspace product at northwindlabs.example. This policy explains what personal data we collect, why we collect it, how we share it, and the rights you have over it.
1. Who this policy covers
This policy applies to everyone who visits northwindlabs.example, creates a Northwind account, or otherwise interacts with our services. It does not cover personal data we process on behalf of a customer (for example, content uploaded into a customer's workspace) — for that, the customer is the data controller and their own privacy policy governs.
2. Information we collect
Information you provide directly
When you create an account, we collect your name, email address, and a password (which we store as a salted hash, never in plaintext). If you join a team, we record which teams you belong to and your role within each. When you communicate with our support team, we keep a copy of your messages and any context you provide.
Information collected automatically
When you use Northwind, we collect:
- Account activity — when you log in, which workspaces you visit, which features you use.
- Device and connection information — browser type, operating system, IP address, approximate location derived from IP (city-level).
- Error reports — when something breaks, we collect the stack trace and the URL you were on so we can fix it.
Information from third parties
When you pay for Northwind through Stripe, we receive your name, email address, billing country, and the last four digits of your payment card. We do not receive or store full card numbers.
3. How we use information
We use the information above to:
- Operate the service: authenticate you, route your requests, send transactional emails (sign-up confirmation, password resets, billing receipts).
- Provide support: respond to your messages, troubleshoot bugs.
- Improve the product: understand which features are used and which aren't, prioritize what to build next.
- Detect and prevent abuse, fraud, and security incidents.
- Send service announcements and (with separate consent) product news.
We rely on the following GDPR legal bases:
- Contract — for everything required to deliver the service you signed up for.
- Legitimate interests — for security, fraud prevention, and product analytics conducted in privacy-preserving ways.
- Consent — for marketing communications and any non-essential cookies.
- Legal obligation — for tax and accounting records.
