Privacy policy
What Northpoint collects, why we collect it, who touches it, and the choices you have. This policy is written to describe what the product actually does — nothing more.
Last updated: [DATE — set at legal sign-off]
1. Who we are
Northpoint is a CRM for US real estate agents and teams, operated by Bridge Elevate LLC, a Utah limited liability company (“we”, “us”). This policy covers the Northpoint app and this marketing site. You can reach us about anything in it at support@northpointcrm.com.
2. Two kinds of personal data
Northpoint handles two distinct kinds of personal data, and the difference matters:
- Your data — the account and billing information you give us as our customer. For this data, we decide how it's used, as described in this policy.
- Your contacts' data — the CRM records you store about your clients and contacts. This data belongs to you and your workspace. You control it; we process it only to run the service for you, on your instructions (see section 6).
3. What we collect
Account information. Email address, display name, and password (stored hashed by our authentication provider), plus optional profile details — title, phone number — your timezone, and the US state of residence you attest at signup.
CRM content you store. Contacts, deals, tasks, appointments, notes, documents, files, and the rest of the working data you and your workspace members put into Northpoint.
Billing information. Payments are handled by Stripe; your card number never touches our servers. We keep your plan, subscription status, invoice records, and the billing address state and country Stripe reports to us (used for tax and for the state availability program).
Usage and diagnostics. We use Sentry for error and performance monitoring, including session replay inside the signed-in app. Replay is configured with personal-data masking on: all text is masked, all inputs are masked, and media is blocked, so your CRM content and your contacts' details are not captured in recordings. Replay never runs on this marketing site. We configure our monitoring not to attach IP addresses or request headers by default. If you send feedback through the in-app widget, we receive the message you write along with your user and workspace context.
Availability (geo) checks. To run the state availability program, we derive a country and region code from your IP address at request time, make the availability decision, and log the decision with the country/region code only — we do not store raw IP addresses for these decisions. Logs of blocked requests are kept for 30 days.
Messages you send us. If you email us or use the contact form, we keep the message and your contact details so we can respond.
4. Cookies
We use functional cookies only:
- Session cookies that keep you signed in (set by our authentication provider, Supabase).
- np_geo, which remembers the result of the availability check so we don't re-derive it on every request.
We don't use advertising cookies, cross-site tracking cookies, or third-party analytics beyond the diagnostics described above.
5. How we use your information
- to provide, operate, and secure the service;
- to bill you and manage your subscription;
- to run the state availability program described in the terms of service;
- to respond to support requests and feedback;
- to diagnose errors and improve the product;
- to send you service emails about your account, billing, and material changes (these aren't marketing);
- to comply with the law.
We do not sell personal data — yours or your contacts' — and we don't share it for advertising.
6. Your contacts' data
Agents and teams using Northpoint are responsible for the contact data they store: they decide what goes in, who in their workspace can see it, and when it's deleted. We host and process that data solely to run the service, on the workspace's instructions.
If you're a client or contact of a Northpoint user and want your information corrected or deleted, the agent or brokerage you work with controls that record — contact them first. If you can't reach them, write to us at support@northpointcrm.com and we'll help route the request.
Northpoint gives workspaces the tools to honor these requests: records can be deleted (deleted records sit in a trash area for 30 days, where they can be restored or removed), and full data can be exported at any time.
7. Service providers
We share data only with the providers that run the service:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting and edge network.
- Stripe — payments; Stripe collects and holds your payment details and billing address.
- Sentry — error monitoring and masked session replay, as described in section 3.
If you connect or use these optional features, the relevant provider also applies:
- Google — if you sign in with Google or connect calendar sync.
- Resend — if you use email features, to deliver your messages.
- Twilio — if you use text-messaging features, to deliver your messages.
Each provider processes data only to provide its service to us. Data is stored in the United States. [OWNER: confirm — the production database is US-hosted; verify the same holds for all providers before sign-off.]
8. Other sharing
Beyond service providers, we disclose personal data only: within your workspace according to the roles and visibility settings your workspace has chosen; when the law requires it (for example, a valid legal request); to protect the rights, safety, or security of the service and its users; or as part of a merger, acquisition, or sale of the business — in which case this policy continues to apply to your data and we'll notify you of any change. [LAWYER: review the business-transfer clause.]
9. Retention
- Account and CRM data: kept while your account is active.
- Deleted records: recoverable from trash for 30 days, then removed.
- Lapsed subscriptions: your workspace becomes read-only and the data is retained so you can come back or export it (see the terms of service for archive timing).
- Availability-check block logs: 30 days.
- Backups: [OWNER: confirm backup retention window with the hosting provider before sign-off.]
10. Export and deletion
You can export your workspace's data at any time from Settings → Data → Export, as CSV or JSON, per data type — no lock-in. To delete your account and its data, email support@northpointcrm.com and we'll complete the deletion within a reasonable time, except where we're required to keep records (for example, invoices for tax purposes). [OWNER: confirm the deletion turnaround you want to commit to, and whether self-serve account deletion ships before launch.]
11. Security
Data is encrypted in transit. Access to workspace data is isolated per workspace and enforced at the database layer, and access within a workspace follows the roles and visibility rules its owner sets. No method of storage or transmission is perfectly secure, but we design for the boring, durable protections first. If a breach affects your data, we'll notify you as required by law.
12. Your privacy rights
Depending on your state of residence, you may have rights over your personal data — such as the right to access it, correct it, delete it, or receive a copy. To exercise any of these, email support@northpointcrm.com; we'll verify the request and respond as applicable law requires. We honor these requests regardless of which state you live in where we reasonably can.
An honest note on scope: Northpoint launches in states without comprehensive consumer privacy statutes, and this policy doesn't claim certification under any specific regime. As we expand into states with comprehensive privacy laws, we'll update this policy with the specific disclosures those laws require. [LAWYER: add state-specific rights disclosures as the availability list expands.]
13. Children
Northpoint is a business tool for adults. It isn't directed at anyone under 18, and we don't knowingly collect personal data from children. If you believe a child has provided us data, contact us and we'll delete it.
14. Changes to this policy
We'll update this policy when the product's data practices change. If a change is material, we'll notify you by email or in the app before it takes effect, and the “last updated” date above will change.
15. Contact
Privacy questions and requests: support@northpointcrm.com. Brokerages and teams that need a data processing agreement can request one at the same address. [LAWYER: prepare the B2B DPA template referenced here.]