North Metric is currently offered to US-based founders. The sections below describe the data rights we honor for all users, but the automated opt-in flows required for full EU/UK GDPR and the opt-out automation required for full CCPA / CPRA compliance are still in development. If you are an EU/UK resident, please do not create an account until those controls are live. California residents may exercise the rights described in §9.2 by emailing [email protected].
Who We Are
North Metric, Inc. (“North Metric,” “we,” “us,” or “our”) is a Delaware corporation that operates an AI-powered revenue intelligence platform (the “Service”). We connect to your Stripe account via OAuth to analyze your billing and subscription data and deliver AI-generated revenue actions.
For the purposes of the EU General Data Protection Regulation (GDPR) and UK GDPR, North Metric is the data controller responsible for your personal data when you use the Service. We determine the purposes and means of processing data collected through the Service.
Privacy contact
This contact serves as our interim privacy point of contact for all data protection inquiries, including requests from EU/UK data subjects and CCPA-related requests from California residents.
What This Policy Covers
This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, who we share it with, and what rights you have. It applies to all users of the Service, our website at northmetric.io, and any related features or tools.
This policy uses the same definitions as our Terms of Service. Key terms:
Categories of Personal Data We Collect
3.1 Account Data
When you create an account, we collect:
- Full name
- Email address
- Company name
- Password (stored as a cryptographic hash — we never store or see your plaintext password)
Source: Provided directly by you at registration via Supabase Auth.
3.2 Company Profile Data
During onboarding and in your account settings, we collect business information about your company:
- Company website URL
- Business model (e.g., SaaS, marketplace, e-commerce)
- Software industry or category
- Pricing model (e.g., subscription, usage-based, one-time)
- Monthly revenue range
- Referral source (“How did you hear about us?”)
This data is used to personalize your experience within the Service and to match you with the most relevant peer benchmarks. When anonymized and combined with data from other customers, it also feeds the Aggregated Data used to build industry benchmarks (see Section 4.1).
Source: Provided directly by you during the onboarding flow or updated in your account settings.
3.3 Customer Data (Stripe-Sourced)
When you connect your Stripe account via OAuth, we access and store the following Stripe data under read-only permissions:
- Charges — transaction amounts, dates, statuses, currency
- Invoices — invoice line items, amounts, dates, customer references
- Subscriptions — plan details, billing intervals, statuses, start/end dates
- Customer records — names, email addresses, billing addresses (and in some cases phone numbers or IP addresses recorded by Stripe)
- Products and Prices — product names, pricing tiers, billing configurations
- Balance Transactions — fee breakdowns, net amounts, payout references
- Events — subscription creation events, subscription update events (including before/after state), and discount creation events, with timestamps and change history
Important: Your Stripe account may contain personal data belonging to your own end-customers (for example, names and email addresses on invoices or customer records). By connecting your Stripe account, you confirm you have the authority to share this data with North Metric, as stated in Section 3 of our Terms of Service.
What we never access: Full payment card numbers, CVVs, bank account details, payment methods, or your Stripe account settings. We never write to, modify, or create any data in your Stripe account.
Source: Imported via Stripe Connect OAuth (read-only scopes).
3.4 AI Interaction Data
When the Service generates Derived Insights, the following data is created:
- Prompts — structured queries sent to our AI provider that contain excerpts of your Customer Data as context (for example, revenue figures, subscription patterns, churn indicators)
- Responses — the AI-generated analysis and recommended actions returned by the AI provider
- Feedback signals — any explicit feedback you provide on the quality or relevance of Derived Insights (such as thumbs up/down or dismissals)
Source: Generated at runtime via server-side Supabase Edge Functions communicating with the Anthropic API.
3.5 Usage and Telemetry Data
We collect data about how you interact with the Service:
- Pages visited, features used, buttons clicked
- Session duration and frequency
- Device type, browser type, operating system
- IP address (anonymized in analytics tools where configured)
- Referring URL
Source: PostHog (product analytics) runs as an essential part of the Service for every visitor to understand how the product is used (started shortly after page load, on the basis of our legitimate interest). Google Analytics (GA4, traffic and behavior analytics) operates client-side only after you grant cookie consent.
3.6 Advertising Data
If you arrive at our website through a paid advertisement or interact with marketing content, we may collect:
- Conversion events (e.g., sign-up after clicking an ad)
- Audience signals and ad interaction data
- Hashed user identifiers for remarketing
- Ad click identifiers
Source: Google Ads and Google Tag Manager, operating client-side and subject to your cookie consent preferences.
3.7 Cookie and Tracking Data
Our website uses cookies and similar tracking technologies. Details are provided in Section 11 (Cookie Policy) of this Privacy Policy.
3.8 Error and Diagnostic Data
We collect technical diagnostic data to identify and fix bugs:
- Error messages and stack traces
- Browser and device information at the time of an error
- In rare cases, error payloads may incidentally contain fragments of personal data
Source: Better Stack (error monitoring + uptime).
How and Why We Use Your Data (Legal Bases)
Under GDPR, we must have a valid legal basis for each type of processing. Here is how each data category maps to a legal basis:
| Data Category | Purpose | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Account Data | Create and manage your account, authenticate you, communicate with you about the Service | Contract performance (Art. 6(1)(b)) |
| Company Profile Data | Personalize your experience, match you with relevant peer benchmarks, feed anonymized Aggregated Data for industry benchmarks | Contract performance (Art. 6(1)(b)) for personalization; Legitimate interest (Art. 6(1)(f)) for benchmarks |
| Customer Data (Stripe) | Provide the core Service — ingest your Stripe data, compute SaaS metrics, feed AI Agents to generate Derived Insights | Contract performance (Art. 6(1)(b)) |
| AI Interaction Data | Generate Derived Insights, improve AI output quality, debug AI-related issues | Contract performance (Art. 6(1)(b)) |
| Aggregated Data (Benchmarks) | Build and enrich anonymized industry benchmarks across all customers | Legitimate interest (Art. 6(1)(f)) — see Section 4.1 |
| Usage / Telemetry Data | Understand product usage, improve features, fix bugs | Legitimate interest (Art. 6(1)(f)) for product improvement; Consent (Art. 6(1)(a)) for analytics cookies |
| Advertising Data | Measure ad campaign performance, remarketing | Consent (Art. 6(1)(a)) — collected only with cookie consent |
| Cookie / Tracking Data | Session management (necessary cookies), analytics, advertising | Necessary cookies: Legitimate interest; Non-essential cookies: Consent (Art. 6(1)(a)) |
| Error / Diagnostic Data | Identify and fix bugs, maintain service stability | Legitimate interest (Art. 6(1)(f)) |
| Billing Records | Process payments, comply with tax and accounting obligations | Contract performance (Art. 6(1)(b)) and Legal obligation (Art. 6(1)(c)) |
Scroll horizontally to see more →
4.1 Legitimate Interest Assessment — Aggregated Benchmarks
We use anonymized, de-identified Aggregated Data — derived from both Customer Data and Company Profile Data, combined across multiple customers — to build and enrich industry benchmarks. Company Profile Data (such as your industry, pricing model, and revenue range) helps us segment and contextualize these benchmarks so they are relevant to your peer group. These benchmarks may be made available to other North Metric customers or used in marketing materials.
This data cannot reasonably be used to identify any individual customer, their business, or their end-customers. We believe this processing is justified under legitimate interest because it provides direct value to all customers (better benchmarks improve the quality of Derived Insights), the privacy impact is minimal due to thorough anonymization and de-identification, and no individual customer can opt out of anonymization since the data is no longer personal data once aggregated.
This is consistent with Section 6.3 of our Terms of Service.
How AI Processes Your Data
Transparency about AI processing is important to us. Here is exactly how it works:
5.1 Where Processing Happens
All AI processing occurs server-side through Supabase Edge Functions. Your browser never communicates directly with our AI provider. Customer Data is sent to the Anthropic API (Claude) as structured prompts, and the AI-generated response is returned to our servers and stored in our database.
5.2 What Data Is Sent to the AI Provider
Prompts sent to Anthropic contain excerpts of your Customer Data relevant to the analysis being performed — for example, revenue trends, subscription patterns, churn indicators, or billing anomalies. Prompts are structured programmatically by the Service; you do not type freeform prompts.
5.3 No Model Training on Your Data
Your data is not used to train AI models.Under Anthropic’s API terms, inputs (prompts containing your data) and outputs (Derived Insights) are excluded from model training by default. North Metric does not opt in to any data sharing or training programs with its AI provider.
5.4 How Derived Insights Are Stored
AI-generated Derived Insights are stored in our Supabase database, associated with your account. You own your Derived Insights as stated in Section 6.2 of our Terms of Service. Upon account termination, Derived Insights are deleted according to the retention schedule in Section 8 below.
5.5 No Automated Decision-Making with Legal Effect
The AI Agents provide informational recommendations only. No automated decision is made that produces legal effects or similarly significant effects on you. You always decide whether and how to act on any Derived Insight. Accordingly, GDPR Article 22 (automated individual decision-making) does not apply to the Service.
This is consistent with Section 7 of our Terms of Service, which states that Derived Insights are for informational purposes only and do not constitute financial, legal, or professional advice.
Who We Share Your Data With
We do not sell your personal data. We share data only with the third-party sub-processors necessary to operate the Service, and only to the extent required for their specific function.
6.1 Sub-Processor List
| Provider | Role | Data Accessed | Location | DPA Status |
|---|---|---|---|---|
| Supabase, Inc. | Database, authentication, edge functions | All stored data (Account Data, Customer Data, Derived Insights, AI Interaction Data) | US (AWS us-east-1) | DPA in place (Supabase Pro plan) |
| Anthropic, PBC | AI model provider (Claude API) | Customer Data excerpts included in prompts; AI-generated responses | US | API terms exclude training; DPA executed |
| Stripe, Inc. | Payment processing (North Metric's own billing) + OAuth data source | Billing data for your subscription; OAuth-sourced Customer Data | US | Stripe DPA in place |
| Vercel, Inc. / Cloudflare, Inc. | Hosting, CDN, edge network | Application code, static assets, request logs (may include IP addresses) | Global edge (US origin) | DPAs in place |
| PostHog, Inc. | Product analytics, feature telemetry | Usage data, session identifiers, feature interactions, IP addresses | US (PostHog Cloud) | DPA in place |
| Google LLC (Analytics) | Traffic and behavior analytics | IP addresses (anonymized), page views, session data, device info | US | Google Ads Data Processing Terms; SCCs included |
| Google LLC (Ads) | Conversion tracking, remarketing, audience signals | Conversion events, hashed identifiers, ad click data | US | Google Ads Data Processing Terms; SCCs included |
| Better Stack (Productboard, s.r.o.) | Error monitoring + uptime monitoring | Error logs, stack traces, performance traces, user identifier (id + email) when signed in, device/browser info (may incidentally contain PII), public-URL uptime checks | EU (Frankfurt) | DPA in place |
| Resend, Inc. | Transactional email delivery | Customer name, email address | US | DPA in place |
| Intercom, Inc. | In-product support chat (Messenger widget) | User identifier, email, company name, chat message content, device/browser info, IP address | US (Intercom Cloud) | DPA in place (Intercom Startup program) |
Scroll horizontally to see more →
6.2 Additional Service Providers
From time to time, we may engage additional service providers to support the operation, maintenance, or improvement of the Service — for example, infrastructure monitoring, logging, security scanning, or communication tools. Any such provider that processes personal data on our behalf will be subject to a data processing agreement and will only receive the minimum data necessary for their function. We will update this sub-processor list when material changes occur and notify you in accordance with Section 13 of this policy.
6.3 Other Disclosures
We may also disclose personal data if required by law, regulation, or legal process (such as a court order or subpoena), if necessary to protect the rights, property, or safety of North Metric, our customers, or others, or in connection with a merger, acquisition, or sale of all or substantially all of our assets, in which case you will be notified in advance.
International Data Transfers
North Metric is based in the United States. If you are located outside the US — including in the European Economic Area (EEA), United Kingdom, or Switzerland — your personal data will be transferred to and processed in the US.
7.1 Safeguards for EU/UK Transfers
We rely on the following mechanisms to ensure adequate protection for international data transfers:
Standard Contractual Clauses (SCCs): We use EU-approved Standard Contractual Clauses with our sub-processors to provide appropriate safeguards for data transferred from the EEA, UK, or Switzerland to the US. This applies to transfers to Supabase, Anthropic, Vercel, Cloudflare, PostHog, Google, and Resend. Better Stack data is processed in the EU and is therefore not subject to a cross-border transfer regime for EEA / UK / Swiss data subjects.
EU-US Data Privacy Framework: Where applicable, some of our sub-processors (including Google) self-certify under the EU-US Data Privacy Framework. We monitor the continued validity of these frameworks.
Google Analytics — Additional Safeguards: In light of EU Data Protection Authority scrutiny of Google Analytics, we have implemented IP anonymization in our GA4 configuration, configured GA4 data retention to the minimum period appropriate for our analytics needs, and ensured that Google Analytics scripts only load after the user grants cookie consent (for all visitors).
7.2 Your Rights Regarding Transfers
You have the right to request information about the specific safeguards in place for transfers of your personal data. Contact us at [email protected].
How Long We Keep Your Data
| Data Category | Retention While Active | Post-Termination | Justification |
|---|---|---|---|
| Account Data | Duration of your account | Deleted within 30 days of account termination | No longer needed for service delivery |
| Company Profile Data | Duration of your account | Deleted within 30 days of account termination; anonymized contributions to benchmarks retained indefinitely per Section 8.2 | Personalization and benchmark segmentation |
| Customer Data (raw Stripe) | Full historical import + continuous sync | Deleted within 30 days of account termination | Core to service; 30-day grace period enables reactivation and data export |
| Derived Insights | Duration of your account | Identifiable insights deleted within 30 days; anonymized aggregates retained indefinitely | Aggregated data serves benchmark purposes and is no longer personal data |
| AI Interaction Data | Duration of your account | Deleted within 30 days of account termination | Prompt logs contain financial context |
| Usage / Telemetry (PostHog) | Duration of your account | Retained in anonymized/aggregated form | Product improvement |
| Traffic Analytics (Google Analytics) | Per GA4 retention settings (2 or 14 months) | Governed by Google's retention policy | Traffic analysis |
| Advertising Data (Google Ads) | Per Google Ads retention policy | Governed by Google's retention policy | Campaign performance |
| Cookie Data | Per cookie duration (session to 12 months) | Cleared on browser action or consent withdrawal | Standard practice |
| Error / Diagnostic Data (Better Stack) | 90 days rolling | Same rolling window (auto-expires) | Debugging |
| Billing Records | Duration of your account | Retained as required by tax and accounting law (typically 7 years) | Legal obligation |
Scroll horizontally to see more →
8.1 Post-Termination Data Export
When your account is terminated (by you or by us), you have 30 daysto export your Customer Data and Derived Insights in CSV or JSON format through the Service’s export functionality. After the 30-day window, all identifiable data is permanently deleted. This is consistent with Section 12.3 of our Terms of Service.
8.2 Aggregated Data Survival
Anonymized, de-identified Aggregated Data — derived from both Customer Data and Company Profile Data — that has already been incorporated into industry benchmarks is retained indefinitely, as it can no longer be attributed to you, your business, or your end-customers. This is consistent with Section 6.3 of our Terms of Service.
Your Rights
Depending on where you are located, you have specific rights regarding your personal data. We honor these rights for all users regardless of location, to the extent they are practical and applicable.
9.1 Rights Under GDPR (EEA and UK Residents)
Right of access — You can request a copy of the personal data we hold about you.
Right to rectification — You can ask us to correct inaccurate or incomplete personal data.
Right to erasure (“right to be forgotten”) — You can request deletion of your personal data. We will comply unless we have a legal obligation to retain it.
Right to restriction of processing — You can ask us to temporarily limit how we use your data while a concern is resolved.
Right to data portability— You can request your data in a structured, commonly used, machine-readable format (CSV or JSON). This is also available through the Service’s built-in export functionality.
Right to object — You can object to processing based on legitimate interest (including Aggregated Data for benchmarks). We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
Right to withdraw consent— Where processing is based on consent (such as non-essential cookies), you may withdraw consent at any time using the “Cookie settings” link in the footer of our website. Withdrawal does not affect the lawfulness of processing before withdrawal.
9.2 Rights Under CCPA / CPRA (California Residents)
Right to know — You can request the categories and specific pieces of personal information we have collected, the purposes for collection, and the categories of third parties with whom we share it.
Right to delete — You can request deletion of the personal information we have collected from you.
Right to correct — You can request correction of inaccurate personal information.
Right to opt out of sale or sharing— We do not sell personal information in the traditional sense. However, the use of Google Ads for conversion tracking and remarketing may constitute “sharing” under CPRA. You can opt out at any time by rejecting non-essential cookies in our cookie banner, which you can reopen via the “Cookie settings” link in the footer of our website.
Right to non-discrimination — We will not discriminate against you for exercising your CCPA rights.
9.3 How to Exercise Your Rights
To exercise any of the rights listed above, contact us at:
Subject line:“Data Subject Request” or “CCPA Request”
We will acknowledge your request within 5 business days and respond substantively within 30 days. If we need additional time due to the complexity or volume of the request, we will notify you and may extend the response period by up to 60 additional days, as permitted under GDPR and CCPA.
We may need to verify your identity before processing your request. We will never charge a fee for a standard data subject request.
Children's Data
The Service is not directed at individuals under 18 years of age. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from a child under 18, we will delete that data promptly. If you believe a minor has provided us with personal data, please contact us at [email protected].
This is consistent with Section 2 of our Terms of Service, which requires users to be at least 18 years old.
Cookie Policy
11.1 What Cookies Are
Cookies are small text files stored on your device by your browser. They help us understand how you use our website, remember your preferences, and (with your consent) measure the effectiveness of our advertising.
11.2 Cookie Categories
Our website uses a cookie consent component that categorizes cookies as follows:
| Category | What It Covers | Consent Required | Examples |
|---|---|---|---|
| Strictly Necessary | Supabase Auth session cookies, CSRF protection tokens, cookie consent preference storage | No (exempt — required for the website to function) | sb-access-token, sb-refresh-token, cookie_consent, cookie_consent_id |
| Product Analytics (essential) | PostHog — how the product is used (pages, clicks, sessions). Started a few seconds after load so it doesn't affect page performance. | No (legitimate interest — runs for all visitors) | ph_*, _ph_* (PostHog) |
| Analytics | Google Analytics (gtag.js / GA4) — traffic and behavior | Yes — loaded only after you grant consent | _ga, _ga_* (Google Analytics) |
| Advertising / Marketing | Google Ads conversion pixel, Google Tag Manager, remarketing tags | Yes — loaded only after you grant consent | _gcl_*, _gac_* (Google Ads) |
Scroll horizontally to see more →
11.3 How to Manage Your Cookie Preferences
On first visit: A cookie consent banner appears. Essential product analytics (PostHog) runs for every visitor on the basis of our legitimate interest. Non-essential cookies (Google Analytics and advertising) are not loaded until you affirmatively accept. Consent is a single choice — you can Accept or Reject all non-essential cookies together.
At any time: You can change or withdraw your choice using the “Cookie settings” link in the footer of every page, which reopens the banner.
Browser controls: You can also block or delete cookies through your browser settings, although this may affect the functionality of the Service.
11.4 “Do Not Sell or Share My Personal Information” (California)
If you are a California resident, you can opt out of the “sharing” of your personal information (as defined under CPRA) by rejecting non-essential cookies in our cookie banner. You can reopen the banner at any time via the “Cookie settings” link in the footer of our website. Rejecting non-essential cookies stops Google Analytics and any advertising tracking on your device.
Data Breach Notification
In the event of a confirmed data breach that affects your personal data:
We will notify affected users without undue delay and no later than 72 hours after becoming aware of the breach. Notification will be sent via the email address associated with your account.
The notification will include the nature of the breach and the approximate date it occurred, the categories of personal data affected, the likely consequences of the breach, the measures taken or proposed to address the breach and mitigate its effects, and a contact point ([email protected]) for further information.
Where required by applicable law (including GDPR Article 33), we will also notify the relevant supervisory authority within the required timeframe.
This is consistent with Section 14.6 of our Terms of Service.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the Service itself.
When we make changes:
- We will provide at least 30 days’ advance notice via email to the address associated with your account.
- The updated Privacy Policy will include a new “Last Updated” date at the top.
- Your continued use of the Service after the 30-day notice period constitutes acceptance of the updated Privacy Policy.
- If you do not agree with the changes, you may close your account before the updated policy takes effect (see Section 12 of our Terms of Service).
We will not make retroactive changes that materially reduce your privacy rights without your explicit consent.
This notice period is consistent with Section 13 of our Terms of Service.
How to Contact Us / File Complaints
14.1 Contact Us
For any questions, concerns, or requests related to this Privacy Policy or your personal data:
14.2 EU/UK Supervisory Authority Complaints
If you are located in the EEA or UK and believe we have not adequately addressed your data protection concern, you have the right to lodge a complaint with your local Data Protection Authority.
A list of EU Data Protection Authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
For UK residents, you may contact the Information Commissioner’s Office (ICO) at: https://ico.org.uk/make-a-complaint/
We encourage you to contact us first at [email protected] so we can try to resolve the matter directly.
Reach our privacy team at [email protected].
© North Metric, Inc. All rights reserved.