Definitions
Throughout these Terms, the following words have specific meanings:
Account Registration & Eligibility
You must be at least 18 years old to use the Service. By creating an account, you represent that you are 18 or older and have the legal capacity to enter into these Terms.
You agree to provide accurate, current, and complete registration information. You are responsible for maintaining the confidentiality of your account credentials and for all activity that occurs under your account.
One Stripe account per North Metric account. Each connected Stripe account may only be linked to one North Metric account at a time.
You must notify us immediately at [email protected] if you believe your account has been compromised.
Stripe OAuth Authorization & Scope of Data Access
To use the Service, you must authorize North Metric to access your Stripe account through Stripe’s OAuth connection. Here is exactly what that means:
What we access (read-only)
- Charges
- Invoices
- Subscriptions
- Customer records
- Products and Prices
- Balance Transactions
- Subscription and discount events (creation, update, and discount change history including timestamps and before/after state)
What we never access
- Full payment card numbers, CVVs, or bank account details
- Your Stripe account settings
- Payment methods or stored card data
- We never write to, modify, or create any data in your Stripe account
Your authorization warranty
By connecting your Stripe account, you represent and warrant that:
- (a) You own or are an authorized administrator of the connected Stripe account.
- (b) You have the legal right to grant North Metric read access to all data within that Stripe account, including any personal data of your own end-customers that may appear in Stripe objects, including event history and change logs (such as names and email addresses on invoices or customer records).
- (c) Your authorization complies with any applicable agreements you have with Stripe.
We only look at your Stripe data — we never touch or change anything. You’re confirming you have the authority to let us see this data, including data about your customers that Stripe stores.
North Metric’s access to your Stripe account is also subject to Stripe’s Connected Account terms and platform policies.
You may revoke North Metric’s access to your Stripe account at any time through your Stripe dashboard or by disconnecting within the North Metric app.
Plans, Billing & Cancellation
4.1 Plans
North Metric offers a free plan with limited features and a paid plan with expanded capabilities. Feature availability and current pricing are described on our pricing page at northmetric.io/pricing. We may introduce additional plans or pricing options at any time; current details are always available there.
The free plan is governed by these same Terms, with the same liability protections and obligations.
4.2 Paid Subscriptions
Paid subscriptions are currently billed monthly. Additional billing options may become available — visit northmetric.io/pricing for the latest details.
Billing is processed through Stripe. By subscribing, you authorize North Metric to charge your payment method on a recurring basis at the applicable rate.
4.3 Cancellation
You may cancel your paid subscription at any time through your account settings. Upon cancellation:
- Access continues until the end of your current paid billing period. You will not be charged again after cancellation takes effect.
- After your paid period ends, your account will revert to the free plan (if available) or be deactivated.
4.4 No Refunds
All payments are non-refundable. We do not provide refunds or credits for any partial subscription periods, upgrades, downgrades, or unused features.
If you cancel mid-month, you keep access for the rest of that month but won’t get money back for it.
4.5 Price Changes
We may change our pricing with 30 days’ advance notice sent to the email address on your account. If you do not agree with a price change, you may cancel before the new pricing takes effect.
Permitted Use & Restrictions
5.1 Permitted Use
You may use the Service to connect your Stripe account, analyze your revenue data, and receive AI-generated Derived Insights for your internal business purposes.
5.2 Restrictions
You agree not to:
- (a) Use the Service to build or improve a competing product or service. This includes reverse-engineering our AI methodology, benchmarking the Service against a competitive offering you are building, or systematically extracting our analytical approaches.
- (b) Share, resell, sublicense, or redistribute the Service or any Derived Insights to third parties as a standalone product or data feed.
- (c) Attempt to access, tamper with, or reverse-engineer any non-public component of the Service, including our AI models, algorithms, or infrastructure.
- (d) Use the Service in any way that violates applicable law, infringes third-party rights, or facilitates fraud.
- (e) Submit data through any means other than the authorized Stripe OAuth connection (no scraping, manual uploads of fabricated data, or unauthorized API calls).
- (f) Interfere with or disrupt the Service, its servers, or networks connected to the Service.
Intellectual Property
6.1 Your Customer Data
You retain all rights to your Customer Data. North Metric does not claim ownership of any data you import from Stripe. Our access to your Customer Data is limited to what is necessary to provide and improve the Service as described in these Terms.
6.2 Your Derived Insights
You own the Derived Insights generated from your data. The AI-generated analysis, revenue actions, metrics, and recommendations the Service produces specifically from your Customer Data belong to you.
6.3 Aggregated Data & Benchmarks
You grant North Metric the right to use Aggregated Data derived from your Customer Data and Company Profile Data — combined with data from other customers — to build and enrich industry benchmarks. This data is anonymized and de-identified so that it cannot reasonably identify you, your business, or your end-customers. These benchmarks may be made available to other North Metric customers or used in marketing materials.
Your individual data is yours. This includes the company details you provide at onboarding (like your industry and revenue range), which help us build more relevant peer comparisons. But we take patterns across all our customers — with no way to trace anything back to you — and use them to build benchmarks that help everyone. Think of it like how a salary survey reports industry averages without revealing any one person’s pay.
6.4 North Metric IP
The Service itself — including its design, AI models, algorithms, software, branding, and documentation — is and remains the exclusive property of North Metric, Inc. These Terms do not grant you any rights to our IP other than the limited right to use the Service as described here.
AI Disclaimers
This section is important. Please read it carefully.
7.1 No Financial Advice
North Metric is not a financial advisor, accountant, or fiduciary. Derived Insights — including dollar-quantified revenue actions, churn predictions, and MRR calculations — are generated by AI and are for informational purposes only. They do not constitute financial, legal, tax, investment, or accounting advice.
7.2 No Guarantee of Accuracy
AI Agents process your Customer Data to generate Derived Insights using machine learning models provided by third parties. We do not guarantee the accuracy, completeness, or reliability of any Derived Insight. AI outputs may contain errors, hallucinations, or outdated conclusions.
7.3 Your Responsibility
You are solely responsible for any decisions you make based on Derived Insights. You should independently verify any AI-generated information before acting on it, especially for material business decisions involving pricing changes, customer outreach, or revenue projections.
7.4 No Fiduciary Duty
Nothing in these Terms or in North Metric’s provision of the Service creates a fiduciary relationship, advisory relationship, or duty of care between North Metric and you beyond what is expressly stated in these Terms.
Our AI gives you data-driven suggestions, not professional advice. Think of it as a very smart starting point — always double-check before making big decisions.
Data & Privacy
Your use of the Service is also governed by our Privacy Policy, which describes how we collect, use, store, and share your data.
Key points relevant to these Terms:
- Customer Data processing: We process your Customer Data as a data controller to provide the Service [see Privacy Policy, Section: Legal Bases for Processing].
- End-customer data: Your Stripe account may contain personal data of your own end-customers. We process this data under the authorization you provide in Section 3 above [see Privacy Policy, Section: Categories of Personal Data].
- Company Profile Data: We collect business information during onboarding (industry, pricing model, revenue range, and others) to personalize your experience and feed anonymized benchmarks. This data is stored and processed as described in our Privacy Policy [see Privacy Policy, Section: Categories of Personal Data].
- AI processing transparency: Customer Data is sent to our AI provider (Anthropic) via server-side functions to generate Derived Insights. Anthropic does not use this data for model training [see Privacy Policy, Section: AI Processing].
- Aggregated Data for benchmarks: We use anonymized, aggregated data across customers to build industry benchmarks as described in Section 6.3 [see Privacy Policy, Section: Data Usage for Product Improvement].
- Cookies and tracking: Our website uses analytics (PostHog, Google Analytics) and advertising (Google Ads) technologies subject to your cookie consent preferences [see Privacy Policy, Section: Cookie Policy].
- Sub-processors: A complete list of third-party sub-processors is maintained in our Privacy Policy [see Privacy Policy, Section: Sub-Processors].
Service Availability
9.1 Availability
We use commercially reasonable efforts to keep the Service available, but we do not guarantee any specific uptime percentage. The Service depends on third-party infrastructure providers (including Supabase, Stripe, Vercel, Cloudflare, and Anthropic), and their availability directly affects ours.
9.2 Maintenance
We may perform scheduled or emergency maintenance that temporarily limits or suspends access to the Service. Where reasonably possible, we will provide advance notice of planned maintenance via email or in-app notification.
9.3 No SLA
These Terms do not include a service level agreement (SLA). We do not offer service credits, financial remedies, or penalties for downtime. A formal SLA may be offered on specific plans in the future.
We work hard to keep things running, but we can’t promise 100% uptime — especially since we depend on Stripe and other services too. We don’t currently offer uptime guarantees with financial penalties attached.
Limitation of Liability & Indemnification
10.1 Limitation of Liability
To the maximum extent permitted by law:
- (a)North Metric’s total aggregate liability to you for any and all claims arising out of or related to these Terms or the Service is limited to the total fees you paid to North Metric in the twelve (12) months preceding the event giving rise to the claim. If you are on the free plan and have paid nothing, our maximum aggregate liability is $100 USD.
- (b) North Metric is not liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, revenue, data, business opportunities, or goodwill, regardless of whether such damages were foreseeable or whether North Metric was advised of their possibility.
- (c) North Metric is not liable for decisions you make based on Derived Insights, AI Agent outputs, or any other information provided through the Service.
10.2 Indemnification
You agree to indemnify, defend, and hold harmless North Metric and its officers, directors, employees, and agents from any claims, damages, losses, liabilities, and expenses (including reasonable attorneys’ fees) arising from:
- (a) Your use of the Service.
- (b) Your violation of these Terms.
- (c)Your representation that you are authorized to connect the Stripe account in question (Section 3), including any claims from your end-customers related to North Metric’s processing of data originating from your Stripe account.
- (d) Your violation of any applicable law or third-party rights.
If something goes wrong because of how you used the Service — including if it turns out you didn’t have permission to share that Stripe data — you’re covering us, not the other way around. Our financial liability to you is capped at what you’ve paid us in the last year.
Dispute Resolution
11.1 Governing Law
These Terms are governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict-of-law provisions.
11.2 Informal Resolution First
Before filing any formal proceeding, you agree to contact us at [email protected] and attempt to resolve the dispute informally for at least 30 days.
11.3 Binding Arbitration
If the dispute is not resolved informally and the total amount in controversy is $250,000 or less, either party may elect to resolve the dispute through binding arbitration administered by the American Arbitration Association (AAA) under its Commercial Arbitration Rules. The arbitration will be conducted in New York, NY (or remotely if mutually agreed). The arbitrator’s decision is final and enforceable in any court of competent jurisdiction.
11.4 Court Litigation
For disputes exceeding $250,000, or where a party seeks injunctive or equitable relief, the exclusive venue is the courts of the State of Delaware or the United States District Court for the District of Delaware, and both parties consent to personal jurisdiction in those courts.
11.5 No Class Actions
You agree to resolve disputes with North Metric on an individual basis only. You waive any right to participate in class actions, class arbitrations, or representative proceedings.
Termination & Data on Churn
12.1 Termination by You
You may stop using the Service and close your account at any time through your account settings or by contacting [email protected].
12.2 Termination by North Metric
We may suspend or terminate your account if:
- (a) You breach these Terms and do not cure the breach within 15 days of our notice.
- (b) You engage in activity that poses a security risk to the Service or other customers.
- (c) We are required to do so by law.
- (d) We discontinue the Service entirely (with at least 30 days’ notice).
12.3 What Happens to Your Data
Upon termination (by either party):
- 30-day data access window. You will have 30 days from the effective date of termination to export your Customer Data and Derived Insights in CSV or JSON format through the Service’s export functionality.
- Permanent deletion. After the 30-day window, we will permanently delete all of your Customer Data, Derived Insights, and AI Interaction Data, and Company Profile Data from our systems. This deletion is irreversible.
- Stripe OAuth revocation. We will revoke our OAuth connection to your Stripe account. You can also revoke access from your Stripe dashboard at any time.
- Aggregated Data survives. Anonymized, aggregated data that has already been incorporated into industry benchmarks (Section 6.3) — derived from both Customer Data and Company Profile Data — will not be deleted, as it cannot be attributed to you.
- What we retain. We retain basic billing records (transaction dates and amounts) as required for tax and accounting purposes, and server logs for up to 90 days for security and debugging purposes.
You get 30 days to grab your data after leaving. After that, we delete everything that identifies you. The only thing that sticks around is anonymized benchmark data (which can’t be traced to you) and basic billing records we need for taxes.
Modifications to These Terms
We may update these Terms from time to time. When we do:
- We will provide at least 30 days’ advance notice via email to the address associated with your account.
- The updated Terms will include a new “Last Updated” date at the top.
- Your continued use of the Service after the 30-day notice period constitutes acceptance of the updated Terms.
- If you do not agree with the changes, you may cancel your account before the updated Terms take effect (see Section 12).
We will not make retroactive changes that materially reduce your rights under these Terms without your explicit consent.
Security
We take the security of your Customer Data seriously. This section describes our core security commitments. For details on how we handle your data, see also our Privacy Policy [see Privacy Policy].
14.1 Infrastructure & Encryption
The Service is built on infrastructure provided by Supabase (database, authentication, edge functions), Vercel and Cloudflare (hosting, CDN, edge network), and Stripe (payment processing and OAuth). Each of these providers maintains independent security certifications and compliance programs.
All Customer Data is encrypted at rest using AES-256 encryption (or equivalent) as provided by our infrastructure providers. All data in transit is encrypted using TLS 1.2 or higher. This applies to all communication between your browser and our servers, between our servers and Stripe, between our servers and our AI provider, and between our servers and our database.
14.2 Access Controls
Access to production systems and Customer Data follows the principle of least privilege. Access is restricted to authorized personnel only, limited to what is necessary for operating and maintaining the Service.
We use Supabase Auth for customer authentication, which supports email/password login and time-based one-time password (TOTP) multi-factor authentication. We encourage all customers to enable MFA on their accounts.
Role-based access controls govern internal access to infrastructure, and access rights are reviewed regularly as the team scales.
14.3 Stripe OAuth Token Security
Your Stripe OAuth tokens grant North Metric read-only access to your Stripe account. These tokens are:
- (a) Stored encrypted within our database — never in plaintext, client-side storage, or application logs.
- (b) Scoped to read-only access. North Metric cannot modify, create, or delete any data in your Stripe account.
- (c) Revoked on account termination. When your account is closed (by you or by us), we revoke the OAuth connection and delete the stored token. You may also revoke access at any time from your Stripe dashboard.
14.4 AI Provider Data Handling
Customer Data is sent to our AI provider (Anthropic) via server-side Supabase Edge Functions to generate Derived Insights. This means:
- (a) No client-side AI calls. Your data is never sent directly from your browser to the AI provider.
- (b)No model training on your data. Under Anthropic’s API terms, inputs and outputs are excluded from model training by default. North Metric does not opt in to any data sharing or training programs with its AI provider.
- (c) Processing is transient. Customer Data included in AI prompts is used to generate a response and is not retained by the AI provider beyond what is necessary to deliver that response, in accordance with the AI provider’s data processing terms.
14.5 Application Security
We implement standard application security practices including input validation and parameterized queries to prevent injection attacks, dependency monitoring and regular updates to address known vulnerabilities, secure session management through Supabase Auth, and HTTPS enforcement across all endpoints.
14.6 Incident Response & Breach Notification
We maintain an incident response process covering detection, classification, containment, remediation, and notification. In the event of a confirmed data breach that affects your Customer Data:
- (a) We will notify affected customers without undue delay and no later than 72 hours after becoming aware of the breach, via the email address associated with your account.
- (b) The notification will include the nature of the breach, the categories of data affected, the measures taken or proposed to address the breach, and a point of contact for further information.
- (c) Where required by applicable law (including GDPR), we will also notify the relevant supervisory authority within the required timeframe.
For additional details on breach notification, see our Privacy Policy [see Privacy Policy, Section: Data Breach Notification].
14.7 Business Continuity & Data Backups
Customer Data stored in our database is backed up using Supabase’s Point-in-Time Recovery (PITR), which provides continuous backups with the ability to restore to any point in time. We maintain backup and recovery procedures designed to minimize data loss and restore service availability in the event of an infrastructure failure.
14.8 Vendor & Sub-Processor Security
We evaluate the security practices of all third-party sub-processors before engaging them and on an ongoing basis. A complete list of our current sub-processors is maintained in our Privacy Policy [see Privacy Policy, Section: Sub-Processors]. We require data processing agreements (DPAs) with all sub-processors that handle Customer Data.
14.9 Your Security Responsibilities
You are responsible for:
- (a) Maintaining the confidentiality and security of your account credentials.
- (b) Enabling multi-factor authentication where available.
- (c) Ensuring that the devices and networks you use to access the Service are reasonably secure.
- (d) Notifying us promptly at [email protected] if you suspect unauthorized access to your account.
General Provisions
15.1 Entire Agreement
These Terms, together with the Privacy Policy, constitute the entire agreement between you and North Metric regarding the Service.
15.2 Severability
If any provision of these Terms is found to be unenforceable, the remaining provisions remain in full force and effect.
15.3 No Waiver
Our failure to enforce any provision of these Terms does not constitute a waiver of that provision or any other provision.
15.4 Assignment
You may not assign your rights or obligations under these Terms without our prior written consent. North Metric may assign these Terms in connection with a merger, acquisition, or sale of all or substantially all of its assets, provided the assignee agrees to honor these Terms.
15.5 Notices
Legal notices to North Metric should be sent to:
Notices to you will be sent to the email address associated with your account.
15.6 Force Majeure
North Metric is not liable for any failure or delay in performing its obligations due to circumstances beyond its reasonable control, including natural disasters, government actions, internet or infrastructure outages, or third-party service disruptions (including Stripe, Supabase, Anthropic, or hosting providers).
Anything unclear about these Terms? Reach us at [email protected].
© North Metric, Inc. All rights reserved.