Skip to main content

Privacy Policy

Last updated:

1. Overview

Northline Systems (“Northline,” we,” “us,” or our”) respects your privacy. This Privacy Policy explains what personal information we collect when you visit northlinesystems.ca or engage us as a client, how we use and protect that information, and the rights you have under Canadian privacy law.

This policy is written to comply with the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada’s Anti-Spam Legislation (CASL). Because Northline operates from Ontario and primarily serves clients across Canada, and PIPEDA is the applicable private-sector privacy statute for our activities.

By using our website or submitting a form, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the website or submit your information.

2. Who we are

Northline Systems is a done-for-you website, marketing, and lead generation partner for contractors and home service businesses across Canada. We operate from Ontario, Canada.

For questions about this policy or your personal information, our Privacy Officer can be reached at the contact details in Section 16.

3. Information we collect

We only collect personal information that we genuinely need to respond to your request, deliver our services, or operate the website. Specifically:

Information you give us directly

  • Contact and business details you submit through our forms: your name, business name, trade, current website (if any), service area or city, email address, and phone number.
  • Messages and correspondence you send us by email, phone, text, or through our forms.
  • Consent records — the date, time, and method by which you provided your CASL and PIPEDA consent, so we can prove lawful contact if asked.
  • Client-relationship information if you engage Northline for services: billing details, account credentials for the platforms we manage on your behalf, content you provide (copy, photos, testimonials), and performance data from those platforms.

Information we collect automatically

  • Technical data — IP address, browser type, device type, operating system, referring URL, pages viewed, and timestamps. This is collected when you visit the website so we can serve the site reliably, prevent abuse, and understand aggregate usage.
  • Analytics data — we use Google Analytics 4 and Microsoft Clarity to understand, in aggregate, how visitors use the site (which pages are popular, how people navigate, and where the experience causes confusion). We do not use analytics to identify individual visitors.
  • Bot-protection signals — Cloudflare Turnstile evaluates your browser and recent behaviour to confirm that form submissions come from humans, not bots. This check is designed to be privacy-preserving.
  • Error and performance telemetry — if the website throws an error, Sentry records anonymous diagnostic information so we can fix the problem. We configure Sentry not to capture form field values.

4. Why we collect it

PIPEDA requires us to identify the purposes for which we collect personal information before or at the time of collection. Our purposes are limited to the following:

  • To respond to your inquiry and deliver the free audit, proposal, or consultation you requested.
  • To follow up by email, phone, or text where you have given express consent for commercial electronic messages.
  • To provide the services you engage us for, including building and maintaining your website, GEO, Generative Engine Optimization, Google Business Profile management, review and referral systems, and automations.
  • To send service-related communications you would reasonably expect from a service provider (invoices, reports, status updates, renewal reminders).
  • To operate, secure, and improve the website — including preventing fraud and abuse, diagnosing errors, and optimizing performance.
  • To comply with legal obligations and to establish, exercise, or defend legal claims.

We do not sell personal information, and we do not use it for automated decision-making that has legal or similarly significant effects on you.

6. Sharing and processors

We do not sell, rent, or trade your personal information. We share it only with service providers (“processors”) who help us run the business under written contracts that require them to protect your information and use it only for the purposes we specify.

  • GoHighLevel (HighLevel LLC) — our CRM. Stores lead submissions and the records of our communications with you.
  • Cloudflare, Inc. — hosts the website (Cloudflare Workers, via the OpenNext adapter), serves images (Cloudflare Images), and provides bot protection (Cloudflare Turnstile) and DDoS / WAF defence.
  • Google LLC — Google Analytics 4 for aggregate analytics, Google Fonts as served via next/font at build time (no runtime request), and Google Workspace for email.
  • Microsoft Corporation — Microsoft Clarity for aggregate session replay and heatmap analytics on the production website.
  • Functional Software, Inc. (Sentry) — anonymous error monitoring.
  • Upstash, Inc. — stores short-lived rate limit counters (IP + timestamp) to prevent form abuse.
  • Professional advisors — our accountants, lawyers, and insurers, where needed and subject to confidentiality.
  • Regulators and law enforcement — only where we are required to disclose information by law or a valid legal process, or where disclosure is necessary to protect rights, property, or safety.
  • Successors in a business transaction — if Northline is ever sold or merged, personal information may be transferred to the successor, who will be bound by this policy or a successor of at least equivalent protection.

7. International transfers

Several of the processors listed above are based in the United States or process data on servers located outside Canada. While your information is in the custody of a processor in another country, it may be subject to that country’s laws, including lawful access requests by foreign authorities.

We use contractual protections (including standard data processing terms) to ensure that cross-border processors provide a comparable level of protection to what PIPEDA requires. By submitting your information, you acknowledge that it may be processed outside Canada for the purposes described in this policy.

8. Cookies and tracking

We use a small number of cookies and similar technologies to operate and improve the website.

  • Strictly necessary — cookies and tokens that are required for the website to work, including those used by Cloudflare for security and by Turnstile to verify that form submissions are human.
  • Analytics — Google Analytics 4 sets cookies (including _ga and related identifiers) to measure how visitors use the site. Microsoft Clarity uses cookies and similar technologies (including _clck and _clsk) to record session replays and heatmaps so we can see, in aggregate, how the site is used. Analytics runs only on the production website, not in development environments.
  • Preferences — if any settings you choose need to persist between visits (for example, a cookie banner choice), we use a cookie to remember that choice.

You can control or delete cookies through your browser settings. You can also opt out of Google Analytics by installing Google’s Analytics Opt-out Browser Add-on. To prevent Microsoft Clarity from recording your visit, block or delete Clarity cookies (such as _clck and _clsk) in your browser, or see Microsoft’s Clarity cookie list for details.

9. Retention

We retain personal information only as long as we need it for the purposes we collected it for, to satisfy our legal and contractual obligations, and to resolve disputes.

  • Lead submissions where we did not enter a service relationship: retained for up to 24 months so we can follow up on active interest, then deleted or anonymized.
  • Client records: retained for the duration of the engagement and for up to seven (7) years after termination for tax, accounting, and dispute-resolution purposes.
  • Consent records: retained for at least three (3) years after the last communication, as required by CASL.
  • Analytics data: retained in Google Analytics with a user-data retention of 14 months; Microsoft Clarity retains session data according to Microsoft’s default project retention settings.
  • Error logs and rate limit counters: 30 to 90 days.

When the retention period ends, we either securely delete the information or irreversibly anonymize it so that it can no longer be linked to you.

10. Safeguards

We use physical, organizational, and technical safeguards appropriate to the sensitivity of the information.

  • Transport Layer Security (HTTPS/TLS) on every page and API endpoint.
  • Cloudflare Turnstile bot protection, honeypot fields, and IP-level rate limiting on our lead-capture endpoint to prevent automated abuse.
  • Access to personal information is restricted to personnel who need it to do their jobs, protected by unique credentials and multi-factor authentication wherever available.
  • Processor agreements with all third parties listed in Section 6.
  • Regular review of our security posture, including patching, least-privilege access, and secure handling of secrets and credentials.

No method of transmission or storage is 100% secure. If we become aware of a breach of security safeguards involving personal information under our control, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as required by PIPEDA.

11. Your rights

Under PIPEDA, you have the right to:

  • Access the personal information we hold about you.
  • Request correction of information that is inaccurate or incomplete.
  • Withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice.
  • Ask questions about how we handle your information and challenge our compliance with this policy.
  • Complain to the Office of the Privacy Commissioner of Canada if you believe we have not handled your information in accordance with PIPEDA. Their contact details are at priv.gc.ca.

To exercise any of these rights, contact our Privacy Officer (see Section 16). We will respond within 30 days, as required by PIPEDA, and may need to verify your identity before releasing information.

12. Canada's anti-spam law (CASL)

We only send commercial electronic messages to individuals or businesses who have given us express or valid implied consent. Every marketing email from Northline includes:

  • A clear identification of Northline Systems as the sender.
  • Our current mailing contact information.
  • A working unsubscribe mechanism you can use to withdraw consent at no cost.

Unsubscribe requests are honoured within ten (10) business days, as required by CASL. If you believe you received a message from us that does not comply with CASL, please contact our Privacy Officer and we will investigate and correct the issue.

13. US visitors and clients

Northline is based in Ontario, Canada, and primarily serves contractors and home service businesses in Canada. We may also work with clients outside Canada, including the United States. This section describes the additional rights and disclosures that apply if you are a US resident or your business is located in the United States. It supplements — and does not replace — the rest of this Privacy Policy.

Categories of personal information we collect

For purposes of US state privacy laws, the categories of personal information we collect are described in detail in Sections 3 through 6 above. In the terminology of the California Consumer Privacy Act (CCPA) and similar state laws, those categories are:

  • Identifiers — name, business name, email, phone number, IP address.
  • Commercial information — your trade, the services you have asked about, and, if you become a client, your billing and transaction history.
  • Internet or other electronic network activity — pages visited, referring URL, device and browser information, interactions with our forms.
  • Geolocation data — approximate location inferred from IP address; city you voluntarily provide on a form.
  • Professional or employment-related information — your role and the business you represent.
  • Inferences — a limited set of inferences we draw about your likely fit for our services, based only on the information you provide to us.

We do not knowingly collect sensitive personal information (such as government ID numbers, precise geolocation, health information, biometric data, or data concerning children) through the Website, and we do not use sensitive personal information to infer characteristics about you.

No sale or sharing of personal information

Northline does not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA and similar state laws. We have not sold or shared personal information in the preceding 12 months. We also do not use or disclose sensitive personal information for purposes that require a right to limit under those laws.

Your US state privacy rights

Depending on the state where you reside, you may have some or all of the following rights:

  • Right to know / access the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties we have disclosed it to.
  • Right to delete personal information we have collected from you, subject to lawful exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of any sale or sharing of personal information (as noted above, we do not sell or share, so there is nothing to opt out of).
  • Right to limit the use and disclosure of sensitive personal information (as noted above, we do not use sensitive personal information in ways that trigger this right).
  • Right to non-discrimination — we will not deny you service, charge you a different price, or provide a different level of service because you exercised a privacy right.
  • Right to appeal — if we deny your request, you can appeal our decision by replying to our written response. If your state offers a regulator complaint process (for example, the California Privacy Protection Agency or your state Attorney General), you may also contact them.

To exercise any of these rights, contact our Privacy Officer using the details in Section 16. We will acknowledge your request within 10 business days and respond substantively within 45 days, as required by most state privacy laws. We may need to verify your identity before releasing information. An authorized agent may submit a request on your behalf with written authorization.

Marketing calls and text messages (TCPA)

If you provide us with a US phone number and check the consent box on our lead form, you give Northline your prior express written consent under the US Telephone Consumer Protection Act (TCPA) to contact you at that number by phone and text message — including through automated dialing systems or pre-recorded voices — about our marketing services. Standard message and data rates may apply.

Consent to marketing calls or texts is not a condition of purchasing anything from us. You can opt out of marketing texts at any time by replying STOP to any message, and you can opt out of marketing calls by telling the caller or writing to our Privacy Officer.

Commercial emails (CAN-SPAM)

Marketing emails we send to US recipients comply with the US CAN-SPAM Act. Every commercial email identifies Northline as the sender, includes our valid postal contact information, uses non-deceptive subject lines and headers, and provides a working unsubscribe mechanism. We honour unsubscribe requests within 10 business days.

Nevada and other state-specific notes

Nevada residents: Nevada law (NRS 603A.340) gives you the right to submit a verified request directing us not to sell certain covered information. As stated above, we do not sell personal information; contact our Privacy Officer if you would like confirmation in writing.

California “Shine the Light” (Civil Code §1798.83): California residents may request, once per calendar year, information about any disclosure of personal information to third parties for their direct marketing purposes. We do not disclose personal information for third parties’ direct marketing.

14. Children

Our website and services are directed to adult business owners and decision-makers. We do not knowingly collect personal information from children under the age of majority in their province of residence (age 18 in Ontario). If you believe a child has submitted personal information to us, please contact our Privacy Officer and we will delete it.

15. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our service providers, or the law. The “Last updated” date at the top of this page reflects the most recent revision.

For material changes, we will take reasonable steps to notify you — for example, by an email notice to active clients or a prominent notice on the website — before the change takes effect. Continued use of the website or our services after an update means you accept the revised policy.

16. Contact us

Questions, access requests, complaints, or any other concerns about your personal information can be directed to our Privacy Officer:

Privacy Officer — Northline Systems
Email: privacy@northlinesystems.ca
Phone: (647) 558-5476
Mail: Northline Systems, Ontario, Canada

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca or 1-800-282-1376.