Privacy Policy
Last updated: June 22, 2026
Northwind Metrics ("Northwind Metrics," "we," "us," or "our") operates the website at northwindmetrics.com and the Northwind Metrics platform (the "Service") — an AI-powered financial reporting and advisory tool that connects to your accounting systems to generate dashboards, reports, and AI-assisted insights. This Privacy Policy explains what we collect, how we use it, and your choices. The Service is operated by Northwind Metrics LLC. If you do not agree with this policy, please do not use the Service.
1. Information we collect
Account information. When you create an account we collect your name, email address, business or firm name, industry, chosen plan, and a password (stored only as a salted hash by our authentication provider).
Financial data from QuickBooks. With your authorization, we connect to your QuickBooks via Intuit's OAuth using read-only access to retrieve financial data — such as revenue, expenses, invoices, balances, and transactions — solely to generate your dashboards, reports, and insights. We do not write to, modify, or delete anything in your QuickBooks. You can disconnect at any time.
Files you upload. If you use file-upload features, we process documents you provide (e.g., CSVs, PDFs, bank or statement exports) to produce analytics and summaries.
Prospect & marketing information. If you use our public "Ask Northwind" assistant or request a skill, we collect the name, email, company, and message you submit, along with your conversation with the assistant, so we can answer and follow up.
Usage & technical data. We collect log data, device and browser information, and basic analytics about how the Service is used. Our site uses session-based storage for access control and does not use third-party advertising cookies.
2. How we use information
We use information to: provide, operate, and maintain the Service; generate financial dashboards, reports, and AI-assisted insights; authenticate you and secure your account; process subscriptions and payments; respond to inquiries and provide support; follow up on requests you submit through public forms or the assistant; improve and develop the Service; detect and prevent security issues, fraud, or abuse; and comply with legal obligations. We do not sell your personal information.
3. AI processing
To produce insights and power the assistant, relevant inputs (your questions and the financial context needed to answer them) are sent to our AI provider, Anthropic (the Claude API), for processing. Anthropic does not use data submitted through its API to train its models, and we do not use your financial data to train any model. Outputs are generated for your use within the Service.
4. Service providers (subprocessors)
We share data with vendors who process it on our behalf under contractual confidentiality and security obligations: Supabase (database, authentication, and file storage hosting); Lovable (application hosting); Anthropic (AI processing — Claude); Intuit / QuickBooks (source of your financial data, read-only, at your direction); Stripe (payment processing); and Resend or our configured email provider (transactional and notification emails).
5. How we share information
We disclose information only: (a) to the service providers above; (b) to comply with law, legal process, or enforceable governmental requests; (c) to protect the rights, safety, and security of users, the public, or Northwind Metrics; and (d) in connection with a merger, acquisition, or sale of assets, with notice to affected users. If you access the Service through a CPA, bookkeeper, or partner using our white-label features, your data may be visible to that firm as your service provider.
6. Data retention
We retain personal and financial data for as long as your account is active or as needed to provide the Service, then delete or de-identify it within a reasonable period, except where longer retention is required by law (e.g., tax, accounting, or legal obligations). You can request deletion as described below.
7. Your rights & choices
Depending on your location (including under the GDPR and California's CCPA/CPRA), you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can disconnect QuickBooks at any time, and unsubscribe from marketing emails using the link in those emails. To exercise any right, contact us at hello@northwindmetrics.com and we will respond as required by applicable law.
8. Security
We use technical and organizational safeguards including encryption in transit and at rest, row-level access controls, and least-privilege access. See our Security page for details. No method of transmission or storage is 100% secure.
9. International transfers
We may process and store information in countries other than your own. Where required, we rely on appropriate safeguards for such transfers.
10. Children
The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal information from children.
11. Changes
We may update this policy from time to time. We will post the updated version with a new "Last updated" date and, where appropriate, notify you.
12. Contact
Questions or requests: hello@northwindmetrics.com.
