NorthForm Privacy Policy

NorthForm · Effective: 2026-09-01 · Last updated: 2026-09-09


The distinction this policy turns on

NorthForm is used by accounting firms to manage information about their clients. That creates two different relationships, and they carry different obligations:

Whose informationOur role
Firm account dataThe firm and its staff — names, work emails, billing detailsWe decide how it is used. We are responsible for it directly.
Client dataThe firm's clients — entered or uploaded by the firmThe firm decides how it is used. We process it on the firm's instructions only.

We do not contact a firm's clients for our own purposes, never use client data for our own purposes, and never sell any data to anyone. The one exception is at the firm's own instruction: when a firm asks someone to sign a document, we email that person the one-time code they need (§1, §4). If you are a client of a firm that uses NorthForm and want to know what is held about you or want it corrected, contact your accountant — they control that information, and we will support them in answering you.


1. What we collect

Firm account data

Client data the firm enters

Client name and contact name, email, phone, mailing address, business type, incorporation date, fiscal year end, filing frequencies, and notes. Also CRA and provincial identifiers: business number, GST account, payroll account, WCB account, and corporate access number.

Documents the firm uploads

Files uploaded by the firm, or by the firm's clients through a secure upload link.

We do not have a field for a Social Insurance Number — but uploaded documents commonly contain one. A T4, a notice of assessment or a personal return will carry SINs and other sensitive identifiers. We therefore treat all uploaded documents as containing sensitive personal information, regardless of what a firm intends to upload.

Electronic signatures

When a firm asks someone to sign a document electronically, the firm gives us that person's name and email address. From the person signing, we then collect, and keep as the record of the signing: a one-way hash of the one-time code we email them (never the code itself), and whether it was entered correctly; their consent to sign electronically, with the wording they agreed to; the signature they draw or the name they type; the IP address and browser details of the device they signed from; and the time of each step. A person who signs does not need a NorthForm account. The signed document, with a certificate page listing these details, is stored in the firm's client file.

Collected automatically

Standard technical data — IP address, browser type, timestamps — for security, abuse prevention and diagnostics. We do not use advertising trackers, and we do not sell or share data with advertisers.

Cookies and browser storage. When you sign in to the app, it sets a session cookie on our own addresses under getnorthform.com that holds your signed-in session. That cookie is strictly necessary to provide the service, is sent only to our own addresses, and is cleared when you sign out; if you never sign out it expires after 400 days. The app also uses your browser's own storage on the device you are using: for display preferences (theme, text size, list filters), a cached copy of your firm's name and logo so the screen paints without waiting, short-lived sign-in markers that last only for the browser tab, and small records of notices you have acknowledged or prompts you have already seen — one of those records is keyed to your account identifier. None of this is sent to us or to anyone else. Signing out clears the session cookie; the tab-scoped markers end when you close that browser tab; the preferences and records stay on that device until you clear your browser's site data, so on a shared computer use a private window or clear site data when you finish. The marketing site and these legal pages set no cookies. We use no advertising or analytics cookies of any kind.


2. Why we collect it

We use information only to provide the service:

Marketing email

With your consent, we may also send product news and feature announcements. Consent is a separate, unchecked box at signup — never assumed, never bundled with creating an account — and every marketing email includes a working unsubscribe link. Unsubscribing from marketing never affects service messages, which we send as part of operating the service.

We do not train artificial intelligence models on your data, and we do not permit our vendors to. See §4.


3. Legal basis and consent

We operate under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta's Personal Information Protection Act (PIPA).

For firm account data, we rely on your consent, given when you create an account and accept our Terms of Service, and on the necessity of processing to provide a service you requested.

For client data, the firm is responsible for having the authority to provide it to us and for any consent its own clients must give. We process it solely on the firm's instructions. This is set out in the Terms of Service.

For information about a person who signs a document at a firm's request (§1, "Electronic signatures"), the firm is responsible for its relationship with that person, including telling them that NorthForm operates the signing on the firm's behalf. We process what the signing itself produces — the consent, the signature, the device details and the timestamps — on the firm's instructions, and only to make and keep the record of that signing.


4. Who else processes your data

We use the service providers below. Each provider we send information to is bound to protect it consistent with this policy, and none is permitted to use it for its own purposes. Two rows are different in kind. We send Google Fonts nothing and have no contract with Google — your browser fetches typefaces directly from Google's servers, and the row states exactly what Google sees when it does. The timestamp authorities are public services we use without a contract; that is acceptable only because they receive a cryptographic digest and nothing else, and the row says so.

ProviderWhat it doesWhat it can seeWhere
SupabaseDatabase, authentication, file storage, and the application functions that operate the serviceAll firm and client dataCanada — AWS ca-central-1 (Montréal) for stored data and for the application functions; three narrow call paths run nearest the caller (see below)
Amazon Web Services (S3, KMS)Encrypted offsite backups; and, for sealed electronic signatures, signing the signature's own attributes with a key held in AWS KMSBackups only, encrypted before they leave our systems; for sealing, a SHA-256 digest of the signature's own attributes — never the document itselfCanada — S3 and the KMS key in ca-central-1 (Montréal), a guaranteed region
NetlifyServes the applicationNo stored data; request metadata onlyGlobal
OpenRouter / AnthropicOptional AI document extractionContents of documents you choose to processUnited States
StripeSubscription billingBilling identity and payment detailsUnited States
GitHubSource control and automated backup jobsNo customer data in source codeUnited States
Google (Gmail)Sends the email notifying your firm's owners when a support session opens, and the one-time code emailed to a person your firm asks to sign a documentOwner email addresses, your firm's name, and the fact and time a support session opened; for a signing, the signer's email address, your firm's name and the code — never client data, and never the documentUnited States
Timestamp authority (DigiCert; Sectigo as fallback)Issues an independent timestamp for every completed electronic signature — one over the finished document, and, when a signature is cryptographically sealed, a second one over the signature itself — so the time of signing can be verified without trusting usA cryptographic digest and a random number, never a file name, client name, firm name, document content or any other detailUnited States
Google Fonts (Google LLC)Delivers the typefaces on our web pages and in the applicationYour IP address and browser details when a page or the app loads — never account or client dataUnited States

The AI document feature, stated plainly

AI-assisted document import is off until your firm's owner turns it on, in the firm's own settings. When it is off, no document contents are ever sent to an AI provider.

When a firm enables and uses it, the contents of that document are transmitted to OpenRouter, which routes it to an AI model provider, for the sole purpose of extracting client details. We have configured our account to route only to endpoints that contractually do not retain data, and we do not enable any setting that would permit retention, training, or commercial use of that content.

Information stored outside Canada

Where the service's code runs. Your firm and client data are stored in Canada, and the application functions that operate the service — including the one that receives documents uploaded to your firm — are set to run in Canada as well (AWS ca-central-1, Montréal). Three narrow paths are not, because they are triggered from outside the application rather than by it, and Supabase runs them at whichever of its locations is nearest the caller — which may be in the United States: the notice Stripe sends us when a subscription changes, which carries billing identity; the nightly maintenance job that permanently removes files a firm has already deleted, which handles file names and never file contents; and the unsubscribe endpoint when a link is opened directly against it, which carries only the token in that link. None of the three receives a client document.

Some providers process information in the United States. While information is outside Canada it is subject to the laws of that jurisdiction, and may be accessible to foreign courts and law enforcement under those laws. We disclose this because PIPEDA requires it, not because we are aware of any such request.


5. How we protect it

Encryption in transit and at rest. Firm-level isolation enforced at the database layer, so one firm's queries cannot reach another firm's data. Multi-factor authentication is available. Encrypted offsite backups are taken nightly, and our ability to restore from them has been tested against real data rather than assumed. Access to production systems is limited to personnel who require it, reviewed quarterly, and documented.

Support access. When your firm asks us for help inside its account, we can enter only by a code your firm's owner generates and gives to us. The code works once, opens a session of at most two hours, and your firm can end it at any time. From the moment a session opens it is visible to your firm in the app; an email goes out to each of your firm's owners, and the app shows whether those notices have been sent. Every change made during the session to your client records, your team, your firm's settings, and your client upload links is recorded in your firm's own activity history, and the session itself is attributed to our support account; backup snapshots are not written to that history — their lifecycle is visible on your Backups screen. During that window, support sees what your firm sees — including client documents.

Our full security program is documented internally; a summary is available to customers on request.

No system is perfectly secure, and we do not claim otherwise. If a breach occurs that creates a real risk of significant harm, we will notify affected firms without unreasonable delay and report to the Privacy Commissioner of Canada and the Alberta Information and Privacy Commissioner as required. We maintain records of all breaches, including those we assess as not reportable.


6. How long we keep it

Firm account and client dataFor the life of the account
After account closure90 days — then permanently deleted, signed documents and their signing records included (below)
Encrypted backups90 days — deleted data persists in backups until they age out, so full disappearance from backups follows roughly 90 days after deletion
Electronically signed documents and their signing recordsSix years from signing — the record-keeping floor the CRA applies to the documents these signatures are used for. The system refuses ordinary deletion of them for the whole period, including when the client file they belong to is deleted, and the signing record itself cannot be deleted by anyone at the firm. While the account is open, a firm owner can end the hold early by releasing it, which requires a written reason and is recorded in the firm's audit history. Restoring a snapshot keeps signed documents that are still under hold and preserves or re-creates the client records they belong to; re-creating a client record for these documents does not bring back its tasks, notes, folders or upload links. Deleting a client file voids any signing that was still in progress for that client. When a snapshot is restored, signings stay linked if their client returns, including a client re-created for a held document; in-progress signings for clients that remain absent are permanently cancelled. Completed signing records survive either operation. If your firm closes its account inside that period, the hold does not extend past closure: they are deleted with everything else 90 days after closure, and it is your firm's responsibility to download the signed documents and their certificate pages from the client file while it still has access, and keep them for the rest of the period in its own records
Audit recordsFor the life of the account
Breach records24 months minimum, as PIPEDA requires

The 90-day post-closure window exists so a firm closing its account — even mid–tax-season — has a real opportunity to export its records first. The structured export is self-serve, available at any time, and stays available after access ends; it is an index of your documents, not the documents themselves, which must be downloaded from the client file while your firm still has access (§7).


7. Your rights

Under PIPEDA and Alberta PIPA you may:

Firms can export their own records as a structured file at any time, without asking us. The file is an index of the documents in each client file rather than the documents themselves, and it does not include the activity log or signing records.

We respond to requests within 30 days, as required by law. We may need to verify identity first. If your request concerns information a firm holds about you as its client, or a document you signed at a firm's request, contact that firm — they control it, and we will assist them. A completed signing record is evidence of the signing and is not altered afterwards; a correction is made by the firm issuing a new request.


8. Children

NorthForm is a business tool, not directed at children, and we do not knowingly collect personal information from anyone under 18 as an account holder. Client records may include information about minors — for example, dependants on a tax return — provided by the firm under its own authority.


9. Privacy Officer

Alberta PIPA requires a designated individual accountable for compliance. Reach NorthForm's Privacy Officer at:

hello@getnorthform.com


10. Changes

We will post material changes here and notify firm account holders by email before they take effect. Continuing to use NorthForm after that means accepting the updated policy.


11. Contact

NorthForm · hello@getnorthform.com