The short version. Northdue helps businesses collect overdue invoices. To do that, our clients connect their accounting software and mailbox, and we use that data only to provide the service they asked for.
We don't sell personal information or use it for advertising. We don't use it, or let our AI provider use it, to train AI models. The website you're on doesn't use tracking cookies or analytics.
1. Who this policy covers
This policy explains how Northdue ("we", "us") handles personal information in three situations:
- Visitors to northdue.com, including anyone who asks for a demo, a quote or a Cash Leak Scan.
- Clients and their users: businesses that use the Northdue service at app.northdue.com, and the people who sign in on their behalf.
- Our clients' customers: the businesses, and the people at those businesses, that our clients ask us to contact about invoices. We handle their information on our clients' behalf (see section 8).
For information about visitors and client users, we decide how it's used. For the data in a client's accounting software and mailbox, we act as a service provider to that client and process it only to provide the service, under our agreement with them.
2. What we collect
Information you give us
- Forms on this website: your name, work email, company, role, phone number (optional), accounting software, approximate overdue balance, your message, and any aging report you upload.
- Accounts: your name, email address, role, a salted hash of your password, and your two-step sign-in secret if you set one up.
- Correspondence: what you send us by email or through the app.
Information from connected accounts
When a client connects its tools, we receive, on the client's behalf:
- From accounting software (QuickBooks Online, QuickBooks Desktop, Xero, or an uploaded report): customers and their contact details, invoices, payments, credits and invoice PDFs.
- From a mailbox (Gmail, Google Workspace, Microsoft 365, or another mail server): the mailbox's email address, and the messages we keep: replies from the client's customers, and messages from other senders that mention an invoice or payment. Every new message other than sent mail, drafts, spam and trash is downloaded and checked automatically to find these; the rest are skipped. We also send the emails the client approves from that mailbox. See section 4 for how Google data is handled.
Information from our clients' customers
When a client's customer replies to an email, answers on their customer page, or speaks to us or an AI caller on the phone, we record what they tell us, such as a payment date, a dispute or a new contact. AI calls, if a client turns them on, may be recorded and transcribed.
Information collected automatically
- Logs: our servers record IP addresses, browser types, pages requested and times, to run and secure the service.
- Security records: sign-in attempts and an audit log of actions taken in the app.
- Cookies: this website sets no cookies and uses no analytics, advertising or tracking tools. The app uses only strictly necessary cookies to keep you signed in and to protect forms, and your browser's local storage for display preferences such as light or dark mode.
3. How we use information
- To provide the service: reading a client's books, deciding who to contact, drafting emails, sending approved emails, reading and acting on replies, preparing calls, matching payments, producing reports and billing.
- To answer you: replying to demo and quote requests and preparing Cash Leak Scans.
- To keep things secure: authenticating users, preventing fraud and abuse, and keeping audit records.
- To meet legal obligations and enforce our terms.
- To run our business: for example, sending account emails such as invitations, password resets and fee invoices.
We don't sell personal information, share it for cross-context behavioral advertising, or use it to make decisions about anyone's creditworthiness or eligibility for credit.
4. Google user data
This section explains how Northdue accesses, uses, stores and shares data from Google accounts when a client connects Gmail or Google Workspace.
What we access
- Send email (
gmail.send): to send, from the client's own address, the collection emails the client or its chosen approver has approved. - Read email (
gmail.readonly): every new message other than sent mail, drafts, spam and trash is downloaded and checked automatically, to find replies from the client's customers and messages about invoices or payments, so the service can record promises, disputes and questions. - Email address (
openid,email): to identify the connected mailbox and set the sender address.
How we use it
We use Google user data only to provide these user-facing features to the client who connected the account: sending approved emails, and understanding and acting on customers' replies. We don't use it for any other purpose.
How we store it
Replies from the client's customers, and messages from other senders that mention an invoice or payment, are stored in that client's records so the client, its approvers and Northdue's team can handle them. They're kept for as long as the client's other records (section 9). Other messages are skipped: we keep only the message's ID so it isn't checked again, and we don't store its content. Access tokens are encrypted with a key that's kept separately from the data.
How we share it
- The text and subject of a customer's reply, without the history it quotes where that can be separated, are sent to our AI provider, Anthropic, so the reply can be understood (see section 6). This is necessary for the feature the client uses and is covered by the client's agreement to these terms.
- We don't transfer or sell Google user data to advertising platforms, data brokers or information resellers, and we don't use it for advertising, for determining creditworthiness, or for lending.
- We don't use Google user data, and we don't retain it, to develop, improve or train generalized or non-personalized AI or machine learning models.
Who can read it
As part of the service a client engages us for, Northdue's team reads customers' replies and messages that may be about invoices or payments, so we can handle them for the client. The client agrees to this when it accepts our Terms of Service and connects its mailbox. Beyond that, staff read Google user data only for security purposes such as investigating abuse, to comply with the law, or when the data has been aggregated and anonymized for internal operations.
Limited Use
Northdue's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Removing access
A client can disconnect the mailbox from its Connections page at any time, or remove Northdue's access from its Google Account permissions. We then stop using the connection and delete its tokens. To have stored messages deleted, write to privacy@northdue.com.
5. Microsoft, Intuit and Xero data
The same principles apply to data from Microsoft 365, QuickBooks and Xero. We use it only to provide the service to the client that connected it. We read accounting data and never change it. We don't sell it, use it for advertising, or pass it to anyone except the service providers in section 7 who help us deliver the service. We don't use it, or allow it to be used, to train, fine-tune or improve AI models. Clients can disconnect from their Connections page, or revoke access from their Microsoft, Intuit or Xero account, at any time.
6. AI processing
Northdue uses Claude, provided by Anthropic, PBC, through its commercial API, to draft collection emails and to understand replies.
- To draft an email we send: the client's company and sender name, the tone the client chose, the customer's company name and contact's first name, invoice numbers, the total past due, how many days past due, how many emails were already sent, any promised payment date, and the reply-by date.
- To understand a reply we send: the customer's message and its subject, without the history it quotes where that can be separated, and the open invoice numbers on that account.
- Under Anthropic's commercial terms, Anthropic may not train its models on this content. Anthropic deletes API inputs and outputs within 30 days, except content flagged for a usage-policy review, or where the law requires it to keep data longer.
- At a client's request we switch AI drafting off. Templates and rules then do the same jobs, and email content isn't sent to Anthropic.
If a client turns on AI phone calls, the call audio and transcript are processed by Vapi and the providers Vapi uses to run calls, which can include speech and language model providers.
7. Who we share information with
| Who | Why |
|---|---|
| Render (hosting, Virginia, US) | Runs the app and stores its data. |
| Anthropic | Drafts emails and understands replies (section 6). |
| Vapi | Places AI phone calls, only for clients that turn them on. |
| Our email provider | Sends account emails such as invitations, password resets and fee invoices. |
| The client's own providers | Emails are sent through the client's mailbox, and data is read from its accounting software, at the client's direction. |
We may also disclose information to professional advisers under confidentiality; when required by law or to protect rights, safety and security; in connection with a merger, acquisition or sale of assets, subject to this policy; or with your consent.
8. Our clients' customers
If you received an email about an invoice, used a customer page, or got a call, it was sent on behalf of the business you owe, which is our client. That business decides how your information is used, and our handling of it follows their instructions and this policy. Northdue contacts businesses only, not consumers, and honors requests to stop calls.
If you have a question or a request about your information, you can contact the business directly or write to us at privacy@northdue.com, and we'll pass it on and help them respond.
9. How long we keep information
- Website requests: as long as needed to respond and follow up, and no longer than 24 months.
- Uploaded aging reports: deleted after 90 days, along with any scan we made from them, or sooner if you ask.
- Client data: kept while the client uses the service and, after an engagement ends, while its account is archived so it can be restored. If a client asks us to delete its data, we delete it, except records we're required to keep, such as fee invoices, and confirm when it's done. Copies in our nightly backups are replaced within 7 days by default, and our hosting provider's disk snapshots expire on its own schedule.
- Connection tokens: deleted when a connection is removed.
- Logs: kept for a limited period to run and secure the service.
10. Security
We protect information with encryption in transit and at rest, a separate key for connection tokens, two-step sign-in, role-based access, audit logs and nightly backups. Our Security page has the details. No system is perfectly secure; if we learn of a breach affecting your information, we'll notify you as the law requires.
11. Your rights and choices
Depending on where you live, you may have the right to know what personal information we hold about you, to get a copy, to correct it, to delete it, to object to or restrict some uses, and to have it transferred. You won't be treated differently for exercising these rights.
- California residents: in the past 12 months we collected identifiers, commercial information (such as invoice and payment records), internet activity (logs), professional information, and audio information (recordings of AI calls, for clients who use them), for the purposes in section 3. We don't sell or share personal information as those terms are defined in California law, and we don't use sensitive personal information to infer characteristics about anyone.
- People in the EEA, UK and Switzerland: we rely on performing our contract with our clients, our legitimate interests in running and securing the service and responding to inquiries, your consent where we ask for it, and legal obligations. You can also complain to your local data protection authority.
To make a request, email privacy@northdue.com. We'll verify your request before acting on it, and you can use an authorized agent. If your information is held on behalf of one of our clients, we'll work with that client to respond.
12. Where data is processed
Northdue's app and data are hosted in the United States. If you're outside the US, your information will be transferred to and processed in the US, where our service providers also operate.
13. Children
Northdue is a business service. It isn't directed to children, and we don't knowingly collect information from anyone under 16.
14. Changes to this policy
We'll post any changes here with a new date. If a change is significant, we'll tell clients by email or in the app before it takes effect, and where the law or a provider's rules require it, such as a new use of Google user data, we'll ask for consent.
15. Contact
Northdue
Email: privacy@northdue.com