Privacy Policy
Effective date: June 28, 2026
Northstar Analytics, a product of Captive Demand.
This Privacy Policy explains how Northstar Analytics, a product of Captive Demand (“Northstar Analytics”, “we”, “us”, or “our”), collects, uses, shares, and protects information when you use our marketing-analytics application available at northstaranalytics.io (the “Service”). By using the Service, you agree to the practices described here.
1. Who we are
Northstar Analytics is a multi-tenant analytics platform operated by Captive Demand. We help teams connect their advertising, analytics, and CRM tools and turn that data into dashboards, reports, and AI-assisted insights. If you have any questions about this policy or your data, you can reach us at support@captivedemand.com.
2. Information we collect
Account & identity
Authentication and account management are handled by our identity provider, Clerk. When you sign up or sign in, we receive and store your name, email address, and your organization (workspace) membership and role. We use this to authenticate you, scope your access to the correct organization, and operate multi-tenant access controls.
Application data
Data you create in the Service — dashboards, reports, saved metric definitions, integration connection metadata, sharing links, and audit logs of actions taken in your workspace — is stored in our database (Supabase, a managed PostgreSQL service). This data is scoped to your organization and isolated from other tenants using row-level security.
Billing data
Subscriptions and payments are processed by Stripe. We store billing metadata such as your Stripe customer and subscription identifiers, plan tier, and subscription status. We do not collect or store your full payment-card details — card data is handled directly by Stripe under their security and compliance program.
Connected data sources
With your explicit authorization, the Service connects to third-party platforms on your behalf via OAuth to read advertising, analytics, and CRM data. The platforms we integrate with are Google Ads, Google Analytics (GA4), Meta Ads, and HubSpot. For each connection we:
- Store the OAuth access and refresh tokens needed to query the platform’s API, encrypted at rest. We never receive or store your password for these platforms.
- Read advertising spend and performance metrics, web/app analytics metrics, and CRM object data (e.g. contacts and deals) in order to display them back to you as analytics.
- Store the metrics, dimensions, and aggregates we derive from those sources so your dashboards and reports load quickly.
3. Google API Services — Limited Use disclosure
When you connect Google Ads or Google Analytics, the Service accesses Google user data through Google APIs using the https://www.googleapis.com/auth/adwords and https://www.googleapis.com/auth/analytics.readonly scopes (read-only access to your Google Ads and Google Analytics data).
Northstar Analytics’ use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we only use Google user data to provide and improve the user-facing analytics features you request, we do not transfer or sell this data to third parties for advertising or other unrelated purposes, we do not use it for serving advertisements, and we do not allow humans to read it except where you give affirmative consent, where it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or where the data has been aggregated and anonymized.
4. How we use your information
- To provide, operate, and maintain the Service and your account.
- To build and render the analytics dashboards and reports you configure from your connected data sources.
- To power AI analysis features (for example, answering questions in plain English or generating a chart on request), where relevant metrics or aggregates are sent to our AI/LLM provider to produce a response.
- To process subscriptions, billing, and invoices via Stripe.
- To provide customer support and respond to your requests.
- To secure the Service, prevent abuse, debug issues, and comply with legal obligations.
We do not sell your personal data or your connected platform data.
5. Sharing and sub-processors
We share data only with service providers (“sub-processors”) who process it on our behalf to deliver the Service, and with the third-party platforms you choose to connect. Our key providers are:
- Clerk — authentication and identity management.
- Supabase — application database and storage.
- Stripe — subscription billing and payment processing.
- Vercel — application hosting and content delivery.
- An AI/LLM provider — to power AI analysis features.
- The connected platforms you authorize (Google Ads, Google Analytics, Meta Ads, HubSpot), which we query on your behalf.
We may also disclose information if required by law, to enforce our agreements, or to protect the rights, safety, and security of our users and the Service. If we are involved in a merger or acquisition, data may be transferred subject to this policy.
6. Data security
We take reasonable technical and organizational measures to protect your data. OAuth tokens for connected data sources are encrypted at rest. Tenant data is isolated using PostgreSQL row-level security (RLS) so that one organization cannot access another’s data. Access to production systems is restricted, and traffic is served over encrypted connections (HTTPS). No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
7. Data retention
We retain your account and application data for as long as your account is active or as needed to provide the Service. When you disconnect an integration, we revoke and delete the stored OAuth tokens for that connection. You may request deletion of your account and associated data at any time (see “Your rights and choices” below). We may retain limited records where required for legal, accounting, or security purposes.
8. Your rights and choices
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise these rights as follows:
- Access / deletion requests: email support@captivedemand.com and we will respond within a reasonable timeframe.
- Revoking connected sources: disconnecting an integration from within the app revokes and deletes the OAuth tokens we store for that source. You can also revoke our access directly from the relevant platform’s security settings (for Google, via your Google Account permissions).
9. Cookies and sessions
We use strictly necessary cookies to keep you signed in and maintain your authenticated session (managed by Clerk). These are required for the Service to function. We do not use the Service’s cookies for third-party advertising.
10. Children’s privacy
The Service is a business tool intended for use by organizations and professionals. It is not directed to children, and we do not knowingly collect personal information from anyone under the age of 16 (or under 13 where applicable). If you believe a child has provided us information, contact us and we will delete it.
11. International data transfers
We and our sub-processors may process and store data in the United States and other countries. Where data is transferred across borders, we rely on appropriate safeguards and process it in accordance with this policy and applicable law.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, provide additional notice. Your continued use of the Service after an update constitutes acceptance of the revised policy.
13. Contact us
If you have questions, concerns, or requests regarding this policy or your data, contact us at support@captivedemand.com.