Northlight Privacy Policy
1 · Who We Are
Northlight is a strategy and operations consulting business created by Elizabeth Lemoine.
Operator: Elizabeth Lemoine
Business Registration: Pending (Nova Scotia)
Contact: support@bynorthlight.ca
Website: bynorthlight.ca
Physical Address: 15 Kaleigh Drive, Eastern Passage, Nova Scotia B3G 1E3, Canada
2 · Our Commitment to Your Privacy
Northlight is built on a philosophy of minimal data collection and maximum transparency. We collect only the information we need to serve you and improve our work — never to identify you personally or build profiles for advertising.
This policy explains:
- What information we collect on this website
- How we use third-party services (responsibly)
- Your rights under Canadian privacy law (PIPEDA) and international standards (GDPR)
- How to access, correct, or delete your data
Note: If you use Northlight Vault (our desktop app), that service has a separate privacy policy tailored to its specific data practices. View the Northlight Vault Privacy Policy.
3 · Information We Collect
On This Website (bynorthlight.ca)
Newsletter Signup — Aurora Brief
- You enter your first name and email address on our signup form
- You see optional consent checkboxes for promotional emails and personalised ads (controlled by Kit.com)
- You receive a confirmation email with a link to verify your subscription
- After confirming, you're subscribed to the Aurora Brief newsletter (sent monthly)
Your subscription to the Aurora Brief is confirmed whether or not you consent to the optional checkboxes.
Analytics — Plausible
Plausible collects no personal data — no cookies, no tracking IDs, no email addresses or names. Only anonymous aggregated data: page views, traffic sources, device types.
This helps us understand trends and improve the website, but we cannot tie any activity back to you as an individual.
No Contact Form
We don't have a contact form on this website. If you'd like to reach out, email us at support@bynorthlight.ca.
From the Aurora Brief Newsletter (Kit.com)
Kit.com collects and stores your first name, email address, and your optional consent choices for promotional emails and personalised ad targeting.
Kit.com's servers are US-based. Data is transferred under the EU–U.S. Data Privacy Framework, UK extension, and Swiss–U.S. Data Privacy Framework. Kit.com is SOC 2 Type II compliant and committed to GDPR, PIPEDA, and CCPA compliance.
When you confirm your subscription, Kit.com shows you two optional checkboxes. We encourage you to consent to promotional emails — that's how we share updates, early access, and relevant product news. You can manage these preferences at any time through Kit.com.
Unsubscribing
- Unsubscribe from promotional emails: link in any email from us, or manage in Kit.com account settings
- Unsubscribe from the Aurora Brief: same process
Delete Your Data — Right to Be Forgotten
Under PIPEDA and GDPR, you have the right to request deletion of your personal data.
Self-service (fastest): Fill out Kit.com's Right to Be Forgotten form
Or through us: Email support@bynorthlight.ca with "Data Deletion Request" in the subject line, and we'll submit the form on your behalf.
From Northlight Vault — If You Submit Feedback
If you submit feedback about Northlight Vault, we collect your name (optional), email address, and feedback text and type (bug report, feature idea, or general feedback).
Your feedback is stored in ClickUp (our task management system) so we can review, respond, and improve the app. We keep feedback for 12 months, then automatically delete it. You can request earlier deletion at any time by emailing support@bynorthlight.ca.
For full details on how Vault works with your data, see the Northlight Vault Privacy Policy.
From Client Projects — If You Engage Northlight for Services
If you work with Northlight on a project or consulting engagement, we may collect personal and business information needed to deliver the work: your name, email, and company information; documents you share with us; communications (emails, meeting notes, feedback); and project-related data specific to your engagement.
Google Workspace — email, documents, and communications
ClickUp — project tracking, timelines, and feedback
Both services are PIPEDA and GDPR compliant. We only access data needed for your project, don't use it for marketing, don't share it with third parties, and delete it when the project ends or upon your request.
4 · Third-Party Services & Data Flows
We use several tools to run Northlight. Here's where your data goes and why:
Kit.com — Newsletter Platform
| What data | First name, email, consent preferences |
| Where | US-based servers (data transferred via EU–U.S. DPF) |
| Why | Manages our Aurora Brief newsletter, sends monthly emails, handles subscriber preferences |
| Privacy | Kit.com Privacy Policy |
| Your control | Manage subscription settings in Kit.com account, or use the right-to-be-forgotten form linked above |
Plausible Analytics
| What data | None. Anonymous aggregated website traffic only — no personal data collected |
| Where | Plausible servers (EU-based) |
| Why | Understand how people use bynorthlight.ca, identify trends, improve the site |
| Privacy | Plausible Privacy Policy |
| Your control | No personal data is collected, so there's nothing to manage or delete |
Google Workspace
| What data | Email communications and documents (only if engaging Northlight for services) |
| Where | Google's global data centres (GDPR-compliant) |
| Why | We use Gmail and Google Drive to manage client projects, store documents, and communicate |
| Privacy | Google Privacy Policy |
| Your control | If you engage Northlight, we'll discuss data handling as part of your project agreement. You can request deletion when the project ends. |
ClickUp — Project Management & Feedback
| What data | Vault feedback (name, email, feedback text — with your consent) or client project data (name, email, project-related information) |
| Where | AWS servers (US and international, GDPR/SOC 2 compliant) |
| Why | We use ClickUp to track feedback, manage projects, and respond to users |
| Privacy | ClickUp Privacy Policy |
| Your control | For Vault feedback: request deletion by emailing support@bynorthlight.ca (we delete within 30 days). For client projects: deletion handled per your project agreement. |
Social Media
Northlight has a presence on LinkedIn, Threads (Meta), and Instagram. We link to these platforms on our website. When you click through to our social profiles, those platforms collect data according to their own privacy policies — we don't control this.
5 · Cookies & Tracking
Plausible Analytics: No cookies, no tracking IDs.
Kit.com: May use cookies to manage your subscription and track email engagement. See the Kit.com Privacy Policy for details.
Retargeting & Ads: We do not use retargeting pixels, ad trackers, or external ad networks. We don't track you across other websites.
6 · Data Retention
| Data Type | Retention | Who Manages |
|---|---|---|
| Newsletter email | Until you unsubscribe or submit right-to-be-forgotten | Kit.com |
| Vault feedback | 12 months, then auto-deleted | Northlight |
| Vault feedback — early deletion | Deleted immediately upon request | Northlight |
| Website analytics | N/A — anonymous only | Plausible |
| Client project data | As long as needed for project; deleted upon request | Northlight |
7 · Your Rights Under Canadian & International Privacy Law
PIPEDA — Personal Information Protection and Electronic Documents Act
As a Canadian resident, you have the right to:
- Know whether Northlight holds personal information about you
- Access any personal information we hold
- Correct inaccurate or incomplete information
- Withdraw consent for the collection or use of your personal information
- Request deletion of your personal information
- Lodge a complaint with the Office of the Privacy Commissioner of Canada
GDPR — If You're in the EU
If you're in the European Union, United Kingdom, or Switzerland, GDPR and similar laws give you additional rights:
- All PIPEDA rights above
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability — receive your data in a portable format
- Right to object to certain processing
- Lodge a complaint with your local data protection authority
How to Exercise Your Rights
Email support@bynorthlight.ca with your name, email, and a description of what you're requesting. We'll respond within 30 days. If your request involves a third-party service (Kit.com, ClickUp, etc.), we'll direct you to their forms or submit on your behalf.
For Kit.com right-to-be-forgotten requests: Fill out Kit.com's form directly — it's fastest.
8 · Bill C-27 & Emerging Privacy Standards
Canada's proposed Consumer Privacy Protection Act (Bill C-27) will replace PIPEDA with stricter requirements around consent, transparency, and data minimisation. While not yet law, Northlight is designed to align with these emerging standards:
- Minimal data collection: We collect only what we need
- Clear consent: Explicit opt-in for promotional communications
- User control: Easy access to manage, correct, and delete your data
- No dark patterns: We don't use manipulative design to trick you into sharing data
- Transparency: This policy is written in plain language, not legalese
When Bill C-27 becomes law, Northlight will be ready.
9 · Children's Privacy
Northlight services are not directed at anyone under 18. If you're under 18, please do not subscribe to our newsletter or submit feedback without parental consent.
10 · Changes to This Policy
We may update this privacy policy as our practices evolve. Material changes include:
- Adding new data collection practices
- Changing data retention periods
- Adding or removing third-party services that store your data
- Changes to how we use or share your personal information
We'll notify newsletter subscribers of material changes via email and updated release notes. Continued use of our services after notification constitutes acceptance of the updated policy.
Minor clarifications or corrections don't require notification.
11 · Contact Us
Questions about this privacy policy or your privacy rights?
Northlight
Physical Address: 15 Kaleigh Drive, Eastern Passage, Nova Scotia B3G 1E3, Canada
Privacy Commissioner of Canada — to lodge a complaint:
Office of the Privacy Commissioner of Canada