Privacy Notice
1. Scope and roles
This notice explains how Tan Ming Jing handles personal information when operating Northstar. For workspace content, an organisation may act as the primary decision-maker or controller and the Northstar operator may act as its processor or service provider. Users should direct workspace-specific requests to their organisation where appropriate.
2. Information collected
We may process account and profile information; workspace membership and role data; proposals, votes, comments, decisions, projects, tasks, calendar items, chat messages, and attachments; authentication and security events; device, session, browser, and coarse network identifiers; support communications; and limited usage and performance telemetry.
3. How information is used
Information is used to provide and personalise the service, authenticate users, enforce workspace isolation and permissions, deliver notifications, maintain chat and search, prevent abuse, investigate incidents, recover data, support users, comply with law, and improve reliability and usability.
4. Legal bases
Depending on jurisdiction and context, processing may be based on performing a contract, legitimate interests in operating and securing the service, consent where required, compliance with legal obligations, or instructions from the organisation that controls a workspace.
5. Cookies and local storage
Northstar uses essential cookies and browser storage for authentication, security, active-workspace selection, theme preference, limited client caching, and notification settings. Non-essential analytics or advertising technologies should not be enabled without updating this notice and implementing any consent mechanism required by law.
6. Sharing and service providers
Information may be processed by infrastructure and service providers used for database hosting, authentication, storage, deployment, email, anti-bot protection, monitoring, backups, and alerting. Information may also be disclosed to workspace administrators, authorised members, advisers, or authorities where required by law or necessary to protect rights and security.
7. International transfers
Service providers and users may be located in different countries. Where required, the operator and relevant organisation should use recognised safeguards for international transfers and select suitable hosting regions.
8. Retention
Account, workspace, security, and backup data are retained for as long as needed to provide the service, meet contractual or legal obligations, resolve disputes, enforce agreements, and maintain security. Workspace owners should define retention and deletion rules. Backup deletion may occur on a delayed cycle.
9. Security
Controls may include encryption in transit and at rest, PostgreSQL Row Level Security, role-based permissions, MFA, rate limiting, CAPTCHA, audit and security events, session management, CSP, backups, and restricted server credentials. No system is completely secure, and standard chat is not end-to-end encrypted.
10. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent. Northstar provides private account and owner/admin workspace JSON exports and a recorded account-deletion request workflow. Some requests must be handled by the organisation that controls your workspace, and identity verification, audit retention, backup cycles, and legal exceptions may apply.
11. Children
Northstar is not intended for children below the minimum age permitted for independent use in their jurisdiction. Schools or organisations using the service with younger users must obtain required permissions and configure appropriate safeguards.
12. Changes and contact
We may update this notice as the service or law changes. The effective date and version identify the current notice. Contact mjtan091123@gmail.com for privacy questions or requests.