Skip to main content
NORTHLINEIQDIGITAL PRESENCE INTELLIGENCE
Menu

PRIVACY, ASSESSMENTS & ANALYTICS

How NorthlineIQ handles public-site measurement and Digital IQ requests.

This notice explains what the URL-first founding-pilot journey collects, how a reviewed assessment and bounded Fix use it, how long information is retained, and what the public site sends to Google Analytics.

DIGITAL IQ FOUNDING PILOT

Only what the current step needs.

The initial score request collects one public business website URL. It creates or reopens the assessment journey; it does not require a contact profile before NorthlineIQ can show the real assessment state.

After useful reviewed findings are available, a customer may provide an email for the complete report and essential service communication. Additional business or fulfillment information is requested only when operationally necessary. Phone is not required for the standard journey.

NorthlineIQ may also retain minimized campaign fields (UTM source, medium, campaign, and content), the intake landing path, an external referrer origin or same-site path, submission time, consent version, privacy-notice version, and consent timestamps. Referrer query strings and fragments are not retained.

The information is used only to receive, review, perform, manually deliver, support, fulfill, or delete the requested assessment or purchased work. Owner-supplied goals and context do not become verified or scored evidence automatically.

Do not submit passwords, Google or platform credentials, card information, customer lists, health information, or other sensitive information. There is no marketing enrollment, CRM transfer, customer account, or autonomous publication in this release.

Assessment information is not used to improve the methodology. Any future methodology-improvement reuse would require a separate explicit opt-in that does not exist in V1.

PAYMENT & TRANSACTIONAL MESSAGES

Production commerce remains explicitly gated.

Digital IQ Fix checkout is disabled in production unless NorthlineIQ separately enables a verified payment provider and the required commercial policies. Local validation may use a clearly labeled test adapter that creates no live charge and never accepts raw card data.

If hosted payment is enabled later, card entry occurs on the payment provider’s hosted surface. NorthlineIQ stores order and verified payment status, provider references needed for reconciliation, and the frozen purchased scope—not raw card numbers or security codes.

Transactional assessment, purchase, access, completion, and reassessment messages are queued in a disabled outbox until an approved sender is configured. Tests may use a local capture adapter; it never delivers to an external recipient. NorthlineIQ does not treat essential service messages as marketing consent.

PUBLIC EVIDENCE

Bounded collection, started by a reviewer.

Submitting a request never starts outbound website collection. An authenticated human reviewer must explicitly accept the request and start any bounded inspection of the submitted public website.

The collector may record normalized observations such as public page status, titles, canonical and robots directives, headings, navigation, structured-data types, public service/location/contact signals, calls to action, and sampled same-site link integrity. It does not sign in, execute forms, retain cookies, bypass access controls, or crawl unrelated sites.

NorthlineIQ does not retain a mirror of the website. It stores the minimum observation needed for review, its source URL, collection method, retrieval time, caveat, and content hash. Public business information may still be personal data for a sole proprietor and is handled under the same assessment controls.

RETENTION & DELETION

Each data class has a bounded schedule.

  • Withdrawn or unaccepted requests, optional owner context, and attribution: 30 days
  • Accepted contact information, optional owner context, and attribution: 90 days after delivery or closure
  • Approved assessment and evidence snapshot: 12 months
  • Operational and security logs: 30 days
  • Backups: 35-day expiry

A verified deletion request removes live contact and assessment data, retained report artifacts, and identifying audit details. Non-identifying tombstones and keyed erasure controls may remain solely to record and enforce erasure, including after a restore. Deleted data may remain in retained backups until the 35-day expiry.

Launch gate: a monitored privacy-request address and identity-verification procedure must be configured before production intake can be enabled. Unaccepted requests still expire automatically after 30 days.

PUBLIC-SITE ANALYTICS

Aggregate use and fixed interaction events—not form contents.

NorthlineIQ uses Google Analytics 4 for site measurement and performance analysis on eligible public pages under a notice-only analytics posture.

Google Analytics may measure page views, session activity, browser/device category, approximate geography, standard engagement, and fixed public interactions such as CTA clicks, sample-dimension selection, methodology disclosure, and starting the URL form.

After a protected assessment begins, NorthlineIQ records the real lifecycle states score_completed, report_requested, fix_viewed, checkout_started, purchase_completed, fulfillment_completed, and rescore_completed in its first-party audit store. Personalized assessment, checkout, report, and internal-review pages do not load Google Analytics, so those lifecycle records are not sent to Google in this release.

Analytics parameters are fixed product-area, funnel-stage, and source-context labels. They never contain a business name, contact name, email, phone, submitted website, order or assessment identifier, form text, evidence, credentials, or payment information.

Google Analytics uses cookies or similar browser identifiers, including the _ga cookie, to compile aggregate reports. NorthlineIQ does not set a Google Analytics User-ID, enable Google Signals, or enable advertising-personalization signals.

Query-bearing pages, this notice, internal review pages, customer reports, sign-in, private application pages, APIs, and operations routes are not tagged. Direct visits, duplicate submissions, honeypot traffic, and visual-only states do not manufacture a completed lifecycle event.

Google processes Analytics data as the measurement provider. Learn how Google uses information from sites that use its services, review Google’s Privacy Policy, or use Google’s Analytics opt-out browser add-on.

Effective date: August 25, 2026.