Skip to main content
NORTHLINEIQDIGITAL PRESENCE INTELLIGENCE
Menu

PRIVACY, ASSESSMENTS & ANALYTICS

How NorthlineIQ handles public-site measurement and Digital IQ requests.

This notice explains what the free-review journey collects, how NorthlineIQ uses it, how long information is retained, and what the public site sends to Google Analytics.

DIGITAL IQ FOUNDING PILOT

Only what the current step needs.

The initial score request collects one public business website URL after the requester explicitly authorizes NorthlineIQ to process that URL for the requested assessment and acknowledges this notice. It creates one assessment linked to a protected browser session. A returning visitor resumes it only while that same secure session remains valid; a website URL alone is not used to reveal or reopen another person’s assessment.

On the protected assessment page, the requester may provide one email address for manual assessment notification and essential operational follow-up. The address is linked to the existing assessment record, does not enroll the requester in marketing, and does not trigger an automated email in this release. Additional business information is requested only when operationally necessary. Phone is not required.

NorthlineIQ may also retain minimized campaign fields (UTM source, medium, campaign, and content), the intake landing path, an external referrer origin or same-site path, submission time, consent version, privacy-notice version, and consent timestamps. Referrer query strings and fragments are not retained.

The information is used only to receive, review, perform, manually deliver, support, fulfill, or delete the requested assessment or purchased work. Owner-supplied goals and context do not become verified or scored evidence automatically.

Do not submit passwords, Google or platform credentials, card information, customer lists, health information, or other sensitive information. There is no marketing enrollment, CRM transfer, customer account, or autonomous publication in this release.

Assessment information is not used to improve the methodology. Any future methodology-improvement reuse would require a separate explicit opt-in that does not exist in V1.

PAYMENT & SERVICE MESSAGES

Card details stay with the payment provider.

NorthlineIQ does not currently collect card details on this public site. When hosted checkout is available, card entry occurs on the payment provider’s secure surface. NorthlineIQ retains the order, verified payment status, provider references needed for reconciliation, and the agreed scope—not raw card numbers or security codes.

Assessment, purchase, access, completion, and reassessment messages are essential service communication. They are not treated as consent to receive marketing.

PUBLIC EVIDENCE

Bounded collection, started by a reviewer.

Submitting a request never starts outbound website collection. An authenticated human reviewer must explicitly accept the request and start any bounded inspection of the submitted public website.

The collector may record normalized observations such as public page status, titles, canonical and robots directives, headings, navigation, structured-data types, public service/location/contact signals, calls to action, and sampled same-site link integrity. It does not sign in, execute forms, retain cookies, bypass access controls, or crawl unrelated sites.

NorthlineIQ does not retain a mirror of the website. It stores the minimum observation needed for review, its source URL, collection method, retrieval time, caveat, and content hash. Public business information may still be personal data for a sole proprietor and is handled under the same assessment controls.

RETENTION & DELETION

Each data class has a bounded schedule.

  • Withdrawn or unaccepted requests, optional owner context, and attribution: 30 days
  • Accepted contact information, optional owner context, and attribution: 90 days after delivery or closure
  • Approved assessment and evidence snapshot: 12 months
  • Operational and security logs: 30 days
  • Backups: 35-day expiry

A verified deletion request removes live contact and assessment data, retained report artifacts, and identifying audit details. Non-identifying tombstones and keyed erasure controls may remain solely to record and enforce erasure, including after a restore. Deleted data may remain in retained backups until the 35-day expiry.

To withdraw a request or ask for access or deletion, email thaddeus@northlineiq.com. NorthlineIQ verifies the request before acting so one person cannot erase another business’s assessment.

PUBLIC-SITE ANALYTICS

Aggregate use and fixed interaction events—not form contents.

NorthlineIQ uses Google Analytics 4 for site measurement and performance analysis on eligible public pages under a notice-only analytics posture.

Google Analytics may measure page views, session activity, browser/device category, approximate geography, standard engagement, and fixed public interactions such as CTA clicks, sample-dimension selection, methodology disclosure, and starting the URL form.

After a protected assessment begins, NorthlineIQ records real lifecycle state changes in its first-party audit store. Personalized assessment, checkout, report, and internal-review pages do not load Google Analytics, so the submitted website, notification email, assessment content, and private lifecycle records are not sent to Google.

Analytics parameters are fixed product-area, funnel-stage, and source-context labels. They never contain a business name, contact name, email, phone, submitted website, order or assessment identifier, form text, evidence, credentials, or payment information.

Google Analytics uses cookies or similar browser identifiers, including the _ga cookie, to compile aggregate reports. NorthlineIQ does not set a Google Analytics User-ID, enable Google Signals, or enable advertising-personalization signals.

Query-bearing pages, this notice, internal review pages, customer reports, sign-in, private application pages, APIs, and operations routes are not tagged. Direct visits, duplicate submissions, honeypot traffic, and visual-only states do not manufacture a completed lifecycle event.

Google processes Analytics data as the measurement provider. Learn how Google uses information from sites that use its services, review Google’s Privacy Policy, or use Google’s Analytics opt-out browser add-on.

Effective date: August 30, 2026.