Privacy and Customer Data Policy

Effective: August 19, 2026 · Version: 2026-08-19

1. Who we are and what this policy covers

North Bench provides an open-order dashboard and vendor follow-up service for lab, science, and procurement teams. This policy covers northbench.co, the North Bench application, and information processed while providing the service.

North Bench is operated by Safari Tedeneke, a Virginia sole proprietor doing business as North Bench. Questions or privacy requests can be sent to hello@northbench.co or to the business mailing address below.

2. Information we collect

We collect or process only the information reasonably needed to operate the service:

  • Business account and contact information: name, business email, organization, role, account credentials, and support requests.
  • Open-order information: order and line references, vendor and item details, dates, quantities, status, aging information, and customer notes supplied through an authorized CSV or Excel export.
  • Vendor-contact and communication information: vendor names, business email addresses, message metadata, message subjects, message bodies, attachments when authorized, delivery events, and reply history related to the customer's orders.
  • Service and security information: essential session and security cookies, IP address, browser/device information, request and error logs, timestamps, and audit records used to operate, secure, and troubleshoot the service.
  • Billing information: plan, subscription, invoice, and payment-status information. Stripe processes card or bank details; North Bench does not store complete payment-card numbers.

We receive information directly from the customer or its authorized users, from vendors responding to customer-authorized messages, and from service providers that operate the workflow.

3. Information the service must not receive

Do not provide patient or protected health information, study-subject identifiers, regulated research data, sensitive research content, government identification numbers, account passwords or API keys, card or bank-account data, employee or HR records, export-controlled information, or confidential information that the customer is not authorized to share. North Bench may reject, quarantine, or delete prohibited information.

4. How we use information

We use information to:

  • configure and operate the subscription service;
  • import and normalize authorized open-order records;
  • prepare and send customer-authorized vendor follow-ups;
  • receive, classify, and organize vendor replies;
  • produce dashboards, exception lists, support records, and agreed proof metrics;
  • secure, monitor, troubleshoot, and improve the service; and
  • administer agreements, billing, and customer requests.

North Bench does not sell customer data or share it for cross-context behavioral advertising. We do not publish a customer's name, logo, quote, case study, or identifying metrics without separate written permission.

North Bench may maintain a shared directory of vendor organizations and business contact information obtained from public sources or customer-authorized inputs. Customer-specific order relationships, sendability and routing decisions, messages, replies, and activity history remain tenant-scoped. North Bench applies lawful-retention, customer-license, notice, accuracy, objection, suppression, and deletion rules to customer-provided vendor information consistent with this policy.

5. Automated processing and AI providers

North Bench may use automated rules and an AI service provider to classify vendor replies and recommend a next action. The applicable provider and permitted data categories are documented in the customer agreement, Data Processing Addendum, or subprocessor schedule.

Automated classifications are operational aids. Uncertain, sensitive, or failed results are routed for review and are not final procurement decisions.

6. Service providers

North Bench currently relies on the following service-provider categories:

Provider Role Information involved
Render Application hosting, PostgreSQL database, Redis task infrastructure, and service logs Account, order, workflow, audit, and technical data
Cloudflare DNS and R2-compatible object storage for uploaded files Network-routing data and authorized raw upload files
Resend Outbound transactional and vendor-follow-up email Recipient, subject, message content, and delivery metadata
Google Workspace Business email and inbound reply mailbox Business contacts, message content, attachments, and routing metadata
AI service provider Vendor-reply classification and structured recommendations Authorized operational information documented in the applicable customer agreement, Data Processing Addendum, or subprocessor schedule
Stripe Billing, invoices, subscriptions, and payment processing Customer and billing identity, plan, invoice, and payment information
Google Fonts Delivery of website typefaces IP address, browser/device, and request metadata received by Google when fonts load

These providers process information under their own terms and data-processing commitments. North Bench remains responsible for selecting providers and limiting what it sends to each provider.

7. Cookies and tracking

North Bench uses essential cookies for sign-in, session continuity, and cross-site request-forgery protection. The verified product does not currently use advertising cookies or behavioral analytics. The service does not currently respond to browser "Do Not Track" signals because it does not perform cross-site behavioral tracking. If analytics or advertising tools are added, this policy and any consent controls must be updated first.

8. Retention and deletion

North Bench keeps normalized order records, vendor-reply history, audit records, and support information while needed for the active service and documented closeout period. Customer-specific retention terms may be stated in a signed order form or Data Processing Addendum.

At verified customer erasure, North Bench deletes the departing customer's tenant mappings and customer-specific order, routing, message, reply, and activity records. Shared vendor/contact directory records and non-identifying vendor-level engagement totals may remain, subject to the license, notice, accuracy, suppression, objection, and deletion boundary described in this policy.

Successful raw upload files are scheduled for deletion after 30 days and failed or cancelled raw uploads after 7 days, or earlier after a verified customer request.

Deletion from active systems may not immediately remove information from security logs, provider systems, or backups. Provider-specific deletion and aging obligations are tracked through the customer-erasure receipt.

9. Security and incidents

North Bench uses safeguards intended to protect customer information, including access controls, tenant-scoped records, encrypted connections, restricted intake, and provider-managed infrastructure. No system is completely secure. If North Bench confirms a security incident affecting customer information, it will investigate, contain the issue, coordinate with affected providers, and notify affected customers as required by the agreement and applicable law.

10. Customer requests

An authorized customer representative may ask what customer information North Bench holds, request a correction or export, or request deletion by emailing hello@northbench.co. North Bench will verify the requester's authority before acting.

If the Virginia Consumer Data Protection Act or another applicable privacy law requires additional rights, North Bench will provide the required authenticated access, correction, deletion, portability, opt-out, response-timing, extension, and appeal process. If a statute does not currently apply, North Bench documents its threshold analysis and reassesses it as its customers and processing change.

11. Changes to this policy

The effective date appears at the top. Material changes will be posted here and communicated to active customers before they take effect when reasonably practicable. A prior policy version continues to govern earlier processing when required by the applicable agreement.

12. Contact

Email: hello@northbench.co

Business mailing address: 590 Grove St #10, Herndon, VA 20172