Privacy and Customer Data Policy
Effective: August 19, 2026 · Version: 2026-08-19
1. Who we are and what this policy covers
North Bench provides an open-order dashboard and vendor follow-up service for lab, science, and procurement teams. This policy covers northbench.co, the North Bench application, and information processed while providing the service.
North Bench is operated by Safari Tedeneke, a Virginia sole proprietor doing business as North Bench. Questions or privacy requests can be sent to hello@northbench.co or to the business mailing address below.
2. Information we collect
We collect or process only the information reasonably needed to operate the service:
- Business account and contact information: name, business email, organization, role, account credentials, and support requests.
- Open-order information: order and line references, vendor and item details, dates, quantities, status, aging information, and customer notes supplied through an authorized CSV or Excel export.
- Vendor-contact and communication information: vendor names, business email addresses, message metadata, message subjects, message bodies, attachments when authorized, delivery events, and reply history related to the customer's orders.
- Service and security information: essential session and security cookies, IP address, browser/device information, request and error logs, timestamps, and audit records used to operate, secure, and troubleshoot the service.
- Billing information: plan, subscription, invoice, and payment-status information. Stripe processes card or bank details; North Bench does not store complete payment-card numbers.
We receive information directly from the customer or its authorized users, from vendors responding to customer-authorized messages, and from service providers that operate the workflow.
3. Information the service must not receive
Do not provide patient or protected health information, study-subject identifiers, regulated research data, sensitive research content, government identification numbers, account passwords or API keys, card or bank-account data, employee or HR records, export-controlled information, or confidential information that the customer is not authorized to share. North Bench may reject, quarantine, or delete prohibited information.
4. How we use information
We use information to:
- configure and operate the subscription service;
- import and normalize authorized open-order records;
- prepare and send customer-authorized vendor follow-ups;
- receive, classify, and organize vendor replies;
- produce dashboards, exception lists, support records, and agreed proof metrics;
- secure, monitor, troubleshoot, and improve the service; and
- administer agreements, billing, and customer requests.
North Bench does not sell customer data or share it for cross-context behavioral advertising. We do not publish a customer's name, logo, quote, case study, or identifying metrics without separate written permission.
North Bench may maintain a shared directory of vendor organizations and business contact information obtained from public sources or customer-authorized inputs. Customer-specific order relationships, sendability and routing decisions, messages, replies, and activity history remain tenant-scoped. North Bench applies lawful-retention, customer-license, notice, accuracy, objection, suppression, and deletion rules to customer-provided vendor information consistent with this policy.
5. Automated processing and AI providers
North Bench may use automated rules and an AI service provider to classify vendor replies and recommend a next action. The applicable provider and permitted data categories are documented in the customer agreement, Data Processing Addendum, or subprocessor schedule.
Automated classifications are operational aids. Uncertain, sensitive, or failed results are routed for review and are not final procurement decisions.
6. Service providers
North Bench currently relies on the following service-provider categories:
| Provider | Role | Information involved |
|---|---|---|
| Render | Application hosting, PostgreSQL database, Redis task infrastructure, and service logs | Account, order, workflow, audit, and technical data |
| Cloudflare | DNS and R2-compatible object storage for uploaded files | Network-routing data and authorized raw upload files |
| Resend | Outbound transactional and vendor-follow-up email | Recipient, subject, message content, and delivery metadata |
| Google Workspace | Business email and inbound reply mailbox | Business contacts, message content, attachments, and routing metadata |
| AI service provider | Vendor-reply classification and structured recommendations | Authorized operational information documented in the applicable customer agreement, Data Processing Addendum, or subprocessor schedule |
| Stripe | Billing, invoices, subscriptions, and payment processing | Customer and billing identity, plan, invoice, and payment information |
| Google Fonts | Delivery of website typefaces | IP address, browser/device, and request metadata received by Google when fonts load |
These providers process information under their own terms and data-processing commitments. North Bench remains responsible for selecting providers and limiting what it sends to each provider.
7. Cookies and tracking
North Bench uses essential cookies for sign-in, session continuity, and cross-site request-forgery protection. The verified product does not currently use advertising cookies or behavioral analytics. The service does not currently respond to browser "Do Not Track" signals because it does not perform cross-site behavioral tracking. If analytics or advertising tools are added, this policy and any consent controls must be updated first.
8. Retention and deletion
North Bench keeps normalized order records, vendor-reply history, audit records, and support information while needed for the active service and documented closeout period. Customer-specific retention terms may be stated in a signed order form or Data Processing Addendum.
At verified customer erasure, North Bench deletes the departing customer's tenant mappings and customer-specific order, routing, message, reply, and activity records. Shared vendor/contact directory records and non-identifying vendor-level engagement totals may remain, subject to the license, notice, accuracy, suppression, objection, and deletion boundary described in this policy.
Successful raw upload files are scheduled for deletion after 30 days and failed or cancelled raw uploads after 7 days, or earlier after a verified customer request.
Deletion from active systems may not immediately remove information from security logs, provider systems, or backups. Provider-specific deletion and aging obligations are tracked through the customer-erasure receipt.
9. Security and incidents
North Bench uses safeguards intended to protect customer information, including access controls, tenant-scoped records, encrypted connections, restricted intake, and provider-managed infrastructure. No system is completely secure. If North Bench confirms a security incident affecting customer information, it will investigate, contain the issue, coordinate with affected providers, and notify affected customers as required by the agreement and applicable law.
10. Customer requests
An authorized customer representative may ask what customer information North Bench holds, request a correction or export, or request deletion by emailing hello@northbench.co. North Bench will verify the requester's authority before acting.
If the Virginia Consumer Data Protection Act or another applicable privacy law requires additional rights, North Bench will provide the required authenticated access, correction, deletion, portability, opt-out, response-timing, extension, and appeal process. If a statute does not currently apply, North Bench documents its threshold analysis and reassesses it as its customers and processing change.
11. Changes to this policy
The effective date appears at the top. Material changes will be posted here and communicated to active customers before they take effect when reasonably practicable. A prior policy version continues to govern earlier processing when required by the applicable agreement.
12. Contact
Email: hello@northbench.co
Business mailing address: 590 Grove St #10, Herndon, VA 20172