Privacy Policy
Last updated: March 9, 2026
Who We Are
Northlight Labs Inc. ("Northlight Labs", "we", "us") builds technology for workplace safety. Our flagship product, Pharos, is a safety management platform designed for teams who value efficiency without compromising on safety.
Contact: privacy@northlightlabs.com
What Data We Collect
Waitlist Signup
When you join the Pharos waitlist, we collect:
- Name (required)
- Email address (required)
- Company name (optional)
- Role (optional)
- Industry (optional)
We also record CTA attribution data (which page or link brought you to the signup form) and a cryptographic hash of your IP address for rate limiting. We do not store your raw IP address.
Website Analytics
We collect anonymous funnel events (such as button clicks and form outcomes) to understand how visitors interact with the site. These events contain only CTA attribution identifiers (which link or page led to the action), an industry category when selected from a dropdown, and whether a company name was provided (as a yes/no flag). No names, email addresses, IP addresses, or other personal data are included in analytics events.
Analytics events are stored in our Cloudflare D1 database and automatically deleted after 6 months. No cookies are set for analytics purposes and no third-party analytics vendors are used.
Why We Collect It
We collect your information based on your explicit consent when you submit the waitlist form. We use it to:
- Notify you when Pharos is available for early access
- Understand interest by industry and role to guide product development
- Prevent abuse through rate limiting
How We Store Your Data
Your data is stored in Cloudflare D1, a serverless SQL database. Data is encrypted at rest and in transit using Cloudflare's infrastructure security. All data processing occurs within Cloudflare's global network.
IP addresses and email addresses used for rate limiting are hashed using HMAC-SHA256 with a secret key before storage. The raw values are not retained.
How Long We Keep It
Waitlist submissions are retained for 12 months from the date of submission. After this period, your data is automatically deleted unless you have explicitly opted in to Pharos (at which point separate terms and a separate privacy policy will apply).
Rate limiting data is automatically deleted after 24 hours.
Anonymous analytics events are automatically deleted after 6 months.
Data Processors
We use the following third-party processors:
- Cloudflare, Inc. — hosting, content delivery, D1 database, Turnstile verification, and Web Analytics. Cloudflare Privacy Policy.
We do not sell, rent, or share your personal data with any other parties.
Your Rights
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data (right to erasure)
- Withdraw consent at any time
To exercise any of these rights, email privacy@northlightlabs.com. We will acknowledge your request within 3 business days and complete it within 20 business days.
Unsubscribe
To remove yourself from the waitlist, email privacy@northlightlabs.com with the subject "Waitlist removal" and the email address you signed up with. When we introduce email notifications in a future phase, each email will include a one-click unsubscribe link.
Cookies
This website does not set tracking cookies. Cloudflare may set essential cookies required for security and performance (such as bot management). These are strictly necessary and do not track your browsing activity.
Changes to This Policy
We may update this privacy policy from time to time. Significant changes will be communicated via email to waitlist subscribers. The "Last updated" date at the top reflects the most recent revision.