Privacy

Privacy Policy

How Northrow Studio handles your information — in plain English.

Last updated September 29, 2026

Northrow Studio (“Northrow”, “we”) is a web design and development studio based in Baltimore, MD. This policy covers northrowstudio.com, the Start a Project flow, and the client portal. Questions or requests: luke@northrowstudio.com.

We only collect what we need to run projects and bill for them:

  • Account details — your name, email address, business name and, if you give it, a phone number. Sign-in uses one-time email codes; we never ask for or store a password.
  • Project information — what you tell us when you start a project (type of business, current website, pages and features you need, notes) and your onboarding answers (goals, customers, services, content, preferences, domain and access details).
  • Files you upload — photos, logos, documents and other files you share through the portal.
  • Messages and decisions — support requests and replies, feedback on designs, approvals, and proposals you accept.
  • Agreement records — when you accept an agreement we record the exact version you accepted, your typed name, the time, your IP address and your browser’s user-agent string, as a record of that acceptance.
  • Payment records — amounts, invoices, payment status, and references to the related records at our payment processor. Card details are entered on Stripe’s pages and never reach Northrow.
  • Technical data — like any website, our hosting provider processes request data such as IP addresses to deliver and protect the site.

Please don’t send passwords or other secrets through the portal — it’s built to refuse them, and Luke will never ask for one.

  • To design, build, host and support your website or brand, and to communicate with you about it.
  • To sign you in, keep your account secure, and show you only your own project.
  • To take and record payments and keep records of what was agreed.
  • To send project emails you asked for — sign-in codes, updates, agreements and payment notices.
  • We don’t sell or rent your information, and we don’t use it for advertising.
  • This site doesn’t use analytics, advertising or tracking cookies.

We use a small number of providers to run Northrow. Each processes information only as needed to provide its service:

  • Supabase — database, sign-in and private file storage.
  • Stripe — card payments, subscriptions and receipts.
  • Resend — delivery of sign-in and project emails.
  • Vercel — website hosting.
  • Google Workspace — our business email, when you write to us.

We may also share information if the law requires it, or to protect our rights in a dispute.

When you sign in, we use cookies to keep you signed in — they are needed for the portal to work. The Start a Project flow saves your answers in your browser tab (session storage) so a refresh doesn’t lose them, and the portal may remember unsent drafts and dismissed notices on your device. None of this is used for tracking.

We keep project and account information while we work together and for as long as reasonably needed afterwards for support, records and our legal and tax obligations. Agreement and payment records are kept as a record of what was agreed and paid. Files and information we no longer need are deleted.

We take reasonable measures to protect your information — private file storage with short-lived download links, access limited to your own account, and encrypted connections. No system is perfectly secure, but we work to keep your information safe.

You can ask to see, correct or delete the information we hold about you by emailing luke@northrowstudio.com. We’ll respond within a reasonable time. We may keep some records where we need them — for example agreement and payment records.

Northrow’s services are for businesses and aren’t directed at children.

If we change this policy, we’ll update this page and the date above. See also our Terms of Use.