Last updated 2026-08-09
Privacy
Short version, if you have browsed this site or joined the waitlist: the only personal data we hold is what you typed into the waitlist form, plus the connection details that arrive with it. We don't sell it, we don't share it, and it deletes itself.
A customer account is a bigger record than that — your email, your orders, the serial numbers of your receivers — and it is set out under When you create an account. That section is a draft: the portal is not open, so there are no accounts yet and none of it is happening today.
Who is responsible for your data
Oran Dynamics is the data controller. Northing is a product of Oran Dynamics, a company established in Ireland, so this site is governed by the GDPR and the Irish Data Protection Acts. The Irish Data Protection Commission is the supervisory authority.
Contact for anything on this page, including deletion requests: hello@northinggnss.com.
What we collect, and when
There is exactly one place on this site that collects personal data: the pilot-batch waitlist form. If you submit it, we store
- your email address — the reason the form exists;
- the date and time you signed up;
- your IP address and the two-letter country code our host derives from it;
- your browser's user-agent string.
The last two exist to tell real signups from bot submissions and to know roughly where interest is coming from before we commit to shipping regions. We're naming them rather than burying them because an IP address is personal data and pretending otherwise would be the dishonest option.
Browsing the rest of the site collects nothing. There is no contact form, no account, no comments, and nothing to log in to.
Why we're allowed to hold it
Consent (GDPR Article 6(1)(a)). You give it by submitting the form, having been told at that point what is stored. It is a single-purpose list: one email when the pilot batch opens. Nothing else is sent to it, and it is never passed to anyone else, sold, or used for advertising.
You can withdraw consent at any time, and withdrawing it is as easy as giving it — one email to us, or one click on the unsubscribe link when we do write.
How long we keep it
Until the pilot batch ships, or 24 months from your signup — whichever comes first. The 24-month limit is enforced automatically: each record is written with an expiry, so it is removed by the storage layer whether or not anyone remembers to do it. When the pilot batch ships, the list is purged.
Where it is stored, and who else touches it
Signups are stored on Cloudflare's key-value storage, which also hosts this site. Cloudflare acts as our processor. We have not loaded the list into a mailing platform — when we do, before the first email is sent, that provider becomes a processor too and this page will say so by name.
Cloudflare operates globally, so data may be processed outside the EEA under the standard contractual clauses in their data processing agreement.
Cookies and analytics
Browsing this site sets no cookies and stores nothing on your device. We use PostHog to count page views and see how far people get through the page, configured so that it keeps its state in memory for the length of a single page view and writes no cookie or local storage — which is also why you are not being asked to dismiss a consent banner. It does not build a profile of you and does not follow you to other sites.
Signing in is the one exception, and it is worth being exact about it rather than leaving the sentence above sounding more absolute than it is. Signing in to a customer account sets one cookie, and its only job is to keep you signed in from one page to the next. It is strictly necessary — it is not analytics, not advertising, and the thing you asked for cannot work without it — so it needs no consent banner either. What it holds and how long it lasts is spelled out under When you create an account. You never get one by reading this site, and there is nothing to sign in to yet.
Our host keeps standard server request logs for security and abuse prevention. Those are Cloudflare's, retained on their schedule, and we do not use them for analytics.
When you create an account
What an account will hold
- Your email address — it is your sign-in, and where receipts, renewal reminders and service notices go.
- How you sign in. Today that means a link emailed to you, so there is no password for us to store or to lose. Sign in with Apple is planned, and this page will say so when it ships.
- Your orders — what you ordered, when, the amount, and where it got to.
- The serial numbers of the receivers you own, and whether each one is currently entitled to Northing RTK.
- Anything you email us about your account, kept with it so the next person to answer you has the thread.
Staying signed in: the one cookie we set
Following a sign-in link sets a single cookie, and it is the only
cookie this site sets. Its name begins with northing. What it contains is a random session token — not your email, not
your name, and nothing that can be read off it. It is the reason the
next page you open still knows who you are.
- It lasts 30 days, and while you keep using the portal it is extended — at most once a day, not on every click. Left alone for 30 days it expires and you sign in again.
- Signing out deletes it, on your device and on our side.
- Scripts on the page cannot read it (it is HttpOnly), it is not sent when another site links to us (SameSite=Lax), and on the live site it is only ever sent over HTTPS.
Alongside it we keep a matching record of the session itself: which account it belongs to, when it was created, when it expires, and the IP address and browser user-agent of the device that signed in. Those last two are there so a sign-in you did not make is something you can be shown rather than something we shrug at. The record goes when the session does.
This is a strictly necessary cookie in the ePrivacy sense: it does one job you asked for, and there is no version of "signed in" without it. That is why there is no consent banner on this site, and why turning it down is not offered — declining it and signing in are the same request cancelling itself out. We set no analytics, advertising or tracking cookies, signed in or signed out.
Counting attempts, so the form cannot be abused
Asking for a sign-in link sends an email to whatever address is typed in, which is a thing worth protecting from a script — both from somebody using it to post mail at a stranger, and from a loop pointed at the payment provider. So we count recent attempts: sign-in requests against the email address asked for and against the IP address asking, and checkout and billing requests against the IP alone.
Those counters are the whole record. There is no history, no log of who tried what: a counter holds a number and the address it belongs to, it runs for one hour, and it deletes itself about a minute after that window ends — the storage expires it, the same mechanism as the waitlist retention above. The basis is legitimate interests in preventing abuse, and the counters are used for nothing else, ever.
Paying, and what we deliberately do not hold
Payments run through Stripe, which acts as our processor. Card details go to Stripe and are never stored on our systems: what we hold is that an order exists, its amount, and its status. TODO(legal): which Stripe entity contracts with an Irish seller, the transfer basis, and exactly which fields come back to us from a payment. Also whether we store the delivery address for a physical shipment or leave it with the processor and the carrier.
Your receiver and the corrections service
To switch corrections on for a receiver, this site tells our own provisioning system two things: the receiver's serial number, and whether it is entitled to the service. It does not send your name or your email with them. The service credentials a receiver uses are issued by that system and never touch this website — which is also why you never see one.
This portal holds entitlement state, not positions. It has no access to the coordinates your receiver computes.
TODO(legal): the honest version of the paragraph that belongs here. A network correction service has to know roughly where a receiver is in order to send it the right corrections, so something location-shaped does leave the receiver. State what, at what precision, what our own server logs, and how long the upstream corrections provider keeps it — answered from the code and the provider contract, because a field position is personal data when it is your farm.
When one of us acts on your account
Charging an order, activating a receiver, issuing a refund: we record who did it, to which account, and when. That log exists so you can be told what happened rather than have it guessed at, and it is not used for anything else. TODO(legal): how long those records are kept.
Analytics once you are signed in
The analytics described above are cookieless and anonymous, and that does not change for anyone browsing the site. Inside the portal there is a decision we have not made: whether product analytics stays anonymous there too, or becomes tied to your account so a support question can be answered with what actually happened rather than with a reconstruction.
TODO(legal): make that decision. If analytics becomes identified for signed-in customers, it very likely needs consent, and the consent has to be built before it ships rather than after. Until then nothing in the portal is identified, and we are not going to start quietly.
Why we would be allowed to hold it
Not consent — that is the basis for the waitlist above and it does not stretch to cover a customer record. Account data would rest on performance of our contract with you (GDPR Article 6(1)(b)) for orders, entitlements and the service itself; legal obligation (Article 6(1)(c)) for the records of a sale we are required to keep; and legitimate interests (Article 6(1)(f)) for the audit log and for preventing fraud and abuse.
How long it would be kept
An account and its order history stay while you are a customer. TODO(copy): needs a sourced number — how long after your last entitlement ends the account is kept, and separately the statutory retention owed on records of a sale for tax. Two different numbers, both missing.
Getting a copy, or getting deleted
The rights set out below apply to account data exactly as they apply to a waitlist signup: email hello@northinggnss.com from the address on the account and we will action it and confirm within 30 days, with no charge and no reason needed.
Where we cannot delete something we will say which record and why, rather than refusing in general terms. Deleting an account ends the corrections service for its receivers — and, as everywhere else on this site, the hardware keeps working without it, on Northing Global.
Who else would touch it
Cloudflare, as above, for hosting and for the database. Stripe, for payments. Our own server, which runs the per-receiver corrections lifecycle and holds the credentials this website never sees. And an email provider, for sign-in links and renewal reminders. TODO(legal): name the email provider, and name the hosting provider and country for our own server. The commitment above — that a mail provider is named here before the first email is sent — covers this one too.
Your rights
Under the GDPR you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct it if it's wrong;
- delete it;
- stop using it, or restrict how we use it;
- hand it to you in a portable format.
Email hello@northinggnss.com from the address you signed up with, and we will action it and confirm within 30 days. There is no charge and you don't have to give a reason — "delete me" is a complete request.
If you think we've handled your data badly, you can complain to the Irish Data Protection Commission at dataprotection.ie.
Children
This is professional survey and guidance equipment. The site is not directed at children and we do not knowingly hold data about anyone under 16.
Changes to this page
If what we collect changes, this page changes first and the date at the top moves. Material changes to a list you're already on — a new purpose, a new processor — get an email, not a silent edit.