NORTHMRKSign in

Privacy Policy

Last updated August 3, 2026

This Privacy Policy describes how NORTHMRK (“NORTHMRK”, “we”, “us”) collects, uses, stores, and shares information when you use the NORTHMRK CRM application at crm.northmrk.com and related services (the “Service”).

1. Who this applies to

NORTHMRK is a business CRM for life insurance agency producers and owners. It is not directed at children. If you are a producer or agency staff using the Service, this policy applies to your account and the customer/lead data you enter.

2. Information we collect

  • Account information — name, email, and authentication identifiers from your NORTHMRK organization login (for example via Authentik / SSO).
  • CRM business data — leads, clients, call dispositions, notes, lists, pipeline stages, and related production records you or your agency create.
  • Connected advertising accounts — when you choose to connect Meta Ads, TikTok Ads, Google Ads, or similar platforms, we receive OAuth tokens and account metadata needed to display campaign analytics inside NORTHMRK.
  • Usage data — basic technical logs (IP, device/browser type, timestamps) used for security and reliability.

3. Google user data

If you connect a Google account to NORTHMRK (directly or through the NORTHMRK organization login), we access Google user data only with your explicit OAuth consent and only for the scopes you approve.

  • Access — we request only the scopes needed to (a) authenticate you into NORTHMRK and/or (b) show advertising performance and account identity inside the CRM when Google Ads is connected.
  • Use — Google user data is used solely to provide sign-in and the NORTHMRK features you enabled (CRM access, analytics, reporting, and account linking). We do not use Google user data for advertising to other people, or for unrelated AI/ML training.
  • Storage — OAuth tokens and related account metadata are stored securely in our database, associated with your agency tenant, and retained while the connection remains active.
  • Sharing — we do not sell Google user data. We do not share it with third parties except subprocessors that help us run the Service (for example cloud hosting), under confidentiality obligations, or when required by law.
  • Limited Use — NORTHMRK’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You may disconnect Google (or other ad platforms) at any time from Settings in the CRM. Disconnecting revokes our ongoing access; we then delete or invalidate stored tokens for that connection.

4. How we use information

  • Provide dialing, lead list, pipeline, and agency CRM features
  • Authenticate users and enforce per-producer data separation
  • Show campaign analytics when you connect ad platforms
  • Maintain security, prevent abuse, and troubleshoot issues
  • Comply with legal obligations

5. How we share information

We share data with service providers who process it on our behalf (hosting, databases, email/SMS delivery when configured). Agency owners may see operational data for their tenant according to role permissions. We do not sell personal information.

6. Retention

We retain CRM records for as long as your agency account is active or as needed to provide the Service. You may request deletion of account or connection data by contacting us (see below).

7. Security

We use industry-standard safeguards including encrypted transport (HTTPS), access controls, and tenant isolation. No method of transmission or storage is 100% secure.

8. Your choices

  • Sign out or request account deprovisioning via your agency admin
  • Disconnect OAuth-linked ad accounts in Settings
  • Contact us to access, correct, or delete personal data we hold

9. Contact

Questions about privacy or Google data use: jake@northmrk.com

Application homepage: https://crm.northmrk.com/

← Back to NORTHMRK