Northland Retail Acquisitions

Legal Centre

Privacy Policy

We handle sensitive business and personal information, so this policy sets out plainly what we collect, what we do with it and the control you have over it.

In short

  • We collect what we need to evaluate an acquisition and operate the platform.
  • Submitting information to us does not create a public listing of your business.
  • Sensitive documents — tax returns, financial statements, proof of funds — sit in restricted storage with access controls and logging.
  • We use service providers to run the platform, and they only get what they need.
  • Marketing preferences are separate from the emails we must send you about your enquiry or deal.
  • You can ask us about access, correction, deletion and communication preferences at any time.

Information we collect

Contact information

  • Name
  • Email address
  • Phone number
  • Mailing address
  • Business address
  • Communication preferences

Account information

  • Account identifier
  • Sign-in and authentication events
  • Role and organisation
  • Security information relating to your account

Business information

  • Business name and trading name
  • Entity structure and ownership
  • Operations and sales
  • Employees at role or aggregate level
  • Contracts, licences and vendors
  • Inventory and equipment

Financial and transaction information

  • Revenue and expenses
  • Profit and loss statements and tax returns
  • SDE and EBITDA
  • Debt, loans and property loans
  • Bank or proof-of-funds information when supplied
  • Financing capability and purchase-price expectations
  • Valuation inputs and results

Property information

  • Address and parcel information
  • Property characteristics
  • Assessments and taxes
  • Owner estimates and appraisals where supplied
  • Lease information

Buyer verification information

  • Identity verification status
  • Entity information
  • Acquisition experience
  • Proof-of-funds information and financing details
  • Verification results

Where identity verification is carried out by a specialist provider, that provider handles the government identification document itself and we receive the outcome — verified or not verified, a name match, a reference, a date and any manual-review flag.

Documents

  • Profit and loss statements
  • Tax returns
  • Point-of-sale reports
  • Fuel reports
  • Property documents
  • Environmental documents
  • Contracts
  • Proof of funds
  • Other files you choose to upload

Usage and technical data

  • IP address, browser and device
  • Pages visited, referrer and campaign parameters
  • Sign-in events and portal activity
  • Document-access activity
  • Cookie identifiers
  • Security logs

Communications

  • Emails
  • Portal messages
  • Support requests
  • Deal correspondence
  • Notes from calls
  • Text messages where you have opted in

Where the information comes from

  • Directly from you
  • From representatives you authorise
  • Public records
  • Service providers
  • Professional advisers
  • A counterparty where you have authorised the exchange
  • Publicly available sources
  • Automatically, from how the website and platform are used

How we use information

  • Running the platform and maintaining accounts
  • Evaluating a possible acquisition
  • Preparing valuations and financial analysis
  • Carrying out due diligence and reviewing financial information
  • Communicating with you
  • Providing secure data rooms
  • Verifying buyers
  • Preventing fraud and protecting the platform
  • Keeping records
  • Improving the platform and understanding how it is used
  • Meeting legal requirements
  • Marketing, only where you have agreed to it
  • Matching buyers to opportunities where the owner has authorised it

Confidential owner information

Sending us information about your business does not create a public listing.

We do not automatically pass owner-identifying information to our buyer network. If we decide not to pursue an acquisition ourselves, your information is only presented externally in line with the authorisation you have given and our disclosure controls.

Information moves through defined disclosure levels:

  • Anonymous or redacted — region and category only
  • Qualified review — additional approved financial and operating information
  • Data room — approved confidential diligence materials
  • Identified opportunity — business identity and exact location, only once the required approvals are in place

Identifying information requires the appropriate authorisation and access controls at every step.

Who information is shared with

We share information where it is reasonably necessary, with:

  • Cloud, hosting and security providers
  • Email and text-messaging providers
  • Identity-verification providers and other data processors
  • Professional advisers, accountants and attorneys
  • Lenders and financing partners, where authorised
  • Environmental consultants and appraisers
  • Approved buyers, where an owner's disclosure authorisation permits it
  • Government or legal authorities where we are required to
  • A successor, if the business is merged, acquired or reorganised

That list is the limit of routine sharing — we do not share information beyond what these purposes require.

Selling personal information

We do not sell personal information for advertising or data-broker purposes. Introducing a business opportunity to an approved buyer, where the owner has authorised it, is a different thing and is described above.

Marketing versus service messages

Messages about your enquiry, your account, document requests and deal activity are service messages and are part of using the platform.

Marketing messages are separate, always optional, and never pre-ticked. You can unsubscribe from marketing without losing the messages you need about your deal.

Cookies and analytics

We use cookies in these categories: strictly necessary, security, preferences and analytics.

Full detail, and the controls, are in our cookie policy.

How long information is kept

We do not keep everything forever. Retention is set by category, and reflects business need, security, legal requirements, transaction record-keeping, disputes and the consent you gave.

  • Enquiry records where no account followed
  • Active accounts
  • Deal records and closed transactions
  • Uploaded financial documents
  • Verification and proof-of-funds records
  • Audit and security logs
  • Marketing subscriptions and consent records
  • Anything under a legal hold

When information is no longer needed we delete it, de-identify it or dispose of it securely, subject to obligations that require us to keep it.

How information is protected

We use administrative, technical and organisational safeguards suited to the sensitivity of the information: private document storage, role-based access, multi-factor authentication for staff, time-limited signed links for files, access controls, audit logging and monitoring.

No system is completely secure, and we do not claim otherwise.

Security incidents

We investigate security incidents and make the notifications required by applicable law. We have an internal incident process covering containment, investigation, legal review and notification decisions.

Privacy requests

You can ask us to:

  • Give you access to information we hold about you
  • Correct something that is wrong
  • Delete information or close your account
  • Stop marketing, or change your communication preferences
  • Exercise any other right available to you under applicable law

We may need to verify who you are first. We cannot always delete everything — some information must be kept for legal, security, transaction, fraud-prevention or record-keeping reasons, and we will tell you when that applies and why.

Requests can be made through our privacy request form or by contacting our contact page.

Rights under state law

Some states give residents specific privacy rights. Whether a particular state law applies to us depends on where you live, our size and how the information is processed.

Children

The platform is built for adults doing business. It is not intended for anyone under 18, and we do not knowingly collect information from children through these services.

Where we operate

We operate in the United States, with a focus on Wisconsin. The platform is not intended for use from outside the United States, and we do not claim compliance with non-US privacy regimes.

Contact

Privacy questions go to our contact page, or by post to our contact page.

This document is a draft prepared for review by qualified Wisconsin counsel.