Norbeck Manager
Privacy & Trust
This page is maintained by Norbeck to answer common privacy and security questions about Norbeck Manager. It describes how the application handles data today and is not an independent certification. Last updated June 18, 2026.
Overview & access
Norbeck Manager is a private, invite-only administrative workspace for the Norbeck team. Account creation is restricted to approved corporate email domains and requires an administrator invitation. There is no public signup or open social login.
The application supports planning, renewals, accounting (accounts receivable), and staff operations. Access to features is gated by authenticated sessions and role-based permissions enforced server-side.
Data we collect
To operate the workspace, Norbeck Manager stores the following categories of data:
- Account information. Full name, corporate email address, and an optional profile avatar, captured at sign-in.
- Financial & billing records. Invoices, accounts receivable ledgers, transaction amounts, payment statuses, and associated client billing details entered by staff.
- Operational & staff records. Permission levels, internal notes, and activity logs that record who modified an invoice or changed a status, and when.
- Technical metadata. Session tokens used to keep you signed in, plus request metadata (such as IP address and browser user-agent) processed by our hosting infrastructure for security and abuse prevention.
How we use it
- Providing the service. Generating, tracking, and managing invoices, renewals, and dashboard analytics for the Norbeck team.
- Security & auditing. Authenticating users, enforcing permissions, preventing unauthorized access, and maintaining an audit log of administrative and financial changes.
- Communication. Sending operational notifications related to billing, invoice status, and account or system events.
Norbeck Manager does not sell personal data and does not share data with third-party advertisers.
Security controls
- Authentication. Invite-only accounts restricted to approved corporate email domains; no anonymous sign-ups.
- Authorization. Role-based permissions enforced server-side, with row-level security on database tables.
- Transport encryption. All traffic between browsers, the edge runtime, and the backend is served over HTTPS.
- Auditability. Administrative and financial changes are recorded in an internal audit log.
- Service-to-service trust. Internal calls between Norbeck services are authenticated with signed requests rather than shared network trust.
Retention & user rights
Account records are retained while the account is active. Financial and invoice records are retained for standard corporate tax and accounting periods consistent with applicable law, even after an individual user's account is removed.
Staff and administrators can request corrections to their account information, or ask that their account be deactivated, by contacting the address below. Some business records associated with prior work (such as historical invoices) may be retained for compliance after a user is removed.
Contact
For privacy questions, data correction requests, or to report a security concern, contact the Norbeck administrator team at admin@norbecktech.com.