Legal
Effective date: July 26, 2026
This policy describes how Cost Nudge (“Cost Nudge,” “we,” “us”) collects, uses, and shares data in connection with the Cost Nudge Chrome extension, its companion admin dashboard, and related backend services (together, the “Service”).
Cost Nudge is a business-to-business (B2B) product. It is deployed to an organization’s employees by that organization’s IT administrator through the Google Workspace admin console (force-install). If you are an individual employee using the Service because your employer has installed it, your employer’s own privacy notices and policies also apply to you, and your employer controls certain settings and data described below.
1. Scope
This policy covers:
The Cost Nudge Chrome extension (Manifest V3). Its content script runs only on calendar.google.com, where it displays an in-context meeting-cost badge to meeting organizers; a background service worker handles sign-in and communication with the Cost Nudge backend.
The Cost Nudge admin dashboard, used by an organization’s designated administrators to view aggregate meeting-cost analytics.
The Cost Nudge backend (Google Cloud Functions and Cloud Firestore) that performs all cost calculations and stores organizational data.
This policy does not cover third-party websites, services, or products, including Google Calendar, Google Workspace, or Stripe, except as described in Section 6 (Data Sharing & Sub-processors).
2. Controller vs. Processor Roles
For data protection purposes, the organization that subscribes to Cost Nudge (your employer, the “Customer”) is the data controller of the meeting, employee, and organizational data processed through the Service. Cost Nudge acts as the Customer’s data processor (or “service provider” under U.S. state privacy laws): we process data on the Customer’s behalf and according to the Customer’s instructions, as reflected in the Customer’s subscription agreement with Cost Nudge.
If you have questions about how your employer uses meeting-cost data, please contact your employer’s IT, People Ops, or Finance team directly. If you have questions about how Cost Nudge itself processes data as a processor, see Section 15 (Contact).
3. Information We Collect
3.1 Organizer identity (via Google Sign-In)
When an employee first uses the extension, it authenticates the user against their organization’s Google Workspace account using Chrome’s built-in identity capability (the extension’s identity permission) and Firebase Authentication. To establish a signed-in identity, the extension requests the basic identity scopes (openid, email — including its full-URI form userinfo.email — and profile). The extension additionally requests one sensitive scope: read-only access to Google Calendar events (calendar.events.readonly), used solely to detect and read newly created meetings for the cost capture described in Section 3.2. The extension does not request access to Gmail, Drive, or any other Google Workspace content, and it cannot create, modify, or delete calendar events. Google Sign-In is the sole authentication method; there is no separate username/password.
3.2 Meeting data captured on meeting creation
The extension detects newly created meetings in two ways. First, its content script (which runs only on calendar.google.com) reads certain fields already visible in the Calendar page — the guest list and scheduled duration — when Calendar displays a saved meeting’s details (for example, in the event detail popover or the full event editor, whether immediately after saving or on a later visit to that event). Second, because a saved meeting’s details are not always reopened in the Calendar page, the extension’s background service worker periodically (approximately every 5 minutes while a trial or subscription is active) queries the Google Calendar API, using the read-only Calendar scope described in Section 3.1, for the signed-in user’s recently changed calendar events since a start point the extension records locally the first time it is installed (or, for an existing install with no such point yet recorded, when it is next updated), and locally narrows those results to newly created meetings the signed-in user organized. From either path, the extension extracts and sends only the following fields to the Cost Nudge backend so that a per-meeting labor-cost estimate can be computed:
Attendee email addresses, as they appear in the meeting’s guest list, are transmitted to our backend when a new meeting is saved, so the backend can match them against the Customer’s internal employee roster and determine whether the meeting meets the 3-attendee eligibility threshold (see below). Because eligibility is evaluated server-side, attendee emails are transmitted for every saved meeting, not only those that ultimately qualify.
Scheduled meeting duration, scheduled start time, and Google Calendar event identifiers (used to prevent duplicate cost records for the same event).
For recurring meetings, recurrence linkage information (a series identifier, whether the event is a recurring instance, and the instance date), so that recurring-series cost attribution and the backend’s recurrence window can be applied.
Organizer email address and Firebase user ID.
What is actually stored, and the eligibility gate. Attendee email addresses are used only transiently, server-side, to determine how many attendees match active employees in the Customer’s roster. A persistent, per-event cost record is created only if at least 3 attendees match active internal employees (“badge/capture threshold”). If fewer than 3 attendees match, no cost record is written and no meeting data is retained. When a record is created, it contains the fields listed in Section 3.4 below — it does not contain the individual attendee email addresses, individual attendee identities, or attendee RSVP status. In other words, raw attendee email addresses are used as a one-time matching input and are not persisted in Cost Nudge’s database.
This capture happens automatically for every qualifying new meeting during an active trial or subscription; it is not limited to meetings where the badge is visibly displayed to the organizer (see Section 3.5).
3.3 What we do NOT capture
Meeting titles, descriptions, agendas, attachments, or locations. (Google Calendar API responses received by the extension can include such fields, but the extension does not extract, transmit, or store them — they never leave the browser.)
Meeting content, notes, chat, or recordings.
Edits or cancellations of existing meetings — in the current beta, data capture occurs only on new meeting creation. Editing or cancelling a meeting after creation does not update or remove its cost record.
Individual employee salaries. See Section 7.
3.4 Cost record fields (what is actually stored per meeting)
Each per-event cost record stored in the Customer’s organization data contains: Google Calendar event ID, organization ID, organizer Firebase user ID, organizer email address, calculated cost (dollar amount), display tier, count of matched internal eligible attendees, scheduled duration (minutes), trial phase (baseline/active), capture timestamp, scheduled start time, and (for recurring meetings) recurrence linkage fields. Cost records are immutable once written.
3.5 Live cost preview (badge)
When the extension displays the in-context cost badge to an organizer, it sends the same attendee-email and duration data to a separate, read-only backend function that returns only an aggregate total cost, a matched-attendee count, and a yes/no “below threshold” flag. This preview function does not create or store any record — it exists only to render the badge in real time. No individual attendee or rate data is ever returned to the browser.
3.6 Employee roster data (uploaded by the Customer, not collected from the extension)
Separately from extension usage, the Customer’s administrator uploads a CSV of the organization’s employees (work email, assigned salary band, department, active/inactive status) using a Cost Nudge-provided template. This roster is used server-side to match meeting attendees and compute cost. This data comes from the Customer, not from individual employees’ extension activity, and is described here for completeness.
3.7 Account and billing data
If your organization converts from trial to a paid subscription, Cost Nudge’s payment processor (Stripe) is used to manage billing. Stripe receives only organization-level billing information (such as the organization name and an administrator’s billing contact email) supplied by the Customer or Cost Nudge’s operator — Stripe never receives meeting, attendee, or salary data.
4. How We Use Information
We use the information described in Section 3 solely to:
Authenticate users and enforce organization-scoped access to data.
Compute and display approximate meeting labor cost to meeting organizers (during the “active” phase of the trial or after conversion).
Compute aggregate, organization-level analytics for the Customer’s admin dashboard (meetings, hours, meeting labor allocation, and estimated savings, broken down by department).
Enforce the eligibility, privacy-tiering, and abuse-prevention rules described in Section 7.
Operate, secure, and improve the Service (e.g., rate-limiting to prevent abuse, diagnosing failures).
We do not use meeting or attendee data for advertising, and we do not sell personal information.
5. Legal Basis / Data Processing Role
Where applicable data protection law (such as the EU/UK GDPR) requires a legal basis for processing, Cost Nudge processes personal data as a processor on behalf of the Customer, under the Customer’s instructions and its own legal basis (typically legitimate interests in managing workplace scheduling costs, or another basis the Customer determines). Questions about the legal basis for a specific organization’s use of Cost Nudge should be directed to that organization.
6. Data Sharing & Sub-processors
We share data only with service providers necessary to operate the Service, under contractual confidentiality and data-protection obligations:
Google Cloud Platform / Firebase (Cloud Firestore, Firebase Authentication, Cloud Functions, Firebase Hosting) — hosting, database, authentication, and compute for the entire Service. Data involved: all Service data described in Section 3.
Stripe — subscription billing. Data involved: organization-level billing/contact information only (see Section 3.7); no meeting or attendee data.
The extension contains no third-party analytics or advertising code and no remotely-hosted code; it bundles the Firebase SDK locally. Its network communication is limited to Google and Firebase endpoints — Google Sign-In and Firebase Authentication to establish the user’s identity, the Google Calendar API (read-only) for the meeting detection described in Section 3.2, and our own Cloud Functions and Firestore backend for attendee matching and cost computation — in addition to the calendar.google.com page the content script runs on. The extension sends no data to any third-party analytics provider or advertiser.
We do not sell personal data, and we do not share data with third parties for their own marketing purposes.
We may disclose information if required by law, subpoena, or other legal process, or to protect the rights, property, or safety of Cost Nudge, our customers, or others.
7. What We Do NOT Collect or Expose (Salary Privacy Safeguards)
Cost Nudge is designed so that no individual employee’s salary or compensation is ever exposed to anyone, including meeting organizers, People Ops, Finance users, or Cost Nudge operators, through three layered safeguards:
3-attendee minimum. A cost figure is only computed and shown when at least 3 matched internal employees are in a meeting, so a cost estimate can never be reverse-engineered to a single individual’s rate.
Salary bands, not individual salaries. Cost is computed from 6 organization-defined salary bands (each represented by a band midpoint), never from an individual employee’s actual salary. Individual salary figures are never uploaded to or stored in the Service at all — only the band assignment.
$150 display tiers. Costs shown to organizers and on the dashboard are bucketed into $150 increments (ceiling-rounded), not shown as exact dollar figures, further preventing inference of individual compensation.
No hourly rate, salary band midpoint, or per-attendee rate data is ever sent to or stored in the browser extension; all cost computation happens on our servers.
8. Data Retention
Cost records are immutable once written and are retained while the Customer’s subscription or trial is active. When a trial expires, the extension is deactivated (badge turned off) but the Customer’s data is retained and remains accessible on the dashboard, so the organization can review its results.
On termination of a Customer’s subscription, the organization’s data — cost records, uploaded employee roster data, and salary bands — is permanently deleted within 15 days of termination, except where a longer retention period is required by law.
Employee roster data (uploaded via CSV) is retained and updated as the Customer uploads new rosters; records for employees no longer in an uploaded roster are retained for historical reporting but excluded from future attendee matching, until deletion under the termination timeline above.
Customers may also request deletion of their organization’s data at any time by contacting us (Section 15), subject to the terms of the Customer’s subscription agreement.
9. Security
We rely on Google Cloud Platform / Firebase’s infrastructure security (encryption in transit and at rest, access-controlled service accounts) to protect Service data. Within the Service, access to organizational data is restricted by role-based Firestore security rules: dashboard-level aggregate data is limited to users with an assigned administrative role (System Admin, People Ops, or Finance) within their organization, and all cost-record writes are performed exclusively by server-side Cloud Functions — the extension and dashboard clients cannot write cost, employee, or salary-band data directly.
Cost Nudge does not currently hold a formal security certification (such as SOC 2) and does not conduct scheduled third-party penetration testing; we will update this section if that changes.
10. Your Rights / Your Organization’s Rights
Because Cost Nudge acts as a data processor for the Customer organization, individual employees who want to access, correct, or delete personal data processed through the Service (such as their own captured meeting or roster data) should generally direct that request to their employer (the Customer), who controls the data. Where applicable law gives us direct obligations to individuals, or where the Customer directs us to fulfill such a request, we will respond as required by law and by our agreement with the Customer.
Organizations (Customers) may contact us directly (Section 15) regarding access, export, correction, or deletion of their organization’s data in the Service. A Data Processing Agreement (DPA) is available to Customers on request.
11. Children’s Data
The Service is a workplace productivity tool intended for use by employees of business customers and is not directed to, marketed to, or knowingly used by children. We do not knowingly collect personal information from children. This section is not applicable to the ordinary use of the Service.
12. International Data Transfers
Cost Nudge stores and processes all Service data on Google Cloud Platform / Firebase infrastructure located in the United States. The Service is offered and distributed only to organizations in the United States; we do not market the Service outside the United States and do not transfer Service data internationally.
13. Governing Law
This policy and the Service are governed by the laws of the State of Colorado, United States, without regard to its conflict-of-laws provisions.
14. Changes to This Policy
We may update this policy from time to time to reflect changes in the Service or applicable law. We will update the “Effective date” above when we do. Material changes affecting how we process data on behalf of Customers will be communicated to Customer administrators.
15. Contact
Questions about this policy or about how Cost Nudge processes data as a processor can be directed to:
Cost Nudge Industries, LLC
Attn: Jonathan Epstein
6644 Legend Ridge Trail
Niwot, CO 80503
jonathane@costnudge.com
© 2026 Cost Nudge Industries, LLC