Account and organization access
Nudge uses authenticated accounts and organization-scoped access. Internal users, client contributors, client administrators, and client read-only users receive different product access. Client users do not receive Workspace or Time access through their portal role.
Client-visible information
Captured time, internal notes, draft work, internal files, rates, and profitability are not client visible by default. Consultants choose which supported updates, tasks, files, and approved time-and-budget information cross into the portal.
Web application infrastructure
Nudge uses Supabase for authentication and application data and Vercel for web hosting and delivery. Database access rules are designed to scope records to the appropriate account and organization. Transport to production services uses HTTPS.
Chrome extension boundaries
The extension does not read CRM records, page text, form fields, typed content, cookies, passwords, authentication tokens, clipboard contents, downloads, or browsing history. Users grant site access explicitly. Nudge uses the site hostname, user-entered tracking context, and anonymous activity signals needed for local reminders and timer placement.
Analytics and privacy controls
The public website uses Google Analytics and first-party funnel events to understand product interest and conversion. Nudge respects browser Do Not Track and Global Privacy Control signals in its first-party marketing instrumentation. Sensitive timer and workspace content is not placed in marketing event metadata.
Report a concern
Send security or privacy questions to hello@crmhacker.com. Do not include customer data, passwords, or authentication tokens in the first message.