Privacy Policy - CostLoop

1. Introduction

CostLoop is a subscription and recurring-cost tracking service operated by Antevski ENK, a Norwegian sole proprietorship with organisation number 934 334 507, at Harry Fetts Vei 5B, 0667 Oslo, Norway ("CostLoop", "we", "us", or "our"). Antevski ENK is the controller of personal data described in this policy unless a separate agreement states that we process data only on a customer's behalf.

This policy explains what personal data we collect, why we use it, who receives it, how long we keep it, and the choices and rights available to you. It applies to the CostLoop website, application, browser extension, referral program, and affiliate program.

Questions and privacy requests may be sent to hello@costloop.app.

2. What Data We Collect

We collect only the data necessary to provide the CostLoop service. This includes:

Account data

When you register, we collect your email address. Password authentication is handled by Supabase; CostLoop does not receive your password in plain text. We may also store a display name if you choose to provide one.

Subscription data you enter

CostLoop allows you to enter and import workspace, software-subscription, license, and recurring-cost information. This may include workspace names, team-member roles, vendor names, prices, currencies, renewal dates, billing cycles, owners, notes, document links, cancellation URLs, and related records. A workspace administrator may invite other people and manage their access.

Payment data

Stripe processes subscription payments, invoices, refunds, disputes, and related tax or fraud-prevention information. We receive records such as your Stripe customer ID, plan, subscription and invoice status, payment amount, currency, billing country, and limited payment-method details such as brand and last four digits. We do not receive or store full card numbers or security codes. Stripe may act as our processor for some activities and as an independent controller for regulated payment, fraud-prevention, identity-verification, and legal-compliance activities. See Stripe's Privacy Policy.

Referral and affiliate data

When you visit or sign up through a referral link, we may collect the referral code, referring affiliate, landing page, click or attribution time, signup and conversion status, and related technical identifiers needed to prevent duplicate or fraudulent attribution. Referral attribution does not change the price charged to the referred customer unless a promotion states otherwise.

If you apply to or participate in the affiliate program, we collect application details, name, email address, business or website information, country, program status, referral-code activity, referred-customer status, commission calculations, payout status, and communications with us.

Affiliate payout and Stripe Connect data

Affiliate payouts are handled through Stripe Connect. Stripe may collect identity, contact, bank-account, tax, and verification information directly from affiliates. CostLoop may receive a connected-account identifier, onboarding or verification status, payout eligibility, country, and payout or reversal records. We generally do not receive complete bank-account or identity-document details. Affiliates are also subject to Stripe's applicable connected-account or recipient terms.

Usage data

Our systems and service providers may collect IP address, browser and device type, operating system, pages or features used, timestamps, referring URL, session identifiers, error and security logs, and cookie or consent preferences. Optional analytics on the marketing website are used only according to your consent settings.

Support and communications

If you contact us, we collect your contact details and the contents of your request. We also keep records of service notices, consent choices, and program communications that we send or receive.

Marketing consent

We store a record of whether you have consented to receive marketing emails from us. This flag is set only if you actively opt in - we never pre-check marketing consent boxes.

Email Scanner (browser extension - Gmail and Outlook)

If you install the CostLoop Email Scanner browser extension and connect a Gmail or Outlook account, the extension requests read-only OAuth access to the inbox you authorize. Here is exactly what it reads and how it is processed.

All scanned messages (identification pass): sender address, subject line, date, and provider message ID. These fields are read from every message in the scan window to identify likely billing and subscription emails.

Likely billing messages (content pass): For messages the extension identifies as billing or subscription emails, it additionally fetches the text and HTML MIME parts of those messages through the Gmail API. Ordinary file attachments (images, PDFs, and other binary files) are not requested or read.

Scan processing: Email content is used only during the scan to identify likely subscription receipts and is not stored or shared. Provider errors are converted to short user-facing messages, and authentication tokens are redacted from error messages.

What is sent to CostLoop on import: When you choose to import a detected subscription, only derived fields are transmitted to CostLoop servers: service name, estimated cost, billing currency, billing cycle, and renewal date. Raw email text is never uploaded.

Local storage in your browser: The extension stores only temporary pairing, session, consent, checkpoint, scan-result, and job-status data needed to run the scanner reliably. Disconnecting CostLoop clears local session state, pending connection state, scan consent, workspace state, checkpoints, and completed scan or import results. Withdrawing scan consent removes the consent record and any saved scan results, and cancels any active scan. Completed scan and import results expire automatically.

Disconnecting and revocation: Disconnecting Gmail or Outlook from CostLoop deletes the server-side integration and stored credentials. Gmail disconnect attempts Google OAuth revocation where officially supported. Microsoft disconnect removes CostLoop-held credentials and provides Microsoft account or enterprise-app permission-removal instructions where targeted programmatic revocation is not available without broader Microsoft permissions.

OAuth tokens: The extension does not store raw OAuth refresh tokens. Provider access is handled through CostLoop's server-side token broker, and provider credentials are stored server-side in encrypted form. Raw OAuth refresh tokens are not returned to or stored by the browser extension.

What we do not do with email data: We do not sell it, use it for advertising, apply it to credit decisions, or allow routine human reading of your email content.

CostLoop's use of Google API data complies with the Google API Services User Data Policy, including the Limited Use requirements. CostLoop does not use Google user data to develop, improve, or train generalised AI or machine-learning models.

Detection results are heuristic. The extension may miss some billing emails and may suggest messages that are not subscriptions. You review and confirm every suggestion before it is saved to your account.

Supported providers: The scanner currently supports Gmail and Outlook/Hotmail accounts authorized by the user.

Usage Monitor (optional browser extension feature)

The CostLoop browser extension includes an optional Usage Monitor feature. Usage Monitor only accesses browser history when you choose to run a usage scan.

What Usage Monitor checks: When you start a usage scan, the extension requests the browser History permission if it has not already been granted. The extension checks the selected scan window locally in your browser and compares browser activity against website domains associated with subscriptions in your CostLoop account.

What is saved: The extension may save derived usage results locally, such as the related subscription ID, whether a matching subscription domain was found, the latest matching browser activity timestamp, scan status, and selected scan window. This allows CostLoop to show whether a subscription appears active, may need review, has no matching browser visits, or needs a website added.

What Usage Monitor does not collect or upload: CostLoop does not upload your full browsing history, complete URLs, page titles, page content, search queries, form submissions, passwords, payment details, emails, chats, or unrelated browsing activity. Raw browser history is not sent to CostLoop servers as part of a Usage Monitor scan.

Your controls: You decide when a usage scan runs and which scan window to use. You can revoke the browser History permission at any time from your browser's extension settings. Disconnecting the CostLoop extension clears locally stored Usage Monitor scan state.

CostLoop's use of information obtained through Chrome extension permissions complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

3. How We Use Your Data

We use your personal data for the following purposes:

  • Providing the service - to create and authenticate accounts, manage workspaces and permissions, store subscription data, deliver requested features, and provide customer support.
  • Renewal reminders - to send you email notifications about upcoming subscription renewals. These are transactional emails tied to the service. You can configure the timing of reminders in your account settings.
  • Billing and payments - to manage paid subscriptions in USD, process payments, invoices, taxes, refunds, disputes, and failed payments through Stripe.
  • Referral attribution - to associate a signup or paid subscription with an affiliate referral code, calculate eligibility, and prevent duplicate, manipulated, or fraudulent attribution.
  • Affiliate administration - to review applications, operate the affiliate program, calculate commissions, manage the 30-day hold, process monthly payouts through Stripe Connect, meet the USD $50 payout threshold, and maintain tax and accounting records.
  • Marketing communications - to send product updates, tips, and promotional emails, but only if you have given explicit consent. You can withdraw consent at any time.
  • Security and service improvement - to protect accounts, prevent abuse and fraud, investigate errors, understand feature performance, and improve the service. We use aggregated or de-identified information where reasonably possible.
  • Optional usage monitoring - if you enable Usage Monitor in the browser extension, to show when tracked subscription domains were last visited and help identify potentially unused subscriptions.
  • Legal and contractual obligations - to keep required records, respond to lawful requests, handle claims and disputes, and enforce our Terms of Service and Affiliate Program Terms.

4. Legal Basis for Processing

Where the GDPR or equivalent EEA rules apply, we rely on the following legal bases:

  • Contract - to create your account, provide CostLoop, administer a paid subscription, and operate the affiliate program you join.
  • Legitimate interests - to secure and improve the service, prevent fraud and abuse, attribute referrals, manage business records, and establish or defend legal claims, after considering the effect on your rights.
  • Consent - for optional analytics, marketing communications, connected-account permissions, and other processing where we ask for consent. You may withdraw consent without affecting earlier lawful processing.
  • Legal obligation - to meet tax, accounting, payment, sanctions, anti-fraud, and other requirements that apply to us.

5. Data Retention

We keep account and workspace data while the account is active and for the time reasonably needed to complete deletion, resolve disputes, secure the service, and meet legal obligations. Following a verified deletion request, active account and workspace records are normally deleted or de-identified within 30 days, although limited copies may remain temporarily in backups or where retention is required by law.

Security and diagnostic logs are generally retained for 30-90 days unless an incident, abuse investigation, or legal claim requires longer retention.

Referral and affiliate records are kept while attribution or commissions remain active and afterward for the period reasonably needed for chargebacks, fraud prevention, accounting, tax, and legal claims. Payment, invoice, payout, identity-verification, and tax information retained by Stripe is subject to Stripe's own legal obligations and retention practices.

When we no longer need personal data, we delete or de-identify it unless applicable law permits or requires continued retention.

6. Third-Party Subprocessors

We disclose personal data to service providers where needed to operate CostLoop. Their role can vary by service and law; in particular, Stripe may act as a processor for some activities and as an independent controller for regulated payments and identity verification.

Key providers include:

  • Supabase - authentication, database, and storage infrastructure.
  • Stripe and Stripe Connect - subscription billing, invoices, refunds, payment disputes, fraud prevention, affiliate onboarding, verification, and payouts.
  • Resend - transactional email delivery.
  • Vercel - website and application hosting and content delivery.
  • Google - optional Gmail connection and consent-based website analytics.
  • Microsoft - optional Outlook/Hotmail connection through Microsoft Graph.

Providers may use their own subprocessors. For additional information, see our Subprocessor List, Supabase Privacy Policy, and Stripe Privacy Policy.

7. Security

We use administrative, technical, and organisational safeguards intended to protect personal data, including access controls, encryption in transit, managed authentication, restricted production access, and monitoring appropriate to the service. No online service can guarantee absolute security. You are responsible for using a strong password, protecting login credentials, and promptly reporting suspected unauthorised access.

8. EEA and GDPR Rights

If the GDPR applies to you, you may have the following rights, subject to legal conditions and exceptions. You can exercise many of them in CostLoop or by contacting hello@costloop.app. We may need to verify your identity before completing a request.

  • Access personal data and information about its use.
  • Correct inaccurate or incomplete personal data.
  • Request deletion where the data is no longer needed or another legal ground applies.
  • Restrict processing in certain circumstances.
  • Receive portable data where processing is automated and based on consent or contract.
  • Object to processing based on legitimate interests and object at any time to direct marketing.
  • Withdraw consent at any time.
  • Not be subject to a solely automated decision producing legal or similarly significant effects, where applicable. CostLoop does not currently make such decisions about users.

You may also lodge a complaint with the Norwegian Data Protection Authority, Datatilsynet, or the supervisory authority where you live or work. Account deletion and data-export instructions are available on our Account Deletion and Data Export pages.

9. Cookies and Referral Tracking

CostLoop uses necessary browser storage for authentication, security, consent choices, and core preferences. The marketing website uses optional analytics according to the choices shown in the cookie banner.

If you follow an affiliate link, CostLoop may store or receive a referral code and attribution information so that a later signup or eligible payment can be credited to the referring affiliate. Where applicable law requires consent for non-essential referral storage, we request it before using that storage. Referral attribution does not change your CostLoop price unless a promotion states otherwise.

For full details, see our Cookie and Tracking Notice.

10. International Data Transfers

CostLoop is operated from Norway in the EEA. Depending on the infrastructure region selected and the services used, personal data may be processed in the EEA, United States, or other countries where our providers and their subprocessors operate.

When the GDPR requires a transfer mechanism for data sent outside the EEA, we rely on mechanisms made available by the relevant provider, such as an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful safeguard. You may contact us for information about the safeguard relevant to your data.

11. California Privacy Notice

This section applies only to the extent the California Consumer Privacy Act, as amended (CCPA), applies to CostLoop and to the person making the request. In the preceding 12 months, CostLoop may have collected the following categories: identifiers and contact information; customer records; commercial and subscription information; internet or network activity; approximate location derived from IP address; professional or business information supplied by affiliates; and payment, payout, tax, or verification information handled through Stripe.

We use and disclose these categories for the business and commercial purposes described in this policy, including providing and securing CostLoop, processing billing and payouts, referral attribution, customer support, analytics with consent, fraud prevention, and legal compliance. Recipients may include the providers listed in Section 6, workspace administrators as directed by the customer, and authorities where legally required.

CostLoop does not sell personal information for money. Depending on California law and the way optional analytics or referral technologies are configured, some disclosures could be treated as "sharing" for cross-context behavioural advertising. You may opt out of optional analytics through the cookie preferences interface and may send a sale/share, access, deletion, correction, limitation, or non-discrimination request to hello@costloop.app. Where required, we will process recognised browser-based opt-out signals such as Global Privacy Control. We do not knowingly sell or share personal information of people under 16.

12. Changes to This Policy

We may update this policy as CostLoop or applicable law changes. We will post the updated version and revise the date above. If a change materially affects how we use personal data, we will provide additional notice where required.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Antevski ENK (CostLoop)
Harry Fetts Vei 5B, 0667 Oslo, Norway
Org. No. 934 334 507
hello@costloop.app