Last updated: July 2026
This Privacy Policy applies to the Cornerstone Guide browser extensions, including the Cornerstone Guide Creator and the Cornerstone Guide Player (collectively, the “Extension”), which provide interactive, in-context guided walkthroughs inside web applications. This is a complete, standalone privacy policy for the Extension: the sections below describe what user data the Extension does and does not collect, how it is handled and used, how it is stored, and how it is shared. This Extension section governs the Extension’s data practices. The broader Cornerstone Client Portal Privacy Policy that follows further down this page applies to Cornerstone’s websites and hosted software, not to the Extension, and is provided for reference only.
The single purpose of the Extension is to deliver in-context guided walkthroughs. The following table states how the Extension treats each category of personal or sensitive user data defined by the Chrome Web Store User Data policy.
| Data category | How the Extension handles it |
|---|---|
| Personally identifiable information (name, email, address, etc.) | Not collected from web pages. A user identifier is obtained from the organization’s SSO session only when an administrator enables PII tracking, and is used solely to attribute guide analytics. |
| Authentication information & passwords | Collected at sign-in. When you sign in to the Cornerstone Guide extension, the Extension collects the username (email address) and password you enter into the extension’s own sign-in form only (or your Single Sign-On credentials, where SSO is used). It does not collect credentials or data you enter into the host web application. This credential data is collected only to authenticate you to the Cornerstone Guide service. It is sent over encrypted HTTPS; the password is not retained after login (only a session token is stored locally and cleared on logout); and it is never sold or shared with third parties. For automated walkthrough steps that demonstrate a sign-in, the Extension may enter a value into a field — which may be a password field — using credentials your administrator pre-configured for that guide, used only to perform the demonstrated step. The Extension does not read, capture, log, or transmit passwords that you type into third-party web pages for your own use. See the “Passwords and Login Credentials” section below for full detail. |
| Form data / keystrokes | Not collected. The Extension does not read or record values typed into any form field. |
| Financial and payment information | Not collected. |
| Health information | Not collected. |
| Web browsing activity | Not collected. The Extension does not track the pages you visit or your activity across sites. |
| Website content and resources | The Extension reads only the structural attributes of elements you author or that host a guide (such as element type, id, and CSS locators) to position guidance. Page content is not stored or transmitted for any other purpose. |
| User-provided content & personal communications | Not collected. |
| Guide interaction data (guide views and completions) | Collected to provide guide analytics. Recorded anonymously unless an administrator enables PII tracking, in which case it is associated with the SSO user identifier. |
The Extension does not collect personal data from the browser or from the web applications you visit, does not read or scrape any user identity from those pages, and does not track your browsing activity across pages. The Extension maintains its own separate session and identifies a user only through that session.
By default the Extension does not collect any personal or user-identifiable data. A user identity is associated with activity only when PII tracking is explicitly enabled by the customer’s administrator. In that case, the user’s identity is obtained through the organization’s Single Sign-On (SSO) session, which is configured by the customer’s web application administrator — not read from the page content. Even when enabled, this identity is used only for guide analytics and is recorded solely when a user views or interacts with a guide associated with the Extension. When PII tracking is disabled, guide interaction data is recorded anonymously and no user-identifiable data is collected.
Login credentials the Extension does collect. The Extension has its own sign-in. When you log in, the Extension collects the username (email address) and password that you enter into the Cornerstone Guide extension’s own sign-in form only (or your Single Sign-On credentials, where SSO is used). These login credentials are collected for the sole purpose of authenticating you to the Cornerstone Guide service. The Extension does not collect the username, password, or any other credentials or data that you enter into the host web application’s own login or form fields. Full details of how this credential data is used, handled, stored, and shared are described in the “Passwords and Login Credentials” section immediately below.
The Extension does not collect keystrokes, the values entered into form fields for your own use, financial information, or health information from the pages you visit.
Because the handling of passwords is important, this section describes exactly how and when the Extension uses password and login information.
a) Signing in to the Cornerstone Guide service. To use the Extension, you sign in through the Extension’s own sign-in form using your login credentials — an email address (username) and password, or your Single Sign-On (SSO) login where SSO is configured.
The Extension maintains its own session and does not use or depend on your credentials for the underlying host web application.
b) Automated (“auto-play”) guide steps. A guide may include automated steps that demonstrate a workflow, including a sign-in step. When a guide author has configured such a step, the Extension may enter a value into a field on the page — which may be a password or login field — using credentials that the customer’s administrator has pre-configured for that specific guide. These pre-configured values are used only to perform the demonstrated step within that guide and for no other purpose.
c) Passwords you type for your own use. When you type your own password into a login or form field on a web page you are visiting, the Extension does not read, capture, log, store, autofill, or transmit that password or its value. While authoring a guide, the Extension may recognize that a field is a password/login field (from its type and locator attributes) in order to attach a guide step to it, but it does not access the value entered into that field. Such password values never leave the page and are never sent to Cornerstone’s servers.
Collected data is used solely to deliver interactive guided walkthroughs and to report guide usage analytics to the customer’s administrators. Data is never used for advertising, profiling, or any purpose unrelated to the Extension’s single purpose of providing in-application guidance. Data is processed in direct support of this functionality and is not sold or used for creditworthiness or lending purposes.
Session data is stored locally in the browser using the Chrome storage APIs and is cleared on logout. Where guide usage data is collected (only when the PII setting is enabled), it is stored on Cornerstone’s servers and is retained only as long as necessary to provide guide analytics, in accordance with the agreement between Cornerstone and the customer Organization. Details of how data is encrypted in transit and at rest are described in the “Data Security and Secure Handling” section below.
Data collected by the Extension is not sold, rented, transferred, or shared with any third parties. Guide usage reports are accessible only to the customer’s own organization administrators. Data may be disclosed only where required to comply with applicable law or valid legal process.
The Extension handles all user data securely. Any user data transmitted between the Extension and Cornerstone’s servers — including authentication during sign-in and guide usage data — is sent only over encrypted connections using modern cryptography (HTTPS / TLS). The Extension does not transmit user data over unencrypted (HTTP) connections.
User data that is retained on Cornerstone’s servers is stored at rest using strong, industry-standard encryption (such as AES). Data held locally in the browser (for example, session state via the Chrome storage APIs) is limited to what is needed for the Extension to function and is cleared on logout. Cornerstone applies commercially reasonable physical, administrative, and technical safeguards to protect user data against unauthorized access, disclosure, or loss.
The Extension’s use of information received from its permissions and from users complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:
Collection of user-identifiable guide interaction data occurs only when the customer’s administrator explicitly enables PII tracking; it is off by default and no user-identifiable data is collected unless it is turned on. You can stop the Extension from associating activity with your identity at any time by logging out, which clears the locally stored session data. To request access to, correction of, or deletion of any data associated with your in-extension identity, contact your organization’s administrator or Cornerstone’s Data Protection Officer at DPO@csod.com.
For any questions about the Extension’s data practices, contact Cornerstone’s Data Protection Officer at DPO@csod.com.
Scope note: The following policy describes the data practices of Cornerstone’s websites and hosted software (the “Software”). It does not describe the browser Extension. Any references below to collecting IP addresses, clickstream data, or pages visited apply to Cornerstone’s own web servers and websites — not to the Extension. The Extension’s data practices are governed solely by the “Cornerstone Guide Browser Extension – Privacy Policy” section at the top of this page.
Cornerstone OnDemand, Inc. and its global affiliates (collectively, “Cornerstone”) help organizations recruit, train, and manage their people. The entity granting you access to Cornerstone’s software (“Organization”) is a Cornerstone customer that collects and processes your personal data. This privacy policy (“Privacy Policy”) governs Cornerstone’s processing of personal data you and/or the Organization has inputted into Cornerstone’s software application (“Software”) for the purpose of recruiting, training, and/or managing you.
Cornerstone does not directly collect your personal data. Cornerstone processes data you and/or the Organization inputs into the Software for the purpose of recruiting, training, and/or managing you. Such data may include, but is not necessarily limited to, candidate data, employee data, contractor data, student data, training data, and performance data.
Cornerstone will process the data only in accordance with the agreement between Cornerstone and the Organization, including, but not necessarily limited to, providing technical or functional support, and ensuring the security of the Software. Please contact the Organization with any questions about its use of your personal data.
The Organization is a data controller. A (“Data Controller”) determines the purposes for which and the means by which personal data is processed. Cornerstone is a data processor of your personal data. A (“Data Processor”) processes personal data only on behalf of the controller and in accordance with the Data Controller’s instructions. All queries regarding your personal data should be directed to the Organization.
For information on the cookies we use, and their functionality please refer to our Cookie Policy.
Our servers automatically collect data about your internet protocol (“IP”) address when you visit a Cornerstone webpage (“Website”). Our servers may log your IP address and sometimes your domain name when you request pages from a Website. Our servers may also record the referring page that linked you to us (e.g. another website or a search engine); the pages you visit on a Website; the website you visit after the Website; other information about the type of web browser, computer, platform, related software and settings you are using; any search terms you have entered on the Website or a referral website; and other data logged by our web servers. We use this information for internal system administration, to help diagnose problems with our servers, and to administer our Websites. Such information may also be used to gather broad demographic information, such as country of origin and Internet service provider. Personal data including IP addresses are not used to facilitate contact with users who have not provided their contact details to Cornerstone. Personal data is not shared with nor sold to any unauthorized third-party.
The data practices of the Cornerstone Guide browser extension are described in detail in the Browser Extension Privacy Policy section at the top of this page.
We may use third-party partners to operate and maintain our Software and deliver our products and services in accordance with the agreement we have with the Organization. Third-party service providers are contractually restricted from using or disclosing your personal data except as necessary to perform services on our behalf or to comply with legal requirements. Data may be processed within or outside of the European Economic area, according to the contractual agreement and applicable laws.
We may aggregate and anonymize non-personally identifiable data into statistics regarding user behavior such as overall patterns or demographic reports that do not describe or identify any individual user. This shall always be done in accordance with the agreement between the Organization and Cornerstone.
We may disclose your personal data if required to do so by law or subpoena or if we believe that such action is necessary to: (a) conform to law applicable to Cornerstone or our partners; (b) comply with a judicial or court order, or comply with legal processes served on us or Affiliated Parties; or (c) protect and defend our rights and property, Websites, and/or the users of the Websites.
(Applies unless otherwise agreed in writing between you or the Organization and Cornerstone.) Cornerstone may use your data for the purposes described herein and per the agreement between Cornerstone and the Organization. Depending on contractual requirements and applicable law, your data may be processed and transferred in and to the United States and other countries and territories listed herein, which may have different privacy laws from your country of residence, and which may afford varying levels of protection for your personal data. Regardless of the laws in place in these countries, we will treat the privacy of your information in accordance with this Privacy Policy and the agreement between Cornerstone and the Organization.
You retain the right to access and correct or delete your personal data by contacting the Organization. Cornerstone OnDemand, Inc. is subject to the investigatory and enforcement powers of the United States Federal Trade Commission.
Cornerstone OnDemand, Inc., Saba Software, Inc., EdCast L.L.C. and SumTotal Systems L.L.C. has self-certified commitment with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/. For Data Privacy Framework related (or general privacy-related) complaints, contact DataPrivacyFramework@csod.com or DPO@csod.com.
When you are on this Website you may have the opportunity to visit or link to other websites, including other websites operated by us or by unaffiliated third parties. These websites may collect personal data about you, and because this Privacy Policy does not address the information practices of those other websites, you should review the privacy policies of such other websites to see how they treat your personal data.
This Website is not directed at minors, as described under applicable law, we do not knowingly collect personal data from minors. If we become aware that we have inadvertently received personal data from a minor on a Website, we will delete the information from our records.
The security and privacy of personal data is of utmost importance to Cornerstone. We use commercially reasonable and industry-standard physical, managerial, and technical safeguards to preserve the integrity and security of your personal data. More information can be found at https://www.cornerstoneondemand.com/company/security.
The General Data Protection Regulation 2016/679 (“GDPR”) requires Data Processors to provide certain information. Cornerstone acts only as a processor; the Organization is the controller of your personal data and should provide you appropriate contact details. Cornerstone has appointed a Data Protection Officer who can be reached at DPO@csod.com. Cornerstone will process the data only in accordance with the agreement between Cornerstone and the Organization. Cornerstone will retain your data only as agreed between Cornerstone and the Organization and in accordance with applicable laws to which Cornerstone is subject.
Where Cornerstone is subject to U.S. privacy requirements, Cornerstone collects or is provided personal data such as name, address, email address, and social security numbers from job applicants, employees, and contractors for legitimate human resource business reasons. Cornerstone does not engage in automated decision-making. Personal data provided to Cornerstone by the Organization is processed as defined in the Collection of Information and Usage of Data sections of this policy. Your browser may allow you to set a “Do not track” preference; unless otherwise stated, our sites do not honor “Do not track” requests.
This Privacy Policy may be updated periodically and without prior notice to you to reflect changes in our online information practices. We will indicate at the top of the statement when it was most recently updated.
The governing language of this Privacy Policy is English, which shall prevail over any other language used in any translated document.