Expiring Codesby Tofu Labs

Privacy policy

Last updated: October 10, 2026

Expiring Codes is run by Tofu Labs. This page says what we store and why. Contact: codes@tofulabs.app.

What we store

WhatWhy
Your Kit account ID, name, email address and time zoneTo know which account a request is for, to show deadlines in your time zone, and to email you when subscribers are stuck at the step (at most once a day)
Kit access tokens (encrypted)To write codes into your subscribers' custom fields, and to tag subscribers who used their code
Your Stripe or Paddle API key (encrypted)To create the discount codes in your account and to check every 15 minutes whether they've been used
For each code: the Kit subscriber ID, the offer name, the code, its deadline and when it was usedSo a subscriber who passes the step again gets the same code back while it's still good, and so you can see, search and export your codes in your settings
Recent step results (time, subscriber IDs that couldn't get a code, the error), kept 30 daysTo show you what's stuck and how to fix it
A monthly count of codes madeFor your plan's limit
Your plan and Paddle subscription IDBilling

What we don't store

We only use subscriber ID numbers. We never ask Kit for your subscribers' email addresses, names or other fields, and we don't store them. Kit's sign-in screen says the app can "read and write" your Kit account because Kit apps get one broad permission; we use it only to create our custom fields and tags and to fill them in for the subscribers who reach your Expiring offer step. We don't see card details: Paddle handles payments for our plans, and your own customers pay through your Stripe or Paddle checkout.

The codes we write into Kit custom fields (named like offer_code, offer_expires_at, offer_expires_text and offer_used) and the "Used code: …" tags stay in your Kit account and are covered by your agreement with Kit. Tell your subscribers in your own privacy notice that you send personal discount codes.

Who processes it

Cloudflare hosts the app and its database (United States). Resend sends our emails to you. Paddle processes payments for our plans as merchant of record. Kit, Stripe and Paddle receive the requests needed to do the job: we ask Kit to save fields and ask Stripe or Paddle to create codes. We don't sell data, show ads or use tracking cookies. The one cookie we set keeps you signed in to your settings. The countdown image in your emails is loaded from our server when a subscriber opens the email; we don't log who opened it.

How long we keep it

Code records are deleted 90 days after the code expires. When you uninstall the app in Kit, we stop using your tokens and delete your Stripe or Paddle key at once, and delete the rest of your account data within 30 days. Disconnecting a checkout deletes its key straight away. To have everything deleted sooner, email us.

Your rights

You can ask to see, correct, export or delete your data at codes@tofulabs.app. We reply within 30 days. If you're in the EU or UK you can also complain to your data protection authority.