Checkout Syncby Tofu Labs

Privacy policy

Last updated: October 9, 2026

Checkout Sync is run by Tofu Labs. This page says what we store and why. Contact: support@tofulabs.app.

When you use Checkout Sync, you are the controller of your customers' data and we process it on your behalf, only to pass your checkout's events to your Kit account.

What we store

WhatWhyHow long
Your Kit account ID, name, email address and time zoneTo know which account an event belongs to, show dates in your time zone, and contact you about the appUntil you uninstall, plus 30 days
Kit access tokens (encrypted)To record purchases, add tags and look up subscribers in your Kit accountUntil you uninstall
Your Paddle or Stripe API key, and webhook signing secrets (encrypted)To check each webhook really came from your checkout, and to look up the buyer's email when the webhook leaves it outUntil you disconnect that checkout
A Lemon Squeezy API key or Polar access token you paste for an import (encrypted)To read your past orders for that importUntil that import ends (deleted then, or after 2 days at most)
Per buyer: their email address, the status, last product and first-purchase date we last wrote to KitTo keep the three Kit custom fields right without writing the same value twiceUntil you uninstall
Each event we receive: the buyer's email address and name, the product, amount, order or subscription ID, and what we did with itTo avoid recording a sale twice, to retry anything Kit didn't accept, and to show you recent activity30 days
The Kit subscriber ID and the event details your automations use (product, amount, links)To start your Kit automations30 days
Product names, tag IDs and a monthly count of salesFor the product filter, tags and your plan's limitUntil you uninstall
Your plan and Paddle subscription IDBillingAs long as tax law requires

What we don't store

We never see card or bank details: your checkout keeps those. We don't receive your Kit subscribers' other fields or your email content. We don't sell data, show ads or use tracking cookies. The one cookie we set keeps you signed in to your settings.

Who processes it

Cloudflare hosts the app and its database (United States). Paddle processes payments for our plans as merchant of record. Kit receives the purchases, tags and events we send on your behalf. Paddle, Stripe, Lemon Squeezy and Polar receive the lookups we make with your key.

Your customers

You choose whether buyers who aren't on your Kit list are added, added with a "Not opted in" tag, or left out. If they're added, make sure your checkout or privacy notice tells buyers they'll hear from you, and give them a way to unsubscribe (Kit adds one to every email). The same choice applies to past customers you import.

Deleting data

Disconnecting a checkout deletes its key and secret straight away. When you uninstall the app in Kit we stop at once and delete your account data within 30 days. To have everything deleted sooner, or to remove one buyer's records, email us.

Your rights

You can ask to see, correct, export or delete your data at support@tofulabs.app. We reply within 30 days. If you're in the EU or UK you can also complain to your data protection authority.