Privacy policy
Last updated: October 9, 2026
Checkout Sync is run by Tofu Labs. This page says what we store and why. Contact: support@tofulabs.app.
When you use Checkout Sync, you are the controller of your customers' data and we process it on your behalf, only to pass your checkout's events to your Kit account.
What we store
| What | Why | How long |
|---|---|---|
| Your Kit account ID, name, email address and time zone | To know which account an event belongs to, show dates in your time zone, and contact you about the app | Until you uninstall, plus 30 days |
| Kit access tokens (encrypted) | To record purchases, add tags and look up subscribers in your Kit account | Until you uninstall |
| Your Paddle or Stripe API key, and webhook signing secrets (encrypted) | To check each webhook really came from your checkout, and to look up the buyer's email when the webhook leaves it out | Until you disconnect that checkout |
| A Lemon Squeezy API key or Polar access token you paste for an import (encrypted) | To read your past orders for that import | Until that import ends (deleted then, or after 2 days at most) |
| Per buyer: their email address, the status, last product and first-purchase date we last wrote to Kit | To keep the three Kit custom fields right without writing the same value twice | Until you uninstall |
| Each event we receive: the buyer's email address and name, the product, amount, order or subscription ID, and what we did with it | To avoid recording a sale twice, to retry anything Kit didn't accept, and to show you recent activity | 30 days |
| The Kit subscriber ID and the event details your automations use (product, amount, links) | To start your Kit automations | 30 days |
| Product names, tag IDs and a monthly count of sales | For the product filter, tags and your plan's limit | Until you uninstall |
| Your plan and Paddle subscription ID | Billing | As long as tax law requires |
What we don't store
We never see card or bank details: your checkout keeps those. We don't receive your Kit subscribers' other fields or your email content. We don't sell data, show ads or use tracking cookies. The one cookie we set keeps you signed in to your settings.
Who processes it
Cloudflare hosts the app and its database (United States). Paddle processes payments for our plans as merchant of record. Kit receives the purchases, tags and events we send on your behalf. Paddle, Stripe, Lemon Squeezy and Polar receive the lookups we make with your key.
Your customers
You choose whether buyers who aren't on your Kit list are added, added with a "Not opted in" tag, or left out. If they're added, make sure your checkout or privacy notice tells buyers they'll hear from you, and give them a way to unsubscribe (Kit adds one to every email). The same choice applies to past customers you import.
Deleting data
Disconnecting a checkout deletes its key and secret straight away. When you uninstall the app in Kit we stop at once and delete your account data within 30 days. To have everything deleted sooner, or to remove one buyer's records, email us.
Your rights
You can ask to see, correct, export or delete your data at support@tofulabs.app. We reply within 30 days. If you're in the EU or UK you can also complain to your data protection authority.