Privacy policy
Effective September 29, 2026. SlipKit is made by Lemnos Holdings LLC ("we"). Questions: hello@lemnosholdings.com.
The short version: SlipKit reads your Squarespace orders when you ask it to, turns them into packing slips in your browser, and doesn't keep them. Your customers' names, addresses and orders are never saved on our side. What we do keep is listed below, all of it.
What we store about you (the merchant)
- Your email address, to sign you in and to tell you about your account.
- Your Squarespace API key, encrypted with AES-256-GCM before it's saved. The encryption key is kept separately as a server secret. We also keep the last 4 characters in plain text so you can tell which key is connected.
- Your slip settings: shop name, brand color, template, paper size, thank-you note, discount code and its text, QR link and label, social handle, return policy, which fields to show, and your answer to "how do you buy shipping labels" if you gave one.
- Your logo, the image file you upload.
- "Slips that sold" numbers: how many orders used your slip code in the last 30 and 90 days and their total. Numbers only, no order details. They're kept for up to an hour so the page loads fast, then recounted.
- Your trial dates and plan status. If you pay, Stripe tells us your Stripe customer and subscription IDs, and we keep those with a yes/no for whether the subscription is active.
- Sign-in tokens. A sign-in link works once and expires after 15 minutes. Signing in sets one
cookie (
sk_session) that keeps you signed in for 30 days. We store both tokens hashed, not the tokens themselves.
We also keep a few running totals for the whole service (sign-ups, keys connected, slips printed, checkouts). They aren't tied to you.
Your customers' data (from Squarespace)
With your API key, SlipKit calls the Squarespace Commerce Orders API when you open the Orders page,
open the print view, or load "slips that sold" on the home page. It reads the orders, including customer
names, shipping addresses, items, prices, checkout form answers (like gift messages), and the discount
codes used. It uses them to build the page you asked for and then drops them. They're not written to a
database, a file or our logs, and the pages are sent with no-store so browsers and proxies
don't cache them. The PDF you save from the print dialog is yours, on your computer.
The key SlipKit asks for only has read access to orders. It can't change orders, products or anything else in your store.
Services we use
- Cloudflare hosts the app and the website, and stores the data listed above (Workers KV).
- Stripe handles payments. We never see your card number.
- Resend sends the sign-in emails. It gets your email address and the link.
- Squarespace, which SlipKit calls with your key, on your behalf.
We don't sell data, share it for ads, or use it to train AI models.
This website
The website uses Cloudflare Web Analytics to count visits. It doesn't set cookies or track you across sites. The app sets only the sign-in cookie described above.
Deleting your data
- Disconnect Squarespace: "Disconnect and delete the key" on the SlipKit home page deletes the key right away. You can also revoke it in Squarespace (Settings > Advanced > Developer API Keys), which cuts SlipKit off even if we still had it.
- Delete your account: at the bottom of the SlipKit home page. It deletes your account, API key, settings, logo and counts right away. If your subscription is still active, we keep the Stripe IDs until it ends so the cancellation can be processed, then delete them. Cancel first if you don't want to be charged again.
- Export: the same section has a link to download your settings as a JSON file.
- Or email hello@lemnosholdings.com and we'll do it within 30 days. Stripe keeps payment records as the law requires.
Security
Everything goes over HTTPS. API keys are encrypted at rest. Sign-in is by one-time email link, so there's no password to leak. If we ever find that someone got access to data they shouldn't have, we'll email affected merchants without delay and tell them what happened.
Changes
If this policy changes, the new version goes on this page with a new date. If a change means we'd store something new, we'll email you before it takes effect.