Legal & Privacy
Review our terms of service, data processing agreement, privacy practices, and refund policy below.
Questions? Contact us with the Help button above (or at hello@label.kitchen).
Terms of Service
Effective date: 2026 April 19th
These Terms of Service ("Terms") govern your access to and use of The Label Kitchen, a web-based label and document design platform ("Service"), operated by The Label Kitchen LLC, a limited liability company registered in the state of Minnesota ("Company," "we," "us," or "our").
By creating an account or using the Service, you agree to be bound by these Terms. If you do not agree, do not use the Service.
1. Eligibility
You must be at least 18 years old and capable of forming a binding contract to use the Service. By using the Service on behalf of an organization, you represent that you have authority to bind that organization to these Terms.
2. Accounts
You are responsible for maintaining the confidentiality of your account credentials and for all activity that occurs under your account. You agree to notify us immediately of any unauthorized use. We reserve the right to suspend or terminate accounts that violate these Terms.
3. Subscription & Payment
Access to the Service requires a paid subscription. Subscriptions are billed on a recurring monthly basis. Payments are processed by our merchant of record, Creem ("Creem"), which handles billing, tax collection, and payment processing on our behalf. Your purchase is subject to Creem's Terms of Service.
Prices are listed on our website and may be updated with 30 days' notice. Existing subscribers will be notified before any price change takes effect on their next billing cycle.
4. Free Trials & Early Access
We may offer free trials or early-access periods at our discretion. At the end of a trial, your account will require an active subscription to continue accessing the Service. We may modify or discontinue trial offers at any time.
5. Acceptable Use
You agree not to: (a) use the Service for any unlawful purpose; (b) attempt to reverse-engineer, decompile, or derive source code from the Service; (c) interfere with or disrupt the integrity or performance of the Service; (d) access the Service through automated means (bots, scrapers) except via our published API; or (e) resell access to the Service without written authorization.
6. Intellectual Property
All rights, title, and interest in the Service — including software, design, trademarks, and documentation — remain the exclusive property of The Label Kitchen LLC. Templates and documents you create using the Service are yours. "Templates" means the visual designs you create and their rendered outputs, including PDF and ZPL exports. The underlying schema, data model, rendering engine, and internal representations used to store and process templates are part of the Service and remain our exclusive property.
7. Data & Privacy
Your use of the Service is also governed by our Privacy Policy (see below), which describes how we collect, use, and protect your information.
8. Service Availability
We strive to maintain high availability but do not guarantee uninterrupted access. We may perform scheduled maintenance or experience outages. We are not liable for any loss resulting from Service downtime.
9. Limitation of Liability
To the maximum extent permitted by law, The Label Kitchen LLC shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from your use of the Service. Our total aggregate liability shall not exceed the amount you paid us in the twelve (12) months preceding the claim.
10. Termination
You may cancel your subscription at any time through your account settings or by contacting us. We may suspend or terminate your access for violation of these Terms, with or without notice. Upon termination, your right to access the Service ceases immediately. Sections that by their nature should survive termination (including Limitation of Liability and Governing Law) will survive.
11. Modifications
We may update these Terms from time to time. Material changes will be communicated via email or in-app notice at least 14 days before taking effect. Continued use after the effective date constitutes acceptance of the revised Terms.
12. Governing Law
These Terms are governed by the laws of the State of Minnesota, without regard to conflict-of-law principles. Any disputes shall be resolved in the state or federal courts located in Minnesota.
13. Contact
Questions about these Terms? Click the "Help" button at the top of this page.
Data Processing Agreement
Effective date: 2026 April 19th
This Data Processing Agreement ("DPA") forms part of the agreement between The Label Kitchen LLC ("Processor," "we," "us," or "our"), a limited liability company registered in the state of Minnesota, and the entity or individual subscribing to our web-based label and document design platform ("Controller," "you," or "your"). This DPA supplements our Terms of Service and governs the processing of personal data by us on your behalf.
By subscribing to the Service and accepting our Terms of Service, you enter into this DPA. This DPA satisfies the requirements of Article 28 of the UK General Data Protection Regulation ("UK GDPR"), the EU General Data Protection Regulation ("EU GDPR"), and any successor legislation.
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person, as defined in the UK GDPR and EU GDPR. "Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, transmission, erasure, and destruction. "Data Subject" means the identified or identifiable natural person to whom Personal Data relates. "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
2. Scope and Purpose of Processing
Subject matter: The Processor provides a web-based label and document design platform. In the course of providing the Service, the Processor may process Personal Data submitted by the Controller through templates, address tables, and related workspace data.
Duration: Processing continues for the duration of the Controller's active subscription. Following account deletion or subscription termination, Personal Data is retained for up to 30 days solely to allow for export or recovery, after which it is erased.
Nature and purpose: Storage and retrieval of template configurations, address data, and workspace metadata necessary to operate the Service. Rendering and generation of labels and documents using data provided by the Controller.
Types of Personal Data: Names, postal addresses, email addresses, telephone numbers, company names, and any other data the Controller includes in templates, address tables, or API requests.
Categories of Data Subjects: The Controller's customers, suppliers, recipients, employees, or other individuals whose data the Controller includes in the Service.
3. Controller's Instructions
The Processor shall process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law. The Controller's instructions are documented in this DPA, the Terms of Service, and any configuration the Controller makes within the Service. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes applicable data protection law.
4. Confidentiality
The Processor ensures that all persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation survives the termination of this DPA and the underlying subscription.
5. Security Measures
The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the UK GDPR and EU GDPR. These measures include: encryption of data in transit using TLS/HTTPS; access controls restricting database and system access to authorised personnel; regular security reviews and vulnerability assessments; logical separation of customer data by workspace; and secure deletion of data upon account termination.
6. Sub-processors
The Controller provides general written authorisation for the Processor to engage Sub-processors. The Processor shall maintain a current list of Sub-processors, which is set out in the Annex below. The Processor shall notify the Controller by email at least 14 days before adding or replacing a Sub-processor. If the Controller objects to a new Sub-processor on reasonable data protection grounds, the Controller may terminate the subscription by providing written notice within 14 days of receiving notification. Upon termination under this provision, the Processor shall refund any prepaid fees covering service periods after the termination effective date on a pro-rata basis.
Where the Processor engages a Sub-processor, the Processor shall impose on that Sub-processor the same data protection obligations as set out in this DPA by way of a contract. The Processor remains fully liable to the Controller for the performance of the Sub-processor's obligations.
7. Data Subject Rights
The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures in fulfilling the Controller's obligation to respond to requests from Data Subjects exercising their rights under the UK GDPR and EU GDPR (including rights of access, rectification, erasure, restriction, portability, and objection). If the Processor receives a request from a Data Subject directly, the Processor shall promptly forward it to the Controller.
The Processor satisfies portability requests by providing rendered template exports in PDF and ZPL formats, together with any personal data values provided by the Data Subject in a commonly-used machine-readable format. Internal schema representations, rendering engine configurations, and proprietary data structures are not included, consistent with Article 20(4) of the UK GDPR and EU GDPR, which preserves the rights and freedoms of others including intellectual property rights.
8. Breach Notification
The Processor shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach. The notification shall include: the nature of the breach, including the categories and approximate number of Data Subjects and records concerned; the likely consequences of the breach; and the measures taken or proposed to address the breach and mitigate its effects. The Processor shall assist the Controller in meeting the Controller's breach notification obligations under Articles 33 and 34 of the UK GDPR and EU GDPR.
9. Data Protection Impact Assessments
The Processor shall provide reasonable assistance to the Controller with data protection impact assessments and prior consultations with supervisory authorities, where required under the UK GDPR and EU GDPR, taking into account the nature of the processing and the information available to the Processor.
10. International Transfers
The Service is operated from infrastructure located in the European Union (Scaleway). Administrative access by the Processor's personnel may occur from the United States; such access is covered by the Standard Contractual Clauses referenced below. No general-purpose transfer of Personal Data to the United States occurs at rest.
For transfers of Personal Data from the European Economic Area to a third country without an adequacy decision, the parties incorporate the Standard Contractual Clauses approved by the European Commission under Commission Implementing Decision (EU) 2021/914, Module 2 (Controller to Processor), as set out in Annex B to this DPA. For transfers from the United Kingdom, the UK International Data Transfer Addendum to the EU SCCs (issued under Section 119A of the Data Protection Act 2018) applies.
11. Audit Rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. Audits shall be conducted at the Controller's expense, with reasonable prior notice (at least 30 days), during normal business hours, and no more than once per calendar year unless required by a supervisory authority or following a data breach. Any auditor appointed by the Controller must sign a non-disclosure agreement and may not be a competitor of the Processor. Once the Processor holds SOC 2 Type II or ISO 27001 certification, delivery of the attestation report satisfies audit requests unless the Controller demonstrates a specific reason for on-site audit.
12. Deletion and Return of Data
Upon termination of the subscription or upon the Controller's written request, the Processor shall, at the Controller's choice, delete or return all Personal Data to the Controller and delete existing copies, unless applicable law requires retention. Deletion shall be completed within 30 days of the request or termination date.
13. Liability
The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
14. Governing Law
This DPA is governed by the laws of the State of Minnesota, except that the data protection obligations are governed by the UK GDPR and EU GDPR as applicable to the Controller's jurisdiction. Any disputes arising under this DPA shall be resolved in accordance with the dispute resolution provisions of the Terms of Service.
15. EU Representative
The Processor will appoint an EU Representative under Article 27 of the EU GDPR upon commencement of its first paid subscription with a Controller subject to the EU GDPR. Representative details will be provided to affected Controllers at that time and published in the Privacy Policy.
16. Contact
Questions about this DPA? Click the "Help" button at the top of this page.
Annex A: Sub-processors
The following Sub-processors are authorised to process Personal Data on behalf of the Controller as of the effective date of this DPA:
Scaleway (Scaleway SAS, EU) — cloud infrastructure hosting, database, and container services. Processing location: European Union.
Creem (Creem) — merchant of record for payment processing and subscription billing. Processes billing-related data only.
Featurebase (Featurebase, EU) — customer support messenger, feedback, and changelog widget. Processes messages, email addresses, and feedback submitted through the support channel. Data stored in the Netherlands and Germany. Featurebase's AI assistant (Fibi) uses OpenAI and Google Gemini models; your data is not used for model training. Standard Contractual Clauses (SCCs) apply for potential transfers outside the EEA.
Proton (Proton AG, Switzerland) — business email hosting. Processes email content exchanged with the Company. All data encrypted at rest and in transit. Processing location: Switzerland.
This list is updated when Sub-processors are added or changed. The Controller will be notified by email at least 14 days in advance of any changes.
Annex B: Standard Contractual Clauses
For transfers of Personal Data from the European Economic Area to a third country without an adequacy decision, the parties incorporate the Standard Contractual Clauses approved by the European Commission under Commission Implementing Decision (EU) 2021/914, Module 2 (Controller to Processor). The completed SCC annexes are as follows:
Annex I.A — Parties. Data exporter: the Controller (the subscribing entity). Data importer: The Label Kitchen LLC (the Processor).
Annex I.B — Description of transfer. Categories of data subjects: the Controller's customers, suppliers, recipients, employees, or other individuals whose data the Controller includes in the Service. Categories of personal data: names, postal addresses, email addresses, telephone numbers, company names, and any other data the Controller includes in templates, address tables, or API requests. Purpose of processing: storage, retrieval, rendering, and generation of labels and documents as described in §2 of this DPA. Frequency: continuous for the duration of the subscription. Retention period: duration of the subscription plus up to 30 days for export or recovery.
Annex I.C — Competent supervisory authority. The competent supervisory authority is the Irish Data Protection Commission, as the Processor intends to appoint an EU Representative based in Ireland.
Annex II — Technical and Organisational Measures. As described in §5 of this DPA: encryption of data in transit (TLS/HTTPS); access controls restricting database and system access to authorised personnel; regular security reviews and vulnerability assessments; logical separation of customer data by workspace; secure deletion upon account termination.
Annex III — Sub-processors. As set out in Annex A of this DPA.
For transfers from the United Kingdom, the UK International Data Transfer Addendum to the EU SCCs (issued under Section 119A of the Data Protection Act 2018) applies and is incorporated by reference.
Privacy Policy
Effective date: 2026 April 19th
This Privacy Policy describes how The Label Kitchen LLC ("Company," "we," "us," or "our") collects, uses, and protects information when you use our web-based label and document design platform ("Service").
1. Information We Collect
Account information. When you create an account, we collect your email address. We use passwordless authentication (email one-time codes), so we do not store passwords.
Workspace and template data. We store the templates, documents, and configuration data you create within the Service. This may include label designs, address data, and EDI field mappings.
Usage data. We collect basic usage information such as pages visited, features used, browser type, and IP address to improve the Service and diagnose issues.
Payment information. Payment details (credit card numbers, billing addresses) are collected and processed exclusively by our merchant of record, Creem. We do not store your payment information on our servers.
2. How We Use Your Information
We use your information to: (a) provide, operate, and maintain the Service; (b) process transactions and send billing-related communications; (c) respond to support requests; (d) send product updates and announcements (you may opt out at any time); and (e) monitor and improve performance, security, and reliability.
3. Data Sharing
We do not sell your personal information. We share data only with the following recipients. A current list of our sub-processors, including their roles and processing locations, is maintained in the Annex to our Data Processing Agreement.
Scaleway (Scaleway SAS, EU) — cloud infrastructure hosting, database, and container services. Processing location: European Union.
Creem (Creem) — our merchant of record, which processes payments and manages billing on our behalf. Creem's handling of your data is governed by their Privacy Policy.
Featurebase (Featurebase, EU) — customer support messenger, feedback, and changelog widget. Data stored in the Netherlands and Germany.
Proton (Proton AG, Switzerland) — business email hosting. Processes email content exchanged with the Company. Processing location: Switzerland.
Legal obligations — we may disclose information if required by law, court order, or governmental request.
4. Data Retention
We retain your account and template data for as long as your account is active. If you delete your account, we will remove your personal data within 30 days, except where retention is required by law or for legitimate business purposes (such as resolving disputes).
5. Data Security
We implement industry-standard security measures including encrypted data transmission (TLS/HTTPS), secure database access controls, and regular security reviews. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
6. Cookies
We use essential cookies to maintain your session and remember your active workspace. We do not use third-party advertising or tracking cookies.
7. Your Rights
Depending on your jurisdiction, you may have the right to: access, correct, or delete your personal data; object to or restrict processing; request data portability; and withdraw consent. To exercise these rights, contact us at the address below.
8. Automated Decision-Making
The Service does not engage in automated decision-making, including profiling, that produces legal effects concerning Data Subjects or similarly significantly affects them.
9. Children's Privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will promptly delete it.
10. International Data Transfers
The Service is operated from infrastructure located in the European Union (Scaleway). Administrative access by our personnel may occur from the United States; such access is limited to named personnel for operational purposes and is covered by the Standard Contractual Clauses incorporated in our Data Processing Agreement. No general-purpose transfer of personal data to the United States occurs at rest. Where data protection laws in your jurisdiction differ, the safeguards described in our DPA ensure an adequate level of protection.
11. EU Representative
We will appoint an EU Representative under Article 27 of the EU GDPR upon commencement of our first paid subscription with a customer subject to the EU GDPR. Representative details will be published here at that time. We will appoint a UK Representative under Article 27 of the UK GDPR if and when we begin offering the Service to data subjects located in the United Kingdom.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice at least 14 days before taking effect.
13. Contact
Questions about this Privacy Policy? Click the "Help" button at the top of this page.
Refund Policy
Effective date: 2026 April 19th
This Refund Policy applies to subscriptions purchased through The Label Kitchen LLC ("Company," "we," "us," or "our") for use of our web-based label and document design platform ("Service"). All payments are processed by our merchant of record, Creem.
1. Subscription Billing
Subscriptions are billed on a recurring monthly basis. By subscribing, you authorize Creem to charge your chosen payment method at the start of each billing cycle until you cancel.
2. Free Trial
If we offer a free trial period, you will not be charged until the trial ends. You may cancel at any time during the trial without being billed.
3. Cancellation
You may cancel your subscription at any time from your account settings. Cancellation takes effect at the end of the current billing period — you will retain access to the Service until then.
4. Refund Eligibility
All payments are processed by Creem as our merchant of record. As the legal seller of our subscriptions, Creem governs refund eligibility under their terms of service. Please review Creem's Terms of Service to understand your refund rights.
Nothing in this Refund Policy limits any statutory rights you may have as a consumer under applicable law in your jurisdiction.
To request a refund or ask a billing question, click the "Help" button at the top of this page, and we will work with Creem to resolve your request.
5. How Refunds Are Processed
Refunds are processed by Creem and returned to the original payment method used at checkout.
6. Plan Changes
If you upgrade your plan mid-cycle, you will be charged a prorated amount for the remainder of the current billing period. If you downgrade, the new rate takes effect at the start of your next billing cycle.
7. Disputes
If you believe you have been charged in error, please contact us before filing a dispute with your payment provider. We are committed to resolving billing issues promptly and fairly.
8. Changes to This Policy
We may update this Refund Policy from time to time. Material changes will be communicated via email or in-app notice at least 14 days before taking effect.
9. Contact
Questions about refunds or billing? Click the "Help" button at the top of this page.