IntoSquare Contact us ↗

Your data & your choices

Privacy Policy

This policy explains how IntoSquare handles personal data when you visit our website, use our Figma plugin or Chrome extension, or use our account service.

Last updated:

The essentials. IntoSquare uses your data to transfer Figma designs into Squarespace, operate your account and respond to you. Design processing and import backups stay in your browser until you choose to transfer content to Squarespace. We do not sell personal data or use it for advertising.

1. Who is responsible

IntoSquare is operated by Ilia Mikheenko, based in Georgia, who is the controller of personal data handled for the website, launch list, IntoSquare accounts, billing and support. Contact: hello@intosquare.app.

This policy covers intosquare.app, the IntoSquare Figma plugin, the IntoSquare Chrome extension and the associated IntoSquare API. Account, payment and import records described below apply when you use those features. Figma, Squarespace and payment providers also have their own privacy policies for their services.

2. Data we handle

Launch-list and support information
Your email address, signup date, consent and signup source when you request a launch notification. If you contact us, we receive your email and the information you choose to send. Launch signup is optional.
Account and authentication information
Your email address, account identifier, verification status, password hash and session records. The extension sends your password over HTTPS to authenticate you; it does not save your password in extension storage. Session tokens and account settings are stored in browser session storage.
Payment and subscription information
Plan, subscription status, payment-provider identifiers, transaction status, amount, currency and relevant billing dates. Paddle handles checkout and payment details. IntoSquare does not receive full card numbers or card security codes.
Designs and destination website content
The Figma content you choose to export, including layout, text and style information; the selected Squarespace site's identifier, domain, page path and title; and page or Site Styles data needed to prepare, apply and verify an import. Local history can include before-and-after snapshots.
Import activity and technical records
Import type, time, status, site identifier and result are used for history, recovery and usage limits. The account API processes IP addresses for sign-in abuse prevention. Operational records can include request identifiers, route, status and error information. We do not request GPS location or track your general browsing, mouse movements or keystrokes.
Preferences
Theme preferences and import settings stored on your device. The website uses local storage to remember its theme; the Figma plugin uses Figma client storage for its theme.

3. How your designs move

The Figma plugin processes the content you select inside Figma. Its current manifest permits no external network requests. You choose when to copy an export to the clipboard or save a file and then paste or open it in the Chrome extension.

The Chrome extension prepares a preview locally, reads the Squarespace destination you select and sends the requested changes directly to that Squarespace site using your existing Squarespace session. Page snapshots and import history are kept in local extension storage. The account API receives account information, site identifiers and import-operation results; it does not receive the full design package or local page backups as part of the normal import flow.

If you approve downloading missing fonts for Site Styles, the extension requests font files and metadata from the official Google Fonts repository on GitHub and uploads the selected fonts to your Squarespace site. Those requests reveal your IP address and requested font URLs to the hosting provider.

The extension is designed for Figma-to-Squarespace transfers. It does not monitor unrelated tabs or collect a general browser history.

4. Why we use data

  • Provide the service you request: authenticate your account, transfer designs, verify changes, manage access and process purchases. This processing is necessary to provide the service and perform our agreement with you.
  • Send the launch notification: we use your email with your consent. You can withdraw consent by emailing us at any time.
  • Maintain security and reliability: prevent abuse, enforce import limits, investigate errors and respond to support requests. We rely on our legitimate interests in running a secure, functional service, taking your rights into account.
  • Meet legal obligations: keep records required for accounting, tax or valid legal requests.

You can browse the public website without creating an account or joining the launch list. Account information is needed for account-based imports; destination access is needed to transfer a design. Declining optional font access prevents that automatic font download, rather than giving access to unrelated websites.

Usage limits and subscription checks automatically determine which product features are available. If you believe an access decision is wrong, contact us for review.

5. Service providers & sharing

Data is shared where needed to operate the service:

  • GitHub Pages hosts the public website. Infrastructure providers run the account API, database and associated technical services. These providers process connection information such as IP addresses and request metadata.
  • Google Apps Script and Google Sheets receive launch-list submissions and store the private signup list. A signup notification is sent to our support inbox.
  • Email providers, including Brevo for account messages, process recipient addresses and message content to deliver verification, password-reset and service emails.
  • Paddle processes checkout, subscriptions and billing. Its handling of payment information is also described in its own privacy notice.
  • Squarespace receives the content and fonts you choose to import. GitHub's Google Fonts repository supplies fonts only when that feature is requested.

We may also disclose necessary information to comply with law, investigate abuse or protect the service. We do not sell or rent personal data, share it for advertising, or use design content to train AI models.

Providers may process data outside Georgia. Where international transfers require a legal mechanism or safeguards, those requirements apply to the transfer. Contact us for information about the providers, destination countries and safeguards relevant to your data.

6. Storage, security & retention

We use HTTPS for service requests, hashed passwords, access controls and session-based authentication. Security and error logs are designed to exclude passwords and authentication tokens. No transmission or storage system can be guaranteed completely secure.

  • Local data: import history, recovery snapshots and preferences remain in your browser until you remove the extension or clear its data. Files you export and copies in your clipboard are under your control. Signing out clears the active IntoSquare token; it does not automatically erase local import history.
  • Launch list: we keep the address to deliver the requested launch announcement and manage removal requests. We retain the minimum consent and withdrawal record for the period required by applicable law.
  • Accounts and service records: we keep data while needed to provide your account, reconcile imports, enforce usage limits and resolve disputes. You may request deletion; records still needed for legal obligations or fraud prevention can be retained for those purposes.
  • Technical data: expired authentication records and old logs are periodically removed under the API's configured cleanup rules. Backup copies may remain until the applicable backup-retention cycle ends.
  • Billing records: we retain the records needed for accounting, tax, refunds and disputes for the applicable legal retention period.

The website does not include advertising trackers or third-party analytics. Essential local storage supports theme preferences. Separate services such as Figma, Squarespace and Paddle manage their own cookies and storage.

7. Your rights & choices

Depending on the law that applies, you can request information about processing, access to or a copy of your personal data, correction, deletion, restriction, objection or a portable copy. You may withdraw consent without affecting processing that was lawful before withdrawal.

Email hello@intosquare.app with your request. We may ask for information needed to verify that the data belongs to you. We respond within applicable legal time limits and explain any lawful reason that prevents us from fully carrying out a request. You can also complain to the competent data-protection authority or seek a judicial remedy.

To stop launch emails, write “Remove me from the launch list” from the address you used to subscribe. Clearing local extension data removes your local history, but does not delete account or billing records held by the service. A server-side account-deletion request does not remove content already imported into your Squarespace site.

8. Chrome Web Store limited use

IntoSquare's use and transfer of user data follows the Chrome Web Store User Data Policy, including its Limited Use requirements. Data accessed through the extension is used to provide and maintain the disclosed Figma-to-Squarespace transfer, account, import-history and access-management features.

We do not use or transfer that data for personalized advertising, unrelated profiling, creditworthiness or lending decisions. Human access is limited to necessary support with your consent, security investigations, legal obligations or aggregated internal operations allowed by the policy.

9. Changes & contact

We update this page when our practices change and revise the date above. If a change requires additional notice or consent, we provide it before the new processing begins.

Ilia Mikheenko · IntoSquare
Georgia
hello@intosquare.app