KITSLATE

How it worksFeaturesBuy used gearFind crewPricingSign inEnter the sandbox →

Privacy Policy

Version 1.2 · Effective 28 August 2026 · Last updated 9 September 2026
Summary. This Policy describes how MIXEL INC, a New York corporation doing business as KitSlate, collects, uses, discloses and retains personal information in connection with the KitSlate platform. Personal information is collected for the purpose of operating Customer accounts and workspaces and is not collected for advertising purposes. MIXEL INC does not sell personal information, does not share it for cross-context behavioural advertising, and does not use Customer Data to train machine-learning models. Cardholder data is processed by Stripe and is not received by MIXEL INC. Customer Data may be exported at any time, and accounts may be deleted on request. This summary is provided for convenience only; the provisions below govern.

1. Who we are

KitSlate is a production-management platform for studios, freelancers and crews. It is operated by MIXEL INC, a corporation organised under the laws of the State of New York, United States, doing business as KitSlate (“MIXEL INC,” “KitSlate,” “we,” “us,” “our”). MIXEL INC is the data controller for the information described in this policy, except where section 3 says you are.

The Service runs at https://kitslate.app and covers gear and inventory management, productions, quotes, invoices, call sheets, crew and client records, a used-gear marketplace and a public crew directory. This policy explains what we collect, why, how long we keep it, who else touches it, and what you can ask us to do. If anything here is unclear, email [email protected] and we will explain it plainly.

2. What this policy covers

It covers the KitSlate website, the demo sandbox, the application, the documents and emails KitSlate generates on your behalf, the marketplace and the crew directory. It does not cover a third-party site you reach from a link in KitSlate, or what one of your own clients does with a document you sent them.

3. Two roles: your information, and other people’s

The allocation of controller and processor roles is as follows.

  • Your own information — we are the controller. Your name, email address, sign-in records, profile, company details, subscription and billing status, support correspondence and usage analytics. We decide how these are used, within the limits of this policy, and you can exercise the rights in section 20 against us directly.
  • Information about other people that you put into your workspace — you are the controller and we are your processor. Your clients’ contact details, your crew’s names, rates and phone numbers, cast on a call sheet, signatories on a release. We hold and process these on your instructions in order to run the Service for you. We do not decide what to do with them, we do not use them for our own purposes, and we do not contact those people except to deliver something you asked us to send.

If one of your crew or clients contacts us about their information, we will normally point them to you, because you hold the relationship and the lawful basis. If you need a signed data-processing agreement, email [email protected].

4. Your account

When you create a KitSlate account we collect your email address and the name you give us, and we create the records needed to sign you in and run your workspace. KitSlate does not use passwords. You sign in either with Google, or with a one-time code sent to your email address — so there is no KitSlate password for us to store or for anyone to steal. We also keep sign-in timestamps and session records to secure the account.

5. Google Sign-In and Google Calendar

If you sign in with Google, we receive only the basic Google account information required for authentication: your name, your email address, and your Google profile picture. We use it to create and secure your KitSlate account and to show you who is signed in.

KitSlate does not access your Gmail, Google Drive, Google Contacts or any other Google data, with one exception that you choose: the Google Calendar connection described below. Signing in with Google never grants it. It is a separate, optional step that asks for its own permission through Google’s own consent screen, and declining it never affects your ability to sign in or use KitSlate.

The Google Calendar connection

Under Calendar → Publishing you can connect a Google account so that the bookings on your KitSlate calendar are written to a Google calendar of your choosing, and kept up to date as they change. When you connect, Google asks you to grant KitSlate two permissions, and KitSlate asks for nothing more:

  • See the list of your calendars — only their names and identifiers, so that you can pick which calendar each of your companies writes to.
  • Create, change and delete events — used only for the events KitSlate itself creates. KitSlate keeps a record of every event it has written and touches only those. It does not read, copy or process the events that are already in your Google Calendar, and it never reads your calendar to import anything.

Google also tells us the email address of the account you connected, so that the Publishing page can show you which account is linked.

What KitSlate sends to Google. For each booking it publishes: the title, the dates, the location, a short description, whether it is tentative or confirmed, and a KitSlate identifier so the same event can be updated later. Which details are included follows the content choices you make for that company’s calendar feed on the same page. Invoice amounts are never sent.

How the credential is kept. When you connect, Google issues KitSlate a credential that lets it write on your behalf. That credential is stored encrypted (AES-256-GCM) in our database, is decrypted only inside the server function that talks to Google, is never sent to your browser, and is never shared with anyone. It is used for one purpose: writing your bookings to the calendar you chose.

Disconnecting. Disconnect on the Publishing page removes the events KitSlate wrote to your Google calendar, revokes the credential at Google, and deletes it from our records. You can also withdraw KitSlate’s access at any time from your Google account permissions; when you do, the connection stops and is marked as revoked in KitSlate. Deleting your KitSlate account deletes the credential with it.

Limited Use. KitSlate’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Information obtained through the Google Calendar connection is used only to provide and improve that connection. It is not used for advertising, is not sold, is not transferred to anyone other than as necessary to provide the feature or to comply with the law, is not used to train AI models, and is not read by a person except with your explicit permission, for security purposes, or where the law requires it.

6. Your email address

We use your email address to sign you in, to send account, billing and security messages, and to deliver the working email the app sends on your behalf — a quote or invoice you email to a client, a crew invitation, a call sheet, a document handed off for signing. Invitations and some notifications contain a small image that tells us the message was opened, and links that tell us they were clicked; mail providers routinely load these images automatically, so we treat opens as a rough signal, not a fact. Every invitation carries an unsubscribe link, and using it stops us emailing you. We do not use your email address for third-party marketing, and we never make an email address a public display name.

Replies to a document you sent can be routed back into KitSlate. Where that is enabled, the reply address on the message is a unique token address at reply.kitslate.app; a reply sent to it is delivered into your KitSlate inbox and a copy is forwarded to you. The body of that reply is stored with the document it belongs to.

7. Your profile and the crew directory

Your KitSlate profile — your name, photo, roles, services, city and anything else you add — is private until you choose to publish it. A published profile page is public on the open web at your chosen handle, is listed in the crew directory, and can be indexed by search engines; that is its purpose. You can unpublish it at any time and the public page comes down. Profile pictures you remove are deleted immediately.

8. Company information

For each company in your workspace you can store its name, branding, addresses, contact details, tax and payment particulars, and the defaults used on documents. This exists so your quotes, invoices and call sheets carry the right letterhead and bank details. It is shown only to people you send those documents to, and to teammates you invite into the workspace.

9. Equipment and inventory

Your inventory — equipment records, categories, kits, cases, locations, serial numbers, purchase prices and values — is your business data. We store and sync it to run the Service for you. It is not public unless you explicitly list an item on the marketplace (section 13) or include it in a document you send.

10. Productions, quotes, invoices and call sheets

Productions and their schedules, the clients and crew attached to them, the packing and return records around them, and the documents they generate are private working data. They are synced to the devices you sign into and visible only to you, your invited teammates, and the people you deliberately send a document to.

Quotes and invoices contain your company details, your client’s details, line items and amounts. We store them so you can edit, send and track them. Call sheets contain production details and the names, roles and contact details of crew and cast you add, and are shared only with the people you send them to. You are responsible for having a proper basis to circulate your crew’s contact details, the same as with any call sheet you would hand out on paper. We do not use the contents of your financial or production documents for anything other than running the Service for you.

11. Crew records and handoffs

When you invite a crew member to fill in their own details, they receive a scoped link, and what they submit goes into your address book. Their submission merges into your records; it is visible to them while they fill it in and to you afterwards. In that exchange you are the controller of their information and we are your processor.

12. Agreements and signatures

Where you send a release or agreement for signature, we store the document, the version of the text that was actually presented, the signer’s name and email, the timestamp, and technical details of the signing event kept as evidence that the signature is genuine. Once signed, the signed text and the signer’s identity are immutable — this immutability is a deliberate control, as a signature record that remains alterable after execution has no evidential value.

13. Marketplace listings

Listing gear on the KitSlate market is a choice to publish. A live listing — its title, description, photos, price, condition and general location — is public and can be indexed by search engines. When a listing is removed or sold it leaves the market immediately; its photos are permanently deleted 90 days later, and the listing’s basic record (title, price, condition, dates) is kept as your sales history. KitSlate does not handle marketplace payments and never sees buyer payment details.

14. Files you upload

Files you upload — equipment photos, listing photos, profile pictures, receipts, logos — are stored with our database and storage provider and served over encrypted connections. They are private to your workspace unless attached to something you publish or send.

15. AI features

Several KitSlate features use a third-party AI model to read or interpret material you supply: reading a receipt or supplier invoice, matching an equipment description to a catalogue entry, mapping the columns of a spreadsheet you import, parsing a production document or call sheet, checking a listing photo, and drafting suggested text. When you invoke one of these, the specific material you submitted is sent to Anthropic PBC, processed, and the result returned to you.

This happens only when you invoke the feature on that item — we do not stream your workspace to an AI model in the background. Under Anthropic’s commercial API terms, inputs and outputs are not used to train its models. We do not use your content to train any model, and we do not license it to anyone who does. AI output is a suggestion, it can be wrong, and you should review it before relying on it.

16. Cookies and storage on your device

KitSlate sets no cookies. Not one, on any page. That is unusual enough to be worth stating plainly rather than burying: everything we keep on your device is kept in your browser’s local storage, on this site only, and none of it is readable by any other website. The law treats browser storage exactly as it treats a cookie, so the choice below is a real one and we present it in those terms.

When you first arrive we ask what you are willing to allow. Nothing optional runs until you say yes — the analytics and advertising tools described below are not merely switched into a quiet mode, they are never loaded at all until you allow them. Refusing is one click, in the same place and at the same size as accepting. You can change or withdraw your answer at any time using the Cookie preferences link in the footer of every page.

WhatWhoWhat it is forCategoryKept for
gearlist-sessionKitSlateKeeps you signed in. Without it the app cannot open.EssentialUntil you sign out or clear site data
gearlist-wsKitSlateYour workspace itself — productions, gear, documents — held on your device so the app works.EssentialUntil you clear site data
ks-consent-v2KitSlateThe privacy choice you made on this page. We have to store it in order to honour it.EssentialUntil you change it or clear site data
kit-themeKitSlateLight or dark, dark depth and high-contrast text — preferences you set deliberately.EssentialUntil you change it or clear site data
ks-attrKitSlateIf you arrive from a link we published, this remembers the campaign for the length of that one visit, so that if you then create an account we know which link brought you. It holds no identifier, cannot be read by any other site, and is discarded when you close the tab.EssentialUntil you close the tab
Delivery and securityCloudflareServing the site, blocking abuse, and a page-speed measurement that stores nothing at all on your device and cannot identify you. Because it stores nothing, it needs no permission.EssentialNot stored on your device
ks-uidKitSlateA random identifier that lets us tell a returning visitor from a new one, so our own usage counts are not wrong. Only ever written if you allow analytics.AnalyticsUntil you withdraw or clear site data
ks-attr-firstKitSlateRemembers the first link that brought you, across visits, so an advert clicked one day still gets the credit if you sign up later. Only ever written if you allow analytics.AnalyticsUntil you withdraw or clear site data
Google Analytics 4GoogleMeasuring how the site is used. Not currently configured — no Google tag is loaded today, and none will be unless you allow analytics.AnalyticsNot currently in use
Google Ads conversion measurementGoogleTelling whether an advert we paid for led anywhere. Not currently configured. If we begin advertising it will only run for people who allowed marketing.MarketingNot currently in use

There is no “personalisation” category because there is no personalisation: KitSlate does not change what it shows you based on stored behaviour. We do not sell or share your personal information, we do not use advertising cookies, and we do not take part in any cross-site tracking or data broking. If your browser sends a Global Privacy Control signal we treat it as a refusal of everything optional, switch those off without asking, and tell you we have done so — you can still opt in afterwards if you want to.

If you clear your browser’s site data you will be signed out, your privacy choice will be forgotten and we will ask again, and locally cached work not yet synced may be lost.

17. Analytics and logs

We keep our own record of which pages and screens get used and which links get clicked, so we can see what is worth building and what is quietly broken. This is first-party analytics on our own infrastructure. We are not running any third-party tracker today, and any we ever add will be behind the consent choice described above.

Signed out, on our public pages, this only happens if you allowed analytics. If you refused, or have not answered yet, we send nothing about you at all — not an anonymised record either. What we still see is Cloudflare’s count of the visit, which stores nothing on your device and cannot pick you out.

Signed in, inside the app, we record this as part of running the product you hold an account for, as described in the Terms, rather than under the cookie choice. It is tied to your account, it writes nothing to your device, and it tells us which screens are worth keeping. In both cases these records are deleted automatically after 180 days, and immediately if you close your account.

We also keep a record of the privacy choice itself — what you allowed, when, which version of this policy it was made against, and whether it came from the banner, the preferences panel or a Global Privacy Control signal. That record deliberately contains no IP address, no device fingerprint and no user agent; it is tied to a random identifier that names a decision rather than a person. It cannot be altered after the fact, including by us, because a consent record that can be edited is not evidence of anything. These are kept for 24 months.

Our infrastructure providers also keep short-lived technical logs — IP address, timestamp, request path, user agent — for delivery, abuse prevention and debugging. We use these to keep the Service running and secure, not to profile you.

18. Payments and Stripe

Subscription billing, and online invoice payments where you enable them, are processed by Stripe, Inc. Your card number, expiry date and security code go directly to Stripe and never touch our servers at any point. What we receive is limited to what we need to run your subscription and show you its status: the plan and interval, whether a payment succeeded or failed, the renewal date, the card brand and last four digits, and Stripe’s identifiers for your customer and subscription records. Stripe’s handling of your information is governed by Stripe’s privacy policy.

19. Why we use your information, and our legal bases

Where the GDPR, the UK GDPR or similar legislation applies, we rely on these bases:

  • To perform our contract with you — creating and running your account, storing and syncing your workspace, generating and sending your documents, processing your subscription, providing support.
  • Our legitimate interests — keeping the Service secure and free of abuse, understanding which features are used so we can improve them, keeping records of what we sent and when, and defending legal claims. We balance these against your interests, and you can object under section 20.
  • Your consent — publishing your profile to the public directory, listing an item on the marketplace, connecting an optional integration, and any optional marketing email. You can withdraw consent at any time; withdrawal does not affect what was lawful before it.
  • Legal obligation — keeping billing and tax records, and responding to a lawful request from an authority.

20. Who else handles your information

We share information only with the providers we need to run the Service. Each is bound by contract to handle it only on our instructions. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not disclose it to data brokers. Our current subprocessors:

The subprocessors engaged in delivering the Service, the processing each performs and its location are set out in the subprocessor register, which is maintained as the authoritative record and is incorporated into this Policy by reference.

We may also disclose information where the law requires it, to enforce our Terms & Conditions, to protect the rights or safety of people, or to a successor in a merger or acquisition — in which case this policy continues to apply until you are told otherwise. We will tell you about a legally compelled disclosure unless we are prohibited from doing so.

21. Where your information is stored, and international transfers

KitSlate’s database, files and backups are stored in the United States. If you are in the United Kingdom, the European Economic Area or another region with transfer restrictions, using KitSlate means your information is transferred to the United States. Those transfers are made under the European Commission’s and the UK’s Standard Contractual Clauses, incorporated into our agreements with the providers listed in section 20, together with the technical measures on our Security page. You can ask us for details of the safeguards that apply to a particular transfer.

22. How long we keep information

  • Workspace data — for as long as your account is open, and until you delete it.
  • Account and profile records — until you delete your account.
  • Google Calendar credential — until you disconnect, or Google withdraws KitSlate’s access; deleted immediately when either happens, and when you delete your account. The record of which events KitSlate wrote is deleted with it.
  • Analytics records — 180 days, then deleted automatically; immediately on account closure.
  • Removed marketplace listing photos — permanently deleted 90 days after the listing comes down.
  • Encrypted backups — retained on a rolling schedule of fourteen daily, eight weekly and twelve monthly copies. A deleted record leaves the most recent backups within about two weeks and ages out of all retained copies within about twelve months.
  • Billing and tax records — retained for as long as tax and accounting law requires, typically seven years, even after account closure.
  • Signed agreements — retained while the account is open, because a signature record is evidence and deleting it destroys its value; you can ask us to remove one.

23. How we protect your information

Connections are encrypted in transit, data and files are encrypted at rest by our infrastructure providers, account backups are encrypted before they are stored, every account is scoped to its own records at the database level, and every write is checked on the server rather than trusted from your browser. Because we do not use passwords, there is no KitSlate password database to breach. The full picture, including what we have not yet done, is on our Security page.

No online service can promise perfect security. So we also make it easy to keep your own copies: you can export your entire workspace to a single backup file, or export records as CSV and PDF, at any time. If we become aware of a breach affecting your personal information, we will tell you what happened, what it affected and what we are doing about it, without undue delay and in any case within the time the law requires.

24. Your rights

You can ask us at any time to:

  • Access — give you a copy of the personal information we hold about you.
  • Correct — fix anything that is wrong or out of date.
  • Export — give it to you in a portable form; the app’s own export tools do this without needing to ask.
  • Delete — remove your account and its data (section 26).
  • Object or restrict — stop or limit a particular use, including anything we do on the basis of legitimate interests.
  • Withdraw consent — where we relied on it, such as a published profile or a listing.

Email [email protected] from your account’s email address to exercise any of these. We respond within 30 days. MIXEL INC honours these rights for all users irrespective of jurisdiction, and will not charge a fee for, or degrade the Service in response to, the exercise of any such right.

25. If you are in the EEA, the UK, or California

EEA and UK. The rights in section 24 are your rights under the GDPR and the UK GDPR, and the bases we rely on are in section 19. You also have the right to complain to your national supervisory authority — in the UK, the Information Commissioner’s Office at ico.org.uk. MIXEL INC requests the opportunity to address complaints directly in the first instance, without prejudice to that right. We do not currently have an appointed EU or UK representative; enquiries reach us directly at [email protected].

California. Under the CCPA as amended by the CPRA you have the right to know, delete, correct, and to opt out of sale or sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have not done so in the preceding twelve months, so there is nothing to opt out of. The categories we collect, why, and who we disclose them to are described in sections 4 to 20. We do not use or disclose sensitive personal information for purposes requiring an opt-out right. We will not discriminate against you for exercising a right.

26. Deleting your account

You can request deletion by emailing [email protected] from your account’s email address. Deletion removes your account, workspaces, inventory, productions, documents, uploaded files and analytics records. Published profile pages and listings come down. Some records are retained where the law requires it — principally payment and tax records — and encrypted backups age out on the cycle in section 22. Customers should export any data they wish to retain before submitting a deletion request, as deletion cannot be reversed.

27. Automated decision-making

We do not make decisions about you by automated means that produce a legal or similarly significant effect. The AI features in section 15 suggest and extract; they do not decide anything about you, and a person — you — reviews the result.

28. Children

KitSlate is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16. You must be old enough to enter a contract where you live to hold an account. If you believe a child has given us information, tell us and we will delete it.

29. Changes to this policy

If we change this policy we will update the date at the top, and if a change is material we will tell you — by email or a notice in the app — before it takes effect. We will never quietly reduce your rights over your own data.

30. How to reach us

Privacy questions and rights requests: [email protected]. Security reports: [email protected]. Everything else: [email protected].

MIXEL INC
a New York corporation, doing business as KitSlate
State of New York, United States
[email protected] · kitslate.app

KITSLATE

Production management for studios, freelancers and crews.

© 2026 KitSlate
Product How it works Pricing Manual Sandbox
Features Call sheets Gear lists Equipment inventory Quotes & invoicing Agreements & releases Calendar & availability Crew directory Public profile Used-gear market
Marketplace Buy used gear Find crew Market & rates
Legal Privacy Policy Cookie preferences Terms & Conditions Security Subprocessors Contact