Terms & Conditions
Effective Date: August 24, 2026
Last Updated: August 24, 2026
Introduction
These Terms & Conditions (“Terms”) govern access to and use of Control Room, the Squarespace Connector module of the Lynn Music Foundation Staff Portal (the “Portal”). Control Room is the administrative panel through which authorized staff connect, monitor, and manage the integration between the Portal and the Lynn Music Foundation Squarespace site, including OAuth authorization, membership tier mapping, and automated member data synchronization.
Control Room is operated by Lynn Music Foundation (“LMF,” “we,” “us,” or “our”), a nonprofit organization located at 360 Union Street, Lynn, Massachusetts. These Terms supplement, and do not replace, the LMF Staff Portal Terms & Conditions, which continue to govern your overall use of the Portal. Where the two conflict as to the Squarespace Connector specifically, these Terms control.
By accessing or using Control Room, you agree to be bound by these Terms. If you do not agree to these Terms, you may not access or use Control Room.
Definitions
"Control Room" means the Squarespace Connector administration panel within the Portal, including its configuration screens, connection status views, and sync logs.
"Connector" or "Squarespace Connector" means the OAuth application, webhook subscriptions, and related API integrations that link the Portal to the LMF Squarespace site for the purpose of syncing membership and order data.
"Authorized User" means any Portal user granted access to Control Room by LMF, limited to staff whose assigned role includes Squarespace Connector permissions.
"Squarespace Account" means the LMF-owned Squarespace site and Commerce account authorized to communicate with the Portal through the Connector.
"Member Data" means data received from Squarespace through the Connector, including customer name, email address, phone number, purchased product, subscription status, and related order metadata.
"Webhook Event" means a notification (such as an order.create event) sent from Squarespace to the Portal describing a change on the Squarespace Account.
"Credentials" means the OAuth client ID, client secret, access tokens, refresh tokens, and webhook signing secret used to authenticate the Connector.
Purpose & Scope
The Squarespace Connector automates the flow of membership information between the LMF Squarespace site and the Portal so that staff do not need to manually create or update member records. Specifically, the Connector:
Authenticates to the Squarespace Account via OAuth, using a client ID and secret registered with Squarespace's developer platform.
Subscribes to Squarespace Commerce webhook events (including order.create) and receives them at a Portal webhook endpoint.
Maps purchased Squarespace products to LMF membership tiers (for example, Artist Membership → artist, Audio Engineers Guild → engineer, Non-Profit Partnership Member → nonprofit).
Automatically creates or updates the corresponding member record in the Portal, and initializes the onboarding queue for tiers that require it.
Logs each received webhook event, including verification status, for audit purposes.
Control Room does not itself process payments; payment processing occurs on Squarespace and, separately, through Square for in-Portal transactions. Control Room is limited to reading order and profile data and, where configured, writing profile updates back to Squarespace.
Access & Authorization
4.1 Role-Based Access
Access to Control Room is restricted to Authorized Users whose role grants Squarespace Connector permissions, consistent with the Portal's Role-Based Access Control (RBAC) matrix. Viewing connection status and sync logs may be available to a broader set of roles than initiating, reauthorizing, or revoking the connection.
4.2 Authorizing the Connection
Only designated administrators may complete the Squarespace OAuth authorization flow on behalf of LMF. By completing this flow, the authorizing user represents that they are authorized to grant the requested Squarespace permissions (Commerce Orders read access, Profiles read/write access, and Webhook Subscriptions) on behalf of Lynn Music Foundation.
4.3 Credential Handling
OAuth Credentials and the webhook signing secret are stored as environment variables in the Portal's hosting configuration and must not be shared, copied into other systems, committed to source control, or exposed in logs, screenshots, or support tickets. Any suspected exposure of Credentials must be reported to the Portal administrator immediately so that they can be rotated.
5. Acceptable Use
5.1 Permitted Uses
Monitoring connection health and webhook delivery status.
Reviewing sync logs to troubleshoot a missing or misassigned member record.
Reauthorizing the connection after a credential rotation or Squarespace-side change.
Updating the product-to-tier mapping to reflect new or changed Squarespace membership products, subject to LMF approval.
5.2 Prohibited Uses
Using Control Room to access, export, or copy Member Data for any purpose outside legitimate LMF membership administration.
Modifying the webhook handler's signature verification, tier mapping logic, or Credentials without authorization from the Portal administrator.
Connecting the Squarespace Connector to any Squarespace site other than the authorized LMF Squarespace Account.
Attempting to replay, forge, or manually trigger webhook events other than for authorized testing.
Disabling webhook signature verification, audit logging, or other security controls.
6. Data Handling and Member Data
Member Data received through the Connector is Confidential Information under the LMF Staff Portal Terms & Conditions and is subject to the same handling obligations. In addition, with respect to the Squarespace Connector specifically, Authorized Users agree to:
Treat Member Data received via webhook as authoritative only after signature verification succeeds; unverified or failed-signature events must not be used to create or modify member records.
Correct tier-mapping or data-entry errors promptly and document the correction in the sync log or a supervisor ticket.
Retain squarespace_webhook_log records in accordance with LMF's data retention policy and not delete them except as that policy permits.
Limit any manual re-sync or backfill of historical Squarespace orders to what is necessary to correct a specific, identified data issue.
7. Third-Party Service Dependency
The Squarespace Connector depends on the availability, behavior, and policies of Squarespace, a third-party platform not owned or controlled by LMF. Your use of the Squarespace Account, and any data you view or manage through Squarespace directly, remains subject to Squarespace's own terms of service and privacy policy. LMF is not responsible for Squarespace outages, API changes, delayed or dropped webhook deliveries, or other failures originating on Squarespace's platform, and will make reasonable efforts to reconcile data once service is restored.
8. Security
All inbound webhook requests are validated against the configured webhook signing secret before being processed; requests that fail verification are logged and discarded.
OAuth tokens are refreshed and stored server-side only and are never exposed to the browser or to Squarespace member-facing pages.
Multi-factor authentication is required for any Portal account with permission to view or modify Control Room settings, consistent with Portal-wide account security requirements.
Any suspected compromise of the Squarespace Account, the Connector, or its Credentials must be reported immediately so that tokens can be revoked and rotated.
9. Monitoring and Audit
All Control Room activity, including connection changes, mapping edits, manual re-syncs, and webhook processing outcomes, is logged for security and compliance purposes. By using Control Room, you consent to such monitoring and auditing. Logs are retained and reviewable in accordance with LMF's data retention policies and may be used to investigate data discrepancies or suspected misuse.
10. Termination and Revocation of Access
LMF may suspend, revoke, or reconfigure Squarespace Connector access, or disconnect the Squarespace Account entirely, at any time and without notice, including where necessary to address a security concern, a Squarespace policy change, or a data integrity issue. Your individual access to Control Room may be terminated or suspended consistent with Section 10 of the LMF Staff Portal Terms & Conditions (end of employment or volunteer relationship, violation of these Terms, security concerns, or LMF's sole discretion).
11. Disclaimer of Warranties
CONTROL ROOM AND THE SQUARESPACE CONNECTOR ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. LMF DOES NOT WARRANT THAT WEBHOOK DELIVERY WILL BE UNINTERRUPTED, TIMELY, OR ERROR-FREE, OR THAT MEMBER DATA SYNCED FROM SQUARESPACE WILL ALWAYS BE COMPLETE OR ACCURATE.
12. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, LMF SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING OUT OF OR RELATED TO THE USE OF CONTROL ROOM OR THE SQUARESPACE CONNECTOR, INCLUDING BUT NOT LIMITED TO LOSS OF DATA, MISSED OR DUPLICATED MEMBER RECORDS, OR BUSINESS INTERRUPTION CAUSED BY A SQUARESPACE OUTAGE OR API CHANGE.
13. Indemnification
You agree to indemnify, defend, and hold harmless Lynn Music Foundation, its officers, directors, employees, and volunteers from any claims, damages, losses, or expenses (including reasonable attorneys' fees) arising out of your violation of these Terms or your misuse of Control Room or the Squarespace Connector.
14. Changes to These Terms
LMF reserves the right to modify these Terms at any time, including to reflect changes to the Squarespace integration, its permission scopes, or its data flow. We will notify Authorized Users of material changes by posting the updated Terms and updating the “Last Updated” date. Continued use of Control Room after such changes constitutes acceptance of the revised Terms.
15. Governing Law
These Terms shall be governed by and construed in accordance with the laws of the Commonwealth of Massachusetts, without regard to its conflict of law provisions. Any disputes arising under these Terms shall be resolved exclusively in the state or federal courts located in Essex County, Massachusetts.
16. Contact Information
For questions about these Terms, please contact:
Lynn Music Foundation
Attn: Executive Manager of Operations
25 Exchange Street, Lynn, MA 01901
Email: info@lynnmusic.org
Website: www.lynnmusic.org
17. Acknowledgment
By accessing and using Control Room, you acknowledge that you have read, understood, and agree to be bound by these Terms & Conditions, in addition to the LMF Staff Portal Terms & Conditions.

