Privacy Policy
1. What Data We Collect
We collect data only to the extent necessary to provide the Service (data minimization principle), primarily in the following categories:
| Data category | Details | Source |
|---|---|---|
| Account information | Registration email, account name, login credentials (stored encrypted), team and role information | Provided by you when you register and use the Service |
| TikTok Shop API authorization data | Shop ID, shop name, OAuth access tokens (access token / refresh token, stored encrypted), authorization scopes | Obtained through the official TikTok Shop API after you authorize us via the official TikTok Shop OAuth flow |
| Shop operational data | Product information (title, images, price, inventory, links), order and sales statistics, content performance data (views, clicks, conversions) | Synced through the official TikTok Shop API with your authorization |
| Content and creative data | Materials you upload (images, videos, copy), generation task instructions, AI-generated videos/images/scripts and their publishing records | Generated while you use the Service |
| Usage and log data | Operation logs, access IP, device and browser type, error logs | Collected automatically while you use the Service, for security auditing and troubleshooting |
We do not collect data unrelated to the Service: we do not collect sensitive personal information such as buyers' government ID numbers or bank card numbers, and we only access the data fields returned by the TikTok Shop platform to the extent necessary and authorized for functions such as order analysis.
2. Browser Extension (ReelFlock for Chrome)
ReelFlock offers an optional Chrome extension. It runs inside the browser profile where you install it and publishes videos to the TikTok account already signed in to that profile. This section describes the extension's data handling specifically.
What the extension stores on your device
Two items, both held in the browser's local extension storage (chrome.storage.local) and neither transmitted anywhere except as described below: the ReelFlock agent token you paste on the extension's options page, and a randomly generated instance identifier used to attribute task results.
What the extension sends to us
Only the instance identifier, the TikTok handle signed in to that browser profile, and the status of publishing tasks. Requests are authenticated with your agent token and are sent only to your own ReelFlock backend.
What the extension does not do
- It does not read, extract, or transmit your TikTok cookies or session credentials. The extension requests no cookies permission and never accesses them.
- It does not read your browsing history, your other tabs, or page content beyond the TikTok Studio upload form it operates.
- It does not collect data from any site other than the TikTok Studio upload page.
- It does not display advertising, track you across sites, or share any data with third parties.
Removal
Uninstalling the extension deletes everything it stored locally. Revoking the agent token in your ReelFlock account immediately disables its access, whether or not the extension is still installed.
3. Why We Collect This Data (Purposes)
- Providing core functionality: syncing your product, order, and analytics data through the official TikTok Shop API, generating commerce videos and image/text content, and publishing content to TikTok Shop on your behalf (publishing is performed by the optional browser extension described in Section 2, which runs in your own browser).
- Analytics and review: aggregating content performance and sales data to help you optimize your content strategy.
- Account and security: verifying identity, maintaining account security, preventing fraud and abuse, and conducting security audits.
- Service improvement and support: diagnosing faults, improving the product experience, and responding to your support requests.
- Legal compliance: fulfilling obligations required by applicable laws and regulations and by TikTok Shop platform policies.
Each official API authorization scope we request maps one-to-one to the purposes above, and we do not request scopes unrelated to our features; automated access used for publishing is likewise strictly limited to the operations necessary for publishing (data minimization principle). We will not use data for purposes beyond those stated in this Policy.
4. How Data Is Stored and Transmitted
- Storage location: data is stored in our production environment hosted with compliant cloud providers; data for the US market is managed separately in accordance with TikTok Shop US data security requirements.
- Encryption in transit: all data transmission uses TLS 1.2 or above.
- Encryption at rest: protected data (including OAuth access tokens) is stored encrypted with AES-256 or an algorithm of equivalent strength; keys are managed by a dedicated key management service and rotated periodically.
- Cross-border transfers: where personal data must be transferred across borders, we implement safeguards in accordance with applicable law (such as GDPR Standard Contractual Clauses).
5. Data Sharing and Third Parties
We do not sell your personal data. We share necessary data with third parties only in the following circumstances:
- TikTok Shop platform: necessary data interaction with the TikTok Shop platform to complete functions such as product and data syncing (through the official API) and content publishing.
- Infrastructure service providers: providers of cloud computing, content delivery, AI model inference, etc., limited to the data necessary to perform the Service and bound by data processing agreements (DPAs).
- Legal requirements: lawful requests from competent authorities.
We conduct data security assessments of all subcontractors and vendors and require them to meet protection standards no lower than those in this Policy.
6. How Long We Keep Data (Retention and Deletion)
| Data category | Retention period |
|---|---|
| Account information | For the duration of the account; deleted or anonymized within 30 days after account closure |
| TikTok Shop OAuth access tokens | For the duration of the authorization; deleted within 72 hours after you revoke the authorization or disconnect the app |
| Shop operational data | For the duration of the authorization; deleted within 30 days after revocation or disconnection, except where otherwise required by law |
| Content and creative data | For the duration of the account; deleted within 30 days after account closure |
| Security and audit logs | Up to 12 months from creation |
When you revoke this app's authorization in TikTok Shop Seller Center, disconnect the shop within the Service, or close your account, we will delete the relevant data within the periods above and retain deletion records for audit purposes.
7. How We Protect Data (Security Measures)
- Role-based access control (RBAC) following least-privilege and need-to-know principles; access to protected data is logged, and access rights are reviewed at least annually;
- Multi-factor authentication (MFA) enforced for administrator accounts;
- Segregation of production, staging, and office networks, with intrusion detection and endpoint protection deployed;
- Regular vulnerability scanning and penetration testing, with a remediation SLA and tracking mechanism;
- A data security incident response process; in the event of a security incident that may affect your data, we will notify you and relevant regulators promptly as required by law, and inform the TikTok Shop platform accordingly.
8. Your Data Rights
Under applicable law (including the GDPR, CPRA, and China's Personal Information Protection Law), you have the right to:
- Access and obtain a copy: query and access the personal data we hold about you and obtain a copy (portability);
- Rectification: correct inaccurate or incomplete data;
- Deletion: request deletion of your personal data;
- Restriction and objection: restrict or object to our processing of your data in legally prescribed circumstances;
- Withdraw consent: revoke the API authorization in TikTok Shop Seller Center at any time, or disconnect the shop within the Service;
- Complaint: lodge a complaint with the data protection authority in your jurisdiction.
You can submit the above requests via the contact details at the bottom of this page. We will respond within 15 business days after verifying your identity (or a shorter period where required by law).
9. Minors
The Service is intended for businesses and adult creators, and is not directed to minors under 18. If we discover that we have inadvertently collected a minor's personal data, we will delete it immediately.
10. Cookies and Similar Technologies
We use only the cookies / local storage necessary to maintain login state and ensure security. We do not use third-party advertising tracking cookies. You can manage cookies through your browser settings, though this may affect some functionality.
11. Updates to This Policy
We may update this Policy from time to time. We will provide advance notice of material changes via in-app notification or email, and the updated Policy takes effect on the stated effective date. Continued use of the Service constitutes acceptance of the updated Policy.
12. Contact Us
Contact details for our Privacy Owner / DPO:
- Email: [email protected]
- Operating entity: Infinite Flow Labs
We will process and respond to your message as soon as possible.