Data & security
Your shop's data, for your shop only.
We collect data only through official TikTok Shop APIs and show it only to the connected shop's users.
How data flows
What we read, where we keep it, and what we write. Writes happen only after your staff approve them.
Read
TikTok official API
- Orders, products, stock
- Streams and sales over time
- Ad spend and results
Store
COMSEE (Tokyo region)
- Kept separate per organization
- Encrypted at rest
- No buyer personal data stored
Write after approval
Your shop
- Listings and prices
- Stock
- Sale registration
Four principles
- 01
Read only through TikTok's official API
We collect data through the official TikTok Shop and TikTok Ads APIs. No scraping, and we never hold your password.
- 02
Changes only after approval
Changes to your shop, such as listings, prices and stock, run only after your staff review and approve them, and every change is logged.
- 03
Separated by organization
Data from a connected shop is shown only to users of that organization, and stored so that other organizations cannot read it.
- 04
Never passed to third parties
We do not share data obtained through the API with third parties, and never show it on public pages.
Permissions and approval
Each member's permission decides what they can do. Changes to your shop are applied only after approval.
- Owner
- Organization settings, shop connections, inviting members and changing permissions.
- Operator
- Day-to-day work on deals, scripts, streams and sales.
- Viewer
- View only. Cannot make changes.
How a change reaches your shop
- Draft the change
- Staff review
- Approve
- Apply to shop
- Log
Managed per device
See signed-in devices in a list and revoke each one.
Sign-in attempt limits
Password attempts and emails sent are capped.
Storage
- Tokyo region
- Stored in the Amazon Web Services Tokyo region.
- Encrypted in transit and at rest
- Connections are encrypted and the database is encrypted at rest. Shop connection credentials are encrypted again individually.
- What we store
- Summaries and details of orders, products, streams and ads. Only what the work needs.
- What we don't store
- Buyers' names, addresses or other personal data. Buyer IDs are pseudonymized.
Following TikTok's terms
In line with TikTok's developer terms, data obtained through the API is used only to run the connected shop.
- 01
Limited use
Data is used only to support operating the connected shop.
- 02
Kept inside
No sharing with or selling to third parties, and never shown on public pages or to other organizations.
- 03
Permitted routes only
No scraping, and no collecting data from other services without permission.
Questions about data handling
If anything is unclear, contact us. Our company-wide information security policy is published on our corporate site.


