Personal Data Protection Policy
This document defines how ICE SQUAD MEDIA LLC handles personal data, including data obtained through the TikTok Shop Open API. The Information Security Policy describes how systems are protected; this document covers how the data itself is handled.
1. Scope
This policy applies to all systems and to everyone with access to personal data on behalf of the company, contractors included.
2. Responsible person
The product owner of ICE SQUAD MEDIA LLC is the designated data protection contact. Contact: privacy@tikshopro.com. The role covers enforcing this policy, handling data subject requests, maintaining the record of processing activities and acting as the point of contact on privacy matters.
3. Processing principles
- Lawfulness. Shop data may be processed only while the seller authorisation is in force.
- Minimisation. Only the permissions the advertised features cannot work without are requested.
- Purpose limitation. Data is used only for the features the seller themselves uses.
- Storage limitation. Data is deleted when it is no longer needed, not whenever somebody gets round to it.
- Accuracy. Correction is available on request.
- Security. The safeguards are described in the Information Security Policy.
4. Categories of data
| Service users | Email address, account and subscription data |
| TikTok Shop API data | Shop id and name, product data and data on the creators linked to them — within the permissions granted by the seller |
| Payment data | Processed by Stripe. Not stored in our systems |
| Technical | IP address and security event logs — 90 days |
5. Legal bases
Performance of the contract with the service user, and the explicit seller authorisation granted through TikTok Shop OAuth. The latter can be withdrawn in one click in TikTok Shop settings, and the basis ends the moment it is.
6. Disclosure to third parties
Personal data is not sold and is not shared with third parties for their own purposes. Only the vendors in the subprocessor list are used, each under a contract with data protection obligations. Data is not used to train models.
7. Cross-border transfers
All data is stored and processed within the United States. The primary database region is Eastern North America; backups stay in the same region.
8. Retention periods
| Access tokens | Until authorisation is revoked |
| Operational data | Subscription term plus 30 days |
| Access logs | 90 days |
| Financial records | As required by law |
9. Data subject rights
Access, correction, deletion, export and objection to processing.
- Intake: the form on this site or privacy@tikshopro.com.
- Acknowledgement — within 5 business days. Sent automatically, not whenever somebody gets round to it.
- Identity verification — mandatory. Otherwise a request for data becomes a way to obtain somebody else’s.
- Fulfilment — within 30 calendar days.
- Requests received through a seller or through TikTok Shop are handled in the same way and to the same deadlines.
- Every request is logged with its due date — which rules out the “read the email and forgot” case.
10. Deletion
When a seller revokes authorisation, access tokens are destroyed immediately and the related data within 30 days. Data leaves backups as those rotate: instant deletion from backups is not technically possible, and we will not promise it. Each deletion is recorded in a log with the date and the shop id — that record is the evidence of fulfilment at audit.
11. Breach notification
The procedure is set out in the Incident Response Policy. TikTok Shop and affected sellers are notified within 72 hours of an incident being confirmed.
12. Awareness
Everyone with access to personal data has read this policy. Only the responsible person has access to seller data.
13. Review
At least once a year, and whenever the categories of data processed, the set of subprocessors or the applicable requirements change.