跳到主要内容Skip to main content
T土拨鼠(厦门)网络有限公司Tuboshu (Xiamen) Network Co., Ltd.TBS GMVmax 由本公司开发和运营TBS GMVmax is owned and operated by the company
产品Product安全Security隐私Privacy数据删除Data deletion审核指南Reviewer guide
控制台Console
PRIVACY

隐私政策Privacy Policy

本政策说明土拨鼠 GMVmax 如何处理客户主动授权的广告数据和账户信息。This policy explains how TBS GMVmax processes advertising data and account information that customers explicitly authorize.

生效日期:2026-07-19Effective date: 2026-07-19
适用范围Scope处理的数据Data processed处理目的Purposes保留与删除Retention用户权利Your rights联系我们Contact

适用范围

本产品由土拨鼠(厦门)网络有限公司开发和运营。本政策适用于 gmv.tbsapi.com 的公开网站、控制台、土拨鼠 GMVmax 紫鸟浏览器插件,以及经客户授权后提供的官方 API 集成。TikTok 官方 API 应用已经通过平台审核,但每个广告账户仍必须由有权用户在 TikTok 官方页面明确完成 OAuth 授权。

重要说明

我们不会要求、读取或保存您的 TikTok 登录密码。官方接入使用 TikTok 提供的 OAuth 授权页面。

我们处理的数据

账户与授权信息

管理员账户名、经过哈希处理的本产品密码、客户主动授权的广告账户标识、授权范围、访问令牌状态及令牌有效期。OAuth 令牌在服务端加密存储。

广告运营数据

广告账户、店铺、GMV Max 计划、预算、目标 ROI、消耗、收入、订单、商品和素材表现,以及同步时间和平台返回状态。

操作与安全日志

规则条件、预演结果、人工确认、执行前后值、错误信息、登录和授权安全事件。我们不使用这些数据构建面向第三方的广告画像。

处理目的

  • 展示客户授权账户的广告表现和多店铺汇总。
  • 计算客户创建的规则,并在执行前提供可检查的预演结果。
  • 在客户明确确认且安全开关允许时执行已批准的广告动作。
  • 维护审计记录、诊断故障、防止滥用并响应支持请求。
  • 履行法律、安全和平台政策要求。

我们不会出售客户数据,不会将广告数据用于其他客户,也不会在未经授权时访问广告账户。

数据共享与跨境处理

我们仅向提供托管、数据库、安全和故障排查所必需的服务商披露最少数据,并要求其按合同保护数据。服务器位于新加坡。客户使用本产品即表示了解数据可能在其所在国家或地区之外处理。我们会依据适用法律采取合理保护措施。

TikTok 数据的使用同时受 TikTok 平台条款和客户与 TikTok 之间协议的约束。

保留与删除

授权令牌保留至用户断开授权、令牌失效或平台撤销。运营数据在账户有效期间保留,用于规则、报表和审计;用户申请删除后,活动数据目标在 30 天内删除,安全备份目标在 90 天内轮换清除,但法律要求或安全调查需要保留的记录除外。

详细步骤见 数据删除说明。

您的权利

在适用法律允许的范围内,您可以请求访问、更正、导出或删除数据,也可以随时断开 OAuth 授权。撤销授权不会影响撤销前已经合法完成的处理。

联系我们

隐私、访问或删除请求:min360058129@tbsapi.com数据控制方:土拨鼠(厦门)网络有限公司网站:https://gmv.tbsapi.com

请不要通过电子邮件发送密码、访问令牌或完整身份证件。

Scope

TBS GMVmax is developed and operated by Tuboshu (Xiamen) Network Co., Ltd., registered in China as 土拨鼠(厦门)网络有限公司. This policy applies to the public website, console, TBS GMVmax browser extension, and official API integration provided after customer authorization. The TikTok official API app has passed platform review, but every advertiser account still requires explicit OAuth consent by an authorized user on TikTok's official page.

Important

We do not request, read or store your TikTok password. Official access uses TikTok's OAuth authorization page.

Data we process

Account and authorization data

Administrator username, hashed product password, authorized advertiser identifiers, granted scopes, token status and expiration. OAuth tokens are encrypted on the server.

Advertising operations data

Advertisers, shops, GMV Max campaigns, budgets, target ROI, spend, revenue, orders, product and creative performance, sync timestamps and platform response status.

Operations and security logs

Rule conditions, previews, human confirmations, before and after values, errors, login events and authorization events. We do not use this data to build advertising profiles for third parties.

Purposes

  • Display performance for customer-authorized advertiser accounts and shops.
  • Evaluate customer-created rules and present a reviewable preview before execution.
  • Execute approved advertising actions only after explicit confirmation and safety checks.
  • Maintain audit records, diagnose failures, prevent abuse and respond to support requests.
  • Meet legal, security and platform policy obligations.

We do not sell customer data, use one customer's data for another customer, or access an advertiser without authorization.

Sharing and international processing

We disclose only the minimum data needed to hosting, database, security and support providers under contractual safeguards. Our server is located in Singapore. Data may therefore be processed outside the customer's country or region, subject to applicable legal safeguards.

Use of TikTok data is also governed by TikTok platform terms and the customer's agreements with TikTok.

Retention and deletion

Authorization tokens remain until the user disconnects, the token expires or the platform revokes it. Operational data remains while the account is active for rules, reporting and audit. After a valid deletion request, our target is to remove active data within 30 days and cycle it out of security backups within 90 days, except where law or a security investigation requires retention.

See the Data Deletion Instructions.

Your rights

Subject to applicable law, you may request access, correction, export or deletion, and you may disconnect OAuth at any time. Revocation does not affect processing lawfully completed before revocation.

Contact

Privacy, access and deletion requests:min360058129@tbsapi.comData controller: 土拨鼠(厦门)网络有限公司Website: https://gmv.tbsapi.com

Do not send passwords, access tokens or full identity documents by email.

© 2026 土拨鼠(厦门)网络有限公司Company | Terms | Support | Reviewer guide