适用范围
本产品由土拨鼠(厦门)网络有限公司开发和运营。本政策适用于 gmv.tbsapi.com 的公开网站、控制台、土拨鼠 GMVmax 紫鸟浏览器插件,以及经客户授权后提供的官方 API 集成。TikTok 官方 API 应用已经通过平台审核,但每个广告账户仍必须由有权用户在 TikTok 官方页面明确完成 OAuth 授权。
我们不会要求、读取或保存您的 TikTok 登录密码。官方接入使用 TikTok 提供的 OAuth 授权页面。
我们处理的数据
账户与授权信息
管理员账户名、经过哈希处理的本产品密码、客户主动授权的广告账户标识、授权范围、访问令牌状态及令牌有效期。OAuth 令牌在服务端加密存储。
广告运营数据
广告账户、店铺、GMV Max 计划、预算、目标 ROI、消耗、收入、订单、商品和素材表现,以及同步时间和平台返回状态。
操作与安全日志
规则条件、预演结果、人工确认、执行前后值、错误信息、登录和授权安全事件。我们不使用这些数据构建面向第三方的广告画像。
处理目的
- 展示客户授权账户的广告表现和多店铺汇总。
- 计算客户创建的规则,并在执行前提供可检查的预演结果。
- 在客户明确确认且安全开关允许时执行已批准的广告动作。
- 维护审计记录、诊断故障、防止滥用并响应支持请求。
- 履行法律、安全和平台政策要求。
我们不会出售客户数据,不会将广告数据用于其他客户,也不会在未经授权时访问广告账户。
保留与删除
授权令牌保留至用户断开授权、令牌失效或平台撤销。运营数据在账户有效期间保留,用于规则、报表和审计;用户申请删除后,活动数据目标在 30 天内删除,安全备份目标在 90 天内轮换清除,但法律要求或安全调查需要保留的记录除外。
详细步骤见 数据删除说明。
您的权利
在适用法律允许的范围内,您可以请求访问、更正、导出或删除数据,也可以随时断开 OAuth 授权。撤销授权不会影响撤销前已经合法完成的处理。
联系我们
请不要通过电子邮件发送密码、访问令牌或完整身份证件。
Scope
TBS GMVmax is developed and operated by Tuboshu (Xiamen) Network Co., Ltd., registered in China as 土拨鼠(厦门)网络有限公司. This policy applies to the public website, console, TBS GMVmax browser extension, and official API integration provided after customer authorization. The TikTok official API app has passed platform review, but every advertiser account still requires explicit OAuth consent by an authorized user on TikTok's official page.
We do not request, read or store your TikTok password. Official access uses TikTok's OAuth authorization page.
Data we process
Account and authorization data
Administrator username, hashed product password, authorized advertiser identifiers, granted scopes, token status and expiration. OAuth tokens are encrypted on the server.
Advertising operations data
Advertisers, shops, GMV Max campaigns, budgets, target ROI, spend, revenue, orders, product and creative performance, sync timestamps and platform response status.
Operations and security logs
Rule conditions, previews, human confirmations, before and after values, errors, login events and authorization events. We do not use this data to build advertising profiles for third parties.
Purposes
- Display performance for customer-authorized advertiser accounts and shops.
- Evaluate customer-created rules and present a reviewable preview before execution.
- Execute approved advertising actions only after explicit confirmation and safety checks.
- Maintain audit records, diagnose failures, prevent abuse and respond to support requests.
- Meet legal, security and platform policy obligations.
We do not sell customer data, use one customer's data for another customer, or access an advertiser without authorization.
Sharing and international processing
We disclose only the minimum data needed to hosting, database, security and support providers under contractual safeguards. Our server is located in Singapore. Data may therefore be processed outside the customer's country or region, subject to applicable legal safeguards.
Use of TikTok data is also governed by TikTok platform terms and the customer's agreements with TikTok.
Retention and deletion
Authorization tokens remain until the user disconnects, the token expires or the platform revokes it. Operational data remains while the account is active for rules, reporting and audit. After a valid deletion request, our target is to remove active data within 30 days and cycle it out of security backups within 90 days, except where law or a security investigation requires retention.
See the Data Deletion Instructions.
Your rights
Subject to applicable law, you may request access, correction, export or deletion, and you may disconnect OAuth at any time. Revocation does not affect processing lawfully completed before revocation.
Contact
Do not send passwords, access tokens or full identity documents by email.