Socify

Privacy policy

Last updated: 18 September 2026

This document contains placeholders. Every highlighted field must be replaced with the operating company’s real details before Socify is submitted for TikTok Shop Partner review or offered to customers. A policy that names no controller is not a valid policy.

1. Controller

The controller responsible for processing personal data in connection with the Socify service (“Socify”, “we”) is:

COMPANY LEGAL NAME
STREET, POSTCODE CITY, COUNTRY
Email: PRIVACY@SOCIFY.CC

Data protection officer: DATA PROTECTION OFFICER OR "not appointed"

2. What this policy covers

Socify is a business tool for merchants who sell on TikTok Shop. It covers two distinct groups of people:

  • Users — the employees of a merchant who sign in and use the workspace.
  • Creators — TikTok creators whose public profile and performance data, and whose collaboration history with the connected shop, are shown to that merchant.

This policy also covers visitors to socify.cc and users of the public demo.

3. Categories of data and why we process them

CategoryExamplesPurposeLegal basis (GDPR Art. 6)
Account dataName, work email address, password hash, workspace membership and roleProviding the service, authentication, access controlArt. 6(1)(b) — performance of a contract
Session dataA random session token (stored only as a SHA-256 hash), expiry, login attempt countersKeeping a user signed in, rate limiting sign-in attemptsArt. 6(1)(b) and Art. 6(1)(f) — legitimate interest in account security
Workspace dataCreator lists, pipeline stages, notes, campaigns, sample records, messages sent through the platformThe purpose the customer uses the product forArt. 6(1)(b)
Shop data from TikTokProduct catalogue, orders and affiliate-attributed orders, settlement records for the connected shopPerformance analysis and contribution profit for the merchantArt. 6(1)(b)
Creator data from TikTokPublic handle, profile, follower and engagement metrics, audience demographics in aggregate, public video metrics, collaboration and sample history with the connected shopCreator discovery, scoring, and managing an affiliate relationshipArt. 6(1)(f) — legitimate interest of the merchant in identifying and managing commercial partners
Provider credentialsTikTok Shop app key, app secret, refresh token, shop cipher and other integration secretsCalling the APIs on the customer’s behalfArt. 6(1)(b)
Technical logsRequest metadata and error traces generated by our hosting providerOperating, securing and debugging the serviceArt. 6(1)(f) — legitimate interest in a functioning, secure service

We do not process special categories of personal data (GDPR Art. 9), and we do not use personal data for automated decisions producing legal effects within the meaning of Art. 22. The Socify Score ranks commercial suitability for a merchant’s own outreach decision; a human decides whom to contact.

4. Data obtained through TikTok

When a merchant authorises Socify from TikTok Shop, we access only the scopes granted in that authorisation. Specifically:

  • We use shop, order, affiliate and creator data only to provide the features of the workspace that requested it.
  • We do not sell TikTok data, do not use it for advertising, and do not use it to train machine-learning models.
  • We do not share TikTok data with other customers. Each workspace is isolated, and every database query is scoped to a single workspace.
  • We do not scrape TikTok. All data is retrieved through TikTok’s official APIs under the granted authorisation.
  • When a merchant disconnects the integration or deletes the workspace, data derived from TikTok is deleted as described in section 8.

5. Creators: how your data is used

If you are a TikTok creator, a merchant using Socify may see your public profile data, metrics TikTok makes available to that merchant, and the history of your collaboration with that merchant’s shop — samples requested, content posted under the affiliate programme, and messages exchanged through TikTok’s own messaging surface.

We act as a processor on behalf of the merchant for that collaboration history, and the merchant is the controller for it. You can object to processing or request deletion by contacting PRIVACY@SOCIFY.CC; we will forward the request to the relevant merchant where we act only as processor, and act on it ourselves where we are controller.

6. Recipients and processors

We keep the number of processors deliberately small:

  • Cloudflare, Inc. — hosting, edge delivery and the database (Cloudflare Workers and Cloudflare D1). Cloudflare processes data under a data processing agreement and EU standard contractual clauses.
  • TikTok Shop / TikTok Pte. Ltd. — the source of shop and creator data, and the recipient of messages you send to creators through the product.
  • Any further processors — email provider, error monitoring, payment provider — must be listed here before launch.

We do not use advertising networks, third-party analytics or social media tracking pixels on socify.cc.

7. International transfers

Our hosting provider operates a global network, and data may be processed outside the European Economic Area. Transfers are covered by the European Commission’s standard contractual clauses together with the supplementary measures described in the relevant processor’s documentation. Confirm the storage region configured for your production database and state it here.

8. Retention and deletion

  • Account and workspace data is retained while the workspace exists.
  • Sessions expire automatically and expired sessions are deleted by a scheduled job.
  • Sign-in attempt records are deleted after 24 hours.
  • On deletion of a workspace, its data — including data derived from TikTok and any stored credentials — is deleted from the production database. Encrypted backups are overwritten in the normal backup cycle.
  • Records we must keep for statutory accounting or tax reasons are retained for the statutory period and otherwise blocked from use.

See data deletion for how to make a request.

9. Security

Passwords are stored as salted PBKDF2-SHA256 derivations, never in plain text. Session cookies carry a random token and the database stores only its hash, so a database copy cannot be used to resume a session. Integration credentials are encrypted with AES-GCM using a key held outside the database, and no API response ever returns a credential value — not even to the workspace that stored it. Details are on the security page.

10. Cookies

Socify sets no advertising or analytics cookies. We use:

NamePurposeTypeLifetime
socify_sessionKeeps a signed-in user authenticatedStrictly necessary, HttpOnly, Secure, SameSite=LaxSession, with server-side expiry
socify.prefs.v1 (browser storage, not a cookie)Interface preferences such as theme and saved viewsStrictly necessary for the interfaceUntil cleared by the user
socify.overlay.v1 (browser storage, not a cookie)Stores changes made in the public demo so they survive a reload; never leaves the browserStrictly necessary for the demoUntil cleared by the user

Because we use no non-essential cookies, no consent banner is required for the operation of this site.

11. Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21). Where processing is based on consent you may withdraw it at any time with effect for the future.

Requests go to PRIVACY@SOCIFY.CC. You also have the right to complain to a supervisory authority; name the competent authority for your registered seat.

12. Changes

We publish changes to this policy on this page and update the date above. Material changes affecting customers are additionally communicated to workspace owners.