Compliance

AliTok Privacy and Compliance Overview

This page summarizes how AliTok handles personal data, responds to partner requests, and manages vendor relationships relevant to marketplace integrations.

Last updated: July 10, 2026

Data handling principles

  • AliTok processes data only for seller-authorized workflows and platform operations.
  • Access to tenant data is limited to authenticated users with the required workspace permissions.
  • AliTok assists with data access, update, and deletion requests submitted through the support channel.
  • At the end of a customer relationship, AliTok will delete or anonymize stored data within a reasonable period unless retention is legally required.

Data classification

AliTok classifies information according to operational sensitivity so the appropriate protections can be applied.

  • Public: marketing pages and material intended for open publication.
  • Internal: routine operational content that is not intended for public release.
  • Confidential: account data, support records, and business information requiring restricted access.
  • Restricted: seller-authorized marketplace data, credentials, secrets, and other sensitive integration data requiring the strongest controls.

Subprocessors and service providers

ProviderPurpose
VercelApplication hosting, deployment, and edge delivery
SupabaseAuthentication, database hosting, and managed storage services
Email provider configured by AliTokSupport and operational email notifications when enabled

Request handling

AliTok accepts the following request types through the public contact channel and reviews them manually:

  • Access or correction request
  • Deletion request
  • Seller data update assistance
  • Security or privacy complaint

Requests are validated before action is taken, and AliTok will coordinate with connected platforms where a request involves synchronized marketplace data.

Connected-platform disconnection

For TikTok Shop, manual disconnect or seller deauthorization immediately disables access and removes stored access and refresh credentials. AliTok then queues an idempotent purge of TikTok-sourced operational data from its primary application database under an internal 24-hour target. Reconnection is blocked while that purge is queued or processing, and only a minimal non-source receipt or a legally required segregated record should remain after local completion.

The local deletion receipt does not by itself prove erasure from TikTok, LDR, an email recipient or provider, infrastructure logs, observability systems, database backups, or another subprocessor. Those locations follow the relevant provider retention and deletion process, and records retained for legal or security obligations are segregated from ordinary product workflows.

Current posture

  • AliTok publishes a privacy policy, terms of service, and information security program.
  • TikTok Shop production functionality is staged for a controlled single-shop US pilot; Financials and after-sales are partial previews rather than complete source coverage.
  • AliTok does not currently claim ISO 27001, ISO 27701, SOC 2 Type II, or similar certifications.
  • AliTok does not currently list a formal Data Protection Officer role. Privacy and security requests are handled through the support channel.
  • Material security and privacy commitments are documented publicly and supported by internal operating procedures.

Related resources