← Back to Legal

Hallie Platform — Data Security & Privacy Policy

TikTok Account Automation Platform · Powered by TJB Management Inc.
Effective Date: July 1, 2026 · Last Updated: July 1, 2026

Table of Contents

  1. About the Platform
  2. Definitions
  3. Data Collected
  4. Privacy Notice
  5. Data Subject Rights
  6. Data Retention
  7. Data Minimization
  8. Roles & Responsibilities
  9. Operator Obligations
  10. Information Security Policy
  11. Network Security
  12. Endpoint Protection
  13. Security Baselines
  14. Data Protection & Encryption
  15. Access Control Policy
  16. Vulnerability Management
  17. Incident Management
  18. Subprocessors & Infrastructure
  19. US Data Security Compliance
  20. Contact & Requests

1. About the Platform

The Hallie Account Automation Platform ("Platform") is a TikTok account automation and management system developed and operated by TJB Management Inc. ("Platform Provider"), headquartered in the United States.

The Platform connects to TikTok's API on behalf of authorized TikTok accounts to automate account operations including content publishing, comment management, community moderation, mention monitoring, trending discovery, and automated rule execution. It is designed to help brands, creators, and businesses run their TikTok presence with as little manual intervention as possible.

This Policy governs the Platform's data handling practices and applies to all businesses and individuals ("Operators") who use the Platform to manage their TikTok accounts. By using the Platform, Operators agree to this Policy and accept responsibility for ensuring their own use complies with applicable laws and TikTok's terms.

The Platform operates under TikTok's API for Business Developer Terms and is subject to TikTok's Data Security and Privacy Review (DSPR) as a condition of accessing the full scope of TikTok Business API permissions.

2. Definitions

3. Data Collected

The Platform accesses and processes the following data via TikTok's API on behalf of each Operator:

Comment & Community Data

Content Data

Mentions & Discovery Data

Account Data

Automated Rules Data

Direct Message Data (Business Messaging API — Pending DSPR Approval)

Direct message data will only be accessed upon approval of the TikTok Business Messaging API scope following completion of TikTok's Data Security and Privacy Review (DSPR). DM data is processed solely to enable automated responses and message management on behalf of authorized Operators. DM data is subject to the same — or higher — data handling and security requirements as all other data listed above. Until DSPR approval is granted, the Platform does not collect or access direct messages.

The Platform does not collect or process payment information, private account data, advertising campaign data, or any data beyond what is explicitly listed above.

4. Privacy Notice

What data is collected

As described in Section 3, the Platform collects TikTok comment text, usernames, comment IDs, and associated video metadata through TikTok's authorized Business API on behalf of each Operator.

Why it is collected

Data is collected to power automated TikTok account management on behalf of Operators — including publishing content, moderating communities, monitoring brand mentions, discovering trending opportunities, and executing automated account rules. Processing is based on the legitimate interests of Operators in managing and growing their TikTok presence efficiently.

How data is used

Account data is used to perform authorized automation actions: publishing or scheduling content, hiding or pinning comments, replying to comments, managing hashtag mentions, surfacing trending keywords, and executing Operator-defined automation rules. Comment text is analyzed by the Platform's rule-based scoring engine to identify content requiring moderation. No Operator or End User data is sent to third-party AI, analytics, or advertising services. All API calls are back to TikTok on behalf of the Operator.

Where data is transferred

Data travels between TikTok's servers and Platform infrastructure hosted on Vercel Inc. (a SOC 2 Type II certified provider) in the United States. No Operator or End User data is shared with, sold to, or transferred to any third party. The only outbound API calls are back to TikTok to perform actions authorized by the Operator.

How data is protected

All data in transit is encrypted using TLS 1.2 or above. Session tokens are stored as HttpOnly cookies inaccessible to client-side scripts. Each Operator's admin interface is protected by a unique secret key accessible only to authorized personnel within that Operator's organization.

How long data is stored

Comment text, usernames, and other content data fetched from TikTok's API are processed in memory for the duration of the request and are not written to any persistent database operated by the Platform Provider. OAuth access tokens are stored as HttpOnly, Secure browser cookies on the Operator's own device with a 30-day expiration — the Platform Provider does not retain tokens server-side. Operators can immediately revoke all session data at any time by clicking "Disconnect" within the Platform dashboard. See Section 6 for the full data retention policy.

5. Data Subject Rights

The Platform respects the data rights of End Users in accordance with applicable privacy regulations including GDPR and CPRA. Operators are responsible for facilitating these rights for their End Users. The following rights apply to personal data processed by the Platform:

In-platform deletion: Operators can immediately delete all session data — including their OAuth token — by clicking the "Disconnect" button within the Platform dashboard. This takes effect instantly and requires no email request.

To exercise any other rights, or to submit a request on behalf of End Users, contact the Platform Provider at support@tjbmanagementinc.com. We will respond within 30 days. Identity verification may be required before fulfilling a request.

6. Data Retention

Personal data is retained only as long as necessary to fulfill the purpose for which it was collected:

When an Operator clicks "Disconnect" within the Platform dashboard, their OAuth token cookie is immediately expired — no further API access is possible and no session data remains. In-memory data (event logs, seen IDs) associated with that session is also cleared. Operators may alternatively revoke authorization directly in TikTok's app under Settings → Apps and Websites.

End Users who wish to request deletion of any data held about them may contact support@tjbmanagementinc.com. We will respond within 30 days.

7. Data Minimization

The Platform requests only the minimum API scopes necessary to perform authorized account automation functions. Specifically:

Upon approval of the Business Messaging API scope, the Platform will additionally request only the minimum DM-related permissions required to read incoming messages and send automated responses — no other messaging scopes will be requested. No scopes beyond those necessary for each authorized function are requested at any stage. API fields are limited to those actively used by the Platform — no unused fields are fetched.

8. Roles & Responsibilities

The following role structure governs data responsibilities under this Policy:

Operators must designate a Data Protection Officer (DPO) or equivalent privacy contact within their own organization where required by applicable law (e.g., GDPR Article 37).

9. Operator Obligations

By using the Hallie Platform, Operators agree to the following obligations:

10. Information Security Policy

The Platform Provider maintains a comprehensive information security framework governing all aspects of the Hallie Platform. This framework is reviewed and updated at least annually.

Core security principles applied to the Platform:

11. Network Security

The Platform is hosted on Vercel Inc.'s serverless infrastructure, which provides the following network-level protections:

Vercel maintains a SOC 2 Type II certification. Their security documentation is available at vercel.com/security.

12. Endpoint Protection

All Platform administration is performed exclusively on Apple iOS devices (iPhone and iPad). The following protections are enforced by the iOS platform:

Operators are expected to maintain appropriate endpoint protections on any device used to access their Hallie Platform dashboard.

Software development and infrastructure changes are carried out with the assistance of an AI coding tool operating in an isolated, ephemeral cloud execution environment. This environment holds no independent or standing access to any Operator's TikTok account, does not persist credentials or Operator data beyond a single development session, and every action it takes is directed and authorized in real time by the Platform Provider's sole authorized officer from their Apple iOS device.

13. Security Baselines

The following baseline security measures are enforced for all access to the Platform and associated infrastructure:

14. Data Protection & Encryption

15. Access Control Policy

Access to the Platform is governed by a strict need-to-know, least-privilege model:

16. Vulnerability Management

The Platform Provider maintains the following vulnerability management practices:

17. Incident Management

The Platform Provider maintains an incident response policy. In the event of a security incident or data breach involving Operator or End User data:

Detection & Containment

Assessment & Notification

Recovery & Review

To report a security incident or suspected breach, contact support@tjbmanagementinc.com immediately.

18. Subprocessors & Infrastructure

The Platform relies on the following third-party subprocessors. All subprocessors are subject to appropriate data protection agreements:

The Platform Provider does not use any other subprocessors that process Operator or End User data. This list is reviewed and updated whenever a new subprocessor is engaged. Operators will be notified of material changes to subprocessors.

Platform Provider Headquarters: United States
Primary Workforce Location: United States
System Location: United States (Vercel US regions)
Ownership: Sole owner Tyler J. Beasley — US citizen and resident, sole shareholder and sole authorized officer of TJB Management Inc.

19. US Data Security Compliance

The Hallie Platform is developed and operated in compliance with TikTok's US Data Security (USDS) requirements. The following attestations map TJB Management Inc.'s specific practices to each USDS requirement area.

Ownership & Corporate Structure

Data Handling & Privacy

Security Controls

Subprocessors

Supporting documentation, including dependency vulnerability monitoring history, is available upon request at support@tjbmanagementinc.com.

20. Contact & Requests

For any questions, data subject requests, privacy inquiries, security reports, or compliance documentation requests related to the Hallie Platform, please contact:

TJB Management Inc.
Platform Provider · United States

We will respond to all privacy and security inquiries within 30 days. Critical security incidents will receive an acknowledgment within 48 hours.