Hallie Platform — Data Security & Privacy Policy
TikTok Account Automation Platform · Powered by TJB Management Inc.
Effective Date: July 1, 2026 · Last Updated: July 1, 2026
Table of Contents
- About the Platform
- Definitions
- Data Collected
- Privacy Notice
- Data Subject Rights
- Data Retention
- Data Minimization
- Roles & Responsibilities
- Operator Obligations
- Information Security Policy
- Network Security
- Endpoint Protection
- Security Baselines
- Data Protection & Encryption
- Access Control Policy
- Vulnerability Management
- Incident Management
- Subprocessors & Infrastructure
- US Data Security Compliance
- Contact & Requests
1. About the Platform
The Hallie Account Automation Platform ("Platform") is a TikTok account automation and management system developed and operated by TJB Management Inc. ("Platform Provider"), headquartered in the United States.
The Platform connects to TikTok's API on behalf of authorized TikTok accounts to automate account operations including content publishing, comment management, community moderation, mention monitoring, trending discovery, and automated rule execution. It is designed to help brands, creators, and businesses run their TikTok presence with as little manual intervention as possible.
This Policy governs the Platform's data handling practices and applies to all businesses and individuals ("Operators") who use the Platform to manage their TikTok accounts. By using the Platform, Operators agree to this Policy and accept responsibility for ensuring their own use complies with applicable laws and TikTok's terms.
The Platform operates under TikTok's API for Business Developer Terms and is subject to TikTok's Data Security and Privacy Review (DSPR) as a condition of accessing the full scope of TikTok Business API permissions.
2. Definitions
- Platform Provider — TJB Management Inc., the company that develops, operates, and maintains the Hallie Platform.
- Operator — Any business, brand, creator, or individual who uses the Hallie Platform to manage their TikTok account(s).
- End User — TikTok users who post comments on an Operator's TikTok content. End Users do not interact with the Platform directly.
- Platform — The Hallie Account Automation Platform, including all associated software, APIs, and infrastructure.
- Connected Account — An Operator's authorized TikTok account connected to the Platform via TikTok's API.
3. Data Collected
The Platform accesses and processes the following data via TikTok's API on behalf of each Operator:
Comment & Community Data
- Comment text — the content of comments posted to an Operator's TikTok videos
- Comment ID — TikTok's internal identifier for each comment
- Username — the TikTok username of the commenter
- Timestamp — the date and time the comment was posted
- Like count — the number of likes a comment has received
- Comment status — whether a comment is visible or hidden
Content Data
- Video ID, title, and creation date — displayed in each Operator's dashboard to identify their content
- View, like, comment, and share counts — displayed for performance visibility
Mentions & Discovery Data
- Hashtag and keyword mentions — monitored to track brand presence and community activity
- Trending search terms and hashtags — used for content strategy and discovery
- Mention video metadata — titles and engagement counts of videos mentioning an Operator's account or hashtags
Account Data
- Display name and avatar — fetched to identify the connected account in the Operator's dashboard
- Follower, like, and video counts — used for display and performance benchmarking
Automated Rules Data
- Rule definitions and configurations — the automation rules Operators create and manage within the Platform
- Rule execution results — the outcome of automated actions triggered by Operator-defined rules
Direct Message Data (Business Messaging API — Pending DSPR Approval)
- Message content — text of direct messages sent to or received from TikTok users on behalf of an Operator
- Sender and recipient identifiers — TikTok user IDs and usernames involved in each message thread
- Message timestamps — date and time each message was sent or received
- Message and delivery status — read, unread, and delivery state of each message
- Conversation thread IDs — TikTok's internal identifiers for message threads
Direct message data will only be accessed upon approval of the TikTok Business Messaging API scope following completion of TikTok's Data Security and Privacy Review (DSPR). DM data is processed solely to enable automated responses and message management on behalf of authorized Operators. DM data is subject to the same — or higher — data handling and security requirements as all other data listed above. Until DSPR approval is granted, the Platform does not collect or access direct messages.
The Platform does not collect or process payment information, private account data, advertising campaign data, or any data beyond what is explicitly listed above.
4. Privacy Notice
What data is collected
As described in Section 3, the Platform collects TikTok comment text, usernames, comment IDs, and associated video metadata through TikTok's authorized Business API on behalf of each Operator.
Why it is collected
Data is collected to power automated TikTok account management on behalf of Operators — including publishing content, moderating communities, monitoring brand mentions, discovering trending opportunities, and executing automated account rules. Processing is based on the legitimate interests of Operators in managing and growing their TikTok presence efficiently.
How data is used
Account data is used to perform authorized automation actions: publishing or scheduling content, hiding or pinning comments, replying to comments, managing hashtag mentions, surfacing trending keywords, and executing Operator-defined automation rules. Comment text is analyzed by the Platform's rule-based scoring engine to identify content requiring moderation. No Operator or End User data is sent to third-party AI, analytics, or advertising services. All API calls are back to TikTok on behalf of the Operator.
Where data is transferred
Data travels between TikTok's servers and Platform infrastructure hosted on Vercel Inc. (a SOC 2 Type II certified provider) in the United States. No Operator or End User data is shared with, sold to, or transferred to any third party. The only outbound API calls are back to TikTok to perform actions authorized by the Operator.
How data is protected
All data in transit is encrypted using TLS 1.2 or above. Session tokens are stored as HttpOnly cookies inaccessible to client-side scripts. Each Operator's admin interface is protected by a unique secret key accessible only to authorized personnel within that Operator's organization.
How long data is stored
Comment text, usernames, and other content data fetched from TikTok's API are processed in memory for the duration of the request and are not written to any persistent database operated by the Platform Provider. OAuth access tokens are stored as HttpOnly, Secure browser cookies on the Operator's own device with a 30-day expiration — the Platform Provider does not retain tokens server-side. Operators can immediately revoke all session data at any time by clicking "Disconnect" within the Platform dashboard. See Section 6 for the full data retention policy.
5. Data Subject Rights
The Platform respects the data rights of End Users in accordance with applicable privacy regulations including GDPR and CPRA. Operators are responsible for facilitating these rights for their End Users. The following rights apply to personal data processed by the Platform:
- Right to Access — End Users may request a copy of any personal data processed on their behalf.
- Right to Correction — End Users may request that inaccurate personal data be corrected.
- Right to Deletion — End Users may request deletion of their personal data. Because the Platform does not maintain a persistent database of comment data, most data is cleared automatically on server restart. Upon request, any retained identifiers will be removed.
- Right to Restriction — End Users may request that processing of their data be restricted while a complaint is under review.
- Right to Object — End Users may object to processing of their personal data where processing is based on legitimate interests.
- Right to Data Portability — End Users may request a structured, machine-readable export of their data.
In-platform deletion: Operators can immediately delete all session data — including their OAuth token — by clicking the "Disconnect" button within the Platform dashboard. This takes effect instantly and requires no email request.
To exercise any other rights, or to submit a request on behalf of End Users, contact the Platform Provider at support@tjbmanagementinc.com. We will respond within 30 days. Identity verification may be required before fulfilling a request.
6. Data Retention
Personal data is retained only as long as necessary to fulfill the purpose for which it was collected:
- Comment text and usernames — processed transiently in memory. Not written to persistent storage. Cleared on server restart.
- Automation event log — recent automation events retained in memory per Operator session. Rolling — oldest events are overwritten as new events are added. Cleared on server restart.
- Seen content IDs — stored in memory to prevent reprocessing. Cleared on server restart.
- OAuth tokens — stored as HttpOnly cookies on the Operator's authorized device only. Expire after 30 days. Not persisted beyond the active session.
When an Operator clicks "Disconnect" within the Platform dashboard, their OAuth token cookie is immediately expired — no further API access is possible and no session data remains. In-memory data (event logs, seen IDs) associated with that session is also cleared. Operators may alternatively revoke authorization directly in TikTok's app under Settings → Apps and Websites.
End Users who wish to request deletion of any data held about them may contact support@tjbmanagementinc.com. We will respond within 30 days.
7. Data Minimization
The Platform requests only the minimum API scopes necessary to perform authorized account automation functions. Specifically:
- The Platform requests comment.list and comment.list.manage scopes to read and manage comments on behalf of Operators
- The Platform requests video.list to display an Operator's videos in their dashboard
- The Platform requests discovery.search.words to surface trending content
- The Platform requests user.info.basic, user.info.username, user.info.stats, user.info.profile, and user.account.type to display the connected account's identity and stats in each Operator's dashboard
Upon approval of the Business Messaging API scope, the Platform will additionally request only the minimum DM-related permissions required to read incoming messages and send automated responses — no other messaging scopes will be requested. No scopes beyond those necessary for each authorized function are requested at any stage. API fields are limited to those actively used by the Platform — no unused fields are fetched.
8. Roles & Responsibilities
The following role structure governs data responsibilities under this Policy:
- Platform Provider (TJB Management Inc.) — Acts as a data processor on behalf of Operators. Responsible for the security and integrity of the Platform infrastructure, and for processing data only as directed by Operators and as permitted under this Policy.
- Operator — Acts as the data controller for their connected TikTok account and the End Users who interact with their content. Operators are responsible for their own privacy notices, lawful basis for processing, and compliance with applicable local laws.
- Data Protection Officer (Platform Provider) — Tyler J. Beasley, sole authorized officer of TJB Management Inc., serves as the Platform Provider's designated Data Protection Officer and Privacy & Security Contact. All privacy inquiries, data subject requests, security incidents, and compliance documentation requests should be directed to support@tjbmanagementinc.com.
Operators must designate a Data Protection Officer (DPO) or equivalent privacy contact within their own organization where required by applicable law (e.g., GDPR Article 37).
9. Operator Obligations
By using the Hallie Platform, Operators agree to the following obligations:
- Lawful basis — Operators must have a valid lawful basis under applicable privacy law for processing End User data through the Platform.
- Privacy notice — Operators must maintain a publicly accessible privacy notice that discloses their use of automated account management tools and the processing of End User data.
- Credential security — Operators are responsible for securing their TikTok account credentials. The Platform does not issue separate credentials — Operators authenticate directly with TikTok via Login Kit.
- Authorized use only — Operators may only use the Platform to manage their own TikTok account(s) that they are authorized to manage.
- Compliance with TikTok terms — Operators must comply with all applicable TikTok API for Business Developer Terms and Community Guidelines.
- Data subject requests — Operators must be able to assist End Users in exercising their data rights and must direct such requests to the Platform Provider where necessary.
- No resale — Operators may not resell, sublicense, or otherwise provide Platform access to third parties without written authorization from the Platform Provider.
10. Information Security Policy
The Platform Provider maintains a comprehensive information security framework governing all aspects of the Hallie Platform. This framework is reviewed and updated at least annually.
Core security principles applied to the Platform:
- Least Privilege — Platform access is restricted to the minimum required to perform authorized functions at both the infrastructure and application level.
- Defense in Depth — Multiple layers of security controls are applied at the application, infrastructure, and operational levels.
- Data Minimization — Only the data necessary for moderation is accessed or retained. No data is processed beyond what Operators authorize.
- Secure by Default — All new features and configurations default to the most restrictive setting and require explicit enablement.
- Continuous Improvement — Security controls are reviewed following any incident, significant change, or annually at minimum.
11. Network Security
The Platform is hosted on Vercel Inc.'s serverless infrastructure, which provides the following network-level protections:
- All traffic is routed through Vercel's edge network with DDoS protection and traffic filtering
- All endpoints are served exclusively over HTTPS with TLS 1.2 or above — HTTP is not permitted
- Serverless function environments are fully isolated — there is no persistent shared runtime between requests or between Operators
- Network access to each Operator's dashboard requires a unique secret administrator key that is never exposed client-side
- All API routes are access-controlled — unauthenticated requests receive a 401 Unauthorized response and no data is returned
Vercel maintains a SOC 2 Type II certification. Their security documentation is available at vercel.com/security.
12. Endpoint Protection
All Platform administration is performed exclusively on Apple iOS devices (iPhone and iPad). The following protections are enforced by the iOS platform:
- Biometric Authentication — All administrator devices require Face ID or Touch ID authentication. Biometric access cannot be bypassed without the device passcode
- Hardware Encryption — iOS enforces full hardware-level disk encryption on all devices with Face ID or Touch ID enabled. Data is inaccessible without successful biometric or passcode authentication
- Automatic Screen Lock — iOS auto-lock is active on all administrator devices, requiring re-authentication after a short period of inactivity
- OS and App Updates — iOS and all applications are kept up to date. Security patches are applied promptly upon release
- App Sandboxing — iOS enforces strict app sandboxing. No application can access data belonging to another application, providing inherent protection against malware and unauthorized data access
Operators are expected to maintain appropriate endpoint protections on any device used to access their Hallie Platform dashboard.
Software development and infrastructure changes are carried out with the assistance of an AI coding tool operating in an isolated, ephemeral cloud execution environment. This environment holds no independent or standing access to any Operator's TikTok account, does not persist credentials or Operator data beyond a single development session, and every action it takes is directed and authorized in real time by the Platform Provider's sole authorized officer from their Apple iOS device.
13. Security Baselines
The following baseline security measures are enforced for all access to the Platform and associated infrastructure:
- Multi-Factor Authentication (MFA) — All Platform infrastructure accounts (Vercel and GitHub) require a password plus a second factor. The Platform Provider's sole authorized officer uses the Oracle Authenticator app to generate time-based one-time passcodes (TOTP), and passkeys bound exclusively to personal Apple iOS devices (protected by Face ID or Touch ID and the device's hardware Secure Enclave) where a service supports passkey sign-in. No single credential is sufficient to gain access
- Firewall — Vercel's web application firewall is active across all Platform endpoints. Traffic is continuously monitored and filtered, with non-compliant requests denied or challenged in real time
- DDoS Mitigation — Vercel's infrastructure provides automatic DDoS protection at the network and application layers. No additional configuration is required — protection is active by default on all deployments
- Bot Protection — Bot Protection is enabled and actively challenging requests from non-browser sources, excluding verified bots. Known AI scrapers and crawlers are blocked
- Operator Authentication — Operators access the Platform exclusively through TikTok Login Kit (OAuth). Each Operator authenticates with their own TikTok credentials — no shared keys or passwords are issued. The Platform Provider does not create, hold, or manage Operator credentials of any kind
- Administrative Access — A single administrative key, held exclusively by the Platform Provider's sole authorized officer, is used only to access operational debug logs. This key does not grant access to any Operator's TikTok account data
- Session Management — Operator sessions use HttpOnly, Secure, SameSite cookies. OAuth tokens expire after 30 days and require re-authentication
14. Data Protection & Encryption
- Data in Transit — All data transmitted between Operators, the Platform, and TikTok's API is encrypted using TLS 1.2 or above. This is enforced at the infrastructure level by Vercel and cannot be downgraded.
- Data at Rest — The Platform does not maintain a persistent database. OAuth tokens stored in cookies are HttpOnly (inaccessible to JavaScript), Secure (HTTPS only), and SameSite=Strict. Environment variables including all secrets are encrypted at rest by Vercel's infrastructure using AES-256.
- Secret Management — API keys, admin secrets, and OAuth credentials are stored exclusively as encrypted environment variables. They are never committed to source control, logged, or exposed in API responses.
- No Third-Party Data Sharing — Comment data is never transmitted to third-party analytics, advertising, AI training, or any other external service. The only outbound API calls are to TikTok's authorized API endpoints on behalf of each Operator.
15. Access Control Policy
Access to the Platform is governed by a strict need-to-know, least-privilege model:
- Operator isolation — Data isolation is architecturally enforced, not just policy. Each Operator authenticates via TikTok Login Kit, which issues an OAuth token scoped exclusively to their own TikTok account. It is technically impossible for one Operator to access another Operator's data.
- Platform Provider data access — The Platform Provider cannot access any Operator's TikTok account data. OAuth tokens are scoped per-Operator by TikTok's API and are stored in the Operator's own session cookies. The Platform Provider's administrative key grants access only to operational debug logs — not to any account data.
- No credential management — The Platform does not issue, store, or manage Operator passwords or access keys. Operators authenticate directly with TikTok via Login Kit.
- API access — TikTok OAuth tokens are scoped to the minimum required permissions and stored only in server-side HttpOnly cookies inaccessible to client-side code.
- Platform infrastructure access — Access to Platform source code and hosting infrastructure is limited to the Platform Provider's sole authorized officer, with Oracle MFA enforced.
16. Vulnerability Management
The Platform Provider maintains the following vulnerability management practices:
- Dependency management — GitHub Dependabot continuously monitors all software dependencies and opens an alert or pull request when a vulnerability is found. Critical and high vulnerabilities are prioritized for prompt remediation.
- Infrastructure scanning — Vercel provides automated infrastructure-level vulnerability detection and patching as part of its platform.
- Development and review process — Code and infrastructure changes are made collaboratively by the Platform Provider's sole authorized officer and an AI coding assistant. Every change is authorized by the Platform Provider before it is committed. When Dependabot identifies a vulnerability, the Platform Provider and the AI assistant jointly evaluate and remediate it before the fix is published to the main repository.
- Security testing — The Platform undergoes AI-assisted security testing against non-production test environments as part of ongoing development. The Platform Provider has not yet engaged an independent third-party penetration testing firm and plans to do so as the Platform's data access needs grow.
- Vulnerability disclosure — Security vulnerabilities may be reported to support@tjbmanagementinc.com. We commit to acknowledging reports within 48 hours and remediating critical issues within 7 days.
17. Incident Management
The Platform Provider maintains an incident response policy. In the event of a security incident or data breach involving Operator or End User data:
Detection & Containment
- Suspicious activity is monitored through Platform runtime logs and error tracking
- Upon discovery of a potential incident, all affected tokens and credentials are immediately revoked and rotated
- The affected system or account is isolated as quickly as possible to prevent further exposure
Assessment & Notification
- The scope and nature of the incident is assessed within 24 hours of discovery
- Affected Operators are notified within 48 hours of discovery
- TikTok is notified of any incident affecting TikTok user data within 72 hours in accordance with applicable regulatory requirements
- Affected End Users and regulatory authorities are notified as required by applicable law (GDPR, CPRA)
Recovery & Review
- All access credentials involved in the incident are permanently rotated
- A post-incident review is conducted within 7 days to identify root cause and implement preventative measures
- Incident reports are documented and retained for a minimum of 12 months
- Incident response procedures are tested at least annually through a tabletop exercise
To report a security incident or suspected breach, contact support@tjbmanagementinc.com immediately.
18. Subprocessors & Infrastructure
The Platform relies on the following third-party subprocessors. All subprocessors are subject to appropriate data protection agreements:
- Vercel Inc. — Hosting and serverless compute infrastructure. SOC 2 Type II certified. Headquartered in San Francisco, CA, USA. Data processed in the United States. Privacy Policy
- GitHub Inc. (Microsoft) — Private source code repository. SOC 2 Type II certified. No production data is stored in version control. Privacy Policy
- TikTok for Business — Data source and action endpoint. All data originates from TikTok's API and moderation actions are returned to TikTok via authorized API calls. No TikTok user data is shared with any other subprocessor.
The Platform Provider does not use any other subprocessors that process Operator or End User data. This list is reviewed and updated whenever a new subprocessor is engaged. Operators will be notified of material changes to subprocessors.
Platform Provider Headquarters: United States
Primary Workforce Location: United States
System Location: United States (Vercel US regions)
Ownership: Sole owner Tyler J. Beasley — US citizen and resident, sole shareholder and sole authorized officer of TJB Management Inc.
19. US Data Security Compliance
The Hallie Platform is developed and operated in compliance with TikTok's US Data Security (USDS) requirements. The following attestations map TJB Management Inc.'s specific practices to each USDS requirement area.
Ownership & Corporate Structure
- TJB Management Inc. is headquartered in the United States and organized under US law
- Solely owned by Tyler J. Beasley, a US citizen and resident. Tyler J. Beasley is the sole shareholder, sole authorized officer, and sole owner of TJB Management Inc. There are no other ownership interests of any kind
- No other officers, board members, or controlling parties exist — the company has a single authorized officer and a single issued share
- The Platform has no operational, contractual, or financial ties to any US-restricted jurisdiction
Data Handling & Privacy
- All data collected via TikTok's API is used solely to perform authorized automation actions on behalf of each Operator — no secondary use, profiling, or sale of data occurs (see Sections 3–4)
- Content data (comments, video metadata) fetched via TikTok's API is processed in-request memory and is not written to any persistent database operated by the Platform Provider. OAuth tokens are stored exclusively as HttpOnly browser cookies on the Operator's own device — not retained server-side. Operators can immediately delete all session data via the in-platform Disconnect button (see Section 6)
- Only the minimum API scopes necessary to perform authorized functions are requested — no excess permissions are sought or held (see Section 7)
- All data is processed and stored within the United States. No data is transferred to or accessible from any US-restricted jurisdiction
- End User data subject rights (access, deletion, correction, portability) are supported and can be exercised by contacting support@tjbmanagementinc.com (see Section 5)
Security Controls
- All data in transit is encrypted with TLS 1.2 or above. All secrets are encrypted at rest using AES-256 via Vercel's infrastructure (see Section 14)
- All infrastructure accounts (Vercel and GitHub) require a password plus a second factor — Oracle Authenticator TOTP codes or passkeys bound to personal iOS devices, protected by Face ID or Touch ID and hardware Secure Enclave (see Sections 12–13)
- Access to the Platform is governed by least-privilege and need-to-know principles. Each Operator is isolated from all others (see Section 15)
- AI-assisted security testing is performed against non-production environments as part of ongoing development. A third-party penetration testing engagement has not yet been conducted (see Section 16)
- A documented incident response process is in place. Affected parties are notified within 48 hours of any confirmed incident (see Section 17)
- The Platform is hosted on Vercel Inc., a SOC 2 Type II certified provider operating US infrastructure (see Section 18)
Subprocessors
- Vercel Inc. — US-headquartered, SOC 2 Type II certified, US infrastructure only
- GitHub Inc. (Microsoft) — US-headquartered, SOC 2 Type II certified, no production data stored
- No subprocessors have material ownership or operational ties to any US-restricted jurisdiction
Supporting documentation, including dependency vulnerability monitoring history, is available upon request at support@tjbmanagementinc.com.
20. Contact & Requests
For any questions, data subject requests, privacy inquiries, security reports, or compliance documentation requests related to the Hallie Platform, please contact:
- All privacy, security & compliance inquiries: support@tjbmanagementinc.com
TJB Management Inc.
Platform Provider · United States
We will respond to all privacy and security inquiries within 30 days. Critical security incidents will receive an acknowledgment within 48 hours.