1. 关于我们
本隐私政策适用于 蚌埠麦嘉网络科技有限公司("我们")在 hnlytk.club 及其相关产品/服务中对个人信息的处理。我们基于 TikTok for Developers 与 TikTok Marketing API 的集成,为企业用户提供广告管理、数据分析及自动化工作流程服务。
2. 我们收集哪些信息
- 账户与身份信息:业务联系人姓名、工作邮箱、公司名称、职位等基本信息。
- 授权与令牌信息:通过 TikTok OAuth 授权获取的访问令牌、刷新令牌,仅用于调用经授权的 API。
- 广告/分析数据:经授权后从 TikTok API 获取的广告系列、广告组、广告、投放结果、报表指标等数据。
- 技术日志:为保障安全与审计用途记录的时间戳、IP地址、接口错误码、调用次数等技术信息。
- Cookie 与类似技术:用于会话维持与安全验证(不用于行为画像或跨站追踪)。
- 使用行为数据:平台使用情况、功能偏好、操作记录等,用于改善服务质量。
3. 我们如何使用信息
- API调用服务:执行经授权的 TikTok API 调用(创建/管理广告、拉取报表、数据分析);
- 服务优化:提供/维护/优化我们的产品与服务,改进性能与稳定性;
- 安全审计:进行安全审计、风控与合规(如异常调用监测、权限校验);
- 客户支持:提供技术支持和客户服务,解决用户问题;
- 合规要求:依法依规响应监管或执法部门的合法请求;
- 产品改进:分析使用数据以改进产品功能和用户体验。
4. 数据共享与第三方
我们不会出售、出租或以其他方式商业化个人信息。仅在以下情形共享数据:
- 服务提供商:与必要的服务提供商(如云计算、日志与监控供应商)签署保密与数据处理协议后;
- 法律要求:为履行法律义务、保护用户与公众安全、响应法院命令或政府要求;
- 业务转让:在公司合并、收购或资产转让时,在通知用户后转移相关数据;
- 用户同意:经您明确同意的其他情形。
5. 数据存储与跨境传输
数据主要存储于 阿里云 和 本地服务器,并可能根据业务需要跨境传输。 我们将采用适当的合同条款与安全措施以满足适用法律的要求。
- 存储位置:主要在中国境内的阿里云数据中心和本地服务器
- 跨境传输:仅在必要时进行,并遵循相关法律法规
- 安全措施:采用加密传输、访问控制、数据备份等安全措施
- 合规要求:遵守《网络安全法》、《数据安全法》、《个人信息保护法》等法律法规
6. 数据保留期限
- 访问令牌:仅在授权有效期内保存,到期或撤销即删除/失效;
- 广告数据:按业务需要保存,默认 180 天(可根据用户需求调整);
- 技术日志:用于安全与审计,默认 90 天 保存;
- 用户信息:在账户活跃期间保存,账户注销后30天内删除;
- 备份数据:定期清理,最长保留1年。
7. 您的权利
根据《个人信息保护法》等相关法律法规,您享有以下权利:
- 知情权:了解我们收集、使用您个人信息的情况
- 访问权:查询、复制您的个人信息
- 更正权:要求更正不准确的个人信息
- 删除权:要求删除您的个人信息
- 撤回同意:撤回您之前给予的同意
- 数据可携带:要求以结构化、通用格式获取您的数据
如需行使上述权利,请联系我们:yuwenqiang@hnlytk.club
8. 儿童隐私保护
我们的产品/服务主要面向企业与成年用户,不主动收集未成年人的个人信息。 若您认为我们错误收集了未成年人的数据,请立即联系我们删除。
- 年龄限制:服务对象为18周岁以上的成年人
- 监护人同意:如涉及未成年人,需获得监护人明确同意
- 数据删除:发现未成年人数据时立即删除
- 特殊保护:对未成年人个人信息给予特殊保护
9. 数据安全措施
我们采取多层次的安全措施保护您的数据安全,但任何系统都无法保证 100% 安全。 我们将持续改进并在发生安全事件时依法通知。
- 加密技术:数据传输和存储均采用行业标准加密技术
- 访问控制:实施最小权限原则,严格控制数据访问
- 密钥管理:采用分级密钥管理,定期轮换密钥
- 安全审计:定期进行安全审计和漏洞扫描
- 员工培训:定期对员工进行数据安全培训
- 事件响应:建立安全事件响应机制,及时处理安全威胁
10. 第三方服务与SDK
我们与 TikTok 的交互基于其官方 API/SDK。使用第三方服务时,您的数据将受其政策约束。 请阅读 TikTok 及相关第三方的隐私政策。
- TikTok API:我们使用TikTok官方API,受其服务条款约束
- 云服务商:使用阿里云等云服务,遵循其数据保护政策
- 分析工具:可能使用第三方分析工具,数据使用遵循其隐私政策
- 支付服务:如涉及支付,使用第三方支付服务
11. 联系方式
公司名称:蚌埠麦嘉网络科技有限公司
联系邮箱:yuwenqiang@hnlytk.club
公司地址:安徽省蚌埠市上淮区淮滨街道永昌国际D栋23楼2310室
公司网站:https://www.hnlytk.club
12. 政策变更
我们可能会不时更新本隐私政策。若本政策有重大变更,我们将在本页更新"最后更新"日期, 并在必要时通过邮件、站内通知等方式提供更显著的通知。
- 轻微变更:仅更新页面日期,无需额外通知
- 重大变更:通过邮件或站内通知告知用户
- 生效时间:变更后的政策自发布之日起生效
- 继续使用:继续使用服务视为接受新政策
1. About Us
This Privacy Policy describes how Bengbu Maijia Network Technology Co., Ltd. ("we", "us") processes personal data on hnlytk.club and related services. We integrate with TikTok for Developers and TikTok Marketing API to provide ad management, data analytics, and automation services for business users.
2. Data We Collect
- Account/Identity: business contact name, work email, company information, job title, and other basic information.
- Auth & Tokens: access/refresh tokens obtained via TikTok OAuth, stored securely and used only for authorized API calls.
- Ads/Analytics: campaigns, ad groups, ads, performance metrics retrieved via TikTok APIs.
- Technical Logs: timestamps, IP addresses, error codes, call counts for security/audit purposes.
- Cookies: session and security cookies; we do not use them for profiling or cross-site tracking.
- Usage Data: platform usage patterns, feature preferences, operation records for service improvement.
3. How We Use Data
- API Operations: Perform authorized TikTok API operations (create/manage ads, fetch reports, data analytics);
- Service Improvement: Provide, maintain, and improve our services;
- Security & Compliance: Security auditing, risk control, and compliance monitoring;
- Customer Support: Provide technical support and customer service;
- Legal Compliance: Respond to lawful requests from regulatory or law enforcement authorities;
- Product Enhancement: Analyze usage data to improve product functionality and user experience.
4. Sharing & Third Parties
We do not sell, rent, or otherwise commercialize personal data. We may share data:
- Service Providers: With necessary service providers (cloud computing, logging, monitoring) under confidentiality and data processing agreements;
- Legal Requirements: To comply with laws, protect users and public safety, respond to court orders or government requests;
- Business Transfers: In case of merger, acquisition, or asset transfer, with user notification;
- User Consent: With your explicit consent in other circumstances.
5. Storage & International Transfers
Data is primarily stored in AliCloud and local servers, and may be transferred across borders where needed. We implement appropriate contractual and technical safeguards.
- Storage Location: Primarily in AliCloud data centers and local servers in China
- Cross-border Transfers: Only when necessary and in compliance with applicable laws
- Security Measures: Encryption, access controls, data backup, and other security measures
- Compliance: Compliance with Cybersecurity Law, Data Security Law, Personal Information Protection Law, etc.
6. Data Retention
- Access Tokens: Retained only during validity; deleted/invalidated upon expiry or revocation;
- Ad Data: Retained for business needs, default 180 days (adjustable based on user requirements);
- Technical Logs: Retained for 90 days for security and audit purposes;
- User Information: Retained during active account period; deleted within 30 days after account closure;
- Backup Data: Regularly cleaned up, maximum retention of 1 year.
7. Your Rights
Under applicable laws including the Personal Information Protection Law, you have the following rights:
- Right to Know: Understand how we collect and use your personal information
- Right to Access: Query and copy your personal information
- Right to Correction: Request correction of inaccurate personal information
- Right to Deletion: Request deletion of your personal information
- Right to Withdraw Consent: Withdraw previously given consent
- Data Portability: Request your data in a structured, commonly used format
To exercise these rights, please contact us at: yuwenqiang@hnlytk.club
8. Children's Privacy
Our services primarily target business and adult users. We do not actively collect personal information from minors. If you believe we have collected data from a minor, please contact us immediately to remove it.
- Age Restriction: Services are intended for adults aged 18 and above
- Parental Consent: If involving minors, explicit parental consent is required
- Data Deletion: Immediate deletion upon discovery of minor data
- Special Protection: Special protection for minors' personal information
9. Data Security Measures
We implement multi-layered security measures to protect your data. No system is 100% secure; we will continuously improve and notify as required by law in case of security incidents.
- Encryption Technology: Industry-standard encryption for data transmission and storage
- Access Control: Implementation of least-privilege principle with strict data access controls
- Key Management: Hierarchical key management with regular key rotation
- Security Auditing: Regular security audits and vulnerability scans
- Staff Training: Regular data security training for employees
- Incident Response: Established security incident response mechanisms
10. Third-Party Services & SDKs
We interact with TikTok via official APIs/SDKs. Your use of third-party services is governed by their policies. Please review TikTok's privacy policy and terms.
- TikTok API: We use TikTok's official API, subject to their terms of service
- Cloud Providers: Use of AliCloud and other cloud services, following their data protection policies
- Analytics Tools: May use third-party analytics tools, data usage follows their privacy policies
- Payment Services: Third-party payment services if payment functionality is involved
11. Contact
Company: Bengbu Maijia Network Technology Co., Ltd.
Email: yuwenqiang@hnlytk.club
Address: 23F-2310, Building D, Yongchang International, Huaibin Street, Shanghuai District, Bengbu, Anhui, China
Website: https://www.hnlytk.club
12. Policy Changes
We may update this Privacy Policy from time to time. For significant changes, we will update the "Last Updated" date and provide additional notice through email, in-app notifications, or other appropriate means.
- Minor Changes: Only update the page date, no additional notification required
- Significant Changes: Notify users via email or in-app notifications
- Effective Date: Updated policies take effect from the date of publication
- Continued Use: Continued use of services constitutes acceptance of the new policy