Last updated: December 4, 2024
1. Introduction
Flowctory ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website and services (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use the Service.
This Privacy Policy should be read alongside our Terms of Service.
2. Information We Collect
2.1 Account Information from TikTok
When you connect your TikTok account to Flowctory, we receive and store the following information from TikTok:
- TikTok Open ID: A unique identifier for your TikTok account (not your username)
- Display Name: Your TikTok display name
- Avatar URL: The URL of your TikTok profile picture
2.2 Authentication Tokens
We store OAuth access tokens and refresh tokens required to communicate with TikTok's API on your behalf. These tokens allow us to upload content to your TikTok account without storing your TikTok password.
2.3 Video Content
When you upload a video through the Service, the video file is temporarily stored on our servers solely for the purpose of transferring it to TikTok. Videos are automatically deleted from our servers after successful upload to TikTok or within 24 hours, whichever occurs first.
2.4 Post Metadata
We store information about your posts, including:
- Video captions and descriptions
- Privacy settings you select (public, friends, private)
- Scheduled posting times
- Upload timestamps
- Post status (pending, processing, published, failed)
- TikTok publish IDs for successful posts
2.5 Technical and Usage Data
We automatically collect certain technical information when you use the Service:
- IP address
- Browser type and version
- Device information
- Access timestamps
- Error logs and diagnostic data
We do not use third-party analytics services or tracking tools.
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:
3.1 Contract Performance
Processing is necessary to provide you with the Service, including:
- Authenticating your TikTok account
- Uploading and scheduling your video content
- Displaying your posting history
3.2 Legitimate Interests
We process certain data based on our legitimate interests, including:
- Improving and securing the Service
- Troubleshooting technical issues
- Preventing fraud and abuse
3.3 Legal Obligations
We may process your data when required by law, such as responding to legal requests or complying with applicable regulations.
3.4 Consent
Where required, we will obtain your explicit consent before processing your data. You may withdraw your consent at any time.
4. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Authenticate you with TikTok's services
- Upload and schedule video content to TikTok on your behalf
- Display your posting history and status within the application
- Troubleshoot issues with failed uploads
- Communicate with you about the Service (service announcements, security alerts)
- Detect, prevent, and address technical issues, fraud, or abuse
- Comply with legal obligations
We do not use your personal information for advertising purposes or sell it to third parties.
6. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy:
| Data Type | Retention Period |
|---|---|
| Account data (TikTok profile info) | Until you revoke access or delete your account |
| OAuth tokens | Until revoked or expired; deleted when you sign out |
| Video files | Deleted within 24 hours of upload |
| Post metadata | 90 days after posting |
| Server logs | 30 days |
7. Your Rights (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):
7.1 Right of Access
You have the right to request a copy of the personal data we hold about you.
7.2 Right to Rectification
You have the right to request correction of any inaccurate personal data we hold about you.
7.3 Right to Erasure ("Right to be Forgotten")
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
7.4 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
7.5 Right to Object
You have the right to object to the processing of your personal data based on our legitimate interests.
7.6 Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances.
7.7 Right to Withdraw Consent
Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. This does not affect the lawfulness of processing based on consent before its withdrawal.
7.8 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority. In France, the supervisory authority is the Commission Nationale de l'Informatique et des Libertés (CNIL): www.cnil.fr.
7.9 Exercising Your Rights
To exercise any of these rights, please contact us at contact@flowctory.com. We will respond to your request within 30 days.
8. California Privacy Rights (CCPA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):
8.1 Right to Know
You have the right to request that we disclose:
- The categories of personal information we have collected about you
- The categories of sources from which we collected the information
- The business or commercial purpose for collecting the information
- The categories of third parties with whom we share the information
- The specific pieces of personal information we have collected about you
8.2 Right to Delete
You have the right to request that we delete the personal information we have collected from you, subject to certain exceptions.
8.3 Right to Opt-Out of Sale
You have the right to opt-out of the sale of your personal information. However, Flowctory does not sell personal information.
8.4 Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights. We will not deny you goods or services, charge you different prices, or provide you with a different level of service for exercising your rights.
8.5 Exercising Your Rights
To exercise your CCPA rights, please contact us at contact@flowctory.com. We will verify your identity before processing your request.
9. International Data Transfers
Flowctory is based in France (European Union). If you access the Service from outside the EU, please be aware that your information may be transferred to, stored, and processed in the EU.
When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, such as:
- Transfers to countries with an EU adequacy decision
- Standard Contractual Clauses approved by the European Commission
- Other legally recognized transfer mechanisms
TikTok, as a third-party service, may transfer your data internationally according to their own privacy policy.
11. Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction:
- Encryption in Transit: All communications use HTTPS/TLS encryption
- Encryption at Rest: Sensitive data is encrypted in our database
- Secure Authentication: OAuth tokens are securely stored and managed
- Access Controls: Limited access to personal data on a need-to-know basis
- Regular Updates: Infrastructure and dependencies are regularly updated
While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately.
12. Children's Privacy
The Service is not intended for children under the age of 16 in the European Union or 13 in other jurisdictions. We do not knowingly collect personal information from children under these ages.
If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at contact@flowctory.com. If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to delete that information.
13. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. When we make changes:
- We will update the "Last updated" date at the top of this policy
- For material changes, we will provide notice through the Service or via email
- We will obtain your consent where required by applicable law
We encourage you to review this Privacy Policy periodically to stay informed about our data practices.
14. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
FlowctoryCancale, France
Email: contact@flowctory.com
Data Protection Authority
If you are in the EU and have concerns about our data practices, you may contact the French data protection authority (CNIL) at www.cnil.fr.