TikTok Shop Legal addendum · Legal version v1 · Last updated: July 13, 2026
TikTok Shop Data Handling & Developer Policy
Last updated: August 24, 2026
This addendum describes AtlasCore controls for TikTok Shop seller data in alignment with TikTok Shop Developer Terms and data security requirements.
Independent application status
AtlasCore is an independent software application. TikTok, TikTok Shop, and related marks are trademarks of ByteDance Ltd. or its affiliates. AtlasCore is not sponsored, endorsed, or affiliated with TikTok.
Data we access
With merchant authorization, AtlasCore may access:
- Shop profile and catalog metadata for dashboard views
Order summaries for fulfillment workflows
Buyer and shipping PII only where required for authorized operational features
Controls
- Token encryption: OAuth tokens are encrypted at rest using AES-256-GCM.
Transport: TLS 1.2+ for all production API and webhook traffic.
PII retention: Terminal TikTok orders (`DELIVERED`, `COMPLETED`, `CANCELLED`) purge buyer/shipping fields 30 days after `fulfilled_at` (shipment stamps upgrade to `delivery_time` when the order is delivered). Open/active orders (`IN_TRANSIT`, `AWAITING_SHIPMENT`, `AWAITING_COLLECTION`, `SHIPPED`) and cancelled orders with no `fulfilled_at` follow a 90-day creation ceiling. See TikTok Shop DPP Compliance.
Webhooks: Incoming TikTok Shop webhooks are verified with HMAC-SHA256 and require a declared `tts_notification_id` on operational topics. The ledger stores an allowlisted operational dictionary.
Isolation: Each AtlasCore user links their own TikTok Shop (B2C `user_id` scope) with optional workspace (`X-Tenant`) overlays; cross-user access is denied.
Seller controls
- Disconnect TikTok Shop in AtlasCore to stop sync and purge credentials.
Revoke AtlasCore in TikTok Seller Center as needed.
Export account metadata via authenticated Export My Data.