Privacy Policy
1. About this policy
Skyler LLC provides Seller OS, an analytics and reporting service for designated TikTok Shop sellers. This Privacy Policy explains how Seller OS collects, uses, stores, protects, discloses, and deletes information received through seller authorization, TikTok Shop APIs and Webhooks, and use of the service.
Seller OS is designed for read-only analytics. It does not perform fulfillment, send buyer communications, make automated decisions, or automatically modify TikTok Shop data.
2. Information we process
Depending on the permissions authorized by a seller, Seller OS may process:
- seller and shop identifiers and basic shop information;
- product, SKU, category, price, and inventory analytics fields;
- order identifiers, status, time, product/SKU, amount, and other approved non-PII analytics fields;
- read-only settlement and financial report fields used for analytics and reconciliation support;
- buyer name, used only for seller-authorized order/customer identification and analytics;
- OAuth access credentials and technical configuration required to provide the service; and
- security and audit information such as account identifier, role, tenant, operation, time, source IP, and approval record.
The Seller OS MVP is not intended to request or store buyer phone numbers, email addresses, full shipping addresses, tracking numbers, customer-service messages, or cancellation, return, refund, or after-sales data. If an API or Webhook temporarily returns unapproved buyer personal information, Seller OS is designed to filter it before database storage.
3. How we use information
We use approved information to:
- authenticate and connect authorized TikTok Shop accounts;
- provide shop, product, inventory, order, marketing, and financial analytics;
- separate seller tenants and enforce authorized access;
- maintain, troubleshoot, and secure Seller OS;
- respond to support, privacy, and data requests; and
- comply with applicable law and enforce our agreements.
We do not sell buyer personal information. We do not use TikTok Shop data to train artificial intelligence models. We do not use it to make automated decisions about buyers.
4. Data minimization and accuracy
Seller OS limits collection to fields needed for the approved analytics purpose and read-only functionality. Sellers and authorized users should notify us if account or service information is inaccurate. Where the source data remains controlled by TikTok Shop or a seller, we may direct the requester to the appropriate source or coordinate the correction with that party.
5. Retention
| Information | Maximum retention |
|---|---|
| Buyer name | 90 days |
| Approved order, product, inventory, marketing, and financial analytics fields | 24 months |
| Security and audit logs | 180 days |
| Each encrypted backup snapshot | 30 days from snapshot creation |
We may delete information earlier when it is no longer needed, authorization is withdrawn, a valid deletion request applies, or the service relationship ends. Limited information may be retained longer only when required by applicable law, necessary to establish or defend legal claims, or required to document completion of a request. Any exception must be limited, access-restricted, and documented.
6. Security
Seller OS uses administrative and technical safeguards proportionate to the service, including least-privilege access, authentication controls, encryption in transit, field-level encryption requirements for buyer names and credentials, tenant separation, security logging, vulnerability management, and incident response procedures. Buyer name is limited to seller-authorized order/customer identification and analytics, must be field-level encrypted, and may be retained for no more than 90 days. No security measure eliminates all risk.
7. Service providers and disclosures
We disclose information only as needed to operate Seller OS, follow seller instructions, comply with law, protect rights or security, or support an approved business transfer. Infrastructure providers must be subject to appropriate confidentiality, security, and data-processing requirements.
8. Data location and cross-border access
Seller OS data will be physically stored and processed in the United States. Production access is restricted to authorized personnel in the United States.
9. Access, correction, export, and deletion requests
An authorized seller or user may request access to, correction of, export of, or deletion of information associated with the seller's Seller OS account. Requests may be sent to support@selleros.team.
We may ask for information reasonably necessary to verify identity, authority, shop association, and request scope. We will coordinate with the relevant seller or TikTok Shop when they control the source data or when their assistance is needed. We aim to acknowledge and complete a verified request within 30 days, unless applicable law permits more time or a documented exception applies. We will explain a denial or limitation where legally permitted.
10. Withdrawal of authorization and end of service
When a verified deletion request is approved, a seller withdraws authorization, or the contractual relationship ends, Seller OS will stop new collection for that seller and disable access as applicable. Customer data in active systems will be deleted or irreversibly de-identified within 30 days, unless retention is legally required. Each encrypted backup snapshot is isolated, is used only for disaster recovery and not ordinary processing, and is retained for no more than 30 days from snapshot creation. The last snapshot containing data already deleted from active systems will therefore expire no later than 30 days after the active-system deletion. From receipt of a verified request or other deletion trigger to expiry of the last backup copy, the worst-case period may be up to 60 days. If a backup is restored for disaster recovery, the deletion instruction will be re-applied before ordinary processing resumes.
11. Changes to this policy
We review this policy at least annually and after material changes to the service, data practices, applicable requirements, or security controls. The published version will show its effective date. Material changes will be communicated through an appropriate service channel.
12. Contact
Privacy and data requests: support@selleros.team
Provider: Skyler LLC
Service: Seller OS
Public address: Not published
Wu Wei is the formally appointed Data Protection Officer (DPO), Manager / Member, and Privacy & Security Owner for Skyler LLC operating Seller OS. DPO contact: wuwei@selleros.team.