Privacy Policy
Last updated: 2026-09-15
This Privacy Policy describes how Seesail Outreach collects, uses, and protects your data when you use our creator discovery and outreach tools for TikTok Shop.
1. Who We Are
Seesail Outreach ("we", "our", "us") is an independent SaaS service operated from Thailand by an individual developer. Seesail Outreach helps TikTok Shop sellers discover creators and send collaboration invitations through official TikTok APIs and, when connected, the seller's own Gmail.
We operate multiple TikTok developer apps under the Seesail brand to serve different product functions.
Data Controller: Seesail, operating from Thailand.
Contact: Mio13266737796@gmail.com
Seesail is not affiliated with, endorsed by, or sponsored by TikTok or ByteDance Ltd.
2. Data We Collect
2.1 From TikTok Shop Partner API — Seller Authorization
When you connect a TikTok Shop seller account, we collect the following data under each scope you explicitly authorize:
- Seller scope: shop metadata (shop name, shop status, region), shop cipher, authorized seller profile identifiers
- Analytics scope: your own shop's aggregated performance metrics — views, clicks, orders, GMV — as reported by TikTok for your authorized store
2.2 Creator & Collaboration Data
- Creator scope: public creator profile data — nickname, avatar URL, content categories, creator tier, follower count, estimated GMV range, live streaming status. This data is publicly available on TikTok's platform and is used solely to display creator discovery results within your Seesail Outreach dashboard.
- Collaboration scope: invitation records you initiate within Seesail Outreach, and per-creator target_collaboration status values returned by TikTok
- Creator contact details a creator published themselves: some creators write an email address or a messaging handle into the public one-line bio on their own TikTok profile. When TikTok returns such a bio to Seesail, we detect the contact details it contains so that you can invite that creator. We do not scrape TikTok pages, and we do not buy, rent, or enrich contact data from data brokers. A creator may ask us to remove their details at any time via the address in Section 13.
2.3 From Your Use of Seesail
- Account email — used for login and account communications
- OAuth access tokens and refresh tokens — stored encrypted using AES-256-GCM; decryption keys are held server-side and never exposed to the browser
- API call audit logs — task_id, timestamp, API endpoint called, result summary (success / error code). Used for error diagnosis and compliance auditing.
2.4 Data We Do NOT Collect
- Creators' private contact details — we obtain no creator contact details from any private or non-public source. We use only what a creator has published themselves in their own public TikTok bio (see Section 2.2); we do not scrape TikTok pages, purchase contact lists, or infer addresses by any other means
- Your YouTube or Google account data for creator discovery — the YouTube feature reads public channel information with an application key only; we request no YouTube or Google account authorization for it, and we receive no private YouTube data (see Section 2.6)
- Buyer / consumer PII — order buyer information is outside our API scope
- Financial or tax data — bank accounts, tax IDs, and payout details are outside our scope
- Advertising or profiling data — we do not deploy advertising pixels, remarketing tags, or behavioural profiling tools. We do use a privacy-focused product analytics service (PostHog) and an error monitoring service (Sentry), both configured to collect the minimum necessary — see Section 9
2.5 Google User Data — Gmail (Email Outreach)
When you connect a Google account to send creator-outreach emails through Seesail's Outreach product, we receive the following data via Google OAuth, under the only scopes we request (openid, email, gmail.send):
- Your Google account email address and basic profile identifier — used to show which account is connected and to send emails from the correct address
- An OAuth token restricted to the gmail.send scope — allows Seesail to send emails on your behalf, and nothing else
How we use and protect this data:
- We use the gmail.send permission solely to send outreach emails that you explicitly compose and trigger within Seesail. We never send an email without your direct instruction.
- We do not read, scan, or store the contents of your Gmail mailbox. The gmail.send scope grants no read access, and we request no read scopes. We store only the outreach task you created and the per-recipient delivery status (sent / failed).
- Google OAuth tokens are encrypted with AES-256-GCM at the application layer before storage (see Section 4). Disconnecting your Google account in Seesail revokes the token immediately; you may also revoke access at any time via your Google Account permissions page.
- We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except with your explicit consent, where necessary for security purposes, or to comply with applicable law.
Limited Use disclosure: Seesail's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
中文说明:Seesail 对 Google 用户数据的使用与转移遵循上述 Google API 服务用户数据政策(含 Limited Use 受限使用要求)——(1) 我们仅使用 gmail.send 权限代您发送您主动创建并确认的建联邮件;(2) 我们不读取、不扫描、不存储您的邮箱内容,只保存您创建的发送任务与逐收件人发送状态;(3) OAuth token 经 AES-256-GCM 加密存储,断开连接即撤销授权。
AI/ML and Google user data. Seesail Outreach does not currently offer any AI-assisted feature, does not integrate with any third-party AI/ML service provider, and does not operate self-hosted or offline AI models. The only Google user data Seesail Outreach holds — your connected Gmail address and an encrypted OAuth token limited to the gmail.send scope — is never used to create, train, improve, or evaluate any machine-learning or artificial-intelligence model, and is never transferred to any AI/ML service provider, whether directly or through an aggregator. Should Seesail Outreach introduce an AI-assisted feature in the future, it will be built so that it never receives Google user data and will be disclosed in this policy before it is made available. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
中文说明:Seesail Outreach 目前不提供任何 AI 辅助功能,不集成任何第三方 AI 服务商,也不运营自托管或离线 AI 模型。我们持有的 Google 用户数据仅为您连接的 Gmail 地址与限定 gmail.send 权限的加密 OAuth 令牌,它们不会被用于创建、训练、改进或评估任何机器学习/人工智能模型,也不会直接或经由聚合平台转移给任何 AI 服务商。若未来引入 AI 辅助功能,将确保其不接触任何 Google 用户数据,并在开放前先在本政策中披露。对来自 Google Workspace API 的原始或衍生用户数据的使用遵循 Google 用户数据政策及其 Limited Use 要求。
2.6 YouTube Public Data — Creator Discovery (YouTube Data API)
Seesail Outreach uses YouTube API Services — specifically the YouTube Data API — to help you discover YouTube creators. This feature is available only when YouTube creator discovery is enabled for your account. We access public channel information only: the channel ID, channel name and handle, the public channel description, subscriber count, upload count, total channel views, channel thumbnail, country, the date the channel was created, and — for the channel's most recent uploads — their titles, thumbnails, publication dates, lengths, public view, like and comment counts, and whether the uploader has declared paid product placement. We read it with an application key held by Seesail. We do not request access to your YouTube or Google account for this feature, and we never receive private YouTube data; this is entirely separate from the optional Gmail connection described in Section 2.5.
Contact details shown for a channel are identified by Seesail only from that channel's own public description — for example an e-mail address the creator published there. YouTube does not provide creator contact details, and we do not scrape web pages, buy or rent contact lists, or infer addresses by any other means — the same commitment we make for TikTok creators in Section 2.2. Contact details stay masked until you choose to reveal them, and the first time you reveal a given channel in a calendar month counts against your monthly allowance.
We use this information solely to show creator-discovery results and channel profiles inside your Seesail Outreach dashboard, and to count the reveals your account has used. We do not sell it, we do not use it for advertising or profiling, and we do not share it with anyone other than the infrastructure providers listed in Section 10 that run the service on our behalf.
Because we obtain this data without any authorization from the channel owner, we store it for no longer than 30 calendar days; after 30 calendar days each stored channel record is either refreshed from YouTube or deleted, as required by the YouTube API Services Developer Policies (Section III.E.4.d). Contact details identified from a channel description are stored with that channel record and are refreshed or deleted together with it. The only thing we keep for longer is a per-month counter of how many reveals your account has used, which holds no YouTube data and is retained for billing (see Section 7).
By using YouTube creator discovery you agree to be bound by the YouTube Terms of Service. Google's own handling of data is described in the Google Privacy Policy. Because Seesail holds no YouTube or Google account authorization for this feature, there is nothing for you to revoke for it on your Google security settings page; the Gmail connection described in Section 2.5 can be revoked there at any time.
中文说明:Seesail Outreach 通过 YouTube API 服务(YouTube Data API)帮助你发现 YouTube 达人,该功能仅在你的账号开通后可用。我们只读取频道的 公开资料:频道 ID、频道名与 handle、公开简介、订阅数、视频数、总播放量、头像、国家与频道创建日期,以及该频道近期公开上传的标题、封面、发布时间、时长、公开的播放、点赞、评论数,以及上传者是否声明了付费推广,读取方式是 Seesail 自己持有的 API key。我们不申请你的 YouTube 或 Google 账号授权,也不接触任何非公开的 YouTube 数据——这与 §2.5 的 Gmail 连接是两条完全独立的路。频道的联系方式由我们从该频道自己的 公开简介里识别(YouTube 不提供这项数据),我们不抓取网页、不购买或租用名单、也不以任何其他方式推断;查看前一律打码,同一频道在同一自然月内第一次查看会计入你的月度额度。
中文说明(续):这些资料只用于在你的 Seesail Outreach 后台展示搜索结果与频道档案、并记录额度用量;我们不出售,不用于广告或用户画像,也不提供给 §10 所列基础设施服务商之外的任何第三方。由于这些数据是在没有频道主授权的情况下取得的,我们 最多保存 30 个自然日,到期即向 YouTube 刷新或删除(YouTube API 服务开发者政策 III.E.4.d);从简介里识别出的联系方式随该频道记录一起刷新或删除。保存更久的只有一个「本月已用几次查看」的计数,它不含任何 YouTube 数据,仅用于计费(见 §7)。使用本功能即表示你同意遵守 YouTube 服务条款;Google 对数据的处理见 Google 隐私政策。由于我们不持有你的任何 YouTube/Google 账号授权,本功能在 Google 安全设置页没有可撤销的授权项;§2.5 的 Gmail 连接可随时在那里撤销。
3. How We Use Your Data
We use the data described above exclusively for the following purposes:
- Rendering your Seesail Outreach dashboard — displaying creator search results, shop analytics, and invitation management
- Executing actions you explicitly trigger — sending collaboration invitations, sending the outreach emails you have composed and confirmed, pulling analytics snapshots. We take no action on your TikTok account, and we send no email, without a direct instruction from you.
- Error diagnosis and service improvement — audit logs and error reports (Sentry) help us identify and fix failures in API calls or email sending jobs
- Product analytics — we collect feature-usage events (e.g. page views, outreach funnel steps) through PostHog to understand where users encounter friction and improve the product. Events are tied to a pseudonymous user ID, never your email or name; automatic click capture and session recording are disabled
- Compliance and audit — invitation records and API audit logs are retained to meet TikTok Partner API compliance requirements and applicable law
We do not use your data for advertising targeting, for training machine-learning models, or for sale or transfer to third parties.
4. Data Storage & Security
- Database: Supabase (PostgreSQL 17), hosted in the AWS ap-south-1 (Mumbai) region. Row Level Security (RLS) policies enforce strict tenant isolation — your data is never accessible to other Seesail users.
- Backend: Deployed on Render (cloud hosting provider).
- Frontend: Deployed on Vercel.
- Encryption in transit: All network connections use TLS 1.2 or higher.
- Encryption at rest: OAuth tokens (access_token and refresh_token) are encrypted with AES-256-GCM at the application layer before being written to the database.
- Access control: Internal access to production data follows a least-privilege principle. System access events are logged and retained for a minimum of one year.
We do not hold certifications such as SOC 2 or ISO 27001. If you require enterprise-grade compliance guarantees, please contact us before subscribing.
5. International Data Transfer
Seesail Outreach is operated from Thailand. Our infrastructure involves servers in India (Supabase / AWS ap-south-1) and the United States (Render, Vercel edge network).
Under Thailand's Personal Data Protection Act 2019 (PDPA), Section 28, personal data may be transferred to a foreign country only if that country has adequate data protection standards, or if appropriate safeguards are in place. We rely on the contractual commitments (equivalent to Standard Contractual Clauses) provided by our infrastructure vendors (Supabase, Render, Vercel) who maintain their own data processing agreements.
For users in the European Economic Area (EEA), transfers of personal data to third countries are made on the basis of the Standard Contractual Clauses adopted under GDPR Article 46(2)(c) as incorporated in our vendors' data processing agreements.
6. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you
- Right of rectification — ask us to correct inaccurate data
- Right of erasure ("right to be forgotten") — request deletion of your personal data, subject to legal retention obligations
- Right to data portability — receive your data in a structured, machine-readable format (JSON)
- Right to object — object to processing in certain circumstances
- Right to withdraw consent — at any time, without affecting the lawfulness of processing before withdrawal
How to exercise your rights:
- Revoke TikTok authorization: Go to Seesail Settings → Connected Accounts and revoke any linked TikTok account. We will immediately stop calling TikTok APIs on your behalf and purge your OAuth tokens within 30 days. You may also revoke via TikTok directly at TikTok Connected Apps Settings.
- Disconnect your Google account: Go to Seesail Outreach Settings and disconnect Google. The gmail.send token is revoked immediately and we stop being able to send on your behalf. You may also revoke it yourself at any time from your Google Account permissions page.
- Data export or deletion request: Email Mio13266737796@gmail.com with your request. We will respond within 30 calendar days.
7. Data Retention
- OAuth tokens (TikTok and Google): Kept active until you deauthorize. Disconnecting your Google account revokes the gmail.send token immediately; every deauthorized token is purged within 30 days.
- Outreach email records: the outreach task you created and its per-recipient delivery status (sent / failed) are retained alongside the invitation records they belong to. We keep no copy of your Gmail mailbox, because we never receive one.
- Creator profile data: Public creator profile data received from TikTok is kept while the creator remains discoverable in Seesail Outreach and is updated when TikTok returns newer data. Creators may ask us to remove their data at any time via the address in Section 13.
- YouTube public channel data: Refreshed from YouTube or deleted within 30 calendar days of retrieval, as required by the YouTube API Services Developer Policies (Section III.E.4.d). Contact details identified from a channel's public description are stored with that channel record and follow the same limit. The per-month counter of reveals used holds no YouTube data and is retained for billing.
- Analytics snapshots: Retained for up to 12 months, then deleted or anonymized.
- Invitation records: Retained for 2 years to meet TikTok Partner API compliance audit requirements.
- API audit logs: Retained for 1 year, then deleted.
- Account data (email, settings): Retained until you delete your Seesail account. Upon deletion, OAuth tokens are immediately revoked, personal data is hard-deleted, and invitation records are anonymized.
8. Children's Privacy
Seesail is not directed to children. We do not knowingly collect personal data from individuals under 18 years of age. Under Thailand's PDPA, individuals under 20 years of age are considered minors for data protection purposes and require consent from a legal guardian.
If we become aware that we have inadvertently collected personal data from a minor without verifiable guardian consent, we will delete that data promptly. If you believe we have collected such data, please contact us at Mio13266737796@gmail.com.
9. Cookies & Tracking
Seesail uses essential cookies plus two privacy-configured operational services: product analytics (PostHog) and error monitoring (Sentry). We do not use advertising cookies, tracking pixels, remarketing, or cross-site tracking.
- Authentication session cookie: Maintains your logged-in session. Required for the service to function.
- User preference cookies: Stores settings such as interface language and display preferences.
- Product analytics (PostHog): Stores a pseudonymous identifier (cookie / localStorage) to count feature-usage events such as page views and outreach funnel steps. Automatic click capture, heatmaps, and session recording are disabled. Never used for advertising.
- Error monitoring (Sentry): When an error occurs, a report (stack trace, browser and OS metadata) is sent to Sentry so we can diagnose and fix the failure. Not used for tracking or advertising.
No cookies are placed for advertising purposes, remarketing, cross-site tracking, or behavioral profiling.
10. Third-Party Services
Seesail Outreach integrates with the following third-party services to operate. Each has its own privacy policy:
- TikTok / ByteDance — TikTok Shop & Affiliate APIs (seller authorization, creator discovery, collaboration invitations). TikTok Privacy Policy
- Google (Gmail API) — sending outreach emails you compose, under the gmail.send scope only (see Section 2.5 for our Limited Use commitments). Google Privacy Policy
- Google (YouTube Data API) — public channel search and profile data for creator discovery, read with an application key; no YouTube or Google account access is requested (see Section 2.6). YouTube Terms of Service · Google Privacy Policy
- Resend — transactional email delivery for our own system notices, and inbound mail handling for replies sent to our reply domain. Resend Privacy Policy
- PostHog — Product analytics (US Cloud, minimal pseudonymous usage events). PostHog Privacy Policy
- Sentry — Error monitoring (EU region, error reports only). Sentry Privacy Policy
- Supabase — Database and authentication hosting. Supabase Privacy Policy
- Render — Backend API hosting. Render Privacy Policy
- Vercel — Frontend hosting. Vercel Privacy Policy
We do not share your personal data with these vendors beyond what is strictly necessary to deliver the service.
11. Changes to This Policy
We may update this Privacy Policy from time to time. For any material change — such as adding new data types, new uses of existing data, or new third-party integrations — we will:
- Post an in-app notification banner at least 14 days before the change takes effect
- Send an email notification to your registered address at least 14 days in advance
Non-material changes (such as clarifications of existing practices or corrections of typographical errors) may be posted without advance notice. The "Last updated" date at the top of this page will always reflect when the policy was last revised.
12. Complaints & Reports
If you believe Seesail Outreach — including any message sent through Seesail Outreach — has violated these policies, applicable law, or your rights, you may submit a complaint or report at any time. This includes creators who wish to have their contact details removed.
- How to report: Email Mio13266737796@gmail.com with a description of the issue, any relevant links or screenshots, and your contact information.
- Processing timeline: We will acknowledge receipt of your complaint within 3 business days and provide a substantive response or resolution within 15 business days. If a complaint requires longer investigation, we will notify you of the delay and the expected timeline.
Copyright infringement notices are handled under the DMCA process in Terms of Service Section 5.4 (24–48 hour response). Data-privacy access, rectification, or deletion requests are handled under Section 6 above (30-day response). This section covers all other complaints, including reports about outreach messages sent through Seesail Outreach.
13. Contact / Data Controller
For any privacy-related questions, data access requests, or complaints:
- Email: Mio13266737796@gmail.com
- Data Controller: Seesail, operating from Thailand
- Response time: We aim to respond to all privacy requests within 30 calendar days.
If you are located in the European Union and believe we have not adequately addressed your privacy concern, you have the right to lodge a complaint with your local data protection authority.