Privacy Policy
Last updated: 11 August 2026 · Ocelot
1. Who we are
Ocelot ("we", "us") operates the Ocelot Social Panel, a social media management tool used by our agency to manage organic TikTok content on behalf of our clients (for example content scheduling, publishing and reporting), only after the client authorizes the connection.
Contact: privacy@ocelot.es
2. TikTok data we collect
When a client connects their TikTok account through TikTok Login Kit / OAuth, we may receive and store:
- Account identifiers — TikTok
open_id, display name, username and profile avatar (user.info.basic,user.info.profile). - Profile statistics — follower and engagement aggregates when granted (
user.info.stats). - Video metadata & metrics — titles, covers, create time, views, likes, comments and shares (
video.list). - Authorization tokens — access tokens and refresh tokens issued by TikTok, used only to call TikTok APIs on the client's behalf (
video.upload,video.publish). - Content the client asks us to publish — video files and captions submitted through the panel.
We do not scrape TikTok. Data is obtained only through official TikTok APIs after explicit user authorization.
3. How we use this data
- Identify which client TikTok account is connected.
- Display organic content and performance inside the panel.
- Upload and publish videos to the authorized account when the client (or authorized agency operator) confirms publication.
- Maintain and renew API sessions according to TikTok token rules.
We do not sell TikTok data. We do not use it for unrelated advertising or profiling outside the agency service agreement with each client.
4. Storage and security
Tokens and account identifiers are stored on our servers, encrypted at rest where applicable, and are never exposed to the browser or to other clients (multi-tenant isolation). Access is limited to authorized Ocelot staff working on that client.
Video files submitted for publishing are transmitted to TikTok via the Content Posting API and retained only as needed to complete the publish request and for operational logs.
5. Retention and deletion
We retain TikTok connection data while the client relationship and authorization remain active. Clients may disconnect TikTok from the panel or revoke access in TikTok settings. Upon disconnect or written request to privacy@ocelot.es, we delete stored tokens and associated TikTok profile/video cache for that connection, subject to short-term backup retention.
6. Sharing
We share data with TikTok only as required to operate the authorized API calls. We may use infrastructure processors (hosting, monitoring) under data-processing terms. We do not share one client's TikTok data with another client.
7. Changes
We may update this policy. The "Last updated" date at the top will change when we do. Material changes affecting TikTok data will be reflected here before new scopes or uses are introduced.