Ocelot Social PanelTerms of Service

Privacy Policy

Last updated: 11 August 2026 · Ocelot

1. Who we are

Ocelot ("we", "us") operates the Ocelot Social Panel, a social media management tool used by our agency to manage organic TikTok content on behalf of our clients (for example content scheduling, publishing and reporting), only after the client authorizes the connection.

Contact: privacy@ocelot.es

2. TikTok data we collect

When a client connects their TikTok account through TikTok Login Kit / OAuth, we may receive and store:

  • Account identifiers — TikTok open_id, display name, username and profile avatar (user.info.basic, user.info.profile).
  • Profile statistics — follower and engagement aggregates when granted (user.info.stats).
  • Video metadata & metrics — titles, covers, create time, views, likes, comments and shares (video.list).
  • Authorization tokens — access tokens and refresh tokens issued by TikTok, used only to call TikTok APIs on the client's behalf (video.upload, video.publish).
  • Content the client asks us to publish — video files and captions submitted through the panel.

We do not scrape TikTok. Data is obtained only through official TikTok APIs after explicit user authorization.

3. How we use this data

  • Identify which client TikTok account is connected.
  • Display organic content and performance inside the panel.
  • Upload and publish videos to the authorized account when the client (or authorized agency operator) confirms publication.
  • Maintain and renew API sessions according to TikTok token rules.

We do not sell TikTok data. We do not use it for unrelated advertising or profiling outside the agency service agreement with each client.

4. Storage and security

Tokens and account identifiers are stored on our servers, encrypted at rest where applicable, and are never exposed to the browser or to other clients (multi-tenant isolation). Access is limited to authorized Ocelot staff working on that client.

Video files submitted for publishing are transmitted to TikTok via the Content Posting API and retained only as needed to complete the publish request and for operational logs.

5. Retention and deletion

We retain TikTok connection data while the client relationship and authorization remain active. Clients may disconnect TikTok from the panel or revoke access in TikTok settings. Upon disconnect or written request to privacy@ocelot.es, we delete stored tokens and associated TikTok profile/video cache for that connection, subject to short-term backup retention.

6. Sharing

We share data with TikTok only as required to operate the authorized API calls. We may use infrastructure processors (hosting, monitoring) under data-processing terms. We do not share one client's TikTok data with another client.

7. Changes

We may update this policy. The "Last updated" date at the top will change when we do. Material changes affecting TikTok data will be reflected here before new scopes or uses are introduced.