Privacy Policy
TJB Management Inc. · Privacy Policy for tjbmanagementinc.com
Effective Date: July 24, 2026 · Last Updated: August 27, 2026
This Privacy Policy brings together the privacy-related practices already described elsewhere on this website — the TikTok Agency Guidelines, the /agency page, the General Legal Terms, and the Hallie Platform Data Security & Privacy Policy, into a single reference. It does not replace those originals — where any difference exists, the original source page governs.
Table of Contents
Part I — General Website Privacy Practices
- Overview
- Information We Collect
- Cookies We Use
- Creator & Talent Data Visibility
- Third-Party Links & Services
- Changes to This Policy
- Contact Us
Part II — Hallie Platform Data Security & Privacy Policy
- About the Platform
- Definitions
- Data Collected
- Privacy Notice
- Data Subject Rights
- Data Retention
- Data Minimization
- Roles & Responsibilities
- Operator Obligations
- Information Security Policy
- Network Security
- Endpoint Protection
- Security Baselines
- Data Protection & Encryption
- Access Control Policy
- Vulnerability Management
- Incident Management
- Subprocessors & Infrastructure
- US Data Security Compliance
- Contact & Requests
Part I — General Website Privacy Practices
1. Overview
TJB Management Inc. ("TJB Management," "we," "us") operates tjbmanagementinc.com (this "Website"). This Privacy Policy describes the data practices of the Website as a whole.
Where a more specific policy applies — such as the Hallie Platform Data Security & Privacy Policy for Operators of the Hallie TikTok Account Automation Platform, or the TikTok Agency Guidelines for signed or signing creators — that specific policy governs in addition to, and where it conflicts, takes precedence over, this general Privacy Policy.
2. Information We Collect
This Website does not install any third-party advertising or tracking scripts — no Google Analytics, Meta Pixel, or similar tools are used anywhere on the Website.
This Website is hosted on Vercel, which provides TJB Management with Vercel Analytics — a built-in traffic dashboard that shows a visitor's IP address and the time of each visit. This data remains visible to TJB Management for approximately 24 hours following a visit and is used only to understand site traffic; it is not sold, shared with advertisers, or used for cross-site tracking.
The Website's contact pages (/tiktok/agency/connect, /tyler/contact/tyler, /hallie/contact/hallie) are directories of direct contact links — email and phone — and do not contain forms that collect or transmit visitor information to TJB Management.
Beyond Vercel Analytics described above and the operational cookies described in Section 3, the Website does not collect additional personal information from general visitors.
3. Cookies We Use
TJB Management uses a small number of cookies, each serving a specific operational purpose. None are used for advertising, analytics, or cross-site tracking.
- tiktok_oauth_state — a short-lived cookie set during TikTok OAuth login flows to prevent cross-site request forgery. Expires after 10 minutes.
- acct_token — stores an Operator's TikTok Account Login token for the Hallie Platform. HttpOnly, Secure. Expires after 30 days. See Part II for full detail.
- biz_token — stores an Operator's TikTok Business/Advertiser token used for the Hallie Platform's automated rules features. HttpOnly, Secure. Expires after 30 days.
- custom_rules — stores an Operator's custom moderation-rule configuration for the Hallie Platform. HttpOnly, Secure. Expires after 30 days.
- admin_session — an internal login-session cookie used exclusively by TJB Management's own personnel to access the Website's administrative dashboard. It is not set for, and does not apply to, general Website visitors. HttpOnly, Secure.
4. Creator & Talent Data Visibility
When a creator joins TJB Management, their creator network managers are given access to certain account data through TikTok's agency dashboard. This is what allows the agency to support, protect, and advocate for creators effectively. Managers have visibility into:
- LIVE replays — managers can review past streams
- LIVE analytics — real-time and historical performance data from streams
- Current violations — any active strikes or policy flags on the account
- Violation clips — the specific clip flagged for each violation
- Diamond count — total diamonds earned
- LIVE time — total hours streamed
- Follower count
- Like count
- Number of videos posted
This data is used solely to support the creator's growth, monitor for violations the agency can help resolve, and qualify the creator for campaigns and opportunities within the network.
5. Third-Party Links & Services
This Website may link to third-party websites and services, including TikTok, for reference and convenience. TJB Management Inc. does not control and is not responsible for the content, policies, or practices of any third-party site. Inclusion of a link does not imply endorsement.
6. Changes to This Policy
TJB Management Inc. may update this Privacy Policy at any time without prior notice. Continued use of the Website following any changes constitutes acceptance of the revised policy. The "Last Updated" date above reflects the most recent revision.
7. Contact Us
Questions about this Privacy Policy, or requests regarding your personal data, can be directed to support@tjbmanagementinc.com.
Part II — Hallie Platform Data Security & Privacy Policy
1. About the Platform
The Hallie Account Automation Platform ("Platform") is a TikTok account automation and management system developed and operated by TJB Management Inc. ("Platform Provider"), headquartered in the United States.
The Platform connects to TikTok's API on behalf of authorized TikTok accounts to automate account operations including content publishing, comment management, community moderation, mention monitoring, trending discovery, and automated rule execution. It is designed to help brands, creators, and businesses run their TikTok presence with as little manual intervention as possible.
This Policy governs the Platform's data handling practices and applies to all businesses and individuals ("Operators") who use the Platform to manage their TikTok accounts. By using the Platform, Operators agree to this Policy and accept responsibility for ensuring their own use complies with applicable laws and TikTok's terms.
The Platform operates under TikTok's API for Business Developer Terms and is subject to TikTok's Data Security and Privacy Review (DSPR) as a condition of accessing the full scope of TikTok Business API permissions.
2. Definitions
- Platform Provider — TJB Management Inc., the company that develops, operates, and maintains the Hallie Platform.
- Operator — Any business, brand, creator, or individual who uses the Hallie Platform to manage their TikTok account(s).
- End User — TikTok users who post comments on an Operator's TikTok content. End Users do not interact with the Platform directly.
- Platform — The Hallie Account Automation Platform, including all associated software, APIs, and infrastructure.
- Connected Account — An Operator's authorized TikTok account connected to the Platform via TikTok's API.
3. Data Collected
The Platform accesses and processes the following data via TikTok's API on behalf of each Operator:
Comment & Community Data
- Comment text — the content of comments posted to an Operator's TikTok videos
- Comment ID — TikTok's internal identifier for each comment
- Username — the TikTok username of the commenter
- Timestamp — the date and time the comment was posted
- Like count — the number of likes a comment has received
- Comment status — whether a comment is visible or hidden
Content Data
- Video ID, title, and creation date — displayed in each Operator's dashboard to identify their content
- View, like, comment, and share counts — displayed for performance visibility
Mentions & Discovery Data
- Hashtag and keyword mentions — monitored to track brand presence and community activity
- Trending search terms and hashtags — used for content strategy and discovery
- Mention video metadata — titles and engagement counts of videos mentioning an Operator's account or hashtags
Account Data
- Display name and avatar — fetched to identify the connected account in the Operator's dashboard
- Follower, like, and video counts — used for display and performance benchmarking
Automated Rules Data
- Rule definitions and configurations — the automation rules Operators create and manage within the Platform
- Rule execution results — the outcome of automated actions triggered by Operator-defined rules
Direct Message Data (Business Messaging API — Pending DSPR Approval)
- Message content — text of direct messages sent to or received from TikTok users on behalf of an Operator
- Sender and recipient identifiers — TikTok user IDs and usernames involved in each message thread
- Message timestamps — date and time each message was sent or received
- Message and delivery status — read, unread, and delivery state of each message
- Conversation thread IDs — TikTok's internal identifiers for message threads
Direct message data will only be accessed upon approval of the TikTok Business Messaging API scope following completion of TikTok's Data Security and Privacy Review (DSPR). DM data is processed solely to enable automated responses and message management on behalf of authorized Operators. DM data is subject to the same — or higher — data handling and security requirements as all other data listed above. Until DSPR approval is granted, the Platform does not collect or access direct messages.
The Platform does not collect or process payment information, private account data, advertising campaign data, or any data beyond what is explicitly listed above.
4. Privacy Notice
What data is collected
As described in Section 3, the Platform collects TikTok comment text, usernames, comment IDs, and associated video metadata through TikTok's authorized Business API on behalf of each Operator.
Why it is collected
Data is collected to power automated TikTok account management on behalf of Operators — including publishing content, moderating communities, monitoring brand mentions, discovering trending opportunities, and executing automated account rules. Processing is based on the legitimate interests of Operators in managing and growing their TikTok presence efficiently.
How data is used
Account data is used to perform authorized automation actions: publishing or scheduling content, hiding or pinning comments, replying to comments, managing hashtag mentions, surfacing trending keywords, and executing Operator-defined automation rules. Comment text is analyzed by the Platform's rule-based scoring engine to identify content requiring moderation. No data obtained from TikTok's API is sent to third-party AI, analytics, or advertising services. All Platform API calls are back to TikTok on behalf of the Operator. Separately from the Platform, the Platform Provider operates an internal, authentication-gated drafting tool that is not connected to TikTok's API in any way; it processes only text the Operator manually types or pastes in, and the Operator is prohibited from submitting TikTok-sourced content to it. That tool's outbound calls are to Groq, Inc. for transient AI inference, and — for one persona's optional writing-style reference feature — to Apple's iCloud IMAP servers to read the Operator's own Sent-folder email. That email import reads only messages the Operator personally authored and sent; it never reads received messages, other mailboxes, or any other person's data, is never sourced from TikTok, and nothing it reads is stored server-side. See Section 18 for both subprocessors' data handling terms.
Where data is transferred
Data travels between TikTok's servers and Platform infrastructure hosted on Vercel Inc. (a SOC 2 Type II certified provider) in the United States. No data obtained from TikTok's API is shared with, sold to, or transferred to any third party. The Platform's only outbound API calls are back to TikTok to perform actions authorized by the Operator.
How data is protected
All data in transit is encrypted using TLS 1.2 or above. Session tokens are stored as HttpOnly cookies inaccessible to client-side scripts. Each Operator's admin interface is protected by a unique secret key accessible only to authorized personnel within that Operator's organization.
How long data is stored
Comment text, usernames, and other content data fetched from TikTok's API are processed in memory for the duration of the request and are not written to any persistent database operated by the Platform Provider. OAuth access tokens are stored as HttpOnly, Secure browser cookies on the Operator's own device with a 30-day expiration — the Platform Provider does not retain tokens server-side. Operators can immediately revoke all session data at any time by clicking "Disconnect" within the Platform dashboard. See Section 6 for the full data retention policy.
5. Data Subject Rights
The Platform respects the data rights of End Users in accordance with applicable privacy regulations including GDPR and CPRA. Operators are responsible for facilitating these rights for their End Users. The following rights apply to personal data processed by the Platform:
- Right to Access — End Users may request a copy of any personal data processed on their behalf.
- Right to Correction — End Users may request that inaccurate personal data be corrected.
- Right to Deletion — End Users may request deletion of their personal data. Because the Platform does not maintain a persistent database of comment data, most data is cleared automatically on server restart. Upon request, any retained identifiers will be removed.
- Right to Restriction — End Users may request that processing of their data be restricted while a complaint is under review.
- Right to Object — End Users may object to processing of their personal data where processing is based on legitimate interests.
- Right to Data Portability — End Users may request a structured, machine-readable export of their data.
In-platform deletion: Operators can immediately delete all session data — including their OAuth token — by clicking the "Disconnect" button within the Platform dashboard. This takes effect instantly and requires no email request.
To exercise any other rights, or to submit a request on behalf of End Users, contact the Platform Provider at support@tjbmanagementinc.com. We will respond within 30 days. Identity verification may be required before fulfilling a request.
6. Data Retention
Personal data is retained only as long as necessary to fulfill the purpose for which it was collected:
- Comment text and usernames — processed transiently in memory. Not written to persistent storage. Cleared on server restart.
- Automation event log — recent automation events retained in memory per Operator session. Rolling — oldest events are overwritten as new events are added. Cleared on server restart.
- Seen content IDs — stored in memory to prevent reprocessing. Cleared on server restart.
- OAuth tokens — stored as HttpOnly cookies on the Operator's authorized device only. Expire after 30 days. Not persisted beyond the active session.
When an Operator clicks "Disconnect" within the Platform dashboard, their OAuth token cookie is immediately expired — no further API access is possible and no session data remains. In-memory data (event logs, seen IDs) associated with that session is also cleared. Operators may alternatively revoke authorization directly in TikTok's app under Settings → Apps and Websites.
End Users who wish to request deletion of any data held about them may contact support@tjbmanagementinc.com. We will respond within 30 days.
7. Data Minimization
The Platform requests only the minimum API scopes necessary to perform authorized account automation functions. Specifically:
- The Platform requests comment.list and comment.list.manage scopes to read and manage comments on behalf of Operators
- The Platform requests video.list to display an Operator's videos in their dashboard
- The Platform requests discovery.search.words to surface trending content
- The Platform requests user.info.basic, user.info.username, user.info.stats, user.info.profile, and user.account.type to display the connected account's identity and stats in each Operator's dashboard
Upon approval of the Business Messaging API scope, the Platform will additionally request only the minimum DM-related permissions required to read incoming messages and send automated responses — no other messaging scopes will be requested. No scopes beyond those necessary for each authorized function are requested at any stage. API fields are limited to those actively used by the Platform — no unused fields are fetched.
8. Roles & Responsibilities
The following role structure governs data responsibilities under this Policy:
- Platform Provider (TJB Management Inc.) — Acts as a data processor on behalf of Operators. Responsible for the security and integrity of the Platform infrastructure, and for processing data only as directed by Operators and as permitted under this Policy.
- Operator — Acts as the data controller for their connected TikTok account and the End Users who interact with their content. Operators are responsible for their own privacy notices, lawful basis for processing, and compliance with applicable local laws.
- Data Protection Officer (Platform Provider) — Tyler J. Beasley, sole authorized officer of TJB Management Inc., serves as the Platform Provider's designated Data Protection Officer and Privacy & Security Contact. All privacy inquiries, data subject requests, security incidents, and compliance documentation requests should be directed to support@tjbmanagementinc.com.
Operators must designate a Data Protection Officer (DPO) or equivalent privacy contact within their own organization where required by applicable law (e.g., GDPR Article 37).
9. Operator Obligations
By using the Hallie Platform, Operators agree to the following obligations:
- Lawful basis — Operators must have a valid lawful basis under applicable privacy law for processing End User data through the Platform.
- Privacy notice — Operators must maintain a publicly accessible privacy notice that discloses their use of automated account management tools and the processing of End User data.
- Credential security — Operators are responsible for securing their TikTok account credentials. The Platform does not issue separate credentials — Operators authenticate directly with TikTok via Login Kit.
- Authorized use only — Operators may only use the Platform to manage their own TikTok account(s) that they are authorized to manage.
- Compliance with TikTok terms — Operators must comply with all applicable TikTok API for Business Developer Terms and Community Guidelines.
- Data subject requests — Operators must be able to assist End Users in exercising their data rights and must direct such requests to the Platform Provider where necessary.
- No resale — Operators may not resell, sublicense, or otherwise provide Platform access to third parties without written authorization from the Platform Provider.
10. Information Security Policy
The Platform Provider maintains a comprehensive information security framework governing all aspects of the Hallie Platform. This framework is reviewed and updated at least annually.
Core security principles applied to the Platform:
- Least Privilege — Platform access is restricted to the minimum required to perform authorized functions at both the infrastructure and application level.
- Defense in Depth — Multiple layers of security controls are applied at the application, infrastructure, and operational levels.
- Data Minimization — Only the data necessary for moderation is accessed or retained. No data is processed beyond what Operators authorize.
- Secure by Default — All new features and configurations default to the most restrictive setting and require explicit enablement.
- Continuous Improvement — Security controls are reviewed following any incident, significant change, or annually at minimum.
11. Network Security
The Platform is hosted on Vercel Inc.'s serverless infrastructure, which provides the following network-level protections:
- All traffic is routed through Vercel's edge network with DDoS protection and traffic filtering
- All endpoints are served exclusively over HTTPS with TLS 1.2 or above — HTTP is not permitted
- Serverless function environments are fully isolated — there is no persistent shared runtime between requests or between Operators
- Network access to each Operator's dashboard requires a unique secret administrator key that is never exposed client-side
- All API routes are access-controlled — unauthenticated requests receive a 401 Unauthorized response and no data is returned
Vercel maintains a SOC 2 Type II certification. Their security documentation is available at vercel.com/security.
12. Endpoint Protection
All Platform administration is performed exclusively on Apple iOS devices (iPhone and iPad). The following protections are enforced by the iOS platform:
- Biometric Authentication — All administrator devices require Face ID or Touch ID authentication. Biometric access cannot be bypassed without the device passcode
- Hardware Encryption — iOS enforces full hardware-level disk encryption on all devices with Face ID or Touch ID enabled. Data is inaccessible without successful biometric or passcode authentication
- Automatic Screen Lock — iOS auto-lock is active on all administrator devices, requiring re-authentication after a short period of inactivity
- OS and App Updates — iOS and all applications are kept up to date. Security patches are applied promptly upon release
- App Sandboxing — iOS enforces strict app sandboxing. No application can access data belonging to another application, providing inherent protection against malware and unauthorized data access
Operators are expected to maintain appropriate endpoint protections on any device used to access their Hallie Platform dashboard.
Software development and infrastructure changes are carried out with the assistance of an AI coding tool operating in an isolated, ephemeral cloud execution environment. This environment holds no independent or standing access to any Operator's TikTok account, does not persist credentials or Operator data beyond a single development session, and every action it takes is directed and authorized in real time by the Platform Provider's sole authorized officer from their Apple iOS device.
13. Security Baselines
The following baseline security measures are enforced for all access to the Platform and associated infrastructure:
- Multi-Factor Authentication (MFA) — All Platform infrastructure accounts (Vercel and GitHub) require a password plus a second factor. The Platform Provider's sole authorized officer uses the Oracle Authenticator app to generate time-based one-time passcodes (TOTP), and passkeys bound exclusively to personal Apple iOS devices (protected by Face ID or Touch ID and the device's hardware Secure Enclave) where a service supports passkey sign-in. No single credential is sufficient to gain access
- Firewall — Vercel's web application firewall is active across all Platform endpoints. Traffic is continuously monitored and filtered, with non-compliant requests denied or challenged in real time
- DDoS Mitigation — Vercel's infrastructure provides automatic DDoS protection at the network and application layers. No additional configuration is required — protection is active by default on all deployments
- Bot Protection — Bot Protection is enabled and actively challenging requests from non-browser sources, excluding verified bots. Known AI scrapers and crawlers are blocked
- Operator Authentication — Operators access the Platform exclusively through TikTok Login Kit (OAuth). Each Operator authenticates with their own TikTok credentials — no shared keys or passwords are issued. The Platform Provider does not create, hold, or manage Operator credentials of any kind
- Administrative Access — A single administrative key, held exclusively by the Platform Provider's sole authorized officer, is used only to access operational debug logs. This key does not grant access to any Operator's TikTok account data
- Session Management — Operator sessions use HttpOnly, Secure, SameSite cookies. OAuth tokens expire after 30 days and require re-authentication
14. Data Protection & Encryption
- Data in Transit — All data transmitted between Operators, the Platform, and TikTok's API is encrypted using TLS 1.2 or above. This is enforced at the infrastructure level by Vercel and cannot be downgraded.
- Data at Rest — The Platform does not maintain a persistent database. OAuth tokens stored in cookies are HttpOnly (inaccessible to JavaScript), Secure (HTTPS only), and SameSite=Strict. Environment variables including all secrets are encrypted at rest by Vercel's infrastructure using AES-256.
- Secret Management — API keys, admin secrets, and OAuth credentials are stored exclusively as encrypted environment variables. They are never committed to source control, logged, or exposed in API responses.
- No Third-Party Data Sharing — Comment data is never transmitted to third-party analytics, advertising, AI training, or any other external service. The only outbound API calls are to TikTok's authorized API endpoints on behalf of each Operator.
15. Access Control Policy
Access to the Platform is governed by a strict need-to-know, least-privilege model:
- Operator isolation — Data isolation is architecturally enforced, not just policy. Each Operator authenticates via TikTok Login Kit, which issues an OAuth token scoped exclusively to their own TikTok account. It is technically impossible for one Operator to access another Operator's data.
- Platform Provider data access — The Platform Provider cannot access any Operator's TikTok account data. OAuth tokens are scoped per-Operator by TikTok's API and are stored in the Operator's own session cookies. The Platform Provider's administrative key grants access only to operational debug logs — not to any account data.
- No credential management — The Platform does not issue, store, or manage Operator passwords or access keys. Operators authenticate directly with TikTok via Login Kit.
- API access — TikTok OAuth tokens are scoped to the minimum required permissions and stored only in server-side HttpOnly cookies inaccessible to client-side code.
- Platform infrastructure access — Access to Platform source code and hosting infrastructure is limited to the Platform Provider's sole authorized officer, with Oracle MFA enforced.
16. Vulnerability Management
The Platform Provider maintains the following vulnerability management practices:
- Dependency management — GitHub Dependabot continuously monitors all software dependencies and opens an alert or pull request when a vulnerability is found. Critical and high vulnerabilities are prioritized for prompt remediation.
- Infrastructure scanning — Vercel provides automated infrastructure-level vulnerability detection and patching as part of its platform.
- Development and review process — Code and infrastructure changes are made collaboratively by the Platform Provider's sole authorized officer and an AI coding assistant. Every change is authorized by the Platform Provider before it is committed. When Dependabot identifies a vulnerability, the Platform Provider and the AI assistant jointly evaluate and remediate it before the fix is published to the main repository.
- Security testing — The Platform undergoes AI-assisted security testing against non-production test environments as part of ongoing development. The Platform Provider has not yet engaged an independent third-party penetration testing firm and plans to do so as the Platform's data access needs grow.
- Vulnerability disclosure — Security vulnerabilities may be reported to support@tjbmanagementinc.com. We commit to acknowledging reports within 48 hours and remediating critical issues within 7 days.
17. Incident Management
The Platform Provider maintains an incident response policy. In the event of a security incident or data breach involving Operator or End User data:
Detection & Containment
- Suspicious activity is monitored through Platform runtime logs and error tracking
- Upon discovery of a potential incident, all affected tokens and credentials are immediately revoked and rotated
- The affected system or account is isolated as quickly as possible to prevent further exposure
Assessment & Notification
- The scope and nature of the incident is assessed within 24 hours of discovery
- Affected Operators are notified within 48 hours of discovery
- TikTok is notified of any incident affecting TikTok user data within 72 hours in accordance with applicable regulatory requirements
- Affected End Users and regulatory authorities are notified as required by applicable law (GDPR, CPRA)
Recovery & Review
- All access credentials involved in the incident are permanently rotated
- A post-incident review is conducted within 7 days to identify root cause and implement preventative measures
- Incident reports are documented and retained for a minimum of 12 months
- Incident response procedures are tested at least annually through a tabletop exercise
To report a security incident or suspected breach, contact support@tjbmanagementinc.com immediately.
18. Subprocessors & Infrastructure
The Platform relies on the following third-party subprocessors. All subprocessors are subject to appropriate data protection agreements:
- Vercel Inc. — Hosting and serverless compute infrastructure. SOC 2 Type II certified. Headquartered in San Francisco, CA, USA. Data processed in the United States. Privacy Policy
- GitHub Inc. (Microsoft) — Private source code repository. SOC 2 Type II certified. No production data is stored in version control. Privacy Policy
- TikTok for Business — Data source and action endpoint. All data originates from TikTok's API and moderation actions are returned to TikTok via authorized API calls. No TikTok user data is shared with any other subprocessor.
- Groq, Inc. — AI inference provider for an internal drafting tool operated separately from the Platform and never connected to TikTok's API. Processes only text manually provided by the Operator; data obtained from TikTok's API is never sent to Groq. Per Groq's services agreement, Groq may not use inputs or outputs to train AI models and does not retain them by default (temporary logs of up to 30 days may exist solely for reliability troubleshooting and abuse investigation). Headquartered in Mountain View, CA, USA. Privacy Policy
- Apple Inc. (iCloud Mail) — The Operator's own email provider, already used for the Operator's business email independent of the Platform. The internal drafting tool connects via IMAP, authenticated with the Operator's own account credentials, solely to read the Operator's Sent folder for an optional writing-style reference feature. No Operator data beyond the Operator's own authored, previously-sent emails is accessed; no End User or TikTok data is ever read; nothing fetched is stored server-side — it is returned directly to the Operator's browser for review. Privacy Policy
The Platform Provider does not use any other subprocessors that process Operator or End User data. This list is reviewed and updated whenever a new subprocessor is engaged. Operators will be notified of material changes to subprocessors.
Platform Provider Headquarters: United States
Primary Workforce Location: United States
System Location: United States (Vercel US regions)
Ownership: Sole owner Tyler J. Beasley — US citizen and resident, sole shareholder and sole authorized officer of TJB Management Inc.
19. US Data Security Compliance
The Hallie Platform is developed and operated in compliance with TikTok's US Data Security (USDS) requirements. The following attestations map TJB Management Inc.'s specific practices to each USDS requirement area.
Ownership & Corporate Structure
- TJB Management Inc. is headquartered in the United States and organized under US law
- Solely owned by Tyler J. Beasley, a US citizen and resident. Tyler J. Beasley is the sole shareholder, sole authorized officer, and sole owner of TJB Management Inc. There are no other ownership interests of any kind
- No other officers, board members, or controlling parties exist — the company has a single authorized officer and a single issued share
- The Platform has no operational, contractual, or financial ties to any US-restricted jurisdiction
Data Handling & Privacy
- All data collected via TikTok's API is used solely to perform authorized automation actions on behalf of each Operator — no secondary use, profiling, or sale of data occurs (see Sections 3–4)
- Content data (comments, video metadata) fetched via TikTok's API is processed in-request memory and is not written to any persistent database operated by the Platform Provider. OAuth tokens are stored exclusively as HttpOnly browser cookies on the Operator's own device — not retained server-side. Operators can immediately delete all session data via the in-platform Disconnect button (see Section 6)
- Only the minimum API scopes necessary to perform authorized functions are requested — no excess permissions are sought or held (see Section 7)
- All data is processed and stored within the United States. No data is transferred to or accessible from any US-restricted jurisdiction
- End User data subject rights (access, deletion, correction, portability) are supported and can be exercised by contacting support@tjbmanagementinc.com (see Section 5)
Security Controls
- All data in transit is encrypted with TLS 1.2 or above. All secrets are encrypted at rest using AES-256 via Vercel's infrastructure (see Section 14)
- All infrastructure accounts (Vercel and GitHub) require a password plus a second factor — Oracle Authenticator TOTP codes or passkeys bound to personal iOS devices, protected by Face ID or Touch ID and hardware Secure Enclave (see Sections 12–13)
- Access to the Platform is governed by least-privilege and need-to-know principles. Each Operator is isolated from all others (see Section 15)
- AI-assisted security testing is performed against non-production environments as part of ongoing development. A third-party penetration testing engagement has not yet been conducted (see Section 16)
- A documented incident response process is in place. Affected parties are notified within 48 hours of any confirmed incident (see Section 17)
- The Platform is hosted on Vercel Inc., a SOC 2 Type II certified provider operating US infrastructure (see Section 18)
Subprocessors
- Vercel Inc. — US-headquartered, SOC 2 Type II certified, US infrastructure only
- GitHub Inc. (Microsoft) — US-headquartered, SOC 2 Type II certified, no production data stored
- No subprocessors have material ownership or operational ties to any US-restricted jurisdiction
Supporting documentation, including dependency vulnerability monitoring history, is available upon request at support@tjbmanagementinc.com.
20. Contact & Requests
For any questions, data subject requests, privacy inquiries, security reports, or compliance documentation requests related to the Hallie Platform, please contact:
- All privacy, security & compliance inquiries: support@tjbmanagementinc.com
TJB Management Inc.
Platform Provider · United States
We will respond to all privacy and security inquiries within 30 days. Critical security incidents will receive an acknowledgment within 48 hours.