Last updated: 25 August 2026
This policy describes what data we handle when we manage advertising accounts on behalf of our clients, and what we do with it. It is written to be read, not to be skimmed past.
BCBAA is a small performance marketing team that plans and manages TikTok Ads campaigns for e-commerce sellers. You can reach us at [email protected] about anything on this page.
Nothing. This site is a set of static pages. There are no accounts, no forms, no cookies set by us, no analytics scripts, and no third-party trackers. Our web server keeps ordinary access logs (IP address, timestamp, requested path, user agent) for operational and security purposes; these are rotated and deleted on a rolling basis.
When a client engages us, they authorise us to access their advertising accounts. We then process:
This is aggregate, business-level advertising data. We do not collect or receive personal information about the client's individual customers — no names, no email addresses, no contact lists, no device identifiers.
Access happens in two ways: through the advertising platform's own interface, and through the platform's official reporting API using access tokens that the account owner grants us.
Data is stored on a server that we operate ourselves, hosted with a commercial cloud provider in Japan. It is not sent to any third-party analytics platform, data broker or advertising network. Access is limited to the people on our team who work on that client's account.
We keep the original API responses as an append-only record. That is deliberate: it is how we can answer "what did the platform actually report that day" months later, when a platform has since restated its own numbers.
We do not sell client data, and we do not share it for anyone else's marketing. The only parties involved are:
We may also disclose data where we are legally required to.
We keep a client's advertising data for as long as we work together, plus a limited period afterwards for accounting and dispute-resolution purposes. On written request from the account owner we will delete their data sooner, other than records we are required to keep. Access tokens are deleted as soon as an engagement ends or authorisation is withdrawn.
If you are a client, you can ask us at any time for a copy of the data we hold about your accounts, ask us to correct it, or ask us to delete it. Email [email protected] and we will respond within 30 days. You never need our permission to revoke our access to your advertising account — that control stays with you.
Traffic to our services is encrypted in transit. Credentials are encrypted at rest. Administrative access requires a password and expires automatically. We do not claim to hold any formal security certification, and we would rather say that plainly than imply otherwise.
If this policy changes, we will update the date at the top. Material changes affecting existing clients will be sent to them by email.