BCBAA
Home Terms

Privacy Policy

Last updated: 25 August 2026

This policy describes what data we handle when we manage advertising accounts on behalf of our clients, and what we do with it. It is written to be read, not to be skimmed past.

1. Who we are

BCBAA is a small performance marketing team that plans and manages TikTok Ads campaigns for e-commerce sellers. You can reach us at [email protected] about anything on this page.

2. What this website collects

Nothing. This site is a set of static pages. There are no accounts, no forms, no cookies set by us, no analytics scripts, and no third-party trackers. Our web server keeps ordinary access logs (IP address, timestamp, requested path, user agent) for operational and security purposes; these are rotated and deleted on a rolling basis.

3. Advertising data we process for clients

When a client engages us, they authorise us to access their advertising accounts. We then process:

  • Aggregate campaign performance — spend, impressions, clicks, conversions and derived metrics, at the account, campaign and ad group level.
  • Account balance and billing status, so we can warn before a prepaid account runs dry.
  • Campaign configuration — names, delivery status and budgets.
  • Product and inventory figures that the client shares with us, so that advertising is not scaled into a stock-out.

This is aggregate, business-level advertising data. We do not collect or receive personal information about the client's individual customers — no names, no email addresses, no contact lists, no device identifiers.

4. How we access it

Access happens in two ways: through the advertising platform's own interface, and through the platform's official reporting API using access tokens that the account owner grants us.

  • Our API access is read-only. We request only reporting and account information permissions. Our tooling cannot create, modify, pause or delete campaigns, budgets or creatives, because it never asks for the permission to do so.
  • Access tokens are encrypted at rest in our database, and are never written to logs, never displayed in our interface, and never shared.
  • Authorisation is revocable. A client can remove our access at any time from their own Business Center, without asking us first. Our access ends immediately when they do.

5. Where it is stored and who can see it

Data is stored on a server that we operate ourselves, hosted with a commercial cloud provider in Japan. It is not sent to any third-party analytics platform, data broker or advertising network. Access is limited to the people on our team who work on that client's account.

We keep the original API responses as an append-only record. That is deliberate: it is how we can answer "what did the platform actually report that day" months later, when a platform has since restated its own numbers.

6. Who we share it with

We do not sell client data, and we do not share it for anyone else's marketing. The only parties involved are:

  • The client, whose data it is — they receive it back as reports.
  • The advertising platform it came from, under that platform's own terms.
  • Our infrastructure provider, which hosts the server. They do not process the data for their own purposes.

We may also disclose data where we are legally required to.

7. How long we keep it

We keep a client's advertising data for as long as we work together, plus a limited period afterwards for accounting and dispute-resolution purposes. On written request from the account owner we will delete their data sooner, other than records we are required to keep. Access tokens are deleted as soon as an engagement ends or authorisation is withdrawn.

8. Your rights

If you are a client, you can ask us at any time for a copy of the data we hold about your accounts, ask us to correct it, or ask us to delete it. Email [email protected] and we will respond within 30 days. You never need our permission to revoke our access to your advertising account — that control stays with you.

9. Security

Traffic to our services is encrypted in transit. Credentials are encrypted at rest. Administrative access requires a password and expires automatically. We do not claim to hold any formal security certification, and we would rather say that plainly than imply otherwise.

10. Changes

If this policy changes, we will update the date at the top. Material changes affecting existing clients will be sent to them by email.

Home Terms of Service
© 2026 BCBAA