Privacy Policy

Last updated: September 27, 2026

LASI (“we,” “us”) provides software that live-auction sellers use to run their business: inventory, live shows, orders, and profit reporting (the “Service”). This Policy explains what data moves through the Service, who can see it, and how long we keep it.

The plain version: your business data is yours. The customer — the auction-selling business that opens an account — is the controller of its data. LASI is a processor: we handle that data only to run the Service for that customer, on that customer’s instructions. We do not sell it, we do not use it for advertising, and we do not read it to run our own business.

Related documents: Terms of Service, Data Processing Addendum, and the Security page.

Information We Process

How We Use Information

Only to provide the Service to the organization the data belongs to: tracking stock and cost, matching platform orders to live-show sales, calculating cost of goods and profit, forecasting reorders, running payroll and scheduling views, sending the notifications you turn on, billing your subscription, and keeping the Service secure. Nothing here is used for advertising or profiling, and personal information is never sold.

What LASI Staff Can See

We do not read your business data to run our business. Here is exactly what our side looks like:

The Stream Stats browser extension

If you install our optional Chrome extension on a computer you stream from, it reads the numbers shown on your own TikTok LIVE dashboard — viewer counts, likes, comments, shares, new followers, product impressions and clicks, orders and sales totals — together with the short labels printed beside them, the address of the dashboard page without its query string, the id of the LIVE room it shows, and the page title, and sends them to your account in the Service every few seconds while the dashboard is open. Apart from the sale snapshots described below, which are off until you turn them on, it reads nothing else on the page, never a buyer’s or a viewer’s name and never a message, and it sends only to the Service. It runs only on the two TikTok Shop LIVE dashboards — the LIVE Data Screen and the Streamer Desktop — and on no other page, TikTok’s or anyone else’s. Readings are kept for 90 days. A summary of each stream built from them — when it started and ended, its peak and totals, and a minute-by-minute record of those same figures — is kept for as long as your account exists, so streams can be compared; it holds nothing about any viewer or buyer. Both are deleted with your account.

Stream figures from TikTok. Where your TikTok Shop connection allows it (TikTok’s “TikTok Shop Analytics” permission), the Service also reads each of your LIVEs from TikTok’s Partner API — the same kinds of figures: viewer, like, comment, share and new-follower counts, product impressions and clicks, items sold and sales totals, the LIVE’s title, room id and the handle of your account that streamed it, and, once it ends, the same figures minute by minute — and keeps them exactly as it keeps the extension’s readings, above. If a TikTok account you go live from signs in to the Service for TikTok’s “Live Data” permission, the Service stores that sign-in’s access tokens, encrypted, with the account’s TikTok id and display name, and uses them only to read how many people are watching that account’s LIVE and its peak: counts, never who they are. An admin can disconnect the account in Settings at any time, which deletes the tokens, and the account can withdraw the permission in TikTok.

Sale snapshots. The extension can also keep a still picture of your own LIVE video at each item your show sells. It is off unless an admin of your organization turns it on in Settings → Integrations → Stream stats; until then nothing is captured, on any computer. A snapshot is a frame copied from the video itself, together with that item’s auction number, the price it sold for and the time — so the chat, the viewers, their names and their messages are never in it, and neither is anything else printed beside the video on the dashboard. Snapshots are kept for 90 days, and longer while a return, a replacement or a dispute points at that sale, so the picture outlives the argument it exists to settle; after that they are deleted automatically. They are deleted with your account.

If you also turn on heard sizes, the extension listens to your stream’s own sound on that computer to catch the size your host says out loud. The listening happens entirely on that computer, using the speech model built into Chrome, and needs a one-time click on the dashboard to install it. No audio and no transcript is sent anywhere or stored — only the size word itself (“XL”, “size 10”) is kept, stamped on that item’s snapshot and always marked as heard rather than scanned.

Following your next LIVE. TikTok starts every LIVE in a new room and leaves your dashboard tabs on the one that ended. When the LIVE a Streamer Desktop tab shows has ended and TikTok says another LIVE of yours is on, the extension presses TikTok’s own “Switch to this LIVE” button on that tab, and then points a LIVE Data Screen still showing the old LIVE at the new one. It does this only on a tab nobody has used for five minutes and with no form open, never while the computer is building a show, and it clicks nothing else. It reads the new LIVE’s room id from the Streamer Desktop’s own link to that LIVE’s dashboard, and it tells the Service which rooms it moved to by itself, so the Service does not file such a stream under a show on the computer’s word alone.

Building shows. If an admin lets a computer build shows (Settings → Integrations → Stream stats → Builds shows), the extension can fill in a show you scheduled in the Service in TikTok’s LIVE Manager, when someone on that computer presses Build. It opens LIVE Manager in a new tab and works only in that tab: it reads the form’s field names and their values, the page’s headings and error messages, and the page address without its query string, sends them to the Service, and types and clicks what the Service answers, asking the person before anything is published. It never reads a password’s value and never types a password or a code. The Service uses Anthropic to work out each next step from that form and your show’s template; each step is logged with the page address, what was done, and what it cost, for as long as the scheduled show exists, and deleted with your account.

Sub-processors

These providers process data on our behalf to deliver the Service. Each receives only what its job needs.

Connected platforms are different: they are the systems you connect, and they are the source of your data rather than a processor of it. LASI reads from them on your behalf, and writes back only what your team decides, using access you can revoke at any time:

We will update this list before adding a sub-processor that handles customer data.

Data Security

Data is encrypted in transit (HTTPS/TLS) and at rest. Third-party OAuth tokens and API keys (TikTok Shop, Shopify, Homebase) are stored in the database encrypted with AES-256-GCM, using a key held only in the hosting provider’s secret store — the application refuses to store a token unencrypted in production. Every record is scoped to your organization and enforced by row-level security in the database, and access inside your organization is role-based. Full details are on the Security page.

Data Retention

Your Rights and Data Portability

Changes to This Policy

We may update this Policy from time to time. Material changes will be reflected by the “Last updated” date above.

Contact

Questions about this Policy or our data practices? Email support@trylasi.com.