Privacy Policy
Last updated: June 14, 2026
This Privacy Policy describes how HAMMR (“we,” “us”) collects, uses, and protects information in connection with our internal inventory, purchasing, and sales-management application (the “Service”). The Service is a back-office business tool that we operate for our own TikTok Shop live-auction business; it is not a consumer-facing product.
Information We Process
- Order & sales data from our connected TikTok Shop: order identifiers, timestamps, product and SKU details, quantities, sale prices, fees, order status, and the limited buyer/recipient information necessary to reconcile and fulfill orders.
- Inventory & purchasing records that we enter: products, suppliers, purchase orders, costs, and supplier invoices.
- Account data for the staff who use the Service (name, email, role) for authentication and access control.
How We Use Information
We use this information solely to operate our business: tracking inventory and stock costs, matching TikTok Shop orders to items sold during live auctions, calculating cost of goods and profit, and managing purchasing and fulfillment. We do not sell personal information and do not use it for advertising or profiling.
Data Minimization
We use only the data needed for order reconciliation and business reporting. Buyer personal details are used only to the extent necessary to identify and fulfill an order; they are not displayed in our analytics and are not shared beyond the service providers listed below.
Service Providers
We share information only with vetted providers who process it on our behalf to deliver the Service:
- TikTok Shop — the source of our order and sales data, accessed via the official TikTok Shop Partner API.
- Supabase — database and authentication hosting.
- Vercel — application hosting.
- Anthropic — AI used only to read uploaded supplier invoices for data entry; it does not process customer order details.
- Shopify — where connected, to synchronize our own product and inventory data.
Data Security
Information is encrypted in transit (HTTPS/TLS) and at rest. Access requires authentication and is restricted by role, and each account’s data is isolated at the database level using row-level security. API credentials and tokens are stored as protected environment secrets, never in our source code. See our Information Security Policy for details.
Data Retention
We retain business records for as long as needed for operational, accounting, and legal purposes, after which they are deleted or anonymized.
Your Rights
To request access to, correction of, or deletion of personal information we hold, contact us at mshenbaum@gmail.com. We will respond in accordance with applicable law.
Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by the “Last updated” date above.
Contact
Questions about this Policy or our data practices? Email mshenbaum@gmail.com.