Privacy Policy
Last updated: September 27, 2026
LASI (“we,” “us”) provides software that live-auction sellers use to run their business: inventory, live shows, orders, and profit reporting (the “Service”). This Policy explains what data moves through the Service, who can see it, and how long we keep it.
The plain version: your business data is yours. The customer — the auction-selling business that opens an account — is the controller of its data. LASI is a processor: we handle that data only to run the Service for that customer, on that customer’s instructions. We do not sell it, we do not use it for advertising, and we do not read it to run our own business.
Related documents: Terms of Service, Data Processing Addendum, and the Security page.
Information We Process
- Account data for each person on your team: name, email address, and role. Used for sign-in and for deciding what each person can see inside your organization.
- Business records your team enters: inventory and product details, purchase costs, sales, shows, expenses, and — where you connect Homebase — your staff schedule, timecards, and wages.
- Order data from platforms you connect (TikTok Shop, Shopify): order identifiers, timestamps, line items, quantities, prices, fees, order status, and the buyer’s display name or username, so you can match orders to what sold on stream; and, from TikTok Shop, buyers’ return, refund and cancellation requests (the reason, status, returned items, refund amount, the return package’s tracking number and carrier, TikTok’s timeline of the request including any note the buyer or your team wrote, and the buyer’s TikTok id and display name so repeat returns can be recognised), so returns can be matched to how the order was packed and decided from LASI. Photos or videos a buyer attaches to a return are shown from TikTok while a page is open and are never copied. When a returned package reaches your warehouse, the photos your team takes of it at the Returns desk (from a webcam, a computer, a phone link or the LASI phone app) are stored privately with the return, with what each item looked like. When your team rejects a return from LASI with photos, those photos are sent to TikTok with the decision, as Seller Center would send them.The platform sync does not store buyer shipping addresses or phone numbers. A working copy of recent orders (ids, times, status, amounts, the items and the buyer’s display name — never an address, phone or email) is kept so screens can read what changed instead of the whole day again, and is deleted 24 hours after its last use.
- Shipping labels you buy through LASI: when you buy a show’s labels on your own carrier account, the box keeps the address the label was bought for — the buyer’s name, street, city, state and ZIP — together with the tracking number and what is in the box, so the packing slip that goes out with the label can be printed at your bench. The same details are printed on the label itself. Used only to ship that box; visible to your team; deleted with the show or with your account.
- Customer-service records your team enters: a replacement request carries the buyer’s name, TikTok username and shipping address as typed by your agent, the order number, a description of the problem, and any photos of the item they attach. Used only to approve and ship the replacement; visible to your team, never to other customers of LASI; deleted with the request or with your account. When your team marks whose mistake a return was, LASI keeps the team member the mark names (a host, the packer who sealed the box, or someone else), what went wrong, any note, and who made the mark. Seen by your admins, managers and customer service (a packer’s name by admins and managers only), never sent to TikTok or the buyer; deleted with the return or with your account.
- Barcodes your team scans to identify products.
- Billing identity, handled by Whop: the email and plan attached to your subscription. Card details are entered on Whop’s checkout and never touch LASI.
- Usage and audit records: which account performed accountable actions (finalizing or deleting a show, exporting data, removing a team member), API-token activity, and integration sync logs.
- Server error reports: when a page or request fails on our servers, we record the page (without anything after the “?” in its address), the error message with any email address masked, and which business it happened in, so we can fix it. Never the request’s contents. Kept for 30 days, and deleted with your business.
- Counts of visits to our public pages. When an AI company’s crawler reads one of our public pages (the marketing site and the User Guide), or a person arrives at one, we add one to a daily tally of the page and where the visit came from — a crawler’s name, or for a person the kind of place by name (a search engine such as Google, an AI assistant such as Claude or ChatGPT, a social network, another website, or nowhere at all), never the full address of the page you came from. The tallies hold no IP address, cookie, browser details or anything else about the visitor, and they are not kept for pages inside the app.
- A launch-waitlist email address, if you ask us to tell you when signups open. We keep the address you typed, which page you asked from, the first page of our site you arrived on and where that visit came from (named as in the tally above), any referral code that brought you to the site, and the date — nothing else, and no IP address or browser details. To know that first page, your own browser keeps a small note of it (the page and where you came from) in its local storage for 30 days; the note leaves your browser only if you send the form. It is used for two things: telling you that signups are open, and knowing which of our pages are worth improving. It is never sold, never shared, and you can ask us to delete it at any time at the address below.
How We Use Information
Only to provide the Service to the organization the data belongs to: tracking stock and cost, matching platform orders to live-show sales, calculating cost of goods and profit, forecasting reorders, running payroll and scheduling views, sending the notifications you turn on, billing your subscription, and keeping the Service secure. Nothing here is used for advertising or profiling, and personal information is never sold.
What LASI Staff Can See
We do not read your business data to run our business. Here is exactly what our side looks like:
- Platform operators are a fixed allowlist of named accounts. It is not a role a customer can grant, and no tenant role — not even your Admin — turns into an operator.
- The operator console shows organization names, subscription and billing status, integration connection health, an audit trail of administrative actions, and how our own public site is doing (the visit tallies above, the launch waitlist, and Google Search Console’s figures for our pages). It doesnot show inventory, costs, sales, orders, or profit.
- There is no “log in as customer” feature.
- Every operator console visit is itself recorded in the audit log.
- Automated nightly jobs — the reorder forecast digest, show autopilot drafts, platform order pulls, payroll sync, and OAuth token refresh — read each organization’s data to produce that organization’s own reports and notifications. They never move data between organizations.
The Stream Stats browser extension
If you install our optional Chrome extension on a computer you stream from, it reads the numbers shown on your own TikTok LIVE dashboard — viewer counts, likes, comments, shares, new followers, product impressions and clicks, orders and sales totals — together with the short labels printed beside them, the address of the dashboard page without its query string, the id of the LIVE room it shows, and the page title, and sends them to your account in the Service every few seconds while the dashboard is open. Apart from the sale snapshots described below, which are off until you turn them on, it reads nothing else on the page, never a buyer’s or a viewer’s name and never a message, and it sends only to the Service. It runs only on the two TikTok Shop LIVE dashboards — the LIVE Data Screen and the Streamer Desktop — and on no other page, TikTok’s or anyone else’s. Readings are kept for 90 days. A summary of each stream built from them — when it started and ended, its peak and totals, and a minute-by-minute record of those same figures — is kept for as long as your account exists, so streams can be compared; it holds nothing about any viewer or buyer. Both are deleted with your account.
Stream figures from TikTok. Where your TikTok Shop connection allows it (TikTok’s “TikTok Shop Analytics” permission), the Service also reads each of your LIVEs from TikTok’s Partner API — the same kinds of figures: viewer, like, comment, share and new-follower counts, product impressions and clicks, items sold and sales totals, the LIVE’s title, room id and the handle of your account that streamed it, and, once it ends, the same figures minute by minute — and keeps them exactly as it keeps the extension’s readings, above. If a TikTok account you go live from signs in to the Service for TikTok’s “Live Data” permission, the Service stores that sign-in’s access tokens, encrypted, with the account’s TikTok id and display name, and uses them only to read how many people are watching that account’s LIVE and its peak: counts, never who they are. An admin can disconnect the account in Settings at any time, which deletes the tokens, and the account can withdraw the permission in TikTok.
Sale snapshots. The extension can also keep a still picture of your own LIVE video at each item your show sells. It is off unless an admin of your organization turns it on in Settings → Integrations → Stream stats; until then nothing is captured, on any computer. A snapshot is a frame copied from the video itself, together with that item’s auction number, the price it sold for and the time — so the chat, the viewers, their names and their messages are never in it, and neither is anything else printed beside the video on the dashboard. Snapshots are kept for 90 days, and longer while a return, a replacement or a dispute points at that sale, so the picture outlives the argument it exists to settle; after that they are deleted automatically. They are deleted with your account.
If you also turn on heard sizes, the extension listens to your stream’s own sound on that computer to catch the size your host says out loud. The listening happens entirely on that computer, using the speech model built into Chrome, and needs a one-time click on the dashboard to install it. No audio and no transcript is sent anywhere or stored — only the size word itself (“XL”, “size 10”) is kept, stamped on that item’s snapshot and always marked as heard rather than scanned.
Following your next LIVE. TikTok starts every LIVE in a new room and leaves your dashboard tabs on the one that ended. When the LIVE a Streamer Desktop tab shows has ended and TikTok says another LIVE of yours is on, the extension presses TikTok’s own “Switch to this LIVE” button on that tab, and then points a LIVE Data Screen still showing the old LIVE at the new one. It does this only on a tab nobody has used for five minutes and with no form open, never while the computer is building a show, and it clicks nothing else. It reads the new LIVE’s room id from the Streamer Desktop’s own link to that LIVE’s dashboard, and it tells the Service which rooms it moved to by itself, so the Service does not file such a stream under a show on the computer’s word alone.
Building shows. If an admin lets a computer build shows (Settings → Integrations → Stream stats → Builds shows), the extension can fill in a show you scheduled in the Service in TikTok’s LIVE Manager, when someone on that computer presses Build. It opens LIVE Manager in a new tab and works only in that tab: it reads the form’s field names and their values, the page’s headings and error messages, and the page address without its query string, sends them to the Service, and types and clicks what the Service answers, asking the person before anything is published. It never reads a password’s value and never types a password or a code. The Service uses Anthropic to work out each next step from that form and your show’s template; each step is logged with the page address, what was done, and what it cost, for as long as the scheduled show exists, and deleted with your account.
Sub-processors
These providers process data on our behalf to deliver the Service. Each receives only what its job needs.
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Whop — subscription billing and our affiliate program.
- Resend — team-invitation email, where enabled.
- Anthropic — the in-app assistant (Ask LASI), building shows in TikTok’s LIVE Manager (above), and invoice reading, where enabled. When someone asks the assistant a question, Anthropic receives the question, the recent conversation, and the figures LASI looks up to answer it — only what that person’s role can already see in LASI, such as bin counts, show and sales figures, or their own commission. A buyer’s name, address, phone and email are removed first. For invoice reading, it receives the supplier invoice (a PDF or photos) you choose to upload so its lines can be read; an uploaded invoice is kept in your own private storage so it can be read again. LASI does not store the questions or the answers; it keeps only a count of how much the assistant is used.
- Expo — push notifications to the mobile app, and the app’s updates. When the app checks for an update it sends only what picks the right one: the app’s platform and version, which update it is running, and a random identifier for that installation (plus a technical error report if an update fails to start), never your account or business data. For notifications it receives the notification text, such as low-stock and show-close reminders. A sale notification’s text includes a sales figure (for example the day’s sales so far, or one order’s total) and goes only to your organization’s admins and managers; it never names a buyer. The mobile app’s home-screen widget shows sales figures the app saved on that phone; they are not sent anywhere to draw it.
- UPCitemdb and Barcode Lookup — barcode identification. Receive only the scanned digits.
- PrintNode — silent label printing at the packing bench, where you connect a printer. Receives the shipping-label and hold-tag PDFs you print, which carry the buyer’s name and shipping address, and holds them only long enough to deliver them to your printer.
- Shippo — buying a replacement’s shipping label, where you connect a Shippo account. Receives the buyer’s name, shipping address and phone number, your ship-from address, and the box size, so the carrier can rate and print the label; the postage is charged to your Shippo account.
- UPS — pricing and buying a show’s shipping labels, where you connect your own UPS account and an admin turns buying on. Receives the buyer’s name, shipping address and — where your order data carries one — phone number, together with the box’s weight and size and your ship-from address, so UPS can rate the shipment and issue the label. The postage bills to your UPS account; LASI is not a party to the carriage.
- GitHub — hosts our source code and runs the hourly scheduled-sync trigger. Receives no customer data, only a signed trigger.
Connected platforms are different: they are the systems you connect, and they are the source of your data rather than a processor of it. LASI reads from them on your behalf, and writes back only what your team decides, using access you can revoke at any time:
- TikTok Shop — orders, live-session data, settlements, and return, refund and cancellation requests, via the official Partner API; once an admin turns it on, the decisions your team makes on those requests (and the photos attached to a rejection), the refunds and cancellations your team starts on an order, and the tracking number of each box whose label you buy in LASI, are sent back the same way.
- Shopify — products, inventory levels, and orders; inventory sync runs both ways where you enable it.
- Homebase — schedules, timecards, and wages, read-only.
We will update this list before adding a sub-processor that handles customer data.
Data Security
Data is encrypted in transit (HTTPS/TLS) and at rest. Third-party OAuth tokens and API keys (TikTok Shop, Shopify, Homebase) are stored in the database encrypted with AES-256-GCM, using a key held only in the hosting provider’s secret store — the application refuses to store a token unencrypted in production. Every record is scoped to your organization and enforced by row-level security in the database, and access inside your organization is role-based. Full details are on the Security page.
Data Retention
- Active account: your data is retained for as long as your account is active.
- After you delete your business: primary database records are deleted immediately (a cascading delete across every table that carries your organization). Provider backups age out within 30 days.
- Legal holds: audit and billing records the law requires us to keep — invoices and the payment ledger — are retained for 7 years.
- Buyer display names in your sales records are part of your business records and are deleted with them.
- Server error reports: 30 days.
- When a platform is disconnected: the stored access for it (its tokens or keys) is deleted at once and nothing more is read from it. That happens when an admin presses Disconnect in Settings, and for TikTok Shop also when you remove LASI’s access in TikTok Shop itself, which TikTok reports to us. What was already imported stays with your business records and is deleted with them, or earlier if you ask.
Your Rights and Data Portability
- Export: an organization admin can export the entire organization as JSON at any time from Settings → Your Data.
- Delete: an admin can delete the business from Settings → Account on the web, or from the mobile app’s Delete account screen.
- Anything else — access, correction, or a request from one of your buyers that reaches us directly — email support@trylasi.com. We refer buyer requests to the business they bought from unless the law prevents it, and respond in accordance with applicable law.
Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by the “Last updated” date above.
Contact
Questions about this Policy or our data practices? Email support@trylasi.com.