Privacy Policy
Last updated: May 8, 2026
The small print on how we take care of your data.
Contents
- 1. Introduction
- 2. Information We Collect
- 3. How We Use Your Information
- 4. AI and Machine Learning
- 5. How We Share Your Information
- 6. Data Security
- 7. Data Retention
- 8. Your Privacy Rights
- 9. Cookies
- 10. International Data Transfers
- 11. GDPR Compliance (European Economic Area)
- 12. CCPA Compliance (California Residents)
- 13. Children's Privacy
- 14. Changes to This Policy
- 15. Contact Us
1. Introduction
This Privacy Policy describes how OperaX and its affiliates ("OperaX," "we," "us," or "our") collect, use, share, and protect personal information when you use our websites (operax.ai), applications (app.operax.ai), and related services (collectively, the "Services").
By using our Services, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use our Services.
2. Information We Collect
Information You Provide
- Account information: Name, email address, company name, password when you create an account
- Shop data: TikTok Shop credentials and OAuth tokens when you connect your store
- Payment information: Billing address and payment method details (processed by our payment provider; we do not store full card numbers)
- Communications: Messages you send us via contact forms, email, or support channels
- User content: Any configurations, rules, or preferences you set within the platform (commission tiers, approval criteria, outreach templates)
Information Collected Automatically
- Usage data: Features used, actions taken, pages visited, time spent, and interaction patterns within the platform
- Device information: Browser type, operating system, device identifiers, IP address
- Log data: Server logs including access times, pages viewed, and referring URLs
- Cookies and similar technologies: Session cookies for authentication, analytics cookies for understanding usage patterns (see Section 9)
Information from Third Parties
- TikTok Shop: Store performance data, creator information, order data, and campaign metrics accessed through authorized API connections
- Messaging platforms: Message metadata from Slack, Lark, WhatsApp, and other connected channels (only when explicitly configured by you)
- Analytics providers: Aggregated website analytics data
3. How We Use Your Information
We use the information we collect to:
- Provide and operate the Services: Connect your shops, manage creator relationships, process sample reviews, optimize ad campaigns, generate reports
- AI processing: Our AI agents process your shop data to execute operations (creator outreach, sample review, ad optimization, anomaly detection, morning reports). This processing is essential to delivering the core functionality of OperaX
- Improve our Services: Analyze usage patterns, identify bugs, develop new features, and optimize performance
- Communicate with you: Send service notifications, morning reports, anomaly alerts, and respond to your inquiries
- Security and fraud prevention: Detect and prevent unauthorized access, abuse, or fraudulent activity
- Legal compliance: Comply with applicable laws, regulations, and legal processes
4. AI and Machine Learning
OperaX uses AI agents to process your data and execute operations on your behalf. It is important to understand how this works:
Your individual data: Your shop data, creator information, and operational history are used exclusively to serve your account. We do not share your individual data with other customers.
Aggregated learning: We may use aggregated, anonymized data across the platform to improve our AI models, discover operational patterns, and enhance the quality of recommendations. This aggregated data cannot be traced back to any individual customer or store.
Opt-out: You may opt out of cross-platform aggregated learning at any time by contacting us at alex.yang@boostengine.ai. Opting out will not affect your access to the Services but may limit certain recommendation features.
Human oversight: All AI operations follow a tiered safety system. Read-only queries execute automatically. Write operations require your confirmation. High-risk operations require explicit approval. You maintain final authority over all decisions.
5. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
- Service providers: With trusted third-party providers who help us operate the Services (hosting, payment processing, analytics). These providers are bound by contractual obligations to protect your data
- Platform integrations: With TikTok Shop, Slack, Lark, WhatsApp, and other platforms you explicitly connect, only to the extent necessary to deliver the Services
- Legal requirements: When required by law, regulation, legal process, or government request
- Business transfers: In connection with a merger, acquisition, or sale of assets, with appropriate notice to you
- With your consent: When you explicitly authorize us to share information with a third party
6. Data Security
We implement industry-standard security measures to protect your information:
- Encryption: All data is encrypted in transit (TLS 1.2+) and at rest
- Access control: Strict role-based access controls and multi-tenant data isolation (x-shop-id isolation ensures your data is separated from other customers)
- Authentication: JWT-based authentication with SSO support
- Infrastructure: Hosted on enterprise-grade cloud infrastructure with regular security audits
- Monitoring: Continuous security monitoring and incident response procedures
No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
7. Data Retention
- Active accounts: We retain your data for as long as your account is active and as needed to provide the Services
- Account deletion: Upon account deletion request, we will delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes (such as resolving disputes or enforcing agreements)
- Aggregated data: Anonymized, aggregated data may be retained indefinitely for analytics and service improvement purposes
- Backups: Backup copies may be retained for up to 90 days after deletion for disaster recovery purposes
8. Your Privacy Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data (subject to legal retention requirements)
- Portability: Request your data in a structured, commonly used, machine-readable format
- Restriction: Request restriction of processing in certain circumstances
- Objection: Object to processing based on legitimate interests
- Opt-out of AI learning: Request that your data not be included in aggregated AI model training
- Withdraw consent: Where processing is based on consent, withdraw that consent at any time
To exercise any of these rights, contact us at alex.yang@boostengine.ai. We will respond within 30 days.
9. Cookies
We use the following types of cookies:
- Essential cookies: Required for authentication, session management, and security. These cannot be disabled
- Analytics cookies: Help us understand how visitors interact with our website. You can opt out through your browser settings
- Preference cookies: Remember your language and display preferences
We do not use advertising or tracking cookies. You can control cookie preferences through your browser settings. Disabling essential cookies may prevent you from using certain features of the Services.
10. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for such transfers, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA
- Compliance with applicable data transfer frameworks
- Contractual protections with all service providers
11. GDPR Compliance (European Economic Area)
If you are located in the European Economic Area (EEA), the following applies:
Legal basis for processing: We process your data based on: (a) your consent, (b) performance of a contract, (c) compliance with legal obligations, or (d) legitimate interests (such as improving our Services).
Data Protection Officer: For GDPR-related inquiries, contact alex.yang@boostengine.ai.
Supervisory authority: You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.
12. CCPA Compliance (California Residents)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know: What personal information we collect, use, and share
- Right to delete: Request deletion of your personal information
- Right to opt-out: Opt out of the "sale" of personal information (note: we do not sell personal information)
- Non-discrimination: We will not discriminate against you for exercising your CCPA rights
To exercise these rights, contact alex.yang@boostengine.ai or submit a request through our Contact page.
13. Children's Privacy
Our Services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at alex.yang@boostengine.ai.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on this page with a revised "Last updated" date
- Sending you an email notification for significant changes
- Displaying a notice within the platform
Your continued use of the Services after changes become effective constitutes acceptance of the updated policy.
15. Contact Us
If you have questions about this Privacy Policy, your data, or your privacy rights, contact us at:
OperaX
Email: alex.yang@boostengine.ai
Website: https://www.operax.ai/contact