Privacy Policy
Last updated: June 24, 2026
This Privacy Policy explains how socommerce.io collects, uses, and protects personal data. We operate in full compliance with the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679).
1. Data Controller & Processor Roles
socommerce.io is operated by Nory Es-Sadiki, registered in Spain under NIF/NIE Z3659698N, with registered address at Calle Tudela 30, 18007 Granada, Spain (“socommerce”, “we”, “us”, or “our”).
No Data Protection Officer has been appointed, as one is not legally required under GDPR Article 37 given the current scale and nature of our processing. For all data protection inquiries, contact us at info@socommerce.io.
As Data Controller: we act as the data controller for personal data we collect directly from you for account management, billing, communications, and operating the Service.
As Data Processor: when you use the Service to manage creator campaigns, affiliate outreach, or other activities on behalf of your own clients or end-users, we act as a data processor on your behalf, processing data only according to your instructions and the terms of our Data Processing Agreement (DPA), available upon request.
2. Information We Collect
Account & Profile Data
Personally identifiable information such as your name, email address, company name, billing address, and contact details, collected when you register, subscribe, or communicate with us.
Creator Data
To power our Creator Search and analytics features, we collect and process publicly available data about TikTok creators. This data is obtained from two sources: publicly available creator content collected via a third-party data provider, and, for a TikTok Shop you connect, data made available through the TikTok Shop Partner API. The data may include:
- TikTok username and public profile information
- Public content such as recent video captions, hashtags, and topics
- Engagement metrics (views, likes, comments, follower count)
- Estimated commerce performance, expressed only as a band/range (e.g. low / mid / high) and never as an exact figure
Because this data concerns publicly available information about creators, we process it on the basis of our legitimate interests in operating a creator-discovery service (GDPR Article 6(1)(f)). To keep costs sustainable and avoid redundant collection, enriched creator data is held in a shared cache that serves all users of the platform. It is retained only for as long as necessary to provide the feature and is periodically refreshed or deleted. Creators’ data remains subject to TikTok’s own privacy policy and terms.
Campaign & Business Data
Business data you upload or generate — creator lists, campaign configurations, briefings, scripts, affiliate performance metrics, and sales data. This is processed solely to provide the Service and remains your property.
Usage Data
Information about your interactions with the Service, including IP address, browser type, operating system, device information, pages viewed, features used, and the dates and times of your visits.
Cookies & Tracking Technologies
We use the following categories of cookies:
- Strictly Necessary Cookies — required for the Service to function (authentication, security). No consent required.
- Functional Cookies — remember your preferences and settings. Require consent.
- Analytics Cookies — help us understand how the Service is used. Require prior consent under the ePrivacy Directive.
You may withdraw consent to non-essential cookies at any time via your browser settings.
3. Legal Basis for Processing
We process personal data on the following bases under GDPR Article 6:
- Performance of Contract (Art. 6(1)(b)) — to provide, operate, and maintain the Service, process transactions, and manage your account.
- Legitimate Interest (Art. 6(1)(f)) — to improve platform performance, prevent fraud, monitor security, optimize the Service, and operate creator discovery using publicly available data. We have assessed that these interests are not overridden by your data protection rights.
- Consent (Art. 6(1)(a)) — for marketing communications you opt into, and for non-essential cookies.
- Legal Obligation (Art. 6(1)(c)) — to comply with applicable EU laws, regulations, and legal processes.
4. How We Use Your Information
- Provide, operate, and maintain the Service
- Process transactions and manage billing
- Match creators with brands based on search criteria and performance data
- Generate and deliver AI-powered scripts and campaign briefings
- Track campaign performance and analytics
- Communicate with you about your account, updates, and support
- Improve platform performance, prevent fraud, and ensure security
- Comply with our legal obligations
5. AI-Powered Features & Automated Processing
- AI Providers:AI script generation and content analysis are powered through OpenRouter, which routes requests to underlying large-language-model providers (currently Anthropic’s Claude models). A complete list of AI sub-processors is available upon request.
- Model Training: data submitted to AI features is used solely to generate the requested output and is not used to train third-party AI models, subject to the terms of our agreements with those providers.
- Automated Creator Matching (Art. 22 GDPR): creator recommendations are generated algorithmically from publicly available metrics and your search criteria. This does not constitute automated decision-making with legal or similarly significant effects under Article 22, as final creator-selection decisions are always made by you, the human user.
- Profiling: we do not profile individual users or creators for any purpose other than the creator-matching functionality described above.
7. Sub-processors
We use the following sub-processors to deliver the Service. All are reviewed for security and GDPR compliance and are contractually obligated to protect your data:
- Supabase(Ireland, EU — AWS eu-west-1): database (PostgreSQL), backend infrastructure, and Edge Functions. Data stored within the EEA, encrypted at rest (AES-256) and in transit (TLS).
- Vercel (EU / Ireland region): frontend hosting and API layer. Data encrypted at rest and in transit.
- OpenRouter: AI model routing for script generation and content analysis (routes to Anthropic Claude models).
- ScrapeCreators: collection of publicly available TikTok creator content used to enrich Creator Search.
A complete, up-to-date list of sub-processors is available on request at info@socommerce.io. We will notify users of material changes to this list at least thirty (30) days in advance.
8. International Data Transfers
socommerce.io is established in Spain. All primary data is stored and processed within the European Economic Area (EEA): our database and backend run on Supabase in Ireland (AWS eu-west-1), and our frontend and API run on Vercel in its EU (Ireland) region.
Some sub-processors (for example, AI model routing and creator-data collection) may process limited data outside the EEA. Where this occurs, we rely on appropriate safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission or an adequacy decision.
9. Data Protection & Security
- Encryption — sensitive data is encrypted in transit using TLS 1.2+ and at rest using AES-256.
- Access Controls — access to personal data is limited to authorized personnel under the principle of least privilege.
- Data Minimization — we collect and retain only the minimum personal data necessary.
- EU Data Residency — all primary data is stored within the EEA (Supabase, Ireland) and processed within the EEA (Vercel, Ireland).
- Infrastructure Security — network segregation, intrusion detection, and host monitoring are enforced by our managed providers, which maintain SOC 2 Type II and ISO 27001 certifications.
- Incident Response — we maintain a documented incident response policy that is reviewed regularly.
10. Breach Notification
In the event of a confirmed personal data breach, we will notify affected users and the Spanish Data Protection Authority (Agencia Española de Protección de Datos, AEPD) without undue delay and within seventy-two (72) hours of becoming aware of the breach, in accordance with GDPR Articles 33 and 34.
11. Your Data Protection Rights
As a resident of the European Economic Area, you have the following rights under GDPR. We respond without undue delay and at the latest within one month of receiving your request:
- Right to Access (Art. 15) — request copies of the personal data we hold about you.
- Right to Rectification (Art. 16) — request correction of inaccurate or incomplete data.
- Right to Erasure (Art. 17) — request deletion of your data, subject to legal exceptions.
- Right to Restrict Processing (Art. 18) — request that we limit processing.
- Right to Object (Art. 21) — object to processing based on legitimate interests.
- Right to Data Portability (Art. 20) — request transfer of your data in a structured, machine-readable format.
- Right to Withdraw Consent (Art. 7(3)) — withdraw consent at any time without affecting prior lawful processing.
- Right to Lodge a Complaint — with the AEPD (aepd.es) or your local EU data protection authority.
To exercise any of these rights, contact us at info@socommerce.io.
12. Data Retention & Deletion
- Account Data — retained for the duration of your account and for up to thirty (30) days after deletion.
- Creator Data — retained only as long as necessary to provide Creator Search, then periodically refreshed or deleted.
- Usage & Analytics Data — retained in identifiable form for up to twenty-four (24) months, then anonymized or deleted.
- Billing Records — retained for up to seven (7) years as required under Spanish and EU tax law.
- Campaign & Creator Lists — retained for the duration of your active subscription and deleted within thirty (30) days of account termination upon request.
- API Tokens — deleted upon disconnection of the integration or termination of your account.
13. Data Processing Agreement
For users who require a formal Data Processing Agreement (DPA), we offer one covering the scope and purpose of processing, sub-processor management, data subject rights assistance, breach notification, and data deletion upon termination. To request a DPA, contact info@socommerce.io.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. For material changes, we will post a prominent notice on our website or email the address associated with your account at least thirty (30) days before the changes take effect.
15. Contact Us
For any questions about this Privacy Policy or to exercise your data protection rights:
socommerce.io
Operated by Nory Es-Sadiki
NIF/NIE: Z3659698N
Calle Tudela 30, 18007 Granada, Spain
Email: info@socommerce.io