At a glance
- Used to provide your serviceAccount, order, and team data helps you and authorized colleagues run your business. We do not sell it, rent it, or use it for advertising.
- Separated by organizationData is accessible only within the relevant organization. Its owner controls member access through roles and management scope.
- No TikTok password requiredTikTok accounts connect through official QR authorization. You can revoke access in TikTok or Star Captain.
- Sensitive credentials are encryptedTikTok authorization tokens and passwords entered into account inventory are encrypted. Password views are logged.
- Service providers are listedSection 4 lists TikTok APIs, public-data services, AI models, Tencent Cloud, and other providers, with their purposes and data involved.
- You have choicesYou can access, correct, export, or delete your data and close your account. Contact support or email us; we respond within 15 business days.
01Scope and who we are
This policy covers all services from Star Captain at our website and desktop service (xingduizhang.com), mobile website, Star Captain WeChat mini program, TikTok developer authorization app, and Star Captain Sync Assistant Chrome extension. Together, these are referred to as Star Captain or we.
Star Captain is an operations platform for TikTok commerce teams (organizations). The organization owner invites members and enters team and business data.Organizations are responsible for the data they enter or authorize, and decide how it is used. We process that data according to their settings and this policy.If you are a member, some of your information, such as name, role, attendance, and performance, is entered and managed by your organization. You may contact its owner or us with questions.
Star Captain is independent and is not an official TikTok product. Use of your TikTok account is also governed by TikTok's terms and privacy policy.
02Information we collect
We collect information needed to provide the features you use:
| Category | Information | Source | Purpose |
|---|---|---|---|
| Login account | Username or phone number, name, avatar, organization, and role. Login passwords are stored only as irreversible hashes. | Your registration or organization owner | Login, identity, and role-based access |
| Organization & team | Organization, departments, groups, roles, pay rules, clock-in times, network or location checks at clock-in, reports, tasks, and review records | Entered by owners or members; recorded at clock-in | Team operations, attendance, payroll, and reports |
| Authorized TikTok data | Account profiles, videos and metrics, Showcase and commerce permissions, orders, commission, and authorization tokens from official authorization | Your consent on TikTok's authorization page | Account dashboards, orders, performance, and restriction detection |
| Public TikTok data | Public profiles, public videos, views, likes, and other public metrics | Public-data services listed in Section 4 | Video and view refreshes, viral monitoring, and Showcase checks |
| Channel account QR sign-in (optional) | The channel account's TikTok login session on our dedicated server after you scan to sign in | Your voluntary QR sign-in | Syncing that account's current-day self-operated sales data only |
| Account inventory (optional) | TikTok accounts, passwords, email, devices, and network details entered by your organization | Organization members | Inventory and account assignment. Passwords are encrypted, limited to the requester, business staff, and owner, and every view is logged. |
| Business data | Partners, stores, commission, settlements, costs, product library, assignments, submitted videos, and screenshots | Entered or uploaded by members | Settlements, Profit & cost, and team collaboration |
| Toolbox submissions | TikTok links or uploaded audio and video, plus analysis, transcripts, and translations | Your submissions | Viral video teardown, transcription, and translation |
| WeChat mini program | WeChat openid for login; an avatar you choose; photos and files you select when saving images or uploading content | WeChat authorization or your actions | Login, avatar changes, saving posters, and uploads |
| Devices & logs | IP address, browser and device model, access time, and key action records, such as commission edits or password views | Generated during use | Security, troubleshooting, and audit trails |
We do not collect unrelated information, read your contacts, messages, or browsing history, or ask you to provide your TikTok login password.
03How we use information
- Provide account dashboards, order sync, team office, settlements, Profit & cost, reports, toolbox, and other features you use;
- Control data access by organization and role;
- Protect accounts and systems by detecting unusual logins, preventing abuse, and logging key actions;
- Provide support, troubleshoot, and improve the product using aggregate usage statistics rather than individual profiling;
- Meet legal obligations, including lawful requests from authorized authorities.
What we do not do
- Sell or rent personal information or organization data;
- Use your data for advertising or user profiling;
- Publish, send messages, follow accounts, or take other actions you did not initiate through an authorized TikTok account;
- Show one organization's data to another organization.
05Storage and retention
Star Captain's website and database are hosted in Hong Kong, China (Tencent Cloud). Channel QR sign-in sessions and public-data retrieval use servers in the United States. Some providers in Section 4 process data overseas. Using these features means you understand and consent to the related cross-border processing. We apply safeguards required by applicable law.
| Data | Retention |
|---|---|
| Login accounts and organization profiles | While the account exists; deleted or anonymized within 30 business days after closure |
| TikTok authorization tokens | While authorization is valid; removed after revocation, account deletion, or organization closure |
| Channel QR sign-in sessions | Until disconnected in Star Captain, signed out in TikTok, or expired |
| Orders, business, and team data | While the organization uses the service; deleted within 30 business days of its deletion request or closure, unless law requires otherwise |
| Account inventory passwords | While the organization uses the service; deletable at any time; access is logged |
| Toolbox uploads | Original files are removed after processing; analysis, transcripts, translations, and teardown screenshots are retained |
| Security and activity logs | Retained for security and audit needs; deleted with organization data after closure |
06How we protect information
- HTTPS encryption in transit across the site;
- Encrypted TikTok tokens and inventory passwords; login passwords stored only as irreversible hashes;
- Channel QR sign-in sessions stored separately on dedicated servers, used only to sync that account. Disconnect or sign out to remove the session;
- Organization separation and role-based access. Profit and cost are restricted to organization owners by default;
- Audit trails for key actions, including password views, commission changes, and data deletion;
- Regular encrypted database backups and server access limited to necessary operations staff.
No system can guarantee absolute security. If a security incident occurs, we will respond promptly and notify affected users and organizations as required by law.
07Your rights and how to use them
| Your request | How to proceed |
|---|---|
| Access or correct your profile | Use Personal center on desktop or My account in the mini program. Ask the owner to correct information entered by your organization. |
| Revoke TikTok authorization | Delete or disable the account in Star Captain, or remove Star Captain in TikTok's Settings and privacy → Security → Apps and services. |
| Disconnect channel QR sign-in | Disconnect in account details or sign that device out in TikTok. |
| Export data | Export orders and settlement statements on their pages. Contact support for a broader export. |
| Delete data or close an account | Contact support or email us. We verify identity before processing. Organization closure deletes all its data. |
| Withdraw consent, complain, or give feedback | Contact us using Section 14. We respond within 15 business days. |
Some member data is managed by the organization. We may need to confirm a correction or deletion with its owner, and will keep you informed of progress.
09Minors
Star Captain is for businesses and teams, not people under 18. We do not knowingly collect information from minors. Contact us if this happens and we will remove it promptly.
10Additional terms for TikTok user data
- We call TikTok APIs only within your authorization scope, and use the data only to display and calculate information for your organization in Star Captain;
- We do not sell or transfer TikTok user data or use it for purposes unrelated to the features you use;
- When authorization is revoked, we stop API access and remove tokens as described in Section 5;
- We follow TikTok developer terms and data-use policies.
11WeChat mini program permissions
The mini program requests permissions only when you use the relevant feature. Declining does not affect other features:
- Avatar and nickname: used when you choose to change your avatar;
- Save to photos: used when saving a sharing poster or QR code;
- Select video / file: used when uploading audio or video for translation;
- Clipboard: used when you choose Copy or Paste link.
12Star Captain Sync Assistant Chrome extension
Only after your action, the extension syncs Showcase authorization and business data from the currently signed-in TikTok channel account to the channel account you select in Star Captain.
- Information processed: the six-digit sync code you generate on desktop and enter manually, the resulting short-lived pairing credential, and the selected channel account identifier. Authentication cookies needed for the current TikTok login are handled only when you click Sync Showcase data.
- The extension does not read or sell passwords, browsing history, or unrelated website content, and does not display raw cookies.
- The sync code, selected account, and necessary settings are stored locally in Chrome extension storage. Authentication information is sent only over HTTPS to Star Captain to complete the sync, never for advertising, profiling, or marketing.
- Uninstalling removes local pairing information. To revoke synced authorization or delete server-side information, contact support through My account → Contact support in Star Captain.
Chrome Web Store user data commitment: Star Captain Sync Assistant collects, uses, and transfers user data only to provide or improve the single user-facing function described above, in compliance with the Chrome Web Store User Data Policy and Limited Use requirements.
13Policy updates
We may update this policy as features or legal requirements change, and will update the date shown here. Material changes to collection, purposes, or providers will be highlighted in Star Captain, with renewed consent where needed.
14Contact us
For questions about this policy or your data, contact us below. We respond within 15 business days after verifying your identity:
- Email: bd@xingduizhang.com
- Desktop or mini program: My account → Contact support

