TikPay signal
Privacy policy
Effective date: set one before publishing. Draft for review before publishing.
Sandbox mode. Demo environment. TikTok verification, Pump.fun launches, creator-fee events and treasury actions are simulated sandbox records. Wallet connection and signature checks are real and verify actual keys.
This policy is written for the current build of TikPay. It describes what this website stores today. It is a draft prepared by the builders, not legal advice — have it reviewed before the site is published or a TikTok app is submitted for approval.
Who we are
TikPay is operated by the TikPay project (no legal entity registered yet). Questions about this policy, or any request to exercise your rights, go to legal@tikpay.example.
What we store
- Launch details you submit. Token name, ticker, description, image link, the TikTok handle you assign, and launch settings such as initial buy size and slippage limit. These are stored so a launch can be shown, audited and attributed.
- Verification records. For a TikTok handle: the challenge code issued, when it was checked, the result, and which provider performed the check. When real TikTok sign-in is connected, this also includes the account identifier and public profile information TikTok returns — display name, avatar and the TikTok user ID.
- Payout wallet address. Stored against a verified handle so creator fees can be attributed to the right wallet. We store the address and the signature you produced; we never store a private key or a seed phrase, and we have no way to generate one.
- Ownership session on your device. After a handle is verified we keep a random token in this browser so you can return to the claim flow. Clearing site data removes it; it grants access only to the verification you already completed.
- Fee and claim records, and an audit log. Each fee event, claim hand-off and administrative action is stored with its actor and timestamp so the history can be reconstructed and never double-counted.
What we never store or hold
- Private keys, seed phrases, or any material that could move funds.
- Custody of creator fees. Fees accrue on Pump.fun and are claimed by you, to your own wallet.
- Passwords for third-party services, including TikTok.
Why we process it
To attribute a token launch to a creator, to check that the person claiming a handle controls it, to bind a payout wallet that the claimant demonstrably owns, and to keep an auditable record that prevents a fee being paid twice for the same event.
TikTok data specifically
- We request the minimum TikTok profile information needed to confirm that a handle belongs to the person using it. We do not ask for private videos, direct messages or contact lists.
- TikTok access tokens are held on our servers, never in your browser, and are used only to read the profile information described above.
- We do not sell TikTok data, and we do not share it with advertisers. TikTok data stays inside TikPay's own storage for the purpose it was collected.
- You can disconnect at any time by asking us to delete your verification record; the steps are in the "Your rights" section.
Where it is stored and for how long
Data is stored in a managed Postgres database with row-level security, in the region configured for this project. Launch and audit records are kept while the token exists and for as long as we are required to be able to reconstruct who did what. Verification sessions expire on their own. Anything we no longer need is deleted.
Your rights
You can ask us to show you what we hold about your handle or wallet, correct it, or delete it. Email legal@tikpay.example from an address you can prove you control, or sign in with the verification you made and tell us which handle. Deletion of a verification record also removes the link between a handle and a payout wallet; launch and audit entries that describe a token's history are retained in a minimised form because they are the record of what happened.
Cookies and analytics
This site does not use advertising cookies. Hosting and error monitoring may record standard request metadata such as IP address, user agent and timing, which is used to keep the service running and to diagnose failures.
Third parties
DexScreener and a Solana RPC node are queried for public market and mint data. Wallet extensions act on your own device. A payment or hosting provider may process data on our behalf under their own terms. No creator funds pass through TikPay at any point.
Security
Every write is server-side and validated; database access is scoped by row-level security; fee events are idempotent so a retried request cannot double-count; and every state change is written to an audit log. No system is unbreakable — if you believe you have found a weakness, tell us at legal@tikpay.example.
Children
TikPay is not directed at people under 18, and we do not knowingly collect their data.
Changes
If this policy changes in a way that matters to you, we will say so on this page with a new effective date before relying on the change.