This Privacy Policy explains how TikPay collects, uses, discloses, and protects personal data when you use its token-launch, creator-reference, TikTok verification, wallet verification, creator-fee, and related services (the “Service”). It reflects the Service’s current data flows and does not describe advertising or tracking systems that TikPay does not use.
Data controller: [Operating legal entity to be added before production launch]. This identity and a monitored privacy contact must be completed before production launch.
1. Data TikPay processes
Token launches and creator references
TikPay processes the token name, ticker, description, image or image URL, public TikTok creator reference, launcher alias where supplied, launch settings, environment, provider, mint address, metadata URI, Pump.fun URL, launch status, timestamps, and transaction status or signature where available. If a launcher connects a wallet, TikPay may also process its public Solana address and signature-verification status.
TikTok Login Kit and creator verification
When you choose Connect TikTok, TikPay requests the user.info.basic and user.info.profile scopes. Subject to what you authorize and TikTok returns, TikPay receives an opaque TikTok account identifier, unique username, display name, and granted scopes. TikPay uses this information to match the signed-in account to the permanent creator reference.
TikPay stores the verification result, handle, provider, sandbox/live status, verification time, TikTok account identifier, display name, and scopes in verification or audit records. TikTok access tokens are used server-side only to retrieve the authorized profile and are not persisted by the current implementation. TikPay does not request private videos, direct messages, contact lists, or your TikTok password.
Wallet verification and creator claims
TikPay processes public Solana wallet addresses, the wallet-signed message and signature, verification provider and method, verification time, associated creator handle, and whether the record was created in a demo environment. TikPay also processes creator-fee events, allocation amounts, claim and payout amounts and status, relevant token or launch, transaction hashes, timestamps, provider references, and reconciliation or error status where applicable.
TikPay never asks for or stores seed phrases or private keys. A signature proves control of a public address for the stated purpose; it does not give TikPay custody of that wallet.
Images and user-submitted content
If you upload token artwork, TikPay processes the image file, file type, size, and a randomly generated storage path. Uploaded token art is stored so it can be displayed with the launch. Alternatively, TikPay may store an image URL you provide. Files are currently stored as submitted; TikPay does not strip embedded image metadata. Remove location, device, or other metadata before uploading if you do not want it retained with the file.
Browser, security, and operational data
TikPay creates short-lived, HTTP-only cookies for TikTok OAuth state, PKCE verification, and the expected handle. Equivalent single-use request records are stored server-side and expire after approximately 15 minutes. After verification, an opaque creator owner token and handle may be stored in your browser’s local storage so you can return to the claim flow; up to ten such sessions are retained on that device. Session storage is used briefly to prevent repeated reload loops after stale application files are detected.
The application records operational and audit events such as launches, verification outcomes, wallet binding, claims, payouts, and administrative actions, together with timestamps and relevant identifiers. Server and hosting infrastructure may also process ordinary request and security data, such as IP address, user agent, request time, status, and error information, to deliver, protect, and troubleshoot the Service. TikPay currently does not use advertising cookies or an in-app advertising analytics service.
2. How and why TikPay uses data
TikPay processes data to:
- provide token-launch, creator-reference, verification, wallet, claim, and payout features;
- match an authorized TikTok account to the referenced public username;
- verify control of a Solana wallet without collecting private keys;
- display public launches and creator references and maintain accurate fee records;
- prevent duplicate claims, fraud, impersonation, abuse, and unauthorized access;
- confirm blockchain activity, diagnose errors, secure the Service, and enforce its terms;
- comply with legal obligations and establish, exercise, or defend legal claims; and
- respond to rights requests, complaints, and support inquiries.
3. Legal bases
Where the UK GDPR, EU GDPR, or similar law applies, TikPay relies on one or more of the following legal bases: performance of a contract or steps requested before entering one; legitimate interests in operating, securing, documenting, and improving the Service and preventing fraud; compliance with legal obligations; and consent where the law requires it, including your choice to authorize TikTok profile access. You may withdraw consent at any time, without affecting processing already carried out lawfully. Some data is necessary to provide a requested feature; without it, that feature may not work.
4. Public information and blockchains
Token names, tickers, descriptions, artwork, creator references, mint addresses, public wallet addresses, launch status, fee or payout activity, and transaction hashes may be displayed publicly where needed for transparency and operation of the Service. Do not submit information you do not want associated publicly with a launch or wallet.
Public blockchains are transparent and independently replicated. Wallet addresses, balances, transactions, token activity, and transaction hashes written to Solana may be viewed and copied by anyone. Confirmed blockchain records generally cannot be changed, erased, or made private by TikPay, even if TikPay removes information from its own interface.
5. Creator verification does not imply endorsement
A creator reference may be added by a community member before the referenced creator interacts with TikPay. TikTok verification establishes control of the relevant account for TikPay’s creator and payout functionality only. It does not show that the creator authorized, created, reviewed, promoted, endorsed, supports, or is affiliated with a token. Receiving or claiming eligible fees does not by itself amount to endorsement or approval.
6. When data is shared
TikPay discloses or transmits data only as needed to operate the current Service, including:
- TikTok Login Kit: authorization requests are sent to TikTok, and TikTok returns the profile information you authorize. TikPay is independent from TikTok and does not represent that TikTok endorses, sponsors, or partners with TikPay.
- Solana, Pump.fun, wallets, and RPC services: public addresses, transaction data, token metadata, and signed transactions may be sent to or read from these services to perform or verify actions you request.
- DexScreener: TikPay may request public token-market information for display.
- Infrastructure providers: hosting, managed database, storage, security, and network providers process data on TikPay’s behalf to deliver and protect the Service.
- Legal and safety disclosures: data may be disclosed where reasonably necessary to comply with law, protect rights or safety, investigate abuse, or establish or defend claims.
- Business changes: data may transfer as part of a financing, reorganization, merger, acquisition, or sale, subject to appropriate safeguards and applicable law.
TikPay does not sell TikTok profile data or share it with advertisers.
7. International transfers
TikPay’s providers and public blockchain infrastructure may process data in countries outside your own. Where applicable law requires it, TikPay will use an approved transfer mechanism or other appropriate safeguard. Public blockchain data is globally distributed by design and is not confined to a single country.
8. Retention
TikTok OAuth request records and related cookies expire after approximately 15 minutes and are single-use. TikTok access tokens are not retained by the current implementation. Browser owner sessions remain until removed by the user, replaced by newer sessions, or cleared with site data.
Launches, immutable creator references, wallet proofs, fee events, claims, payouts, transaction references, and audit records are retained for as long as reasonably necessary to operate the Service, preserve transaction and anti-fraud integrity, resolve disputes, and meet legal obligations. Token artwork is generally retained while its launch remains available. TikPay will delete or anonymize personal data when it is no longer needed, unless retention is required or the data is on a public blockchain that TikPay cannot alter. Specific statutory retention periods will be applied once the operating entity and jurisdictions are finalized.
9. Security
TikPay uses measures designed to protect data, including server-side credential handling, short-lived and single-use OAuth state, PKCE, HTTP-only secure cookies, validation of submitted data, cryptographic wallet-signature checks, restricted database and storage access, randomized image paths, and audit records. TikTok secrets and access tokens are not sent to the browser. No service can guarantee absolute security. You are responsible for securing your wallet, devices, browser, and recovery materials and should never share a seed phrase or private key with anyone.
10. Your privacy rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, or objection; withdraw consent; and complain to a data-protection authority. These rights may be limited where data must be retained for legal, security, fraud prevention, transaction-integrity, or freedom-of-expression reasons, or where data exists on a public blockchain beyond TikPay’s control.
TikPay may ask you to verify control of the relevant TikTok account or wallet before acting on a request. Requests should be sent to: [Legal and privacy contact email to be added before production launch]. This placeholder must be replaced with a monitored privacy contact before production launch.
11. Children
TikPay is not directed to children under 18 and does not knowingly collect personal data from them. If you believe a child has provided personal data, use the contact method above.
12. Changes to this policy
TikPay may update this policy to reflect legal, security, technical, or product changes. Material changes will be identified by a new effective date and, where required, additional notice. Your use of the Service is also governed by the Terms of Service.
Effective date: September 23, 2026