Privacy Policy
Last updated: 9 August 2026
NorthStar Finds (“we”, “us”) operates northstarfinds.co.uk. This policy explains what happens when you connect your TikTok account to NorthStar Finds, and what we do — and do not do — with your information.
1. What this integration is for
NorthStar Finds uses TikTok's Login Kit and Content Posting API so that an authorised NorthStar Finds operator can review short-form product videos and upload them to a connected TikTok account's inbox as drafts. NorthStar Finds does not automatically or publicly post content on your behalf. Direct Post is not implemented — every video is delivered to your TikTok inbox as a draft that you review and publish yourself inside the TikTok app.
2. Information we request from TikTok
When you authorise NorthStar Finds via TikTok, we request:
- Basic account information (scope
user.info.basic): your TikTok open ID, display name and avatar URL, so we can show you which account is connected. - Video upload permission (scope
video.upload): permission to upload a video to your account's inbox as a draft. We do not use this permission to read, download or analyse your existing TikTok videos.
We do not request or receive your TikTok password. Authorisation happens entirely on TikTok's own sign-in and consent screens.
3. How we use this information
We use your TikTok open ID and display name only to show you the correct connected account and to address the upload request to the right account. We use the upload permission only when you explicitly choose a video and explicitly click to upload it — nothing is uploaded automatically or without your action.
4. Token and security handling
TikTok issues an access token and refresh token when you authorise the connection. These tokens are handled server-side only: the client secret and every token are read from server-only configuration or held in server-side session state, and are never sent to your browser as readable values, embedded in page source, written to application logs, or included in error messages. We do not sell, rent or share your TikTok data with third parties, and we do not use it for advertising.
5. Data retention
In the current version of this integration, connection state is held only for the duration of your active session on this server and is not written to a permanent database. A production deployment may introduce longer-lived, encrypted server-side storage for connected-account state; this policy will be updated first if that changes, and retention will always be limited to what is needed to operate the feature you requested.
6. Revoking access
You can disconnect NorthStar Finds at any time from within the TikTok app (Settings and privacy → Security → Manage account connections), which immediately invalidates the tokens issued to us. You may also contact us using the details below to request that any data we hold about your connection be deleted.
7. Other information
Pages on this site that are not part of the TikTok integration (such as this policy page itself) do not use analytics, advertising trackers or non-essential cookies.
8. Contact
For privacy questions or deletion requests, see our Contact pagefor our monitored contact address.