Effective date: August 10, 2026
Security and privacy contact: support@getcaughtup.io
Review cycle: At least annually and after material product, provider, regulatory, or security changes.
1. Governance and risk management
The CaughtUp owner and operator is accountable for the program and acts as Security and Privacy Lead. Security decisions consider data sensitivity, Internet exposure, tenant impact, provider dependency, likelihood of misuse, and the effect of unauthorized disclosure. High-risk changes involving authentication, sending, secrets, personal data, or production access require explicit verification before release.
2. Access control
Access follows least privilege, need to know, and unique identity. Administrative access is limited to specifically authorized persons with an operational need. Multi-factor authentication is required wherever a provider supports it. User requests require authenticated identity and are scoped to the owning account. Public clients never receive service-role credentials, refresh tokens, or secret keys.
3. Data classification and encryption
CaughtUp classifies information as Public, Internal, Confidential, or Restricted. OAuth tokens, passwords, secret keys, and privileged credentials are Restricted. Internet traffic carrying account or personal data uses HTTPS and TLS. Sensitive integration configuration remains in server-side protected storage. Managed database and storage providers supply encryption at rest for hosted data.
4. Network and endpoint protection
Managed cloud services separate public delivery, application processing, database and private storage, authentication, and secret management. Public delivery uses Cloudflare edge protection and restrictive security headers. Backend data is protected through authenticated APIs, owner scoping, row-level security, private storage, and service-only roles. Company endpoints must use supported software, automatic security updates, antivirus, firewall protection, screen locking, device encryption where supported, and unique password-protected accounts.
5. Incident response and notification
Suspected unauthorized access, data exposure, malware, credential loss, service compromise, or material policy violation must be reported promptly. The Incident Lead records, triages, contains, investigates, remediates, and validates recovery. When an incident affects TikTok Shop, a seller, a creator, or personal data, CaughtUp will notify the affected party and any required authority without undue delay and within applicable legal or contractual deadlines.
6. Vulnerability and threat management
CaughtUp reviews application code, authentication boundaries, dependencies, provider advisories, error reports, and public exposure at least monthly and after material releases. Findings are prioritized by exploitability, exposure, data sensitivity, tenant scope, privilege gained, and operational impact. Secret exposure, authentication bypass, cross-user access, unauthorized sending, or public personal-data exposure is treated as urgent.
7. Personal data requests and deletion
Users, sellers, creators, and TikTok Shop may request access, correction, restriction, export, or deletion through the support channel. Identity and authority are verified before disclosure or change. After a verified deletion request or the end of the applicable relationship, customer data is removed from active systems without unreasonable delay, subject to limited legal, security, fraud-prevention, dispute, and backup-recovery exceptions.
8. Assurance and limitations
CaughtUp reviews this program at least annually and after material changes. CaughtUp uses security-conscious service providers, but a provider's certification does not certify CaughtUp. CaughtUp does not claim ISO 27001, ISO 27701, SOC 2 Type 2, ePrivacy, or another independent certification unless one is formally obtained.