Tideline (“Tideline,” “we,” “us”) provides a social media planning and publishing workspace. Contact us at privacy@tideline.club about this policy or a privacy request.
1. Data we process
- Account and workspace data: email address, user identifier, organization, membership, and role.
- Connected social account data: platform account identifiers, display name, username, profile image, connection status, and provider metadata needed to operate the connection.
- Publishing data: captions, uploaded media, schedules, platform settings, destination accounts, provider identifiers, delivery status, and error information.
- Performance data: post and account metrics made available by connected platforms or our publishing provider.
- Technical and support data: security events, request metadata, app diagnostics you choose to share, and correspondence with us.
The public website does not intentionally use advertising trackers. Cloudflare may process basic request and security data to deliver and protect the site.
2. Why we use it
We process data to authenticate users, operate workspaces, connect social accounts, store drafts and media, schedule and publish posts, show delivery results, provide support, secure the service, comply with law, and improve reliability. Where applicable, our legal bases include performing our contract, legitimate interests in operating and securing the service, consent for optional connections, and legal obligations.
3. Service providers and platforms
- Supabase provides hosted authentication, database, storage, and server-side functions used by Tideline.
- Outstand acts as our social publishing integration provider. Connection details and publishing content are sent to Outstand when needed to connect accounts and deliver or schedule posts.
- TikTok receives authorization requests and content you direct Tideline to upload or publish. TikTok handles data under its own terms and privacy policy.
- Cloudflare delivers and protects tideline.club and the OAuth callback proxy. The proxy only redirects an allowlist of callback query fields and is configured not to log authorization codes or tokens.
Other connected social platforms process content and account data according to their own terms. We do not sell personal data or use connected-platform data for targeted advertising.
4. TikTok connection data
When you authorize TikTok, the callback may include a short-lived authorization code, state value, granted scopes, or an error. Our Cloudflare callback route forwards only allowed fields to Outstand’s fixed callback endpoint. It does not exchange, persist, inspect, or intentionally log the authorization code. Outstand completes the connection and handles resulting credentials for the publishing integration. Tideline stores provider account identifiers and non-secret account metadata needed to display and operate your connection.
5. Retention
Account, workspace, connection, draft, media, publishing, and metrics data is retained while the relevant account or workspace remains active and as needed to provide the service. When an authorized deletion request is completed, we remove or de-identify covered data from active Tideline systems within 30 days. Residual copies may remain in encrypted backups for up to 90 days before rotation. We may retain limited records longer when required for security, dispute resolution, fraud prevention, or law.
Connected platforms and Outstand maintain their own retention schedules. Disconnecting an account stops future Tideline use but does not remove posts already delivered to a social platform.
6. Your choices and rights
You may disconnect a social account, revoke TikTok access, or request access, correction, deletion, portability, restriction, or objection where local law provides those rights. We may verify identity and authority before acting. See our data deletion instructions.
7. Security and international processing
We use access controls, scoped server functions, encrypted transport, and provider secret-handling controls intended to protect data. No service can guarantee absolute security. Our providers may process data in countries different from yours, subject to their contractual and legal transfer mechanisms.
8. Children
Tideline is a business productivity service and is not directed to children under 13 or the minimum age required in their jurisdiction. We do not knowingly collect children’s personal data.
9. Changes
We may update this policy as the service changes. We will revise the date above and provide additional notice when required.
10. Contact
Email privacy@tideline.club. Include the email associated with your Tideline account and the workspace concerned; never include a password or access token.