KingKung · Seller Center (TikTok Shop OMS) |
Document ID: PIPS-KK-2026-1.1 |
Classification: Internal — Data Protection
Personal Information Protection Standard
Version 1.1 · Effective June 2026 ·
Review cycle: Annual · Primary data region: Singapore
1. Purpose and scope
This Personal Information Protection Standard (“PIPS”) defines how SINGAPORE KINGKUNGMEDIA PTE. LTD. (“KingKung”, “we”, “our”) protects personal data and TikTok Shop merchant data processed through the KingKung Seller Center OMS and related integrations.
This standard applies to:
All employees, contractors, and administrators with access to production systems
All environments that store or process TikTok Shop OAuth tokens, order data, product data, or seller account metadata
Third-party infrastructure providers engaged under written confidentiality obligations
Public privacy notice: https://apitt.douking.vip/privacy.php
2. Roles and responsibilities
Role
Responsibility
Management
Approves this standard, security resources, incident escalation
KingKung maintains this PIPS and related procedures covering acceptable use, authentication, remote access, change management, and vendor management. Reviewed at least annually and after material incidents.
4. Network security and monitoring
Production hosted on Alibaba Cloud (Singapore) with security groups: public HTTPS (443); admin SSH restricted by IP allowlist
Assessment — scope, data categories, affected merchants
Notification — TikTok Partner support and merchants within 72h if breach confirmed
Remediation — patch, rotate credentials, root cause
Post-incident review — update controls within 30 days
Incident reports retained ≥ 3 years.
10. Privacy, merchant rights, and data lifecycle
Assist access, correction, deletion, export within 30 days where feasible
Disconnect OAuth → stop API calls; delete tokens within 30 days
Contract end → delete/return data within 90 days
No sale of personal data
11. Training and awareness
Security orientation before production access; annual refresher; developer training on TikTok API credential handling.
12. Subprocessors
Primary: Alibaba Cloud (Singapore) — hosting and networking under provider confidentiality terms.
13. Compliance statements
No reportable personal data breach in the past 3 years (as of document date)
No unresolved regulatory complaints in the past 3 years
ISO 27001 / SOC 2: not certified; controls aligned with this PIPS
14. Document control
Version
Date
Changes
1.0
2024
Initial personal data protection policy
1.1
June 2026
Expanded to TikTok Partner PIPS format
Approved by:
Management — SINGAPORE KINGKUNGMEDIA PTE. LTD.
Date: June 2026
Confidential — Internal use. Upload PDF to TikTok Shop Partner Center → Data Security & Privacy Questionnaire.
Filename suggestion: Personal_Information_Protection_Standard_KingKung_2026.pdf