Legal
Privacy Policy
Effective September 23, 2026
JS Data and Media Consults, Inc. ("js data", "we", "us") builds and operates data pipelines that move our clients' commerce and advertising data from the platforms they sell and advertise on into data warehouses that our clients own. This policy explains what data we access, why, and how we handle it.
The short version: we access only the data our clients authorize, we use it only to deliver the services they hired us for, it lands in a warehouse they own, and we never sell it or share it with anyone else.
Who we are
JS Data and Media Consults, Inc. is a United States data consultancy. For anything in this policy, contact jon@jsdata.ai.
In privacy terms, we act as a service provider / data processor on behalf of our clients — the brands whose accounts we connect to. Each client remains the owner of, and the controller for, its own data.
What data we access
We connect to platforms exclusively through their official APIs, and only after a client explicitly authorizes our access to their specific account. Depending on the platforms a client uses, that data includes:
- Commerce platforms (Shopify, TikTok Shop, Amazon Seller Central)
- Orders, products, inventory, settlements and payouts, and shop or product analytics for the client's own store.
- Advertising platforms (Meta, TikTok Ads, Google, Amazon Ads)
- Campaign structure and aggregated performance metrics — spend, impressions, clicks, conversions — for the client's own ad accounts. We do not access or store profiles, browsing activity, or other personal information about the individuals who see or interact with ads.
Personal data minimization
Our pipelines are built to carry as little end-customer personal data as each engagement allows. For example, our TikTok Shop pipeline stores no buyer names, phone numbers, email addresses, or street addresses: geography stops at city level, and repeat-purchase analysis uses only the privacy-safe, platform-provided buyer key rather than any identifying information. Where a platform offers a reduced-data option, we take it; where a client engagement requires customer-level data (for example, Shopify customer records for lifetime-value analysis), we process it solely on that client's instructions and deliver it only into that client's warehouse.
Your js data account
When you connect a TikTok Shop through jsdata.ai/connect, you create a js data account so you can see your connected shops and the status of your data syncs. For that account we collect your name, work email address, and company name, and a password that we store only as a salted one-way hash (we cannot read it). If you choose Sign in with Google instead, we receive only your name, email address and Google account identifier from Google, and no password. We set a single sign-in cookie that is strictly necessary to keep you signed in; we use no advertising or tracking cookies. Shop metrics shown in your account are fetched from the platform when you view them and cached for up to one hour. We use your account details only to operate your account and to contact you about the service, and we delete them on request or within 30 days of the end of an engagement.
How we use data
- Solely to deliver the pipeline, reporting, and analytics services each client has contracted for.
- Never sold, rented, or disclosed to third parties.
- Never used for our own marketing or advertising.
- Never combined across clients — each client's data is processed for that client alone.
- Never used to train machine-learning or AI models.
Where data lives
Pipeline output is delivered into infrastructure the client owns — typically an Amazon Redshift, Google BigQuery, or Snowflake warehouse in the client's own cloud account. For managed pipelines, data may transit our own infrastructure (hosted on Amazon Web Services in the United States) for extraction, staging, and processing before it lands in the client's warehouse. AWS is the subprocessor we ordinarily use to deliver these services, and we remain responsible for it.
Retention and deletion
- Data in a client's own warehouse belongs to the client and is retained under the client's control.
- Platform credentials and tokens, and any client data held on our infrastructure, are deleted within 30 days of the end of an engagement (excluding routine backups, which age out on schedule).
- Clients and platform account holders can request deletion at any time — see our data deletion instructions.
- When a client revokes our platform access (for example in Meta Business Settings, TikTok Seller Center, or Amazon's Manage Your Apps), that access ends immediately, and we honor platform-issued deletion and revocation signals.
Security
- Access is authorized through each platform's official OAuth or partner-authorization flow — we do not ask clients for passwords to their platform accounts.
- Credentials and tokens are stored encrypted, and data is encrypted in transit (TLS) and at rest.
- Access is limited to personnel who need it to deliver the services, under confidentiality obligations.
- If we become aware of a security incident affecting client data, we notify the affected client without undue delay and cooperate in the response.
Platform terms
Our access to each platform is governed by that platform's developer and data-use terms, and we handle platform data in accordance with them — including the Meta Platform Terms and Developer Policies, TikTok's partner and data-protection requirements (our TikTok Shop application has passed TikTok's US data-security and privacy reviews), Amazon's Selling Partner API and Amazon Ads data-protection policies, and Shopify's API terms.
If you're a shopper or ad viewer
If you bought from, or saw an ad for, one of the brands we serve, that brand — not js data — is the controller of your information. Please direct access or deletion requests to the brand; we assist our clients in honoring them. If you believe we hold personal data about you and want it removed, email jon@jsdata.ai and we will handle it per our deletion process.
Changes to this policy
If we change this policy, we will post the updated version at this address with a new effective date. Material changes are communicated to active clients directly.
Contact
JS Data and Media Consults, Inc. · jon@jsdata.ai