Privacy Policy
Last updated: 2026-06-20
Market4U (“we”, “our”, “the Service”) is operated by Ecremmoce. This Privacy Policy explains what information we collect when you use Market4U to generate and publish marketing content, how we use it, and your rights regarding that information.
1. Information We Collect
- Account information: name, email address, organization, and authentication identifiers issued by our identity provider.
- Connected channel credentials: OAuth access tokens and refresh tokens for third-party platforms (Shopee, Facebook, Instagram, TikTok, YouTube, and similar) that you explicitly connect. Tokens are encrypted at rest using PostgreSQL pgcrypto and are accessible only to the service-role process performing your authorized publish actions.
- Product data: product names, descriptions, images, prices, and metadata you import from connected seller accounts (e.g., Shopee).
- Generated content: text copies, images, and videos produced on your behalf by AI providers.
- Operational logs: API call timestamps, error messages, and asset references needed to operate queues, retries, and billing.
2. How We Use Information
- To generate marketing content (copy, images, videos) using AI providers under your direction.
- To publish content to the third-party channels you have connected, on the schedule you configure.
- To improve the reliability of the Service (error analysis, capacity planning, fraud prevention).
- To communicate operational notices such as failed publish attempts or token expirations.
3. Third-Party Processors
We rely on the following processors to operate the Service:
- Supabase (database, storage, authentication)
- Vercel (application hosting, cron jobs)
- Google Gemini and Higgsfield (AI text/image/video generation)
- fal.ai (alternative AI video generation)
- Shopee Open Platform, Meta Graph API, TikTok Content Posting API, YouTube Data API (publishing endpoints)
Data is shared with these processors only to the extent required to perform the action you initiated. We do not sell your data, and we do not use connected channel data to train AI models.
4. Data Retention
We retain account, product, and generated content data for the duration of your subscription and for a reasonable period afterward to support audit and dispute resolution. You may request deletion of your data at any time by contacting james@ecremmoce.io. Connected channel tokens are deleted immediately when you disconnect a channel.
5. Security
All traffic is served over TLS. Channel access tokens are encrypted at rest. Access to production data is restricted to authorized engineers and audit-logged. We will notify affected users without undue delay in the event of a confirmed data breach.
6. Your Rights
Depending on your jurisdiction (GDPR, CCPA, PIPA in Korea), you may have the right to access, correct, export, or delete your personal information, and to object to processing. To exercise these rights, contact james@ecremmoce.io.
7. Children
The Service is not directed to children under 14 and we do not knowingly collect their data.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email and reflected on this page with a new “Last updated” date.
9. TikTok Integration (Content Posting API)
When you connect a TikTok account, we request the following OAuth scopes and process the corresponding data strictly to deliver the publishing features you initiate.
- user.info.basic — to display your connected TikTok username and avatar in the dashboard so you can confirm which account you are publishing to.
- video.upload — to upload AI-generated short product videos to your TikTok inbox (drafts) for review and final publishing inside the TikTok app.
- video.publish — to publish AI-generated short product videos with operator-approved captions (including legally required advertisement disclosure) directly to your TikTok account.
We do not store TikTok video content on our servers after upload completes; we retain only post metadata (publish_id, permalink, publish timestamp) for tracking and for your dashboard view. We do not share TikTok user data with third parties, do not use it for advertising profiling, and do not use it to train AI models. You can revoke our access at any time by disconnecting the TikTok channel in your dashboard or by removing the authorization at TikTok > Settings > Manage Apps. Upon disconnection, all stored TikTok access tokens are deleted immediately.
10. YouTube / Google Integration (YouTube Data API)
When you connect a YouTube channel, Market4U uses the YouTube Data API Services and requests the following Google OAuth scopes strictly to deliver the publishing features you initiate:
- youtube.upload — to upload AI-generated short product videos to your channel.
- youtube.readonly — to read your channel and video metadata (e.g., upload status, video ID, watch URL) so we can show publish results in your dashboard.
- youtube / youtube.force-ssl — to set the custom thumbnail and post an operator-approved comment (such as your store link) on the video you just published.
- userinfo.email, userinfo.profile, openid — to identify the connected Google account so you can confirm which channel you are publishing to.
Market4U’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use YouTube/Google user data only to provide the user-facing publishing features described above; we do not transfer or sell it, do not use it for advertising, and do not use it to train AI models. Our use of YouTube API Services also complies with the YouTube Terms of Service and the Google Privacy Policy. We do not store your video content after upload completes; we retain only post metadata (video ID, watch URL, publish timestamp). You can revoke Market4U’s access at any time by disconnecting the channel in your dashboard or at Google Account > Third-party access. Upon disconnection, all stored Google tokens are deleted immediately.
11. Meta Integration (Instagram & Facebook)
When you connect a Facebook Page and its linked Instagram professional account, Market4U uses the Meta Graph API and requests the following permissions strictly to deliver the publishing features you initiate:
- instagram_basic, instagram_content_publish — to read your connected Instagram professional account identity and publish AI-generated short product videos (Reels) to it.
- pages_show_list, pages_read_engagement, pages_manage_posts — to list your Facebook Pages, confirm the target Page, and publish video posts to the Page you select.
- business_management — to access the Business account that owns the Page and Instagram account so the publishing action can be authorized.
We do not store your Meta, Instagram, or Facebook content after publishing completes; we retain only post metadata (media/post ID, permalink, publish timestamp). We do not sell Meta user data, do not use it for advertising profiling, and do not use it to train AI models. You can revoke access at any time by disconnecting the channel in your dashboard or at Facebook > Business Integrations. To request deletion of the data we hold about you, disconnect the channel or contact james@ecremmoce.io; upon disconnection, all stored Meta access tokens are deleted immediately.
12. Contact
Ecremmoce — james@ecremmoce.io