← Back to home

Legal

Important information about how TikDrop works, how we handle data, and the terms that govern your use of the platform.

Last updated: 11 September 2026

This policy is written to meet the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).

1. Who we are (data controller)

TikDrop Limited (“we”, “us”, “our”) helps e-commerce sellers find products, prepare listings and fulfil orders. We are the data controller for the personal data described in this policy.

Registered office: 42 Victoria Street, London SW1H 0HW, United Kingdom.
Contact: privacy@tikdropglobal.com.

Owner action required: company number and (if appointed) the Data Protection Officer or UK representative must be added once available. UK company and e-commerce law require these identity details to be available on the website.

2. Personal data we collect

Information you give us: name, email address, phone number, business name, enquiry content and any billing details. Information we collect automatically: IP address, device and browser information, pages viewed and cookie identifiers. Information from connected stores: where you authorise an integration such as TikTok Shop, Shopify or WooCommerce, we receive product, order, inventory and delivery data, which may include your customers' names and delivery addresses.

3. Why we use it and our lawful bases

Contract (Article 6(1)(b)): to create and manage your account, provide the platform, process and fulfil orders and provide support. Legitimate interests (Article 6(1)(f)): to secure and improve the service, prevent fraud and abuse, keep business records and respond to enquiries — balanced against your rights. Consent (Article 6(1)(a)): non-essential cookies and analytics, and marketing email where required. Legal obligation (Article 6(1)(c)): tax, accounting and compliance with lawful requests. We do not sell personal data and we do not carry out automated decision-making that produces legal effects.

4. Sellers' customer data (processor role)

Where we handle end-customer data supplied by a seller in order to fulfil that seller's orders, the seller is the controller and we act as a processor on their documented instructions, under Article 28 UK GDPR terms. Sellers remain responsible for having a lawful basis and their own privacy notice for their customers.

5. Cookies and similar technologies

Strictly necessary cookies are used to operate the site and keep it secure. Analytics, advertising and other non-essential cookies are only set with your consent, which you can give or withdraw at any time through the cookie controls or your browser settings, as required by PECR.

6. Sharing and recipients

We share personal data with service providers who help us run TikDrop: hosting and infrastructure, our contact-form provider (FormCraft), advertising and conversion measurement providers (such as Google Ads, where you have consented), suppliers and carriers who fulfil orders, and professional advisers. We may also disclose data where required by law or to establish, exercise or defend legal claims. Each provider acts under contract and, where they are processors, on our instructions.

7. International transfers

Some providers, suppliers and carriers are located outside the UK. Where personal data is transferred outside the UK, we rely on UK adequacy regulations or, where no adequacy applies, on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, together with a transfer risk assessment. You can request details of the safeguards used.

8. How long we keep data

Enquiry and contact records: up to 24 months from the last contact. Account records: for the life of the account and up to 6 years afterwards where needed for legal claims. Order, invoice and tax records: 6 years, in line with UK tax requirements. Cookie and analytics data: no longer than the retention period stated in the cookie controls. We delete or anonymise data once these periods end.

9. Security

We use appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit and limits on who can see your information. No online service is completely secure, so please use a strong, unique password. We will report qualifying personal data breaches to the ICO within 72 hours and notify affected individuals where the law requires it.

10. Your rights

Under the UK GDPR you have the right to be informed, and rights of access, rectification, erasure, restriction, data portability, objection (including to direct marketing at any time) and the right to withdraw consent where we rely on it. Contact privacy@tikdropglobal.com and we will respond within one month. Exercising your rights is free in normal circumstances.

11. Complaints

If you are unhappy with how we handle your data, please tell us first so we can put it right. You also have the right to complain to the UK Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, helpline 0303 123 1113, ico.org.uk.

12. Children

TikDrop is a business service and is not intended for anyone under 18. We do not knowingly collect personal data from children.

13. Changes to this policy

We may update this policy from time to time. Material changes will be posted on this page with a new “last updated” date, and we will tell you directly where the law requires it.