EBC — Everything But Content Request access

Personal data protection policy

Version 1.0, effective September 14, 2026. Internal policy of DB3 LLC, doing business as EBC Studio, published for transparency. It governs how we handle personal data day to day; our public privacy and data protection policy tells people what we collect and why, and our information security policy covers the technical controls. Reviewed at least once a year.

1. Principles

  • Minimisation. Collect only what a feature needs, keep it only as long as the feature needs it.
  • Purpose limitation. Data obtained for one purpose (for example, showing a creator their own sample deadlines) is not reused for another without the creator’s agreement.
  • Transparency. Everything we collect is described in the public privacy policy before we collect it.
  • Creator ownership. Data about a creator belongs to that creator. They can see it, correct it, export it, and delete it, and they can revoke the TikTok Shop connection at any time.
  • Security by default. Confidential and private data is encrypted in transit and at rest, and access follows least privilege.
  • No sale, no profiling of third parties. We never sell personal data and never build profiles of viewers, buyers, sellers, or other creators.

2. Data protection officer

DB3 LLC has appointed a data protection officer (DPO) who is accountable for this policy, answers requests from individuals, sellers, TikTok Shop, and regulators, and leads breach response.

RoleContact
Data protection officer (Brian Brown, managing member)bbrown@cyrenitycyber.com
General privacy requestshello@momfinds.co (monitored by the DPO)

3. What we hold and where

We keep a record of processing. In summary:

CategoryPeopleStored inPurpose
TikTok Shop sample, showcase, and order data; access tokensAuthorizing creatorsApplication database (United States)Show the creator their own data; deadline reminders
Creator studio data: statistics, scorecards, briefs, coaching conversations, notesCreators and their designated partnerApplication database (United States)Operate the studio
Contact and newsletter submissionsWebsite visitorsApplication database (United States)Reply; send the newsletter
Server logsWebsite visitorsHosting provider (United States)Security and troubleshooting, 30 days

All data is physically stored and processed in the United States.

4. Handling rules

  • Personal data is accessed only through the studio application or the database console, by authorized personnel with an individual account, for a reason connected to operating the service.
  • Personal data is not exported to spreadsheets, personal devices, email, or chat. If a one-off export is unavoidable, it is deleted the same day.
  • Personal data is not sent to any AI model except the creator’s own statistics, captions, and conversations, used to generate their own briefs and answers, with providers that do not train on our data.
  • Screenshots or examples used in documentation or support are anonymised.
  • New features that touch personal data are checked against the privacy policy before launch; if the policy does not already cover the new use, the policy is updated first and affected creators are told.

5. Requests from people, sellers, and TikTok Shop

We assist creators, sellers, and TikTok Shop with requests to access, correct, provide a copy of, restrict, or delete personal data. The procedure:

  1. Requests arrive at hello@momfinds.co, bbrown@cyrenitycyber.com, through TikTok Shop, or by the creator revoking access in TikTok Shop. The DPO logs the request the day it arrives.
  2. We verify the requester using the email address or account on file, or TikTok Shop’s own channel for requests that come from TikTok.
  3. We act within 30 days: provide a copy in a readable format, correct the record, restrict the use, or delete, as asked. Deletion covers our database and any backup once it ages out of the retention window.
  4. We confirm completion in writing to the requester and keep the log entry (date, type, outcome, no personal data) for two years.

Requests from a seller or from TikTok Shop about a creator’s data are honoured where TikTok Shop’s terms require it, and the creator is informed.

6. Retention and deletion

DataKeptThen
TikTok Shop access and refresh tokensWhile the connection is activeDeleted immediately on revocation or disconnect
TikTok Shop sample, showcase, and order dataWhile connected, plus 30 daysDeleted
Studio data (statistics, scorecards, briefs, conversations, notes)While the creator uses the studioDeleted within 30 days of a request or of the relationship ending
Contact and newsletter submissionsUntil unsubscribe or requestDeleted
Server logs30 daysExpire automatically
Request log (no personal data)2 yearsDeleted

Deletion means removal from the live database; backups roll off within the provider’s retention window (currently up to 7 days) and are never restored to bring deleted data back.

7. End of a relationship

When a creator stops using EBC Studio, revokes TikTok Shop access, or when an agreement with a seller or with TikTok Shop ends, we delete all collected personal data in our possession relating to that relationship within 30 days, including TikTok Shop data and tokens, and confirm the deletion in writing on request. We keep nothing back for our own purposes. The only exception is a record we are legally required to keep, which we would identify to the requester.

8. Breach notification process

A personal data breach is any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Our process, which the DPO runs alongside the incident response steps in the information security policy:

  1. Hour 0. Anyone who suspects a breach tells the DPO immediately (email or the internal incident channel). The DPO opens a record with the time, what was observed, and by whom.
  2. Within 24 hours. Contain: rotate or revoke affected credentials including TikTok Shop tokens and app secrets, disable the affected component, preserve logs. Assess what data and whose was affected.
  3. Within 72 hours of confirmation. Notify affected creators by email with what happened, what data was involved, what we did, and what they should do. Notify TikTok Shop through the Partner Center and the developer support channel, and any seller whose data was involved. Notify the relevant regulator where the law requires it (for U.S. state laws, attorneys general where thresholds are met; for any EEA or UK data, the supervisory authority). Notifications are not delayed for a complete investigation; we send what we know and follow up.
  4. After. Write the post-incident review, fix the cause, update this policy and the security policy if they fell short, and close the record.

9. Processors and transfers

Our processors, what they receive, and why are listed in section 5 of the public privacy policy. Each is engaged under its standard data processing terms, stores our data in the United States, and is reviewed at the annual policy review. We add no processor that would receive personal data without updating the public list first. We do not transfer personal data outside the United States.

10. Training and accountability

  • All personnel with access to personal data read this policy, the privacy policy, and the information security policy when they are adopted, on joining, and at each annual review, and confirm in writing that they have.
  • The DPO is accountable for compliance with this policy and reports any material issue to the management of DB3 LLC, which records it in the compliance log.
  • Breaches of this policy by personnel are treated as a security incident.

11. Compliance history

As of the effective date, DB3 LLC has not experienced any breach of security leading to the exposure of personal data, has not been required to notify any authority or customer of one, and has not received any complaint, objection, or notice from a data protection authority, regulator, customer, or individual about its processing of personal data. This section is updated at each review.

12. Review

The DPO reviews this policy at least once a year, after any breach or request that exposes a gap, and before any new processing of personal data. Changes are recorded by version and effective date at the top of this page.

DB3 LLC, doing business as EBC Studio
United States
DPO: bbrown@cyrenitycyber.com · General: hello@momfinds.co