API governance

API Data Use and Internal Access Policy

Qingyu Commerce Operations uses authorized API access only for internal ecommerce operations, store reporting, product management, promotion review, and advertising performance optimization.

TikTok Shop API Use

TikTok Shop API access is used after a store grants authorization. We use store data to maintain internal dashboards, review performance, identify abnormal changes, and support authorized product or promotion operations.

Store dataShop profile, shop region, authorization status, and store identifiers.
Product dataProduct listing information, product status, pricing, inventory signals, and content fields needed for operations.
Order and refund dataOrders, order status, refund information, fulfillment status, and operational exception monitoring.
Analytics dataGMV, orders, visitors, conversion, average order value, refunds, reviews, top products, and abnormal changes.

TikTok Marketing API Use

TikTok Marketing API access is used after an advertiser account grants authorization. Advertising authorization is separate from store authorization because one store may be connected with multiple advertiser accounts.

Advertiser accessAdvertiser account ID, account name, market, account status, and authorized access status.
Campaign reportingCampaign, ad group, ad, creative, spend, impressions, clicks, CTR, conversions, CPA, ROAS, and ROI.
Optimization workInternal campaign performance review, budget allocation analysis, creative review, and reporting for related stores.
Data limitsAdvertising data is not sold or provided to third parties. It is used for authorized internal operations only.

Access separation

Store tokens and advertising tokens are managed separately

Each authorization record is labeled so operational teams can identify the exact market, store, Shop Code, advertiser account, and app configuration.

Store Token Label

Format: region store number, Shop Code, and current store name. Example: MX-S01 | CNMXCBB3LT2J | GALBE.MX.

Ad Token Label

Format: region store number, advertiser ID, advertiser name, and related store when applicable.

Regional App Credentials

App keys and secrets can be separated by market, including MX, TH, PH, MY, US, and JP, so each authorization can be traced to the correct app.