CLOUDBRIX LLC / TYPIQ STUDIO
Privacy notice
Last updated
This notice explains how we handle information on the TypiQ website and in its private production workspace, including our planned TikTok Shop creator-reporting connection.
Who is responsible
Cloudbrix LLC operates TypiQ Studio in the United States. James Oku is responsible for privacy and security questions. Contact jamesoku@typiqteam.com about this notice or information about you.
Information we use
The production workspace uses work names and email addresses, account identifiers, Trello members and card assignments, video approval and classification records, compensation records, and administrative activity. These records support access, production tracking and compensation administration.
The TikTok Shop reporting connection is planned and is awaiting review, account authorization and live verification. When enabled for the two owned creator accounts, it is designed to use creator identity and authorization tokens, product, order and source-video identifiers, dates, statuses, sales and estimated or settled commissions.
The reporting design selects necessary fields rather than retaining the complete provider response. Buyer contact details, delivery addresses and payment-card information are not needed for this purpose. These exclusions still require verification against the first authorized live import.
Authentication involves email addresses, login codes and time-limited session records. The application database does not store raw authenticator seeds or recovery codes.
How information is used and accessed
We use information to manage workspace access and assignments, track production, report authorized creator performance, administer compensation, correct records, respond to requests and protect the service. Sales, estimated commissions, settled commissions and editor compensation are separate figures; an uncertain video match does not establish payable earnings.
The website portfolio and this notice are public. Workspace records require sign-in and an authorized role. Owner financial and administrative access requires authenticator verification. Approved editors can access their own authorized records; unrestricted creator reports and creator credentials are not provided to editors. James reports that he is currently the only person accessing confidential TypiQ information.
Our adopted policy limits reporting data to these purposes and does not permit its sale or use for unrelated marketing. The planned TikTok permission is read-only reporting. It does not authorize posting, advertising changes, product changes, buyer contact or purchases.
Providers and processing locations
We use OpenAI Sites with Cloudflare Workers and D1 for hosting and application storage, Supabase for authentication, Resend for login-email delivery, and Atlassian Trello for production records. TikTok will provide creator reporting if the connection is approved and authorized. Providers process information needed for hosting, delivery, security, administration and support.
James has confirmed that his access is from the United States. The Supabase authentication project's primary region is East US (Ohio), United States. Resend states that its stored data is in the United States. Other relevant hosting, infrastructure and provider support can involve international processing. Primary US storage does not mean all processing occurs only in the United States; this notice does not claim an exhaustive country list.
Portfolio pages request fonts from Google Fonts. Opening an embedded portfolio video loads TikTok's player and involves that provider and browser connection information. These providers may apply their own privacy and cookie practices. Portfolio playback is separate from authorizing TikTok Shop reporting. This notice page has no embedded player or tracking script.
Provider information: Supabase data processing, Resend security and storage, Atlassian privacy and Cloudflare privacy.
Retention and deletion
Our adopted retention schedule calls for operational and security logs to be kept for 90 days from the event, detailed performance records for 12 months after the reporting period, and finalized payment records with minimum supporting accounting evidence for seven years after the payment year. These are business settings, not a statement that the law requires those periods. An unresolved dispute or applicable obligation may justify keeping limited records longer.
The schedule is under implementation. Cleanup automation, actual deletion across providers, backup expiration and restoration handling have not been fully verified. We do not promise that every record is already removed automatically on those dates or give a fixed deletion-completion deadline.
Our adopted termination procedure calls for collection to stop, provider access to be revoked and unneeded information to be removed through an approved procedure, with any valid retained-record exception explained. Revoking TikTok authorization does not itself delete information already held by TypiQ.
Your questions and requests
Email jamesoku@typiqteam.com to request access to, correction of or deletion of information about you, or to raise a privacy concern. Our manual procedure verifies the requester, identifies relevant records, assesses applicable obligations and exceptions, and coordinates a response. An automated request service or completed end-to-end deletion exercise is not claimed.
If you revoke a TikTok connection through TikTok's controls, also contact us about information already collected. Any retained records or limitations should be explained in the response.
We will update this notice when the service's information use, access, providers, processing arrangements or operating safeguards change. The date above identifies the current notice version.