The short version
- We use your data only to run Inbound for you. We do not sell it, use it for advertising, build profiles from it, combine it across sellers or use it to train AI models.
- Our access to TikTok Shop is read-only and limited to the Order Information and Shop Authorized Information scopes.
- Buyer names and addresses are deleted on a schedule: 30 days after an order is completed or cancelled, and never kept more than 120 days after purchase.
- When you disconnect a shop, its access tokens and buyer addresses are deleted at once and the rest of its data 30 days later.
- Our tracking provider receives only a tracking number and carrier, never buyer names or addresses.
Who we are
Inbound (the “Service”) is operated by Caravan Transport LLC, a Pennsylvania limited liability company (“Caravan Transport”, “we”, “us”). We are responsible for the information described in this policy.
Caravan Transport LLC Philadelphia, Pennsylvania, United StatesPrivacy questions: [email protected]
What this policy covers
This policy covers the Inbound iOS app, the Inbound servers it talks to, and this website, shipinbound.com. A seller web dashboard is coming soon; it is not available yet.
Inbound is a tool for businesses that sell on TikTok Shop. It imports a seller’s orders, follows each parcel with the carriers and flags delivery problems. That means we handle two kinds of personal information:
- About our users: the sellers and team members who sign in to Inbound. For this information we decide how it is used, as described here.
- About our sellers’ buyers: the recipient name and shipping address that come with an order. We process this on behalf of the seller who connected the shop, only to provide the Service to that seller, as their service provider. See section 10 if you are a buyer.
Information we collect
Account information
You can sign in with Apple or with your email address and a one-time code.
- Sign in with Apple: the account identifier Apple gives us, and the email address Apple shares (which may be a private relay address if you choose “Hide My Email”). Apple shares your name only the first time you sign in; if it does, we save it as your display name.
- Email sign-in: your email address, used to send you a 6-digit sign-in code.
- Profile: your display name and basic settings such as time zone and language, plus when your account was created.
We do not use passwords, and we never receive your Apple ID password.
Workspace and team information
- Workspaces you create or join: the workspace name, time zone (taken from your device when you create it), currency and language.
- Members and their roles, and invitations, including the email address an invitation was sent to.
- What your team does in Inbound: exceptions you acknowledge, assign, resolve or dismiss, notes you write on them, the detection settings you choose, and shipments you archive.
- An audit log of actions taken in the workspace, which records who acted (by account ID), what was done, when and whether it succeeded.
Connected TikTok Shop data
When someone in your workspace with permission to manage stores connects a TikTok Shop, we import through the official TikTok Shop Open API:
- Shop details: the shop’s name, ID, region and currency, and the TikTok Shop seller account that authorized us.
- Orders: order ID, status, dates, fulfillment and shipping type, totals, currency and the marketplace’s promised delivery date.
- Items: product name, SKU, product image link, quantity and price.
- Packages: package ID, status, tracking number and the shipping provider’s name.
- Buyer (recipient) information: the recipient’s name and shipping address. We do not store the buyer’s phone number, email address or TikTok user ID. When TikTok Shop masks an address, we treat it as absent and remove the earlier copy.
- Access tokens that let us read your shop, stored encrypted and only on our servers.
We skip unpaid orders. The full list of what we access, and how it is deleted, is in section 5.
Carrier tracking data
For each parcel in flight, we receive tracking information from carriers through our tracking provider: status, scan events with their descriptions, times and locations (city level), the carrier’s delivery estimate, delivery time and carrier handoffs. From this we derive each shipment’s current status and any delivery exceptions.
Information from your device
- Camera: if you choose to scan a shipping label, the camera image is read on your device to find a tracking number. Images are not stored or uploaded; only the cleaned-up tracking number is sent, as a search. Web links and product barcodes are ignored.
- Sign-in session: your session is stored in the device’s Keychain.
- The app contains no advertising or analytics SDKs and does not collect advertising identifiers, contacts, photos or location. It does not send push notifications today.
Operational and security logs
Our servers write technical logs to keep the Service running and secure: for each request, the method, path, response code, duration and a request ID; and for background work, what ran and whether it succeeded. Query strings are not logged. Logs are passed through a redaction step that removes tokens, keys, passwords, email addresses, names, phone numbers, street addresses and IP addresses, and masks tracking numbers to their last four digits. Sync errors are stored only as a category, such as “timeout”, never with provider messages or order data.
To protect the TikTok Shop connection page from abuse, we count requests per network address. The counter stores a one-way hash, not the address itself, and is deleted within 2 days. Our service providers may also process your IP address when they deliver requests to us, for example when you sign in.
This website
shipinbound.com is a static website. It sets no cookies and uses no analytics, trackers or third-party scripts or fonts. Our hosting provider processes standard request information, such as IP address, to deliver the pages. If you email us, we receive your email address and whatever you choose to include.
How we use information
We use information only to provide Inbound to the seller and workspace it belongs to:
- to sign you in and keep your account and session secure;
- to run your workspace, its members and roles, and check permissions on every request;
- to import your orders and packages, follow each parcel with the carriers and detect delivery exceptions;
- to show your team the orders that need attention, and record what was done in the audit log;
- to keep the Service reliable and secure: detect abuse, fix errors and enforce rate limits;
- to reply when you contact us, and to send sign-in codes you request;
- to meet legal obligations and enforce our Terms of Service.
We do not:
- sell or rent personal information, or share it for cross-context behavioral advertising;
- use it for advertising, marketing to your buyers, or profiling;
- combine one seller’s data with another’s, or use it for any seller other than the one it came from;
- use it to train machine-learning or AI models;
- contact your buyers in any way, by email, text, phone or otherwise.
TikTok Shop data
Inbound is an independent product. It is not affiliated with or endorsed by TikTok. These rules apply to everything we receive from TikTok Shop:
- Read-only, least access. We request only two scopes: Order Information (orders, their packages, tracking numbers and shipping providers) and Shop Authorized Information (which shops you authorized, and our webhook subscriptions). We never change orders, buy labels or write anything to your shop; the only thing we set up is our own subscription to order-update notifications.
- Official API only. We use the TikTok Shop Open API with webhooks and scheduled incremental sync. We never scrape.
- Consent before connecting. Before you connect, the app tells you that tracking numbers and carriers are shared with our tracking provider to follow deliveries. The connection is tied to the person and workspace that started it.
- Only for you. Data from your shop is used only to provide Inbound to your workspace, as your service provider. One shop can be connected to only one workspace at a time.
- Buyer data kept short. While your shop is connected, a buyer’s name and address are deleted 30 days after the order is completed or cancelled, and never kept more than 120 days after purchase.
- Deletion when you disconnect. If you disconnect a shop in Inbound, or remove Inbound’s access in TikTok Shop Seller Center (deauthorization), we stop syncing and, at once, delete the shop’s access tokens and all of its buyer names and addresses. The shop’s remaining data (orders, items, packages and shipments) is deleted 30 days later, unless you reconnect it within that time. Parcels that no longer belong to any shipment are then removed from our tracking provider.
- Broken connections. If a shop’s connection stays broken for 30 days (for example, the authorization expired or was rejected), we treat it as deauthorized and apply the same deletion.
Disconnecting in Inbound stops our access on our side. To also remove Inbound from your TikTok Shop account, revoke it in TikTok Shop Seller Center under App Store ▸ My apps and incidents.
How long we keep information
We keep information only as long as it is needed to provide the Service. Deletions below run automatically; scheduled clean-up runs daily.
| Data | How long we keep it |
|---|---|
| Buyer name and shipping address (connected shop) | 30 days after the order is completed or cancelled; never more than 120 days after purchase |
| TikTok Shop access tokens | Until you disconnect, access is revoked or the workspace is deleted; then deleted at once |
| Disconnected or deauthorized shop | Buyer names and addresses deleted at once; orders, items, packages and shipments deleted 30 days later unless reconnected |
| Carrier tracking records and scan events | While a shipment uses them; then removed from our tracking provider at the next daily clean-up and deleted a day later |
| Account (profile, email, sign-in identity) and workspace memberships | Until the account is deleted; deleted immediately when it is |
| Workspace data (members, roles, invitations, exceptions, notes, settings) | While the workspace exists |
| Incoming notification payloads from TikTok Shop and our tracking provider | Contents 30 days; the record that it arrived 90 days, to ignore duplicates |
| Background job records | 7 days when successful, 30 days when failed |
| Internal event and operational error records | 90 days |
| Shop connection requests and pending order refreshes | 1 day |
| Rate-limit counters | 2 days |
| Audit log | Kept as a permanent, append-only security record. Entries identify people only by account ID, which no longer links to a person once that account is deleted |
Backups kept by our database provider may hold deleted data for a limited period until they expire. We may keep information longer if the law requires it.
Security
We design Inbound so that each workspace’s data stays separate and the least possible data leaves our systems. Measures in place today include:
- Encryption in transit: the app talks to our servers only over HTTPS; release builds refuse insecure or development server addresses.
- Encrypted tokens: TikTok Shop access tokens are encrypted at rest in a secrets vault, readable only by server code, and never sent to the app or written to logs, errors or URLs.
- Workspace isolation: every record belongs to one workspace, and the database checks membership and permissions on every request (row-level security and per-column access rules).
- Least privilege: roles and permissions decide who can see buyer details, manage stores, work exceptions or manage the team; apart from owners, people can grant only roles below their own, and nobody can change their own role.
- Verified connections: shop connections use single-use, short-lived codes bound to the person who started them (with PKCE); team invitations are single-use, expiring, revocable and stored only as hashes.
- Signed notifications: notifications from TikTok Shop and AfterShip are rejected unless their signature is valid.
- Redacted logs and an append-only audit log that no one, including us, can edit.
- No caching of personal data: API responses are marked not to be cached, and the app clears on-screen buyer data when your session ends or access is removed.
No system is perfectly secure. If we learn of a security incident that affects your information, we will notify you and, where required, the authorities, as the law requires. Report security concerns to [email protected].
Your choices and rights
Whatever state or country you live in, you can ask us to:
- access the personal information we hold about you, or get a copy of it;
- correct information that is wrong;
- delete your account and personal information;
- tell you how your information is used and shared.
You can also act directly in the app:
- Disconnect a shop under More ▸ Stores (if your role can manage stores). This starts the deletion described in section 5.
- Deny camera access at any time in iOS Settings; you can still type tracking numbers.
Deleting your account inside the app is not available yet. Until it is, email [email protected] from the address on your account and we will delete it. If you are the only owner of a workspace, we will ask whether to hand the workspace to another member or delete it along with its data.
We will respond within 30 days, and may need to confirm your identity first. We will not treat you differently for exercising these rights. If you signed in with Apple, you can also stop using Sign in with Apple for Inbound in your Apple ID settings.
If you bought from a seller
If you bought something from a seller who uses Inbound, the seller controls your order information, and we process your name and shipping address only on the seller’s behalf, to track the delivery. We never contact you. For requests about your data, please contact the seller first. You can also write to [email protected] and we will help the seller respond.
Children
Inbound is a business tool and is not directed at anyone under 18. We do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will delete it.
Where information is processed
Inbound is operated from the United States and offered to sellers in the United States. Information we collect is processed in the United States. If you use Inbound from elsewhere, you understand that your information will be transferred to and processed in the United States, where data protection laws may differ from those where you live.
Changes to this policy
We will update this policy when the Service changes, for example before we add push notifications or the seller web dashboard. We will change the “Last updated” date above, and for material changes we will tell you in the app or by email before they take effect.
Contact us
For privacy questions or requests, email [email protected]. For anything else, email [email protected].
Caravan Transport LLC Philadelphia, Pennsylvania, United States