Privacy Policy
Last updated: 31 July 2026
This notice explains how this application handles data. It supplements — and does not replace — the privacy policies of the websites it serves: HELLO! Privacy Policy and HOLA! USA Privacy Policy. Where this notice is silent, those policies apply.
1. Who is responsible
HOLA, S.L. (Calle Miguel Ángel 1, 28010 Madrid, Spain; VAT ES-B86326360) is the data controller. HELLO! LTD (Wellington House, 69–71 Upper Ground, London SE1 9PQ, United Kingdom; VAT GB-480771530; ICO registration 1121037) operates the HELLO! feed, and ¡HOLA!, Inc. operates the HOLA! USA feed, both as processors on the controller's behalf.
Privacy enquiries: privacy@hellomagazine.com (HELLO!) or ayuda@hola.com (HOLA! USA).
2. What this application does
It generates a Media RSS (MRSS) feed of each brand's own TikTok posts, so that content can be distributed to authorised syndication partners. It reads from the TikTok Display API using the user.info.basic and video.list scopes, for TikTok accounts owned by the brands and authorised by us.
3. What data we access and store
For each brand-owned TikTok account we have authorised, we store:
- OAuth access and refresh tokens, and the account's TikTok
open_id, held in a private Redis database and used solely to call the TikTok API on that account's behalf. - Public metadata for that account's posts: post ID, title and description, cover image URL, embed link, share URL, duration, dimensions and creation time.
- Basic profile fields for that account: display name, bio description, avatar URL and profile link, used to populate the feed's channel details.
4. What we do not do
- We do not access data about any TikTok user other than the brand accounts we own and authorise.
- We do not collect personal data from visitors to this application — no analytics, no advertising, no tracking.
- We do not download, re-host or modify TikTok video files.
- We do not sell or license the data we retrieve, or use it to build profiles of individuals.
5. Legal basis
Processing rests on our legitimate interest in distributing our own published content, with the authorisation of the account holder, given through TikTok's own consent flow. No third-party personal data is processed for this purpose.
6. Retention
Tokens are retained until they expire or the authorisation is revoked, whichever comes first, and are replaced each time TikTok rotates them. The generated feed is cached and regenerated at least every 15 minutes. When an authorisation is revoked, the associated tokens and cached feed cease to be usable and are deleted.
7. Who else is involved
Hosting is provided by Vercel Inc. and the token/cache database by Upstash, Inc., both acting as processors. Feed content — the same content already published publicly on TikTok — is made available to authorised syndication partners. Video playback happens through TikTok's own embedded player and is subject to TikTok's privacy policy, not ours.
8. Cookies
This application sets one cookie: a short-lived, httpOnly anti-forgery token during the TikTok authorisation flow, valid for 10 minutes and used for no other purpose. It sets no analytics or advertising cookies. Cookies on the main brand websites are covered by the HELLO! cookie policy and the HOLA! USA cookie policy.
9. Your rights and how to withdraw access
The holder of an authorised TikTok account can revoke this application's access at any time in TikTok under Settings → Security and permissions → Manage app permissions, which immediately stops all further data access. Rights of access, rectification, erasure, restriction, objection and portability can be exercised using the contact addresses in section 1. Complaints may also be made to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.
10. Changes
We may update this notice; the date at the top reflects the current version. Material changes will be reflected here before they take effect.