Privacy Policy

Product: Supover Seller Hub (Chrome Extension) · Last updated: August 17, 2026

This Privacy Policy explains what data the Supover Seller Hub browser extension (the “Extension”, “we”, “us”) collects, how we use it, how it is stored, how long it is kept, and with whom it is shared. The Extension is operated by Dragon Media LLC, trading as Supover (ai.supover.com), 6545 Market Ave N, Suite 100, Canton, OH 44721, United States. In this policy, “Supover” means Dragon Media LLC. By installing and using the Extension you consent to the practices described in this policy.

1. Single Purpose of the Extension

Supover Seller Hub is a management and automation tool for e-commerce sellers. Its single purpose is to help sellers operate their own online stores on TikTok Shop — including store synchronization, order synchronization and lookup, Flash Sale management, Request Review (asking your own buyers for a product review), product/variant listing creation, synchronization of the product reviews your own shop has received, and payout/settlement synchronization with the payment and fulfillment providers you use (PingPong, LianLian, WorldFirst, FlashShip, Gearment, SimplePrint, Printify). The Extension only collects and processes data in direct support of these features. Support for Etsy and Shopify was offered in earlier versions and has been removed entirely.

2. Data We Collect

The table below lists every category of user data defined by the Chrome Web Store, and states clearly whether the Extension handles it. Data is accessed only when you use the related feature.

Chrome data category Handled? What exactly, and why
Personally identifiable information Yes

(a) Your own information: your Supover account name, email address and avatar, and the seller profile / shop information (store name, shop ID, seller ID, region, and the account email address registered with that store) of the TikTok Shop accounts you connect. Used to identify you and link your stores to your Supover account.

(b) Your customers’ information, contained in your own orders: when you run order synchronization, the Extension reads the order records of your stores, which include the buyer’s name, shipping address, phone number and email address, together with order IDs, order status, items and fulfillment details. This information is transmitted to the Supover backend so your orders can be displayed, synchronized, bulk-updated and fulfilled through your connected fulfillment providers — the same purpose for which you already hold it as the merchant. See Section 7.

Health information No The Extension does not collect, access, transmit or store any health or medical information.
Financial and payment information Yes

Payout, settlement and transaction records retrieved from your own seller and payment accounts — amounts, currencies, dates, transaction/reference IDs, fees and payout status — from TikTok Shop, PingPong, LianLian, WorldFirst, FlashShip, Gearment, SimplePrint and Printify. Order-level amounts and fulfillment costs are also read. Used to synchronize payouts/settlements and to generate the reconciliation reports and spreadsheets you request.

In addition, when you open the TikTok Shop store-overview panel inside the Extension, it reads your shop’s payout account summary as displayed to you by TikTok — bank account type, the bank account identifier TikTok shows, bank account status, processing and pending settlement balances, and your shop health/violation score — and sends it to Supover’s AI recommendation service (n8n.supover.com) to produce the seller recommendations shown in that panel. See Sections 4 and 8. The Extension never collects full card numbers, CVV codes, online-banking or payment passwords, or any other payment credential.

Authentication information Yes Your Supover login token, and the existing session cookies and access tokens of the seller, payment and fulfillment platforms you are already logged in to in your browser. Used solely to make authenticated requests to those platforms on your behalf so the features above can work. If you use the Hidemyacc anti-detect browser, the proxy credentials configured in your local Hidemyacc profile are also read and stored against your store record so synchronizations keep using that proxy (see Section 3). The Extension does not collect the account passwords of your seller, payment or fulfillment platforms, and does not transmit third-party platform cookies to Supover except where a token is required to complete a sync you initiated.
Personal communications Yes The Request Review feature, when you start it, opens the TikTok Shop buyer-message (IM) thread for each eligible order of your own store and sends a review-request message to that buyer on your behalf. The message text is either text you type yourself, or text generated for you by Supover’s message service (n8n.supover.com), which receives only the message template option you selected — not the buyer’s identity or your conversation history. The Extension does not read, collect, store or transmit the content of your existing conversations, and does not access any messaging service other than the TikTok Shop seller chat threads belonging to the orders you chose to process.
Location No The Extension does not collect your IP address and does not determine your location. To schedule region-aware Flash Sale start/end times, it reads the timezone your browser already reports through the standard Intl.DateTimeFormat API; that value is used on your own device for the scheduling calculation and is not transmitted anywhere. Earlier versions obtained your public IP address and an IP-derived region through two third-party services (api.ipify.org and ipapi.co); both lookups have been removed. The Extension does not use GPS or the browser geolocation API.
Web history No The Extension does not collect your browsing history, does not request the history or webNavigation permissions, and does not read or report the list of sites you visit. It runs only on the specific seller, payment, fulfillment and marketplace domains listed in Section 3.
User activity No The Extension does not monitor your activity. It does not log keystrokes, mouse movement or coordinates, click targets, scroll positions, focus/visibility changes, time spent on a page, or which application you are using, and it performs no analytics, tracking, profiling or advertising measurement. A periodic “heartbeat” signal that measured active working time was present in earlier versions; it has been removed, together with the alarms permission it required.
Website content Yes On the domains listed in Section 3, the Extension reads page content needed for the feature you triggered: (a) order, payout and transaction tables shown in your own seller, payment and fulfillment dashboards, read when a sync or extraction runs; (b) the form fields of the TikTok product-creation page, which the Extension fills in for you during listing creation; (c) the product images of your own TikTok Shop listing, when you click “Get Image”; (d) the product reviews your own shop has received, read from your TikTok Shop seller dashboard and sent to the Supover backend so your reviews can be displayed and tracked there — specifically the review ID, the related order ID, the product name, the star rating, the review text and its timestamp. The reviewer’s name, profile picture and account identity are not collected. No other page text, image, sound or file is read, and nothing is read from pages outside those domains. Earlier versions also captured product information and images from third-party marketplace product pages for a product-research (“AI Clone”) feature, and analysed the public statistics and reviews of other sellers’ product pages; both features have been removed and no such capture takes place.
Form data Yes The Extension reads and fills form fields only on supported seller and product-listing pages when you use a related feature. This includes listing titles, descriptions, prices, variants/options, images, Flash Sale settings, order filters and review-request settings. Used only to create or update listings, run seller workflows and remember the settings you chose. The Extension does not read or collect form data from unrelated websites.
User-generated content Yes Content you provide or approve inside the Extension, such as listing text, product descriptions, image selections, review-request message text/templates, notes and per-feature settings. Used only to perform the action you requested, such as creating a listing, sending a review request or saving your workflow preferences.

3. How and Where We Collect Data

Data is collected only while you are signed in and actively using the Extension, and only on these domains: tiktok.com, pingpongx.com, lianlianglobal.com, worldfirst.com, simpleprint.io, seller.flashship.net, gearment.com, printify.com and supover.com. The Extension reads the information listed in Section 2 directly from the pages and APIs of those services, using your own authenticated session. Apart from the local connection described in the next paragraph, the Extension does not run on, read from, or collect anything from any other website. Earlier versions also ran on etsy.com, admin.shopify.com and the marketplace domains amazon.com, ebay.com, walmart.com and pinterest.com; all six have been removed from the Extension.

Timezone. To schedule Flash Sales in your own timezone, the Extension reads the timezone your browser already reports through the standard Intl.DateTimeFormat API (Section 2, “Location”). This involves no network request: the value is used on your own device and is not sent to Supover or to anyone else. The IP-based region lookup used in earlier versions (api.ipify.org and ipapi.co) has been removed.

Local anti-detect browser integration. If you use the Hidemyacc anti-detect browser, the Extension additionally queries that application’s local API on your own computer (http://127.0.0.1:2268) to read the browser profile and proxy configuration you have already set up there, and to start the matching profile, so that requests to your seller platforms go out through the proxy you intended. This is a connection to software running on your own device; the Extension sends nothing to Hidemyacc’s own servers. It reads the profile name and ID, the browser user-agent of that profile, and the proxy settings (host, port and, where you configured one, the proxy username and password). When you run a store synchronization, the proxy address and credentials, the profile ID and the user-agent are stored against your store record on the Supover backend (ai.supover.com), so that later synchronizations for that store are performed through the same proxy and browser identity. They are used for no other purpose and are not shared with anyone else. If Hidemyacc is not installed or not running, the check simply fails silently and the Extension continues without a proxy.

The Extension requests only the browser permissions it needs for the features above:

Permission Why it is needed
storage Stores your login state, settings and session data locally so you stay signed in and your preferences are remembered.
cookies Reads your existing authenticated session cookies for the seller, payment and fulfillment sites you are logged in to, so requests can be made on your behalf for store, order and payout sync.
tabs Opens, tracks and closes tabs on the supported sites to run the sync, Request Review, Flash Sale and bulk-update flows you initiate.
contextMenus Adds right-click menu entries so you can send a product image of your own listing to the optional AI image redesign / mockup feature.
Host access Lets the Extension read and update your own data on the seller, payment and fulfillment sites listed above, using your authenticated session, only for the features described in this policy.

4. How We Use Data

  • To provide the Extension’s core features: store sync, order sync and lookup, Flash Sale, Request Review, listing/variant creation, product-review sync, payout & settlement sync, and bulk updates.
  • To power the optional AI-assisted features you explicitly trigger — AI product-image mockup/redesign, and store recommendations. When you use one of these, the relevant data (the image URL you selected; or your store’s payout/health summary) is sent to Supover’s AI service at n8n.supover.com, which may in turn pass it to a third-party AI model provider such as Google Gemini or OpenAI in order to generate the result that is returned to you. The AI image-generation request carries an AI-provider API key field; the Extension no longer offers a settings panel for entering one, so this field is sent empty unless a key was saved on your device by an earlier version. Any such key is kept only on your own device via Chrome’s storage.local (see Section 6), is never stored on Supover’s servers, and is erased when you uninstall the Extension. These features run only when you activate them.
  • To authenticate requests to your connected store, payment and fulfillment accounts on your behalf.
  • To keep your store sessions synchronized and maintain service reliability and security.

We do not sell or rent your data. We do not use or transfer it for advertising, ad targeting, profiling, credit assessment, lending, or any purpose unrelated to the Extension’s single purpose. We do not use it to train generalized machine-learning or AI models: data sent to the AI features described above is used only to generate the result you asked for and return it to you. Human beings do not read your data except where strictly necessary to provide support you requested, to comply with the law, or to investigate abuse or a security incident.

5. Compliance with the Chrome Web Store Limited Use Policy

Supover Seller Hub’s use of information received from the Extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. All user data collected by the Extension is used solely to provide and improve the user-facing features described in this policy, and is never sold, never used for advertising, and never transferred except as required to provide those features, to comply with applicable law, or as part of a merger or acquisition in which case we will give affected users notice.

6. How We Store, Protect and Retain Data

  • Where: operational data (store, order, payout and account data) is processed and stored on Supover’s servers at ai.supover.com. Account avatar images are stored on Backblaze B2 cloud storage. The product images you download with “Get Image” are saved directly to your own device and are not uploaded anywhere.
  • Locally: your auth token, user/shop info and per-feature settings — including any AI provider API key you choose to save — are stored on your own device via Chrome’s storage.local API. Nothing is stored in chrome.storage.sync, so this data is not synchronized to other devices, and none of it leaves your device except as described in Section 8.
  • In transit: all traffic between the Extension, Supover’s servers and the third-party platforms is sent over HTTPS (TLS, encrypted in transit).
  • At rest: server-side databases, backups and cloud object storage used by Supover are protected using access controls and encryption at rest provided by the hosting, database and storage providers. Locally stored Extension data is protected by Chrome and the operating system profile on your device.
  • Access control: server-side data is accessible only to your own Supover account and to authorized Supover personnel bound by confidentiality obligations, on a need-to-know basis.
  • Retention: store, order, payout and listing data is retained for as long as your Supover account remains active, because it is your operating record as a seller. On account closure or on a verified deletion request it is deleted within 30 days, except where a longer period is required by law (for example tax or accounting records). Locally stored data is removed from your device as soon as you uninstall the Extension.

7. Your Customers’ Data — Roles and Responsibilities

Some of the data the Extension processes is personal data belonging to your customers (buyer names, addresses, phone numbers and email addresses inside your own orders). For that data you are the data controller and Supover acts as a data processor on your instructions: we process it only to deliver the order-sync, fulfillment and review-request features you activate, and never for our own purposes. You are responsible for having a lawful basis to process your customers’ data and for honoring their rights under applicable law. If one of your customers asks us directly to access or delete their data, we will refer them to you and assist you in responding.

8. How We Share Data

We share data only as needed to operate the Extension:

Recipient What it receives, and why
Supover backend (ai.supover.com) Your store, order (including buyer name/address/phone/email), payout, product-review (Section 2, “Website content”) and account data, form data, user-generated content, Supover auth token, the account email of the store, and selected third-party session cookies or access tokens required to complete sync, extraction, fulfillment or listing actions you initiate, so the Extension’s features work. If you use Hidemyacc, the proxy address and credentials, profile ID and user-agent of your local profile are stored with your store record so later syncs reuse them (Section 3). Supover does not receive the account passwords of your seller, payment or fulfillment platforms.
Supover job service (jobs.supover.com) Your seller ID and order IDs, to queue order-status webhooks.
Supover AI & message service (n8n.supover.com)

This service backs several optional, user-triggered features, and receives only the data needed for the one you ran:

  • Request Review — only the message template option you selected, in order to return the message text. It does not receive buyer identities or your conversation history.
  • AI image mockup / redesign — the image URL you selected, the listing ID, the number of images and model requested, and an AI-provider API key field that is empty unless a key was saved on your device by an earlier version.
  • Store recommendations — your TikTok Shop payout and health summary, including settlement balances and the bank account type, identifier and status that TikTok displays to you.

This service may pass the data above to a third-party AI model provider, such as Google Gemini or OpenAI, solely to generate the result returned to you. Any AI-provider API key carried by the image-generation request is read from your own device and is never stored on Supover’s servers (Sections 4 and 6).

The seller, payment and fulfillment platforms you connect (TikTok Shop, PingPong, LianLian, WorldFirst, Printify, Gearment, SimplePrint, FlashShip) Requests are sent to these services, using your own authenticated session, to read and update your data at your direction. Their handling of that data is governed by their own privacy policies.
Cloud storage (Backblaze B2) Your account avatar, for hosting.
Image CDN (www.gravatar.com) The generic placeholder avatar used when your account has no picture is loaded from this public image CDN. Like any image request, it may receive standard request metadata such as your IP address, browser user-agent, language/header information and referring site origin. No account, store, order, product or personal data is intentionally sent to it; the placeholder avatar URL is a fixed generic image and contains nothing derived from your email address.

We do not sell, rent, or share your personal or sensitive data with third parties for their own marketing or any unrelated purpose. There are no advertising networks, analytics trackers or data brokers involved. We may disclose data only where required by law or valid legal process.

10. Data Deletion & Your Rights

You may request access to, a copy of, correction of, or deletion of your personal data held by Supover by emailing us at the address in Section 13. We will verify your identity and respond within 30 days. Depending on where you live you may also have the right to object to or restrict processing, to data portability, and to lodge a complaint with your local data protection authority. Uninstalling the Extension immediately removes all locally stored data from your browser.

11. Children’s Privacy

The Extension is intended for business sellers and is not directed to children under 13. We do not knowingly collect data from children. If we learn that we have collected data from a child under 13, we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced on this page and reflected by updating the “Last updated” date at the top.

13. Contact Us

If you have any questions about this Privacy Policy, or to make a data access or deletion request, contact us at:
Data controller: Dragon Media LLC, trading as Supover, operator of ai.supover.com
Address: 6545 Market Ave N, Suite 100, Canton, OH 44721, United States
Email: support@supover.com
Tel: +1 (310) 620 3752
Website: https://supover.com