Privacy Policy
Last updated: July 25, 2026
DraftPort is operated by VeraLayer Studio LLC. This Privacy Policy explains how we collect, use, disclose, and protect information in connection with the DraftPort website, private beta, application, seller tools, and seller-authorized integrations with ecommerce platforms such as TikTok Shop, Shopify, WooCommerce, eBay, Etsy, and other supported services.
DraftPort is a product intake, listing preparation, review, and channel publishing workflow for ecommerce sellers. DraftPort is designed for seller-controlled use: sellers review product data, images, prices, inventory, and channel readiness before creating or publishing listings.
Information We Collect
We may collect information you provide directly, such as your name, email address, company or shop information, beta request details, support messages, and account or onboarding information.
When you use DraftPort product and channel features, we may process product and listing workflow data that you submit, import, review, or authorize, including supplier product URLs, product titles, descriptions, images, variants, prices, inventory, SKU information, category data, compliance or readiness notes, channel payloads, publishing status, and related operational records.
If you connect a third-party channel or marketplace account, we may process data made available through that authorized integration. For TikTok Shop, the current DraftPort workflow is focused on seller-authorized product draft and listing preparation. It may include shop identifiers or shop context, product draft/listing data, product images, category information, warehouse or inventory settings needed for SKU creation, connection metadata, and API response data needed to create or support seller-reviewed product drafts. We do not access TikTok Shop data unless a seller authorizes the integration or otherwise provides the data to DraftPort.
DraftPort does not currently use TikTok Shop order, buyer, shipping, fulfillment, finance, or messaging data for the TikTok product-draft workflow. If those features are added later, we will update this Privacy Policy and the requested platform permissions before using that data.
We may also collect technical information automatically, such as IP address, device and browser information, request logs, error logs, security events, and usage information needed to operate, secure, debug, and improve DraftPort.
How We Use Information
We use information to provide and improve DraftPort, respond to beta and support requests, operate product intake and listing-preparation workflows, create and manage seller-reviewed channel drafts, authenticate and secure integrations, diagnose issues, prevent abuse, comply with legal obligations, and communicate about DraftPort access, updates, and service notices.
DraftPort does not sell personal information. We do not use seller-authorized TikTok Shop data or other channel integration data for unrelated advertising or for building unrelated consumer profiles.
Seller-Authorized Integrations
DraftPort may connect to ecommerce platforms and service providers only when a seller authorizes the connection, provides credentials, or otherwise enables the integration. API credentials, app secrets, and access or refresh tokens are handled outside public client-side code by non-public local or server-side service components. In the current private beta TikTok workflow, the local TikTok bridge stores authorization tokens in a non-public local token file used by that bridge.
Platform data is used to support the specific workflow requested by the seller, such as preparing product drafts, uploading product images, validating listing requirements, retrieving required shop context, or recording channel publishing status. Sellers remain responsible for reviewing listings and complying with each platform's policies before publishing.
Service Providers
We may share information with service providers that help us operate DraftPort, such as hosting, DNS, edge security, database, authentication, storage, email delivery, logging, analytics, support, and application infrastructure providers. These providers are authorized to process information only as needed to provide services to us and are not permitted to use it for their own unrelated purposes.
Current infrastructure and service providers include Cloudflare for hosting, DNS, edge delivery, security, and request handling; Supabase for database, authentication, and application data services; Resend for beta and support communications; and ecommerce/API providers that a seller authorizes DraftPort to use for seller-requested product intake and channel workflows.
Legal and Compliance Disclosures
We may disclose information if required to comply with applicable law, regulation, legal process, platform requirements, security investigations, or enforceable government requests. We may also disclose information to protect DraftPort, sellers, users, platforms, service providers, or others from fraud, abuse, security threats, or policy violations.
Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information, including HTTPS/TLS, restricted administrative access, managed infrastructure controls, server-side handling of sensitive credentials where supported, and operational monitoring. No system is completely secure, and we cannot guarantee absolute security.
Disconnecting Integrations
If you disconnect or revoke a third-party integration, DraftPort will stop using that authorization for future API access where technically applicable. Depending on the platform and current beta implementation, disconnection may require a manual request to VeraLayer Studio LLC or revocation through the platform's own seller/admin settings. We may retain limited records needed for security, legal, accounting, dispute, backup, or operational purposes.
Retention
We retain information for as long as needed to provide DraftPort, support seller workflows, maintain business and security records, comply with legal obligations, resolve disputes, enforce agreements, and improve the service. We may delete or de-identify information when it is no longer needed, subject to backup, security, fraud-prevention, legal, accounting, and operational retention needs.
Your Choices and Requests
You may contact us to request access, correction, export, deletion, or disconnection of information associated with DraftPort, subject to applicable law, platform requirements, identity verification, and technical limitations. Sellers can also revoke third-party platform authorizations through the relevant platform account settings when supported by that platform.
VeraLayer Studio LLC has not appointed a separate Data Protection Officer. The founder/administrator is responsible for privacy and data protection requests for DraftPort.
Children
DraftPort is intended for business use by ecommerce sellers and is not directed to children. We do not knowingly collect personal information from children.
International Processing
DraftPort is operated by VeraLayer Studio LLC in the United States. Our service providers may process information in the United States and other locations where they operate, subject to their service terms, technical configuration, and data processing safeguards.
Changes to This Policy
We may update this Privacy Policy as DraftPort evolves, including when we add new product features, integrations, service providers, or data practices. The "Last updated" date above shows when this policy was most recently revised.
Contact
Questions, privacy requests, disconnection requests, deletion requests, and data protection inquiries can be sent to yurian@veralayerstudio.com.