1. Integration principles
An authorised customer representative connects a channel. CCA requests limited scopes, displays the connected source, retrieves only permitted data and analyses it within the documented engagement. A platform connection does not create permission to access unrelated accounts, bypass platform controls or use every type of available data.
2. TikTok integration
The TikTok integration is designed for an organisation or authorised account representative to connect its own account. Certello uses the following products and scopes:
| Product | Scope | Purpose in CCA |
|---|---|---|
| Login Kit | Consent and account authorisation | Allows the TikTok user to sign in and grant the selected access. |
| Display API | user.info.basic | Reads permitted basic profile information to identify the connected account. |
| Display API | video.list | Reads public video metadata returned for the authorised user and presents it in CCA. |
| Data Portability API | portability.postsandprofile.single | Requests one Posts and Profile transfer after separate consent so permitted post media can be processed. |
Certello does not request portability.activity, portability.directmessages or portability.all. Certello does not describe this authorised integration as general crawling or scraping.
3. Display API
Display API is used for the connected account’s profile information and public video metadata that TikTok makes available. It can support an inventory view, captions or titles, publication data, TikTok links and permitted engagement metadata. It does not by itself provide a downloadable source-video file for transcription or OCR.
4. One-time Posts and Profile transfer
A Posts and Profile request is a separate, one-time user-authorised transfer. Before proceeding, CCA explains which data is requested and why. Where TikTok supplies a permitted media download link, CCA may temporarily process the file for transcription, OCR, evidence-frame extraction and compliance analysis.
The user journey shows the connection option, a pre-consent explanation, TikTok’s own authorisation page and a final connection or import result. The user can go back before authorisation.
5. Coverage and limitations
CCA reports only the records and fields made available by the selected platform access and successfully processed by the service. It does not guarantee that a platform returns every historical item. Coverage, unavailable records and processing failures must be reported transparently rather than inferred or fabricated.
Independent creators, influencers and third-party accounts require their own valid access basis and, where applicable, their own authorisation. One customer account cannot authorise access to another account.
6. Revocation, deletion and security
Connections can be revoked and associated data can be requested for deletion. Tokens are protected, permissions are limited, and temporary media is separated from retained findings and reports. Details are provided in the Privacy Policy and GDPR and deletion page.
7. Other platforms
Certello may support other platforms only after reviewing their product, API, OAuth, attribution, retention, deletion and review requirements. A platform name does not mean that the integration is active or endorsed by that platform.