Security policy overview
Version 1.0 · effective September 12, 2026. BATONNEWS LLC operates RealBilShop Analytics as a one-user internal pilot. This overview summarizes the security, access, data classification, privacy, incident response and vulnerability procedures issued for this project. The owner is accountable for these procedures and reviews them quarterly and after material changes or incidents.
Access and data handling
Access is limited to the owner and tools authorized for specific tasks. The private app requires the configured owner identity and private-network access; anonymous access is rejected. Its public waitlist is a separate deployment. Current developer integration work is limited to approved read-only creator permissions, subject to app approval and separate account authorization.
Our classification policy distinguishes public, internal, confidential and restricted data. Non-public post records, credentials and identity documents receive the strictest handling and are excluded from public deployments. Data collection and disclosure must be necessary for the stated purpose. A public post does not grant commercial reuse rights. Provider and AI-assisted processing require scope review; we do not represent all processing as US-only.
Current controls and limits
The current primary private storage and transferred backups are encrypted. Retained legacy working and rollback copies still require a separate retirement process; we do not claim that all historical copies are encrypted. We verify recovery before destructive cleanup and preserve private post visibility.
A local monitor runs every five minutes while the signed-in Windows host is available. It checks defined access-denial and server-error patterns, Windows antivirus and firewall status, private service binding, selected source changes and encrypted-backup freshness. An owner-only status page shows findings and stale monitoring status. Security events contain a timestamp and event kind, not request contents, identities or tokens. They are pruned after 30 days; resolved alert records after 90 days, when the monitor runs.
These checks are limited signals, not proof that a breach cannot occur. They do not provide a staffed 24-hour response service or automatic external notification. Initial Windows protection checks passed; complete enforcement of endpoint locking and account MFA across all systems remains under verification. We claim no independent security certification.
Incident response and reporting
Report suspected security or privacy problems to quickshipquirks@yahoo.com. The owner records and assesses the report, contains affected access, preserves minimal evidence, investigates scope and restores only after relevant checks. The owner coordinates notices to TikTok Shop, affected counterparties or authorities when required through their verified channels. Our internal target is prompt initial communication, within 24 hours of awareness of a credible affected-data incident, or sooner where the applicable agreement or law requires. This is our target, not a statement of TikTok's contractual deadline.
Notifications are reviewed and sent by the owner. A detection threshold alone does not establish a breach, and a draft notification is not a completed report. Incidents receive a follow-up review and corrective actions.
Maintenance and privacy requests
The owner reviews relevant advisories and updates weekly, prioritizes exposed critical issues, tests changes and records unresolved exceptions. Access and data necessity are reviewed monthly. New providers, data sources and external users require review before activation. Our policies call for periodic incident exercises and isolated recovery tests; creating a procedure does not establish a history of completed exercises.
We assist with verified access, correction and deletion requests and commit to relationship-end deletion subject to actual legal or contractual requirements. Current analytics retention and backup deletion still have manual steps and implementation limits; our privacy notice explains them. Customer/API-data retention, revocation and deletion must be tested before expanded access. The terms of use describe the pilot's scope.