Privacy Policy for STONK AI GMV Chrome Extension

This privacy policy explains how the STONK AI GMV Chrome Extension collects, uses, processes, stores, protects, deletes, and shares user data. It also explains the prominent disclosure and consent flow used before user data is collected for extension features.

Product: STONK AI GMV Chrome Extension
Current reviewed version: 56.6.9 or later
Chrome Web Store item ID: paegnhaplcckghdkmmdcbdabmimljmil
Developer and data controller: Công ty TNHH Truyền thông và Dịch vụ Stonk Agency (Vietnam)
Effective date: July 20, 2026
Privacy contact: privacy@stonkagency.vn
Support site: https://stonkagency.vn/

1. Summary and single purpose

STONK AI GMV is a business operations extension for authorized TikTok Shop sellers, shop operators, and agency staff. Its single purpose is to help authorized users operate TikTok Shop workflows, advertising workflows, reports, recaps, content/video analysis, LIVE operations, export tools, and optional cloud synchronization for the shops and accounts they manage.

Limited use summary

STONK AI GMV does not sell user data, does not use user data for personalized advertising, does not transfer user data to data brokers, and does not use user data to determine credit worthiness or for lending purposes.

2. Prominent disclosure and user consent before collection

Plain-language disclosure shown inside the extension

STONK AI GMV processes STONK login information; TikTok cookies, session identifiers and account identifiers; and shop, advertising, product, video, LIVE and report data from the supported TikTok pages. This data is used to authenticate the user, display operational dashboards, synchronize authorized shops, perform actions requested by the user, and run reports or alerts enabled by the user.

Data may be stored in the user's Chrome profile. Data is sent to STONK servers only for authentication, licensing, update delivery, user-enabled cloud synchronization/backup, or other server features requested by the user. Data is sent to Telegram, Zalo, Google Apps Script/Sheets, Gemini or another configured service only when the user enables or invokes that integration.

The login and registration screens display this disclosure immediately next to a consent checkbox. The checkbox is not pre-selected. The user must affirmatively select it before login or registration credentials are transmitted. The extension records the fact, time, source and policy URL of that consent in local Chrome storage. Existing signed-in users who have not accepted this consent version are shown the same disclosure before the extension menu is made available.

Automatic seller-page signal processing is gated by the recorded privacy consent. Cloud Sync has a separate accept/decline dialog. Optional Telegram, Zalo, Google Apps Script/Sheets, Gemini AI, local relay, media download, report scheduling and campaign/video actions require a separate configuration, button, toggle or confirmation. Declining Cloud Sync does not prevent local workflows that do not require it.

If the extension introduces a materially different data practice after installation, the extension will disclose that change in the product interface or release notes before the changed data practice starts, and will require the user to enable or continue the relevant feature.

3. Data the extension may collect, access, or process

The exact data depends on which features the user chooses to use. The extension may collect, access, or process the following categories only as needed for user-facing features.

Data category Examples Purpose Default storage / transmission
STONK account and authentication data Username, password submitted for login or password change, session token, license status, extension version. Sign in, license validation, account status, version updates, support, and security. Password is transmitted over HTTPS to STONK authentication services and is not saved by the extension in Chrome storage. Session tokens may be stored locally to keep the user signed in.
TikTok authentication/session data TikTok Shop or TikTok Ads cookies, CSRF values, active session state, seller identifiers, advertiser identifiers. Read or submit TikTok Shop/TikTok Ads workflows requested by the user, such as reports, campaign operations, shop/account mapping, and automation within the user's authorized account. Stored locally when needed for the user's workflow. Sent to STONK cloud only if the user enables cloud sync, backup, multi-device access, or a related user-requested automation feature.
Website content and business resources Shop names, seller IDs, product IDs, product names, campaign names, campaign IDs, video IDs, creator names, live room IDs, promotion information, page tables, and visible operational page state. Show dashboards, detect shop context, build reports, analyze Ads/Content/LIVE status, and perform user-requested shop, campaign, video, and product workflows. Usually stored locally as cache or operational state. Selected data may be sent to configured report destinations or STONK sync services when the user enables those features.
Shop, Ads, LIVE, content, and report metrics Revenue, GMV, ad spend, ROI, CPO, order count, clicks, impressions, views, CTR, CVR, budgets, balances, product performance, LIVE metrics, video performance, and report date ranges. Generate dashboards, reports, quick recap messages, business alerts, campaign recommendations, and operational task queues. Stored locally and optionally transmitted to STONK services, Telegram, Zalo, Google Sheets, Apps Script, or Gemini only when the user enables or starts those features.
User settings and configuration Selected shops, privacy-consent record, feature toggles, report schedules, timezone, currency settings, manual exchange rates, profit margin settings, sync server URL, local relay URL, and automation settings. Remember user preferences, run scheduled reports, prevent duplicate sends, and keep workflows consistent across sessions. Stored in Chrome local storage; limited video-tool preferences may use Chrome Sync so the user's own Chrome profile can synchronize them. Selected settings may be backed up to STONK cloud only if the user enables cloud sync or account backup.
Optional integration credentials Telegram bot token, Telegram chat IDs/topic IDs, Zalo group/user IDs, Zalo relay host, Google Apps Script or Google Sheets URLs, Gemini API key, local relay secret. Send reports or alerts, export to Sheets, request AI analysis, or connect to user-configured local/third-party workflows. Stored locally unless the user enables sync/backup. Transmitted only to the configured destination or STONK service required to provide the enabled feature.
Downloaded media metadata TikTok video URLs or IDs, creator names, product labels, download status, and generated filenames. Support user-requested TikTok video viewing or download features. Stored locally as operational state. Sent to Tikwm only when the user starts a video download or video retrieval action.
Diagnostics and logs Scheduler state, sync status, send status, request status, error messages, queue status, retry status, and duplicate-send prevention keys. Operate scheduled workflows, troubleshoot failures, prevent duplicate sends, maintain reliability, and support security investigations. Stored locally. Relevant diagnostics may be transmitted to STONK support/services only for support, reliability, security, abuse prevention, or user-requested troubleshooting.
Authorized organization and role data Assigned username, role, organization/shop ownership, permitted child shops, and operator-to-shop mappings. Restrict each user to authorized shops, allow an authorized organization administrator to manage assigned users/shops, and support scheduled reporting for those shops. Stored locally and on STONK servers as required for account authorization, cloud synchronization and organization administration.

The extension is not designed to intentionally collect payment card numbers, bank account credentials, government ID numbers, health information, or personal passwords unrelated to STONK login and the supported user-requested services.

4. How data is collected

5. How data is used and processed

Data is used only to provide or improve the extension's disclosed single purpose, including:

6. All parties user data may be shared with

STONK AI GMV does not sell user data. User data is shared only when required for a feature the user is actively using, has configured, or has enabled.

Party / service Data that may be shared Purpose When shared
TikTok, TikTok Shop, TikTok Ads, Affiliate, and related TikTok domains Shop/session identifiers, campaign/product/video/LIVE data, form values, and workflow actions. Read or submit seller, ads, product, video, promotion, affiliate, or LIVE workflows requested by the user. Only when the user opens supported pages or starts a supported TikTok workflow.
STONK-operated services such as sync.stonkagency.vn, data.stonkagency.vn, tool.stonkagency.vn, gmv.stonkagency.vn, and policy.stonkagency.vn Account/license data, consent status, selected shop/account bindings, selected configuration, selected cookies/session data when cloud sync is enabled, reports, recap payloads, logs, and update/version data. Login, license validation, cloud sync, backup/restore, account management, report transport, update delivery, support, reliability, and abuse prevention. When the user signs in, enables sync/backup/report/cloud features, requests support, or checks for updates.
Telegram Telegram bot token, chat IDs, topic IDs, report text, recap text, alerts, and send status. Send user-configured Telegram reports, alerts, recaps, or summaries. Only when the user configures Telegram and manually sends or enables scheduled sending.
Zalo relay services Zalo group IDs, user IDs, relay host, report text, recap text, alerts, and send status. Send user-configured Zalo reports, alerts, recaps, or summaries. Only when the user configures Zalo and manually sends or enables scheduled sending.
Google Apps Script or Google Sheets Configured Apps Script/Sheets URL, selected report rows, shop metrics, Ads metrics, date ranges, and send status. Export reports or summary data to the user's configured Google destination. Only when the user configures Google export and manually sends or enables scheduled export.
Google Gemini / Google AI API Normalized business metrics, candidate tasks, shop/campaign/video/product context, and optional user-provided Gemini API key. Provide optional AI-assisted explanation, prioritization, and analysis. Only when the user enables AI analysis and provides or uses a valid AI configuration. AI is not allowed to execute actions automatically.
Tikwm TikTok video URL or video ID and related metadata needed to retrieve media. Support user-requested TikTok video viewing or download features. Only when the user starts a video retrieval/download feature.
Exchange-rate providers such as Vietcombank, Open ER API, or FXRatesAPI Currency pair/rate requests and date/rate metadata. Convert foreign-currency Ads or report values into the user's selected currency. Only when currency conversion is used or configured.
User-configured local relay servers Only the payload needed for the local workflow configured by the user. Support local automation or report delivery controlled by the user. Only when the user enters and enables a local relay URL.
Infrastructure, hosting, security, and legal recipients Operational logs, account metadata, diagnostics, and security-related data. Host, secure, monitor, troubleshoot, prevent abuse, comply with law, or respond to valid legal requests. Only as necessary for operations, security, support, abuse prevention, or legal compliance.
Authorized administrators inside the user's organization or managed workspace Assigned shop names/IDs, operational metrics, report configuration, account/shop mapping and, only where required for the configured managed-report workflow, synchronized TikTok session data for assigned shops. Allow an authorized owner or agency administrator to operate and troubleshoot the shops/users placed under that administrator's responsibility. Only within role-based access assigned by STONK or the organization. Data is not made public or shared with unrelated customers.

7. Storage and retention

8. Chrome permissions and why they are necessary

The extension requests only permissions used by currently implemented user-facing features.

PermissionHow it is usedUser-data impact
storageStore consent, settings, selected shops, caches, report state, scheduler checkpoints and integration configuration.Data remains in the user's Chrome profile unless a disclosed cloud/integration feature sends it elsewhere.
unlimitedStoragePrevent large multi-shop, campaign, product and video caches from failing Chrome's small default quota.Does not itself transmit data.
tabsFind/open supported TikTok or STONK pages, detect the active supported workflow and communicate with those tabs.The extension does not collect the user's general browsing history; tab access is used for the supported domains and user-requested workflows.
scriptingInject the implemented helper/UI into a supported page when needed for a feature.Limited to the declared supported host permissions.
cookiesRead TikTok Shop/TikTok Ads session cookies needed to call TikTok endpoints for the user's authorized accounts and reports.Cookie/session data is sensitive; Cloud Sync transmission requires the separate consent/control described above.
contextMenusOffer user-invoked TikTok video/product helper actions from Chrome's context menu.Only the selected page/resource context is processed for that action.
alarmsRun report, recap, LIVE review and retry schedules enabled by the user.Scheduled transmission occurs only for destinations and schedules configured by the user.
offscreenKeep supported background media/report helper work available where a visible page is not appropriate.Does not add a separate data purpose.
downloadsSave user-requested exports, media and cookie-backup files.Files are saved to the user's device through Chrome's download system.
declarativeNetRequestWithHostAccessApply narrowly scoped request rules needed for supported TikTok/extension workflows.It is not used to monitor unrelated websites or create an advertising profile.
Declared host accessConnect only to the listed TikTok/ByteDance, STONK, Telegram, Zalo, Google, Tikwm and exchange-rate endpoints used by disclosed features.Optional third-party hosts receive data only for the feature the user enables or invokes.

9. Security and safe transmission

STONK AI GMV is a business operations tool. Users should not enter unrelated sensitive personal data such as payment card numbers, bank account credentials, health data, or government ID numbers into the extension.

10. Chrome Web Store Limited Use statement

STONK AI GMV uses user data only to provide or improve the extension's disclosed single purpose and related operational purposes such as security, reliability, abuse prevention, support, and performance.

The extension does not use or transfer user data for personalized advertising, does not transfer or sell user data to advertising platforms, data brokers, or information resellers, and does not use or transfer user data to determine credit-worthiness or for lending purposes.

Required Limited Use disclosure: STONK AI GMV's use and transfer of information received through Chrome extension APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

11. Human access to user data

Human access to user data is limited. STONK personnel may access user data only when the user requests support or recovery, when required for security or abuse prevention, when the data is aggregated and anonymized for internal operations, or when required by law.

Authorized owners or administrators of a managed organization may access operational data for the users and shops explicitly assigned to them. This role-based product access is used to operate assigned shops, scheduled reports and account recovery; it is not access by unrelated customers or the public.

12. User choices and controls

13. Children

STONK AI GMV is intended for business users and is not directed to children under 13. We do not knowingly collect personal information from children.

14. Changes to this policy

We may update this policy when the extension's features, data flows, legal requirements, or Chrome Web Store policies change. The latest version will be published at the privacy policy URL provided in the Chrome Web Store listing.

15. Chrome Web Store user-data disclosure map

The developer's Chrome Web Store Privacy Practices answers must remain consistent with this policy and the current extension build. For clarity, the current extension handles the following Chrome Web Store data categories:

Chrome Web Store categoryHandled?Exact scope
Personally identifiable informationYesSTONK username, display name, email, phone number, seller/shop/account IDs and user-configured recipient IDs used for account, licensing, authorized-shop mapping, support and report delivery.
Health informationNoThe product does not request or intentionally process health information.
Financial and payment informationLimited business metricsShop revenue/GMV, Ads spend, budgets, balances, ROI and related commercial metrics. The extension does not request payment-card numbers, online-banking credentials or consumer credit information.
Authentication informationYesSTONK login credentials during authentication, STONK session token, TikTok cookies/session values and optional third-party API credentials configured by the user.
Personal communicationsLimited outbound contentReport, recap and alert text sent to recipients configured by the user. The extension does not read the user's unrelated private Telegram, Zalo or email conversations.
LocationCoarse operational context onlyCountry/region, currency and timezone attached to a shop or advertising account where returned by the supported service. The extension does not request GPS or precise physical location.
Web historyYes, narrowly limitedThe current URL and supported-page context may be processed on declared TikTok/STONK domains to identify the active workflow and associate it with the correct authorized shop. The extension does not monitor unrelated websites or build/sell a cross-site browsing profile.
User activityLimited to product workflowsUser-selected shop/campaign/video/product actions, report scheduling, integration toggles and extension button/context-menu actions needed to execute and audit the requested workflow.
Website contentYes, supported domains onlyVisible page state and API data for authorized TikTok Shop, Ads, Affiliate, LIVE, product, campaign and video workflows.

16. Contact and privacy requests

For privacy questions, data access, correction, export, or deletion requests, contact: privacy@stonkagency.vn.

Please include the STONK username, the request type, and enough information for us to verify that the requester controls the account. Do not email TikTok cookies, passwords, Telegram tokens, Gemini keys or other secrets. Developer/data controller: Công ty TNHH Truyền thông và Dịch vụ Stonk Agency, Vietnam.

This page applies specifically to the STONK AI GMV Chrome Extension and is intended to satisfy the Chrome Web Store privacy policy, prominent disclosure, consent, secure handling, and Limited Use disclosure requirements for the current reviewed build.