SSS Social is a social media management product operated by SSS Trading, a company registered in Bangladesh. This policy describes what information SSS Social collects, how we use it, what we receive from the social platforms you connect, and how you can remove it.
01 Who we are
SSS Social (social.ssstrading.site) lets a business schedule and publish content across its own social media accounts from one dashboard. It is one of the products operated by SSS Trading. SSS Trading is the data controller for the information described here.
02 Information you give us
- Account details — name, email address, and password (stored only as a bcrypt hash). You may instead sign in with Google, Facebook, GitHub, or Discord, in which case we receive your basic profile and email from that provider.
- Workspace content — the posts, captions, hashtags, images, and videos you upload to publish or schedule, plus templates and saved replies you create.
- Team information — the members you invite to your workspace and the role you assign them.
03 Information we receive from connected platforms
When you connect a social account, we receive only what you authorise in that platform's own consent screen, and we use it only to operate the features you asked for.
| Platform | What we receive | What we do with it |
|---|---|---|
| TikTok | Your TikTok user identifier (open_id), display name and avatar, and the creator settings TikTok returns before posting (nickname, allowed privacy levels, and whether comment, duet, and stitch are available on your account). |
Show you which TikTok account is selected, present only the posting options TikTok says your account permits, and publish the video you explicitly submit. |
| Facebook & Instagram | Your name and email, the Pages you manage, the Instagram Business accounts linked to them, and the id and link of each post we publish for you. Only where Facebook grants the matching permission: comments and messages on those Pages, post insights, and lead form submissions. | Publish on your behalf and show you where each post went out. Where those permissions are granted, also show the comments, messages and post performance they cover. |
| YouTube | Channel identity, and the permissions needed to upload and publish the content you submit. | Publish on your behalf and read back the resulting post link and metrics. |
| Telegram | The identity of the bot you connect (its numeric id, username and name). Then, for each person who sends that bot a message: their Telegram numeric user id, the name and username Telegram supplies with the message, and the message itself. Telegram's delivery is recorded as it arrives, so it also contains whatever profile details Telegram chooses to include in it. | Show that conversation in your inbox and deliver the replies you write. We do not read chats your bot is not part of, we do not read your personal Telegram account, and we never message anyone who has not messaged your bot first. |
Telegram works differently from the others and it is worth being plain about it. There is no consent screen: you create a bot with Telegram's BotFather and give us its token, which lets us receive messages sent to that bot and reply to them. It is also the one channel where what we hold is mostly not about you — it is about the people who choose to contact your business. We hold their messages so that you can answer them, we keep them only while the conversation is in your inbox, and if you disconnect the bot, Telegram stops sending us anything.
We never receive your password for any connected platform. We do not use platform data for advertising, we do not sell it, and we do not use it to train machine learning models.
04 How we use TikTok data
If you connect a TikTok account, we use the access token TikTok issues solely to: (a) identify the connected account in your dashboard, (b) request your current creator settings immediately before you compose a post, so the privacy, comment, duet, and stitch options we show you are the ones TikTok actually permits, and (c) upload and publish the specific video you submit, with the privacy level you select. Nothing is posted without your explicit action. We do not read your TikTok inbox, your followers, or any content you did not create through SSS Social.
05 How we use YouTube data
SSS Social uses YouTube API Services. Google's own handling of your data is described in the Google Privacy Policy, and content you publish is also subject to the YouTube Terms of Service.
If you connect a YouTube channel, we use the token Google issues solely to: (a) read your channel's name, identifier, and avatar, so you can see which channel is selected, (b) upload and publish the specific video you submit, with the title, description, and privacy setting you choose, and (c) read back that video's processing status and its public view, like, and comment counts, to report how the post performed. Nothing is uploaded without your explicit action. We do not read your subscriber list, your inbox, or any video you did not publish through SSS Social.
You can revoke SSS Social's access to your Google account at any time from the Google security settings page. Disconnecting the channel in SSS Social deletes the stored token immediately.
06 Information collected automatically
IP address, browser and device type, referring URL, page timestamps, and basic usage events. We use these to keep the service secure, diagnose faults, and understand aggregate usage. We do not build advertising profiles.
Counting visits to our public pages. When you open one of our public pages (the home, features, pricing, guide, how-to, support and policy pages), your browser tells our server which page it was and, on the first page of a visit, which website linked you here. We count page views this way without cookies and without storing anything on your device. Your IP address is used for only two things, in our server's memory, and is then discarded — it is never stored:
- to look up an approximate country and city in an offline database on our own server (IP geolocation by DB-IP; no outside service is asked), so we can count visits per location; and
- to make a one-way hash that changes every day, so the same visitor is counted once per day rather than once per page. The daily secret behind the hash is deleted at the end of the day, together with the day's hashes, after which they cannot be linked to anyone.
What we keep is totals only: views and visitors per page, per country and city, and per day, plus the domain (never the full address) of sites that linked to us. Automated visitors such as search-engine crawlers and other bots are recognised and counted separately from people. Pages you use after signing in are not counted this way.
07 Information stored on your device
SSS Social stores a small amount of information in your browser's local storage and session storage, on the device you are using. This is what it is, in full:
| What is stored | Why | Removed when |
|---|---|---|
| Your signed-in session token | Keeps you signed in as you move between pages, so you are not asked for your password on every screen. | You sign out, or you clear your browser's site data. |
| Which workspace you last had open | Reopens the same workspace next time instead of making you pick it again. | You sign out, or you clear your browser's site data. |
| A post you are in the middle of uploading | Lets a large video upload survive a page refresh or an accidental navigation, instead of being lost. | The post finishes publishing, or you discard it. |
| A creator invitation you are sending | Carries the creator's username and role across to the invitation screen so you do not have to type them twice. Session storage only. | You close the browser tab, or you clear your browser's site data. |
| A support-console session (SSS Trading staff only) | Keeps a staff member signed in to the read-only support view. It is never created for a normal account. | The staff member signs out, or the session expires. |
We do not use cookies or local storage for advertising, and we do not track you across other websites. SSS Social sets no advertising or analytics cookies of its own, loads no third-party advertising or analytics scripts, and none of the information above is shared with anyone. You can delete all of it at any time using your browser's "clear site data" control; the only effect is that you will be asked to sign in again.
Third parties that may store information on your device:
- The platform you sign in with. Connecting a Google/YouTube, Facebook, Instagram or TikTok account takes you to that provider's own website to approve it. That provider may place, access or recognise its own cookies on your device while you are there, under its own privacy policy — not ours. We never see those cookies.
- Our payment provider. If you buy a package, you are taken to a checkout page hosted by our payment provider, Creem (
creem.io), where the payment is entered. Creem may store information on your device to process the payment and prevent fraud, under Creem's own privacy policy, and that happens on Creem's pages rather than ours. Our own pages load no payment script and place nothing on your device for payment; no card details ever reach our servers.
08 How we share information
We do not sell your personal information. We share it only:
- With the platform you publish to — the post, caption, media, and options you selected are sent to that platform's API at your request.
- With the platform you are messaging on — a reply you write in the inbox is sent to that platform (Telegram, or a Meta platform) so it reaches the person you are answering. Nothing is sent until you send it.
- With service providers — cloud hosting and email delivery, acting under contract and only as needed to run the service.
- With other members of your workspace — colleagues you invite can see the workspace's connected accounts, posts, and inbox.
- When legally required — under Bangladeshi law or a valid court order.
- On a business transfer — with protections at least as strong as this policy.
09 Storage, security and retention
Data is stored in a PostgreSQL database on managed cloud infrastructure. All traffic uses TLS, passwords are hashed with bcrypt, and platform access tokens are stored encrypted with least-privilege access controls.
We keep your workspace data while your account is active. Disconnecting a social account deletes its stored access token immediately. If you delete your account, personal data is removed or anonymised within 30 days, except where law requires longer retention.
Images and videos you upload for a post, and videos we render for one, are held on our servers only until the post has been published everywhere it was sent, and are deleted about 30 minutes after that (about 7 days after a post that could not be published, so you can fix and resend it). Your post history keeps the caption and links to the published posts, not the files. A video you generate to download is never stored beyond the short window in which you can fetch it. Pictures that a post links to on your own website are never copied to our servers at all.
10 Your choices and rights
- Disconnect any platform at any time — Accounts page in SSS Social, which revokes and deletes the stored token. You can also revoke access from the platform itself (for TikTok: Settings and privacy → Security and permissions → Manage app permissions).
- Correct or export your account information from Settings.
- Delete your data — submit a request through our Data Deletion page. No SSS account is required to submit one.
- Ask us anything — admin@ssstrading.site.
11 Children
SSS Social is a business tool and is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact us and we will delete it.
12 International users
SSS Trading is registered in Bangladesh. Data is processed on infrastructure that may be located in Bangladesh, Singapore, or other regions where our cloud providers operate. By using SSS Social you consent to this processing.
13 Changes
We may update this policy. Material changes will be announced by email or by a banner in SSS Social at least 30 days before they take effect.
14 Contact
197/B, Road No. 5, Mohammadia Housing Limited, Mohammadpur, Dhaka-1207, Bangladesh
Email: admin@ssstrading.site
Governing law: Bangladesh.