Platform API Compliance
Supportive is built to comply with the developer policies, data use requirements, and terms of service of every platform we integrate with.
TikTok Business API
Authorized Usage Only
Supportive accesses TikTok Business accounts exclusively through TikTok's official OAuth authorization flow. Users explicitly grant permission.
OAuth Authentication Flow
Users are redirected to TikTok's authorization page. Supportive never handles TikTok passwords or credentials directly.
Permissions Requested
We request only the minimum scopes required: read and send Direct Messages on behalf of the business account holder.
Revocation
Users can revoke Supportive's TikTok access at any time from Settings or directly from TikTok's connected apps page.
Meta (Facebook & Instagram)
Authorized Usage Only
Facebook Pages and Instagram Business accounts are connected through Meta's official OAuth login flow with explicit user consent.
OAuth Authentication Flow
Users authorize Supportive via Meta's secure login dialog. We receive a page access token with the permissions explicitly granted.
Permissions Requested
We request pages_messaging, instagram_basic, and instagram_manage_messages — only what is needed for inbox functionality.
Revocation
Users can disconnect Meta integrations from Supportive Settings or from Facebook's Business Integrations page at any time.
General Compliance Principles
Compliance questions? compliance@supportive.com