1.Information We Collect
The FrontRow Events Publisher (the “Publisher”) is an internal tool. It does not offer accounts to the public, so it collects no personal information from visitors to this page or from members of the public generally.
In the course of operating, the Publisher handles three kinds of information:
Public event information
Event listings that have already been published openly by organisers, venues and ticketing pages — event title, description, venue, date and time, category, and the event image. This information is gathered by the FrontRow Events Crawler and stored in our PostgreSQL database. Where an organiser’s name appears in a public listing, it is treated as part of that public event record.
Authorisation credentials
OAuth access and refresh tokens issued by TikTok for the official FrontRow TikTok account. These are our own credentials for our own account. The Publisher does not request, receive or store credentials belonging to any other person.
Operational records
Records the service needs in order to publish reliably: which event was posted, to which platform, at what time, the caption used, the resulting platform post identifier, and any error message if publishing failed. Server logs may also record timestamps, error traces and request details.
2.How Information Is Used
Information is used only to operate the service. Specifically, to:
- select approved, upcoming events that are eligible to be promoted;
- generate a caption and hashtags describing the event;
- publish the event promotion to the official FrontRow TikTok account;
- record whether each post succeeded or failed, and retry failures;
- diagnose faults and keep the service running correctly.
We do not use this information for profiling, behavioural advertising or automated decision-making about individuals. We do not sell personal information, and we do not share it with third parties for their own marketing.
3.TikTok OAuth
The Publisher uses TikTok’s OAuth authorisation flow to obtain permission to post to the official FrontRow TikTok account. Authorisation is granted once, by a FrontRow administrator signing in to that account.
Through this integration the Publisher:
- requests only the scopes required to upload and publish content to the authorised account;
- stores the resulting access and refresh tokens securely, and refreshes them automatically when they expire;
- uses the tokens solely to publish FrontRow’s own event promotions.
The Publisher does not read other users’ TikTok content, does not access followers or direct messages, and does not act on behalf of anyone other than FrontRow. Authorisation can be revoked at any time from TikTok’s account settings, which immediately stops the Publisher from posting.
4.Cookies
This website sets no cookies. It uses no analytics, no advertising pixels and no cross-site trackers. Pages are static files served directly from Cloudflare Pages.
Cloudflare may set a strictly necessary cookie for security and bot mitigation as part of delivering the site. TikTok sets its own cookies when you visit TikTok; that is governed by TikTok’s privacy policy, not this one.
5.Data Storage
Event records and publishing history are stored in a PostgreSQL database operated by FrontRow. Event images are stored as files on FrontRow-controlled infrastructure and are read by the Publisher without modification.
Supporting infrastructure runs on Google Cloud, and Cloudflare provides DNS, TLS and content delivery for FrontRow’s public-facing sites, including this one. OAuth tokens are held in the service’s protected configuration and are encrypted at rest.
FrontRow operates from Kenya. Because our infrastructure providers run global networks, information may be processed on servers located outside Kenya.
6.Data Retention
- Event information is retained while the event remains relevant to the FrontRow platform, and thereafter for historical reporting.
- Publishing records — which event was posted and when — are retained so the service does not publish duplicates.
- Operational logs are retained for a limited period, normally no longer than 90 days, and then rotated out.
- OAuth tokens are retained only while the integration is active, and are deleted when authorisation is revoked or the integration is retired.
7.Third-Party Services
The Publisher depends on the following third parties, each governed by its own privacy policy:
- TikTok — publishing destination, via the Content Posting API.
- Cloudflare — DNS, TLS and hosting for these legal pages.
- Google Cloud — supporting infrastructure.
We share with these providers only what is necessary for them to deliver their service. We do not sell or rent information to anyone.
8.Security
We take reasonable technical and organisational measures to protect the information we hold, including encrypted connections (HTTPS/TLS) for all traffic, restricted access to production systems on a need-to-know basis, credentials held in protected configuration rather than in source code, and read-only access to the event database where the service does not need to write.
No system can be guaranteed completely secure, but we work to protect information against unauthorised access, alteration and loss.
9.Your Rights
Under the Kenyan Data Protection Act, 2019, and comparable data protection laws, you may ask us to confirm what information we hold about you, correct it if it is inaccurate, delete it, or restrict how we use it. You may also object to a particular use.
If you are an event organiser and you would prefer your publicly listed event not to be promoted by FrontRow, contact us and we will remove it from the publishing queue.
To exercise any of these rights, write to us using the details in section 11. We will respond within the period required by applicable law.
10.Changes to this Policy
We may update this policy as the service changes or as the law requires. The revised version takes effect when it is published on this page, and the “Last updated” date at the top will change to reflect it. Where a change materially affects how we handle personal information, we will take reasonable steps to highlight it.
11.Contact Information
Questions, requests or complaints about privacy can be sent to:
- Organisation
- FrontRow
- privacy@frontrow.co.ke
- Location
- Nairobi, Kenya
- Service
- FrontRow Events Publisher
The companion document sets out the rules for using this service.
Read the Terms of Service