Internal tool — no public sign-up
Eleven ads managers, one place to see what the money is doing.
Drumlee is a back-office console built for our own team. The advertising is ours and so is the budget behind it; each account is connected by the person on the team who holds it. The console exists to answer one question every morning — what did we spend yesterday, and what should be switched off today — without opening every ads manager by hand.
19 Aug 2026 11 accounts synced 3 ahead of pace 2 paused by threshold 0 sync errors
Example of the daily digest the console produces — not live dataWhat the console does
Drumlee is not sold, resold or offered to anyone outside the team, and there is no way to sign up for it. An advertising account appears in the console only after the team member who holds that account has authorised it in TikTok Ads Manager, and it disappears again the moment they revoke that authorisation.
- Account roster
- Every connected account on one screen, with its currency, time zone and the budget we set for it.
- Pace against budget
- Yesterday's spend and spend to date measured against that budget, so an account running hot is visible before the day is over rather than at the end of the week.
- Switching things off
- Pausing, resuming or removing campaigns, ad groups and ads in the connected accounts when a threshold is crossed or a test has run its course.
- One report, not eleven exports
- Impressions, clicks, conversions and cost pulled into a single daily figure per account instead of a manual export from each ads manager.
Removing a campaign, ad group or ad deletes that object inside the connected advertising account and the platform cannot undo it. That is a different action from erasing the data Drumlee stores, which is covered on the Delete data page.
What we ask the TikTok Marketing API for
Three permission groups, each tied to a function above. The ledger below is the whole of it — and the second ledger is the part we think matters more: the permissions we leave on the table because nothing in Drumlee would use them.
Not requested
- audiences
- creatives & video upload
- catalogues & product feeds
- pixels & events
- lead generation forms
- comment management
- Business Centre asset management
- identity & Spark Ads posts
We have not asked for any of these, because Drumlee has no screen that would show them and no job that would need them. Nothing is moved into or shared through a Business Centre of ours; each account is authorised on its own.
How an account gets connected
There is no public sign-up page. The team member who holds an account is sent a one-time authorisation link, and this runs once for that account.
-
Authorise The person who holds the account approves Drumlee inside TikTok Ads Manager and is returned to
/auth/callbackon this domain. -
Sync Once a day the console reads that account's campaign structure and its performance report for the previous day.
-
Flag Spend is compared with the budget we set. Accounts running ahead of pace are marked in the digest.
-
Act A team member reads the digest and pauses, resumes or removes what needs it. Every change is recorded against the person who made it.
-
Disconnect Revoking access in TikTok Ads Manager kills the token at once, and the stored data is erased as set out under Delete data.
What we hold, and for how long
Everything Drumlee obtains through the TikTok Marketing API is used to run the advertising accounts our team advertises through, and for nothing else.
| Data | Why it is held | Kept for |
|---|---|---|
| Advertiser ID, name, currency, time zone | Attributing records to the right account and reporting in the right currency | Until the account is disconnected |
| Campaign, ad group and ad IDs, names, status, budgets | Showing the account structure and changing the status of its objects | Rolling 18 months |
| Spend, impressions, clicks, conversion counts | Pacing against budget and building the daily digest | Rolling 18 months |
| Access and refresh tokens | Keeping the authorised session alive between daily syncs | Encrypted; erased on disconnect |
We do not sell data obtained through the API, pass it to advertising networks or data brokers, use it to profile individuals, use it to train machine learning models, or touch any account that has not been connected to the console by the person who holds it. The full account is in the privacy policy.
Safeguards
- Tokens are never visible
- Access and refresh tokens are encrypted at rest, held server-side, and never rendered in the interface or written to logs.
- Named access only
- The console is reachable by named members of the team over authenticated sessions. There is no shared login and no anonymous access.
- Least privilege, and it is checked
- Only the three permission groups listed above are requested. When a feature is retired, the permission behind it goes with it.
- Revocation is immediate
- Withdrawing the authorisation in TikTok Ads Manager invalidates the token straight away and starts the erasure described under Delete data.
Contact
Questions about the console, this website, privacy or erasure all go to the same address. We acknowledge every message within 3 working days; privacy and erasure requests are then completed within the periods set out in the privacy policy and under Delete data.
Operator
Drumlee Properties Limited
Registered in Northern Ireland, company number NI063033
Fpm Chartered Accountants, 1–3 Arthur Street, Belfast BT1 4GA