Skip to main content

Your catalogue, open to AI shoppers.

See how
GDPR & CCPA Compliant

Privacy Policy

Cresva, Inc. provides a SaaS analytics platform (the "Service"). We respect your privacy and are transparent about how we collect and use data to deliver and improve the Service.

Last updated: August 28, 2026

Legal name: Cresva, Inc. • Privacy Contact: hello@cresva.ai

California Residents (CCPA)

We do not sell or share your personal information. You have rights to access, delete, and opt-out. See Section 10 for details.

Request Data Deletion →

1. Information we collect

We collect the following categories of information:

a) Account Information

  • Name, email address, company name
  • Google OAuth profile data (if you sign in with Google)
  • Timezone, language preferences

b) Connected Platform Data

  • OAuth tokens for connected platforms (Meta Ads, Google Ads, Google Analytics, Google Tag Manager, Google Merchant Center, TikTok, Shopify, Klaviyo, Slack, Notion)
  • Campaign performance data (spend, revenue, impressions, clicks, conversions)
  • Ad account names, campaign names, creative performance metrics
  • Historical performance data for forecasting

c) Service Usage Data

  • Questions you ask in the chat feature
  • Dashboard views, report generation, forecast requests
  • Feature usage, clicks, interactions within the Service
  • Team member invitations and permissions

d) Technical Data

  • IP address, browser type, device information
  • Log data, error reports, performance metrics
  • Cookies and similar tracking technologies (see Section 6)

e) Payment Information

  • Billing details (processed by Stripe; we don't store full credit card numbers)
  • Transaction history, invoices

f) Communications

  • Support tickets, feedback, emails you send us
  • Survey responses, product feedback

Important: Where an agent can act on a platform, we request the write access those actions need. The exact scopes are shown to you by that platform's own consent screen before you grant anything, and you can revoke them there at any time.

By default an agent proposes a change and it does not run until you approve it. That default is a per-brand setting you control, and raising it is deliberate: a higher level asks you to confirm, and full autonomy asks you to type a confirmation. Whatever the setting, every change an agent makes is recorded in an audit log you can read.

For users in the EU/UK, we process your personal data under the following legal bases:

Contract Performance

We process your data to provide the Service you signed up for (account management, analytics, forecasts, etc.)

Legitimate Interests

We process data to improve our Service, prevent fraud, ensure security, and send relevant product updates (you can opt out of marketing emails)

Consent

For cookies (other than essential ones), AI training on your data, and marketing communications, we ask for your explicit consent

Legal Obligations

We may process data to comply with laws, regulations, court orders, or tax requirements

3. How we use your data

We use the information we collect to:

Provide & maintain the Service

Process your ad data, generate forecasts, answer questions via chat

Improve & develop features

Analyze usage patterns, fix bugs, develop new features

Customer support

Respond to your questions, troubleshoot issues

Security & fraud prevention

Detect and prevent abuse, unauthorized access, and security threats

Communications

Send service updates, billing notices, security alerts (you can opt out of marketing emails)

Legal compliance

Comply with laws, regulations, court orders, tax obligations

4. AI & machine learning

🤖 How we use AI

Cresva uses AI and machine learning to analyze your marketing data, generate forecasts, and provide insights. This processing happens in real-time and is essential to the Service.

AI Training & Your Data:

  • We do NOT use your individual marketing data to train general AI models unless you explicitly opt in
  • We may use aggregated, anonymized data (with no personally identifiable information) to improve our models
  • If you want to opt out of even anonymized data usage for AI training, contact us at hello@cresva.ai

Third-party AI providers: We may use AI services from providers like OpenAI, Anthropic, or Google. Your data is processed according to their privacy policies and data processing agreements. We do not allow these providers to use your data for their own model training without your consent.

5. Sharing & subprocessors

⚠️ We do NOT sell your data

We never sell your personal information to third parties. Period.

We may share your data with:

Service Providers (Subprocessors)

We use trusted third-party services to help operate Cresva:

  • Hosting: Vercel (infrastructure), AWS/Google Cloud (storage)
  • Payments: Stripe (payment processing)
  • Analytics: PostHog, Google Analytics (anonymized)
  • Advertising measurement: Google Tag Manager, Meta Pixel, loaded only after you grant analytics or marketing consent in our cookie banner; see Section 6
  • AI Services: OpenAI, Anthropic (with DPAs)
  • Email: Resend
  • Support: Intercom (if enabled)

All subprocessors sign data processing agreements (DPAs) and are contractually obligated to protect your data.

Legal Requirements

We may disclose data if required by law, court order, subpoena, or to protect our rights, safety, or property.

Business Transfers

If Cresva is acquired or merged, your data may be transferred to the new entity. We'll notify you and update this policy accordingly.

With Your Consent

We may share data with other parties if you explicitly consent (e.g., integrations you enable, case studies you approve).

6. Assistant connectors

This section describes what happens when a user connects a third party AI assistant to Cresva. It applies in addition to the rest of this policy, not instead of it.

What a connected assistant can read

Cresva operates a Model Context Protocol server at https://cresva.ai/mcp. A user may connect a third party AI assistant, such as Claude, ChatGPT or Cursor, to that server. The assistant is the client: it authenticates to Cresva using OAuth 2.1 and holds its own access token.

A connection can read only the brands the user selected on the Cresva consent screen at the time of granting, and only through the tools that the granted scopes permit. It cannot enumerate or reach an account the user did not grant, and it cannot reach another customer's data.

The connector is read only by default. Of the tools the server registers, all but one are reads. The single tool that is not a read opens a price negotiation on the customer's own storefront, and it requires a scope that is off unless the user turns it on when granting.

The assistant acts as the user, and every call is logged

A connection is granted by an individual user and carries that user's identity. Anything the assistant reads is what that user is entitled to read, and their permissions are re-evaluated at the time of each call rather than frozen when the grant was made. A user who loses access to a brand loses it through the connector at the same moment.

Every tool call is written to Cresva's audit log against the granting user, the assistant that made it and the grant it was made under. An administrator can therefore attribute any connector activity to a named person. Audit records are retained on the same schedule as other account audit data.

What leaves Cresva's systems

When a connected assistant calls a tool, Cresva returns the answer to that tool call to the assistant, over TLS. Nothing else is transmitted: Cresva does not send the assistant vendor credentials, connected platform tokens, other customers' data, or any bulk export of the customer's account.

Once an answer reaches the assistant it is governed by the agreement between the user and that assistant's vendor. Cresva has no visibility into, and makes no representation about, how a vendor stores, processes or trains on content the user brings into their own conversation. A customer evaluating that risk should read the vendor's terms.

Grants, tokens and retention

Cresva stores, for each connection: the registered client, the granting user, the brands and scopes granted, the time of grant, and the time the connection was last used. Access tokens and refresh tokens are stored as hashes rather than in a recoverable form.

Access tokens are short lived. Refresh tokens are single use: a refresh issues a new refresh token and invalidates the one presented, and presenting a token that has already been used revokes the grant. Records of a revoked grant are retained as audit history rather than deleted, so that past access remains attributable.

How to revoke a connection

A user can revoke a connection at any time from Connected apps in their Cresva settings. Revocation takes effect immediately: the tokens are invalidated and the next call from that assistant is refused. Revoking one user's connection does not affect any other user's.

Removing a user from the Cresva account, or removing their access to a brand, has the same effect on what their connections can reach, because permissions are evaluated per call.

Test credentials read simulated data

Cresva issues test API keys, distinguishable by their sk_test_ prefix, alongside live keys. A request authenticated with a test key reads simulated data only. It does not read the customer's connected accounts and cannot change any record. Test keys exist so that an integration can be built and run in a customer's own CI without touching production data.

6a. Claiming a store

A store listed in our public AI Shopper Index can be claimed by whoever controls its domain. Claiming is something you start; it never happens as a side effect of anything else.

What you send us.

Which store you are claiming, and, when you come back to finish, the value we gave you. That is the whole of it. We do not ask for anything about the business and we do not ask you to upload anything to us.

What we do with it.

We give you a value to publish, either as a DNS TXT record on the domain or as a file at a fixed address on the site. When you ask us to check, we make one DNS lookup and at most one request to that address on your own domain. All we look for is whether the value is there. Nothing else on the site is fetched, and no page of it is stored.

What we keep.

That the store is claimed, when it was proved, and which of the two methods proved it. We keep the account that made the claim so that the claim can be managed, and a one way digest of the value rather than the value itself. An unfinished claim expires after seven days, after which a nightly job removes the account, the timestamp and the digest, and the store is claimable again by anybody.

What a claim proves, and what it does not.

It proves control of the domain on the day the check ran. It does not prove ownership of the business, and we do not treat it as such: an agency proving a client's domain is an ordinary case rather than a misuse. For that reason a claimed store is shown as claimed, never as belonging to the person who claimed it, and we do not publish who claimed anything.

7. Cookies & tracking

We use cookies and similar technologies to improve your experience. Here's what we use:

Essential Cookies (Required)

These are necessary for the Service to function:

  • Authentication (keeping you logged in)
  • Security (CSRF protection)
  • Preferences (timezone, language)

Analytics Cookies (Optional)

Help us understand how you use the Service (anonymized):

  • PostHog (product analytics)
  • Google Analytics (anonymized)

Declining this category in our cookie banner (or choosing "Essential Only") means these do not load. You can also block them at the browser level.

Marketing Cookies (Optional)

Used only with your consent, to measure advertising effectiveness:

  • Meta Pixel
  • Google Tag Manager (loaded when you grant either analytics or marketing consent)

Declining this category, or choosing "Essential Only," means these do not load.

How to control cookies:

  • Most browsers allow you to block or delete cookies in settings
  • Note: Blocking essential cookies may prevent the Service from working properly
  • Learn more: allaboutcookies.org

8. Security measures

We take data security seriously and implement industry-standard measures to protect your information:

Encryption

All data is encrypted in transit (TLS/SSL) and at rest (AES-256)

Access Controls

Strict access controls, least-privilege principle, regular audits

Infrastructure Security

Hosted on SOC 2-compliant platforms (Vercel, AWS/GCP)

Monitoring & Logging

24/7 monitoring for suspicious activity, automated alerts

Regular Updates

Frequent security patches, dependency updates, penetration testing

Employee Training

All team members undergo security training and sign NDAs

Data breach notification: If a security breach affects your data, we'll notify you and relevant authorities within 72 hours (GDPR requirement) via email and in-app notification.

9. Data retention

We retain your data for as long as necessary to provide the Service:

Active Accounts

As long as your account is active, we retain your data to provide the Service.

After Account Deletion

  • Account data: We process deletion requests within 30 days of verification
  • Backups: Purged on our normal backup rotation, which does not exceed 90 days
  • Billing records: Retained for 7 years (tax compliance)
  • Anonymized analytics: May be retained indefinitely
  • Settled Agent Commerce transactions: Where a brand has a completed negotiated sale (an accepted negotiation with an order reference), we retain that transaction's record for accounting and legal reasons, consistent with how any completed sale record is kept

Legal Holds

We may retain data longer if required by law, legal proceedings, or to resolve disputes.

Want to delete your data? Visit /data-deletion or email hello@cresva.ai

10. International transfers

Cresva is based in the United States. If you're accessing the Service from outside the US, your data may be transferred to, stored, and processed in the US and other countries.

For EU/UK users (GDPR):

  • We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for data transfers to the US
  • All subprocessors handling EU data sign Data Processing Agreements (DPAs) with SCCs
  • We implement additional safeguards (encryption, access controls) to protect your data

By using the Service, you consent to the transfer of your data to the US and other countries where we or our service providers operate.

11. Your rights & choices

Under GDPR, CCPA, and other privacy laws, you have the following rights:

Access

Request a copy of your personal data we hold

Rectification

Correct inaccurate or incomplete data

Erasure ("Right to be forgotten")

Request deletion of your account and data

Data portability

Download your data in a portable format

Object to processing

Object to certain uses (e.g., AI training)

Restrict processing

Limit how we use your data

Withdraw consent

Opt out of cookies, emails, AI training

Lodge a complaint

File a complaint with your data protection authority

California Residents (CCPA/CPRA)

You have additional rights under California law:

  • Right to know what personal information we collect and how we use it
  • Right to deletion
  • Right to opt-out of "sale" or "sharing" (we do neither)
  • Right to non-discrimination for exercising your rights

How to exercise your rights:

Email: hello@cresva.ai

Data deletion form: /data-deletion

Response time: We'll respond within 30 days (GDPR) or 45 days (CCPA)

Verification: We may ask for additional information to verify your identity before processing requests

No fees: We don't charge for requests unless they're excessive or repetitive

12. Children's privacy

Our Service is not intended for children under 16 years old (or 13 in the US). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately at hello@cresva.ai so we can delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We'll update the "Last updated" date at the top of this page.

For material changes: We'll notify you through the Service, via email, or with a prominent notice on our website at least 30 days before the changes take effect. For non-material changes, we encourage you to review this policy periodically.

Continued use of the Service after changes become effective constitutes acceptance of the updated policy. If you don't agree with the changes, you may close your account.

Contact us

Privacy questions or requests?

Contact our privacy team for any questions about this policy or to exercise your rights.

Email: hello@cresva.ai

Company: Cresva, Inc.

Response time: Within 2 business days

EU/UK residents: If you're not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.

Using the Cresva Chrome extension? It is covered by its own policy, which states exactly what a scan sends, what it never reads and which pages it refuses outright: Chrome extension privacy policy.