California Residents (CCPA)
We do not sell or share your personal information. You have rights to access, delete, and opt-out. See Section 10 for details.
Request Data Deletion →Table of Contents
1. Information we collect
We collect the following categories of information:
a) Account Information
- Name, email address, company name
- Google OAuth profile data (if you sign in with Google)
- Timezone, language preferences
b) Connected Platform Data
- OAuth tokens for connected platforms (Meta Ads, Google Ads, Google Analytics, Google Tag Manager, Google Merchant Center, TikTok, Shopify, Klaviyo, Slack, Notion)
- Campaign performance data (spend, revenue, impressions, clicks, conversions)
- Ad account names, campaign names, creative performance metrics
- Historical performance data for forecasting
c) Service Usage Data
- Questions you ask in the chat feature
- Dashboard views, report generation, forecast requests
- Feature usage, clicks, interactions within the Service
- Team member invitations and permissions
d) Technical Data
- IP address, browser type, device information
- Log data, error reports, performance metrics
- Cookies and similar tracking technologies (see Section 6)
e) Payment Information
- Billing details (processed by Stripe; we don't store full credit card numbers)
- Transaction history, invoices
f) Communications
- Support tickets, feedback, emails you send us
- Survey responses, product feedback
Important: Where an agent can act on a platform, we request the write access those actions need. The exact scopes are shown to you by that platform's own consent screen before you grant anything, and you can revoke them there at any time.
By default an agent proposes a change and it does not run until you approve it. That default is a per-brand setting you control, and raising it is deliberate: a higher level asks you to confirm, and full autonomy asks you to type a confirmation. Whatever the setting, every change an agent makes is recorded in an audit log you can read.
2. Legal basis for processing (GDPR)
For users in the EU/UK, we process your personal data under the following legal bases:
Contract Performance
We process your data to provide the Service you signed up for (account management, analytics, forecasts, etc.)
Legitimate Interests
We process data to improve our Service, prevent fraud, ensure security, and send relevant product updates (you can opt out of marketing emails)
Consent
For cookies (other than essential ones), AI training on your data, and marketing communications, we ask for your explicit consent
Legal Obligations
We may process data to comply with laws, regulations, court orders, or tax requirements
3. How we use your data
We use the information we collect to:
Provide & maintain the Service
Process your ad data, generate forecasts, answer questions via chat
Improve & develop features
Analyze usage patterns, fix bugs, develop new features
Customer support
Respond to your questions, troubleshoot issues
Security & fraud prevention
Detect and prevent abuse, unauthorized access, and security threats
Communications
Send service updates, billing notices, security alerts (you can opt out of marketing emails)
Legal compliance
Comply with laws, regulations, court orders, tax obligations
4. AI & machine learning
🤖 How we use AI
Cresva uses AI and machine learning to analyze your marketing data, generate forecasts, and provide insights. This processing happens in real-time and is essential to the Service.
AI Training & Your Data:
- We do NOT use your individual marketing data to train general AI models unless you explicitly opt in
- We may use aggregated, anonymized data (with no personally identifiable information) to improve our models
- If you want to opt out of even anonymized data usage for AI training, contact us at hello@cresva.ai
Third-party AI providers: We may use AI services from providers like OpenAI, Anthropic, or Google. Your data is processed according to their privacy policies and data processing agreements. We do not allow these providers to use your data for their own model training without your consent.
⚠️ We do NOT sell your data
We never sell your personal information to third parties. Period.
We may share your data with:
Service Providers (Subprocessors)
We use trusted third-party services to help operate Cresva:
- Hosting: Vercel (infrastructure), AWS/Google Cloud (storage)
- Payments: Stripe (payment processing)
- Analytics: PostHog, Google Analytics (anonymized)
- Advertising measurement: Google Tag Manager, Meta Pixel, loaded only after you grant analytics or marketing consent in our cookie banner; see Section 6
- AI Services: OpenAI, Anthropic (with DPAs)
- Email: Resend
- Support: Intercom (if enabled)
All subprocessors sign data processing agreements (DPAs) and are contractually obligated to protect your data.
Legal Requirements
We may disclose data if required by law, court order, subpoena, or to protect our rights, safety, or property.
Business Transfers
If Cresva is acquired or merged, your data may be transferred to the new entity. We'll notify you and update this policy accordingly.
With Your Consent
We may share data with other parties if you explicitly consent (e.g., integrations you enable, case studies you approve).
6. Assistant connectors
This section describes what happens when a user connects a third party AI assistant to Cresva. It applies in addition to the rest of this policy, not instead of it.
What a connected assistant can read
Cresva operates a Model Context Protocol server at https://cresva.ai/mcp. A user may connect a third party AI assistant, such as Claude, ChatGPT or Cursor, to that server. The assistant is the client: it authenticates to Cresva using OAuth 2.1 and holds its own access token.
A connection can read only the brands the user selected on the Cresva consent screen at the time of granting, and only through the tools that the granted scopes permit. It cannot enumerate or reach an account the user did not grant, and it cannot reach another customer's data.
The connector is read only by default. Of the tools the server registers, all but one are reads. The single tool that is not a read opens a price negotiation on the customer's own storefront, and it requires a scope that is off unless the user turns it on when granting.
The assistant acts as the user, and every call is logged
A connection is granted by an individual user and carries that user's identity. Anything the assistant reads is what that user is entitled to read, and their permissions are re-evaluated at the time of each call rather than frozen when the grant was made. A user who loses access to a brand loses it through the connector at the same moment.
Every tool call is written to Cresva's audit log against the granting user, the assistant that made it and the grant it was made under. An administrator can therefore attribute any connector activity to a named person. Audit records are retained on the same schedule as other account audit data.
What leaves Cresva's systems
When a connected assistant calls a tool, Cresva returns the answer to that tool call to the assistant, over TLS. Nothing else is transmitted: Cresva does not send the assistant vendor credentials, connected platform tokens, other customers' data, or any bulk export of the customer's account.
Once an answer reaches the assistant it is governed by the agreement between the user and that assistant's vendor. Cresva has no visibility into, and makes no representation about, how a vendor stores, processes or trains on content the user brings into their own conversation. A customer evaluating that risk should read the vendor's terms.
Grants, tokens and retention
Cresva stores, for each connection: the registered client, the granting user, the brands and scopes granted, the time of grant, and the time the connection was last used. Access tokens and refresh tokens are stored as hashes rather than in a recoverable form.
Access tokens are short lived. Refresh tokens are single use: a refresh issues a new refresh token and invalidates the one presented, and presenting a token that has already been used revokes the grant. Records of a revoked grant are retained as audit history rather than deleted, so that past access remains attributable.
How to revoke a connection
A user can revoke a connection at any time from Connected apps in their Cresva settings. Revocation takes effect immediately: the tokens are invalidated and the next call from that assistant is refused. Revoking one user's connection does not affect any other user's.
Removing a user from the Cresva account, or removing their access to a brand, has the same effect on what their connections can reach, because permissions are evaluated per call.
Test credentials read simulated data
Cresva issues test API keys, distinguishable by their sk_test_ prefix, alongside live keys. A request authenticated with a test key reads simulated data only. It does not read the customer's connected accounts and cannot change any record. Test keys exist so that an integration can be built and run in a customer's own CI without touching production data.
6a. Claiming a store
A store listed in our public AI Shopper Index can be claimed by whoever controls its domain. Claiming is something you start; it never happens as a side effect of anything else.
What you send us.
Which store you are claiming, and, when you come back to finish, the value we gave you. That is the whole of it. We do not ask for anything about the business and we do not ask you to upload anything to us.
What we do with it.
We give you a value to publish, either as a DNS TXT record on the domain or as a file at a fixed address on the site. When you ask us to check, we make one DNS lookup and at most one request to that address on your own domain. All we look for is whether the value is there. Nothing else on the site is fetched, and no page of it is stored.
What we keep.
That the store is claimed, when it was proved, and which of the two methods proved it. We keep the account that made the claim so that the claim can be managed, and a one way digest of the value rather than the value itself. An unfinished claim expires after seven days, after which a nightly job removes the account, the timestamp and the digest, and the store is claimable again by anybody.
What a claim proves, and what it does not.
It proves control of the domain on the day the check ran. It does not prove ownership of the business, and we do not treat it as such: an agency proving a client's domain is an ordinary case rather than a misuse. For that reason a claimed store is shown as claimed, never as belonging to the person who claimed it, and we do not publish who claimed anything.
We use cookies and similar technologies to improve your experience. Here's what we use:
Essential Cookies (Required)
These are necessary for the Service to function:
- Authentication (keeping you logged in)
- Security (CSRF protection)
- Preferences (timezone, language)
Analytics Cookies (Optional)
Help us understand how you use the Service (anonymized):
- PostHog (product analytics)
- Google Analytics (anonymized)
Declining this category in our cookie banner (or choosing "Essential Only") means these do not load. You can also block them at the browser level.
Marketing Cookies (Optional)
Used only with your consent, to measure advertising effectiveness:
- Meta Pixel
- Google Tag Manager (loaded when you grant either analytics or marketing consent)
Declining this category, or choosing "Essential Only," means these do not load.
How to control cookies:
- Most browsers allow you to block or delete cookies in settings
- Note: Blocking essential cookies may prevent the Service from working properly
- Learn more: allaboutcookies.org
8. Security measures
We take data security seriously and implement industry-standard measures to protect your information:
Encryption
All data is encrypted in transit (TLS/SSL) and at rest (AES-256)
Access Controls
Strict access controls, least-privilege principle, regular audits
Infrastructure Security
Hosted on SOC 2-compliant platforms (Vercel, AWS/GCP)
Monitoring & Logging
24/7 monitoring for suspicious activity, automated alerts
Regular Updates
Frequent security patches, dependency updates, penetration testing
Employee Training
All team members undergo security training and sign NDAs
Data breach notification: If a security breach affects your data, we'll notify you and relevant authorities within 72 hours (GDPR requirement) via email and in-app notification.
9. Data retention
We retain your data for as long as necessary to provide the Service:
Active Accounts
As long as your account is active, we retain your data to provide the Service.
After Account Deletion
- Account data: We process deletion requests within 30 days of verification
- Backups: Purged on our normal backup rotation, which does not exceed 90 days
- Billing records: Retained for 7 years (tax compliance)
- Anonymized analytics: May be retained indefinitely
- Settled Agent Commerce transactions: Where a brand has a completed negotiated sale (an accepted negotiation with an order reference), we retain that transaction's record for accounting and legal reasons, consistent with how any completed sale record is kept
Legal Holds
We may retain data longer if required by law, legal proceedings, or to resolve disputes.
Want to delete your data? Visit /data-deletion or email hello@cresva.ai
10. International transfers
Cresva is based in the United States. If you're accessing the Service from outside the US, your data may be transferred to, stored, and processed in the US and other countries.
For EU/UK users (GDPR):
- We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for data transfers to the US
- All subprocessors handling EU data sign Data Processing Agreements (DPAs) with SCCs
- We implement additional safeguards (encryption, access controls) to protect your data
By using the Service, you consent to the transfer of your data to the US and other countries where we or our service providers operate.
11. Your rights & choices
Under GDPR, CCPA, and other privacy laws, you have the following rights:
Access
Request a copy of your personal data we hold
Rectification
Correct inaccurate or incomplete data
Erasure ("Right to be forgotten")
Request deletion of your account and data
Data portability
Download your data in a portable format
Object to processing
Object to certain uses (e.g., AI training)
Restrict processing
Limit how we use your data
Withdraw consent
Opt out of cookies, emails, AI training
Lodge a complaint
File a complaint with your data protection authority
California Residents (CCPA/CPRA)
You have additional rights under California law:
- Right to know what personal information we collect and how we use it
- Right to deletion
- Right to opt-out of "sale" or "sharing" (we do neither)
- Right to non-discrimination for exercising your rights
How to exercise your rights:
Email: hello@cresva.ai
Data deletion form: /data-deletion
Response time: We'll respond within 30 days (GDPR) or 45 days (CCPA)
Verification: We may ask for additional information to verify your identity before processing requests
No fees: We don't charge for requests unless they're excessive or repetitive
12. Children's privacy
Our Service is not intended for children under 16 years old (or 13 in the US). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately at hello@cresva.ai so we can delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We'll update the "Last updated" date at the top of this page.
For material changes: We'll notify you through the Service, via email, or with a prominent notice on our website at least 30 days before the changes take effect. For non-material changes, we encourage you to review this policy periodically.
Continued use of the Service after changes become effective constitutes acceptance of the updated policy. If you don't agree with the changes, you may close your account.
Contact us
Privacy questions or requests?
Contact our privacy team for any questions about this policy or to exercise your rights.
EU/UK residents: If you're not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.
Using the Cresva Chrome extension? It is covered by its own policy, which states exactly what a scan sends, what it never reads and which pages it refuses outright: Chrome extension privacy policy.