Your catalogue, open to AI shoppers.
See howTerms of Service
These Terms govern your use of Cresva, Inc. (the "Service"). By accessing or using the Service, you agree to these Terms. If you do not agree, do not use the Service.
Legal name: Cresva, Inc. • Contact: hello@cresva.ai
Table of Contents
1. Acceptance
By using the Service, you agree to these Terms and our Privacy Policy. If you use the Service on behalf of an organization, you represent that you have authority to bind that organization.
2. Eligibility & accounts
- You must be at least 18 years old and able to form a binding contract.
- You are responsible for all activity under your account and for keeping credentials secure.
- Provide accurate information and keep it up to date.
3. Acceptable use
- No illegal activity, malware, scraping without permission, or attempts to bypass security.
- No misuse of webhooks/APIs or interference with the Service's normal operation.
- Respect third-party platform terms (e.g., Slack, Meta, Google) when you connect them.
4. Customer data & privacy
"Customer Data" means data you provide to the Service, including settings, prompts, files, and data from connected platforms (Meta Ads, Google Ads, Shopify, etc.). You retain ownership of Customer Data.
How we use your data:
- To provide the Service: Process your data to generate insights, forecasts, and recommendations
- To improve the Service: Analyze aggregated, anonymized data to improve features and models (we do NOT use your individual data to train general AI models without your consent)
- To comply with laws: When required by legal obligations
For details on how we protect and process your data, see our Privacy Policy. You grant us a limited license to use Customer Data solely to provide the Service. We will not disclose Customer Data except as described in our Privacy Policy or with your consent.
5. Assistant connectors
This section applies when you connect a third party AI assistant to Cresva. It is in addition to the rest of these terms, not instead of them. Last reviewed 2026-09-10.
What a connected assistant can read
Cresva operates a Model Context Protocol server at https://cresva.ai/mcp. A user may connect a third party AI assistant, such as Claude, ChatGPT or Cursor, to that server. The assistant is the client: it authenticates to Cresva using OAuth 2.1 and holds its own access token.
A connection can read only the brands the user selected on the Cresva consent screen at the time of granting, and only through the tools that the granted scopes permit. It cannot enumerate or reach an account the user did not grant, and it cannot reach another customer's data.
The connector is read only by default. Of the tools the server registers, all but one are reads. The single tool that is not a read opens a price negotiation on the customer's own storefront, and it requires a scope that is off unless the user turns it on when granting.
The assistant acts as the user, and every call is logged
A connection is granted by an individual user and carries that user's identity. Anything the assistant reads is what that user is entitled to read, and their permissions are re-evaluated at the time of each call rather than frozen when the grant was made. A user who loses access to a brand loses it through the connector at the same moment.
Every tool call is written to Cresva's audit log against the granting user, the assistant that made it and the grant it was made under. An administrator can therefore attribute any connector activity to a named person. Audit records are retained on the same schedule as other account audit data.
What leaves Cresva's systems
When a connected assistant calls a tool, Cresva returns the answer to that tool call to the assistant, over TLS. Nothing else is transmitted: Cresva does not send the assistant vendor credentials, connected platform tokens, other customers' data, or any bulk export of the customer's account.
Once an answer reaches the assistant it is governed by the agreement between the user and that assistant's vendor. Cresva has no visibility into, and makes no representation about, how a vendor stores, processes or trains on content the user brings into their own conversation. A customer evaluating that risk should read the vendor's terms.
Grants, tokens and retention
Cresva stores, for each connection: the registered client, the granting user, the brands and scopes granted, the time of grant, and the time the connection was last used. Access tokens and refresh tokens are stored as hashes rather than in a recoverable form.
Access tokens are short lived. Refresh tokens are single use: a refresh issues a new refresh token and invalidates the one presented, and presenting a token that has already been used revokes the grant. Records of a revoked grant are retained as audit history rather than deleted, so that past access remains attributable.
How to revoke a connection
A user can revoke a connection at any time from Connected apps in their Cresva settings. Revocation takes effect immediately: the tokens are invalidated and the next call from that assistant is refused. Revoking one user's connection does not affect any other user's.
Removing a user from the Cresva account, or removing their access to a brand, has the same effect on what their connections can reach, because permissions are evaluated per call.
Test credentials read simulated data
Cresva issues test API keys, distinguishable by their sk_test_ prefix, alongside live keys. A request authenticated with a test key reads simulated data only. It does not read the customer's connected accounts and cannot change any record. Test keys exist so that an integration can be built and run in a customer's own CI without touching production data.
6. Automated actions and authorization
The Service includes AI agents that can take actions on your behalf on platforms you connect (for example: Meta Ads, Google Ads, TikTok, Shopify, Klaviyo, Google Tag Manager). Examples of actions an agent may take include pausing or resuming a campaign, adjusting a budget, changing a price, creating a discount, and other configuration changes on the connected platform.
By connecting a platform and configuring an agent to act on it, you expressly authorize Cresva to take those actions on your behalf, subject to the limits you configure under Section 7 (Approval, review, and autonomy settings). You are solely responsible for the limits you configure, for reviewing what an agent is permitted to do before granting it that permission, and for the consequences of the actions taken within the limits you set.
7. Ad spend and budget
You pay the advertising platforms you connect (Meta, Google, TikTok, and any other connected ad platform) directly, under your own agreement with that platform. Cresva does not hold your advertising budget, does not charge your payment method on a platform's behalf, and is not a party to your agreement with that platform. Actions an agent takes under Section 5, including budget increases, budget decreases, and campaign pause/resume, can change how much you spend and how quickly, within the limits you configure. You own that budget and bear that spend.
8. Approval, review, and autonomy settings
Every brand you connect has an autonomy setting you control, with three levels:
- Propose (default). An agent proposes an action; nothing executes until you approve it.
- Reversible. Actions that are easy to undo (for example, pausing a campaign) can execute without a per-action approval; you confirmed this level for the brand and can change it at any time.
- Full. An agent can execute actions, including ones that are not trivially reversible, without a per-action approval. Raising a brand to this level requires you to type an explicit confirmation; it is not a default and does not happen by accident.
You are responsible for choosing and maintaining the autonomy level for each brand, and for reviewing actions taken at that level. Every action an agent takes is recorded in an audit log available to you regardless of autonomy level. Approving a proposed action, or configuring a brand to a level where actions execute without per-action approval, is your decision, and you are responsible for the outcome of that decision.
9. AI output accuracy
Forecasts, recommendations, scenario outputs, and other AI-generated content in the Service are estimates based on available data and models. They are not guarantees of future results and should not be relied upon without your own review. You are responsible for evaluating any AI-generated output before acting on it, whether that action is taken by you or, under Section 7, by an agent you have configured to act without per-action approval.
10. Agent Commerce negotiation
If you enable Agent Commerce negotiation for a brand, Cresva's agent can negotiate price and terms with a third-party purchasing agent (for example, an AI shopping assistant acting for an end consumer) on your behalf, within a maximum discount you configure. A negotiation that results in an accepted transaction is a binding sale on the terms reached, subject to your underlying obligations to fulfill it. You are responsible for the discount ceiling, negotiation style, and platform allowlist you configure, and for disabling this feature for a brand if you do not want Cresva negotiating sales on your behalf.
11. Platform suspension
Connected platforms (Meta, Google, Shopify, TikTok, and others) enforce their own policies on automated activity, and a platform may restrict, suspend, or terminate your account on that platform based on activity from an agent acting under Section 5, even where that activity was within the limits you configured. You bear the risk of platform-side enforcement action arising from automated activity on your connected accounts. Cresva is not responsible for a platform's decision to restrict or suspend your account there.
12. Intellectual property
- Our IP: We (or our licensors) own all rights in the Service, including software and branding. These Terms do not grant you any rights except a limited license to use the Service.
- Your IP: You retain ownership of Customer Data and any content generated for you through the Service, including AI-generated copy, creative, or other outputs produced from your inputs and configuration. Cresva claims no ownership interest in outputs generated for your account. You grant us a license to use it to provide the Service.
- Feedback: If you provide feedback or suggestions, we may use them without restriction or compensation.
13. Beta features
We may offer preview/beta features. They are provided "as is", may change or be withdrawn, and may have additional terms.
14. Fees & taxes
- Paid plans (if applicable) are billed in advance per billing cycle; fees are non-refundable except as described in our Refund Policy or where required by law.
- Prices may change with reasonable notice for the next term.
- You are responsible for applicable taxes, excluding our income taxes.
15. Changes to the Service
We may modify, add, or remove features. If a change materially reduces core functionality, we will use reasonable efforts to notify you in advance.
16. Suspension & termination
- You may stop using the Service at any time. To delete your account or export your data, contact us at hello@cresva.ai.
- We may suspend or terminate access for breach, risk to the Service, legal requirements, or non-payment (if applicable).
- Upon termination, your right to use the Service ends, but sections that by nature should survive will continue to apply.
17. Confidentiality
Each party may access non-public information of the other ("Confidential Information"). The receiving party will use it only to perform under these Terms and protect it with reasonable care. Exclusions include information that is public, independently developed, or rightfully received without confidentiality obligations.
18. Compliance & export
You will comply with applicable laws, including anti-bribery, sanctions, and export control laws. You will not use the Service in embargoed countries or by prohibited parties.
19. Disclaimers
The Service is provided "as is" and "as available". We disclaim all warranties, express or implied (including merchantability, fitness for a particular purpose, and non-infringement). We do not warrant that the Service will be uninterrupted or error-free.
20. Limitation of liability
To the fullest extent permitted by law, neither party will be liable for any indirect, incidental, special, consequential, or punitive damages, or lost profits, even if advised of the possibility. Each party's aggregate liability for claims arising out of or relating to the Service will not exceed the greater of (a) the amounts paid by you to us in the 12 months before the claim, or (b) USD $100 for free tiers.
21. Force majeure
Neither party is liable for delay or failure to perform an obligation under these Terms (other than payment obligations) to the extent caused by circumstances beyond that party's reasonable control, including acts of God, war, terrorism, riot, embargo, government action, fire, flood, or a failure or outage of a third-party platform, network, or utility that the Service or the affected party reasonably depends on.
22. Indemnification
You will defend, indemnify, and hold us harmless from third-party claims arising from your unlawful use of the Service or violation of these Terms, excluding our willful misconduct.
23. Governing law & disputes
These Terms are governed by the laws of the State of Delaware, USA, excluding conflict-of-laws rules. Disputes will be resolved in the state or federal courts located in Wilmington, Delaware, and the parties consent to personal jurisdiction there. The U.N. Convention on Contracts for the International Sale of Goods does not apply.
24. Miscellaneous
- Entire agreement. These Terms and referenced policies are the entire agreement.
- Severability. If a provision is unenforceable, the rest remains in effect.
- Assignment. You may not assign without our consent; we may assign in connection with a merger or sale.
- Notices. We may notify you via the Service or email. Update your contact details to receive notices.
Contact
Questions about these Terms?
hello@cresva.ai