Privacy & Cookie Policy
Who we are
Savva HQ ("Savva", "we") provides an AI store manager for Shopify merchants: store audits, a mentor chat and hands-on store management. The service is operated by Zoxas LLC (Wyoming, USA).
Contact for anything privacy-related: hello@savvahq.com (or t.me/SavvaRun_bot if you prefer Telegram).
What we collect
- Account data. When you sign in with email: your email address (and a password hash if you set one). When you link Telegram: your Telegram ID, name and username.
- Usage data. Chat messages you send to Savva, store URLs you submit for audits, products you save or watch. We use these to provide the service and improve Savva's answers.
- First-party analytics. With your consent (cookie banner): page views, referrer and a random visitor ID. No cross-site tracking by us.
- Meta Pixel. If enabled and you consent, Meta's pixel may collect visit data per Meta's privacy policy — used to measure our ads.
Store data via Shopify (OAuth)
If you connect your store, you grant Savva access through Shopify's standard OAuth app flow. We request only the scopes Savva needs to do its job, and here is what each is for:
- Products & collections (read/write). Read: audits, listing checks, answering your questions with real data. Write: applying the specific changes you approved — titles, descriptions, prices, images.
- Orders (read). Daily reports, revenue and margin maths, support answers like "where is order #1042". Through Shopify's protected customer data programme we request Level 1 only: order totals and line items for summaries and alerts — never customer names, emails, phone numbers or addresses.
- Customers (read). Segments for email flows, answering questions like "revenue from new customers this month". We never message your customers without a flow you approved.
- Discounts & price rules (read/write). Finding margin-killing codes; creating or fixing codes you approved.
- Inventory (read). Stock checks — for example, catching bundles that can't be purchased.
- Themes/content (write, when applicable). Only for changes you approved (e.g. a page edit), always as a draft or preview first.
Three commitments on top of that:
- Every write action is logged — you can see the full journal in your dashboard.
- We use your store data only to run your store. We do not use one client's private store data for another client, and we do not sell it — to anyone, ever.
- You can revoke access at any time from your Shopify admin (Settings → Apps). Revoking cuts our access immediately.
Cookies
- Essential: session token (keeps you signed in). Always on.
- Analytics: visitor-ID cookie (savva_uid, 12 months) — only after you click "Accept" in the banner.
You can change your choice anytime by clearing site data in your browser.
What we do NOT do
- We do not sell your data.
- We do not read your store's customer data unless you explicitly connect your store for management.
- Audit documents live at unlisted URLs and are not indexed.
Public store data
Audits read publicly available storefront data (the same pages any visitor sees). We do not access private data of third-party stores. Stores of Savva clients are never shown to other users as examples — by rule, not by request.
Storage & retention
- Data is stored on our servers in the EU.
- Chat logs and analytics: kept up to 12 months.
- Account data: kept for as long as your account exists.
- Store data (connected stores): kept while your store is connected. If you disconnect the store or close your account, we delete stored store data within 30 days (backups roll off on their own schedule shortly after).
- We honour Shopify's mandatory privacy webhooks: customer data requests, customer data erasure and shop data erasure are processed within 30 days.
How to delete your data
Email hello@savvahq.com from your account email (or message t.me/SavvaRun_bot) and say "delete my data". We delete your account, chat logs and stored store data within 30 days and confirm when it's done. Disconnecting the app in your Shopify admin also triggers deletion of stored store data.
Your rights (GDPR and similar laws)
If you are in the EU/EEA or UK (and in many other places), you have the right to:
- Access — ask for a copy of the personal data we hold about you;
- Rectification — have inaccurate data corrected;
- Erasure — have your data deleted ("right to be forgotten");
- Restriction & objection — limit or object to how we process your data;
- Portability — receive your data in a machine-readable format;
- Withdraw consent — e.g. for analytics cookies, at any time;
- Complain — to your local data-protection authority, though we'd appreciate the chance to fix things first.
To exercise any of these, email hello@savvahq.com. We respond within 30 days.