Security Overview
Handing an AI access to your store is a trust decision. We earn it with how the product is built — not with a badge. This page is the plain-English version of what protects your store, your data and your money. If anything here is unclear, a human on our team answers at hello@savvahq.com.
The short version
🔑 No passwords, ever
Savva connects to Shopify through official OAuth. You never share a password, and you revoke access in two clicks from your Shopify admin.
🎯 Least privilege
We request only the scopes Savva needs to do its job — each one is listed and explained in the Privacy Policy.
✅ Approval before action
Every change starts as a draft or proposal. Nothing ships until you approve it with one tap — and money never moves without you.
🧾 Everything logged
Every action Savva takes is written to a timestamped journal in your dashboard. No black box.
How access works
- OAuth 2.0 only. When you connect your store, Shopify issues Savva a scoped access token through its standard app-authorization flow. You never hand us a password, and Savva never sees your Shopify login.
- Access tokens are encrypted at rest. The token that lets Savva talk to your store is stored encrypted, not in plain text.
- Least-privilege scopes. Savva asks only for the permissions it actually uses — products, orders, customers (read), discounts, inventory, content — each mapped to a concrete job in the Privacy Policy. We do not request permissions we don't use.
- Revoke in two clicks. Settings → Apps in your Shopify admin cuts Savva's access immediately, any time, no email required.
- The free audit needs no access at all. It reads your public storefront — the same pages any visitor sees — so you can try Savva with zero risk before connecting anything.
How your data is handled
- Used only to run your store. Your store data is used to provide the service to you — and nothing else. We do not use one client's private data for another client.
- Never sold. We do not sell your data, to anyone, ever.
- Client stores are walled off from the market feed. The Product Finder is built from public storefronts of stores that are not our clients. The moment you hire Savva, your store is excluded from that feed — by rule, not by request.
- Stored in the EU. Data lives on our servers in the European Union.
- Retention and deletion. Disconnect your store or close your account and we delete stored store data within 30 days; we also honour Shopify's mandatory data-erasure webhooks. Full detail — including how to send a delete request — is in the Privacy Policy.
How changes are controlled
- Draft-first. Products, prices, pages and email flows arrive as a draft or proposal — invisible to shoppers — until you approve them.
- Money is never touched autonomously. Launching ads, changing budgets, purchases: Savva only prepares these. They go live when you approve, and never before.
- Humans take the hard calls. Anything legal, financial or genuinely ambiguous is escalated to a person on our team. The AI does not make judgement calls on your behalf.
- The action log is the receipt. Every write is recorded with a timestamp and a link to the result, visible in your dashboard from day one and exportable on request.
The guarantee, in writing
If a change you didn't approve ever ships, we revert it and refund your current month's subscription. This isn't a slogan on a landing page — it's a contractual commitment in our Terms of Service. The action log makes verifying it straightforward for both of us.
Product & platform integrity
- Real numbers only. No invented metrics, no fake reviews, no fake client logos. Every feature runs on our own live store before it runs on yours, and the results — wins and misses — are public.
- Parameterised store queries. Actions against Shopify go through parameterised API calls, and inputs (discount codes, prices) are validated before use — not stitched together as raw text.
- Secrets stay server-side. API keys and tokens live in server configuration, never in the browser and never in logs.
- Third parties. Savva integrates with Shopify, Stripe, Telegram, Meta and email providers. Their own security and terms govern their platforms; we limit what we send them to what the service needs.
Reporting a vulnerability
If you believe you've found a security issue, email hello@savvahq.com with the details and steps to reproduce. We'll acknowledge it, investigate, and keep you posted on the fix. Please give us a reasonable chance to resolve it before disclosing publicly — we're grateful for the help.
What we don't claim
We'd rather tell you than have you find out. As of August 2026 Savva is an early-stage product operated by Zoxas LLC (Wyoming, USA). We do not yet hold formal certifications like SOC 2 or ISO 27001, and we won't pretend to. What we do offer is the concrete, verifiable protection described above — OAuth-only access, least privilege, encrypted tokens, approval-before-action, a full log, and a guarantee written into the Terms. As we grow, this page grows with us — and the date at the top will tell you when it last changed.
Contact
Zoxas LLC · hello@savvahq.com · t.me/SavvaRun_bot