Legal Framework

Privacy
Policy

Version 1.0 — Last updated: April 9, 2026

Previous version: N/A (initial policy). Material changes will be communicated to merchants via email at least 14 days before taking effect.

01.

Introduction

Wardova is a product of Cravid Labs LLC, a Wyoming limited liability company ("Wardova," "we," "us," or "our"). For privacy correspondence: Cravid Labs LLC, 30 N Gould St Ste R, Sheridan, WY 82801, United States. Email: privacy@cravidlabs.com.

This Privacy Policy explains how we collect, use, and protect your information when you install and use the Wardova Shopify app. By installing Wardova, you agree to the practices described in this policy. We are committed to transparency and to handling your data — and your shoppers' data — with the highest level of care.

02.

Information We Collect

We collect the minimum information needed to deliver AI-powered product recommendations. This includes:

03.

How We Use Your Information

Information collected is used exclusively to operate and improve the Wardova service:

We never use your data or your shoppers' data for advertising, profiling, or any purpose outside of providing the Wardova service to your store.

Tailoring and craft

Your data rights are tailored to you.

Wardova processes only the minimum data required to deliver AI-powered recommendations. We never sell your data or your shoppers' data to any third party.

Exercise Data Rights →

Data minimization summary

  • check_circleNo PII stored for end shoppers
  • check_circleAnonymous visitor IDs only
  • check_circleRedis data auto-purged by TTL
  • check_circleDeleted within 30 days of uninstall
04.

Data Storage & Security

All merchant and product data is stored on Gadget.dev infrastructure, which provides encrypted storage, automated backups, and SOC 2-compliant security practices. Recommendation caches are stored in Upstash Redis at the network edge with automatic TTL expiry (24 hours to 8 days depending on cache type). No raw payment data is ever accessed or stored by Wardova — all billing is handled directly through Shopify's Billing API.

All data in transit is encrypted via TLS 1.2+. We employ rate limiting, HMAC verification on webhooks, and input validation on all API endpoints to prevent unauthorized access.

To report a suspected security vulnerability or data breach, contact security@cravidlabs.com. We will acknowledge reports within 24 hours and provide a resolution timeline within 5 business days.

05.

Shopify Integration

Wardova accesses your Shopify store via OAuth with the minimum required scopes: read_products and read_orders. We register a ScriptTag on your storefront to serve the recommendation widget, and we listen to product update, product delete, and orders/paid webhook events to keep our cache and analytics synchronized with your store in real time. Shopify webhooks are verified using HMAC signatures to prevent spoofed requests.

06.

Cookies & Local Storage

The Wardova widget stores the following data in your shoppers' browsers using localStorage:

No cross-site tracking cookies are used. No third-party advertising cookies are set. All localStorage keys are prefixed with wardova_ for easy identification.

ePrivacy Notice for EU Merchants

Under the EU ePrivacy Directive, storing data in a user's browser via localStorage may require prior informed consent. As the merchant operating the storefront, you are responsible for ensuring your consent banner covers Wardova's localStorage usage where required by applicable law in your jurisdiction.

07.

Third-Party Services & Sub-Processors

Wardova uses the following trusted third-party services to operate:

All four sub-processors are US-based. GDPR data transfers to these processors are made under Standard Contractual Clauses (SCCs) per EU Commission Decision 2021/914. UK merchants: UK IDTAs apply.

Sub-Processor Purpose Server Location GDPR Transfer Mechanism
Anthropic AI catalog analysis USA SCCs (EU Commission Decision 2021/914)
Gadget.dev Serverless backend & database USA SCCs (EU Commission Decision 2021/914)
Upstash Edge Redis caching USA / EU (edge) SCCs (EU Commission Decision 2021/914)
Klaviyo CRM event delivery (optional) USA SCCs (EU Commission Decision 2021/914)
08.

Data Retention

Data is retained only as long as necessary to provide the service:

09.

Your Rights

As a Wardova merchant, you have the following rights regarding your data:

To exercise any of these rights, email privacy@cravidlabs.com. We will respond within 45 days.

10.

GDPR Compliance

For EU merchants and their shoppers, Wardova processes data under the following specific legal bases as required by GDPR Article 6:

We do not engage in automated decision-making that produces legal effects on any individual. EU merchants are entitled to a Data Processing Agreement (DPA) as required by GDPR Article 28. To receive your DPA, email legal@cravidlabs.com or visit wardova.com/gdpr-dpa. We will execute and return within 5 business days.

EU data subjects have the right to lodge a complaint with their national supervisory authority. A directory of EU supervisory authorities is available at: edpb.europa.eu.

11.

CCPA Compliance

Wardova does not sell or share personal information for cross-context behavioral advertising. No opt-out action is required.

California residents may exercise the following rights under the CCPA:

Please direct shopper-level requests to the merchant whose store you visited, as Wardova processes data as a service provider on behalf of the merchant. Merchant requests may be submitted to privacy@cravidlabs.com. We will respond within 45 days, with an extension to 90 days where reasonably necessary.

12.

Children's Privacy

Wardova is a B2B service directed exclusively to Shopify merchants. We do not knowingly collect personal information from children under 13 (COPPA) or under 16 (GDPR Article 8, subject to applicable member state law). If we become aware that we have inadvertently collected such information, we will delete it promptly. Merchants are responsible for ensuring appropriate age verification on their storefronts. If you believe a child has provided personal information, please contact us at privacy@cravidlabs.com.

13.

Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please contact us:

General & Support

support@cravidlabs.com

Data Rights & Privacy

privacy@cravidlabs.com

Legal & DPA Requests

legal@cravidlabs.com

Security & Vulnerabilities

security@cravidlabs.com
14.

Data Breach Notification

In the event of a personal data breach, Wardova will notify affected merchants within 72 hours of becoming aware, as required by GDPR Article 33. Notification will include:

To report a suspected security vulnerability, contact security@cravidlabs.com.

15.

Governing Law

This Privacy Policy is governed by the laws of the State of Wyoming, USA. Nothing in this policy limits your rights under applicable data protection laws in your jurisdiction, including GDPR and CCPA.