SHOVVA / PRIVACY
What we collect, why, and what you control.
Last updated · 18 September 2026
On this page
- The short version
- Who we are
- What this policy covers
- What we collect
- Why we use your information
- Our legal bases under UK GDPR
- Processors and subprocessors
- Third-party tools business owners add
- Who we share information with
- International transfers
- Retention periods
- Your privacy rights
- Visitors to business pages
- Children
- Security
- Cookie Policy
- Marketing emails
- Changes to this policy
- Contact us
The short version
Shovva provides a customer-facing business page and the connected workspace behind it. We collect the information needed to create your account, publish your business page, process payments through Stripe, protect the platform, provide support and show you useful analytics.
We do not sell your personal data. We do not use your workspace data for third-party advertising. We do not store full card numbers. You can ask us for a copy of your data, ask us to correct it, or ask us to delete it where the law allows.
This policy explains what we collect, why we collect it, how long we keep it, who we share it with, and the rights you have under UK GDPR and other applicable privacy laws.
Who we are
SHOVVA LTD is the controller responsible for the personal data processed through the Shovva website, business workspace, public business pages, account-support process, billing flows, and related services.
SHOVVA LTD is a company registered in England and Wales under company number 17223729, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
SHOVVA LTD
Registered in England and Wales. Company number: 17223729.
Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
Privacy questions and rights requests: [email protected]
General support: [email protected]
Contact page: /contact/
What this policy covers
This policy covers:
- The public website at shovva.me.
- The registration, login and business workspace areas.
- Public business pages such as
https://shovva.me/your-name. - Support, billing, security, account, and privacy requests sent to us.
- Platform analytics and payment-related information connected to your Shovva account.
It does not cover third-party websites, services, embeds, links, or tracking tools that business owners choose to add to their business pages. Those providers have their own privacy notices.
What we collect
Account information
- Name, display name, username, and email address – used to create your account, identify your business page, send account notices, and provide support.
- Password data – passwords are stored in hashed form. We do not store your password in plain text.
- Account status – plan, registration date, login status, billing status, business page status, and workspace preferences.
- Support messages – messages you send through forms or email, plus any screenshots or files you choose to include.
Business page content
- Business page name, bio, images, social links, buttons, sections, videos, audio, products, offers, booking links, FAQs, forms, and other content you add.
- Theme choices, colours, layout preferences, business page mode, section order, and visibility settings.
- Public business page URL and username, for example
https://shovva.me/your-name.
Public business page content is visible to anyone who visits your public business page unless you choose settings that make content private or restricted.
Visitor and analytics information
When someone visits a public business page, we may collect limited event data to show the business owner how their business page is performing.
- Page views, section views, button clicks, link clicks, and form interactions.
- Referral source, campaign parameters, and UTM tags where present.
- Approximate device, browser, and country-level location information.
- Technical data used for bot filtering, abuse prevention, and basic analytics reliability.
We aim to use analytics in a privacy-conscious way. We do not sell visitor analytics to advertisers.
Payments and Stripe Connect
Payments are processed by Stripe. This may include subscriptions, plan upgrades, tips, donations, paid offers, and business payouts through Stripe Connect.
Shovva does not store full card numbers, CVC codes, or full payment-card details. Stripe handles card processing, payment authentication, fraud checks, billing, receipts, connected-account onboarding, and payouts.
Depending on the payment flow, we may receive and store limited payment metadata from Stripe, such as:
- Stripe customer ID, subscription ID, checkout session ID, payment intent ID, or connected account ID.
- Plan name, billing amount, currency, payment status, renewal date, cancellation status, and invoice status.
- Limited card information such as brand, last four digits, and expiry month/year where Stripe makes this available.
- Business payout status, connected-account status, and verification state.
Stripe may act as an independent controller for some payment and compliance activity. You should also read Stripe’s privacy notice and connected-account terms when using payment features.
Forms, leads, and messages
If a visitor submits a form on a business page, the submitted information may be stored so the business owner can view, export, or respond to it. Business owners are responsible for using that information lawfully and telling their audience how they handle it.
If you contact Shovva, we use your message to respond, investigate the issue, improve the service, and keep a record of the request.
Cookies and similar technologies
We use cookies and similar technologies for login sessions, security, preferences, payments, analytics, and optional integrations. Our Cookie Policy explains this in more detail.
Some third-party services, such as Stripe, embedded media providers, or optional tracking tools added by business owners, may set their own cookies.
Why we use your information
- To provide the platform – create accounts, publish business pages, save sections, manage plans, and render pages.
- To process payments – manage subscriptions, tips, donations, paid offers, invoices, billing events, Stripe Connect payouts, and payment disputes.
- To provide analytics – show business page views, clicks, traffic sources, and campaign performance.
- To provide support – respond to questions, troubleshoot issues, investigate bugs, and manage account requests.
- To keep the platform safe – prevent spam, fraud, abuse, unauthorised access, scraping, malware, and payment misuse.
- To comply with law – handle tax, accounting, legal requests, copyright notices, fraud checks, and regulatory obligations.
- To improve Shovva – understand which features are used, diagnose errors, improve performance, and make the product easier to use.
Our legal bases under UK GDPR
Where UK GDPR applies, we rely on the following legal bases:
- Contract – to create and manage your account, publish your business page, provide workspace features, process paid plans, and deliver the service you asked for.
- Legitimate interests – to keep the platform secure, prevent abuse, improve reliability, respond to support requests, understand product usage, and protect our rights and users.
- Consent – where you opt in to optional marketing, optional cookies, optional tracking tools, or other features that require consent.
- Legal obligation – where we need to keep records, comply with tax rules, respond to lawful requests, or meet accounting and regulatory requirements.
Processors and subprocessors
We use trusted third parties to help run Shovva. These providers only receive information needed for the service they provide.
- Stripe – payments, subscriptions, billing, fraud checks, receipts, Stripe Connect onboarding, and business payouts.
- Hosting and infrastructure providers – website hosting, databases, file storage, backups, server logs, and performance delivery.
- Email delivery providers – transactional emails such as login, account, billing, support, and notification emails.
- Analytics and error-monitoring tools – platform performance, uptime, diagnostics, and aggregated usage information where used.
- Embed providers – services such as YouTube, Vimeo, Spotify, SoundCloud, TikTok, or similar services where business owners embed third-party content.
- Professional advisers – accountants, lawyers, insurers, or compliance advisers where needed for legal, tax, or business reasons.
If we add or change important processors, we will update this policy or publish a separate processor list.
Third-party tools business owners add
Business owners may be able to add tracking pixels, analytics IDs, embeds, booking tools, payment links, email forms, or other third-party tools to their business pages.
If you add those tools to your business page, you are responsible for using them lawfully, including giving visitors any required privacy information or cookie choices. Third-party providers may collect data directly from visitors under their own privacy policies.
Important: Shovva provides the field or feature that lets a business owner add certain integrations. We do not control what those third-party providers do with the data they collect directly.
Who we share information with
We may share personal information:
- With processors and subprocessors who help us run the platform.
- With Stripe and payment providers to process subscriptions, tips, donations, paid offers, refunds, disputes, verification, and payouts.
- With a business owner, where a visitor submits information through that business owner’s public business page form.
- With law enforcement, regulators, courts, or legal advisers where required by law or necessary to protect rights, safety, or security.
- With a buyer, successor, or adviser if Shovva is involved in a merger, acquisition, restructuring, or sale of assets.
We do not sell personal data.
International transfers
Some of our providers may process data outside the UK or EEA. Where this happens, we use appropriate safeguards where required, such as UK International Data Transfer Agreements, the UK Addendum to the EU Standard Contractual Clauses, EU Standard Contractual Clauses, or other lawful transfer mechanisms.
Payment providers and embed providers may also carry out their own international transfers under their own policies.
Retention periods
We keep personal information only for as long as needed for the purposes described in this policy, unless a longer period is required by law.
- Account data – kept while your account is active. If you delete your account, most account data is deleted or anonymised within 30 days, unless we need to keep it for legal, security, fraud-prevention, billing, or accounting reasons.
- Public business page content – kept while your business page is active. Deleted business page content may remain in backups for a limited period before automatic overwrite.
- Support messages – usually kept for up to 24 months so we can track issues, disputes, and previous account requests.
- Billing and tax records – usually kept for 6 years, or longer if required for tax, accounting, legal, fraud-prevention, or dispute purposes.
- Security logs – usually kept for up to 12 months, unless needed longer to investigate abuse, fraud, or security incidents.
- Email delivery logs – usually kept for up to 90 days for troubleshooting and deliverability.
- Business page analytics – the history available in your workspace depends on your plan: Free 30 days, Pro 90 days and Premium 365 days, unless your workspace states otherwise. These are reporting windows, not automatic deletion deadlines. Retention is determined separately by whether the data is needed to provide analytics, prevent abuse, resolve disputes or meet legal obligations.
- Stripe records – retained by Stripe under Stripe’s own retention policies. We may keep related payment metadata for billing, accounting, tax, dispute, and fraud-prevention purposes.
Your privacy rights
Under UK GDPR, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your personal information in certain circumstances.
- Restrict how we use your information in certain circumstances.
- Object to certain processing based on legitimate interests.
- Withdraw consent where processing is based on consent.
- Data portability for certain information you provided to us.
- Complain to the UK Information Commissioner’s Office or your local supervisory authority.
To exercise these rights, email [email protected]. We may need to verify your identity before acting on a request.
Visitors to business pages
If you visit a public business page, we may process limited analytics and technical information to deliver the page, prevent abuse, and provide business page analytics to the business owner.
If you submit a form, send a message, join a mailing list, book something, buy something, or send a tip through a business page, your information may be visible to that business owner and may also be processed by relevant third-party providers such as Stripe or an embed provider.
Children
Shovva is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account or sent us personal information, contact [email protected] and we will investigate.
Users aged 13 to 15 must have a parent or guardian involved as explained in our Terms of Service.
Security
We use technical and organisational measures designed to protect personal information, including access controls, HTTPS, password hashing, security monitoring, abuse prevention, and limited access to account data.
No online service can guarantee absolute security. If you believe you have found a security issue, please follow our Security Policy or email [email protected].
Cookie Policy
Cookies and similar technologies are explained separately in our Cookie Policy. That page explains what cookies we use, why we use them, and how optional cookies can be controlled.
Marketing emails
We may send account, billing, security, and service emails where needed to run your account. These are not optional marketing emails.
If we send marketing emails, product announcements, or optional newsletters, you can unsubscribe using the link in the email or by contacting us.
Changes to this policy
We may update this Privacy Policy when our platform, providers, features, or legal obligations change. The “Last updated” date at the top shows when this version took effect.
If a change materially affects your rights or how we use your personal information, we will take reasonable steps to notify you, such as by email, workspace notice, or website notice.
Contact us
Privacy questions and rights requests
Email: [email protected]
General support: [email protected]
Contact page: /contact/
We aim to respond to general privacy questions as soon as reasonably possible. Formal UK GDPR requests will be handled within the required legal timeframe.