Shovva

SHOVVA / SECURITY

How we protect Shovva profiles.

Last updated · 8 July 2026

On this page

The short version

Shovva is a hosted creator profile platform operated by SHOVVA LTD.

We take reasonable technical and organisational measures to protect Shovva accounts, creator profiles, dashboard access, payment workflows, uploads, analytics, customer hubs and platform data.

No online platform can promise perfect security, but we design Shovva to reduce risk, limit unnecessary data exposure, protect account access and respond appropriately when something needs attention.

SHOVVA LTD is a company registered in England and Wales under company number 17223729, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

Important: payment card details are handled by Stripe or the relevant payment provider. Shovva does not store full card numbers on its own systems.

1. Related policies

This Security Policy should be read together with our Terms of Service, Privacy Policy, Cookie Policy, Copyright and DMCA Policy and any other policy or notice shown on Shovva.

Our Privacy Policy explains how we collect, use, store and share personal data.

Our Terms of Service explain the rules for using Shovva, including acceptable use, account security, payment tools, creator content and customer transactions.

2. What this page covers

This page explains Shovva’s general security approach for hosted accounts and creator profiles, including:

  • account and login security;
  • dashboard access;
  • public profile publishing;
  • uploads and creator content;
  • customer hubs and recovery tools;
  • analytics and tracking;
  • Stripe and payment-provider flows;
  • backups and operational recovery;
  • vulnerability reports and responsible disclosure.

This page does not give technical implementation details that could create security risk.

3. Our security approach

Shovva uses a risk-based security approach.

We aim to use appropriate technical and organisational measures based on the type of data involved, the feature being used, the likely risks, the size of the platform and the resources available to us as a growing business.

This may include access controls, authentication checks, request validation, input handling, secure connections, permission checks, monitoring, backups, security reviews, third-party security controls and restrictions on risky activity.

We review security issues based on severity, exploitability, affected users, payment risk, data risk, platform risk and customer harm.

4. Account and login security

Creators are responsible for keeping their account secure.

Shovva uses account and session controls to help protect creator dashboards and private account areas.

Security measures may include:

  • password protection and platform password handling;
  • session checks for logged-in areas;
  • permission checks for dashboard actions;
  • request validation for sensitive forms;
  • account ownership checks for profile, upload, analytics and billing actions;
  • restrictions on suspicious, abusive or unauthorised activity;
  • email notices or support follow-up where needed.

You must not share your login details carelessly, give account access to people you do not trust, reuse weak passwords, or allow someone else to use your account in a way that breaches our Terms of Service.

If you think someone has accessed your account without permission, contact us as soon as possible.

5. Hosted platform protection

Shovva is a hosted platform.

Creators do not need to manage their own WordPress install, hosting security, SSL certificate, plugin updates, server backups or database configuration to use a hosted Shovva profile.

Hosted protection may include:

  • HTTPS for Shovva pages;
  • central maintenance of platform code and templates;
  • account and ownership checks for creator data;
  • authentication requirements for private dashboard areas;
  • security updates where needed;
  • review of suspicious bugs, abuse reports and security issues;
  • restrictions on dangerous scripts, embeds or platform misuse.

6. Payments and billing security

Shovva uses Stripe and may use other payment providers for subscriptions, plan changes, creator payments, tips, donations, bookings, products, events, tickets, digital downloads, customer hubs and related payment flows where available.

Payment security measures may include:

  • Stripe-hosted checkout, billing or Connect flows where used;
  • payment-provider fraud checks and verification;
  • payment-provider dispute, refund and risk controls;
  • account checks before payment features are enabled;
  • limits or restrictions where payment activity appears risky;
  • platform fee and payment information shown in relevant dashboard or pricing flows.

Full card details are processed by Stripe or the relevant payment provider, not stored by Shovva.

Stripe and any other payment provider have their own terms, privacy notices, security practices, restricted-business rules and compliance controls.

7. Uploads and creator content

Creators may add content to their profiles, including text, links, images, embeds, products, offers, events, tickets, digital downloads and sections depending on their plan and enabled features.

Security measures may include:

  • upload restrictions based on file type, size and plan limits;
  • account ownership checks for uploaded assets;
  • input handling and output controls to reduce script injection risk;
  • restrictions on unsafe code, risky embeds or prohibited content;
  • review or removal of content that creates legal, privacy, payment-provider, security or platform risk.

Creators are responsible for making sure the content, links, files, embeds and tools they add are lawful, safe and appropriate for their audience.

8. Analytics, customer hubs and platform data

Shovva may provide analytics, customer hubs, order lookup, ticket recovery, download recovery, booking tools, receipts, confirmations or similar features.

Security and privacy controls may include:

  • keeping private dashboard analytics away from public profile pages;
  • access checks before private order, booking, customer or creator information is shown;
  • limiting recovery tools where needed for privacy, fraud prevention, abuse prevention or security;
  • keeping limited records where needed for legal, tax, accounting, fraud prevention, payment disputes, chargebacks, support, security or compliance reasons;
  • restricting access to data based on account permissions and feature access.

Analytics may include profile views, clicks, referrals, device type, approximate location, campaign parameters, conversion activity and similar events where enabled and lawful.

9. Third-party services and embeds

Shovva may allow creators to use approved third-party services such as Stripe, analytics tools, music players, video players, social widgets, booking tools, maps, calendars, forms, advertising pixels or external links.

Third-party services are controlled by their own providers.

Shovva is not responsible for the security, availability, privacy practices, accessibility, accuracy, terms or failures of third-party services.

Creators are responsible for making sure third-party tools they add to their profile are lawful, secure and suitable for their audience.

We may block, remove or restrict third-party scripts, embeds, pixels, links or tools where we believe they create security, privacy, legal, performance, payment-provider or user-trust risk.

10. User responsibilities

You must not:

  • try to access accounts, dashboards, files, data, profiles, customer hubs, payment flows or systems that are not yours;
  • bypass login, permission, plan, payment, security or access controls;
  • scrape, probe, scan, overload, reverse engineer or attack Shovva without written permission;
  • run denial-of-service tests, spam tests, destructive tests or automated attacks;
  • upload malware, malicious scripts, phishing pages, fake login pages or harmful files;
  • use Shovva to steal data, trick users, impersonate others or commit fraud;
  • publicly disclose a vulnerability before giving us a reasonable chance to investigate and protect users.

Breaking these rules may lead to removal of content, restriction of features, suspension, termination, reporting to authorities or other action allowed by our Terms of Service and the law.

11. Backups and recovery

Shovva is a hosted platform, so platform-level maintenance and operational recovery are handled by us and our hosting or infrastructure providers.

We may use backups or recovery processes to support platform reliability, incident response and operational continuity.

Creators should still keep their own copies of important profile content, images, product information, event information, booking records, customer information, copy, files and business records.

We do not guarantee that deleted, overwritten or lost content can always be recovered.

If you accidentally delete or overwrite something, contact us as soon as possible and we will tell you what recovery options are available.

12. Security incidents

If we become aware of a security issue, we may investigate, contain the issue, apply fixes, restrict affected features, reset access, contact affected users, contact service providers, preserve relevant records or take other reasonable steps.

Where required by law, we will make appropriate notifications to users, regulators, payment providers or other relevant parties.

Not every bug, outage or suspicious report is a reportable security incident.

We assess issues based on the facts available, the data involved, the risk to users, the risk to the platform and applicable legal obligations.

13. Reporting a vulnerability

If you find a possible security vulnerability, please report it privately before sharing it publicly.

Security reports: [email protected]

Please include the affected URL or feature, a clear description, safe steps to reproduce, screenshots if useful, the browser/device/account type used, expected behaviour, actual behaviour and your contact details for follow-up.

Please do not include other people’s personal data unless it is necessary to explain the issue. If you accidentally access data that is not yours, stop immediately and report the issue without copying, changing, deleting or sharing the data.

14. Responsible disclosure

Good-faith security reports are appreciated.

To help us protect users, please:

  • report vulnerabilities privately;
  • give us a reasonable opportunity to investigate before public disclosure;
  • avoid accessing, copying, changing, deleting or exposing data that does not belong to you;
  • avoid disrupting Shovva, creators, customers, payment flows or third-party services;
  • avoid social engineering, phishing, spam, denial-of-service, malware, physical attacks or destructive testing;
  • comply with the law.

We aim to review valid security reports and prioritise fixes based on severity, impact, exploitability and affected users.

We may not respond to reports that are spam, abusive, vague, unrelated to Shovva, generated without verification, or based only on automated scanner output without a real security impact.

15. Bug bounty

We do not currently run a formal bug bounty programme.

We may thank or credit responsible disclosures with permission, but we do not guarantee payment, rewards, public credit or compensation for reports.

Do not carry out testing that could harm Shovva, users, creators, customers, payments, data or third-party services in expectation of a reward.

16. What we do not claim

  • We do not claim that Shovva is completely risk-free.
  • We do not claim guaranteed uptime, perfect security, 24/7 human monitoring, bank-level security or protection against every possible threat.
  • We do not store full card numbers on Shovva systems.
  • We do not ask creators to manage server security to use a hosted Shovva profile.
  • We do not make private creator dashboard analytics public by design.
  • We do not knowingly allow one creator to edit another creator’s profile.

17. Changes to this Security Policy

We may update this Security Policy from time to time.

The “Last updated” date at the top shows the current version.

We may update this policy if our platform, security process, hosting, payment flows, reporting process, customer hubs, creator tools, legal requirements or operational practices change.

18. Contact details

SHOVVA LTD

Registered in England and Wales.

Company number: 17223729.

Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

Security reports: [email protected]

General support: [email protected]

Contact page: /contact/

This policy explains Shovva’s general security approach. It is not a guarantee that no security issue will ever occur.