01Who we are
Serravee Inc. (“Serravee”, “we”) builds growth experiments for consumer brands. This policy covers serravee.com and the Serravee application. For anything not answered here, mail privacy@serravee.com and a person will answer.
We have not appointed a data protection officer, or a representative in the EU or the UK. If we appoint either, we will name them here.
02Whose data is whose
Serravee handles two different kinds of personal data, and your rights depend on which one you are asking about. This is the most useful thing on the page, so it is first.
Data we control. People who visit serravee.com, book a demo, contact us, use the Serravee application, or whom we contact about Serravee. We decide why and how this data is used, and the rights below are ours to action directly.
Data we process for a brand. The customer and subscriber data inside the Klaviyo and Shopify accounts a brand connects. The brand decides why and how that data is used; we act only on their instructions. If you are a customer of a brand that uses Serravee and you want to see or delete your data, that brand is the right party, and we are required to route your request to them rather than act on it ourselves. Write to privacy@serravee.com and we will pass it on and tell you we have.
03What we collect from the website
If you book a demo or send us a message, we collect what you type: your email address and, on the contact form, your name, the topic you picked, and your message. The enterprise form on /pricing also takes your company or store URL, your list size and, if you give it, what you want to test. We record the page you submitted from and your IP address, which we use to rate-limit abuse.
Booking a demo at /signup happens in a calendar run by Cal.com, embedded on the page and under its own privacy policy. It takes your name, work email and store URL, and two optional questions: which email platform you run and roughly how many marketing emails you send a month. When you book, move or cancel, Cal.com sends us those answers, the time you picked, and the page and campaign that brought you here. After you book, we ask three more optional questions: which store platform you run, how many people work on the brand, and whether the email is your own or a client’s, plus what you would want tested first. We use all of it to prepare the demo, and a person reads it before the call. Skipping the questions leaves us with what you gave to book.
We measure how people find and use this site. Page views, referrer, the campaign that brought you here, and rough performance timings. Vercel Analytics and Vercel Speed Insights do that first-party and without cookies. They set nothing on your device and do not identify you. We also run Google Tag Manager as the container our measurement tags load through. Any advertising or conversion tag we add will be named on this page, and an automated test fails our build if one appears in the site without it.
We never sell website visitors to anyone.
04If we contacted you about Serravee
We build lists of businesses that might want Serravee. We obtain business contact details: name, job title, employer, work email address, and sometimes a work phone number or LinkedIn profile, from commercial business-data providers, currently Apollo.io and Clay, and from public sources such as company websites. We did not get them from you.
We use them to send business-to-business messages about Serravee, relying on our legitimate interest in reaching potential customers. We keep them for up to 24 months from our last contact with you, and delete them sooner if you ask.
You can tell us to stop and to delete what we hold at privacy@serravee.com, and we will, without asking why. Every email we send has an unsubscribe link. If you want to know which provider your details came from, ask and we will tell you.
05What we access in your store
When you connect an account, Klaviyo and Shopify to start, Serravee reads your history so it can find experiments worth running: campaigns, flows, segments, orders, customer records and past results.
- Shopify access is read-only. We request three permissions:
read_orders,read_all_ordersandread_customers, and hold no write permission at all. Serravee cannot change anything in your store. - Klaviyo access includes writing the drafts it builds: draft campaigns, email templates, images and audience segments. Those are four write permissions and we name all four rather than the two that sound smallest. We would rather it did not need them, but Klaviyo has no permission that grants “create a draft” without also granting more, so the limit is enforced in our code instead of by Klaviyo.
- Serravee never sends. Not “cannot”. Never. There is no send method in our Klaviyo client, a guard rejects Klaviyo’s send endpoints at runtime, and a test asserts those endpoints appear nowhere in our code. Removing any one of the three fails the build.
- We write drafts, and only drafts. Everything Serravee builds lands as a draft that you review and approve before it reaches anyone. We do not modify or delete your existing campaigns, flows or lists. Your send button, in your Klaviyo account.
- Most of our analysis runs on aggregates: totals, rates and cohorts rather than individual people, and the reporting we show you is aggregate. Some work needs record-level data: matching orders to subscribers, measuring an experiment against a held-back control group, and building an audience definition. We read individual records where the job requires it, and we say so here rather than implying otherwise.
- You can revoke access at any time, and reading stops immediately.
06Why we are allowed to do this
Where UK or EU data protection law applies, we rely on:
- Performance of a contract. Running the Serravee application for the brand that signed up, and processing account and billing data.
- Legitimate interests. Securing the service and rate-limiting abuse; answering enquiries; improving the product using aggregated, de-identified information; and contacting businesses about Serravee. We have considered whether those interests are outweighed by your rights, and you can object at any time at privacy@serravee.com.
- Consent. Where we ask for it, such as optional marketing email. You can withdraw it at any time from the bottom of any message.
- Legal obligation. Where the law requires us to keep or disclose records.
For personal data inside a connected Klaviyo or Shopify account, the brand that connected it is responsible for the legal basis, and we process it only on their instructions.
07How we use it
To run the product for you: finding opportunities, building experiments, measuring what they earned, and showing you the reasoning behind each.
Your data is not used to train anyone’s models. Our agreement with our model provider prohibits them from training on the content we send. We do not train models on your data either. We do use aggregated, de-identified information, from which no individual and no brand can be identified, to improve how Serravee works.
We answer your emails, and we send you product mail you can unsubscribe from at the bottom of any message.
08Who else sees it
We never sell or rent your data. We share it only with the vendors that run Serravee, each bound to use it only to provide their service to us. Every vendor is named, with what it does and where it is, at serravee.com/subprocessors. That page is the current list and it is dated. We also disclose data where the law requires it.
Your data is processed in the United States. Where personal data moves outside its region of origin we rely on the appropriate safeguards for that transfer, set out in our Data Processing Agreement.
09Cookies
This site stores three things in your browser itself, none of them a cookie: which page or campaign first brought you here, so that if you later book a demo we know where you came from; your answer to the cookie question below; and, while you are part-way through booking a demo, a draft of it. All three stay on your device, and clearing your browser data removes them.
The sign-up draft holds your email address, your name if you have given it, and the answers so far, so that reloading the page or coming back to the tab does not make you start again. It lasts for that browser tab and no longer, it is deleted the moment you finish, and it is never sent anywhere on its own: the answers reach us only when you submit them. The calendar on /signup is Cal.com’s own page in a frame, and anything it stores in your browser is Cal.com’s, under its policy.
Measurement cookies. Vercel Analytics and Speed Insights set none. Tags loaded through Google Tag Manager can, and where we run any we name them above.
If you are in the UK, the EEA or Switzerland, no measurement runs until you say yes. We ask once, at the bottom of the page, and declining takes exactly one click in exactly the same place as accepting. Everywhere else measurement runs by default and the same one click turns it off. Either way the answer is remembered, and you can change it by clearing this site’s data.
The two entries described above are not measurement and are not gated on that answer: they are what the site needs to work: remembering where you came from, and not making you retype a half-finished sign-up. Neither is used to profile you, neither follows you anywhere, and neither is read by anyone until you submit the form yourself.
The Serravee application sets strictly necessary cookies to keep you signed in and protect your session; these come from our authentication provider, Clerk.
10How we protect it
Data is encrypted in transit (TLS) and at rest. Credentials for connected accounts are stored encrypted and can be revoked by you in one click. Access is least-privilege and reviewed regularly, and we log what the system did, why, and on whose approval. Customer data is separated between accounts.
Security reviews and vulnerability reports go to security@serravee.com.
11How long we keep it
Account and experiment data is kept while your account is open and for 90 days after it closes, so a cancellation is reversible. Website enquiries are kept in our CRM until you ask us to remove them. Prospect contact details are kept for up to 24 months from our last contact.
If you connected a Shopify store, uninstalling the Serravee app is a deletion instruction. Shopify notifies us 48 hours after an uninstall and we erase that store’s data on receipt, rather than holding it for the 90-day window. We action Shopify’s customer data-request and customer-redaction notifications the same way.
12Your rights
The rights available to you depend on where you live, and may include access, correction, export, deletion, restriction of processing, objection to processing, and withdrawal of consent where we rely on it. Withdrawing consent does not affect anything we did before you withdrew it. Mail privacy@serravee.com. We do not charge for this and we do not treat you differently for asking.
We will respond within 30 days. If we need longer because the request is complex, we will tell you why before that deadline passes. We may need to verify your identity first, and we may retain records we are legally required to keep. If your request is about data we hold for a brand rather than for ourselves, see Whose data is whose above, we will route it to them and tell you we have.
If you are in the UK, the EU or Switzerland, you also have the right to lodge a complaint with your data protection supervisory authority. In the UK that is the Information Commissioner’s Office; in the EU it is the authority in the country where you live or work. We would rather you came to us first, but you do not have to.
13Changes
If we change this policy in a way that affects you, we will say so here and date the change. Continuing to use Serravee after that means the updated policy applies.
Questions about any of this?
Mail privacy@serravee.com and a person will answer. Security reviews go to security@serravee.com.