Legal

Privacy Policy

Last updated: July 19, 2026

This Privacy Policy describes how AccessComply ("we," "us," or "our") collects, uses, and shares information when you install and use the AccessComply application ("App") through the Shopify platform.

1. Information We Collect

Information collected through Shopify APIs

When you install AccessComply, we access the following data through Shopify's APIs:

  • Store information: Your store name, domain, and Shopify plan details to configure the App and manage your subscription.
  • Theme files: Your theme's Liquid templates, CSS, and JavaScript files. We read these files to check supported SEO, speed, and accessibility patterns and generate supported fix suggestions. We change these files only when you explicitly approve a fix.
  • Product data: Product titles, descriptions, and image URLs to check supported search information, image loading, and accessibility patterns and to generate supported image-description suggestions.
  • Online store pages: Page content and rendered markup used for supported SEO, speed, and accessibility checks.

Information collected directly from you

  • Account information: Your email address for service communications and support.
  • Public website submissions: When you request a scan report or join an email list, we collect the email address, store URL, related scan reference, and consent/audit details such as the submission IP where applicable.
  • Email preferences: Email-confirmation and browser-unsubscribe pages require an explicit confirmation before changing consent or preferences, so simply opening a link does not make that change. Unsubscribe URLs use an encrypted, authenticated, expiring opaque token instead of a plaintext email address. Participating mailbox providers may send a standards-based one-click POST from the email header.
  • Settings and preferences: Your scan frequency, notification preferences, and plan tier selection.
  • Accessibility statement content: Information you provide when creating an accessibility statement for your store (organization name, contact details, current work, and known limitations).

First-party website analytics

On accesscomply.com we record limited first-party funnel events such as scan started or completed, report viewed, lead captured, pricing interaction, and install intent. An event may include the page path, source label, selected plan, an opaque public-scan ID, the issue-priority band shown in that report, and UTM campaign parameters. UTM parameters may be kept in session storage for the current browser session. These events do not include your email address or store URL, and this custom event system does not use advertising cookies.

Product usage analytics

Inside the authenticated App, we record limited product events such as opening the dashboard, starting a scan or approved fix, enabling monitoring, publishing a statement, downloading a report, activating a subscription, requesting Shopify's native review prompt, or encountering an App error. An event may include the App path, source label, selected plan, and an internal store identifier. The event record does not contain the store domain, merchant email address, storefront content, issue details, or customer data. We use these events to operate the service, understand activation and subscription conversion, and improve reliability.

Information generated by the App

  • Scan results: URLs sampled, SEO, speed, and accessibility issues detected, module scores when measured, and accessibility issue-priority signals scoped to the pages, states, and rules tested.
  • Fix records: Details of fixes generated, applied, and verified for your store.
  • Monitoring data: Scan history and issue trends over time.

Information from your customers

  • Feedback submissions: If you enable the accessibility feedback widget, your customers may submit the text of their message, the page URL, and an optional email address through a dedicated email field if they choose to provide it for follow-up. We do not ask for customer names. Customers may also voluntarily include personal information in the free-text message.
  • No tracking or cookies: AccessComply does not place cookies on your customers' browsers, does not track customer behavior, and does not collect customer browsing data.

2. How We Use Your Information

We use the information we collect to:

  • Scan your store pages for supported SEO, speed, and WCAG-mapped accessibility issues
  • Generate and apply merchant-approved fixes to supported theme files and storefront content
  • Provide separate module scores when measured, accessibility issue-priority signals scoped to the reported scan, and issue reports
  • Generate AI-assisted alt text and ARIA labels for your store content
  • Monitor your store for new supported issues on the schedule you set
  • Generate fix-activity reports and accessibility statements
  • Manage your subscription and billing through Shopify's Billing API
  • Send requested service emails and opted-in monitoring summaries
  • Deliver requested public scan reports and send marketing messages only after the applicable opt-in
  • Provide customer support
  • Improve the reliability and performance of the App
  • Understand product activation, feature adoption, and subscription conversion

AI Processing

AccessComply uses AI providers to generate image descriptions, accessible labels, and other accessibility fix suggestions. A separate audio transcription provider is used only when video/audio caption transcription is enabled for your store. Your store content (image URLs, surrounding text, element context, and relevant theme snippets) may be sent to the selected AI provider for this purpose. The current list of providers is published in our subprocessor list (available on request) and updated whenever providers are added or removed.

AI inference is performed only on merchant content, only at the merchant's request, and only to generate the specific output the merchant asked for (e.g., alt text for a chosen image). We do not use merchant data to train our models. We minimize the content sent and configure providers for the lowest available retention; provider handling is governed by the current subprocessor terms.

3. How We Share Your Information

We do not sell your information. We share data only with the following sub-processors and circumstances:

  • AI model providers: Image URLs, element context, and relevant theme snippets may be sent to our AI providers to generate requested fix suggestions. A separate provider may be used solely for caption transcription when that feature is enabled. The current subprocessor list and applicable provider handling terms are available on request.
  • Shopify: Your App usage data is shared with Shopify as required by the Shopify Partner Program Agreement and for billing purposes.
  • Infrastructure providers: We use Railway for application hosting, PostgreSQL database, and Redis queue services. Data is processed and stored on Railway infrastructure in the United States.
  • Transactional email: We use ZeptoMail (Zoho Corporation) to send transactional emails such as requested scan reports, scan completion notifications, and GDPR data-request reports. Email content and recipient addresses are processed by ZeptoMail.
  • Marketing email: When you separately opt in and our marketing program is enabled, we use Resend to deliver newsletter and nurture messages. Resend processes the recipient address, message content, delivery details, and unsubscribe headers needed for that delivery. Commercial messages are not sent through our transactional ZeptoMail stream.
  • Error and performance monitoring: We use Sentry to diagnose application errors and reliability problems. Sentry may process stack traces, route and performance details, release identifiers, and the Shopify store domain associated with an App error. We disable default personal-data collection and remove request bodies, query strings, cookies, and sensitive authentication headers before events are sent.
  • Legal requirements: We may disclose information if required by law, regulation, or legal process.

4. Data Storage and Security

  • Location: Your data is stored on servers located in the United States (Railway infrastructure).
  • Security: We use encryption in transit (TLS) and at rest. Database credentials and API keys are stored as encrypted environment variables. Access to production systems is restricted to authorized personnel.
  • Saved originals: Affected theme code and original values for supported content updates are stored to enable restore workflows. These records are retained for up to 90 days and may be deleted earlier after uninstall or erasure.

5. Data Retention

  • Scan data and issue records: Retained for as long as your App is installed and for up to 30 days after uninstallation. We delete this data earlier when Shopify's shop-erasure webhook is successfully processed.
  • Unclaimed public scans: Public scan results that have not been securely claimed by an installed Shopify store are retained for up to 90 days. Claiming a scan moves it under the installed-store retention rules above.
  • Saved original theme files: Retained for up to 90 days after creation, or up to 30 days after uninstallation, whichever comes first. Shop erasure may delete them earlier.
  • Account information: Retained for as long as your App is installed and for up to 30 days after uninstallation.
  • Public website leads: Unverified signups are deleted after 7 days. Verified contact, consent, and scan-reference records are retained until deletion is requested or they are no longer needed for the requested report and compliance records. Unsubscribing stops marketing messages but may preserve opt-out evidence.
  • First-party marketing events: Cookie-free funnel events and their limited attribution fields are retained for up to 13 months.
  • Authenticated product events: Limited App usage events are retained for up to 13 months while the App is installed and no later than 30 days after uninstallation. They are linked only to an internal store identifier and are deleted earlier when Shopify's shop-erasure webhook is successfully processed.
  • Feedback submissions: Retained for as long as your App is installed and for up to 30 days after uninstallation.
  • After the applicable retention period: Data is permanently deleted or de-identified, except limited records we must retain for security, fraud prevention, legal obligations, or opt-out compliance.

6. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the data we hold about you.
  • Correction: Request correction of inaccurate data.
  • Deletion: Request deletion of your data. Note that uninstalling the App triggers automatic data deletion after the retention period.
  • Restriction: Request that we limit how we process your data.
  • Portability: Request your data in a structured, machine-readable format.
  • Objection: Object to processing of your data in certain circumstances.

To exercise any of these rights, contact us at privacyaccesscomply.com.

7. International Data Transfers

Your data is processed and stored in the United States. If you are located outside the United States (including in the European Economic Area), your data will be transferred to and processed in the United States. We take steps to ensure that your data receives adequate protection in accordance with applicable data protection laws, including the GDPR.

8. GDPR Compliance

For merchants and their customers in the European Economic Area:

  • We process data as a data processor on behalf of the merchant (data controller).
  • Our legal basis for processing is the performance of our contract with you (providing the App's services) and your consent where required.
  • We respond to data subject access requests within 30 days.
  • We have implemented mandatory Shopify privacy webhooks (customer data request, customer erasure, shop erasure) to handle data deletion requests.

9. Children's Privacy

AccessComply does not knowingly collect personal information from children under 13 (or under 16 in the EEA). The App is designed for use by Shopify merchants, not consumers.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the App. The "Last updated" date at the top of this policy indicates when it was last revised.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

If you are in the EEA and believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local data protection authority.