Privacy Policy
Last updated: 23 July 2026
AccessProof (“we”, “us”) provides accessibility scanning and compliance tooling for Shopify stores. This policy explains what data the app accesses, how we use it, and your choices. It applies to the AccessProof Shopify app and useaccessproof.com.
What we access and store
- Store identity & authorization — your
.myshopify.comdomain, primary storefront URL, and the Shopify access token that authorizes the app. We request only theread_productsandwrite_productsscopes. - Accessibility scan results — the WCAG/EAA issues found on your public storefront pages, with the page URLs, failing rules, and sample element selectors. Each scan is stored as your dated compliance evidence log (the core product).
- Product image data (alt-text fixer only) — when you use the alt-text feature, we read the URLs and titles of product images that are missing alt text, and store the alt text you review and apply.
What we do not collect
- No customer personal data, orders, or payment/card information.
- Billing is handled entirely by Shopify — we never see or store payment details.
How we use data
- To run scans and produce your report, prioritized fixes, and EAA/EN 301 549 accessibility statement.
- To keep a dated evidence log of your accessibility progress.
- To generate and apply alt text when you use that feature.
Third-party processors
- Amazon Web Services (US, us-east-1) — hosting and encrypted database/backups.
- Anthropic (Claude) — only if you use AI alt-text generation. In that case a product image URL and its title are sent to Anthropic to generate alt text. Not used for any other feature.
- Shopify — authentication and billing.
Retention & deletion
Scan history is retained as your compliance evidence log for as long as the app is installed. When you uninstall the app, or on written request, we delete your store’s data. To request deletion, email us (below).
Your rights
Depending on your location (including the EU/EEA under GDPR), you may have the right to access, correct, export, or delete your data. Contact us to exercise these rights.
Security
Data is transmitted over TLS and stored in an access-controlled database with encrypted nightly backups. Access tokens are stored server-side and never exposed to the browser.
Contact
Questions or requests: jdalcorn01@gmail.com.
This policy describes our current practices and is provided for transparency; it is not legal advice.