Privacy Policy — a11y-guard

Last updated: 22 July 2026

This Privacy Policy explains how the a11y-guard application ("a11y-guard", "the App", "we", "us") processes personal data when a Shopify merchant installs and uses it. a11y-guard is an accessibility auditing and documentation tool for online stores selling to consumers in the EU, with an initial focus on Germany.

1. Who we are (Data Controller)

The controller for the account and billing data described in Section 4 is:

2. Our two roles (controller vs processor)

We act in two distinct roles:

3. Store data we access (and what we deliberately do not access)

To perform audits and generate fixes and statements, the App requests exactly these Shopify scopes and no others: read_themes, read_products, write_products, read_files, write_files, read_content, write_content.

Through these scopes we process merchant / store data, not end-consumer personal data — theme templates and Liquid source, product information and images, store files, and content pages. We also render public storefront pages to run automated accessibility checks (axe-core plus our own rules) and store the resulting scan records, violations, screenshots and DOM snapshots used to produce your reports and fix package.

We do not request or access customer or order data. The App holds no read_customers, read_orders, or equivalent scopes, and does not touch checkout. Because we access no protected customer-data resources, the App is not subject to Shopify's Level 1 / Level 2 protected-customer-data review. (Shopify, "Protected customer data" — https://shopify.dev/docs/apps/launch/protected-customer-data.)

Incidental personal data. Storefront screenshots, DOM snapshots and HTML snippets we capture for audit evidence may incidentally contain personal data that you have published on your storefront (for example, a customer name in a product review). This is not data we seek; it is captured only as part of the rendered page, is used solely to produce audit reports, and is subject to the retention rules in Section 8.

4. Merchant account data we control

As controller we process: your contact email; plan / subscription status and billing identifiers (billing itself is handled by Shopify — we do not receive card details); onboarding / disclaimer acknowledgements; store locale / market / timezone settings needed to run audits; and support correspondence. Shopify session data — which may include the name and email of the staff member who installs the App — is stored to maintain your authenticated session.

5. Alt-text generation and our AI sub-processor (Anthropic)

When you use the alt-text feature, the App sends product images to Anthropic (the Claude API) to generate draft image descriptions. Anthropic acts as our sub-processor for this feature.

6. The compliance journal — retained and pseudonymised (important, non-standard)

A core feature of the App is an immutable, cryptographically chained compliance journal that records the accessibility actions taken (findings, dates, action types), so it can serve as dated evidence of good-faith measures. Please read this carefully — it is a material, non-standard retention practice.

7. Screenshots, DOM snapshots and scan artifacts

Screenshots, DOM snapshots and HTML snippets captured during audits are stored to generate your reports and fix package, and may incidentally contain personal data (Section 3). They are retained for a rolling 90 days from capture and then deleted, and are deleted on shop/redact. They are distinct from the pseudonymised journal in Section 6.

8. Data retention and deletion

9. Sub-processors

We use the following sub-processors and have a data-processing agreement in place with each. Our default posture is to keep store data in the EU.

Sub-processorPurposeDataRegion
ShopifyPlatform, authentication, billingStore & merchant data via APIsShopify's regions
Anthropic (Claude API)Alt-text generationProduct images onlyMay be outside EU/EEA; SCCs (Section 5)
Fly.ioApplication & worker hosting, databaseStore & merchant data in processingEU (Frankfurt)
Upstash (Redis)Background job queueOpaque internal job identifiers only (no personal data)EU (Frankfurt)

We notify you in advance of any change to this list, giving you an opportunity to object on reasonable data-protection grounds.

10. International data transfers

Our default is to keep store data in the EU. The alt-text feature (Section 5) may involve a transfer to a sub-processor outside the EU/EEA; where personal data is transferred outside the EU/EEA, we rely on the EU Standard Contractual Clauses and any necessary supplementary measures.

11. Your rights (GDPR Articles 15–22)

Subject to the conditions in the GDPR, you and other data subjects have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and to object (Art. 21). Where processing is based on consent, it can be withdrawn at any time. Records in the immutable compliance journal (Section 6) are retained on the lawful basis stated there; an erasure request against those records is assessed against that basis and Art. 17(3).

You may lodge a complaint with a data-protection supervisory authority. The authority competent for us, as a controller established in Latvia, is:

Datu valsts inspekcija (Data State Inspectorate)
Elijas iela 17, Riga, LV-1050, Latvia · +371 6722 3131 · pasts@dvi.gov.lv · https://www.dvi.gov.lv

You may also lodge a complaint with the supervisory authority of your own EU Member State of habitual residence or place of work (GDPR Art. 77). This does not change the position of end-consumers: where you are a merchant, you are the controller towards your own end-customers for the store data we process on your behalf as processor, and those end-customers complain to their own national data-protection authority. To exercise any right, contact a11yguardsupport@gmail.com. (GDPR (EU) 2016/679 — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679.)

12. Security

13. Lawful bases (summary)

ProcessingPurposeBasis
Store data via Shopify APIsProvide audits/fixes (as processor)Your instruction under the DPA
Merchant account / support dataOperate the service, supportArt. 6(1)(b) contract / 6(1)(f) legitimate interest
Alt text via AnthropicGenerate image descriptions on requestArt. 6(1)(b)/(f), on your direction
Compliance journal retention (pseudonymised)Tamper-evident evidenceArt. 6(1)(f) + Art. 17(3)(e)

14. Changes to this policy

We may update this Privacy Policy; the "Last updated" date reflects the current version. Material changes affecting sub-processors or retention will be communicated as required by the DPA and applicable law.

15. Contact

Privacy enquiries: a11yguardsupport@gmail.com. Controller: MONIX SIA, Jasmuižas iela 17 - 67, Rīga, LV-1021, Latvia (registration No. 40203684101), represented by Eriks Ivanovs.