Privacy Policy — a11y-guard
Last updated: 22 July 2026
This Privacy Policy explains how the a11y-guard application ("a11y-guard", "the App", "we", "us") processes personal data when a Shopify merchant installs and uses it. a11y-guard is an accessibility auditing and documentation tool for online stores selling to consumers in the EU, with an initial focus on Germany.
1. Who we are (Data Controller)
The controller for the account and billing data described in Section 4 is:
- Legal entity: MONIX SIA (a Latvian limited liability company), registration No. 40203684101
- Registered address: Jasmuižas iela 17 - 67, Rīga, LV-1021, Latvia
- Represented by: Eriks Ivanovs
- Contact email: a11yguardsupport@gmail.com
- Data Protection Officer: We have not appointed a Data Protection Officer. Privacy enquiries are handled at the contact email above.
2. Our two roles (controller vs processor)
We act in two distinct roles:
- Processor — for the store data we access through Shopify's APIs on your behalf (theme code, product data, public storefront pages and screenshots). You are the controller of that data; we process it only to provide the App's features. This relationship is governed by our Data Processing Agreement (DPA).
- Controller — for merchant account data whose use we determine: your contact email, plan/subscription status, onboarding acknowledgements, and support correspondence (Section 4).
3. Store data we access (and what we deliberately do not access)
To perform audits and generate fixes and statements, the App requests exactly these Shopify scopes and no others: read_themes, read_products, write_products, read_files, write_files, read_content, write_content.
Through these scopes we process merchant / store data, not end-consumer personal data — theme templates and Liquid source, product information and images, store files, and content pages. We also render public storefront pages to run automated accessibility checks (axe-core plus our own rules) and store the resulting scan records, violations, screenshots and DOM snapshots used to produce your reports and fix package.
We do not request or access customer or order data. The App holds no read_customers, read_orders, or equivalent scopes, and does not touch checkout. Because we access no protected customer-data resources, the App is not subject to Shopify's Level 1 / Level 2 protected-customer-data review. (Shopify, "Protected customer data" — https://shopify.dev/docs/apps/launch/protected-customer-data.)
Incidental personal data. Storefront screenshots, DOM snapshots and HTML snippets we capture for audit evidence may incidentally contain personal data that you have published on your storefront (for example, a customer name in a product review). This is not data we seek; it is captured only as part of the rendered page, is used solely to produce audit reports, and is subject to the retention rules in Section 8.
4. Merchant account data we control
As controller we process: your contact email; plan / subscription status and billing identifiers (billing itself is handled by Shopify — we do not receive card details); onboarding / disclaimer acknowledgements; store locale / market / timezone settings needed to run audits; and support correspondence. Shopify session data — which may include the name and email of the staff member who installs the App — is stored to maintain your authenticated session.
5. Alt-text generation and our AI sub-processor (Anthropic)
When you use the alt-text feature, the App sends product images to Anthropic (the Claude API) to generate draft image descriptions. Anthropic acts as our sub-processor for this feature.
- What is sent: the product image and minimal instructions. No customer or order data is sent (we hold none).
- Incidental content: an image may itself contain text or personal data (e.g. a photographed label, a person in a lifestyle photo). By using this feature you direct us to transmit the selected images to the AI sub-processor.
- Processing location and transfers: Anthropic processes API data on its infrastructure, which may be outside the EU/EEA. Where personal data is transferred outside the EU/EEA, we rely on the EU Standard Contractual Clauses (SCCs) and any necessary supplementary measures.
- Retention at the sub-processor: under Anthropic's commercial API terms, API inputs and outputs are, by default, deleted within 30 days, and commercial inputs/outputs are not used to train models. (Anthropic Privacy Center — https://privacy.claude.com.)
- Human control: generated alt text is a suggestion; nothing is written to your store without your explicit approval.
6. The compliance journal — retained and pseudonymised (important, non-standard)
A core feature of the App is an immutable, cryptographically chained compliance journal that records the accessibility actions taken (findings, dates, action types), so it can serve as dated evidence of good-faith measures. Please read this carefully — it is a material, non-standard retention practice.
- The journal is designed to record only non-personal audit facts — WCAG / EN 301 549 criterion codes, severity, dates, action types, counters, engine and ruleset versions, and hashes — linked to an opaque internal identifier. It is designed not to contain your store domain, contact email, names, or storefront markup.
- The journal is immutable: records cannot be altered or deleted, and a SHA-256 hash chain makes tampering detectable. This is what gives it evidentiary value.
- On uninstall /
shop/redact, the journal is not deleted. Instead it is pseudonymised: we replace your store domain with a salted hash, clear access tokens and contact email, delete session data and scan artifacts, and retain the non-personal journal records linked to the opaque identifier. (Design decision D-013.) - Legal basis: our legitimate interest in maintaining tamper-evident accessibility evidence (GDPR Art. 6(1)(f)) and, where genuinely necessary, the establishment, exercise or defence of legal claims (Art. 17(3)(e)). We do not claim a statutory obligation to retain.
- Retention period: the pseudonymised journal is retained for 6 years after uninstall and then deleted. This defined period reflects the storage-limitation principle (Art. 5(1)(e)) and the limitation periods for related claims under German law.
- Because pseudonymised data remains personal data under the GDPR (Art. 4(5), Recital 26), the rights in Section 11 continue to apply to it, subject to the lawful basis above.
7. Screenshots, DOM snapshots and scan artifacts
Screenshots, DOM snapshots and HTML snippets captured during audits are stored to generate your reports and fix package, and may incidentally contain personal data (Section 3). They are retained for a rolling 90 days from capture and then deleted, and are deleted on shop/redact. They are distinct from the pseudonymised journal in Section 6.
8. Data retention and deletion
- Uninstall /
shop/redact: about 48 hours after uninstall, Shopify sends ashop/redactrequest; within Shopify's 30-day window we pseudonymise your store's personal data and delete scan artifacts and session data, while retaining the non-personal compliance journal (Section 6) for 6 years after uninstall. (Shopify, "Privacy law compliance" — https://shopify.dev/docs/apps/build/privacy-law-compliance.) customers/redactandcustomers/data_request: we respond to these mandatory requests; because we hold no customer personal data, our response is that no customer data is stored or processed by the App (the only customer-adjacent data is incidental content in scan artifacts, deleted per Section 7).- Account data: retained while the App is installed and pseudonymised/deleted on
shop/redactas above; we do not hold invoices or card data (Shopify does).
9. Sub-processors
We use the following sub-processors and have a data-processing agreement in place with each. Our default posture is to keep store data in the EU.
| Sub-processor | Purpose | Data | Region |
|---|---|---|---|
| Shopify | Platform, authentication, billing | Store & merchant data via APIs | Shopify's regions |
| Anthropic (Claude API) | Alt-text generation | Product images only | May be outside EU/EEA; SCCs (Section 5) |
| Fly.io | Application & worker hosting, database | Store & merchant data in processing | EU (Frankfurt) |
| Upstash (Redis) | Background job queue | Opaque internal job identifiers only (no personal data) | EU (Frankfurt) |
We notify you in advance of any change to this list, giving you an opportunity to object on reasonable data-protection grounds.
10. International data transfers
Our default is to keep store data in the EU. The alt-text feature (Section 5) may involve a transfer to a sub-processor outside the EU/EEA; where personal data is transferred outside the EU/EEA, we rely on the EU Standard Contractual Clauses and any necessary supplementary measures.
11. Your rights (GDPR Articles 15–22)
Subject to the conditions in the GDPR, you and other data subjects have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and to object (Art. 21). Where processing is based on consent, it can be withdrawn at any time. Records in the immutable compliance journal (Section 6) are retained on the lawful basis stated there; an erasure request against those records is assessed against that basis and Art. 17(3).
You may lodge a complaint with a data-protection supervisory authority. The authority competent for us, as a controller established in Latvia, is:
Datu valsts inspekcija (Data State Inspectorate)
Elijas iela 17, Riga, LV-1050, Latvia · +371 6722 3131 · pasts@dvi.gov.lv · https://www.dvi.gov.lv
You may also lodge a complaint with the supervisory authority of your own EU Member State of habitual residence or place of work (GDPR Art. 77). This does not change the position of end-consumers: where you are a merchant, you are the controller towards your own end-customers for the store data we process on your behalf as processor, and those end-customers complain to their own national data-protection authority. To exercise any right, contact a11yguardsupport@gmail.com. (GDPR (EU) 2016/679 — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679.)
12. Security
- Shopify access tokens and refresh tokens that the App stores in its own database are encrypted at rest using AES-256-GCM; the storefront-password field is encrypted with the same scheme.
- Data in transit is protected with HTTPS/TLS.
- The compliance journal's integrity is protected by a SHA-256 hash chain, making alteration or deletion of records detectable.
- Access to personal data is restricted to authorised personnel, and administrative deletion of the immutable journal is prevented at the database-role level.
13. Lawful bases (summary)
| Processing | Purpose | Basis |
|---|---|---|
| Store data via Shopify APIs | Provide audits/fixes (as processor) | Your instruction under the DPA |
| Merchant account / support data | Operate the service, support | Art. 6(1)(b) contract / 6(1)(f) legitimate interest |
| Alt text via Anthropic | Generate image descriptions on request | Art. 6(1)(b)/(f), on your direction |
| Compliance journal retention (pseudonymised) | Tamper-evident evidence | Art. 6(1)(f) + Art. 17(3)(e) |
14. Changes to this policy
We may update this Privacy Policy; the "Last updated" date reflects the current version. Material changes affecting sub-processors or retention will be communicated as required by the DPA and applicable law.
15. Contact
Privacy enquiries: a11yguardsupport@gmail.com. Controller: MONIX SIA, Jasmuižas iela 17 - 67, Rīga, LV-1021, Latvia (registration No. 40203684101), represented by Eriks Ivanovs.