AccessKit Privacy Policy

Last updated: July 24, 2026

AccessKit scans a merchant's public storefront for WCAG 2.1 AA issues and hosts the accessibility statement required by the European Accessibility Act. This policy explains what the app stores and why.

What we collect

What we never collect

AccessKit requests no Shopify access scopes and never calls the Admin API for customer, order, or product data. Scans read only the publicly served HTML of a storefront page — the same markup any visitor's browser receives. No customer personal data ever reaches the app.

Why we hold it

Solely to run the scans, show scan history, and host the accessibility statement. Data is never sold, rented, or shared with third parties, and is not used for advertising.

Where data is stored

All data is stored in the app's own database on Cloudflare's infrastructure. External services are limited to the Shopify Admin API (install, billing, and the uninstall webhook) and Resend, which delivers contact-form email.

Data retention & deletion

When a merchant uninstalls AccessKit, the store's access token is cleared. A shop/redact request permanently erases everything held for that store. Because the app stores no customer personal data, customers/redact and customers/data_request have no personal data to return or delete.

Contact

Questions: accesskit.pages.dev/contact