Last updated: July 24, 2026
AccessKit scans a merchant's public storefront for WCAG 2.1 AA issues and hosts the accessibility statement required by the European Accessibility Act. This policy explains what the app stores and why.
myshopify.com domain, the app's access token, and the plan the store is on.AccessKit requests no Shopify access scopes and never calls the Admin API for customer, order, or product data. Scans read only the publicly served HTML of a storefront page — the same markup any visitor's browser receives. No customer personal data ever reaches the app.
Solely to run the scans, show scan history, and host the accessibility statement. Data is never sold, rented, or shared with third parties, and is not used for advertising.
All data is stored in the app's own database on Cloudflare's infrastructure. External services are limited to the Shopify Admin API (install, billing, and the uninstall webhook) and Resend, which delivers contact-form email.
When a merchant uninstalls AccessKit, the store's access token is cleared. A shop/redact request permanently erases everything held for that store. Because the app stores no customer personal data, customers/redact and customers/data_request have no personal data to return or delete.
Questions: accesskit.pages.dev/contact