Privacy Policy
Last updated: July 22, 2026
AccessGuard (“we”, “us”) provides an automated accessibility scanning tool for websites, with an optional account, subscription plan, and continuous monitoring feature. This policy explains what data we collect, why, and how you can control it. This policy applies wherever AccessGuard is accessible, including to visitors in California and the European Union.
What we collect
- Account data: email address, a bcrypt hash of your password (we never store your password itself), and an optional display name.
- Scan data: the URLs you submit for scanning, and the full scan result (a technical report of accessibility issues found on the page, including small HTML excerpts of the flagged elements). If you're logged in, this is saved to your scan history; anonymous scans are not saved.
- Monitoring data: if you enable continuous monitoring, we store the URLs you choose to monitor and the scan history generated from periodic re-scans.
- Subscription data: your plan (free/Pro), subscription status, and identifiers from our payment processor Creem (customer ID, subscription ID, renewal/expiry dates). We do not collect or store your card number — Creem handles payment collection directly.
- Anonymous usage data: for visitors who scan without an account, we temporarily track IP address to enforce a fair-use rate limit. This is not tied to any other data and is not persisted beyond the rate-limiting window.
- Waitlist data: if you join a feature waitlist, we store the email address and store URL you provide.
How we use it
To operate the scanning service, enforce free-plan usage limits, maintain your scan history, process subscription billing and renewals, send continuous-monitoring alert emails when a monitored site's score drops, and respond to support requests. We do not sell your data, and we do not use third-party advertising or analytics trackers on this site.
Third parties we share data with
- Creem — our payment processor (merchant of record). Handles checkout and billing; we only receive your subscription status, not your payment details.
- Resend — our transactional email provider, used only to send continuous-monitoring alert emails if you enable that feature.
Shopify App integration
If you install AccessGuard from the Shopify App Store, this section describes what we collect and do specifically through that integration, in addition to the data described above.
- What we store on install: your store's domain (e.g.
your-store.myshopify.com), an access token issued by Shopify that lets AccessGuard call your store's Admin API, and the API scopes you granted during installation. The access token is encrypted at rest with AES-256-GCM before it is ever written to our database, and is only decrypted in memory when we need to call your store's Admin API. - What we don't collect:AccessGuard does not access, request, or store any personal information about your store's customers (names, emails, addresses, order history, etc.). Our scans analyze the public-facing pages of your storefront for accessibility issues — we only ever handle store-level scan and monitoring data, never customer-level data.
- Uninstalling the app:if you uninstall AccessGuard, we stop all monitoring immediately and retain your store's data only in case you reinstall. Shopify notifies us to permanently erase all data tied to your store (installation record, access token, scan history, and monitors) on its own mandated schedule after uninstall, and we delete it as soon as that notice arrives.
- Data requests and deletion:as required by Shopify, AccessGuard supports the three mandatory Shopify compliance webhooks. Because we don't store any personal data about your store's end customers, requests relating to a specific customer (data access or erasure) require no action on our part — there is nothing about that customer in our systems to return or delete. As the store owner, you can request a copy of, or deletion of, the data we hold about your store at any time by emailing support@accessguard.qiuyuelab.com, in addition to the automatic erasure described above.
Cookies
We use a single essential, httpOnly session cookie (ag_session) to keep you signed in. It is not used for tracking or advertising, and is not shared with third parties.
Data retention
We retain account, scan, and monitoring data for as long as your account is active, so your scan history and monitors remain available to you. If you'd like your data deleted, contact us (below) and we'll remove your account records and any associated scan history and waitlist entries within a reasonable time.
Your rights
You can request access to, correction of, or deletion of your personal data at any time by emailing us at support@accessguard.qiuyuelab.com. If you're an EU resident, this includes rights under the GDPR; if you're a California resident, this includes rights under the CCPA/CalOPPA.
Children's privacy
AccessGuard is a business tool intended for site owners and developers. It is not directed at children, and we do not knowingly collect data from anyone under 16.
Changes to this policy
If we make material changes to this policy, we'll update the date at the top of this page. Continued use of AccessGuard after a change means you accept the updated policy.
Contact
Questions about this policy? Email support@accessguard.qiuyuelab.com.