Privacy policy
Last updated: September 15, 2026
The short version. A11y Suite reads your product catalogue and opens your public storefront in a browser to check it against WCAG 2.2. It does not ask for, receive, or store your customers’ personal data — no orders, no checkouts, no customer records. It adds no code to your storefront. We do not sell personal data and we do not use your data to train AI models.
Uninstall the app and your login session and any saved storefront password are deleted immediately; your scan history is deleted when Shopify notifies us 48 hours later.
1. Who we are
A11y Suite is operated by Nodiumtech LLC, a limited liability company registered in Texas, United States, with its place of business in Houston, Texas. In this policy “we”, “us” and “our” mean Nodiumtech LLC, and “you” means the merchant who installs the app.
For any privacy question or request, write to admin@nodiumtech.com. We reply within one business day and complete data requests within 30 days.
2. The two roles we play
We are a controller for the account information we need in order to run the service for you — your store address, the Shopify staff account that signs in, and your subscription status.
We are a processor for everything we read out of your store: your product catalogue and the content of your storefront pages. We process that material only to produce your accessibility findings, only on your instructions, and we do not use it for any purpose of our own.
3. What we collect, and why
| What | Why | Kept for |
|---|---|---|
| Store address and access token, and the permissions you granted | Without these the app cannot talk to your store at all. The token is issued by Shopify, not by us, and only works for the permissions you approved. | Until you uninstall |
| The Shopify staff account that opens the app — name, email address, language, and whether that person is the store owner | To show the app to the right person and to keep one merchant’s results separate from another’s. Shopify supplies these fields with the login; we do not ask you for them. | Until you uninstall |
| Product catalogue data — product titles, image addresses, and any alt text already on your images | To find images with missing, duplicated, or unhelpful alt text, and to write alt text back when you approve a draft. | Until you uninstall; drafts you never publish are deleted with the rest |
| Scan results — the addresses of the pages checked, the rule that failed, the CSS selector and a short fragment of the HTML that failed it, measurements such as contrast ratios, and a screenshot of the page | This is the product. The HTML fragment and the screenshot are the evidence behind each finding, so that you (or an auditor, or a lawyer) can see exactly what was measured and on what date. | Findings: until you uninstall. Screenshots: deleted automatically after 90 days |
| Your email preferences — whether you asked for scan results by email, whether you opted in to product news, the date you chose, and the exact wording you agreed to | To send only what you asked for, and to be able to show what you consented to and when. | Until you uninstall |
| Your storefront password, only if your online store is password protected and you enter it in the app | To get past Shopify’s password page, so the scan measures your theme and not that page. Stored encrypted and used for nothing else. | Until your store opens, you remove it, or you uninstall — whichever comes first |
| Ordinary server logs — IP address, browser user agent, date and time of requests | Security, abuse prevention, and diagnosing faults. These are written by the web server, not by the app. | Rotated within 30 days |
4. What we do not collect
The app requests two permissions and no others: read_products and write_products. It has no access to customers, orders, checkouts, draft orders, payments, or discounts, and it cannot obtain that access without asking you to approve a new permission.
Under Shopify’s protected customer data rules, an app that queries only products is Level 0 — no customer data, and we therefore hold no protected customer data of any kind.
When our scanner opens your storefront it behaves as follows:
- It never signs in as a customer and never creates an account.
- It submits no form on your storefront except one: if your store is password protected and you entered the storefront password in the app, it enters that password on Shopify’s password page, as a visitor you gave it to would. It is explicitly forbidden from clicking anything that reads add to cart, buy it now, checkout, subscribe, sign up, log in, apply, place order, or pay. This is enforced in code and covered by our test suite, so a scan cannot place an order or join a mailing list on your live store.
- It looks at one representative page of each kind — home, collection, product, cart, search, and a content page — not your entire catalogue.
- It adds nothing to your storefront. No widget, no overlay, no script tag. Your shoppers are not tracked by us, and nothing we do is visible to them.
If a screenshot of your own storefront happens to contain personal data — for example a review that shows a shopper’s first name — that is a copy of a page any member of the public can already see. Tell us and we will delete the image immediately.
5. The optional theme extension
A11y Suite includes an app embed called Accessibility Fixes that you can switch on in your theme editor. It is off unless you turn it on, it sends stylesheet rules only — a visible focus ring and larger tap targets — and it contains no JavaScript. It does not read the page, does not alter your HTML, does not add ARIA attributes, collects nothing, and sends nothing back to us. It is not an accessibility overlay.
6. Email we send you
There are two kinds, and they are kept separate on purpose.
- Scan results. If you switch on weekly monitoring and ask for results by email, we send you each result. This is part of the service you turned on; it stops when you turn monitoring off.
- Product news. A separate, optional tick box. It is never ticked for you, it is not required to use anything, and refusing it changes nothing about the service. We record the date you chose and the exact sentence you agreed to, so that what you consented to is a matter of record. Untick the box and press Save to stop — withdrawing is exactly as easy as giving it, and every email also carries an unsubscribe link.
We do not add you to a marketing list for installing the app, and we do not pass your address to anyone else for their own marketing.
7. Artificial intelligence
One feature uses AI: drafting alt text for product images. When you run it, we send the address of the product image and the product title to Anthropic PBC and receive a one-sentence description back.
- Anthropic states that data submitted through its commercial API is not used to train its models.
- Nothing is written to your store automatically. Every draft waits for you to read it and press publish. You can edit or discard any of them.
- If you never use the feature, no data of yours ever reaches Anthropic.
- We do not use your store’s data to train any model of our own, and we do not use one merchant’s data to improve results for another merchant.
8. Who else touches your data
We use a small number of service providers. They may process your data only to deliver their service to us, under written terms.
| Provider | What for | Where |
|---|---|---|
| Shopify Inc. | The platform itself: authentication, the permissions you grant, and billing | Canada / United States |
| Hostinger International Ltd. | The virtual server the app and its database run on | United States |
| Anthropic PBC | Alt text drafting — only if you use that feature | United States |
| Twilio SendGrid | Sending you a scan report by email if you turn email reports on, and product news if you separately opt in | United States |
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not disclose it to anyone else except where the law requires it. We will tell you before we add a subprocessor, unless we are legally prevented from doing so.
9. Where your data is held, and transfers
Our servers are in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is transferred to the United States under the European Commission’s Standard Contractual Clauses, together with the UK Addendum where it applies. Ask us and we will send you the clauses we rely on.
10. How long we keep things, and how deletion works
- When you uninstall, Shopify tells us immediately and we delete your login session and access token at once. The app can no longer reach your store from that moment.
- 48 hours after uninstall, Shopify sends the shop erasure request. We then delete every scan, every finding, every screenshot, every alt text draft, every manual check and every report belonging to your store.
- Screenshots older than 90 days are deleted automatically while you are still a customer. The written finding stays; only the image goes.
- You do not have to uninstall to be deleted. Email us and we will erase your data on request.
- Deleted records may survive for a short time in encrypted backups before those backups are rotated out. They are not used for anything and are overwritten on a fixed schedule.
11. Security
The service is served only over HTTPS with HSTS. The application runs as a restricted system account on a hardened server with a default-deny firewall, automatic banning of repeated failed logins, and no public access to the database, which is readable only by the application itself. Access tokens are never written to logs. Administrative access is limited to the operator of Nodiumtech LLC over key-based SSH; there are no shared passwords.
No system is perfect. If we discover a breach affecting your data we will tell you and the relevant supervisory authority without undue delay and, where the law sets a deadline, within 72 hours of becoming aware.
12. Your rights
Depending on where you live, you may have the right to ask for a copy of your data, to correct it, to delete it, to receive it in a portable format, to object to or restrict our processing of it, and to withdraw consent. If you are in the EEA or the UK these rights come from the GDPR; if you are in California they come from the CCPA as amended by the CPRA; similar rights exist in several other US states.
Because we hold no protected customer data, a request from one of your shoppers will normally have nothing for us to return. If Shopify forwards us such a request we answer it anyway, and we tell you that it arrived.
To exercise any right, email admin@nodiumtech.com from the address associated with your store. We do not charge for this and we do not treat you differently for asking. If you are unhappy with our answer, you may complain to your local data protection authority.
13. Children
A11y Suite is a business tool sold to merchants. It is not directed at children and we do not knowingly collect data from anyone under 16.
14. Changes to this policy
If we change this policy we will update the date at the top. If a change materially affects how we handle your data, we will tell you inside the app or by email before it takes effect.
15. Contact
Nodiumtech LLC, Houston, Texas, USA — admin@nodiumtech.com. Our related terms are at Terms of service, and help is at Support.