Skip to content
A11y Suiteby Nodiumtech LLC

Privacy policy

Last updated: September 15, 2026

The short version. A11y Suite reads your product catalogue and opens your public storefront in a browser to check it against WCAG 2.2. It does not ask for, receive, or store your customers’ personal data — no orders, no checkouts, no customer records. It adds no code to your storefront. We do not sell personal data and we do not use your data to train AI models.

Uninstall the app and your login session and any saved storefront password are deleted immediately; your scan history is deleted when Shopify notifies us 48 hours later.

1. Who we are

A11y Suite is operated by Nodiumtech LLC, a limited liability company registered in Texas, United States, with its place of business in Houston, Texas. In this policy “we”, “us” and “our” mean Nodiumtech LLC, and “you” means the merchant who installs the app.

For any privacy question or request, write to admin@nodiumtech.com. We reply within one business day and complete data requests within 30 days.

2. The two roles we play

We are a controller for the account information we need in order to run the service for you — your store address, the Shopify staff account that signs in, and your subscription status.

We are a processor for everything we read out of your store: your product catalogue and the content of your storefront pages. We process that material only to produce your accessibility findings, only on your instructions, and we do not use it for any purpose of our own.

3. What we collect, and why

Every category of data A11y Suite stores, the reason it is stored, and how long it is kept.
WhatWhyKept for
Store address and access token, and the permissions you grantedWithout these the app cannot talk to your store at all. The token is issued by Shopify, not by us, and only works for the permissions you approved.Until you uninstall
The Shopify staff account that opens the app — name, email address, language, and whether that person is the store ownerTo show the app to the right person and to keep one merchant’s results separate from another’s. Shopify supplies these fields with the login; we do not ask you for them.Until you uninstall
Product catalogue data — product titles, image addresses, and any alt text already on your imagesTo find images with missing, duplicated, or unhelpful alt text, and to write alt text back when you approve a draft.Until you uninstall; drafts you never publish are deleted with the rest
Scan results — the addresses of the pages checked, the rule that failed, the CSS selector and a short fragment of the HTML that failed it, measurements such as contrast ratios, and a screenshot of the pageThis is the product. The HTML fragment and the screenshot are the evidence behind each finding, so that you (or an auditor, or a lawyer) can see exactly what was measured and on what date.Findings: until you uninstall. Screenshots: deleted automatically after 90 days
Your email preferences — whether you asked for scan results by email, whether you opted in to product news, the date you chose, and the exact wording you agreed toTo send only what you asked for, and to be able to show what you consented to and when.Until you uninstall
Your storefront password, only if your online store is password protected and you enter it in the appTo get past Shopify’s password page, so the scan measures your theme and not that page. Stored encrypted and used for nothing else.Until your store opens, you remove it, or you uninstall — whichever comes first
Ordinary server logs — IP address, browser user agent, date and time of requestsSecurity, abuse prevention, and diagnosing faults. These are written by the web server, not by the app.Rotated within 30 days

4. What we do not collect

The app requests two permissions and no others: read_products and write_products. It has no access to customers, orders, checkouts, draft orders, payments, or discounts, and it cannot obtain that access without asking you to approve a new permission.

Under Shopify’s protected customer data rules, an app that queries only products is Level 0 — no customer data, and we therefore hold no protected customer data of any kind.

When our scanner opens your storefront it behaves as follows:

If a screenshot of your own storefront happens to contain personal data — for example a review that shows a shopper’s first name — that is a copy of a page any member of the public can already see. Tell us and we will delete the image immediately.

5. The optional theme extension

A11y Suite includes an app embed called Accessibility Fixes that you can switch on in your theme editor. It is off unless you turn it on, it sends stylesheet rules only — a visible focus ring and larger tap targets — and it contains no JavaScript. It does not read the page, does not alter your HTML, does not add ARIA attributes, collects nothing, and sends nothing back to us. It is not an accessibility overlay.

6. Email we send you

There are two kinds, and they are kept separate on purpose.

We do not add you to a marketing list for installing the app, and we do not pass your address to anyone else for their own marketing.

7. Artificial intelligence

One feature uses AI: drafting alt text for product images. When you run it, we send the address of the product image and the product title to Anthropic PBC and receive a one-sentence description back.

8. Who else touches your data

We use a small number of service providers. They may process your data only to deliver their service to us, under written terms.

Our subprocessors.
ProviderWhat forWhere
Shopify Inc.The platform itself: authentication, the permissions you grant, and billingCanada / United States
Hostinger International Ltd.The virtual server the app and its database run onUnited States
Anthropic PBCAlt text drafting — only if you use that featureUnited States
Twilio SendGridSending you a scan report by email if you turn email reports on, and product news if you separately opt inUnited States

We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not disclose it to anyone else except where the law requires it. We will tell you before we add a subprocessor, unless we are legally prevented from doing so.

9. Where your data is held, and transfers

Our servers are in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is transferred to the United States under the European Commission’s Standard Contractual Clauses, together with the UK Addendum where it applies. Ask us and we will send you the clauses we rely on.

10. How long we keep things, and how deletion works

11. Security

The service is served only over HTTPS with HSTS. The application runs as a restricted system account on a hardened server with a default-deny firewall, automatic banning of repeated failed logins, and no public access to the database, which is readable only by the application itself. Access tokens are never written to logs. Administrative access is limited to the operator of Nodiumtech LLC over key-based SSH; there are no shared passwords.

No system is perfect. If we discover a breach affecting your data we will tell you and the relevant supervisory authority without undue delay and, where the law sets a deadline, within 72 hours of becoming aware.

12. Your rights

Depending on where you live, you may have the right to ask for a copy of your data, to correct it, to delete it, to receive it in a portable format, to object to or restrict our processing of it, and to withdraw consent. If you are in the EEA or the UK these rights come from the GDPR; if you are in California they come from the CCPA as amended by the CPRA; similar rights exist in several other US states.

Because we hold no protected customer data, a request from one of your shoppers will normally have nothing for us to return. If Shopify forwards us such a request we answer it anyway, and we tell you that it arrived.

To exercise any right, email admin@nodiumtech.com from the address associated with your store. We do not charge for this and we do not treat you differently for asking. If you are unhappy with our answer, you may complain to your local data protection authority.

13. Children

A11y Suite is a business tool sold to merchants. It is not directed at children and we do not knowingly collect data from anyone under 16.

14. Changes to this policy

If we change this policy we will update the date at the top. If a change materially affects how we handle your data, we will tell you inside the app or by email before it takes effect.

15. Contact

Nodiumtech LLC, Houston, Texas, USA — admin@nodiumtech.com. Our related terms are at Terms of service, and help is at Support.