Privacy Policy

Last updated: May 13, 2026

This Privacy Policy describes how Access Shift collects, uses, and shares information when you visit our marketing site, sign in to our dashboard, or embed our accessibility remediation widget on your website.

Scope of this policy

This policy applies to accessshift.com, the Access Shift dashboard, and the remediation widget served from our domain. It covers personal data we process as a controller (for example, your account information) and, separately, data we process on behalf of our customers as a processor (for example, data the widget encounters on a customer site).

If you visit a website that embeds the Access Shift widget, the operator of that website is the controller of any personal data collected on that site. Their privacy notice — not ours — governs how your information is handled there.

Data we collect

Account information

When you create an account, we collect your name, email address, and (optionally) phone number. If you sign in via Google, we receive your name, email, and Google profile ID. We collect your website URL to set up your first scan.

Scan data

When we crawl your site, we process the publicly accessible HTML of each scanned page to identify accessibility issues. We store WCAG verdicts, issue evidence (DOM fragments, selectors, screenshots), and per-page scores. We do not intentionally collect personal data from your page content, but public pages may incidentally contain it.

Telemetry and usage data

We collect server logs (IP address, user agent, response codes, timestamps) and application events (page views, feature interactions) to operate and improve the service. If you have enabled analytics, we also use Google Analytics 4 under Consent Mode v2 (see below).

How we use data

We use account information to authenticate you, send transactional emails (verification, receipts, scan reports), and provide support. We use scan data to generate your WCAG reports and train our detection models. We use telemetry to monitor uptime, debug errors, and understand how the product is used. We do not sell personal data to third parties.

Analytics and cookies

We use Google Analytics 4 with Consent Mode v2. Analytics is fully inert unless you accept cookies via the consent banner. If you decline, no tracking cookies are set and no personal data is sent to Google. Your consent preference is stored in localStorage and can be changed at any time. We do not use advertising cookies or cross-site tracking.

Data the widget processes

The Access Shift remediation widget runs entirely in your visitors' browsers. It reads and modifies the live DOM to apply accessibility fixes. It does not set tracking cookies, does not send visitor data to our servers, and does not exfiltrate page content. The only network request the widget makes is the initial script load from our CDN.

Subprocessors

We use a small number of trusted subprocessors to operate the service: cloud infrastructure providers, email delivery services, payment processing (Stripe), and error monitoring. Enterprise customers may request a full subprocessor list. We notify customers before adding material new subprocessors.

Retention and deletion

Account data is retained for the life of your account and for 30 days after cancellation or deletion, after which it is purged. Scan data follows the same schedule. Server logs are retained for up to 90 days. You can request deletion of your account and associated data at any time by emailing privacy@accessshift.com.

Your rights

Depending on where you are located, you may have rights to access, correct, port, restrict, or erase your personal data, and to object to certain processing. To exercise any of these rights, email privacy@accessshift.com. We will respond within the timeframe required by applicable law.

International transfers

Access Shift is operated from the United States. If you are located in the EU, UK, or another jurisdiction with data transfer restrictions, we rely on the EU Standard Contractual Clauses (and UK Addendum where applicable) as a transfer mechanism. Enterprise customers may execute a Data Processing Addendum — see our DPA page.

Security

We protect personal data using HTTPS, encrypted storage, hashed passwords, and access controls. See our Security page for a full description of our controls.

Changes to this policy

We will post updates to this page with a revised "Last updated" date. For material changes, we will notify account holders by email at least 14 days in advance.

Contact us

For privacy questions, requests, or complaints: privacy@accessshift.com.