Privacy Policy
Last updated: 2026-09-23
This policy explains what data the Shopify app Capyo: Accessibility WCAG EAA and this website process, why, on what legal basis, and how long it is kept. It is written for the merchant who installs the app. It is not legal advice about your own obligations under the European Accessibility Act, the BFSG or the GDPR.
1. Who is responsible
The controller depends on the data. For your relationship with the app — the store record, plan and billing status, and support correspondence — and for this website, the controller is Capyo, operated by an individual developer. For everything the app reads about your shop and catalog, you are the controller and Capyo acts as your processor under the Data Processing Agreement. Contact for anything in this document, including all data-protection requests: gimbernat13@gmail.com.
Operator legal name and address: [to be added]
For the personal data of your customers, you remain the controller. Capyo is built to never receive your customers' names, email addresses, phone numbers or physical addresses, and it requests no Shopify scope that would give it access to them — see section 2 for exactly what it does read and store.
2. Data the app processes
It comes from Shopify when you install the app, from the scans you run, from the images whose alt text you approve, and from you. In detail:
- Store record. Your
.myshopify.comshop domain, your storefront domains, primary and storefront locales, current plan and when it was last checked, trial end, the optional storefront password you can enter so a password-protected store can be scanned, whether the theme's app embed is enabled and when that was last checked, whether email is enabled, your contact email, and install and uninstall timestamps. - Sessions. The Shopify access token issued to the app for your store, and the session fields Shopify supplies with it: the shop domain, the Shopify staff user id, first and last name, email address, locale, whether the user is the account owner or a collaborator, and the token's scope, expiry and refresh data. This is the data of the merchant and staff who use the app, not of your customers.
- Page set. The URLs the app scans and where each came from (added automatically from the store, or added by you), their kind and their order. Checkout and cart-completion URLs are never added and never scanned.
- Scans, scan pages and findings. Per scan: the trigger, status, page progress and timestamps, and the axe-core version used. Per scanned page: its URL, status, score, counts per impact and how long it took. Per finding: the axe rule id, impact, WCAG criterion, CSS selector, a snippet of at most 400 characters of the page's HTML, and the rule's help URL. The full DOM and any screenshot of your page are not stored.
- Fix states and preview tokens. Which of the app's code-level fixes are off, previewing or live for your shop, when each was applied or reverted, and the short-lived preview tokens you generate to look at a fix on your own storefront.
- Alt jobs and alt items. The selection you chose, the image's Shopify file id and URL, the previous alt text, the generated text, any edit you made, and the item's state (pending, accepted, written, rejected, reverted). Nothing is written to Shopify until you accept an item.
- Reports and statements. The per-criterion result table of each Prüfbericht, the generated PDF and its size, the scan it belongs to and the axe-core version. For the accessibility statement: the legal name, contact email and enforcement-body fields you edit, the known non-accessible areas drawn from findings, the statement date, and whether it is published.
- Widget settings. Whether the storefront widget is on, its button colour, icon style, size, corner position, optional language override, and which of the eight viewer adjustments it offers.
- Alerts. A record of each regression or scan-failure alert: the scan, the affected URLs and rule ids, and when it was emailed and read.
- Product-usage events. Shop domain, an event name from a fixed list (install, scan started, scan finished, fix previewed, fix applied, fix reverted, alt item accepted, report generated, statement published, plan changed and similar) and a timestamp — no personal data, used only to see which steps merchants get stuck on. There is no third-party analytics service.
- Job queue. Queued work items for a scan or an alt job: the job type and the identifiers it needs (shop and scan or job id) until the job completes.
- Operational logs. Error and warning traces from the app's own process: the identifiers a job needs (shop domain, scan id, error text) written to the container's rotating log buffer. No Shopify token, no storefront password, no page body and no OpenAI request or response body is written to a log. The web server in front of the app keeps no access logs, and no IP address or user agent is written to the database.
- Support correspondence. If you email us, we keep the message and our reply.
Where any of this is personal data, it is the personal data of you — the merchant and your staff — not of your customers.
3. What the app sends to OpenAI
To write alt text for a product image, the app sends that image and the app's own prompt to
OpenAI (vision model gpt-5.4-mini) and receives a generated
string. Only product images are sent, only for the alt-text queue, and only the generated
string and an error string are kept — never the request or response body.
No merchant personal data and no customer personal data is sent to OpenAI. The prompt is the app's own; the app uses its own OpenAI key, which belongs to the operator, and you are never asked to paste an AI provider key. If the provider errors or returns empty text, the item is marked failed, the monthly allowance is not consumed, and the job continues.
4. What we never store
- Your customers' names, email addresses, postal addresses, phone numbers or customer ids.
- Order, checkout or payment data — the app requests no
read_ordersscope and no protected customer data. - A shopper's IP address, user agent or per-shopper widget usage; the app has no shopper identifier and no such column.
- The full HTML of your pages or of your storefront's DOM. A finding keeps at most a 400-character snippet.
- Screenshots of your pages.
- OpenAI request or response bodies, beyond the generated alt string and an error string.
- Your Shopify token or an entered storefront password in any log line or error message.
Shopify sends every public app the two mandatory customer-privacy webhooks
(customers/data_request and customers/redact). Capyo acknowledges
them; because it holds no customer personal data, there is nothing to return and nothing to
erase for them.
5. What the storefront does (the widget and the embed)
Nothing renders on your storefront until you enable the app embed in your theme editor. Once enabled, the embed loads one deferred script and one stylesheet, reads its configuration, and does three things: applies the fixes you have set to live, renders the widget if it is on, and appends the statement link to the footer if that setting is on. It never writes to your theme code, and it never loads a third-party overlay script.
The widget stores shopper preferences in localStorage only.
The eight viewer adjustments — text size, line and letter spacing, high contrast, highlighted
links, a readable font, paused animation, hidden images and a reading guide — are kept in the
shopper's own browser under the app's key. There is no cookie, no beacon, no shopper
identifier and no third-party script: nothing about an individual shopper leaves the
page, and no shopper-level record is written anywhere. A reset in the widget clears those
values.
A fix that is only in preview mode is applied solely to requests carrying the preview token you generated; a visitor without the token receives the unchanged page.
6. The free "Barrierefreiheit Check" tool
The Capyo website offers a free single-page check. It needs one thing: a store domain. The scan itself runs on the app's own server against the scanned page's public HTML, and the result is cached by normalized URL for 24 hours; beyond that cache row, no email, IP address or URL of a scan is stored.
If you choose to unlock the detailed result, you submit an email address and the checked
domain. Those are stored in a Cloudflare Worker KV lead record, keyed by a
sha256 hash of the lowercased, trimmed email address, and are
deleted after 12 months. That lead record is the only place the free tool
stores an email; it is not used for marketing lists and it is not passed to anyone else.
7. This website
This site is a set of static pages. It sets no cookies, runs no analytics, and contains no tracking pixels, no advertising tags and no embedded third-party content. The typeface is self-hosted rather than loaded from a font CDN. The host of these pages processes the ordinary request data any web server sees, including your IP address, to deliver them.
8. Why we process it, and on what legal basis
- To provide the app you installed — running scans, computing findings and scores, applying the fixes you enable, generating and writing alt text you accept, creating reports and the statement, and sending regression alerts. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
- To generate alt text, by sending a product image to OpenAI and receiving a string you approve before it is used. Legal basis: Art. 6(1)(b) GDPR.
- To bill you through Shopify's Managed Pricing. We read which plan is active; Shopify performs the billing. Legal basis: Art. 6(1)(b) GDPR.
- To keep the service secure and working — queue handling, provider health, error handling, abuse prevention, and the usage events that show which steps fail. Legal basis: legitimate interests, Art. 6(1)(f) GDPR.
- To store a free-tool lead, only when you submit an email to unlock a result. Legal basis: your consent, Art. 6(1)(a) GDPR, which you can withdraw at any time.
- To answer support requests. Legal basis: Art. 6(1)(b) and (f) GDPR.
- To meet legal obligations, including Shopify's mandatory compliance webhooks. Legal basis: Art. 6(1)(c) GDPR.
We do not use your data for our own advertising, we do not profile you, we do not train models on it, and we never sell or rent it.
9. How long we keep it
- Sessions and queued jobs: deleted immediately when Shopify sends the
app/uninstalledwebhook, and scheduled jobs for your shop are cancelled. - Preview tokens: deleted within 24 hours, or when used.
- Public-scan cache: 24 hours, keyed by normalized URL.
- Scans, scan pages and findings: kept for 12 months on Premium and 3 months on the other plans.
- Reports and statements: kept until uninstall and the deletion in section 11 completes — the Prüfbericht is a record, so it is immutable and a later scan adds a new one rather than overwriting it.
- Usage events: 12 months.
- Free-tool leads (Worker KV): 12 months, then deleted.
- Everything else about your shop — store record, page set, fix states, alt
jobs and items, widget settings, alerts and job rows: deleted when Shopify sends the
shop/redactwebhook, 48 hours after uninstall, which deletes every row for the shop in every table. A reinstall inside those 48 hours cancels the scheduled deletion. Ask us to delete earlier and we will. - Operational logs: kept only for as long as the container's rotation retains them, then overwritten.
- Database backups: taken daily and rotated after 14 days, so a row deleted by uninstall or shop-redact can remain inside a backup until that rotation passes. Backups are used only for disaster recovery, are readable only by the server's root and database accounts, and are never used to restore a deleted shop's data on request.
- Support correspondence: kept up to 24 months, deleted sooner on request.
10. Who else is involved (sub-processors)
| Sub-processor | Company country | What they do | Where the servers are |
|---|---|---|---|
| Shopify International Ltd | Ireland | The platform the app runs on and the source of all store data; also handles billing | Per Shopify's own DPA |
| OpenAI | United States | Writes alt text: receives a product image and the app's prompt and returns a generated string. Product images only — no merchant personal data and no customer personal data | Per OpenAI's own terms |
| Cloudflare, Inc. | United States | Runs the free "Barrierefreiheit Check" Worker, including the KV store that holds the lead record (email hash and checked domain) for 12 months | Cloudflare global network |
| Hostinger International Ltd | Cyprus | Application hosting — the virtual server the app runs on, including its PostgreSQL connection | Boston, Massachusetts, United States |
| netcup GmbH | Germany | Database hosting — the PostgreSQL database holding everything in section 2 | Manassas, Virginia, United States |
| GitHub, Inc. | United States | Hosting of this website only — no app data reaches it | GitHub Pages global infrastructure |
There is no analytics provider, no error-tracking SaaS, no advertising network, no email marketing tool and no CRM in this list. We will update this table before any new sub-processor starts processing.
11. International transfers
Merchant data processed through the app is stored on servers located in the United States — the application server in Boston, Massachusetts and the PostgreSQL database in Manassas, Virginia. Both are operated for us by European companies (Hostinger International Ltd, Cyprus; netcup GmbH, Germany), but the processing itself happens outside the EEA, which engages Chapter V of the GDPR. The product images sent to OpenAI for alt text, and the free-tool lead record held by Cloudflare, are likewise processed by United States-based providers.
For those transfers we rely on the Standard Contractual Clauses included in those providers' data processing terms, together with the technical and organisational security measures in section 12. The app stores no end-customer personal data, so nothing about your shoppers crosses a border. What does is the store configuration, page set, scan and finding data, fix states, alt jobs and items, reports, statement fields and access token described in section 2, plus the product images described in section 3.
Hosting locations can change; any change of hosting location or sub-processor is announced on this page before it takes effect. Shopify may transfer data internationally under its own DPA and transfer mechanisms, which govern the Shopify-to-merchant relationship independently of this policy.
12. Security
- All traffic to the app and to this website is served over HTTPS/TLS. There is no plaintext endpoint.
- The database is not exposed to the public internet: its firewall accepts PostgreSQL connections only from the application server's IP address, over an encrypted connection with password authentication.
- Shopify access tokens are stored in that database and are never written to logs or shown in the UI.
- A storefront password you enter for scanning is stored in that database, never logged, and used only to reach your own storefront.
- Administrative access to the server and the database is limited to the operator, over SSH with key authentication.
- Webhook requests from Shopify are verified by HMAC signature before anything is acted on.
- Every app-proxy request is verified by Shopify's proxy signature before it is served.
- Every embedded route verifies the Shopify session token, and every gated action is checked on the server, not only in the UI.
-
The app requests the minimum Shopify scopes it needs:
read_products,write_products,write_files,read_themesandread_content. It requests noread_ordersscope, noread_customersscope and no protected customer data. - The OpenAI key belongs to the operator, is held as a server environment secret, and is never requested from or shown to merchants.
We claim no formal security standard (no ISO 27001, no SOC 2) and we do not claim encryption at rest beyond what the hosting providers apply to their own storage.
13. Protected customer data
Capyo requests no Shopify protected customer data. Its scopes are
read_products, write_products, write_files,
read_themes and read_content. It never receives customer names,
emails, phone numbers or addresses, and it processes no order data. A future feature that
needed protected customer data would only follow a separate Shopify approval and a change to
this policy before it started.
14. Your rights
Under the GDPR you can ask us to:
- confirm what we hold about you and give you a copy (access, Art. 15);
- correct anything inaccurate (rectification, Art. 16);
- delete it (erasure, Art. 17);
- restrict what we do with it (Art. 18);
- hand it over in a machine-readable form, or send it to another provider (portability, Art. 20);
- stop processing based on legitimate interests or consent (objection and withdrawal, Art. 21 and Art. 7(3)).
Email gimbernat13@gmail.com and we will answer within one month. You do not need to justify a request. Uninstalling the app starts the deletion described in section 9. Where a request concerns data the app holds on your instruction as controller — for example alt text already written to your own product media in Shopify — we forward it to you and support you in answering rather than answering on your behalf; that split is set out in the Data Processing Agreement.
You can also complain to a data-protection supervisory authority — normally the one where you live, work, or where you believe the problem occurred.
15. Changes to this policy
When this policy changes, the new version appears on this page with a new date at the top. The version in force is the one published here.
16. Contact
gimbernat13@gmail.com — data-protection requests, security reports and everything else. See also our Terms of Service and the Data Processing Agreement.