Last updated 1 September 2026
This policy covers both this website and the Shopify app it describes. It is written to be read, not to be survived. If anything here is unclear, ask us and we will fix the wording.
We never see your customers. The app requests only these Shopify
permissions: read_themes, read_products,
write_products, write_content. We hold read-only access to your
theme — we can look at it, we cannot change it. Orders, customers, and payment data require
different permissions that we do not request and therefore cannot access — not by policy, but by
what Shopify will hand us.
Everything we scan comes from pages that are already public on your storefront, plus your theme settings and product data. We store what is needed to show you the report, apply a fix you approved, and let you roll it back.
The page you are reading loads nothing from any other domain — no fonts, no images, no scripts — and sets no cookies and no analytics. It makes zero third-party requests. The only file it fetches is our own stylesheet, served from this same domain. You can verify that in your browser's network panel, and the Content-Security-Policy header we send blocks them at the browser level regardless.
This site collects nothing at all. There is no form, no sign-up, and no way for us to learn who you are from reading it. Scanning happens inside the Shopify app, on a store you have installed it on — so we never scan a shop on someone else's say-so, and we never need to ask you for an email address here.
If you write to us at the address at the bottom of this policy, we obviously have your email — that is an ordinary email conversation, and we keep it only as long as the conversation is useful.
When you install the app, we store the following.
| What | Why we need it |
|---|---|
| Store domain and Shopify access token | To call Shopify's API on your behalf. The token is what authorises every request we make. |
| Your Shopify staff account details — name, email, locale, whether you are the account owner | Shopify includes these in the session it issues. We use the locale to generate alt text in your store's language. |
| Theme name and ID | To identify which theme a scan applies to, and to read its colour settings so we can tell you which one to change. |
| Scan results — page URLs, CSS selectors, short HTML fragments, computed colours, font sizes and weights | These are the findings. The fragments are what let us point at the exact element and generate an accurate fix. They come from pages already public on your storefront. |
| Product titles, variant titles, and image alt text | To find images missing alt text and to compose replacements from information you already entered. |
| Theme setting values before and after any fix you apply | So every change can be rolled back. Without the previous value, "undo" is not possible. |
Scanning is read-only. We do not modify your theme, and we do not create copies of it. For colour and layout problems we tell you which theme setting to change and to what, and link you to that field — you make the change yourself in Shopify's theme editor.
The only things we ever write are product image alt text and the accessibility statement page, and only when you click the button that does it. Both record their previous value first, so either can be rolled back.
You do not have to wait for any of this. Email us and we will delete your data on request.
That is the complete list. We do not use advertising networks, data brokers, or analytics vendors, and we do not sell data to anyone under any circumstances.
If you are in the EU or UK, the GDPR gives you the right to access, correct, export, or delete your personal data, and to object to how it is processed. California residents have comparable rights under the CCPA. We extend these to everyone regardless of where you live, because operating two standards is more work than operating one.
To exercise any of them, email us. We will respond within 30 days, and normally much sooner.
Data is transmitted over HTTPS and stored on servers we control. Access tokens are the most sensitive thing we hold; they are stored to make API calls and deleted the moment you uninstall.
We will not pretend to hold certifications we do not have. This is a small independent project, not an enterprise vendor with a SOC 2 report. What we can promise is a short data inventory — everything we store is listed in the table above — and prompt deletion when you ask.
This is a business tool sold to merchants. It is not directed at children and we do not knowingly collect data from anyone under 16.
If we change this policy in a way that affects what we collect or who we share it with, we will email active users before the change takes effect. The date at the top always reflects the current version.
Questions, deletion requests, or anything else: hello@maycomayco.com