EqualWeb PDF Accessibility - Privacy Policy
How the EqualWeb PDF Accessibility app for Shopify handles your store's data - what it accesses, what it never touches, and what happens when you uninstall.
What the app does
EqualWeb PDF Accessibility scans the document files in your Shopify store for accessibility issues (against PDF/UA) and, on request, remediates them into accessible versions. Checking is free; remediation is a paid EqualWeb service.
What data the app accesses
Using the read_files and write_files access scopes only:
- Store files you choose to check or remediate - PDF and, for remediation, Office documents (Word/PowerPoint/Excel) - including their file name, URL, and byte content.
- Your store's domain (the .myshopify.com identity), used to scope your settings and results.
What the app does NOT access
The app does not request or receive access to customers, orders, products, or any shopper (end-customer) personal data. The access scopes are limited to files.
How your data is processed
- To check or remediate a file, the app sends the file's bytes and name to the EqualWeb accessibility service (login.equalweb.com) through EqualWeb's secure cloud backend. Results (an accessibility score, a report link, and - for remediation - an accessible copy) are returned.
- For paid remediation, your personal EqualWeb API key is stored encrypted (AES-GCM) at rest in EqualWeb's backend and injected only on the server-side call to EqualWeb. It is never exposed to the app's browser interface or written to the app's own storage.
What the app stores, and where
In Cloudflare (KV + a per-store Durable Object), the app stores only:
- your store domain and a per-store access token to EqualWeb's backend;
- your app settings (remediation options);
- per-file accessibility state: scores, EqualWeb document/report identifiers, and your classification decisions.
The app does not store the document files themselves or copies of the accessibility reports (EqualWeb retains those; the app links out to them).
Sub-processors
- EqualWeb (accessibility checking/remediation) - receives file content for processing.
- Cloudflare (hosting + storage of the app's operational data described above).
Data retention and deletion
- EqualWeb retains processed files for a configurable period (the app's "auto-remove" setting).
- The app's per-store operational data is kept while the app is installed.
- On uninstall, the app purges all of your store's stored data (settings, per-file state, access token) via Shopify's shop/redact compliance flow (delivered ~48 hours after uninstall).
The mandatory Shopify compliance webhooks are implemented: customers/data_request, customers/redact, and shop/redact. Because the app holds no shopper personal data, the two customer webhooks have no personal data to return or erase; shop/redact performs the store purge.
Security
Personal EqualWeb API keys are encrypted at rest and never exposed to the browser. All data in transit uses HTTPS.
Changes
We may update this policy; the effective date above will change accordingly.
Contact
Questions about this policy or your data: info@equalweb.com.
See also: PDF Accessibility for Shopify · Setup guide · EqualWeb general Privacy Policy · EqualWeb Terms of Service