Last updated: March 2, 2026
Privacy Policy
1. Who we are
wcag-scan ("we", "us", "our") is an accessibility auditing service operated by its founders. Our website is wcag-scan.com. This policy explains what personal data we collect, how we use it, and your rights.
2. Data we collect
- Account data — name, email address, and authentication credentials managed by Clerk (our identity provider).
- Subscription data — billing details processed by Stripe. We do not store card numbers; Stripe handles payment data under their own PCI-compliant systems.
- Scan data — URLs you submit for scanning and the resulting accessibility reports. These are stored to power your dashboard history.
- Usage data — basic server logs (IP address, request timestamps) for security and rate-limiting purposes.
- Email address — if you request a report by email, your address is used to send that report via Resend.
3. How we use your data
- Providing and improving the wcag-scan service.
- Processing subscription payments and managing your account.
- Sending transactional emails (scan reports, receipts, account notices).
- Enforcing our rate limits and terms of service.
- Complying with legal obligations.
We do not sell your personal data to third parties.
4. Third-party processors
- Clerk — authentication and user management (Privacy Policy).
- Stripe — payment processing (Privacy Policy).
- Supabase — database hosting (Privacy Policy).
- Resend — transactional email (Privacy Policy).
5. Data retention
Scan history is retained for as long as your account is active. You may delete individual scans or clear all history from your dashboard at any time. Deleted scans are permanently purged within 14 days. If you close your account, your data is deleted within 14 days.
6. Cookies
We use only essential cookies required for authentication (managed by Clerk). We do not use advertising or tracking cookies.
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal data. To exercise these rights, contact us at privacy@wcag-scan.com.
8. Security
All data is transmitted over HTTPS. Database access is restricted to server-side processes only. We apply industry-standard security practices to protect your information.
9. Changes to this policy
We may update this policy from time to time. We will notify you of material changes via email or an in-app notice.
10. Contact
Questions about this policy? Email us at privacy@wcag-scan.com.