ADA Monitor

Trust

Privacy policy.

This policy covers both the ADA Monitor Shopify app and this website. If you're a merchant evaluating the app, the section on what we access from your store is the one that matters.

last updated: august 2026

Who we are

ADA Monitor is an accessibility monitoring and remediation app for Shopify storefronts, built by Allure Commerce. For the app, we act as a data processor on behalf of the merchant, who remains the controller of their store's data. For this website, we are the controller.

Privacy contact: privacy@adamonitor.ai.

What the app never accesses

Start here, because it rules out most of what merchants worry about. ADA Monitor does not request, receive, or store:

  • Customer records — no names, emails, addresses, or phone numbers of your shoppers.
  • Orders, carts, or checkout data.
  • Payment or card details. Billing runs through Shopify; we never see a payment instrument.
  • Shopify admin credentials. Access is granted by you through Shopify's OAuth screen and is revocable from your admin at any time.

These are not policy promises we could quietly break — the app does not request the Shopify permissions that would make them possible. You can confirm this on the install screen before you approve anything.

What the app does access, and why

ADA Monitor requests only the permissions its job requires:

PermissionWhy we need it
Read and write themesTo find accessibility issues in theme code, and to prepare fixes in an unpublished copy of your theme for your approval
Read and write productsTo detect and correct product-level accessibility problems, such as missing image alt text
Read and write filesTo read media referenced by your storefront and update associated alt text
Read content and online store pagesTo scan pages, blog posts, and navigation for accessibility issues

Scanning reads the public pages of your storefront — the same pages any visitor or search engine can already load.

What we store

  • Store identifiers — your myshopify domain, primary domain, Shopify store ID, plan, and install date.
  • An access token issued by Shopify when you approve the install, used to call the Shopify API on your behalf.
  • Scan results — the URLs scanned, the accessibility issues found, and the page markup fragments that evidence each issue.
  • Remediation records — proposed changes, the exact diffs, who approved them, when they were published, and the verification result.
  • Settings and audit history — your configured approval rules, and a log of actions taken in the app.
  • Dashboard sessions for staff who sign in.
  • Optional integration credentials — if you connect GitHub or Jira, those tokens are stored encrypted.

Incidental personal data. Because we read theme and content markup, a scan may capture personal information that appears in your published storefront — a blog post author's name, a staff email in a page footer, contact details in your theme. We don't seek this out, isolate it, or use it for anything; it is retained only as part of the evidence for a finding, and it is deleted when the store's data is deleted.

What we do with it

We process store data only to provide the service: to scan your storefront, identify accessibility issues, prepare and verify fixes you approve, and maintain the record of what was done. We also use aggregate, non-identifying operational data to monitor and improve the product.

We do not sell, rent, or trade merchant data. We do not use it to build advertising profiles. We do not use your store's content to train third-party AI models.

Where data is stored

Application data is stored in the United States. Data is transmitted over TLS. Where transfers from the UK or EEA require it, we rely on Standard Contractual Clauses or an equivalent lawful mechanism.

Subprocessors

SubprocessorPurposeLocation
Amazon Web ServicesHosting for this website and its request logsUnited States
RenderHosting and database for the Shopify appUnited States
GoogleDelivering website enquiry emails to our teamUnited States
Allure CommerceOur own team, who operate and support the product—

We'll update this list before adding a subprocessor that handles merchant data.

How long we keep it

  • While the app is installed — scan history, remediation records, and audit history are retained so the record stays continuous, which is the point of the product.
  • After you uninstall — we delete your store's data within 30 days of receiving Shopify's shop redaction request, or of a direct request from you.
  • Website enquiries — up to 24 months from your last contact, then deleted.
  • Server logs — a short operational period, then rotated.

Deletion and data requests

ADA Monitor supports Shopify's mandatory data-privacy requests. When Shopify sends a customer data request, customer redaction request, or shop redaction request, we act on it within 30 days.

Because the app holds no customer records, a customer data or redaction request will typically return or affect nothing — there is no shopper data for us to return or erase. Shop redaction removes your store's scan history, remediation records, settings, and access token.

You can also ask us directly at privacy@adamonitor.ai at any time, whether or not you've uninstalled.

Security

  • Data is transmitted over TLS.
  • Access to the app is scoped per store; a merchant's session can reach only that merchant's data.
  • Optional integration credentials (GitHub, Jira) are encrypted at rest.
  • Actions taken in the app are recorded in an audit log.
  • Staff access to production data is limited to those who need it for support and operations.

No system is perfectly secure. If a breach affects your data, we'll notify you and the relevant authorities as required by law.

This website

Separately from the app, this marketing site collects very little:

  • It sets no cookies. Not one, on any page — which is why you've never seen a cookie banner here. You can confirm it in your browser's developer tools.
  • It loads no third-party scripts. No advertising pixels, no session recording, no heatmaps, no social widgets. The only JavaScript here is ours, and fonts are served from this domain.
  • No analytics product is currently running. If we enable one it will be cookieless, and this page will name it before it goes live.
  • Server logs record standard request information — IP, timestamp, page, user agent — to serve pages and defend against abuse.
  • Campaign attribution is held in your browser's sessionStorage. That is not a cookie: it's first-party, never sent to another site, carries no cross-site identifier, and is discarded when you close the tab.

Two forms collect information: Start a trial (your myshopify domain and work email) and Talk to a specialist (storefront URL, work email, role, and your message). Each carries the campaign attribution above. We use it to reply to you. We won't add you to a sequence you didn't ask for.

We never ask for your Shopify admin credentials on this website. No page here will request a password, an API key, or payment details. Treat any message claiming to be us and doing so as fraudulent.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or export the information we hold about you, to object to or restrict how we use it, and to complain to your data protection authority.

If you're a merchant, you may also have obligations to your own customers as the controller of your store's data; we'll support you in meeting them.

Ask and we'll act. We won't make you justify wanting your own data back, we won't charge you, and we won't treat you differently for asking. Email privacy@adamonitor.ai and we'll respond within 30 days.

Children

This is a business product. It isn't directed at children, and we don't knowingly collect information from anyone under 16.

Changes

If we change how we handle your information, we'll update this page and move the date at the top. Material changes will be called out rather than quietly folded in, and we'll notify merchants of changes that affect the app.

Contact

Privacy questions and data requests: privacy@adamonitor.ai. Anything else: the contact form.