AllyFix

Privacy Policy

Last updated: September 20, 2026

This Privacy Policy explains how AllyFix (“we”, “us”, “our”) collects, uses, and protects information when you install and use the AllyFix app (the “App”) on your Shopify store. By installing the App, you agree to the practices described here.

In short: AllyFix reads your store’s products, images, and public storefront to find and fix accessibility issues. We do not collect, store, or sell your customers’ personal data. We are not in the business of advertising or data brokering.

1. Information we access

To do its job, the App accesses the following data from your Shopify store through Shopify’s official Admin API, using the permissions you approve at install:

2. Information we do NOT collect

AllyFix does not access, request, or store your customers’ personal information — no names, emails, addresses, orders, or payment details. The App requests no customer-data permissions. Payment for the subscription is handled by Shopify; we never see or store your card or billing details.

3. How we use the information

4. AI processing of images

To generate alternative text, AllyFix sends the URL of a product image to a third-party AI vision provider (currently OpenAI) which returns a text description of what the image shows. Only product image URLs are sent for this purpose; no customer personal data is included. These providers act as our subprocessors and process the data solely to return the description to us.

5. Sharing and disclosure

We do not sell or rent any data. We share information only with:

6. Data retention

We keep the minimum data needed to run the App: your store domain, access token, and subscription status, retained while the App is installed. Accessibility scan results are generated on demand and are not retained as permanent records. When you uninstall the App, or upon request, we delete the store credentials associated with your store.

7. GDPR / CCPA compliance

AllyFix supports Shopify’s mandatory data-protection webhooks. Because we do not store customer personal data, requests to export or erase customer data (customers/data_request, customers/redact) return no personal data, and store-erasure requests (shop/redact) remove any store credentials we hold. If you are in the EEA, UK, or California, you have the right to access, correct, or delete data we hold about your store; contact us using the details below.

8. Data security

The App is served over encrypted HTTPS connections. Access tokens are stored on our server and used only to communicate with your store’s Shopify Admin API. We apply reasonable technical and organizational measures to protect data against unauthorized access.

9. Cookies

The embedded App uses only the session mechanisms required by Shopify to load securely inside your Shopify admin. Our marketing website (allyfix.shop) does not use tracking or advertising cookies.

10. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be reflected on this page.

11. Contact us

If you have questions about this Privacy Policy or your data, contact us at support@allyfix.shop.