Barrierlist

Privacy policy

The short version

We scan pages that anyone on the internet can already open. We do not read your orders, your customers, or anything behind a login. We keep the results of those scans, the notes you write on them, and the record of what we sent you — and we delete all of it when you uninstall.

Who is responsible for this data

The data controller is the operator of Barrierlist, reachable at privacy@barrierlist.com. When you install Barrierlist on your Shopify store, you are the controller of your own store’s data and we act as your processor for the parts of it described below.

What we hold about your customers: nothing

This app has never asked for access to customer or order data. The one permission it requests from Shopify is read_themes, which it uses to know when you publish a theme so it can check the storefront again. The scan itself signs in to nothing: it loads your public pages the way a shopper’s browser would.

Shopify requires every app to answer three privacy requests. When Shopify asks us for a customer’s data, we have none to give. When Shopify tells us to erase a customer’s data, there is none to erase. We do not write down the identifiers in those requests — recording a shopper’s email address in order to answer a request to forget them would be absurd. We record only that a request arrived, for which shop, and on what date.

What we do hold, and why

Everything below is about the store and the person running it. Each entry says what it is and what it is for.

Why we are allowed to hold it

For everything that makes the app work — the scans, the reports, the history, the alerts — the basis is the contract between us: you installed an app to do this and it cannot do it otherwise. For the two dates described under retention, the basis is our legitimate interest in stopping one store from taking an unlimited number of free reports.

Who else sees it

Three, and no more. We do not sell data, we do not share it for advertising, and no analytics or tracking service runs inside this app.

All three keep this data inside the European Economic Area. Nothing in this app moves your data outside it.

How long we keep it

While the app is installed, the full report from each scan is kept for 12 months and then deleted. The record of the scan is not: what was checked, when, and what was found stays for as long as you have the app, and so do the notes you wrote and the accessibility record you can export. Nothing obliges us to keep the reports longer, and they hold fragments of your pages, so we do not.

The monitoring history follows the same rule. After 12 months, the address each message went to, its subject, and the notes we keep with each check are deleted. The record that a check ran or a message was sent — the date, what kind it was, and what it counted — stays for as long as you have the app, like the record of a scan.

When you uninstall, Shopify tells us twice: immediately, and again about 48 hours later with a request to erase your store’s data. On the first message we delete your access tokens. On the second we delete everything listed above — every scan, every report, every note, the statement, the monitoring history, the messages we sent, and the billing record.

If that second message never reaches us, a sweep deletes the same data for any store that uninstalled more than 45 days ago. Nothing waits on a webhook that may not arrive.

One thing is kept, and this is the whole of it: your store’s address and two dates — the day the store used its one free report, and the day it started its one trial. Those two dates are what stop a store from uninstalling and reinstalling to take the free report again. They are kept for 2 years after the uninstall, and then the last row goes too.

If you would rather we did not keep even that, write to privacy@barrierlist.com and we will remove it. Your store then has its free report available again.

Your rights

You can ask what we hold about your store, ask for a copy of it, ask us to correct it, ask us to delete it, and object to us holding it. Write to privacy@barrierlist.com. We answer within 30 days, and usually the same week.

You do not have to ask us for the scan data: the app exports the whole record itself, as a file you keep, from the Evidence screen.

If you think we have handled your data badly, you can raise it with your national data protection authority. We would rather you told us first, at privacy@barrierlist.com.

How it is protected

Everything travels over an encrypted connection. The database is not reachable from the internet. Access to the server is limited to the people who operate it, and the app requests no permission it does not use.

If data is exposed by a fault of ours, we tell the affected merchants and the relevant authority within 72 hours of finding out.

Cookies and tracking

The app sets no advertising or analytics cookies, and embeds no tracking pixel. Shopify’s own session handling is what keeps you signed in to your admin; that is Shopify’s, not ours.

Changes to this page

If these words change in a way that affects what we do with your data, the date at the top changes with them and the app says so on your next visit.

Contact

Privacy and data questions: privacy@barrierlist.com. Anything else: support@barrierlist.com.