Legal

Privacy Policy

Last updated: December 25, 2025 | Version 1.0.0

1. Introduction

This Privacy Policy explains how WCAG Scanner ("we", "our", or "us") collects, uses, and protects your personal data when you use our accessibility testing service.

We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR), Austrian data protection laws, and other applicable privacy regulations.

2. Data Controller

The data controller responsible for your personal data is:

Company Name: [Your Company Name]
Address: [Your Address, Austria]
Email: [Your Contact Email]

Note: Please update the bracketed information with your actual company details before going live.

3. Data We Collect

3.1 Account Information

  • Email address (required for account creation and authentication)
  • Display name (optional)
  • Password (encrypted and securely stored)
  • Account creation date and last login

3.2 Accessibility Scan Data

  • URLs of websites you scan
  • Scan results (accessibility violations, compliance scores, affected elements)
  • Scan timestamps and history
  • Generated PDF reports

3.3 Payment Information (Future Implementation)

  • When we implement paid features, payment processing will be handled by Stripe
  • We do NOT store credit card details - Stripe securely processes all payment information
  • We store only: billing email, transaction IDs, and subscription status

3.4 Technical Data

  • IP address (for security and rate limiting)
  • Browser type and version
  • Device information (for responsive design optimization)
  • Usage analytics (only if you consent - see Cookie Policy section below)

4. Legal Basis for Processing (GDPR Article 6)

  • Contract Performance: Processing your email, password, and scan data is necessary to provide our accessibility testing service
  • Legitimate Interest: Security measures, rate limiting, and fraud prevention
  • Consent: Analytics cookies (optional - you can opt out)
  • Legal Obligation: Retaining transaction records for tax and accounting purposes

5. How We Use Your Data

  • To create and manage your account
  • To perform accessibility scans and generate reports
  • To store your scan history and allow you to download PDF reports
  • To process payments for premium features (when implemented)
  • To send essential service emails (password resets, security alerts)
  • To improve our service through analytics (only if you consent to analytics cookies)
  • To protect against fraud, abuse, and security threats

6. Cookie Policy

6.1 Essential Cookies (No Consent Required)

These cookies are strictly necessary for our service to function and cannot be disabled:

CookiePurposeDuration
sb-access-tokenAuthentication session1 hour
sb-refresh-tokenSession refresh30 days
stripe_*Payment processing (future)Session

6.2 Analytics Cookies (Consent Required)

With your consent, we may use analytics cookies to understand how users interact with our service:

  • Google Analytics (if implemented in the future)
  • Page views, session duration, navigation patterns
  • Device type, browser version, screen resolution
  • No personally identifiable information is shared with analytics providers

You can change your cookie preferences at any time in your account settings or by clicking the cookie preferences link in the footer.

7. Data Sharing and Third Parties

We do NOT sell your personal data. We share data only with trusted service providers necessary to operate our service:

  • Supabase: Database and authentication (US-based, GDPR compliant with Standard Contractual Clauses)
  • Stripe (future): Payment processing (EU servers available, PCI-DSS compliant)
  • Google Analytics (future, if enabled): Usage analytics (only with your consent)

All third-party processors are contractually bound to GDPR compliance and Standard Contractual Clauses (SCCs) for data transfers outside the EU.

8. Data Retention

  • Account data: Retained until you delete your account
  • Scan history: Retained for as long as you have an account
  • Payment records: Retained for 7 years for tax/accounting purposes (legal requirement)
  • Analytics data: Aggregated, anonymized after 26 months (Google Analytics default)
  • After account deletion: All personal data is permanently deleted within 30 days

9. Your Rights Under GDPR

As an EU/Austria resident, you have the following rights:

  • Right to Access: Request a copy of all personal data we hold about you
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure ("Right to be Forgotten"): Delete your account and all associated data (available in account settings)
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a machine-readable format (CSV/JSON)
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw analytics cookie consent at any time

To exercise these rights, please contact us at [your-email@example.com] or use the account settings in your dashboard.

10. Data Security

We implement industry-standard security measures:

  • All data transmitted over HTTPS/TLS encryption
  • Passwords hashed using bcrypt (industry standard)
  • Regular security audits and updates
  • Rate limiting to prevent brute-force attacks
  • Secure cookie settings (HttpOnly, Secure, SameSite)
  • Supabase Row Level Security (RLS) policies

11. Children's Privacy

Our service is not intended for children under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

12. International Data Transfers

Some of our service providers (e.g., Supabase) may process data outside the EU. All transfers are protected by:

  • EU Standard Contractual Clauses (SCCs)
  • GDPR-compliant Data Processing Agreements (DPAs)
  • Adequate security measures equivalent to EU standards

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email and/or a prominent notice in the application. Continued use after changes constitutes acceptance. If cookie consent requirements change, we will ask for renewed consent.

14. Supervisory Authority (Austria)

If you believe we have not handled your data properly, you have the right to lodge a complaint with the Austrian Data Protection Authority:

Österreichische Datenschutzbehörde
Wickenburggasse 8, 1080 Vienna, Austria
Email: dsb@dsb.gv.at
Website: www.dsb.gv.at

15. Contact Us

If you have questions about this Privacy Policy or how we handle your data:

Email: [your-privacy-email@example.com]
Response time: We aim to respond within 48 hours

This privacy policy is provided as a template. Before going live, please:
1. Update all bracketed [placeholder] information with your company details
2. Have it reviewed by a legal professional familiar with Austrian/EU law
3. Ensure it reflects your actual data practices