Privacy Policy

Last updated: November 3, 2025

1. Introduction

Welcome to ClearAccess ("we", "our", or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website accessibility scanning service ("Service").

By using ClearAccess, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this policy, please do not use our Service.

2. Information We Collect

2.1 Information You Provide

We collect information that you voluntarily provide when using our Service:

  • Account Information: Email address, password (encrypted), name (optional)
  • Billing Information: Payment details processed securely through Stripe (we do not store full credit card numbers)
  • Scan Data: Website URLs you scan and associated scan results
  • Communications: Messages you send us via email or contact forms
  • Preferences: Account settings and notification preferences

2.2 Automatically Collected Information

When you use our Service, we automatically collect certain information:

  • Usage Data: Pages visited, features used, time spent, click patterns
  • Device Information: IP address, browser type, operating system, device identifiers
  • Log Data: Access times, error logs, referring URLs
  • Cookies: Session cookies, authentication tokens, preference cookies

2.3 Scanned Website Data

When you scan a website, we temporarily access and analyze:

  • Public HTML, CSS, and JavaScript content
  • Page structure and accessibility features
  • Detected accessibility violations

Important: We only scan publicly accessible websites. We do not store the full HTML content of scanned pages—only the accessibility scan results (violations, scores, and metadata).

3. How We Use Your Information

We use the collected information for the following purposes:

  • Provide the Service: Process scans, generate reports, manage your account
  • Authenticate Users: Verify identity and maintain account security
  • Process Payments: Handle subscriptions and billing through Stripe
  • Improve the Service: Analyze usage patterns, fix bugs, develop new features
  • Communicate: Send scan results, account updates, service notifications
  • Customer Support: Respond to inquiries and troubleshoot issues
  • Security: Detect fraud, prevent abuse, enforce our Terms of Service
  • Legal Compliance: Comply with applicable laws and regulations
  • Analytics: Understand user behavior using anonymized, aggregated data

4. How We Share Your Information

We do not sell your personal information. We may share your information only in the following circumstances:

4.1 Service Providers

We share data with trusted third-party providers who help us operate the Service:

  • Stripe: Payment processing and billing management
  • Hosting Providers: Render (backend), Vercel (frontend)
  • Email Service: Transactional emails (account verification, password resets)
  • Analytics: Anonymized usage analytics (if applicable)

These providers are contractually obligated to protect your data and use it only for specified purposes.

4.2 Legal Requirements

We may disclose your information if required by law or in response to:

  • Valid legal requests (subpoenas, court orders)
  • Law enforcement investigations
  • Protection of our legal rights and safety
  • Prevention of fraud or security threats

4.3 Business Transfers

If ClearAccess is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change and provide choices regarding your data.

4.4 With Your Consent

We may share your information for other purposes with your explicit consent.

5. Data Retention

We retain your information for as long as necessary to provide the Service and comply with legal obligations:

  • Account Data: Retained until you delete your account
  • Scan Results: Retained until you delete them or close your account
  • Billing Records: Retained for 7 years for tax and accounting purposes
  • Logs and Analytics: Typically retained for 90 days

After the retention period, we securely delete or anonymize your data.

6. Your Privacy Rights

Depending on your location, you may have the following rights:

6.1 Rights for All Users

  • Access: Request a copy of your personal data
  • Correction: Update inaccurate or incomplete information
  • Deletion: Request deletion of your account and associated data
  • Export: Download your scan results and data
  • Opt-Out: Unsubscribe from marketing emails (account emails are required)

6.2 GDPR Rights (EU/EEA Users)

If you are located in the European Union or European Economic Area, you have additional rights:

  • Right to Restrict Processing: Limit how we use your data
  • Right to Object: Object to processing based on legitimate interests
  • Right to Data Portability: Receive data in a machine-readable format
  • Right to Withdraw Consent: Withdraw consent at any time (where applicable)
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

6.3 CCPA Rights (California Residents)

California residents have the right to:

  • Know what personal information is collected, used, shared, or sold
  • Delete personal information held by businesses
  • Opt-out of the sale of personal information (we do not sell data)
  • Non-discrimination for exercising CCPA rights

6.4 How to Exercise Your Rights

To exercise any of these rights, contact us at privacy@clearaccesses.com or through your account settings. We will respond within 30 days (or as required by applicable law).

7. Cookies and Tracking Technologies

We use cookies and similar technologies to provide and improve our Service:

7.1 Essential Cookies

  • Authentication: Keep you logged in
  • Security: Protect against CSRF attacks
  • Preferences: Remember your settings

These cookies are necessary for the Service to function and cannot be disabled.

7.2 Analytics Cookies (Optional)

With your consent, we may use analytics cookies to understand how you use our Service. You can opt-out via your browser settings or privacy tools.

7.3 Managing Cookies

You can control cookies through your browser settings. Note that disabling essential cookies may limit Service functionality.

8. Data Security

We implement industry-standard security measures to protect your information:

  • Encryption: All data transmitted via HTTPS/TLS
  • Password Protection: Passwords hashed using bcrypt
  • Access Controls: Restricted access to personal data
  • Secure Infrastructure: Hosted on reputable cloud providers
  • Regular Updates: Security patches applied promptly
  • Monitoring: Continuous security monitoring and logging

However, no method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

9. International Data Transfers

ClearAccess is operated from the United States. If you access our Service from outside the US, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.

By using the Service, you consent to the transfer of your information to countries that may have different data protection laws than your country of residence. We take steps to ensure your data receives adequate protection wherever it is processed.

10. Children's Privacy

Our Service is not intended for children under 13 years of age (or 16 in the EU). We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately at privacy@clearaccesses.com, and we will promptly delete it.

11. Third-Party Links

Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any information.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy on our website
  • Updating the "Last Updated" date
  • Sending email notification to registered users (for significant changes)

Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.

13. Do Not Track Signals

Some browsers support "Do Not Track" (DNT) signals. Currently, there is no universal standard for responding to DNT signals. We do not track users across third-party websites for advertising purposes.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

15. Data Protection Officer (EU)

For EU/EEA data protection inquiries, you may contact our Data Protection Officer at dpo@clearaccesses.com.