Privacy
Privacy policy
Policy version 2026-07-31. Operated by Access Ledger, a sole proprietorship in Michigan, USA. This policy describes what the software actually does, checked against the code rather than written from a template.
We are not lawyers and this is not legal advice. This policy was written by the person who wrote the software, from the software. It has not been reviewed by a solicitor. If you are relying on it for your own compliance position, get your own advice.
Who we are
Access Ledger is the controller for the personal data described here. Write to [email protected] about anything on this page. Our postal address appears in the footer of every commercial email we send, as US law requires, and we will give it to you on request.
When we scan your website on your instruction, the relationship is different: you are the controller of anything personal that appears on your own pages and we are your processor. That is covered by the data processing addendum.
What we collect, and on what lawful basis
Every use has to have a lawful basis under Article 6 of the GDPR and UK GDPR. Here is ours, purpose by purpose, rather than one vague sentence covering everything.
| What we do | What that needs | Lawful basis |
|---|---|---|
| Run your account and the scanning service | Your email address, a scrypt hash of your password, the sites you add, your scan results and your issue history. | Contract. GDPR Art. 6(1)(b). We cannot provide the thing you are paying for without it. |
| Take payment | Your email address and billing details, entered on Stripe pages. Card numbers never reach our servers. | Contract to take the payment, and legal obligation (Art. 6(1)(c)) to keep the record afterwards. |
| Run a free scan you asked for and email you the findings | The URL you typed, your email address, and the result. | Consent for the scan you requested, GDPR Art. 6(1)(a). One report, because you asked for one report. |
| Stop one person hammering the free scanner | A one-way hash of your IP address. We never store the address itself. | Legitimate interest, Art. 6(1)(f), in keeping a free service available and not being used as an attack tool. |
| Keep you signed in and protect forms | A session cookie holding a random token, and a hash of the IP the session started from. | Legitimate interest in account security, and contract for the sign-in itself. |
| Count page views with Google Analytics | A random identifier in a cookie set by Google, the pages you view here, and your IP address as Google receives it. | Consent, Art. 6(1)(a), and in the EU, EEA, UK and Switzerland nothing is loaded until you have given it. Elsewhere it runs on an opt-out basis and an opt-out is honoured everywhere. |
| Send occasional accessibility guidance | Your email address, only if you ticked the box. | Consent, Art. 6(1)(a). Withdrawable in one click, and we record the withdrawal. |
| Answer support requests | The address you wrote from and what you told us. | Contract for service questions. Legal obligation for a data rights request, because we have to be able to prove we handled it. |
| Keep the service working | Error diagnostics, which can incidentally include an email address. | Legitimate interest in a service that does not silently break. |
| Prove that consent was given | When consent was given or withdrawn, from where, the wording agreed to, and an IP hash. | Legal obligation. GDPR Art. 7(1) requires us to be able to demonstrate it. |
What we do not do
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising. In CCPA and CPRA terms, we neither sell nor share.
- We run no advertising or remarketing trackers. We use one analytics tool, Google Analytics, and it is described in full below and on the cookies page.
- We do not put you on a mailing list for running a scan. You asked for a report, so you get a report.
- We make no automated decision that produces a legal or similarly significant effect about you. There is no profiling and no scoring of people.
- We do not seek personal data from the pages we scan. Findings can quote a fragment of your own public HTML, which is why the processing addendum exists.
Cookies
This site sets two strictly necessary cookies: one keeps a customer signed in, one keeps an administrator signed in. Both are httpOnly, both are SameSite=Lax, and neither is readable by script. The CSRF protection on our forms is derived from the session token itself, so there is no separate cookie for it. Strictly necessary storage is exempt from the consent requirement in Article 5(3) of the EU ePrivacy Directive and the UK PECR that implements it, so we do not ask you about those and are not required to.
A third cookie, al_consent, records your answer to the analytics question as
analytics=1 or analytics=0. It holds no identifier. It is readable
by script on purpose, because the loader in your browser re-checks it before running
anything, and a choice the page cannot read is a choice the page cannot honour.
Google Analytics sets its own cookies, _ga and _ga_<id>, and
only once analytics is actually running for you. There is a consent banner, and it is
there because analytics is here. Only the analytics category is gated by it. The full
cookie-by-cookie breakdown is on the cookies and tracking page.
Analytics
We use Google Analytics 4 to count page views and see which pages get read. That is the whole purpose. We do not use it to build a profile of you, we do not enable its advertising features or Google Signals, and it is not linked to any advertising account.
Where it is running, Google receives the address and title of the page you are looking at, a random identifier stored in a cookie, and your IP address as Google receives it. Inside an account that means Google sees the URL of the page. It does not receive your scan results, your issue history or any other account content, because none of that is passed to it.
In the EU, the EEA, the UK and Switzerland, and wherever we cannot tell where you are, nothing analytics-related loads until you have opted in. No script is fetched, no cookie is set, and no request reaches Google. Loading a tag first and asking afterwards is already a breach and we do not do it.
Elsewhere, including the United States and Canada, the ordinary legal position is opt-out, so analytics runs and you can switch it off at any time at /consent. Once you switch it off we honour that everywhere, whatever the law where you are would have allowed.
Google Analytics data is processed by Google on its own infrastructure, which includes servers in the United States, so this is an onward international transfer as well as an analytics question.
Said plainly because you should hear it from us: between 2022 and 2023, data protection authorities in Austria, France, Italy and Denmark all found particular uses of Google Analytics unlawful, largely on transfer grounds. The EU-US Data Privacy Framework has changed the picture since, and Google now offers EU-based collection and IP handling controls, but the question remains contested and the Framework is itself under legal challenge. That is exactly why we gate it behind consent rather than treating it as background furniture. If you would rather not be counted, decline: the site works identically.
If we ever add advertising
No advertising or remarketing pixel runs here today. If one is ever introduced:
- It will be described here and listed as its own category on the cookies page, with the date it was switched on.
- In the EU and UK nothing will be stored on or read from your device until you have said yes, exactly as with analytics.
- Withdrawing will be one press, exactly as easy as agreeing, and recorded the same way.
- It would amount to
sharing
under the California CPRA, so aDo Not Sell or Share My Personal Information
link would go up before it went live rather than after.
This section is a description of how we would do it, not your permission for us to do it. Nothing of this kind runs today.
Who else receives your data
These are the only companies involved, and what each one gets.
| Company | What for | What it receives | Where |
|---|---|---|---|
| Stripe, Inc. | Payments and subscription billing | Your email address, billing details and card data, entered on Stripe pages. Stripe also keeps its own billing record as an independent controller. | United States |
| Mailgun Technologies, Inc. | Sending email | Your email address and the contents of the messages we send you, including scan reports. | United States |
| Google LLC | Website analytics, Google Analytics 4 | Only once analytics is running for you: your IP address as Google receives it, the pages you view here, and a random identifier in a cookie. If you have declined, or have not yet answered where an answer is required, Google receives nothing and no request is made. | United States, and Google infrastructure worldwide |
| Cloudflare, Inc. | DNS, CDN and TLS at the edge | Your IP address, the pages you request and connection metadata, as any network in front of a website does. | Global edge network, US operator |
| InterServer, Inc. | The server the application and database run on | Everything in this policy, because the database sits on their hardware. | United States |
We will tell business customers by email before adding or replacing a sub-processor. Nobody else gets your data unless the law compels us, and if we are compelled we will tell you unless we are forbidden from doing so.
International transfers
Our servers are in the United States. If you are in the EU, the EEA, the UK or Switzerland, your data crosses a border the moment it reaches us, and it stays there. There is no EU-hosted option and we are not going to imply that there is.
Google Analytics is a further transfer on top of that, to Google infrastructure that includes the United States. It only happens if analytics is running for you, and in the EU, EEA, UK and Switzerland that means only if you opted in. Decline and there is no transfer to Google at all.
For business customers who need one, we offer Standard Contractual Clauses with the UK International Data Transfer Addendum where UK data is involved. Ask and we will sign them.
Where we stand, in our own words. We have not appointed a representative in the EU or UK under Article 27. A US business serving people in those territories is generally expected to have one unless the processing is occasional and low risk, and we will appoint one in each territory before taking a recurring EU or UK customer rather than after. A transfer impact assessment has been written and is with a solicitor for review; until that review is finished we are calling it a draft rather than pretending otherwise. Business customers who need to see it can ask, and we will send it as it stands, marked as a draft.
How long we keep things
These periods are enforced by a scheduled job, not by intention.
| What | How long | Why |
|---|---|---|
| Free scan results, including the address typed in and the IP hash | 90 days, then deleted automatically | Long enough to answer a question about a report, short enough that we are not sitting on a pile of strangers' data. |
| Per-scan element detail on a paid account | 120 days | Bulky. The dated history of what was found and fixed is what we keep, and that is kept in full. |
| Account data, sites, scans and the issue ledger | For the life of the account | The dated history is the thing you are paying for. Deleting it would be deleting the product. |
| Generated PDF report files | 365 days for the file; the entry stays with the account | Disk is finite. The record that a report was issued is small; the file is not. |
| Sessions | 30 days for customers, 7 for administrators, pruned once expired | A session that never expires is a stolen session that never expires. |
| Marketing subscription and consent records | Until you withdraw or ask for erasure | We have to be able to demonstrate that consent was given, which means keeping the record of it. |
| Payment records | Kept for the period tax and accounting law requires, which outlives the account | Legal obligation. See the erasure section: this is the one thing erasure does not remove. |
| Resolved error diagnostics | 30 days after being marked resolved | Nothing useful in an old fixed bug. |
Your rights, and the buttons that exercise them
Wherever you live, you can see what we hold, get a copy, correct it, and have it erased. In the UK, EU and EEA those are your rights of access, rectification, erasure, restriction, portability and objection under the GDPR and UK GDPR. In California they are your rights to know, delete, correct, and opt out under the CCPA as amended by the CPRA. In Canada they are your rights of access and correction under PIPEDA.
| Right | How | How long we take |
|---|---|---|
| See what we hold | /account/data, signed in. Counted live from the database. | Immediate |
| Get a machine-readable copy | /privacy/export, signed in. A JSON file. | Immediate |
| Erasure or deletion | The button on /account/data, or the support form if you have no account. | Within 30 days, which is inside the CCPA's 45 |
| Correct something wrong | Write to [email protected] or use the support form. | Within 30 days |
| Stop marketing email | The unsubscribe link in any marketing message, no sign-in needed, or the control on /account/data. | Immediate |
| Turn analytics on or off | /consent. No sign-in needed, one press, and declining is exactly as easy as accepting. | Immediate |
| Object, or ask us to restrict a use | Write to [email protected] and say which use. | Within 30 days |
| Opt out of sale or sharing | We do not sell, and we do not share for cross-context behavioural advertising, so there is no such link. Analytics without advertising features is not a sale or a share, and you can switch it off anyway at /consent. | Not applicable |
Exercising any of these costs nothing and we will not treat you differently for it, which the CCPA calls non-discrimination. You may use an authorised agent; we will ask for proof that you authorised them.
What erasure removes, and what it does not
Erasure is real and it is executed by a recorded process that writes down what was destroyed. It removes your account, your sites, your scans, your issue history, your report files, any free scans under your address, your marketing subscription and your consent records.
Payment records stay, and we will not pretend otherwise. Tax and accounting law requires a business to keep records of money it received. GDPR Article 17(3)(b) and CCPA section 1798.105(d)(8) both exempt data held to meet a legal obligation, which is exactly what this is. We sever the link to your account so the record survives without your name attached, but the record itself is kept. The same applies to any chargeback record, which we may need to establish or defend a legal claim under Article 17(3)(e).
Three smaller things also survive, and each for a reason. The shell of your erasure request stays, with your address masked and the message removed, so the fact that you asked and the fact that we acted remain provable. The log of marketing messages stays with your address replaced by a one-way token, which is how we can still prove nothing was sent without consent. And Stripe keeps its own copy of your billing history as an independent controller for its own anti-fraud and financial reporting; we cannot delete that for you, and you would need to approach Stripe directly.
One honest technical limitation: erasure runs against the live database. We do not operate an automated backup rotation, but a manual snapshot taken during a deployment could still contain a record until that snapshot is deleted.
Security
What is actually implemented:
- Traffic is encrypted in transit, twice: TLS at Cloudflare's edge, and TLS again between Cloudflare and our own server.
- Passwords are stored as scrypt hashes with a per-user salt. We never see a plaintext password.
- Session tokens are stored only as SHA-256 digests, so a database leak does not hand over live sessions.
- IP addresses are never stored, only hashed.
- Customer and administrator sessions live in separate tables, so a bug in customer sign-in has no path to producing an administrator.
- A strict Content-Security-Policy of
script-src 'self'means the browser refuses third-party script outright. It is widened, per request, only for a visitor who has consented to analytics, and only to Google's analytics hosts. Decline and you keep the strict policy. - Administrator actions require a CSRF token and are written to an append-only audit log.
- Card details never reach our servers.
What we do not claim: the database is not separately encrypted at rest beyond whatever the host applies, and there is no SOC 2 report, ISO 27001 certificate or penetration test.
Children
This is a business tool and it is not directed at children. We do not knowingly collect personal data from anyone under 16. There is no age verification step, so if you believe a child has given us data, tell us and we will erase it.
Complaints
Tell us first at [email protected] and we will try to put it right. You do not have to. In the UK you may complain to the Information Commissioner's Office. In the EU or EEA you may complain to the supervisory authority where you live, work, or where you think the problem happened. In Canada you may complain to the Office of the Privacy Commissioner. In California you may contact the California Privacy Protection Agency or the Attorney General.
Changes to this policy
The version number at the top changes whenever this page does. Consent records store the version that was in force when you gave them, so we can always tell what you actually agreed to. If a change materially affects how we use data you have already given us, we will tell account holders by email rather than quietly editing the page.
Contact
[email protected], or the support form. Business customers should also read the data processing addendum.