Privacy Policy — Ally Store Audit
Last updated: 2026-10-01
Ally Store Audit is made by Kodex, an independent developer. It comes in two forms that handle data differently: the website scanner at this address, and the Chrome extension. This page covers both.
Summary
- Website scanner: the page you ask us to check is fetched and analyzed on our server, not on your device. We don't save the page or the report, but our hosting provider's request logs record the address you scanned.
- Payments: handled by Stripe. We never see your full card number.
- Chrome extension: the analysis runs on your own device, and your pages and reports are never sent to us.
- Nothing is sold, shared for advertising, or used for profiling.
Website scanner (free scan and Pro audit)
When you enter a store address, your browser sends it to our server. The server then:
- downloads that page's public HTML, the same thing any visitor's browser receives (for the Pro audit, it also reads the store's
robots.txtand sitemap to find up to 100 pages); - runs the accessibility checks on that HTML;
- sends the results back to your browser.
We don't store the page content or the results. The report exists only in your browser tab and is gone when you close it, unless you download it as a PDF or CSV.
The store being scanned receives an ordinary request from our hosting provider's servers, identified as a11y-scanner/1.0. It does not receive your IP address.
The website checks only what is readable from a page's HTML code. It does not render pages, so it does not check color contrast or content added by scripts after the page loads.
Hosting logs
The website runs on Vercel. Like most hosts, Vercel keeps standard request logs: your IP address, the time, your browser type, and the address requested, which includes the store address you entered. These logs are kept under Vercel's own retention rules and are used only to run and debug the service. See Vercel's privacy policy.
Payments and subscriptions
Pro subscriptions are processed by Stripe. Stripe collects your email, card details and billing address on its own checkout page, under Stripe's privacy policy.
We receive from Stripe only what we need to run your subscription: your Stripe customer ID, email, plan and subscription status (for example, active, in trial or canceled). Our server records the customer and subscription IDs when Stripe notifies us of a change. You can update your card, see invoices or cancel at any time from the billing portal.
Embeddable badge
If a store adds our badge, its image is loaded from our server each time a page with the badge is viewed. Our host's logs then record that visitor's IP address and the page showing the badge, as with any image loaded from another site. The badge sets no cookies.
Cookies and analytics
The website sets no cookies of its own and uses no analytics or tracking scripts. If that changes, this policy will be updated first.
Your data
To ask what we hold about you, or to have it deleted, email us at the address below. Billing records that Stripe must keep for legal reasons are managed by Stripe.
Chrome extension
What the extension processes
When you start a scan, the extension reads the URL, the title and the content and structure (the HTML) of the page being analyzed, in order to find accessibility issues. The resulting report includes CSS selectors and short HTML snippets of the elements that failed a check, so you can find and fix them.
Where the report is kept
The most recent report is held in the extension's session storage, which lives in memory. This is still storage, so to be precise about it:
- It is replaced whenever you run a new scan.
- It is cleared when the browser restarts, or when the extension is disabled, reloaded, or updated.
- Closing the popup or the report tab does not clear it.
- It is never written to a server.
Network activity
- Single-page scan: no network requests are made. The accessibility engine (axe-core) is bundled inside the extension and its optional resource-preloading feature is disabled.
- Multi-page scan (only after you explicitly authorize a site): the extension requests that store's
robots.txtand sitemap files, and opens up to 20 of its pages in background tabs. Those pages load normally, including any third-party resources the store itself uses, and the requests use your existing browser session and cookies. The store's servers — and any third parties it loads — therefore receive the ordinary data of a web request, such as your IP address and the URL requested. This is the same traffic that would occur if you visited those pages yourself.
The extension does not use analytics, trackers, or cookies of its own.
Permissions
- activeTab / scripting: run the accessibility analysis on the page you choose.
- storage: hold the most recent report in session memory so the report page can display it.
- Optional site access: requested only when you start a multi-page scan, and only for the store you are scanning. Once granted, that access remains until you remove it in Chrome's extension settings.
Scope and limits of the analysis
The analysis is automated and covers each page's main frame; content inside iframes is not analyzed. A multi-page scan covers a sample of up to 20 pages, not an entire store. Automated testing cannot detect every accessibility issue — some checks are reported as inconclusive and require human review. This tool helps you find and understand accessibility issues; it does not, by itself, make a website compliant with any law or standard.
Limited Use
Use of information received from this extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide the accessibility analysis to you, is never sold or transferred to third parties, and is never used for advertising, credit assessment, or lending purposes.
Exports
Printing or saving the report as a PDF is initiated by you and handled by your browser.
Contact
Questions: thiago.990199@gmail.com