Skip to main content
Back to Home

Privacy Policy

Last updated: July 2026

AuditAble ("we," "us," or "our") is committed to protecting the privacy of our users, particularly the government organizations and public sector entities we serve. This Privacy Policy explains how we collect, use, store, and protect your information when you use our accessibility compliance platform.

1. Information We Collect

Account Information

When you create an account, we collect your name, email address, organization name, job title, and phone number. For billing purposes, we collect payment information which is processed securely by Stripe and never stored on our servers.

Scan Data

When you use our scanning services, we collect and analyze publicly available content from the websites you submit for scanning. This includes HTML content, page structure, images, and other publicly accessible elements necessary to evaluate accessibility conformance against WCAG 2.1 Level AA criteria.

Usage Data

We collect anonymous usage information including pages visited within our platform, features used, scan frequency, and general interaction patterns. This data helps us improve our service and is not linked to personally identifiable information.

2. How We Use Your Information

  • To provide, maintain, and improve our accessibility scanning and reporting services
  • To generate accessibility reports and remediation guidance for your organization
  • To communicate with you about your account, scans, and service updates
  • To process payments and manage billing
  • To provide customer support and respond to inquiries
  • To analyze aggregate usage patterns and improve our platform
  • To comply with legal obligations

3. Data Storage and Security

All data is stored on US-based infrastructure. We employ industry-leading security measures including:

  • Encryption at rest: All stored data is encrypted using AES-256 encryption
  • Encryption in transit: All data transmitted between your browser and our servers is protected with TLS 1.3
  • Access controls: Row-level security (RLS) ensures strict tenant isolation, so your data is only accessible to your organization
  • Infrastructure: Our platform runs on enterprise-grade cloud infrastructure with SOC 2 certified providers

4. Data Retention

  • Scan data and reports: Retained for 3 years from the date of the scan to support compliance history and trend analysis
  • Accessibility findings: Retained for 1 year after the finding has been marked as resolved
  • Account information: Retained for the duration of your account and for 90 days following account closure
  • Billing records: Retained as required by applicable tax and financial regulations

You may request early deletion of your data at any time. See "Your Rights" below.

5. Third-Party Services

We use the following third-party services to operate our platform:

  • Supabase: Database hosting and authentication (US-based infrastructure)
  • Stripe: Payment processing (PCI DSS Level 1 certified)
  • Resend: Transactional email delivery (scan reports, notifications)

Each of these providers maintains their own privacy policies and security certifications. We have data processing agreements in place with all third-party providers.

6. Government-Specific Privacy Commitments

As a platform serving government organizations, we maintain the following commitments:

  • FERPA Compatible: Our platform does not collect, store, or process student education records. Scan data is limited to publicly available website content.
  • CIPA Compatible: Our scanning services do not involve content filtering or monitoring of individual internet usage.
  • No Data Sales: We never sell, rent, or trade your data or your organization's data to third parties for any purpose, including marketing or advertising.
  • No Data Mining: We do not use your scan data to build profiles, target advertising, or for any purpose other than providing our accessibility services to your organization.
  • Government Procurement: We support standard government procurement processes and can provide additional documentation as required.

7. Your Rights

You have the following rights regarding your data:

  • Access: Request a copy of all data we hold about your organization
  • Export: Export your scan data, reports, and findings in standard formats (JSON, CSV, PDF)
  • Correction: Request correction of inaccurate account information
  • Deletion: Request deletion of your data, subject to legal retention requirements
  • Portability: Receive your data in a structured, machine-readable format

To exercise any of these rights, contact us at privacy@auditable.co. We will respond within 30 days of receiving your request.

8. Cookies

We use a limited number of cookies essential to the operation of our platform. For detailed information about the cookies we use and how to manage them, please see our Cookie Policy.

9. Children's Privacy

AuditAble is a business-to-government service and is not directed at children under the age of 13. We do not knowingly collect personal information from children. Our scanning services analyze publicly available website content and do not interact with or collect data from website visitors, including children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will provide at least 30 days' advance notice of any material changes via email to the account holder and by posting a prominent notice on our platform. Your continued use of our services after the effective date of any changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us: