Privacy policy

Last updated: 22 July 2026

Short version: this website collects as little as we could get away with. No advertising trackers, no analytics cookies, and no consent banner theatre, because there is nothing to consent to.

Who we are

AccessPatched is operated by Egghead Labs ("we", "us"), the data controller for personal data described in this policy. Contact: privacy@accesspatched.com. Office address: Egghead Labs, WeWork Prestige Atlanta, 80 Feet Main Road, Koramangala 1A Block, Bengaluru, Karnataka 560034, India.

What we collect, and why

1. Email you send us

If you email us (including via the links on this site), we receive your email address, your name if your mail client includes it, and whatever you write, typically your shop URL. We use it to answer you, run the scan you asked for, and follow up about our services. Legal basis: taking steps at your request before entering a contract (Art. 6(1)(b) GDPR) and our legitimate interest in responding to enquiries (Art. 6(1)(f)).

2. The free scan form

If you request a free scan through the form on our scan page, we collect: the shop URL you enter, your email address, an optional country choice, the fact that you ticked the consent box (with a timestamp), and a one-way hashed form of your IP address (used only to rate-limit the form against abuse; we cannot turn it back into your IP).

We use this data for two separate things, on two separate legal bases:

The hashed IP is processed under our legitimate interest in keeping the form usable and abuse-free (Art. 6(1)(f) GDPR) and is deleted automatically within an hour of your request. Form submissions are received by our infrastructure provider Cloudflare acting as our processor, under Cloudflare's data processing addendum and EU standard contractual clauses. Retention: scan request records and the report we sent are deleted within 12 months if you do not become a client; your address stays on the enforcement-notes list only until you unsubscribe. Our replies and the report itself are sent from our own mailboxes, hosted by our email provider MXroute; if we adopt a dedicated email service for the enforcement-notes list, we will name it and its safeguards here before it sends to anyone.

3. Scan data

When you request a scan, we test publicly accessible pages of the URL you give us. That data is about your website, not about people; we don’t submit forms or create accounts during scans.

4. Server logs

Our hosting provider, Vercel, keeps standard server logs (IP address, user agent, pages requested) for security and reliability, retained for a limited period under Vercel's data processing terms. Legal basis: legitimate interest in keeping the site up (Art. 6(1)(f)).

5. Client project data

If you become a client, we access the code and systems you grant us access to, under the agreement we sign with you. That processing is governed by our contract (and a data processing agreement where applicable), not by this website policy.

What we don’t do

International transfers

We operate from India. If you are in the EU/EEA and email us, your data is transferred to India, which does not have an EU adequacy decision. We rely on standard contractual clauses with our service providers (including Cloudflare and Vercel) where applicable, and on Art. 49(1)(b) GDPR (transfer necessary for pre-contractual steps taken at your request) for direct correspondence.

Retention

Enquiry emails: up to 24 months after last contact, then deleted. Scan results for non-clients: deleted or anonymized within 12 months. Client records: as required by contract and Indian tax law.

Your rights

If you are in the EU/EEA or UK, you have the rights of access, rectification, erasure, restriction, portability, and objection under the GDPR, and the right to complain to your local supervisory authority. Write to privacy@accesspatched.com. A human answers, usually within a few business days.

Changes

If this policy changes materially, the date above changes with it, and the old versions stay available on request. No silent edits.