Privacy policy
Last updated: 22 July 2026
Short version: this website collects as little as we could get away with. No advertising trackers, no analytics cookies, and no consent banner theatre, because there is nothing to consent to.
Who we are
AccessPatched is operated by Egghead Labs ("we", "us"), the data controller for personal data described in this policy. Contact: privacy@accesspatched.com. Office address: Egghead Labs, WeWork Prestige Atlanta, 80 Feet Main Road, Koramangala 1A Block, Bengaluru, Karnataka 560034, India.
What we collect, and why
1. Email you send us
If you email us (including via the links on this site), we receive your email address, your name if your mail client includes it, and whatever you write, typically your shop URL. We use it to answer you, run the scan you asked for, and follow up about our services. Legal basis: taking steps at your request before entering a contract (Art. 6(1)(b) GDPR) and our legitimate interest in responding to enquiries (Art. 6(1)(f)).
2. The free scan form
If you request a free scan through the form on our scan page, we collect: the shop URL you enter, your email address, an optional country choice, the fact that you ticked the consent box (with a timestamp), and a one-way hashed form of your IP address (used only to rate-limit the form against abuse; we cannot turn it back into your IP).
We use this data for two separate things, on two separate legal bases:
- Delivering the report you asked for. We scan the URL and email you the findings. Legal basis: taking steps at your request before entering a contract (Art. 6(1)(b) GDPR). This is the whole point of the form.
- Occasional notes on EU accessibility enforcement. The consent box also opts you into a low-volume email list about accessibility enforcement in the EU. Legal basis: your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time: every email carries a one-click unsubscribe link, or write to privacy@accesspatched.com. Withdrawing does not affect the report you already received, and we do not make the scan conditional on staying subscribed; unsubscribe the minute the report lands if you like.
The hashed IP is processed under our legitimate interest in keeping the form usable and abuse-free (Art. 6(1)(f) GDPR) and is deleted automatically within an hour of your request. Form submissions are received by our infrastructure provider Cloudflare acting as our processor, under Cloudflare's data processing addendum and EU standard contractual clauses. Retention: scan request records and the report we sent are deleted within 12 months if you do not become a client; your address stays on the enforcement-notes list only until you unsubscribe. Our replies and the report itself are sent from our own mailboxes, hosted by our email provider MXroute; if we adopt a dedicated email service for the enforcement-notes list, we will name it and its safeguards here before it sends to anyone.
3. Scan data
When you request a scan, we test publicly accessible pages of the URL you give us. That data is about your website, not about people; we don’t submit forms or create accounts during scans.
4. Server logs
Our hosting provider, Vercel, keeps standard server logs (IP address, user agent, pages requested) for security and reliability, retained for a limited period under Vercel's data processing terms. Legal basis: legitimate interest in keeping the site up (Art. 6(1)(f)).
5. Client project data
If you become a client, we access the code and systems you grant us access to, under the agreement we sign with you. That processing is governed by our contract (and a data processing agreement where applicable), not by this website policy.
What we don’t do
- No analytics or advertising cookies. Currently no cookies at all.
- No sale or sharing of personal data with third parties for their own purposes.
- No third-party fonts, CDNs, or embedded trackers on this site. Everything is served from our own domain.
International transfers
We operate from India. If you are in the EU/EEA and email us, your data is transferred to India, which does not have an EU adequacy decision. We rely on standard contractual clauses with our service providers (including Cloudflare and Vercel) where applicable, and on Art. 49(1)(b) GDPR (transfer necessary for pre-contractual steps taken at your request) for direct correspondence.
Retention
Enquiry emails: up to 24 months after last contact, then deleted. Scan results for non-clients: deleted or anonymized within 12 months. Client records: as required by contract and Indian tax law.
Your rights
If you are in the EU/EEA or UK, you have the rights of access, rectification, erasure, restriction, portability, and objection under the GDPR, and the right to complain to your local supervisory authority. Write to privacy@accesspatched.com. A human answers, usually within a few business days.
Changes
If this policy changes materially, the date above changes with it, and the old versions stay available on request. No silent edits.