Skip to main content
RemediADA

Legal

Privacy Policy

Effective Date: April 25, 2026

Operated by Remediada Holdings LLC, 30 N Gould St, Sheridan, WY 82801

Section 1

Information We Collect Directly From You

When you create an account or purchase a service we collect: account information (name, email, business name, password hash, API tokens), platform credentials for any CMS or commerce platform you ask us to remediate (encrypted at rest with AES-256-GCM and a scrypt-derived key), payment information handled by Stripe (we never see raw card numbers), and the content of any communications you send us through email, the in-app support form, or live chat.

Section 2

Information We Collect Automatically

Scan data: when you or a lead's website is scanned, we store the rendered HTML of audited pages, the axe-core violation list, keyboard navigation results, AI visual analysis findings, screenshots, recorded keyboard-navigation videos, and the compliance score. Usage data: pages you visit on remediada.com, dashboard actions, and feature usage. Technical data: IP address, user agent, browser, device, approximate location, and timestamps. Email engagement: opens, clicks, and bounces reported by our email service provider.

Section 3

Information From Third Parties

Business data from the Google Places API (business name, address, phone, website); and, on our own site, first-party usage events (pages visited, buttons clicked) tied to the attribution cookie above - collected by us, never sold or shared when that data is publicly available. Payment data from Stripe (masked card details, transaction status, dispute and chargeback notifications). Email engagement from Resend (delivery status, bounce and complaint signals).

Section 4

How We Use Information

We use the information described above to provide the Service, generate compliance reports, apply and audit source-code remediation, send transactional and (with consent) marketing communications, process payments through Stripe, comply with legal obligations, and improve the Service through aggregated and anonymized analytics.

Section 5

Information Sharing

We share information only with the following categories of recipients and only to the extent necessary:

  • Stripe — for payment processing and fraud prevention.
  • Resend — for transactional and marketing email delivery.
  • Supabase — our managed Postgres and authentication provider, which hosts account, scan, and remediation data.
  • Anthropic — we send scan data (HTML snippets, screenshots, violation text) to the Anthropic API for AI-powered visual analysis and fix generation. Anthropic does not train models on API inputs. No personal account information is included.
  • Railway — our infrastructure provider, which hosts the scanner, API, and remediation worker.
  • Law enforcement or government authorities — when legally compelled by a valid subpoena or court order.

We do not sell personal information to advertisers or data brokers.

Section 6

Lead Generation Practices

RemediADA collects business information from publicly available sources (Google Places API, public business directories) to identify websites that may benefit from accessibility remediation. We scan the public pages of those websites and we may send commercial email to the business contact address listed in public sources. All commercial email we send complies with the CAN-SPAM Act: the message identifies itself as commercial, lists an accurate physical postal address, and includes a one-click unsubscribe link that removes the recipient from all future marketing communications within 10 business days.

Section 7

Data Security

Platform credentials are encrypted with AES-256-GCM using a key derived via scrypt; plaintext credentials exist only in memory inside the remediation worker at the moment a fix is applied. All traffic is served over HTTPS with modern TLS. Row-level security (RLS) policies on our Postgres database restrict access so clients can only read their own scans, remediation jobs, and fix snapshots. Every API endpoint is rate-limited and the scanner implements SSRF protection against non-public IP ranges. Access to production systems is restricted to named individuals and is logged.

Section 8

Data Retention

Scan results are retained in active storage for one year, after which they are archived in encrypted cold storage for an additional two years and then permanently deleted. Scan data is also retained as compliance documentation to support audit trails, dispute resolution, and rollback operations.

When you delete your account, a 30-day soft-delete period applies before permanent erasure. During that window your data is inaccessible but can be restored if you contact us. After 30 days all account records, OAuth tokens, platform credentials, and personal information associated with the account are permanently and irreversibly deleted, except where a longer retention period is required by law or is necessary to resolve an outstanding dispute.

Lead records (business name, address, contact email obtained from public sources) are retained until the lead unsubscribes, at which point the email address is moved to a persistent suppression list. Remediation audit logs (remediation_audit_log, fix_snapshots, remediation_rollback_queue) are retained for three years in support of dispute resolution and rollback.

Section 9

Your Rights (GDPR and CCPA)

Depending on your location, you may have the following rights with respect to your personal information:

  • Right to access. You can download a machine-readable export of your personal data, scan history, and account information at any time from /dashboard/account. You may also submit a written request to support@remediada.com.
  • Right to correction. You may update your name, email, and business information directly in your account settings at any time. Contact us for any corrections we must make on your behalf.
  • Right to deletion. You may delete your account from /dashboard/account. A 30-day soft-delete window applies (see Section 8). You may also request erasure of specific data by emailing us.
  • Right to data portability. Account exports from /dashboard/account are provided in JSON format, which can be imported into compatible systems. Scan reports are also available as downloadable PDFs.
  • Right to opt out of marketing. Use the unsubscribe link in any marketing email, or manage preferences in your account settings. Transactional emails are not affected.
  • Right to revoke OAuth or platform access. OAuth connections and platform credentials can be revoked at any time from /dashboard/account.

We respond to verifiable privacy requests within 30 days. We will not discriminate against you for exercising any of these rights.

Section 10

California Residents (CCPA / CPRA)

We do not sell personal information within the meaning of the California Consumer Privacy Act or the California Privacy Rights Act, and we do not share personal information for cross-context behavioral advertising. California residents have all of the rights described in Section 9 and additionally have the right to know the categories of personal information we collect (see Sections 1–3), the business or commercial purposes for which it is used (see Section 4), and the categories of third parties with whom it is shared (see Section 5 and Section 10a below). To make a CCPA/CPRA request, contact support@remediada.com.

Section 9a

International Data Transfers

We are a United States company and our service providers process data primarily in the United States. If you access the Service from the European Economic Area, the United Kingdom, or Switzerland, your information is transferred to the United States. Where required, those transfers rely on our providers' safeguards, including Standard Contractual Clauses and, where applicable, certification under the EU-U.S. Data Privacy Framework. You may request a copy of the applicable safeguards, or a data processing agreement covering your account, by contacting support@remediada.com.

Section 10a

Third-Party Service Providers

The following third-party providers process data on our behalf under data processing agreements that restrict their use to providing services to us:

  • Supabase — managed Postgres database and authentication. Stores account records, scan data, remediation logs, and OAuth tokens.
  • Stripe — payment processing and subscription billing. Stores payment method details and transaction records under PCI DSS compliance. We never receive or store raw card numbers.
  • Resend — transactional and marketing email delivery. Receives recipient email addresses and message content only as needed to send email on our behalf.
  • Sentry — application error monitoring and performance tracing. May receive user identifiers, URLs, and stack traces when errors occur. Personal data in Sentry is retained for 90 days.
  • Anthropic — AI processing. Receives HTML snippets, screenshots, and violation text for visual analysis and fix generation. No personal account information is included. Anthropic does not train models on API inputs.

Section 11

Cookie Policy

We use first-party cookies only: essential cookies plus one first-party attribution cookie. We do not use advertising cookies, cross-site trackers, or third-party marketing pixels.

The following cookies are set by remediada.com:

Cookie namePurposeAttributesTTL
rmd-user-sessionAuthenticates signed-in user accounts on the dashboard and customer-facing pages.HttpOnly, Secure, SameSite=Lax30 days
rmd-admin-sessionAuthenticates Remediada Holdings LLC staff on the internal admin console. Only set when accessing admin routes.HttpOnly, Secure, SameSite=Strict4 hours
r_refFirst-party attribution. If you arrive from an email or link we sent, this remembers that referral so we can attribute a later signup or purchase to it. Contains a referral identifier only; never shared with third parties and not used for advertising.Secure, SameSite=Lax90 days

The session and admin cookies are strictly necessary for the Service to function; the attribution cookie is first-party analytics used solely to attribute referrals, and you may clear or block it without affecting the Service. The HttpOnly attribute prevents JavaScript from reading the cookie value, reducing exposure to cross-site scripting attacks. The Secure attribute ensures the cookie is only transmitted over HTTPS. The SameSite attribute limits cross-site request forgery risk.

Section 11a

OAuth Login

You may sign in to RemediADA using a third-party OAuth provider (Google, GitHub, or Shopify) instead of creating a password. When you choose OAuth sign-in:

  • You are redirected to the provider's authorization page and asked to grant permission. We request only the minimum scopes needed: email address, public profile name, and profile avatar.
  • After authorization, the provider returns an access token and refresh token. These tokens are encrypted at rest using AES-256-GCM before being stored in our database. The encryption key is stored separately from the database.
  • The data we receive from the provider (email, display name, avatar URL, and provider user ID) is stored as part of your RemediADA account record.
  • We do not use OAuth tokens to access any data beyond what is required to maintain your session. We never read your email inbox, repository contents, contacts, or any other provider data not explicitly listed above.
  • You can disconnect an OAuth provider and revoke RemediADA's access at any time from /dashboard/account. After disconnection, we delete the stored tokens. You can also revoke access directly from the provider's settings page (e.g., Google Account Permissions, GitHub Authorized OAuth Apps, Shopify Connected Apps).

Section 12

Children

RemediADA is a business-to-business service and is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact support@remediada.com and we will delete it.

Section 13

Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be announced via email to the address on file and by posting the updated policy at this URL. Continued use of the Service after a material change constitutes acceptance of the updated policy.

Section 14

Contact

Remediada Holdings LLC
30 N Gould St
Sheridan, WY 82801
support@remediada.com