Skip to main content

Legal · Privacy Policy · GDPR and CCPA

Privacy Policy

Effective July 18, 2026

ShieldStack ("we", "us") is the Accessibility Department for Shopify Stores: Audit, Remediation, Statement and Monitoring, owned as one. This policy explains what data we collect, why, and what your rights are.

1.Data we collect

  • Contact info you provide: name, email, company name, Store URL
  • Booking data via Cal.com when you book a call (name, email, time)
  • Payment data via Stripe when you purchase (we do not store credit card numbers; Stripe handles all payment data)
  • Audit data: when we audit your Store, we test its public pages by hand and with our own tooling, and we keep the findings
  • Communication: emails and chat messages between us, plus any notes from calls you book with us

2.Why we collect it

  • To deliver the audit service you purchased
  • To communicate about your project
  • To bill and account for purchases
  • For legal and tax compliance

3.Third parties

  • Stripe (payment processing), stripe.com/privacy
  • Wise (receiving Client payments by bank transfer), wise.com/privacy-policy
  • Google Workspace (email and calendar), policies.google.com/privacy
  • Cal.com (booking), cal.com/privacy
  • Vercel (website hosting and analytics), vercel.com/legal/privacy-policy

We do not sell or share your data with marketing companies.

4.How long we keep data

  • Active Client data: while the engagement is ongoing
  • Past Clients: 7 years (Portuguese tax record retention)
  • Marketing leads who didn't convert: deleted after 12 months of no contact
  • Stripe transaction records: per Stripe's retention (7 years US tax law)

5.Your rights (GDPR and CCPA)

  • Access: request a copy of data we hold about you
  • Correction: ask us to correct inaccurate data
  • Deletion: ask us to delete your data (we will, unless legally required to retain it)
  • Portability: get your data in a machine-readable format
  • Opt-out of marketing: reply to any of our emails asking us to stop, and we stop

Email hello@shieldstack.pro to exercise any of these rights.

6.Cookies

We do not use tracking or advertising cookies. Our website uses functional cookies only (none currently). No cookie banner is displayed because none is required for our use.

7.Cold outreach

We send cold emails to businesses that fit our target customer profile (Shopify Stores, US, $1M+ in revenue). Reply asking us to stop and we stop, permanently. We do not buy email lists.

8.Security

We use industry-standard security: HTTPS everywhere, password manager, 2FA on all admin accounts, encrypted backups.

9.Children

Our service is for businesses. We do not knowingly collect data from anyone under 18.

10.Changes

We may update this policy. Material changes will be notified via email to active Clients. The effective date above will be updated.

11.Contact

ShieldStack
hello@shieldstack.pro
Operated from Portugal. Data controller: Bruno Ponce de Leão.

ShieldStack · Accessibility, owned from the inside · United States · ADA Title III · WCAG 2.2 AA