Fix47

Privacy Policy

Last updated: 22 June 2026

1. Information We Collect

URLs you scan: When you use our free scanner, we process the URL you submit to perform the accessibility audit. We do not store the content of the scanned pages.

Scan records (pre-login): When you run a scan, we store the scanned URL, the resulting accessibility score, violation data, risk estimate, and your IP address as an anonymous scan record. If you subsequently create an account using the same email address, this record is linked to your account (see “How We Use Your Information” below). Anonymous scan records that are never claimed by an account are automatically deleted after 30 days.

Account data: If you create a Fix47 account, we collect your name, email address, and — if you sign in with Google — your Google profile image and email-verification status. We do not store passwords. Account data is held in our database until you delete your account.

Authentication data: We use two sign-in methods: (a) Google Sign-In (OAuth 2.0) — Google verifies your identity and shares your name, email address, and profile picture with us; and (b) passwordless magic-link — we send a one-time sign-in link to your email address via Resend. In both cases we store a database session record (session token, expiry, user ID) to keep you signed in. We do not store OAuth access tokens beyond what is required for session management.

Email address: If you choose to unlock your full risk report, we collect the email address you provide.

Usage data: With your consent, we use PostHog (hosted in the EU) for product analytics — pages visited, scan completion, and anonymised session replays with text and input fields masked — to understand how Fix47 is used and improve it. PostHog activates only after you accept analytics cookies in our consent banner; if you decline, no analytics cookies or session recording are set. You can change or withdraw your choice anytime via “Cookie settings” in the footer. See Section 5a.

Technical data: We automatically collect browser type and version, IP address (anonymized after 30 days for non-account visits; see Section 6 for account-linked scan retention), and device type to ensure service compatibility and security.

2. How We Use Your Information

  • To perform accessibility scans and generate reports
  • To send you your risk report via email (if requested)
  • To create and manage your Fix47 account, authenticate your identity, and maintain your session
  • To link prior scan records to your account when you sign in with a matching email address — so your scan history is available in your dashboard without re-scanning
  • To send monthly accessibility monitoring alerts if your site's score deteriorates (free accounts only; you can opt out of this channel at any time via the unsubscribe link in each email)
  • To send a series of service-related emails about your site's accessibility status and how Fix47 can help, over approximately 18 days following account creation (you can opt out at any time via the unsubscribe link in each email)
  • To communicate about our remediation services (you can unsubscribe at any time)
  • To improve our scanning technology and service quality
  • To prevent fraud, enforce rate limits, and ensure platform security

3. Legal Basis for Processing (UK GDPR / EU GDPR)

We process your personal data on the following legal bases, mapped to each purpose:

  • Contract performance (UK GDPR Art. 6(1)(b)): Processing your account data (name, email, profile image), managing your session, delivering scan results, and providing the Fix47 service you have signed up for. Also applies to site-access credentials for remediation customers (see Section 5b).
  • Legitimate interests (UK GDPR Art. 6(1)(f)): Linking prior scan records to your account on sign-in (giving you a seamless dashboard and not losing your scan history; low-impact and expected in context), plus fraud prevention, rate limiting, platform security, and service improvement using anonymized usage data. You may object at any time.
  • Soft opt-in / existing customer relationship (PECR Regulation 22 / ePrivacy Directive Art. 13(2)): The monthly monitoring alert and the follow-up email sequence are sent to users who provided their email in the context of using our service, about our own similar services. You can opt out of either channel at any time, free of charge, via the unsubscribe link in every email.
  • Consent (UK GDPR Art. 6(1)(a)): For any email communications beyond those above, and for any non-essential cookies or analytics we may add in future. You can withdraw consent at any time.
  • Legal obligation (UK GDPR Art. 6(1)(c)): Retaining financial and transactional records as required by UK HMRC and the Companies Act 2006.

4. Data Sharing

We do not sell, rent, or trade your personal information to third parties. We may share data with service providers who assist in operating our platform (e.g., email delivery, hosting), subject to confidentiality obligations. See Section 9 for details of our sub-processors.

5. Cookies and Tracking

We use essential cookies required for the basic functionality of our service (e.g., session management), plus — only with your consent — analytics cookies from PostHog (see Section 5a). We do not use any advertising trackers, marketing cookies, or cross-site tracking.

Our analytics provider, PostHog, is hosted in the EU (Frankfurt). Analytics cookies and session replay are activated only after you accept them in our consent banner; you can change or withdraw your choice at any time via “Cookie settings” in the footer.

5a. Cookies — Detailed Disclosure

We use a minimal set of cookies and similar technologies. The cookies below are either “strictly necessary” under ePrivacy Directive Article 5(3) — set without consent because the service cannot function without them — or analytics cookies (PostHog) that are set only after you give consent via our banner. No marketing or advertising cookies are ever set.

Cookies we use

CookiePurposeDurationType
authjs.session-tokenAuthenticates signed-in Fix47 users. Set when you create an account or log in (Google Sign-In or magic-link). Contains an opaque session ID only — no personal data is stored in the cookie itself; the session record is stored server-side in our database. Not set during anonymous site browsing or scanning.30 days (rolling)Strictly necessary
admin-tokenAuthentication for the Fix47 admin dashboard. Only set if you log in to /admin. Not set during normal site browsing.SessionStrictly necessary
Vercel infrastructureHosting and deployment routing used by our infrastructure provider (Vercel). No personal tracking or profiling.SessionStrictly necessary
PostHog (ph_*)Product analytics and session replay (text and input fields masked) to understand how Fix47 is used and improve it. Hosted in the EU (Frankfurt). Set only after you accept analytics cookies in our consent banner — never if you decline. Session replays are retained for 30 days. No advertising, profiling for ads, or cross-site tracking.Up to 12 monthsAnalytics (consent required)
fix47_cookie_consentRemembers your cookie-consent choice (accept or reject) so we don't ask again for 12 months. Stored in your browser's local storage (not a browser cookie); contains no personal data.12 monthsStrictly necessary

Third-party services — Stripe

When you initiate a payment, you are redirected to Stripe's hosted Checkout page on the stripe.com domain. Fix47 does not load Stripe.js on its own pages. Any cookies set during the Stripe Checkout flow are set by Stripe on their own domain and are governed by Stripe's Privacy Policy: stripe.com/privacy.

What we do not use

  • No Google Analytics, Facebook/Meta Pixel, or advertising trackers of any kind
  • No marketing cookies, retargeting, or behavioural advertising profiles
  • No cross-site tracking, and no selling or sharing of your personal data

Your rights

You can disable cookies in your browser settings. Disabling strictly necessary cookies will prevent your Fix47 account dashboard and the admin dashboard from functioning, but will not affect general site browsing or anonymous scanning.

Updates to cookie usage

We currently use PostHog for analytics, activated only via opt-in consent as described above, in compliance with UK PECR 2003, the ePrivacy Directive 2002/58, and UK/EU GDPR Article 7(1). If we add further tools requiring non-essential cookies, we will update this policy and our consent banner before activation.

5b. Site Access Credentials

When you become a remediation customer, we collect site access credentials (admin URLs, usernames, passwords) you provide via our secure form (fix47.com/credentials/…). These are encrypted at rest using AES-256-GCM, accessible only to authorised Fix47 personnel, used solely for delivering your remediation, and automatically deleted within 14 days of project completion. We never share them with third parties.

Legal basis: contract performance (UK GDPR Art. 6(1)(b)).

6. Data Retention

We retain personal data only as long as necessary for the purposes described in this policy or as required by law. Specific retention periods are as follows:

  • Anonymous scan records (never linked to an account): Automatically deleted 30 days after the scan, where both email and user ID remain null.
  • Scan records linked to an account: Retained for the lifetime of the account. Permanently deleted when you delete your account (see Section 7).
  • IP addresses (anonymous visits): Anonymized after 30 days.
  • IP addresses (stored in scan records): Deleted when the associated scan record is deleted (30-day auto-cleanup for anonymous scans, or account deletion for claimed scans).
  • Account data (name, email, profile image, email-verification status): Retained for the lifetime of your account. Permanently deleted when you delete your account via your account settings or by contacting us, except where a separate legal obligation requires retention (e.g., financial records).
  • Auth session records and verification tokens: Database sessions expire after 30 days of inactivity; pending magic-link tokens expire within minutes. All are permanently deleted when you delete your account.
  • Lead and contact data (email, name): 36 months from the date of last meaningful interaction (e.g., scan, email open, support request). Deleted upon unsubscribe or deletion request if earlier.
  • Email communications: 24 months from the date of the communication.
  • Cookie-consent records: Retained for 5 years from the date of the decision, as proof of consent under UK/EU GDPR Article 7(1). These records contain an anonymous identifier (a random ID), your accept/reject choice, the banner version shown, coarse country, and timestamp. If you are signed in, the record is also linked to your account ID so we can evidence your account's consent. We do not store your full IP address.
  • Payment records and financial transactions: 7 years from the transaction date, as required by UK HMRC and the Companies Act 2006.
  • Client remediation engagement data (audit logs, scan data, remediation evidence, Audit Certificates): 7 years post-engagement, to support warranty claims, legal audit trails, and professional indemnity obligations.

7. Your Rights (UK GDPR / EU GDPR)

Under UK GDPR, EU GDPR, and applicable data protection laws, you have the right to:

  • Access the personal data we hold about you (subject access request)
  • Rectification — correct inaccurate data. You can update your display name directly in your account settings.
  • Erasure (right to be forgotten, Art. 17 UK GDPR) — request deletion of your data. You can exercise this immediately and in full by deleting your account from your account settings. Account deletion permanently removes your scan records, active sessions, linked authentication accounts (Google OAuth tokens), any pending magic-link tokens, and your user record. Alternatively, contact us at carlo@fix47.com. Financial records required by law are retained for the legally required period notwithstanding a deletion request.
  • Restriction of processing in certain circumstances
  • Object to processing based on legitimate interests (including the email monitoring and nurture channels — opt out via the unsubscribe link in any email)
  • Data portability — receive your data in a structured, machine-readable format
  • Withdraw consent for consent-based processing at any time, without affecting the lawfulness of prior processing
  • Lodge a complaint with a supervisory authority — our lead authority is the UK ICO (ico.org.uk); EU residents may also complain to their local authority

8. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know: You may request details about the categories and specific pieces of personal information we have collected about you.
  • Right to delete: You may request the deletion of personal information we have collected from you, subject to certain exceptions.
  • Right to opt-out: You may opt out of the sale of personal information. Note: we do not sell personal information.
  • Non-discrimination: We will not discriminate against you for exercising any of your CCPA rights.

To exercise these rights, contact us at hello@fix47.com.

8a. Children's Data

Fix47's services are intended for businesses and adult professionals. We do not knowingly collect personal data from individuals under 13 (USA, COPPA 16 CFR §312) or under 16 (EU/UK GDPR Art. 8). If we become aware that we have collected data from a child below these ages, we will delete it promptly. If you believe we may have inadvertently collected such data, please contact us at hello@fix47.com.

9. International Data Transfers and Sub-processors

Fix47 uses the following third-party sub-processors who may process personal data outside the UK or EU. Where data is transferred to the United States, we rely on the EU-US Data Privacy Framework (where the processor is certified) or Standard Contractual Clauses (SCCs) approved by the European Commission, and on the UK International Data Transfer Agreement (IDTA) or equivalent addendum approved by the UK ICO, as indicated below.

Sub-processorPurposeLocationTransfer mechanism
Google LLCIdentity and authentication (Google Sign-In / OAuth 2.0). Google receives your email, name, and profile picture when you choose Google Sign-In, and verifies your identity on our behalf. Privacy policy: policies.google.com/privacy.USAEU-US Data Privacy Framework + SCCs / UK IDTA
Stripe Inc.Payment processingUSAEU-US Data Privacy Framework + SCCs
Resend Inc.Transactional and service email delivery (scan reports, magic-link sign-in, monitoring alerts, account email sequence)USAStandard Contractual Clauses
Neon Inc.Database hosting (PostgreSQL)USAStandard Contractual Clauses
Vercel Inc.Website hosting and deploymentUSAStandard Contractual Clauses
PostHog, Inc.Product analytics and session replay (consent-based; text and input fields masked). Privacy policy: posthog.com/privacy.EU (Frankfurt)No transfer — EU-hosted

This list reflects our current sub-processors. We will update this section if we add new sub-processors. Where sub-processors change, material updates will be communicated as described in Section 11.

9a. Authentication and Third-Party Identity Providers

Google Sign-In

When you choose “Sign in with Google”, Google authenticates you and shares the following data with Fix47: your name, email address, profile picture URL, and a flag indicating whether your email is verified. We use this data solely to create and maintain your account. We do not receive your Google password, Google contacts, or any other Google account data. Google's role in this flow is governed by Google's OAuth 2.0 service and their Privacy Policy.

Passwordless Magic-Link

When you choose email sign-in, we send a one-time sign-in link to your email address, valid for a short period. We do not store your password at any point. The email is sent via Resend (see Section 9 for transfer details).

No passwords stored

Fix47 does not store passwords. Authentication relies entirely on verified third-party identity (Google) or a one-time link delivered to your email address.

10. Security

We implement industry-standard security measures including encryption in transit (TLS), secure hosting, and access controls. No method of transmission over the Internet is 100% secure, but we strive to protect your information.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We distinguish between material and non-material changes:

  • Material changes (e.g., new data uses, new sub-processors, changes to your rights): we will provide at least 30 days' advance notice via email or in-product notice, and re-request consent where lawfully required.
  • Non-material changes (e.g., clarifications, typo corrections, formatting): continued use of our services after the update date constitutes acceptance.

12. Data Controller

Data Controller: Carlo Anselmi, trading as Fix47 (UK sole trader).
Address: 124 City Road, London EC1V 2NX, United Kingdom.
ICO Registration: ZC137959.
Legal / data subject requests: carlo@fix47.com
General enquiries: hello@fix47.com
Supervisory authority: UK Information Commissioner's Office (ico.org.uk).

13. Contact

For privacy-related inquiries, contact us at hello@fix47.com.