Skip to content
← Curbline

Privacy

Last updated 15 September 2026

This is a draft

It describes what the product actually does, and the retention periods in it are the ones the code enforces. It has not been reviewed by a lawyer. Every section marked below needs one before this page is published.

Curbline loads a web page in a browser we control, tests it against WCAG 2.1 AA rules, and stores what it found. This page describes exactly what that means for the data involved.

What a scan does

When a URL is submitted, we open it in a headless Chromium browser on our own servers, wait four seconds for the page to finish rendering, and run axe-core against it. A second pass then walks the page with the Tab key, up to 150 stops, recording where keyboard focus goes.

We request the page the way any browser does. We do not sign in, submit forms, follow links beyond the URL given, or interact with anything beyond pressing Tab. Only the single page at the URL submitted is loaded.

What a scan stores

Those snippets are whatever is in the markup at that position. On a normal storefront page that is layout and product copy. We do not extract, index, or search page content for any purpose beyond rendering it back in your report.

Scanning a site you do not own

Anyone can paste any URL into the form on our homepage, including a site they have no relationship with. We do not verify ownership before scanning, and we cannot.

If you submit a URL, you are telling us you have the right to request that scan. Responsibility for that sits with you, not with us — this is set out in the terms. If you operate a site and want a scan of it removed, contact us and we will delete it.

Account data

IP addresses

Free scans are rate limited, which requires recognising repeat requests from the same place. We do not store your IP address to do it. The address is combined with a secret held only on our servers and hashed with SHA-256, and only that hash is written down. The hash cannot be reversed to an address, and it is deleted after 24 hours.

Our hosting provider keeps its own request logs, which do contain addresses. Those are subject to their retention, not ours.

How long we keep things

These are the periods our systems actually enforce. A scheduled job applies them daily; they are not aspirations.

Cancelling a subscription does not delete anything. Your scan history stays visible and ages out on the same 365-day clock as everyone else’s, so reactivating picks up where you left off. If you want it gone sooner, ask and we will erase it.

Deleting your account removes your sites, every scan of them, and the stored snippets, by cascade. Stripe keeps its own record of payments, which we cannot delete and which they are independently required to retain.

Who else processes this data

Curbline is a small product built on other people’s infrastructure. In full:

No analytics, advertising, or tracking service is used. There are no third-party scripts on this site, and we set no cookies other than the one that keeps you signed in.

Where your data is held

Three jurisdictions are involved. Stating that plainly is the point of this section — it is the part most likely to matter and the least likely to be guessed correctly.

So a European or American customer’s data touches the United States, Japan and Australia in the course of normal use. None of that is hidden from you and none of it is incidental — it is how the product is built.

Scans run on behalf of someone else

On the Agency plan, our customer is the agency and the scanned store belongs to their client. We therefore hold fragments of pages belonging to a business that has no relationship with us. We process that content only to produce the agency’s report, we do not use it for anything else, and it is deleted on the schedule above.

The contract that should govern that arrangement does not exist yet. It is recorded as a commercial gap in the terms, because that is what it is.

Contact

Email hello@curbline.app for anything on this page, including removal of a scan or erasure of an account.