How long should a Shopify brand keep accessibility audit records?
If a demand letter arrives, the first question is what the site looked like months ago, and the second is whether you can prove the work you did. Audit records are the evidence. Keeping them is cheap; needing them and not having them is expensive.
Why retention matters more than most brands think
Demand letters rarely describe the site as it looks today. They describe a snapshot from weeks or months earlier, sometimes from a crawl the plaintiff's firm ran long before the letter was sent. Your defense starts with your own snapshot from the same period: what you tested, what you found, what you fixed, and when.
Without records, every claim about diligence becomes a memory contest. With records, it becomes a file folder. The difference shows up in settlement negotiations, where documented remediation history consistently produces better outcomes than assurances. Keep the records as if you will need them, because the brands that need them always wish they had.
What counts as an audit record
Keep the scan reports with their dates and configurations, not just the summaries. Keep the remediation tickets or task lists showing what was fixed and when. Keep before-and-after captures for the significant fixes. Keep every version of the accessibility statement with its effective date. And keep third-party reports from vendors or auditors, including the ones with findings you disagree with.
Also keep the unglamorous metadata: who ran the scan, what tool version, which templates were in scope, and what was deliberately excluded. A report without scope and date is nearly useless as evidence. Future you, or future counsel, will thank present you for the boring details.
How long to keep everything
There is no single federal rule that sets a number, so set a policy and follow it. Three years is a defensible minimum that covers the lookback periods most relevant to website claims. Five years is better and costs nothing extra in cloud storage. Whatever you choose, write it down as a policy with a start date.
The policy matters as much as the duration. A documented retention policy that the business actually follows looks like diligence. An ad hoc pile of old PDFs in someone's email looks like luck. If you use a vendor for monitoring, confirm in writing how long they retain your historical data, because their default may be shorter than your policy.
Store records where the business can find them
The most common failure is not deletion but misplacement: the reports live in a former employee's inbox, or in an agency's project tool the brand no longer pays for. Records should live in storage the business controls, in dated folders, with file names that include the date. Accessibility records are business records; treat them like tax files, not chat history.
Give at least two people access, and make the location part of onboarding for whoever owns the website. When the demand letter arrives, the first 48 hours are for legal strategy, not for hunting through old laptops.
Rebuilding records when they are missing
If you are reading this after the letter arrived and the records are thin, rebuild what you can. Theme version history, app install dates, deploy logs, and design changelogs can reconstruct a timeline. Old accessibility statements may survive in archives. Vendor dashboards often retain more history than anyone remembers.
Be honest about what is reconstructed versus contemporaneous. A rebuilt timeline labeled as such is still useful; a rebuilt timeline presented as original records is a credibility disaster. Start the retention policy now regardless, because the next letter, if there is one, will ask about the period starting today.
Make retention automatic
The policy that survives is the one nobody has to remember. Schedule quarterly exports of scan reports to the records folder. Put the export on the same calendar as the quarterly business review. Assign an owner by role, not by name, so it survives turnover.
Once a year, verify the archive: open a random old report, confirm it is readable, confirm the dates make sense. A five-minute check beats discovering corrupted or missing files when they matter. Retention is a habit, not a project, and habits need owners and calendars.
Sources and testing references
These sources describe accessibility techniques and WCAG success criteria. They do not by themselves establish legal compliance.