Privacy Policy

Last updated: July 15, 2025

Rankley (“we,” “us,” or “our”) provides an AI-powered Local SEO reporting platform (“Services”) for agencies and businesses. This Policy explains what information we collect, how we use it, how we comply with Google API requirements, and the choices available to you.

1. Introduction

Your privacy matters. By using our Services, you agree to the practices described here. If you do not agree, please do not access the Services.

2. Information We Collect

a. Account & Profile Data

Name, email, hashed password, company name, and optional profile details (e.g., logo, branding colors).

b. Usage Data

IP address, device and browser type, pages visited, features used, API calls, and timestamps to operate and improve the Services.

c. SEO & Connected-Account Data

With your permission, we fetch data needed to generate reports, including: Google Business Profile metrics, Google Analytics data, Search Console data, listing data, heat-map results, and competitor or audit data you request.

d. Billing & Payment Data

We use Stripe to process payments. We receive your Stripe customer ID, subscription plan, transaction dates, and credit-balance information. We do not store full card numbers.

e. Support & Communications

Support tickets, emails, chat transcripts, and feedback you provide.

3. How We Use Your Information

  • Provide & Maintain Services. Authenticate you, connect integrations, generate reports, and power dashboards.
  • Billing & Fraud Prevention. Manage subscriptions, process payments, and detect suspicious activity.
  • Product Improvement. Analyze usage to develop features and optimize performance.
  • Communications. Send transactional emails (invoices, password resets) and, if opted-in, marketing updates.
  • Legal & Safety. Comply with laws, enforce our Terms, and protect against misuse.

4. Cookies & Tracking

  • Essential. Session cookies for authentication and security.
  • Performance. Analytics cookies to understand site performance.
  • Functional. Preferences such as theme or language.
  • Advertising. None—Rankley does not place third-party ads.

You can control cookies in your browser. Disabling essential cookies may break core functionality.

5. Third-Party Services

We integrate with and/or process data through the following providers acting as processors on our behalf:

  • Google (Business Profile, Business Profile Performance, Analytics, Search Console).
  • Stripe (payments).
  • Supabase (authentication, database/storage).
  • Vercel (hosting) and typical cloud infrastructure providers.
  • LocalFalcon or other rank-tracking APIs (map grids), if you opt in.
  • CRM/Email platforms (e.g., HubSpot) for account and product communications if you opt in.
  • Automation platforms (e.g., Zapier or GoHighLevel) when you choose to connect them.

Each provider has its own privacy notice. Please review those before connecting.

What we request & why (scopes are only requested when you choose to connect a given integration):

  • Google Analytics 4 (GA4)https://www.googleapis.com/auth/analytics.readonly (read metrics for reports).
  • Google Search Console (GSC)https://www.googleapis.com/auth/webmasters.readonly (read search performance/coverage for reports).
  • Google Business Profile & Performance (GBP)https://www.googleapis.com/auth/business.manage (used by Google to authorize access to Business Profile and Business Profile Performance APIs; Rankley uses it to read performance/location metrics only unless you explicitly perform management actions).

Unbundled consent. You can connect GA4, GSC, and GBP separately. We request only the scope(s) for the feature you choose. Connecting one product does not require you to connect the others.

Incremental authorization. When you add another Google feature later, we use incremental OAuth (include_granted_scopes=true) so previously granted scopes persist and Google shows only the new permissions being requested.

Limited Use & Google policies. Rankley’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Human access. We do not allow humans to read Google user data except (a) with your consent, (b) for security/debugging, or (c) as required by law.

No selling or advertising use. We do not sell your Google data, and we do not use it for ad targeting.

Revocation. You can disconnect any Google integration inside Rankley at any time. You may also revoke Rankley’s access directly in your Google Account at: myaccount.google.com/permissions.

Deletion after disconnect. Upon disconnect or a verified deletion request, we delete or anonymize cached Google data and tokens for that integration within 30 days (sooner where required by law), except where retention is legally required.

7. Data Retention

We retain your account and report data while your account is active and for up to 2 years thereafter for audit, troubleshooting, and legal purposes. You may request earlier deletion (see Section 10). Backups may persist for a limited period consistent with our disaster-recovery practices.

8. Data Security

  • Encryption in transit (TLS 1.2+) and at rest where supported.
  • Least-privilege access and role-based controls.
  • Regular patching and vulnerability management.

No system is 100% secure. Use strong, unique passwords and enable 2FA where available.

9. Children’s Privacy

Our Services are not directed to children under 16, and we do not knowingly collect personal data from minors. If you believe a child under 16 has provided data, contact us and we will delete it.

10. Your Rights & Choices

  • Access & Portability. Request a copy of your data in a machine-readable format.
  • Correction & Deletion. Update or delete your personal information, including cached Google data as described above.
  • Opt-Out of Marketing. Unsubscribe anytime using the link in our emails.
  • Cookie Controls. Manage cookies via your browser settings.
  • Disconnect Integrations. Disconnect GA4, GSC, or GBP individually inside Rankley and/or revoke access in your Google Account.

To exercise these rights, email privacy@rankley.com. We may request information to verify your identity.

11. International Transfers

We are based in the United States and may process data in the U.S. and other countries. Where applicable, we use appropriate safeguards (e.g., Standard Contractual Clauses) for cross-border transfers.

12. Changes to This Policy

We may update this Policy from time to time. We will post the revised version with a new “Last updated” date. For material changes, we will provide notice (e.g., email or in-app) when feasible.

13. Contact Us

If you have questions, concerns, or data requests, please contact:

Email: privacy@rankley.com

Rankley, Inc.
800 N King Street Suite 304 #2230
Wilmington, DE 19801
United States