Privacy Policy
Rankolab (“Rankolab”, “we”, “us” or “our”) operates the websites rankolab.com and app.rankolab.com, the Rankolab AI SEO WordPress plugin, the Rankolab Cloud API, and related SEO tools and services (together, the “Services”). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have.
By using the Services you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Services.
1. Information We Collect
1.1 Information you provide to us
- Account information — name, email address, password (stored hashed), company name and billing details when you create an account or purchase a subscription.
- Website URLs and content — the site addresses, competitor URLs and email addresses you submit to our free SEO audit and other tools, and the site data processed when you connect a website to Rankolab.
- Plugin registration data — when you connect the Rankolab AI SEO plugin to Rankolab Cloud, we receive the email address you enter, your website URL, and technical details needed to operate the service (WordPress and plugin version).
- Communications — messages you send us by email, chat, or contact forms.
1.2 Information collected automatically
- Usage data — pages viewed, features used, referring pages, and interaction data on our websites.
- Device and log data — IP address, browser type, operating system, date/time stamps, and error logs.
- Cookies and similar technologies — see our Cookie Policy for details.
1.3 Website and SEO data processed by our tools
When you run an audit or connect a site, we crawl and analyse publicly available pages of that website (titles, meta tags, headings, links, schema, performance characteristics) to generate reports and recommendations. Audit reports may be stored so you can access them later via a report link.
2. Google User Data
Limited Use disclosure: Rankolab’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
If you choose to connect your Google account (for example to Google Search Console or Google Analytics through our “Sign in with Google” option), we may request access to the following scopes:
- Search Console (webmasters) — to read search performance data, submit sitemaps, and verify site ownership so we can measure and improve your rankings.
- Indexing API — to request indexing or re-indexing of pages you publish or update.
- Analytics (read-only) — to read traffic statistics used in your SEO reports.
- Site verification — to verify that you control the connected website.
We use Google user data only to provide and improve the user-facing SEO features you request. Specifically, we do not:
- sell Google user data;
- use it for advertising, ad targeting, or credit-worthiness decisions;
- transfer it to third parties except as necessary to provide the Services, comply with law, or as part of a merger/acquisition with equivalent protections;
- allow humans to read this data, except with your explicit consent, for security purposes, to comply with law, or where the data is aggregated and anonymised.
OAuth tokens are stored encrypted and are used solely to make the API calls described above on your behalf. You can revoke Rankolab’s access at any time from your Google Account permissions page or by disconnecting the integration inside the Services; revocation disables the related features immediately.
3. How We Use Information
- Provide, operate, maintain and improve the Services;
- Generate SEO audits, reports, AI-assisted content suggestions and automation actions you request;
- Create and manage your account, process payments and send transactional emails (receipts, report links, service notices);
- Respond to support requests;
- Send product updates or marketing you have opted into (you can unsubscribe at any time);
- Monitor usage, prevent abuse, enforce quotas and secure the Services;
- Comply with legal obligations.
4. Legal Bases (EEA/UK users)
Where GDPR applies, we process personal data on these bases: contract (providing the Services you signed up for), consent (marketing, Google account connections, non-essential cookies), legitimate interests (service security, product improvement, fraud prevention), and legal obligation (tax and accounting records).
5. Sharing and Disclosure
We do not sell personal data. We share information only with:
- Service providers — hosting, payment processing, email delivery, and AI processing providers (for example, Google Gemini APIs used to generate SEO content suggestions), bound by confidentiality and data-processing terms;
- Legal authorities — where required by law, subpoena, or to protect rights, safety, and the integrity of the Services;
- Business transfers — in connection with a merger, acquisition or asset sale, subject to equivalent protections.
Content sent to AI providers is limited to what is needed to generate the SEO output you request (for example page titles, descriptions and page text). We do not send your Google account credentials or tokens to AI providers.
6. Data Retention
- Account data — retained while your account is active and for up to 90 days after deletion, except where longer retention is legally required.
- Audit reports and leads — retained until you ask us to delete them or 24 months of inactivity, whichever is sooner.
- OAuth tokens — retained until you disconnect the integration or revoke access, then deleted.
- Server logs — retained up to 30 days.
7. Your Rights
Depending on your location (GDPR, UK GDPR, CCPA/CPRA and similar laws), you may have the right to access, correct, export, restrict, object to the processing of, or delete your personal data, and the right to lodge a complaint with a supervisory authority. California residents have the right to know, delete, correct, and opt out of “sale/sharing” (we do not sell or share personal information as defined by the CCPA).
To exercise any right, email support@rankolab.com from the address associated with your account. We respond within 30 days. You can also request deletion of your data and disconnection of any Google integration at any time — see the “Data deletion” section on our Contact page.
8. Security
We use HTTPS/TLS encryption in transit, hashed passwords, encrypted token storage, role-restricted access, and rate limiting. No method of transmission or storage is 100% secure; we cannot guarantee absolute security, but we notify affected users of any breach as required by law.
9. International Transfers
Our infrastructure may process data in the United States, the United Kingdom and the European Economic Area. Where data is transferred out of the EEA/UK, we rely on adequacy decisions or Standard Contractual Clauses.
10. Children’s Privacy
The Services are not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact us and we will delete it.
11. Third-Party Links
Our Services may link to third-party websites. We are not responsible for their content or privacy practices; review their policies separately.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be announced on this page (and by email for account holders) with an updated “Last updated” date. Continued use of the Services after changes take effect constitutes acceptance.
13. Contact Us
Rankolab — Privacy Team
Email: support@rankolab.com
Admin contact: admin@rankolab.com
Website: https://rankolab.com