Legal
Privacy Policy
Last updated: June 2025
This Privacy Policy describes the types of personal information that Rankply (“Rankply,” “we,” “our,” and/or “us”) collects, uses, and discloses from individuals (“you” or “your”) who use our website (including https://rankply.com/) and services that link to this Privacy Policy (collectively, our “Services”).
As used in this Privacy Policy, “personal information” means any information relating to an identified or identifiable individual. By using our Services, you agree to the collection, use, disclosure, and other processing described in this Privacy Policy. Beyond this Privacy Policy, your use of our Services is also subject to our Terms and Conditions.
Rankply is registered in England and Wales and operates from offices in London, United Kingdom and Barcelona, Spain. We act as the data controller for personal information processed under this Privacy Policy. We process personal information in compliance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and any applicable national implementing legislation.
This Privacy Policy does not apply to the extent we process personal information in the role of a processor on behalf of our customers. In that context, our customers are the data controllers, and our processing of that personal information is governed by our applicable customer contracts and Data Processing Agreements.
1. Personal Information We Collect
A. Personal Information You Provide to Us
Account and Registration Information. When you register for our Services, we collect your full name, work email address, phone number, company name, company website URL, industry, sector, company size, location, target markets, and your role within your company. You may also choose to provide a company logo.
Communications. If you contact us directly — including via our contact form, email, or live chat — we may receive your name, email address, the contents of any messages or attachments you send, and any other information you choose to provide.
Brief and Brand Information. To deliver our Services, we collect brand brief information you provide, including target keywords, content tone, target audience description, key messages, topics to cover, and competitor names you wish to track. This information is used solely to deliver your Rankply service.
Payment Information. If you subscribe to a paid plan, your payment information (such as card details) is collected and processed by Stripe, our third-party payment processor. Rankply does not store your full card details — we only receive a payment confirmation and the last four digits of your card for reference.
Newsletter Subscription. If you subscribe to our newsletter, we collect your email address. We record the date and source of your subscription for compliance purposes.
B. Personal Information We Collect When You Use Our Services
Location Information. We infer your approximate location (country and region) from your IP address to determine your preferred currency and language settings.
Device and Usage Information. We automatically collect information about the device and software you use to access our Services, including IP address, device type, browser type and version, operating system, pages visited, referrer URL, and dates and times of visits.
AI Audit Data. As part of delivering our Services, we submit information about your brand (including your website URL, company description, and keywords from your brief) to AI service providers to conduct visibility audits. Please see Section 4 for details of these providers.
Cookies and Similar Technologies. We use cookies and similar technologies as described in Section 6 of this Privacy Policy.
2. How We Use the Personal Information We Collect
We use the personal information we collect to:
- Provide, maintain, improve, and deliver our Services, including running AI visibility audits, generating content recommendations, and publishing content on your behalf
- Create and manage your account
- Process your subscription payments and manage your billing
- Send you transactional emails relating to your account (audit results, publication notifications, billing receipts, and security alerts)
- Send you our monthly newsletter, where you have subscribed
- Respond to your enquiries and provide customer support via live chat and email
- Analyse how our Services are used and improve their functionality
- Detect and prevent fraud, abuse, and security incidents
- Comply with our legal obligations
- Enforce our Terms and Conditions
We do not use your personal information for automated decision-making that produces legal or similarly significant effects on you.
3. Legal Bases for Processing Personal Information
If you are located in the UK or European Economic Area (EEA), we only process your personal information when we have a valid legal basis:
Contractual Necessity. We process your personal information where necessary to provide you with the Services you have requested — including running audits, generating content, managing your account, and processing payments.
Consent. We process your personal information for certain activities only where you have given your explicit consent — including sending marketing emails and newsletters, loading analytics cookies, and loading live chat cookies. You may withdraw your consent at any time (see Section 5).
Legitimate Interests. We process certain personal information where we have a legitimate interest that is not overridden by your rights — including fraud prevention, improving our Services, and internal analytics. We balance our interests carefully against your privacy rights.
Compliance with a Legal Obligation. We process personal information where required by law, including tax, accounting, and regulatory obligations.
4. How We Disclose the Personal Information We Collect
We do not sell your personal information. We disclose it only as described below.
Sub-processors and Service Providers. We share personal information with the following categories of service providers who process data on our behalf. All sub-processors are bound by Data Processing Agreements:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (Ireland) |
| Vercel | Website hosting and deployment | EU and US |
| Stripe | Payment processing and invoicing | US (EU-adequate transfers) |
| Resend | Transactional and marketing email delivery | US |
| Inngest | Background job processing | US |
| Anthropic (Claude) | AI content analysis and generation (brief data processed) | US |
| OpenAI (GPT) | AI content analysis and generation (brief data processed) | US |
| Google (Gemini) | AI content analysis and generation (brief data processed) | US |
| Firecrawl | Website content extraction for audits | US |
| Tawk.to | Live chat support (only if you consent to support chat cookies) | US |
| SiteGround | WordPress blog hosting for client subdomains | EU |
| Google Analytics | Website analytics (only if you consent to analytics cookies) | US |
AI Service Providers. To perform AI visibility audits and generate content recommendations, we submit limited brand data (including your company name, website URL, and keywords from your brief) to the AI providers listed above. We do not submit sensitive personal data to AI providers. All transfers are subject to appropriate safeguards (see Section 11).
Legal Requirements. We may disclose your information where required by law, court order, or regulatory authority, or where necessary to protect our rights, prevent fraud, or ensure the safety of our users.
Business Transfers. In the event of a merger, acquisition, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you of any such change in accordance with this Privacy Policy.
With Your Consent. We may share your information in other circumstances with your explicit permission.
5. Your Choices
Marketing Communications. You can unsubscribe from our newsletter and marketing emails at any time using the unsubscribe link in every email. You can also manage your email preferences from your account settings. Transactional emails (billing receipts, security alerts, account notifications) cannot be opted out of as they are necessary to provide the Services.
Cookie Preferences. You can manage your cookie preferences at any time using the “Cookie settings” link in the footer of our website. See Section 6 for full details.
Your UK and EU Privacy Rights. If you are located in the UK or EEA, you have the following rights:
- Right of access — request a copy of the personal information we hold about you. You can use the data export feature in your account settings.
- Right to rectification — request correction of inaccurate or incomplete personal information.
- Right to erasure — request deletion of your personal information. You can delete your account from your account settings, or contact us directly.
- Right to restrict processing — request that we limit how we use your personal information.
- Right to data portability — receive your personal information in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent — withdraw consent at any time for any processing based on consent, without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at info@rankply.com. We will respond within 30 days. We may ask you to verify your identity before fulfilling your request.
You also have the right to lodge a complaint with a supervisory authority:
- UK: Information Commissioner’s Office (ICO) — ico.org.uk
- Spain: Agencia Española de Protección de Datos (AEPD) — aepd.es
6. Cookies
We use cookies and similar technologies on our website. Cookies are small text files placed on your device that help us operate the Services and understand how they are used.
Cookie Categories
Strictly Necessary Cookies (always active — cannot be disabled)
These cookies are required for the Services to function. They include authentication cookies that keep you logged in and security cookies that protect your account.
| Name | Purpose | Retention |
|---|---|---|
| rankply_session | Authenticates your account session | Session |
| rankply_csrf | Prevents cross-site request forgery | Session |
| rankply_cookie_consent | Stores your cookie preferences | 1 year |
Analytics Cookies (requires consent)
These cookies help us understand how visitors use our website so we can improve it. We use Google Analytics 4.
| Name | Purpose | Retention |
|---|---|---|
| _ga | Google Analytics — distinguishes users | 2 years |
| _ga_* | Google Analytics — session state | 2 years |
| _gid | Google Analytics — distinguishes users | 24 hours |
Support Chat Cookies (requires consent)
These cookies enable our live chat support, powered by Tawk.to.
| Name | Purpose | Retention |
|---|---|---|
| TawkConnectionTime | Tawk.to session management | Session |
| twk_idm_key | Tawk.to visitor identifier | Session |
| twk_uuid_* | Tawk.to unique visitor ID | 6 months |
Managing Cookies
You can manage your cookie preferences at any time by clicking “Cookie settings” in the website footer. You can also configure your browser to block or delete cookies — please refer to your browser’s help documentation. Note that blocking strictly necessary cookies may affect your ability to use the Services.
7. Third-Party Links
Our Services may contain links to third-party websites or services. This Privacy Policy does not apply to those third-party services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you access.
8. Retention
We retain personal information for as long as necessary to provide the Services and comply with our legal obligations. Our specific retention periods are:
- Account and profile data: retained for the duration of your account, plus 90 days after deletion
- Audit results and visibility data: retained for 24 months from the date of the audit
- Billing and payment records: retained for 7 years (UK legal requirement for financial records)
- Email communications: retained for 2 years
- AI audit data (prompt results): retained for 12 months, then archived
- Brief versions: last 20 versions per account
- Newsletter subscriber records: retained indefinitely (consent audit trail), but email is anonymised on deletion request
When you delete your account, we anonymise your personal information within 30 days and permanently delete all data within 90 days, except where retention is required by law.
9. Security
We implement technical and organisational security measures to protect your personal information, including:
- Encryption in transit (TLS/HTTPS on all connections)
- Encryption at rest for all database data (Supabase AES-256)
- Role-based access control — staff access only what they need
- Two-factor authentication required for all admin access
- Regular security review of third-party processors
- Automated error monitoring (Sentry) with PII scrubbing
Despite these measures, no electronic transmission or storage system is entirely secure. We cannot guarantee absolute security of your personal information. If we become aware of a security incident affecting your data, we will notify you and relevant supervisory authorities as required by law.
10. Children's Privacy
Our Services are intended for use by businesses and their representatives. We do not knowingly collect personal information from individuals under the age of 18. If you believe a minor has provided us with personal information, please contact us at info@rankply.com and we will delete it promptly.
11. International Data Transfers
Rankply is based in the United Kingdom and the European Union. Some of our sub-processors are located in the United States and other countries outside the UK/EEA. When we transfer personal information internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission and/or the UK Government, where applicable
- The UK's International Data Transfer Agreement (IDTA) for transfers from the UK
- Adequacy decisions where they exist
A full list of our sub-processors and the transfer mechanisms we rely on is available on request. Contact us at info@rankply.com.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post any changes on this page and update the “Last updated” date at the top. For significant changes, we will notify you by email or by a prominent notice on our website. We encourage you to review this Privacy Policy periodically.
13. Contact Information
Rankply is the data controller responsible for your personal information.
Email: info@rankply.com
Registered office:
Rankply
950 Great West Road
Brentford, London
TW8 9ES
United Kingdom
Barcelona office:
Rankply
Plaça de Sant Josep Oriol, 4
Ciutat Vella, 08002
Barcelona, Spain
For data protection enquiries, please email info@rankply.com with the subject line “Data Protection Request”.