LEGAL / PRIVACY
Privacy Policy
Effective and last updated: August 26, 2026
This Privacy Policy explains how RankFire (“RankFire,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you visit rankfire.cc, request a diagnostic, create an account, connect a third-party service, or use the RankFire platform.
1. Information we collect
Information you provide
- Account details such as name, work email, password-derived authentication records, and organization membership.
- Workspace and product information including websites, brand names, product facts, categories, competitors, target regions, queries, and content approvals.
- Diagnostic information including the submitted website, email recipient, category, competitors, IP-derived abuse-prevention data, and report results.
- Billing and subscription records. Payment-card details are handled by our payment provider and are not stored directly by RankFire.
- Support messages, feedback, and other information you choose to send us.
Information generated through the service
- AI-answer observations, source links, mentions, citations, timestamps, publication records, directory campaign statuses, and audit evidence.
- Device, request, security, session, and usage data needed to operate and protect the platform.
2. How we use information
- Provide diagnostics, PDF reports, workspaces, publishing, monitoring, directory campaigns, and customer support.
- Authenticate users, maintain sessions, prevent abuse, investigate incidents, and enforce service limits.
- Process subscriptions, maintain entitlements, and provide billing records.
- Communicate essential report, account, billing, security, and service updates.
- Improve query selection, reporting quality, product functionality, and reliability.
- Comply with legal obligations and protect the rights and safety of users, RankFire, and others.
3. Google account data
If you choose Google Sign-In, RankFire requests only the identity scopes needed to authenticate you, such as your basic profile, name, email address, and Google account identifier. We use this data to create or sign in to your RankFire account, associate it with the correct workspaces, and secure access. RankFire does not use Google user data for advertising and does not sell it. Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
4. Service providers and disclosures
We disclose information only as needed to operate the service, complete your requested work, comply with law, or protect legitimate rights. Providers may include:
- Cloudflare for hosting, database, network security, and abuse prevention.
- Dodo Payments for checkout, subscriptions, customer billing, and payment events.
- SendHQ for transactional report and account email.
- Sanity for editorial content management.
- Google for optional OAuth authentication and authorized API services.
- OpenAI and other named AI providers when generating time-bound diagnostic observations.
- Professional advisers, authorities, or transaction counterparties where legally required or reasonably necessary.
Publications and approved product facts may become publicly accessible when that is part of the RankFire service you request. Directory submissions necessarily share approved listing information with the relevant directory.
5. Legal bases and choices
Where applicable law requires a legal basis, we process information to perform our contract with you, pursue legitimate interests such as security and service improvement, comply with law, or act on consent. You can decline optional connections, revoke Google access through your Google account, and request closure of your RankFire account.
6. Retention
We retain account, workspace, billing, publication, and audit records for as long as needed to provide the service, establish what work was delivered, resolve disputes, maintain security, and meet legal obligations. Diagnostic lead and report-delivery records are retained only for a commercially and operationally reasonable period. Backups and fraud-prevention records may persist for a limited period after deletion.
7. Security
We use access controls, scoped credentials, encrypted transport, password hashing, revocable sessions, webhook verification, audit records, and service-provider safeguards. No internet service can guarantee absolute security. Please use a unique password and promptly report suspected unauthorized access.
8. International processing
RankFire and its providers may process information in countries other than yours. Where required, we use appropriate contractual or legal safeguards for cross-border transfers.
9. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent. We may verify your identity before fulfilling a request. You may also complain to your local data-protection authority.
10. Children
RankFire is a business service and is not directed to children under 13 or the minimum digital-consent age in their jurisdiction. We do not knowingly collect personal information from children.
11. Changes
We may update this policy as the service or law changes. We will publish the revised date and provide additional notice when a material change requires it.
12. Contact
For privacy questions or rights requests, contact privacy@rankfire.cc.