Rankfor.AI Privacy Policy
Last updated: 16 September 2026 Data Controller: Rankfor.AI Sp. z o.o., ul. Skarbowców 23B, 53-025 Wrocław, Poland • dpo@rankfor.ai This policy explains what we collect, why, how we use it, and your rights under GDPR.
1) What we collect
- Account & identity: name, email, company, role.
- Auth & logs: login timestamps, session IDs, IP address, user agent.
- Product usage: features used, prompts/inputs you submit, generated artifacts, error telemetry.
- Billing (if paid): billing contact, address; card data handled by our processor (we don't store PANs).
- Content context: public URLs you scan; we process publicly available content for analysis.
- Meeting bookings: name, email, company and the slot you pick, entered in the scheduler embedded on our site. You do not need an account to book.
- Data from other sources: for business-to-business outreach we also collect data about you from somewhere other than you: your name, job title, employer, work email address and the text of your public professional profile. The sources are public professional profiles, public company websites and public forum posts. We use it to decide whether to write to you about our product. We keep it while you are an active prospect and delete it on request.
2) Why we collect (lawful bases)
- Contract (Art. 6(1)(b)): provide the Platform and support.
- Legitimate interests (Art. 6(1)(f)): security, fraud prevention, service improvement, quality analytics (pseudonymous), contacting business prospects about our product, and measuring which advertisement led to a booking by sharing a hashed email address with Google. You can object to either of those last two purposes at any time; section 5 says how.
- Consent (Art. 6(1)(a)): marketing emails; non-essential cookies and analytics.
- Legal obligation (Art. 6(1)(c)): tax and audit records.
3) How we use data
Operate the Platform; secure accounts; measure and improve performance; send service updates; process payments; provide reports/exports; measure which of our advertisements led to a meeting booking, as described in section 5; and (if you opt-in) send marketing. We may use de-identified aggregates to improve reliability and reduce bias.
4) Cookies & tracking
On this website and inside the signed-in product at app.rankfor.ai alike, analytics and marketing scripts load only after you allow them, and refusing keeps them off. Your choice is stored in your browser for a year. Change it whenever you like in Cookie settings, or clear this site's cookies, or write to dpo@rankfor.ai. The Cookie Policy summary in the Terms lists the categories.
5) Sharing (processors/sub-processors)
We use vetted providers. Most act only on our instructions under Article 28 processing agreements. Where a provider also decides for itself how it uses data we send, we say so in that entry.
- AI providers: Google (Gemini and Vertex AI), OpenAI, Anthropic, xAI, Perplexity and Mistral process the prompts, questions and page content you submit, and return the answers and scores the product is built to produce. ElevenLabs turns script text into speech where you use our voice features. All of these providers except Mistral are based in the United States; Mistral is based in the European Union. We use business API plans whose default terms exclude using customer content to train the providers' models, and we do not opt in to training. The exact retention and training position differs by provider and by access plan, so write to dpo@rankfor.ai for the current position on any of them.
- Hosting & infrastructure: Google Cloud and Firebase run our databases, servers and background jobs in EU regions in Finland and Belgium. The data we hold ourselves sits on that infrastructure. Data you hand to a provider directly, such as your card number on Stripe's payment page, never reaches it.
- CRM & scheduling: HubSpot Ireland Limited (EU data centre) is our CRM, and several things on our site are HubSpot's. Its tracking script records the pages you open, your IP address and browser details. Its forms receive the name, email and company you type into them, and on the report-sharing form the link to the report you are sharing. Its live chat receives whatever you write in the chat window. Its meeting scheduler runs in a frame served by HubSpot, so the name, email and company you type into it reach HubSpot directly. We also send it contact records from our own systems: first and last name, email, phone number, LinkedIn address, company, website, and the stage and value of any deal. Purpose: running these tools, holding your contact record, and keeping our correspondence with you in one place.
- Analytics & product measurement: Google Analytics, Google Ads and Google Tag Manager receive your IP address, browser details, the pages you open and the link you arrived from. Google Ads also sets an advertising cookie, _gcl_au, that records the advertisement you arrived from, and on our sales pages a click on the main call-to-action buttons is reported to Google Ads as a conversion. PostHog receives the same plus product usage events and ingests them in the EU; inside the signed-in product it also records screen sessions so we can see how features are used. Purpose: understanding how the site and the product are used, and attributing sign-ups and enquiries to the campaign that produced them.
- LinkedIn advertising: LinkedIn Ireland Unlimited Company runs our advertising campaigns on LinkedIn. Its measurement tag is delivered through the tag manager named above and, once you accept marketing cookies, receives your IP address, browser details and the page you opened. Purpose: measuring which LinkedIn advertisement led to a visit.
- Search Console: Google Search Console, if you connect your own Search Console account to a workspace. Google receives the email address of the account that grants the connection, and we receive the search queries and click statistics for the site you connect. Search queries are free text and can carry personal data.
- Advertising measurement: Google Ireland Limited, with Google LLC processing outside the EEA. When you book a meeting we send a SHA-256 hash of your email address, the time of the booking, a label identifying the booking as a conversion, our own reference for the meeting, and two consent signals. Google never receives the plain-text address from this flow. The two consent signals are set once for the whole account and are identical on every upload; they do not record a decision you made. Purpose: measuring which of our advertisements produced the booking, and improving how our bids are set. Google also uses data of this kind for its own purposes, including improving automated bidding across advertisers and detecting invalid activity. We do not instruct those uses.
- Outreach & enrichment: When we build a prospect list for business-to-business outreach, several providers act for us. Instantly sends the email sequences. Unipile carries LinkedIn invitations and messages. Clay and enrich.so look up a work email address and job details from a name, a company and a public profile. Each of them receives the business contact details we hold for that person and returns what it finds.
- Internal email & chat: Google Workspace holds our own mailboxes and our internal chat. When someone replies to one of our outreach messages, an alert naming that person is posted into our internal chat so a colleague can pick it up.
- Security & abuse prevention: Google reCAPTCHA Enterprise checks whether a visitor to our public tools is a person or a bot. It receives your IP address, browser details and interaction signals, and returns a risk score to us.
- Email delivery: Hostinger delivers the email our public site sends: readiness reports, marketplace order confirmations, sign-in links and digests. A second mail provider delivers the email the product sends: sign-in and password-reset links, invitations, order confirmations and the reports you ask for. Both receive the recipient address and the content of the message. Write to dpo@rankfor.ai for the name of the second provider.
- Fonts, media & embedded content: Our pages load icons, brand logos, site thumbnails, country flags and video players from Google (its website-icon service and YouTube), DuckDuckGo, thum.io and flagcdn. Loading them sends your IP address and browser details to those providers, including on a report you open from a share link. We send them nothing else about you.
- Payments: Stripe (EU and US) handles checkout, billing and subscriptions. It receives your email address and order details, and for book orders also your first name, surname, company and postal address. It collects card details on its own hosted page; card numbers never reach our systems.
Advertising measurement
In plain terms. Sending a hashed email address to Google happens only when you book a meeting through the scheduler on our site. Nothing else you do on the site sends your email address to Google.
When a booking is confirmed we tidy the address the way Google requires before hashing it: spaces removed and everything in lower case, and for Gmail addresses the dots and anything after a plus sign taken out of the first part. Then we turn it into a SHA-256 hash before it leaves our systems.
With that hash we send the time of the booking, a label that marks the booking as a conversion, our own reference for the meeting so that Google discards a repeat upload, and the two consent signals.
Google compares the hash with the hashed email addresses of its own account holders. A match tells us which advertisement led to the meeting and lets Google's bidding learn from it. A hash cannot be read back into an address, and it is still information about you: the same address always produces the same hash, which is exactly what makes the match work.
We use this for measurement and bidding. We do not use it to build advertising audiences. Google's terms let an advertiser instruct Google to turn this same upload into a targeting list. We give no such instruction, and nothing in what we send asks for one.
What we can and cannot undo. Deleting your contact record stops every future upload, because the hash is computed from that record at the moment of upload. For an upload we already made, we ask Google to remove it through the advertiser controls on our account; that request is made by hand, and we cannot verify Google's deletion from our side. We cannot remove a booking's effect on Google's bidding once it has fed it, because that learning is already blended into Google's models and cannot be separated out again.
Google publishes its own description of what it does with data that businesses send it. See Google's Business Data Responsibility site. It also lists the advertising settings you can change in your own Google account.
To stop this sharing for your bookings, or to have an upload we already made removed, write to dpo@rankfor.ai from the address you used to book.
We don't sell personal data.
6) Retention
- Account data: while active + 30 days after deletion request.
- Scan cache: ~24 hours; auto-purged.
- Reports/outputs you keep: until you delete or close account (+30 days).
- Billing records: 7 years (legal).
- Anonymized analytics: may be kept longer; cannot identify you.
- Advertising measurement: we keep no separate copy of the hash. It is computed from your contact record at the moment of upload, so deleting that record stops any further upload. We keep one record per booking: whether it was sent, when, and why it was not, so the same booking is never sent twice. We delete that record after 120 days, a month past the 90-day window in which Google can still count a conversion for a click. Google publishes no retention period for hashes it has already received.
7) International transfers
When data leaves the EEA (for example to OpenAI, to Stripe US, or to Google LLC in the United States for advertising measurement), we use Standard Contractual Clauses. Our contracting party for advertising measurement is Google Ireland Limited.
8) Your rights (GDPR)
Access, rectify, erase, restrict, portability, object, withdraw consent, and lodge a complaint with your authority (PL: UODO). Request at dpo@rankfor.ai (subject: "GDPR Request"). Response within 30 days.
9) Security
We apply technical/organizational measures (encryption in transit, access controls, audit trails). We'll notify you and/or authorities of personal-data breaches as required. (Audit and DPA hooks available for enterprise.)
10) Children
Not for under-18s; we do not knowingly collect children's data.
11) Changes
We'll post updates here and notify of material changes in advance where required.
12) Contact
Data Controller: Rankfor.AI Sp. z o.o., ul. Skarbowców 23B, 53-025 Wrocław, Poland
Privacy: dpo@rankfor.ai • Legal & Support: contact@rankfor.ai