Skip to main content
Rankori

Legal

Privacy Policy

Version 2.0 · Last updated 28 August 2026

This policy explains what personal data Rankori collects, why, who we share it with, and the rights you have over it — whether you're a visitor, a prospect, or a member of a customer organization.

On this page

  1. 1. Who We Are
  2. 2. Summary of Key Points
  3. 3. Table of Contents
  4. 4. Key Definitions
  5. 5. Information We Collect
  6. 6. How We Use Your Information
  7. 7. Legal Bases for Processing (GDPR)
  8. 8. When and With Whom We Share Your Information
  9. 9. International Transfers of Personal Data
  10. 10. Cookies and Other Tracking Technologies
  11. 11. How Long We Keep Your Information
  12. 12. How We Protect Your Information
  13. 13. Children's Privacy
  14. 14. Your Privacy Rights — GDPR / UK / Switzerland
  15. 15. Your Privacy Rights — US State Privacy Laws
  16. 16. Do-Not-Track and Global Privacy Control Signals
  17. 17. Data Deletion
  18. 18. Data Portability
  19. 19. Governing Law
  20. 20. Changes to This Policy
  21. 21. Contact Us

1. Who We Are

Rankori is a multi-tenant Software-as-a-Service (SaaS) platform providing search visibility, keyword tracking, competitor intelligence, and LLM citation-visibility tools for businesses and agencies.

Data Controller / Business:
Nurami Digital B.V., the company operating the Rankori platform
Contact: contact@nuramidigital.com

Under the GDPR, Nurami Digital acts as the data controller for the personal data described in this policy. Under US state privacy laws, Nurami Digital acts as the business with respect to the personal information it collects about its own website visitors, prospects, and account users.

Scope. This policy covers personal data we collect about you as a visitor, prospect, account holder, or member of a customer organisation using Rankori. It does not govern the keyword, competitor, or SERP data itself, which is business data about search results and websites rather than personal data about you — except where such data incidentally includes personal information (for example, a named individual appearing in search results). Where a Rankori customer uses the platform to process personal data about its own end customers (for example, via the integrations described in Section 5.5), we act as a processor/service provider on that customer's behalf under the terms of our Data Processing Agreement, not as controller — that relationship is governed by the DPA, not this policy.

2. Summary of Key Points

This summary is for convenience only — the full sections below control.

  • We collect account and identity data (name, email, password hash), technical and usage data, the business and SEO data you configure (keywords, domains, SERP snapshots, AI-visibility prompts), and billing data.
  • We use it to run the service, secure your account, and bill you.
  • We share data with a defined list of sub-processors (Section 8) covering hosting, email, payments, error monitoring, bot detection, and — for customers on AI Visibility plans — LLM providers. We do not sell your personal information or share it for cross-context behavioral advertising, and we run no advertising cookies.
  • We retain data on the schedules in Section 11, and delete it on account or organisation deletion (Sections 17–18).
  • If you are in the EEA, UK, or Switzerland, you have GDPR rights (Section 14). If you are a US resident in a state with a comprehensive privacy law, you have parallel rights under that law (Section 15).
  • Questions or requests: contact@nuramidigital.com.

3. Table of Contents

See “On this page” above for a linked table of contents.

4. Key Definitions

TermMeaning
Personal Data / Personal InformationInformation that identifies, relates to, or could reasonably be linked with an identified or identifiable individual.
Controller (GDPR)The entity that determines the purposes and means of processing personal data — Nurami Digital, for the data described in this policy.
Processor (GDPR) / Service Provider (CCPA/CPRA)An entity that processes personal data on a controller's or business's behalf and under its instructions — the role our sub-processors play for us, and the role we ourselves play for a customer's end-customer data under a DPA.
Sub-processorA third party a processor engages to help process personal data on the controller's behalf (Section 8).
OrganisationA tenant workspace within Rankori. Every business record belongs to exactly one organisation.
ServicesThe Rankori web application, background workers, LLM orchestrator, and analytics engine, collectively.

5. Information We Collect

5.1 Account and Identity Data

  • Full name — provided at registration
  • Email address — authentication, transactional notifications, account management
  • Password — stored only as a salted scrypt hash, never in plaintext

5.2 Technical and Usage Data

  • IP address — captured at login and in audit log entries for security and fraud prevention
  • Session identifiers — stored in an HttpOnly, SameSite cookie to maintain your authenticated session
  • Usage data — actions taken within the platform and timestamps of that activity, recorded in the audit log
  • Browser and device information — user agent string, used for security logging
  • Aggregate product analytics — page-view counts collected via a self-hosted Umami instance. Umami sets no cookies and does not track you across websites or sessions; we use it only to understand aggregate feature usage, never to build an individual profile of you. This tracking runs in production only.
  • Bot-detection signals — when you register or request a password reset, hCaptcha evaluates your browser session to distinguish humans from automated abuse. See Section 8.

5.3 Business and SEO Data (User-Provided)

  • Keywords you configure for tracking
  • Tracked domains — your website and competitor domains
  • SERP snapshots and keyword ranking data (position, volume, difficulty, cost-per-click, and related metrics) retrieved on your behalf from our data provider
  • Competitor intelligence data — overlap scores, visibility scores, and SERP-discovered competitor domains
  • Site audit data — crawl results, page-level findings, issues, and backlink snapshots for URLs you submit
  • Organisation and project configuration — organisation name, project settings, branding assets
  • Reports — generated PDF and PowerPoint reports based on your data
  • AI-visibility prompts and LLM responses — for customers on plans with AI Visibility enabled: the prompts you configure, the raw responses returned by third-party LLM providers when we run those prompts on your behalf, and the citations, brand and entity mentions, and sentiment we extract from those responses

5.4 Billing Data

  • Subscription status — plan type and lifecycle state (trial, active, cancelled, locked)
  • Payment processing data — handled entirely by Paddle, our payment processor and Merchant of Record. We do not store card numbers or full payment instrument details.

5.5 Information From Third Parties

If your organisation connects an integration (for example GA4, Google Search Console, Google Business Profile, Google Ads, Meta Ads, Facebook, Instagram, AdRoll, or CallRail), we receive the account-performance data that integration exposes, on your organisation's instructions, for display inside the platform. This data is processed under the terms of your organisation's DPA with us, not under this policy directly (see the Scope note in Section 1).

6. How We Use Your Information

  • Providing and operating the Services (account management, keyword tracking, competitor analysis, site audits, report generation, AI-visibility scoring)
  • Authenticating you and securing your account
  • Billing and subscription management
  • Security, fraud prevention, and audit logging
  • Monitoring and improving service reliability (error telemetry via Application Insights, aggregate product analytics via Umami)
  • Sending transactional communications (email verification, password reset, organisation invitations, report and notification delivery)
  • Complying with legal obligations, including financial record-keeping

We do not currently operate a marketing mailing list. If we introduce one, it will be opt-in, and we will update this policy before doing so.

7. Legal Bases for Processing (GDPR)

PurposeData UsedLawful Basis
Account management and authenticationName, email, password hash, session tokenPerformance of contract — Art. 6(1)(b)
Providing the SEO, audit, and AI-visibility serviceKeywords, domains, SERP snapshots, ranking data, competitor data, audit results, reportsPerformance of contract — Art. 6(1)(b)
Billing and payment processingEmail, subscription status, billing methodPerformance of contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c)
Security, fraud prevention, audit loggingIP address, session data, usage events, audit logLegitimate interest — Art. 6(1)(f)
Service improvement and error monitoringUsage data, aggregate product analytics, error telemetryLegitimate interest — Art. 6(1)(f)
Bot detection on registration and password resetBrowser session signals passed to hCaptchaLegitimate interest — Art. 6(1)(f), protecting the platform from automated abuse
Transactional emailsEmail addressPerformance of contract — Art. 6(1)(b)
Preventing repeated abuse of free-trial offersKeyed, non-reversible hash of the signup emailLegitimate interest — Art. 6(1)(f)

US state privacy laws do not require an enumerated “legal basis” in the GDPR sense; Section 15 covers the disclosures those laws do require.

8. When and With Whom We Share Your Information

We share personal data only with the sub-processors below, each engaged to help us deliver the Services and each contractually bound to process data solely on our instructions and in compliance with applicable law. We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.

ProcessorPurposeLocation
Microsoft AzureCloud infrastructure and hosting (compute, storage, database), plus error and performance monitoring (Application Insights)EU — West Europe (Netherlands)
DataForSEOSERP data retrieval, keyword metrics, related keyword discoveryEU (Lithuania)
ResendTransactional email deliveryUSA (SCCs apply)
PaddlePayment processing and subscription management (Merchant of Record)USA / UK (SCCs apply)
hCaptcha (Intuition Machines, Inc.)Bot detection on registration and password resetUSA (SCCs apply)
OpenAIRuns AI-visibility prompts and returns responses (AI Visibility plans only)USA (SCCs apply)
Perplexity AIRuns AI-visibility prompts and returns responses, including source citations (AI Visibility plans only)USA (SCCs apply)
Google (Gemini API)Runs AI-visibility prompts and returns responses (AI Visibility plans only)USA (SCCs apply)

The AI-visibility processors are engaged only for customers on a plan with AI Visibility enabled. Other customers' prompt and response data is never sent to them.

We may also disclose personal data to comply with a legal obligation, subpoena, or valid governmental request; to protect the rights, property, or safety of Nurami Digital, our users, or the public; or in connection with a merger, acquisition, financing, or sale of business assets, subject to standard confidentiality protections.

We will notify affected customers in advance of any change to this sub-processor list that may affect the processing of their personal data.

9. International Transfers of Personal Data

Our infrastructure and primary data storage are located in the European Union. Several sub-processors listed in Section 8 are located in, or process data in, the United States. Where we transfer personal data originating in the EEA, UK, or Switzerland to a country not deemed to provide an adequate level of protection, we rely on the EU Standard Contractual Clauses — and the UK International Data Transfer Addendum where applicable — with each such sub-processor, together with supplementary technical and organisational measures where warranted.

10. Cookies and Other Tracking Technologies

Rankori uses one strictly necessary cookie. We run no advertising, profiling, or cross-site tracking cookies.

CookieTypePurposeDuration
Session authentication cookieStrictly necessary, HttpOnly, SameSiteKeeps you signed inExpires 7 days after it was last refreshed; cleared on sign-out

We also store a single flag in your browser's local storage to remember that you have dismissed the cookie notice, so it is not shown again on every visit. It contains no identifier and is never transmitted to us.

Protection against cross-site request forgery is provided by same-origin request validation performed on the server, not by a cookie.

Two of our sub-processors operate on their own domains, outside the application's cookie scope, and we do not control their cookies:

  • Paddle operates a hosted checkout on paddle.com and may set cookies there. Paddle sets no persistent tracking cookies on the Rankori domain.
  • hCaptcha's challenge widget, embedded on the registration and password-reset pages, may set its own cookies as part of verifying that you are not a bot.

Our aggregate product analytics (Section 5.2) run through a self-hosted Umami instance, which is cookieless by design.

Because the application itself uses only a strictly necessary cookie, we are not required to obtain your consent for cookie use under the ePrivacy Directive or the GDPR. We display an informational cookie notice on your first visit regardless.

11. How Long We Keep Your Information

Retention is enforced automatically by a nightly job. The windows marked configurable are set by an environment variable and may be shortened or lengthened; the values below are the defaults in force.

Data CategoryRetention Period
Active sessionsExpire 7 days after they were last refreshed; expired session records are purged by the nightly job
Verification tokens (email verification, password reset)Deleted 7 days after the token itself expires — a short grace period for delivery delays
Keyword and SERP snapshots365 days (configurable); older records purged automatically
Site audit data (audit runs, crawled pages, issues, backlink snapshots)90 days (configurable); older records purged automatically
AI-visibility LLM responses (raw response text and archived response objects)90 days (configurable). The citations, mentions, and computed visibility scores derived from a response are retained separately on the keyword/SERP snapshot schedule above, since they no longer contain the underlying response text
Usage snapshots (plan and quota accounting)400 days (configurable)
Payment-provider webhook events30 days (configurable)
Audit logRetained for as long as the organisation exists. Entries are anonymised when a user deletes their account, and deleted outright when the organisation is deleted (Section 17)
Account data (name, email, organisation memberships)Deleted when an account-deletion request is processed (Section 17)
Organisation data (projects, keywords, rankings, reports, audits, integrations)Deleted when an organisation-deletion request is processed (Section 17)
Billing and subscription records7 years from the transaction, in compliance with legal accounting and tax obligations — Art. 6(1)(c) GDPR
Trial-eligibility ledger (a keyed, non-reversible HMAC hash of the email that started a free trial)Retained indefinitely, including after organisation deletion — legitimate interest, Art. 6(1)(f), preventing repeated abuse of free-trial offers

12. How We Protect Your Information

  • Passwords are stored only as salted scrypt hashes, never in plaintext.
  • Integration access tokens and SERP-provider credentials are encrypted at rest with AES-256-GCM before being written to the database, and are decrypted only inside the relevant connector code — never in application route handlers.
  • Report share tokens are generated with a cryptographically secure random number generator and compared using a timing-safe comparison, to resist both guessing and timing attacks.
  • Every business record is scoped to an organisation. Every query against tenant data enforces that scope, and every mutating action requires an explicit permission check, so one customer's data is not reachable from another customer's session.
  • Requests that change data are validated against the request origin to prevent cross-site request forgery.
  • Data in transit is encrypted using TLS.
  • Sensitive account actions are rate-limited, and all password reset events revoke every existing session for that account.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.

13. Children's Privacy

Rankori is a business-to-business platform intended for professional use by adults. It is not directed to, and we do not knowingly collect personal information from, individuals under 16. If we learn that we have inadvertently collected such information, we will delete it. Contact contact@nuramidigital.com if you believe a child has provided us with personal information.

14. Your Privacy Rights — GDPR / UK / Switzerland

If you are located in the EEA, UK, or Switzerland, you have the following rights:

  • Right of access (Art. 15): a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): correction of inaccurate or incomplete personal data.
  • Right to erasure (Art. 17): deletion of your personal data where no overriding ground exists for us to continue processing it. Billing records are retained for the legally required 7-year period even after account deletion.
  • Right to data portability (Art. 20): a machine-readable copy of the personal data you provided to us.
  • Right to restriction of processing (Art. 18): restriction of processing in certain circumstances, such as while a rectification request is being resolved.
  • Right to object (Art. 21): objection to processing carried out on the basis of legitimate interest. We will stop unless we can demonstrate compelling legitimate grounds that override your interests.
  • Right to withdraw consent (Art. 7(3)): where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
  • Right to lodge a complaint: with your local supervisory authority. For the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). You may also contact the authority in your own country of residence.

To exercise any of these rights, contact contact@nuramidigital.com. We aim to respond within 30 days.

15. Your Privacy Rights — US State Privacy Laws

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or another US state with a comprehensive consumer privacy law, that law generally gives you the right to:

  • Know and access — request what personal information we have collected about you and why.
  • Delete — request deletion of your personal information, subject to legal exceptions such as our 7-year billing-record retention obligation.
  • Correct — request correction of inaccurate personal information.
  • Data portability — receive your personal information in a portable format.
  • Opt out of sale or sharing — as stated in Section 8, we do not sell personal information and do not share it for cross-context behavioral advertising. There is accordingly nothing to opt out of; we describe the right for completeness and will honour it if our practices ever change.
  • Opt out of targeted advertising — we do not serve targeted advertising, so this right is likewise not currently engaged.
  • Limit the use of Sensitive Personal Information — we do not collect Sensitive Personal Information as defined under the CPRA, such as government identification numbers, precise geolocation, health data, or biometric data, in the ordinary operation of the Services.
  • Non-discrimination — we will not discriminate against you for exercising any of these rights.
  • Appeal — if we decline a request, you may appeal, and our decision will explain how.

How to exercise these rights: email contact@nuramidigital.com. We will verify your identity, typically by confirming that you control the account email address, before acting on the request. We will respond within 45 days, extendable once by a further 45 days where permitted by law. You may use an authorised agent to submit a request on your behalf; we may require proof of that agent's authorisation.

16. Do-Not-Track and Global Privacy Control Signals

Some browsers offer a “Do Not Track” (DNT) signal. There is no accepted industry standard for how a website must respond to it, and we do not currently treat DNT traffic differently. Because we neither sell nor share personal information and serve no targeted advertising, a Global Privacy Control (GPC) signal has no substantive effect on our processing today. We will treat a GPC signal as a valid opt-out of sale or sharing under the CCPA/CPRA if our practices ever change to include either.

17. Data Deletion

Account deletion

You may delete your Rankori account at any time:

  1. In-app: use “Delete my account” in Account Settings and confirm when prompted.
  2. By contacting us: email contact@nuramidigital.com and we will process your request within 30 days.

If you are the sole owner of an organisation, that organisation must first be transferred to another owner or deleted — we will tell you which organisations are blocking the request. This protects the other members of the organisation and any data they rely on.

Once an account deletion completes:

  • Your name, email address, credentials, and active sessions are permanently deleted.
  • Any outstanding email-verification and password-reset tokens for your address are deleted.
  • Existing audit log entries that referenced you are anonymised — your user identifier is replaced with a non-identifying placeholder — so the security record of what happened survives without remaining linked to you.
  • Billing and subscription records are retained for 7 years as required by law, and are no longer associated with a live account.
  • Organisation data is not deleted by deleting your account. Keywords, rankings, reports, audits, and integrations belong to the organisation rather than to you individually, and remain available to its other members. To remove that data, delete the organisation itself.

Organisation deletion

An organisation owner may permanently delete an organisation and all of its data via “Delete Organisation” in the organisation's Settings, confirming by typing the organisation's identifier. An organisation with an active subscription must be cancelled first.

Deletion is processed as a background job shortly after the request. Once complete:

  • All projects, keywords, rankings, reports, site audits, integrations, prompt libraries, and AI-visibility runs belonging to the organisation are permanently deleted.
  • Uploaded files and generated exports — branding logos, report PDFs and PowerPoint files, and archived raw LLM responses — are deleted from object storage.
  • The organisation's audit log is deleted outright.
  • Retained by design: billing and subscription records (7 years, as above), usage snapshots used for plan and quota accounting, and the trial-eligibility ledger entry described below.
  • The trial-eligibility ledger keeps a keyed, non-reversible hash derived from the email address that started the free trial. It does not identify you directly, cannot be reversed back into your email address, and exists solely to stop the same person from obtaining unlimited free trials by repeatedly creating and deleting organisations. This is retained under our legitimate interest in preventing abuse of free-trial offers (Art. 6(1)(f) GDPR).

18. Data Portability

You can download a copy of your personal data at any time:

  1. In-app: use “Download my data” in Account Settings. This produces a rankori-data-export.json file.
  2. By contacting us: email contact@nuramidigital.com.

The export contains the personal data we hold about you: your profile (identifier, name, email address, and account creation date), every organisation you belong to (name, identifier, your role, and the date you joined), and a per-organisation summary of the data associated with your memberships, given as counts of keywords, tracked competitors, and reports.

It does not include raw keyword or SERP data, site audit results, report contents, or payment records. That material is operational business data belonging to the organisation rather than personal data about you, and is available to organisation members directly inside the platform. If you need it in another form, contact us.

19. Governing Law

For personal data of individuals in the EEA, UK, or Switzerland, this policy and our processing are governed by the GDPR (Regulation (EU) 2016/679) and applicable national implementing legislation. For personal information of US residents, the applicable US state privacy law governs the rights described in Section 15. Our operations are based in the European Union.

20. Changes to This Policy

We may update this policy from time to time to reflect changes in our practices, technologies, legal requirements, or other operational reasons.

For material changes — changes that affect how we use your personal data, or that reduce your rights — we will notify you by email to the address associated with your account, and by a notice in the platform, at least 14 days before the change takes effect. Minor or editorial changes update the version and date above without individual notice.

If you continue to use Rankori after a material change takes effect, we will take that as acknowledgement of the updated policy. If you do not agree with the changes, you may delete your account before they take effect.

21. Contact Us

Email: contact@nuramidigital.com

Subject line: “Data Protection Request — [Your Name]”

We aim to respond to all requests within 30 days, or within the statutory period that applies under Sections 14 and 15.

© 2026 Nurami Digital B.V.
Pricing Terms of Service Privacy Policy Data Processing Agreement Refund & Cancellation Policy