Privacy Policy
1. Who we are
Rankvector is operated by Jan Oberpfalzer, an individual entrepreneur registered under the Czech Trade Licensing Act, Company ID (IČO) 76263177, registered at Taškentská 1413/8, Vršovice, 101 00 Prague 10, Czech Republic ("we", "us"). We are the controller of the personal data described in this policy.
For any question about personal data or Google user data, contact us at support@rankvector.ai.
2. What this policy covers
This policy applies to this website, rankvector.ai, and to the Rankvector web application (the "application"). Rankvector is an SEO reporting tool for agencies and in-house teams: it reads data from Google Search Console and Google Analytics 4 with the user's permission and turns it into SEO reports.
Where a customer uploads or connects data about its own clients, we process that data on the customer's behalf as a processor under a data processing agreement. Section 6 describes how we handle Google user data in every case, regardless of that role.
3. This website
The rankvector.ai website uses no cookies, no analytics and no third-party tracking code, and it has no forms. It is hosted by Vercel, which processes the IP address, time of request, page address and browser information of each visit in order to deliver the page and protect it against attacks, and keeps these technical logs only for a short period.
4. Personal data we process in the application
- Account: email address, name (if you provide it) and password. The password is stored only as an irreversible hash (bcrypt), never in readable form. If you sign in with Google, Google gives us only your email address and your Google account identifier.
- Projects and collaboration: project names, website addresses, billing details, tracked competitors, and the email addresses and roles of people you invite to a project.
- Inputs and outputs: what you enter when you run a report, and the reports the application creates.
- Security and operations: IP address and browser information for sign-ins and administrative actions, an action log (who did what and when), pseudonymous fingerprints used to prevent abuse of the free trial (a hash of the IP address and a device fingerprint), and operational and error logs.
- Payments: payments and subscriptions are handled by Paddle as merchant of record. You enter card details directly with Paddle and they never reach us. Paddle sends us information about your subscription and payments, and processes payment data under its own privacy policy.
- Emails: we use your email address for service messages, such as account verification, password reset or a notice that a report is ready.
5. Why we process data and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Running the application and managing your account | account, projects, inputs and outputs, Google user data | performance of a contract, Art. 6(1)(b) GDPR |
| Payments and accounting | subscription and payment information, billing details | performance of a contract and legal obligation, Art. 6(1)(b) and (c) GDPR |
| Security and abuse prevention | IP address, browser information, action log, abuse-prevention fingerprints | legitimate interest, Art. 6(1)(f) GDPR |
| Service emails and support | email address, content of your message | performance of a contract and legitimate interest, Art. 6(1)(b) and (f) GDPR |
We do not send marketing emails without your consent.
6. Google user data
The application connects to your Google account only when you start the connection yourself and grant consent on Google's consent screen.
6.1 Data we access and the scopes we request
| When | Scopes | What we access |
|---|---|---|
| Connecting Google Search Console | openid, email, https://www.googleapis.com/auth/webmasters.readonly | Search Console data: clicks, impressions, click-through rate, average position, search queries, page URLs, sitemaps and indexing status; the email address of the connected account |
| Connecting Google Analytics 4 | openid, email, https://www.googleapis.com/auth/analytics.readonly | Analytics 4 data: traffic, sessions, traffic sources, landing pages, conversions and revenue; the email address of the connected account |
| Sign in with Google | openid, email | your email address and Google account identifier, used only to sign you in |
Both data scopes are read-only. The application never writes, changes or deletes anything in your Google account, and it does not request access to Gmail, Drive, Calendar, Contacts or any other Google service.
6.2 How we use Google user data
We use Google user data only to provide the features you see and run in the application:
- performance overviews of the websites you have added to the application;
- SEO reports you request, in which the application calculates the metrics and a language model writes the interpretation and recommendations.
The email address of the connected Google account is used only to show you which account is connected and to verify that you have access to the website in question.
We do not use Google user data for advertising, retargeting or ad targeting. We do not sell it, we do not use it to build user profiles, and we do not use it to develop, train or improve generalised or non-personalised artificial intelligence or machine learning models.
6.3 Where and how long we store Google user data
The application runs on servers in the European Union.
- OAuth tokens issued by Google are stored encrypted in the application database. They are never written to files or to logs. We keep them until you disconnect the integration or delete your account, and then delete them immediately.
- Retrieved data is cached so that overviews load quickly: for 60 minutes in memory and for at most 90 days in the database cache.
- Calculated metrics and finished reports are kept with your project for 12 months from their creation, then deleted.
6.4 Who we share Google user data with
We share Google user data only to provide the report you requested. To write the text of a report, we send a language model provider the extract needed for that report: calculated metrics, search queries and page URLs for the given website and period. These providers act as our processors, use the data only for that task, and under their commercial API terms do not use it to train their models:
- Anthropic (primary language model provider);
- OpenAI (language model provider for selected types of tasks).
We do not share Google user data with any other third party, except where required by law or where necessary to protect the security of the service. We never share Google user data between customers: each project sees only its own data, and access within a project is governed by user roles. People at Rankvector do not read your Google user data, except with your explicit consent, where necessary for security purposes such as investigating abuse, or to comply with the law.
6.5 How to revoke access and delete your data
- Disconnect in the application: in your project settings, open Integrations and click Disconnect next to Google Search Console or Google Analytics 4. The stored token is deleted immediately and the related cache is cleared.
- Remove access at Google: at myaccount.google.com/permissions you can remove Rankvector's access directly in your Google account.
- Delete your data: delete your account in the application under My account (section 10), which also deletes report files and all connections to Google. You can also ask us at support@rankvector.ai to delete specific reports or data derived from Google sources.
6.6 Limited Use
Rankvector's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Processors and other recipients
We make personal data available only to providers who deliver a specific part of the service:
| Provider | Purpose | Data |
|---|---|---|
| Anthropic | language model that writes report text | extract of report data (section 6.4) |
| OpenAI | language model for selected types of tasks | extract of report data (section 6.4) |
| sign in with Google; source of the Search Console and Analytics data you connect | OAuth tokens, email address | |
| DataForSEO | backlink and search data for selected reports | domains and keywords we query |
| Ahrefs | backlink, keyword and competitor data for selected reports | domains and keywords we query |
| Collabim | ranking data, only if you connect your own Collabim account | your Collabim project identifiers |
| Resend | sending service emails | recipient address and message content |
| Paddle | payments and subscriptions as merchant of record | billing and payment details |
| Vercel | hosting of this website | technical logs of website visits |
We never sell or rent personal data.
8. Transfers outside the European Union
Some providers, including Anthropic, OpenAI, Google and Vercel, are based in the United States and may process data there. Where data leaves the European Economic Area, we rely on a European Commission adequacy decision, including the EU-US Data Privacy Framework for certified recipients, or on standard contractual clauses.
9. How long we keep personal data
- Account and projects: for as long as your account exists.
- Google user data: as set out in section 6.3.
- Account data export: the ZIP file is available for 7 days, then deleted.
- Accounting documents and payment records: for the period required by accounting and tax law, usually 10 years. After account deletion we keep them without your name and email.
- Abuse-prevention fingerprints: pseudonymous, without name or email, kept while they serve to protect the free trial against abuse.
- Database backups: encrypted and overwritten on a rolling basis; deleted data remains in them for at most about 8 weeks.
10. Your rights and how to delete your account
You have the right to access your data, to have it corrected or erased, to restrict processing, to data portability, to object, and to withdraw consent where processing is based on consent. You may also lodge a complaint with the Czech Office for Personal Data Protection (uoou.gov.cz).
- Export your data: in the application, under My account, section Account data, download your account data as a ZIP file. An export can be requested once every 24 hours.
- Delete your account: under My account, section Account deletion. Confirm the request with your password; the account is deleted after 14 days, during which you can cancel the request. An active subscription must be cancelled first.
- Any other request: write to support@rankvector.ai. We respond without undue delay and within one month at the latest.
When an account is deleted, we delete sign-in credentials, project memberships, invitations, share links, connections to Google and other services, branding, and report files. The account record remains only as an anonymous entry without name or email, because accounting documents refer to it.
11. Security
We store passwords as irreversible hashes, encrypt OAuth tokens and integration credentials at rest, and encrypt all communication in transit (TLS). Access is controlled by roles, projects are isolated from each other, sign-in attempts are rate-limited, two-factor sign-in is available, and administrative actions are logged.
12. Automated decision-making
Report text is written by a language model; the numbers in reports are calculated by the application from your data. We do not make decisions about you based solely on automated processing that would have legal or similarly significant effects on you (Art. 22 GDPR).
13. Changes to this policy
We may update this policy when the service or legal requirements change. We will inform account holders about material changes by email before they take effect. The date at the top shows the current version.
14. Contact
Jan Oberpfalzer, Taškentská 1413/8, 101 00 Prague 10, Czech Republic, support@rankvector.ai.