Last updated 2026-08-17
Privacy Policy
This policy explains what personal data RankMerit collects and how it is handled. If you are in the EEA or the UK, we act as data controller for account data and as data processor for the website data you connect.
What we collect
Account data: name, email address, password hash, language preference, and the plan you are on.
Website data you connect: the domains you add, pages we crawl, your Google Search Console metrics (queries, impressions, clicks, positions), keyword lists, and the changes we produce and apply.
Usage data: log entries about actions taken in the application, generation requests and their results, and error diagnostics.
Affiliate data: for partners, referral clicks with a hashed IP address (never the raw address), user agent, referring page and payout details you supply.
Payment data: we do not receive or store card numbers. Payment is handled by our merchant of record, which shares with us only the subscription status and an anonymised reference.
Why we use it
To provide the service: measure your site, generate and apply changes, and report results.
To bill you, prevent fraud, and pay affiliate commissions correctly.
To support you when you contact us, and to send service notices such as billing failures or material changes to these documents.
To improve the service, including quality measurement of generated output. Where used for improvement, data is aggregated or de-identified.
Google account data
When you connect Search Console, RankMerit requests a single Google permission: https://www.googleapis.com/auth/webmasters.readonly. It is read-only. We cannot add, change or remove anything in your Search Console — not properties, not sitemaps, not settings. The write permission that would allow it is deliberately not requested.
What we read: the search queries your site appears for, and their impressions, clicks, average position and click-through rate, together with the list of properties your Google account can access so you can pick the right one.
What we do with it: show you where your pages rank, measure whether our changes moved them, and decide which work to do next. It is shown to you, in your account, and nowhere else.
RankMerit's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell Google user data, do not transfer it for advertising, do not use it to build advertising profiles, and do not use it for creditworthiness or lending purposes. No human at RankMerit reads it except with your explicit permission for support, where required by law, or on de-identified data for security and abuse prevention.
You can disconnect at any time from your account settings, or revoke the permission directly at https://myaccount.google.com/permissions. When you disconnect, we delete the stored access credential immediately and the Search Console metrics we hold for your site within 30 days. Ask [email protected] if you want that done sooner.
Legal basis (EEA/UK)
Performance of a contract, for everything necessary to deliver the subscription you bought.
Legitimate interests, for security, fraud prevention, and improving the service — balanced against your rights.
Legal obligation, for tax and accounting records.
Consent, only where separately requested, such as marketing email. You can withdraw it at any time.
Who processes it
Hosting and databases operated by us on dedicated servers.
Our merchant of record, for payment processing, invoicing and tax.
AI model providers, for generating output. On plans where you connect your own keys, generation runs on your provider account under your agreement with them.
Search and SEO data sources, including the Google Search Console API and the Google Ads API, accessed with the authorisation you grant.
Email delivery for transactional messages.
We do not sell personal data, and we do not share it for advertising purposes.
International transfers
Some processors are located outside your country. Where data leaves the EEA or the UK, transfers rely on adequacy decisions or standard contractual clauses.
How long we keep it
Account and website data: for as long as your account is active, then deleted or anonymised within 90 days of closure unless we must keep it longer.
Invoices and accounting records: as required by law, typically ten years.
Logs and diagnostics: up to 12 months.
Affiliate click records: 24 months, to resolve commission disputes.
Your rights
You may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests.
Write to [email protected] from your account address. We respond within 30 days. If you are in the EEA or UK you may also complain to your local supervisory authority.
Cookies
We use a session cookie to keep you signed in, and an affiliate attribution cookie that lasts 60 days when you arrive through a partner link. We do not use advertising or cross-site tracking cookies.
Security
Passwords are stored hashed. Traffic is encrypted in transit. Application databases are isolated per product and are not reachable from the public internet. Affiliate IP addresses are stored as one-way hashes.
No system is perfectly secure. If a breach affects your personal data we will notify you and, where required, the relevant authority without undue delay.
Children
The service is for business use and is not directed at anyone under 18. We do not knowingly collect their data.
Contact
Privacy questions: [email protected].