Privacy Policy
Last updated: August 2026
This policy explains what information RankingsTracker (operated by Elevation Labs Consulting) collects, how we use it, and the choices you have. We collect the minimum we need to run the Service, and we don't sell your data.
1. Information we collect
- Account information: your name, username, email address, and hashed password (we never store passwords in plain text).
- Workspace data: the clients, keywords, locations, scan results, reports, and Business Profile content you create or connect in the Service. Where a report includes analytics figures, those figures are saved with that report so the report you delivered stays accurate later.
- API credentials: the DataForSEO and AI provider keys you add, stored encrypted at rest and used only to perform your account's operations.
- Billing information: handled by Stripe. We store your plan and subscription status; your card details never touch our servers.
- Usage & log data: standard server logs (IP address, browser type, pages requested) used for security, rate limiting, and troubleshooting.
2. How we use information
- To operate the Service: run scans, track rankings, generate reports, and send transactional email (invites, password resets, notifications).
- To secure the Service: prevent abuse, enforce rate limits, and investigate suspicious activity.
- To bill subscriptions through Stripe.
- We do not sell personal information or use your workspace data for advertising, and no customer can see another customer's data.
3. Third-party processors
We share data only with the processors needed to run the Service:
- DataForSEO: receives the keywords and locations you track (via your own key) to retrieve ranking data.
- Google: Maps rendering and, if you connect them, Business Profile management, Google Analytics, and Google Search Console via Google's APIs.
- Stripe: payment processing and subscription management.
- SendGrid: transactional email delivery.
- Your AI provider (optional): review text you choose to draft a reply for is sent to the provider using your own key.
- Infrastructure providers that host our servers and databases.
4. Google user data
If you connect a Google account, RankingsTracker uses Google APIs to provide the features you ask for. We request the narrowest scopes that do the job, and only for the products you actually connect. This section describes exactly which scopes we request, why, and how the data is handled.
Scopes we request
- Business Profile management (
business.manage) — reads the Business Profile accounts and locations your Google account manages, plus performance insights, posts, and reviews for the locations you choose to import. Used to display insights, publish posts you create, and draft and publish review replies you approve. This is the only scope we request that can write to Google; publishing a post or a reply is not possible without it, and we write only what you have explicitly created or approved in the app. - Google Analytics, read only (
analytics.readonly) — lists the Google Analytics 4 properties your account can see so you can choose one, then reads aggregate traffic figures for the property you map to a client: sessions, users, engaged sessions, average engagement time, sessions by channel, top landing pages, and the key events the property has configured. Used to show traffic next to ranking data inside your account and in the reports you deliver to that client. This scope cannot change anything in Analytics. - Google Search Console, read only (
webmasters.readonly) — lists the Search Console sites your account can see so you can choose one, then reads aggregate search performance for the site you map to a client: clicks, impressions, click-through rate, average position, and top queries. Used for the same reporting purpose. This scope cannot change anything in Search Console.
How that data is handled
- How we use it: only to provide the features above, inside your own RankingsTracker account and the reports you produce from it. We do not use Google user data for advertising or profiling, and we do not use it to develop, improve, or train generalized artificial intelligence or machine learning models. No data is used for any purpose beyond providing these features.
- How we store it: OAuth tokens are stored encrypted at rest and are scoped to your account only. Imported Business Profile data is isolated per customer. Analytics and Search Console figures are read from Google at the moment a page or a report needs them rather than copied into a long-term store; a short-lived cache (about thirty minutes) avoids repeating identical requests. The one exception is that the figures shown in a report you deliver are saved with that report, so it still reads correctly months later. No other customer can see any of it.
- Sharing: we do not sell, transfer, or disclose Google user data to third parties, except as required to operate the Service (our hosting infrastructure) or to comply with applicable law. Google user data is never sent to an AI provider. Humans do not read this data except with your explicit permission for support purposes.
- Revoking access: you can disconnect a Google account at any time in the app — Business Profile under GBP → Connected Accounts, Analytics and Search Console under Settings → Analytics — or at myaccount.google.com/permissions. On disconnection or account deletion we delete the stored tokens. Because analytics figures are not warehoused, disconnecting also ends our access to them immediately, apart from the figures already saved inside reports you have delivered.
RankingsTracker's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Cookies
We use only essential cookies: a session cookie to keep you signed in and a security token to protect forms. We do not use advertising or cross-site tracking cookies.
6. Data retention & deletion
- Workspace data is retained while your account is active.
- If you cancel, your data remains available for export for a reasonable period, then is deleted from active systems and, on schedule, from backups.
- You can request deletion of your account and data at any time at support@rankingstracker.com.
7. Security
All traffic is encrypted with TLS. Stored API keys are encrypted at rest, passwords are hashed, accounts are isolated from one another, and access is protected by rate limiting and security headers. No system is perfectly secure, but we treat your data as confidential and design accordingly.
8. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Contact us and we'll honor them promptly.
9. Changes to this policy
If we make material changes, we'll notify you by email or in the app before they take effect.