4. Information We Collect
4.1 Information You Provide Directly
We collect information you voluntarily provide when you create an account, configure your workspace, or communicate with us. This typically includes:
– Account and Profile Information: Full name, business or organisation name, job title, email address, login credentials, and optional profile information.
– Business and Billing Information: Company name, billing address, VAT or tax ID (where applicable), subscription plan details, and billing history. Payment card data is processed by our payment processor (such as Stripe) and is not stored in full on RankX servers.
– Workspace and Project Information: SEO projects you create (domains, URLs, keywords, competitor lists), configuration settings, saved dashboards, and notes.
– Support and Communications: Messages you send to us via email, support tickets, or feedback forms; survey responses and product feedback
Authentication credentials and role‑based access control (RBAC) data may be stored in managed databases (for example, Supabase or PostgreSQL instances hosted in EU/UK regions) with encryption at rest and in transit
4.2 SEO and Analytics Data
As an SEO analytics and AI content platform, we process specific types of data on your behalf:
– Search and Performance Metrics: Keywords, rankings, impressions, clicks, positions, and other SEO metrics pulled from integrated data sources (for example, search APIs, Google Search Console, or DataForSEO).
– Site and Content Metadata: Page URLs, titles, meta descriptions, internal linking data, schema markup, and technical SEO signals.
– Generated Content: Drafts, outlines, and articles generated via large language models based on prompts, brand guidelines, and content you provide.
We typically process this information as a data processor on your behalf, meaning you determine what data is collected and how it is used, while we provide the platform and infrastructure
4.3 Integration and Connector Data
When you connect third‑party services to RankX (for example, WordPress via our plugin, other CMSs, search or analytics tools), we collect the minimal credentials, tokens, and configuration data necessary to provide and maintain the integration. This may include:
– OAuth tokens or API keys issued by the third‑party.
– Site identifiers (e.g., domain names, site IDs, property IDs).
– Publish settings and content mapping information (e.g., which posts, pages, or blogs you choose to manage through RankX).
We do not collect, store, or process more data from connected platforms than is required to deliver the integration you configure. For example, our WordPress connector is designed to work primarily with site and content data, not your end‑customers’ payment information or other sensitive personal data that you may process on your own website.
4.4 Automatically Collected Information
When you visit our website or use the platform, we automatically collect certain information to operate and secure the Services
– Usage and Activity Data: Pages visited, features used, actions taken, time spent, error events, and performance metrics.
– Device and Technical Information: IP address, browser type, operating system, device identifiers, referral URLs, and approximate location based on IP.
– Cookies and Similar Technologies: Session cookies to keep you signed in, preference cookies, and analytics cookies to understand how the Services are used.
For more details, see our separate Cookie Policy (or cookie banner) which describes the cookies we use and your choices.
4.5 Information from Third Parties
We may receive limited information from third‑party providers, where allowed by law, such as:
– Authentication providers (e.g., Google) providing your name, email address, and profile picture when you sign in using their services.
– SEO data providers (e.g., DataForSEO or search engines) providing performance metrics and search data about your properties.
– Payment processors (e.g., Stripe) providing billing confirmations, partial card information (last four digits, card type), and payment status.