← RankPhoenixPrivacy Policy

Privacy Policy

Last updated: April 12, 2026

This policy explains what information we collect when you use RankPhoenix, how we use it, and what rights you have over it. We have written it in plain English so it is actually readable.

1. What Data We Collect

We collect only what we need to provide the service:

  • Email address — used to log you in and send important account communications (billing, terms updates).
  • Password — stored as a one-way hash (bcrypt via Supabase Auth). We never store or transmit your plain-text password. We cannot recover it — only reset it.
  • Audit inputs — business name, GBP URL, target keyword, and location that you enter when running an audit. These are stored alongside your audit results so you can review them later.
  • Audit results — the scores and recommendations generated by each tool you run. Stored for 12 months.
  • Payment information — handled entirely by Stripe. We never see, store, or process your card number, CVV, or any other raw payment data. We only store a Stripe customer ID so we can manage your subscription.

We do not collect any other personal data. We do not run analytics on individual user behavior beyond what is necessary to operate the platform.

2. Who We Share Data With

We share your data with a small number of trusted third-party services that power RankPhoenix. Each provider has its own privacy policy:

  • Stripe — payment processing. Stripe receives your payment details and billing information directly.
  • Supabase — database and authentication. Your account data and audit results are stored in Supabase.
  • Anthropic — AI analysis. Audit inputs (business name, keyword, GBP data) are sent to Anthropic's Claude API to generate recommendations. Anthropic does not use API inputs to train its models.
  • DataForSEO — SEO data provider. Website URLs and keywords are sent to DataForSEO to retrieve on-page content data.
  • Outscraper — GBP data provider. GBP URLs and business names are sent to Outscraper to retrieve Google Business Profile data.

We do not share your data with any other third parties, and none of these providers are permitted to use your data for their own commercial purposes beyond providing the service to us.

3. We Do Not Sell Your Data

We do not sell, rent, trade, or otherwise transfer your personal data to any third party for commercial purposes. Ever.

This includes data brokers, advertisers, and marketing platforms. We make money by charging for subscriptions, not by monetising user data.

4. How Long We Keep Your Data

  • Audit results — kept for 12 months from the date the audit was run, then automatically deleted.
  • Account data (email, subscription status, billing history) — kept until you request deletion of your account.
  • Payment records — Stripe retains payment history as required by financial regulations, independent of your account deletion.

5. Your Rights

You have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to fix inaccurate data (e.g. your email address).
  • Deletion — request deletion of your account and all associated data. Email us at contact@rankphoenix.io and we will process the request within 30 days.

To exercise any of these rights, email contact@rankphoenix.io from the email address on your account.

6. California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know — you can request disclosure of the categories and specific pieces of personal data we have collected about you.
  • Right to deletion — you can request deletion of your personal data (subject to certain exceptions).
  • Right to opt out of sale — as stated above, we do not sell your data. There is nothing to opt out of.
  • Right to non-discrimination — we will not discriminate against you for exercising any of your CCPA rights.

To submit a CCPA request, email contact@rankphoenix.io with the subject line "CCPA Request".

7. Cookies

We use essential cookies only. These are the session cookies set by Supabase Auth to keep you logged in. They are required for the platform to function.

We do not use:

  • Tracking or analytics cookies (e.g. Google Analytics, Mixpanel)
  • Advertising or retargeting cookies
  • Third-party social media cookies

Because we only use essential cookies, no cookie banner or consent popup is required by law in most jurisdictions.

8. Contact

Privacy questions or requests? Email us at contact@rankphoenix.io. We aim to respond within 2 business days.