Privacy Policy
Version and effective date: August 21, 2026. Rankelo is a product by Brandsap operating from Nagpur, Maharashtra, India. Privacy and grievance contact: contact@brandsap.com.
1. Scope and roles
This Policy applies to Rankelo websites, accounts, workspaces, support, and product operations. Brandsap determines why account, billing, security, and product-use data is processed. For website, analytics, repository, or business data a customer submits or connects, the customer generally determines the purpose and Brandsap processes it to provide Rankelo. The DPA provides additional business-customer terms.
2. Data we collect
We collect account identifiers, profile details, authentication and consent records; workspace membership and settings; billing plan and payment references from Razorpay, but not full card credentials; support communications; security logs, IP-derived hashes, device and user-agent data; product usage and performance events; URLs and content you direct Rankelo to crawl; business facts, prompts, generated drafts, approvals, publications, and measurements; OAuth tokens and API keys you provide; and integration data such as Google Search Console, GA4, GitHub, and CMS records.
3. Sources
Data comes from you, organization administrators, connected providers, sites you authorize Rankelo to access, public web sources, Common Crawl, self-hosted OpenSERP results, and service/security telemetry. We label estimates, simulations, and unavailable signals rather than representing them as observed facts.
4. Purposes and legal grounds
We use data to create and secure accounts; provide crawling, analysis, AI, publishing, measurement, billing, support, and exports; honor preferences and contracts; prevent fraud and abuse; comply with law; and improve reliability. Depending on applicable law, processing is based on contract, consent, legitimate interests balanced against rights, or legal obligation. We do not sell personal data. We do not enable OpenRouter prompt logging and request privacy-preserving routing for customer content. If that policy cannot be satisfied, the AI request is refused.
5. Sharing and subprocessors
We share only what is reasonably needed with providers selected or required for a feature, such as hosting and database infrastructure, SMTP delivery, OpenRouter when configured, Google when connected, Razorpay for billing, GitHub or a CMS when publishing, and security tooling. The current categories and purposes are listed on the Subprocessors page. We may disclose data to comply with valid law, protect users, investigate abuse, or complete a business reorganization subject to appropriate protections.
6. International processing
Providers may process data outside your state or country. We select configurations and contractual safeguards appropriate to the service and applicable law. Customers should assess their own transfer requirements before connecting a provider or submitting regulated data.
7. Retention
Default operational targets are: raw crawl bodies and transient artifacts, up to 90 days; security and audit logs, up to 365 days; product analytics, up to 365 days; encrypted backups, 14 days; and post-termination export availability, up to 30 days. Durable workspace records remain while the account is active or as needed for the service, disputes, fraud prevention, billing, or legal obligations. Deletion propagates to active systems and later to rotating backups, subject to technically necessary and legally required exceptions.
8. Security
Controls include tenant authorization, server-side sessions, CSRF protection, rate limits, network target validation, least-privilege OAuth scopes, encryption of integration credentials, audit logs, dependency and secret scanning, backups, and restricted internal services. No system is perfectly secure. Report concerns to contact@brandsap.com.
9. Your choices and rights
You may update account details, manage members, disconnect integrations, delete a workspace key, export supported data, request account deletion, and manage optional cookies. Subject to applicable law, you may request access, correction, erasure, restriction, portability, withdrawal of consent, or grievance review. We may verify identity and authority before acting. Withdrawal does not invalidate earlier lawful processing and may make a requested feature unavailable.
10. Children
Rankelo is a business service and is not directed to children. Do not submit a child’s personal data unless you have a lawful basis and Rankelo has expressly agreed to the use case.
11. Automated processing
Rankelo produces scores, recommendations, simulations, and drafts, but customers control consequential publishing and business decisions through configured approvals. Rankelo does not claim to make legally significant decisions about individuals.
12. Changes and grievances
We will update the version date when this Policy changes and provide reasonable notice of material changes. Send privacy requests or grievances to contact@brandsap.com with enough detail to locate the account. We aim to acknowledge requests promptly and respond within the period required by applicable law.
This policy is designed around India’s digital-personal-data framework and common SaaS privacy principles, but it is not a certification of compliance and should receive professional review as the service and applicable law evolve.