Legal center

Subprocessors and connected providers

Last updated: August 21, 2026. A provider receives data only when deployed for Rankelo infrastructure or when a customer enables the related feature.

Core and optional providers

Provider or categoryPurposeStatus and data
Production hosting providerCompute, network, TLS, and encrypted backupsOperator-selected before deployment; account, workspace, and service data
PostgreSQL with pgvectorApplication database and vector searchSelf-hosted in the production stack
OpenSERPSearch-result extractionSelf-hosted internal service; search terms and locale
OpenRouterOptional/default free-model inferencePrompts and grounded context when AI runs; privacy routing requests data-collection denial and zero-data retention
SMTP providerTransactional emailOperator-selected; recipient, subject, and message content
GoogleSearch Console and GA4 integrationsCustomer-connected, read-only OAuth; selected property data
RazorpaySubscription and payment processingCustomer-selected paid plan, contact and transaction references; no full card data stored by Rankelo
GitHubRepository publishingCustomer-connected; repository metadata and approved content changes
Customer-selected CMSPublishing to WordPress, Webflow, or webhook targetOnly when configured; approved content and target credentials

Public data sources that are not subprocessors

Common Crawl and public search engines are external data sources used for public-web signals. They do not receive Rankelo account credentials. Search terms and requested public domains may be sent when the corresponding lookup runs.

Changes and objections

Rankelo will publish material changes before a new subprocessor handles customer data when reasonably practicable. A business customer with a valid data-protection concern may contact contact@brandsap.com. The parties will seek a reasonable alternative; if none is available, the affected optional feature may be disabled or the service may be terminated under the Terms.