Privacy Policy
This Privacy Policy explains how RankCraft Collective (“we”, “us”) processes information in connection with our private client area at seorankforum.com and weekly service emails. The Service is strictly B2B and intended for organizations we work with and their authorized personnel. We do not run advertising campaigns and do not sell personal data.
1. Controller & Contact
Controller: RankCraft Collective.
Address: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
Email: [email protected], Phone (non-support): +44 20 8123 4597.
2. Data We Process
- Identification & business contact: name, role, business email/phone, company details.
- Account & security: usernames, role, hashed credentials, access timestamps, IP address, user-agent, session identifiers.
- Project & report data: keywords, ranking snapshots, CTR/traffic aggregates, trend annotations, delivery preferences.
- Email deliverability events: delivered, bounced, dropped, complaint; counts and timestamps only—no behavioral profiling.
- Billing/contract records (if applicable): quotes, invoices, payment confirmations, legal docs.
3. Sources
Contacts are provided by Clients at project start or added manually in the client panel. We do not acquire contacts from external list vendors, scraping, co-registration or advertising sources.
4. Purposes & Legal Bases
- Provide the Service & Reports (contract performance, Art. 6(1)(b) GDPR).
- Safeguard security, prevent fraud/abuse, maintain deliverability (legitimate interests, Art. 6(1)(f)).
- Accounting & legal obligations (Art. 6(1)(c)).
- Product notices such as material changes (legitimate interests). You may object at any time.
5. Cookies & Similar Technologies
The Portal uses strictly necessary cookies for session security and CSRF protection. We do not use third-party advertising cookies. If analytics is enabled, it is configured with IP masking and no cross-site tracking.
6. Sharing & Processors
- We share data only with providers necessary to run hosting, storage, analytics ingestion and email delivery.
- Each provider acts as a processor under written data-processing terms and must apply appropriate safeguards.
- We do not sell or rent personal data and do not permit processors to use it for their own marketing.
7. International Transfers
Where data is processed outside your jurisdiction, we rely on appropriate safeguards such as Standard Contractual Clauses, encryption in transit, and access controls. Copies of relevant transfer mechanisms are available on request.
8. Security Measures
- Encryption in transit (TLS), hardened hosts, role-based access, least-privilege, logging and monitoring.
- Regular patching and separation of environments; employee confidentiality commitments.
- No method is 100% secure; we maintain incident response procedures and will notify where legally required.
9. Retention
- Account & project data — for the duration of the engagement plus up to 24 months for audit continuity.
- Invoices & contracts — typically 6–10 years to satisfy legal/accounting obligations.
- Email events & access logs — typically 90–180 days unless needed to investigate deliverability or abuse.
- Backups — time-limited rolling cycles; backups are encrypted and access-restricted.
10. Your Rights
Subject to applicable law, you may request access, rectification, erasure, restriction, portability, or object to certain processing. Contact [email protected]. We will verify identity before fulfilling requests.
EU/UK Residents
You may lodge a complaint with your local data protection authority or the UK ICO. We aim to respond within 30 days.
California (CCPA/CPRA)
- We do not sell or share personal information for cross-context behavioral advertising.
- You have rights to know, delete (with exceptions), correct, and to non-discrimination for exercising your rights.
11. Children's Data
The Service is intended for business users. We do not knowingly collect personal data from children.
12. Automated Decision-Making
We do not conduct automated decision-making that produces legal or similarly significant effects. Deliverability handling (e.g., automatic suppression of hard-bounced addresses) is a standard safety measure.
13. Changes to this Policy
We may update this Policy; the “Last updated” date will change accordingly and, where appropriate, we will notify you in the Portal or via email.
14. Contact
Questions or privacy requests: [email protected] · Postal: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom · Phone: +44 20 8123 4597.