LEGAL
Privacy Policy
Last updated: September 7, 2026
Overview
RankWin respects your privacy and is committed to protecting the personal information you share with us. This policy explains what we collect, why we collect it, and the choices available to you when you use our website and services.
Information we collect
We may collect account information, contact details, website and business context you choose to provide, product usage data, device information, and communications with our team. We collect only the information needed to operate, secure, and improve the service.
How we use information
We use information to provide and personalize RankWin, operate customer support, understand product performance, prevent fraud and abuse, communicate about the service, and comply with legal obligations.
Cookies, browser storage, and analytics
This section describes what the RankWin website actually stores in your browser and what it transmits, key by key. It states current product behavior rather than a commitment, and where the product implements no control that is said plainly below.
rankai_observability_sid — a first-party cookie and a browser session-storage entry of the same name. Its value is a randomly generated 32-character hexadecimal string that contains no account, device, or personal information. The cookie is scoped to the whole site and marked SameSite=Lax and Secure, and it carries no expiry date, so your browser deletes it when the browsing session ends; the session-storage copy is cleared at the same time. It groups the diagnostic events of a single browsing session together, and it reaches RankWin’s own servers and our logging provider, Datadog.
rankai_observability_visitor — a browser local-storage entry holding a randomly generated 32-character hexadecimal identifier and the timestamp of your first visit. No expiry is set on it: it stays in your browser until you clear this site’s data. It is attached to every diagnostic event sent to RankWin and on to Datadog, which is what lets us tell a returning browser from a new one across sessions.
rankai_observability_new_visitor — a browser session-storage flag recording whether the visitor identifier above was created during the current browsing session. It is cleared when the browsing session ends. The flag itself is never transmitted; only the label it produces, “new” or “returning”, is sent with each event.
rankai_observability_campaign — a browser local-storage entry holding the first utm_source, utm_medium, utm_campaign, utm_content, and utm_term values that appear in a RankWin URL you open, each truncated to 200 characters. No expiry is set on it, later visits do not overwrite it, and it stays until you clear this site’s data. It is attached to every diagnostic event so a visit can be attributed to the campaign that started it.
rankai-theme — a browser local-storage entry holding only your light or dark color preference. A legacy entry named rankai-dashboard-theme is still read as a fallback and is deleted the next time you use the dashboard theme toggle; current code never writes it. Neither entry is transmitted, and neither reaches a third party.
rankwin:cms-request-language:v1 — remembers the programming language selected in CMS request examples. It contains only the language name and is not transmitted to RankWin or third parties. It remains until you clear this site’s data.
What the diagnostic events contain. Each event records the page path you opened — with its query string removed and long opaque segments replaced by a placeholder before it leaves your browser — the calls your browser makes to RankWin’s own API (method, path, HTTP status code, and duration), and unhandled JavaScript errors and promise rejections including their message and stack trace. Before an event is forwarded, our server removes the query string from reported paths, replaces long opaque URL segments such as invitation tokens with a placeholder, drops attributes whose names match authorization, cookie, token, secret, password, or API-key patterns, and runs a value-level redaction pass. Our server then adds, to the copy sent to Datadog, a coarse approximate location our hosting provider derives from your connection — country, region, and time zone only — and, when you are signed in, your RankWin account identifier. If a RankWin operator is viewing the product as your account, that operator’s account identifier is added as well. Your IP address, your city, your approximate latitude and longitude, and your email address are not part of the copy sent to Datadog. Diagnostic events from a signed-in session are therefore not anonymous.
Google Analytics 4. On the production website, and only when a measurement identifier is configured, RankWin loads Google’s gtag.js script from googletagmanager.com and sends one page-view event for each page you open. That event carries only the page path and the page title. Before the path is sent, your browser removes the query string from it and replaces long opaque segments, such as invitation tokens and record identifiers, with a placeholder; the full page URL is deliberately not sent to Google. Google’s own automatic page-view collection is switched off, and that page-view event is the only event RankWin’s own code sends; Google’s script may collect further events of its own, which this policy does not enumerate. Google receives your IP address as part of that request, and Google’s script may set its own cookies in your browser; those cookies are set and controlled by Google rather than by RankWin’s code, and this policy does not enumerate them.
Controls this website does not implement. RankWin does not show a cookie banner or consent prompt, offers no in-product setting that switches the storage or analytics described above off, and does not act on the Do Not Track or Global Privacy Control browser signals. The only measures that are effective today are the ones your browser provides: blocking or clearing cookies and site data for this domain, or blocking googletagmanager.com. Clearing this site’s data removes every entry listed above, and the identifiers are generated again on your next visit.
Retention of this data. RankWin does not keep these diagnostic events in its own database; they are forwarded to Datadog, and the analytics event is sent to Google. How long each of those providers retains the data is determined by the configuration of their services, and this policy does not state a period for it.
Sharing and processors
We do not sell personal information. We may share limited information with vendors that help us provide hosting and cloud storage, payment processing, AI content generation, search and ranking data, analytics, communications, scheduling, and security. These providers are permitted to process information only for the services they supply to us.
Data retention and security
We retain information for as long as necessary to provide the service and meet legal requirements. We use administrative, technical, and organizational safeguards designed to protect information from loss, misuse, and unauthorized access.
Your choices
Depending on where you live, you may request access, correction, deletion, or portability of your information, or object to certain processing. Contact us at admin@rankwin.co to make a request. You can export your project data and delete individual projects yourself from the dashboard settings; to delete your entire account, email admin@rankwin.co from the address on the account and we will complete the deletion for you.
Contact
Questions about this policy can be sent to admin@rankwin.co.
