Rankticker

Legal

Privacy policy

How Rankticker collects, uses and protects personal data on rankticker.com and in the Rankticker platform, and the rights you have under UK data protection law.

Last updated: 8 October 2026

This policy explains what personal data we collect, why we use it, who we share it with, how long we keep it and what rights you have. It covers the public website at rankticker.com and the Rankticker platform: the logged-in app for Buyers at /app/ and the publisher portal. It applies to website visitors, Buyers and their team members, Publishers, and anyone who writes to us.

Rankticker is a business-to-business service. Most of what we handle is information about businesses and websites. Some of it is still personal data, for example your name, your work email address, or the details of a sole trader who sells placements on their own site, and UK data protection law applies to that.

1. Who we are

Rankticker is a trading name of Swoonsy Ltd, a company registered in England and Wales with company number 17494196. Our registered office is 124 City Road, London EC1V 2NX, United Kingdom.

Swoonsy Ltd is the controller of the personal data described in this policy, which means we decide how and why it is used. Section 12 explains the limited cases where we act on a Buyer's instructions instead.

For anything about your personal data, including requests to use your rights, email hello@rankticker.com. You can also use our contact page.

We have not appointed a data protection officer, because the law does not require us to. Privacy questions are handled by the company's directors.

Swoonsy Ltd pays the data protection fee to the Information Commissioner's Office (ICO). Our ICO registration number is [to be added].

2. The personal data we collect

When you visit the website

The website has no accounts, no analytics and no advertising or tracking cookies. Our hosting provider logs each request to keep the service running and to detect abuse. A log entry contains your IP address, the page requested, the date and time, your browser's user agent and the response code. If you choose light or dark mode, your browser stores that choice on your device. It is never sent to us. Our cookie policy has the details.

When you create or use an account

  • Account details: your name, work email address, company name, role, password (stored only in hashed form), billing address, VAT number and phone number if you give it to us.
  • Team members: the names and email addresses of colleagues you invite, and their permissions.
  • Settings: preferences such as notification choices and light or dark theme.
  • Security records: sign-in times, IP addresses used to sign in, and records of important account changes.

Buyer project, order and campaign data

To build and fulfil placements we hold the websites in your projects, target URLs, anchor text, keywords, content briefs, content you upload or we write for you, comments, revision requests, order history, link tracking results and campaign settings (budget, objective, target URLs, anchors, keywords, geo, niche, maximum cost per link, and which recommendations you approve or decline). This is mainly business information. It can include personal data, for example if a target website is a person's own site, or if content or comments name people. Please don't put more personal data in briefs, anchors or content than the job needs.

Publisher data

  • Contact and account details: your name, email address, business name and address.
  • Site details: the sites you list, information you give us to prove you own or control them, your prices and terms per format, and your editorial policies.
  • Order activity: requests you accept or decline, comments, published URLs and live dates.
  • Payout and tax details: bank or payout account details, VAT status and number, tax residence, invoices and payout history. We need some of this to meet tax and reporting duties.

Payment data

Card payments are handled by our payment provider, currently Stripe [to confirm]. We don't receive or store your full card number or security code. We receive limited information from the payment provider, such as the card brand, last four digits, expiry date, billing country or postcode and whether a payment succeeded.

Support and other emails

When you email us we keep your email address, your name if you include it, and what you write, along with our replies.

Publisher vetting data

Before and after a site is listed, we review it using public metrics from third-party SEO data providers, such as Domain Rating, Domain Authority, Trust Flow and Citation Flow, estimated organic traffic, spam scores and referring domains, and our own checks of public pages (for example author attribution, outbound links and indexed pages). This data is about websites. Where a site is run by an individual, some of it may relate to that person.

SEO and AI visibility data for projects

For the SEO performance view we obtain metrics about your project's website from SEO data providers. For AI visibility tracking we send prompts to AI services such as ChatGPT, Google AI Overviews, Perplexity and Gemini, and store the public answers they return, including brand mentions, citations and sentiment. Prompts are built from your project's keywords, brand and competitors. We don't intend to send or collect personal data this way. If your brand is a person's name, prompts and answers will contain that name, and answers can mention people the AI service chooses to name. We store answers as returned and use them only to report visibility. Read more about AI visibility tracking.

Marketing preferences

Whether you have agreed to receive marketing emails from us, when you agreed or unsubscribed, and how you did it.

Data we don't want

We don't ask for special category data (such as health, religion or political views) or criminal offence data. Please don't include it in content, briefs or messages.

Where the data comes from

Mostly from you. We also receive data from the person who invited you to a team, from Buyers and Publishers when an order passes between them, from our payment provider, from SEO data providers, from AI services and from public websites.

3. Why we use your data and our lawful bases

UK data protection law requires a lawful basis for each use of personal data. Where we rely on legitimate interests, we have weighed our interests against yours and concluded they are not overridden. You can ask us for details of that assessment. The ICO explains this basis in its legitimate interests guidance.

"Contract" below applies where you personally are our customer or Publisher, for example as a sole trader. Where you use Rankticker for a company, our contract is with the company, so we rely on legitimate interests in providing the service your organisation signed up for.

PurposeData usedLawful basis
Run the website and platform, keep them secure and detect abuseServer logs, security recordsLegitimate interests: operating a secure service
Create and manage accounts and teams, sign you inAccount details, team members, settingsContract, or legitimate interests where you act for a company
Process orders: write or review content, pass order details to Publishers, track delivery, handle revisions, replacements and refundsProject and order data, Publisher order activityContract, or legitimate interests where you act for a company
Monitor live links after publicationOrder data, published URLsContract, or legitimate interests where you act for a company
Run campaigns in auto or semi-auto mode and make recommendationsCampaign settings, project data, marketplace dataContract, or legitimate interests where you act for a company
Take payments, issue invoices and pay PublishersPayment data, payout and tax details, order historyContract or legitimate interests, and legal obligation for tax and accounting
Keep tax, accounting and other records the law requires, and report to tax authorities where requiredInvoices, payout and tax details, order historyLegal obligation
Vet publishers, keep listings accurate, and detect fraud, private blog networks and metric manipulationVetting data, Publisher account and site details, order activityLegitimate interests: a trustworthy marketplace and fraud prevention
Track SEO performance and AI visibility for projectsProject data, prompts and AI answersContract, or legitimate interests where you act for a company
Answer questions, provide support and handle complaintsEmails and account detailsLegitimate interests: responding to people who contact us. Contract where the request relates to your contract with us
Send service messages, such as order updates, security notices and changes to our termsName, email addressContract, or legitimate interests where you act for a company
Send marketing emails about RanktickerName, email address, marketing preferencesConsent, or legitimate interests where the PECR rules in section 4 allow marketing without consent
Improve the platform and fix problems, using information we already hold, such as order volumes and error reportsAccount, order and log dataLegitimate interests: improving our service
Comply with the law, enforce our terms, and establish or defend legal claimsAny relevant dataLegal obligation, or legitimate interests in protecting our business

4. Marketing emails

Marketing emails are governed by the Privacy and Electronic Communications Regulations (PECR) as well as UK data protection law. We send them as follows.

  • If you are an individual or a sole trader or partnership, we email you marketing only if you agreed to it, or if you are an existing customer and we are telling you about similar Rankticker services. In that second case (the "soft opt-in") we gave you the chance to opt out when we collected your details.
  • If you use an email address at a company, PECR allows business-to-business marketing without consent, provided we identify ourselves and give a way to opt out. Your work email is still your personal data, so you can object at any time and we will stop. The ICO explains these rules in its business-to-business marketing guidance.

Every marketing email has an unsubscribe link, and you can also email hello@rankticker.com. Unsubscribing doesn't stop service messages about your account or orders. We keep a minimal record of people who have unsubscribed so we don't email them again. We don't buy or sell email lists.

5. Who we share data with

We don't sell personal data. We share it only as described here.

Service providers who process data for us

These providers act on our instructions under contracts that require them to protect the data.

ProviderWhat they doWhere
Railway CorporationHosts the website and platform servers, and keeps request logsUS company. Staff or sub-processors may access data from the United States
Supabase, Inc.Database for the platformData stored in an EU region. US company, so staff or sub-processors may access data from outside the UK and EU
Google (Google Workspace)Email and business documentsGoogle operates data centres in several countries, including the United States
Our payment provider, currently Stripe [to confirm]Card payments, refunds and, where used, payoutsGlobal. Stripe also uses some data as an independent controller, for example for fraud prevention and its own legal duties, under its own privacy policy
SEO data providersSupply public metrics about websites. We send them domain names and URLs, not account detailsVaries by provider, including outside the UK
AI servicesAnswer the prompts we send for AI visibility trackingVaries by provider, including the United States

You can ask us for an up-to-date list of the providers we use.

Buyers and Publishers

When you place an order, the Publisher receives what it needs to review and publish the placement: the target URL, anchor text, content or brief, the website the link points to, deadlines and comments on the order. We don't give Publishers your payment details. Buyers see the Publisher's site, listing details, order comments and the published URL. Buyers don't see a Publisher's payout or tax details.

Others

  • Professional advisers such as accountants, lawyers and insurers, when we need their help.
  • Tax authorities, regulators, law enforcement or courts, where the law requires it or to protect our rights or other people's safety.
  • A buyer or investor, or their advisers, if we sell or restructure all or part of our business. They would have to use the data in line with this policy.

6. International transfers

Our platform database is stored in the EU. Some of our providers are US companies, or use staff and sub-processors in other countries, so personal data may be accessed from or sent to countries outside the UK. When that happens we make sure one of these protections applies:

  • UK adequacy regulations, which cover the European Economic Area and some other countries, and cover US organisations certified under the UK Extension to the EU–US Data Privacy Framework (the "UK–US data bridge"). The ICO lists the countries covered in its guidance on adequacy regulations.
  • Standard data protection clauses approved for the UK: the International Data Transfer Agreement (IDTA), or the UK Addendum to the EU standard contractual clauses, as described in the ICO's guidance on the IDTA and the Addendum, together with a transfer risk assessment where one is required.

You can ask us for more information about the safeguard used for a particular provider.

7. How long we keep data

We keep personal data only as long as we need it for the purposes above. These are our standard periods.

DataHow long we keep it
Server request logsDeleted within 30 days at most
Account details and settingsWhile your account is open, then deleted or anonymised within 90 days of closure, except for records we must keep (see below)
Project, order, content, campaign and link tracking dataWhile your account is open and, for each order, at least until its Link Permanence Period ends. Order records needed for accounting are kept as below
Invoices, payments, refunds, payouts and tax records6 years from the end of the financial year they relate to
Publisher vetting dataWhile the site is listed or under review, and up to 2 years after removal so we can spot sites that rejoin under another account
AI visibility prompts and answersWhile the project exists
Support and other emailsUp to 2 years after the last message. If the email forms part of a contract or a dispute, as long as we keep the related business records, usually 6 years
Data protection requests and complaints2 years after we close the matter
Marketing preferencesUntil you unsubscribe. After that we keep a minimal suppression record so we don't contact you again
BackupsOverwritten on a rolling cycle, so deleted data disappears from backups after a short period

We may keep data longer if the law requires it or we need it for a legal claim. Anonymised data that can no longer identify anyone may be kept for statistics.

8. Security

We protect personal data with technical and organisational measures suited to the risk. Connections to the website and platform are encrypted with TLS. Passwords are stored only in hashed form. Access to personal data is limited to people who need it for their work. Our database provider encrypts stored data at rest. We choose providers with recognised security practices and review access regularly.

No system is completely secure. If a personal data breach happens, we will report it to the ICO within 72 hours where the law requires, and tell you without undue delay if it is likely to put your rights and freedoms at high risk.

9. Your rights

Under UK data protection law you have these rights. Some apply only in certain circumstances. The ICO explains them in its information for the public.

  • Access: ask for a copy of the personal data we hold about you. We will carry out reasonable and proportionate searches.
  • Rectification: ask us to correct inaccurate data or complete incomplete data. You can update most account details yourself in the app.
  • Erasure: ask us to delete your data. We may need to keep some records, such as invoices, for legal reasons.
  • Restriction: ask us to limit how we use your data, for example while we check a correction.
  • Portability: ask for data you gave us, where we use it under contract or consent, in a machine-readable format, or ask us to send it to another organisation.
  • Objection: object to our use of your data based on legitimate interests. You can object to direct marketing at any time and we will stop.
  • Withdraw consent: where we rely on consent, withdraw it at any time. This doesn't affect what we did before you withdrew.
  • Automated decisions: we don't make decisions about individuals based solely on automated processing that have legal or similarly significant effects. Campaign auto mode chooses and places orders with publications within the rules and budget a Buyer sets. Those decisions concern websites and placements and have no legal or similarly significant effect on any individual. Publisher vetting uses automated metrics to help us review sites. If we decline or remove your listing and you want a person to look at the decision again, email us.

To use any right, email hello@rankticker.com. We may ask you to confirm your identity or to clarify your request. We reply within one month of receiving your request, or of receiving the information we asked for. We can extend that by up to two further months for complex or numerous requests, and we will tell you if we do. There is no charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse.

10. Complaints

If you are unhappy with how we have handled your personal data, please complain to us first by emailing hello@rankticker.com with "Data protection complaint" in the subject line. We will acknowledge your complaint within 30 days, look into it and tell you the outcome without undue delay. The ICO explains these duties in its note on the new data protection complaints law.

You also have the right to complain to the Information Commissioner's Office, the UK regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113. The ICO will usually expect you to have raised the matter with us first. If you live in the EU, you can also contact the data protection authority in your country.

11. Children

Rankticker is for businesses and is not intended for anyone under 18. We don't knowingly collect personal data from children. If you believe a child has given us personal data, email us and we will delete it.

12. When we act for Buyers

Sometimes a Buyer gives us personal data about other people for us to use only on the Buyer's behalf, for example content that names individuals or a brief containing someone's details. For that data, the Buyer is the controller and we act as its processor under our terms and conditions. People whose data a Buyer has shared should contact that Buyer about their rights. We will help the Buyer respond.

13. Other websites

Publisher websites, payment pages run by our payment provider, and any site we link to have their own privacy policies. We are not responsible for how they handle personal data.

14. Changes to this policy

We will update this policy when our services or the law change. The date at the top shows when it last changed. If we make a significant change, such as adding analytics or a new type of provider, we will tell account holders by email or in the app before the change takes effect.