This Privacy Policy describes how IFace (doing business as "RankBuddy") ("RankBuddy," "we," "us," or "our") handles personal information when you visit https://rankbuddy.io, create an account, or use our software services (collectively, the "Services"). By using the Services, you acknowledge this Privacy Policy.
1. Who we are
The data controller for the Services is IFace (doing business as "RankBuddy"). For privacy questions or to exercise your rights, contact us at alex.repryntsev@gmail.com.
2. Information we collect
2.1 You provide to us
- Account and profile: name, email address, password (stored using secure hashing), organization or team identifiers, and workspace settings.
- Content you submit: topics, drafts, uploads, integration configuration, prompts, feedback, support messages, and other materials you add to the product.
- Billing-related details: limited billing metadata in our systems (for example subscription status). Payment card numbers and full payment credentials are collected by Paddle, not stored by RankBuddy.
2.2 Collected automatically
- Device and usage: IP address, approximate location derived from IP, browser type, operating system, pages viewed, timestamps, referrer URLs, diagnostics, and error logs.
- Cookies and similar technologies: we use cookies, local storage, and similar technologies to operate the site, maintain sessions, remember preferences, prevent fraud, and measure performance. Where required by law, we obtain consent before non-essential tracking.
2.3 From third parties
We may receive information from authentication providers if you connect them, from Paddle (for example transaction IDs, subscription status, and billing country), and from analytics or communication tools we use to operate the Services.
3. How we use information
We use personal information to:
- Provide, maintain, improve, and secure the Services;
- Authenticate users, manage workspaces and permissions, and enforce our agreements;
- Generate and deliver product features you request, including AI-assisted workflows;
- Process subscriptions and communicate about billing, receipts, and service notices;
- Send optional product updates or marketing where permitted—you may unsubscribe from marketing emails;
- Detect, investigate, and prevent abuse, fraud, and security incidents;
- Comply with law, respond to lawful requests, and exercise legal rights;
- Use aggregated or de-identified data that does not identify you for analytics and product insights.
4. Legal bases (EEA, UK, and Switzerland)
Where the GDPR or similar laws apply, we rely on:
- Contract: to provide the Services you request and manage your account;
- Legitimate interests: to secure and improve the Services, prevent fraud, and communicate about the product—balanced against your rights;
- Consent: where required for non-essential cookies or certain marketing;
- Legal obligation: where we must retain or disclose information under law.
5. AI and automated processing
Features of the Services may send your prompts and associated content to model providers strictly as needed to fulfill your requests. We select subprocessors with contractual commitments appropriate for our customers. Do not submit special categories of personal data (such as health or biometric data) or data you are not authorized to share unless your agreement with us expressly covers that processing.
AI-generated drafts are not published automatically. You decide what to edit, schedule, or publish, and you are responsible for reviewing content before it is made public, as described in our Terms of Service.
6. Sharing of information
We do not sell your personal information. We may share information:
- With service providers who process data on our instructions (hosting, email, analytics, logging, security, and AI inference);
- With Paddle when you purchase a subscription—Paddle acts as merchant of record and processes payment and tax data under its own privacy policy: Paddle Privacy Policy;
- With your organization when you belong to a team workspace, as reflected in roles and settings;
- For legal and safety reasons when we reasonably believe disclosure is required by law or to protect users and the public;
- In connection with a business transaction such as a merger or acquisition, subject to appropriate safeguards;
- With your consent or direction.
7. International transfers
Our infrastructure and subprocessors may be located outside your country. Where we transfer personal data across borders, we use appropriate safeguards such as standard contractual clauses or other mechanisms permitted by applicable law.
8. Retention
We keep information only as long as needed for the purposes described, including legal, accounting, and security requirements. Backup copies may persist for a limited period. You may request deletion of your account where applicable; certain records may be retained after closure when the law or legitimate business needs require.
9. Security
We maintain administrative, technical, and organizational measures designed to protect information. No internet transmission is perfectly secure—please protect your credentials and notify us promptly of unauthorized access.
10. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing, and to withdraw consent where processing is consent-based. You may lodge a complaint with a supervisory authority. To exercise rights, email alex.repryntsev@gmail.com—we may verify your identity before responding.
California residents: we do not sell personal information as defined under the CCPA/CPRA. You may request access or deletion as described above.
11. Children
The Services are not directed to children under 16, and we do not knowingly collect their personal information.
12. Third-party links
Our site may link to third-party websites (for example documentation or integrations). Their privacy practices govern those sites.
13. Changes
We may update this Privacy Policy from time to time. We will adjust the "Last updated" date and, when material, provide notice as required—such as an in-product banner or email.
14. Related policies
Purchases are also subject to Paddle's buyer terms and refund policy. See our Terms of Service and Refund Policy.
15. Contact
Privacy questions or requests: alex.repryntsev@gmail.com. Payment privacy questions for checkout transactions should be directed to Paddle via Paddle buyer support.