Privacy Policy

Our privacy policy and how we use your data

Last updated: 26 July 2026

1. Who controls your data

RankShark is operated by RankShark spółka z ograniczoną odpowiedzialnością (RankShark sp. z o.o.), with its registered office at ul. 3 Maja 17, 43-300 Bielsko-Biała, Poland. The company is entered in the Register of Entrepreneurs of the National Court Register kept by the District Court in Bielsko-Biała, 8th Commercial Division of the National Court Register, under KRS number 0001256034. NIP 5472261555, REGON 545308782. Share capital: PLN 5,000.00, paid up in full. In these terms we are "RankShark", "we" or "us". You can reach us at hello@rankshark.ai.

RankShark is the data controller for the information described here. For questions, or to exercise any of the rights below, email privacy@rankshark.ai.

2. What we collect, and why

If you run a visibility scan

You give us a business name or website address. We then collect that business's publicly listed details — name, address, phone number, website, categories, ratings and public reviews — and how it appears in search results and AI assistants. If you ask for the report by email, we collect your name and email address.

Why: to produce the report you asked for, and to follow up on it. Basis: your request, and our legitimate interest in following up.

If you become a customer

We collect your name, email address, business details, website credentials, and the settings and content you create. Stripe collects your payment details directly — we receive only the outcome, the last four digits, and the billing country.

Why: to provide the service and take payment. Basis: performance of our contract with you.

Photographs you upload

If you choose to have imagery reflect your actual premises or team, we store the reference photographs you upload. These may show identifiable people. Only upload photographs where everyone shown has agreed to it.

Why: to generate imagery for your content. Basis: performance of our contract, together with the consent of the people shown, which you are responsible for obtaining.

How you found us

We record which campaign or link brought you to the site and store it in a first-party cookie for up to 90 days. See our cookie policy.

Why: to understand which of our own marketing works. Basis: our legitimate interest in measuring it.

Technical and error data

We log errors and performance problems, including IP address and browser. We deliberately record identifiers rather than names or email addresses in error reports.

Why: to keep the service working and secure. Basis: our legitimate interest in a reliable service.

3. What we do not do

  • We do not sell your personal data.
  • We do not use your content, or your customers' data, to train general-purpose AI models.
  • We do not run advertising trackers on this site that follow you around the web.

4. Where your data is held

Our database and application are hosted in the European Union (Frankfurt). Some providers we rely on process data outside the EU, principally in the United States. Where that happens we rely on the European Commission's standard contractual clauses or an adequacy decision.

5. Who else processes it

We use a small number of providers to run the service. Each is bound to process data only on our instructions:

  • Supabase — database and authentication (EU)
  • Netlify — application hosting
  • Stripe — payments
  • Resend — email delivery
  • Anthropic — content and analysis generation
  • Replicate — image generation
  • DataForSEO — search and review data
  • Google — business profile and places data
  • Sentry — error monitoring (EU)

We will update this list when it changes. If you would like advance notice of changes, email us and we will add you to that list.

6. How long we keep it

  • Customer account and content — while you are a customer, then 12 months, so you can return without losing your library.
  • Scan reports — up to 24 months.
  • Attribution cookie — 90 days.
  • Invoices and financial records — as long as tax law requires, currently 5 years.
  • Error logs — 90 days.

You can ask us to delete your data sooner.

7. Your rights

Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or send it to another provider. You can object to processing we carry out on the basis of legitimate interest.

Email privacy@rankshark.ai and we will respond within one month. There is no charge.

If you think we have handled your data badly you can complain to your national data protection authority. In Poland that is the President of the Personal Data Protection Office (UODO). We would rather you came to us first, but it is your right either way.

8. Security

Data is encrypted in transit and at rest. Access to production systems is restricted and authenticated. Database access is governed by row-level security, so one customer's data is not reachable from another customer's session.

No system is perfectly secure. If a breach occurs that is likely to affect your rights, we will tell you and the regulator within the timeframes the GDPR requires.

9. Children

RankShark is a business service and is not directed at children. We do not knowingly collect data from anyone under 16.

10. Changes

We will update this policy as the service changes and revise the date at the top. If a change materially affects how we use your personal data, we will email you before it takes effect.