Privacy Policy
Last updated: 2026-05-01
RankEngine SEO AEO ("RankEngine", "we", "us") respects your privacy. This policy explains what data we collect, how we use it, and your rights.
1. What we collect
RankEngine is a Shopify-installed app. When you install us, we receive an OAuth access token from Shopify scoped to the permissions you approved. We use this token to read and modify your store's catalog data only:
- Products, collections, pages, articles — title, description, SEO meta, images, handles, tags.
- Theme assets we have permission to modify (e.g.
llms.txt, optimized image variants). - Shop metadata — name, primary domain, plan tier.
- Aggregate analytics — page views, top pages (no per-customer data).
2. What we do NOT collect
RankEngine does not read or store:
- Customer personal data (name, email, address, payment info).
- Order details (line items, shipping addresses, transaction amounts).
- Cart or checkout content.
- Anything outside what's required for catalog SEO.
3. How we use your data
Your store's catalog data is used solely to:
- Compute SEO scores and identify issues.
- Generate fix suggestions (alt text, meta descriptions, content).
- Apply fixes when you explicitly approve them.
- Train or adapt brand-voice prompts on samples you paste in.
We do not sell, lease, or share your data with third parties.
4. Service processors we use
- RankEngine AI services — content generation, image alt text, meta descriptions, semantic search, and quality checks.
- RankEngine search data services — keyword volume, competitor data, rank tracking, backlinks, and public-page diagnostics.
- Google integrations — Search Console, Analytics, and PageSpeed data only when you explicitly connect or request a public-page audit.
- Google Cloud — hosting and storage for the RankEngine application and database.
- Cloudflare — CDN, security, and DDoS protection for public surfaces.
5. Data location & retention
Data is stored in Google Cloud (us-central1). Encrypted at rest (AES-256) and in transit (TLS 1.2+). We retain your data while the app is installed. On uninstall, our app/uninstalled webhook fires; on a Shopify shop deletion, our shop/redact webhook performs full data deletion across all 22 per-shop tables within 30 days as required by GDPR Article 17.
6. GDPR compliance
We are GDPR-compliant via Shopify's mandatory webhook contract:
customers/data_request— returns 200 (we hold no customer data).customers/redact— returns 200 (no customer data to delete).shop/redact— performs full per-shop data deletion in transactional batch.
7. Cookies
We use session cookies set by Shopify's App Bridge for embedded authentication. We do not use third-party tracking cookies. Visitors to the marketing site at rankengine.app may have anonymous analytics events captured by Cloudflare.
8. Your rights
You can:
- Export your RankEngine data — Settings → Data & Export → Export Data.
- Delete your data — uninstall the app;
shop/redactfires automatically within 48 hours. - Change app access — Billing → plan controls.
9. Contact
Questions about this policy? Email hello@rankengine.app.
10. Changes to this policy
We'll post material changes here and (where required by law) notify installed merchants via in-app banner.