Privacy Policy

Last updated: February 23, 2026

1. Introduction

Rankona ("we", "our", "us") is a Google Business Profile management platform operated by Suciu I. Ioan-Daniel Persoană Fizică Autorizată (CUI: 53440010), with registered office in Alba Iulia, Alba County, Romania. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website and services at rankona.com.

2. Information We Collect

We collect the following types of information:

  • Waitlist signup: your email address and the date you signed up.
  • Account information: when you create an account, we collect your name, email address, and profile information provided via Google OAuth.
  • Google Business Profile data: when you connect your Google account, we access your Google Business Profile information (business names, addresses, hours, reviews, posts, photos, and performance metrics) through the Google Business Profile API.
  • Usage data: pages visited, features used, and general interaction patterns to improve our service.

3. How We Use Your Information

We use your information to:

  • Provide, operate, and improve Rankona's features and services.
  • Display and manage your Google Business Profile data within our dashboard.
  • Generate AI-powered posts, health check reports, and rank audit results.
  • Send review alerts via email or SMS when enabled by you.
  • Communicate product updates, waitlist status, and support responses.

4. Google API Data & OAuth Credentials

Rankona uses the Google Business Profile API to access and manage your business listings on your behalf. Here is how we handle this data:

  • OAuth tokens: when you sign in with Google, we receive an access token and a refresh token. The refresh token is encrypted at rest (AES-256) and stored in our database hosted on Vercel. Access tokens are short-lived and held in server memory only — they are never persisted to disk or exposed to the client/browser.
  • Token decryption: when an API call is needed, the encrypted refresh token is decrypted in server memory, used to obtain a fresh access token from Google, and the decrypted value is immediately discarded after use. Decrypted tokens are never written to logs, disk, or any persistent storage.
  • Scope of access: we only request the minimum Google API scopes necessary to provide our features (e.g., reading and managing business profiles, posts, and reviews).
  • Token usage: tokens are used exclusively to make API calls on your behalf. We do not share your tokens with third parties.
  • Revocation: you can revoke Rankona's access at any time through your Google Account permissions page or by deleting your Rankona account. Upon revocation or account deletion, we delete your stored encrypted tokens immediately.
  • Limited Use Disclosure: Rankona's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Data Storage & Security

  • Rankona is hosted on Vercel (vercel.com). Application data is stored in Vercel-managed infrastructure with encryption at rest.
  • OAuth refresh tokens are encrypted using AES-256 before being stored in the database. Decryption happens exclusively in server memory at runtime.
  • All connections to our service use HTTPS/TLS encryption in transit.
  • Vercel's infrastructure provides automatic DDoS protection, edge networking, and secure deployment pipelines.
  • Access to production systems and environment variables is restricted to authorized personnel.
  • We do not sell, rent, or trade your personal data to third parties. Your data is shared only with Google (via the Google Business Profile API, to perform actions you request) and Vercel (our infrastructure provider, for hosting and data storage). No other third parties receive your data.

6. Data Retention

We retain your data for as long as your account is active. If you delete your account, we delete all associated data, including encrypted OAuth tokens, business profile caches, and personal information, within 30 days. Waitlist emails are retained until you unsubscribe or request deletion.

7. Account Deletion

You can delete your Rankona account at any time. To request account deletion:

  • From the app: go to Settings → Account → Delete Account. This triggers immediate deletion of your data.
  • By email: send a request to privacy@rankona.com from the email address associated with your account. We will process your request within 7 business days.

When your account is deleted, we permanently remove:

  • Your profile information (name, email, preferences).
  • All encrypted OAuth tokens — Google API access is immediately revoked.
  • Cached Google Business Profile data (listings, reviews, posts, metrics).
  • AI-generated content history (drafts, scheduled posts).
  • Alert and notification settings.

Account deletion is permanent and cannot be undone. After deletion, you will need to create a new account and re-authorize Google access if you wish to use Rankona again.

8. Third-Party Services

We use the following third-party services:

9. Cookies & Local Storage

Rankona uses essential cookies and local storage to maintain your authentication session and remember your preferences. We do not use third-party tracking cookies or advertising cookies. Analytics, if enabled in the future, will be privacy-respecting and disclosed in an updated version of this policy.

10. Children's Privacy

Rankona is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. Your Rights

You have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data and account (see Section 7).
  • Export your data in a portable format.
  • Revoke Google API access at any time.
  • Opt out of non-essential communications.

To exercise any of these rights, contact us at privacy@rankona.com.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our website or sending you an email. The "Last updated" date at the top reflects the most recent revision.

13. Contact

If you have questions about this Privacy Policy, contact us at privacy@rankona.com.

Suciu I. Ioan-Daniel PFA · CUI 53440010 · Alba Iulia, Alba, Romania