Privacy Policy
What we collect when you book a call or write to us, why we have it, who else sees it, and what you can ask us to do about it.
Who we are
RankForImpact (“we”, “us”) provides editorial SEO and AEO services to businesses. This policy explains what we do with personal information when you read this site, book a call with us, or write to us — and what you can ask us to do about it.
For the purposes of the EU and UK General Data Protection Regulation we are the controller of the information described here. You can reach us about anything in this policy at hello@rankforimpact.com.
[To complete before publishing: our registered legal name and postal address. Data protection law requires a policy to identify the controller by name and give a physical contact address, and we will not invent one here.]
What we collect
When you book a call. Bookings run through Cal.com. You give a name and an email address, optionally a phone number, and anything you choose to type into the notes. Cal.com also records the slot you pick and the time zone your browser reports, because a meeting cannot be scheduled without them.
When you email us. We receive your email address, your name if you sign it, and whatever you decide to put in the message.
Server logs. Our host records the ordinary details of a web request — the IP address it came from, the browser user-agent, the page asked for and the time. This happens for every site on the internet and we do not use it to build a picture of you.
Link parameters. If you arrive on a link carrying tracking parameters in its address, those parameters are passed along to the booking widget when it opens.
We ask for the least we can. There is no form on this site, no account to create, and nothing you have to tell us in order to read it.
What we do not do
- No analytics, measurement or session-recording scripts.
- No advertising or tracking pixels, and no ad networks.
- No selling of personal information, and no sharing of it for cross-context behavioural advertising — under any privacy law, for any price.
- No profiling and no automated decisions that affect you.
- No third-party fonts. The typefaces are served from this site, so reading a page does not announce your visit to a font provider.
Why we use it
To arrange and hold the call you asked for — because you asked us to, which the GDPR treats as performing a contract or taking steps towards one.
To reply to you and follow up on that conversation — our legitimate interest in running a business people can actually contact. We have weighed that against your interests, and you can object at any time.
To keep the site up and secure — also a legitimate interest.
Consent — where you volunteer something we did not ask for. You can withdraw it at any time, and withdrawing it does not affect anything we did while it was given.
To meet a legal obligation — where tax, accounting or another law requires us to keep a record.
Cookies and similar technologies
This site sets no cookies of its own.
The booking widget. Opening the calendar loads it from Cal.com, which may set its own cookies or store data in your browser to make booking work. That happens only when the widget loads, and it is governed by Cal.com’s own privacy notice as well as this one.
Who else sees it
- Cal.com — scheduling and the booking calendar.
- Our website host — serving these pages, and the server logs that come with that.
- Our email provider — receiving and storing what you send us.
Each of them handles information on our instructions, under a contract that limits what they may do with it, except where they are separately responsible for their own operations. Beyond that, we disclose personal information only where the law requires it, or where we need to in order to establish or defend a legal claim.
Where it goes
Our providers may handle information in countries other than your own, including the United States. Where information leaves the EEA, the UK or Switzerland we rely on the protections those laws provide for — an adequacy decision where one covers the destination, and otherwise the standard contractual clauses, together with the provider’s own commitments. The point of those safeguards is that the protection travels with the information rather than stopping at the border.
How long we keep it
Bookings and correspondence: for as long as the conversation and any engagement that follows are live, and afterwards for as long as we are required to keep records for tax, accounting or legal-defence reasons.
Server logs and analytics: for the limited retention window our providers apply, and no longer.
If you ask us to delete something, we will — unless a law requires us to keep it, in which case we will tell you which one and for how long.
Your rights
Wherever you live, you can ask us to: tell you what we hold about you and give you a copy; correct it if it is wrong; delete it; restrict or stop how we use it; hand it over in a portable form; or withdraw a consent you previously gave. You can do any of that without being treated differently for it.
Email hello@rankforimpact.com and say what you want. We do not charge for it. We will answer within one month, or sooner where the law says so, and if a request is complicated enough to need longer we will tell you that and why.
In the EEA, the UK and Switzerland you also have the right to complain to your data protection supervisory authority, and to object to processing we base on legitimate interests.
In California and other US states with privacy laws you have rights to know, delete, correct and opt out. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of on that front — but the other rights apply, and you may use an authorised agent to exercise them.
Elsewhere — including Canada, Brazil, Australia, South Africa, India and Japan — the rights above are what we offer as a baseline. If your local law gives you a right we have not listed, tell us and we will honour it where it applies to us.
Children
This site is for businesses and we do not aim any of it at children. We do not knowingly collect personal information from anyone under 16. If you think a child has sent us something, email us and we will delete it.
How we protect it
The strongest protection here is how little there is to protect: no database of our own, no accounts, no forms, and a deliberately short list of providers. What we do hold sits in our scheduling and email providers’ systems, behind their security controls and our own account protections.
That said, no way of sending or storing information is completely secure, and we would rather say so than promise otherwise.
Changes to this policy
If we change how we handle personal information we will update this page and the date at the top of it. Where a change matters to you — a new provider, a new purpose, a new kind of information — we will say so here rather than leave you to spot it.
Contact and complaints
Questions, requests and complaints all go to hello@rankforimpact.com, and we would genuinely rather hear from you before anyone else. If we cannot put something right, you keep the right to take it to your data protection authority.