Privacy Policy
Last updated: 28/06/2026
This Privacy Policy explains how the RankStandings platform processes personal data across its website, admin panel, integrations, webhooks, imports, reports, and operational communications.
1. Roles in data processing
When a company uses the platform to register sellers, customers, sales, products, goals, or CRM integrations, that company is responsible for defining which data will be sent and for ensuring it has a legal basis for that processing. The platform acts as a service provider and processes that data according to the client company instructions to operate rankings, reports, permissions, audit, support, and security.
2. Data processed
We may process data provided directly by users or received through authorized integrations, including:
- account data, such as name, email, company, access profile, and authentication;
- business data, such as sellers, customers, sales, products, goals, rankings, and performance history;
- integration data, such as external identifiers, webhook payloads, logs, sync status, and errors;
- technical data, such as IP address, browser, sessions, security events, and audit records;
- billing data, such as plan, subscription status, invoices, payments, and related communications.
3. Purposes
Data is used to:
- create and operate rankings, TV dashboards, goals, gamification, and reports;
- authenticate users, apply permissions, and protect accounts;
- process imports, exports, integrations, webhooks, and operational queues;
- send invites, password recovery, trial notices, billing notices, and essential service messages;
- investigate failures, prevent abuse, maintain audit logs, and improve platform reliability;
- comply with applicable legal, tax, accounting, and regulatory obligations.
4. Sharing
Data may be shared with providers needed for hosting, databases, storage, email delivery, payment processing, observability, security, and integrations requested by the client company. We do not sell personal data. We may also share data when necessary to comply with law, an order from a competent authority, defend rights, or prevent fraud.
5. Integrations and webhooks
The client company decides which external systems are connected and which events are sent. Integration payloads may contain personal or business data. The platform uses that data to execute the integration, maintain traceability, reprocess failures, and protect the service against misuse.
6. Retention and deletion
We keep data for as long as necessary to provide the service, comply with legal obligations, maintain security, resolve disputes, and preserve audit records. The client company may request correction or deletion of data according to the contract and applicable law, subject to legal obligations and technical backups.
7. Security
We apply technical and administrative controls to reduce risks, including authentication, role-based permissions, CSRF protection, webhook signatures, audit logs, upload validation, backups, and company-level segregation. No system is fully immune to incidents, but we work to prevent, detect, and respond to security risks.
8. Data subject rights
Under applicable law, data subjects may request access, confirmation of processing, correction, deletion, portability, information about sharing, and review of certain decisions. When the request involves data controlled by a client company, we may direct the request to that company.
9. International transfers
Infrastructure, email, storage, payment, or integration providers may operate outside the user country. When this occurs, we adopt measures compatible with applicable law and with the purpose of providing the service.
10. Contact
For privacy, security, or data subject requests, contact us at [email protected].