Privacy

Privacy

The short version: we collect what a listing needs, we verify domains by reading the certificate on your own page, and we never ask for access to your analytics, your payments or your customers.

Last updated 30 August 2026

Who is responsible

RankCert, operated by Sourabh Singh, decides what data is collected here and why. For anything in this policy, write to hello@rankcert.com.

What we collect

  • Account. Your email address, and whatever your sign-in provider returns as a name and avatar.
  • Listing. Everything you type into the submission form, which is intended to be public.
  • Verification. The totals returned by the read-only connections you authorise, plus the DNS and badge checks we run ourselves.
  • Activity. Your votes, bookmarks and comments, so the board can count them and you can see your own history.
  • Payment. If you buy a sponsor slot, our payment processor handles the card and returns a receipt and a customer reference. We never see or store card numbers.
  • Operational logs. Short-lived request logs (IP, user agent, path, status) used to keep the site up and stop abuse.
  • Nothing else. There is no session recording, no cross-site tracking pixel, and no data broker.

Why we are allowed to hold it

  • Contract. Account, listing and payment data — we cannot run your listing without them.
  • Consent. Each read-only connection, granted by you at the provider and revocable there at any time. Newsletter, if you subscribe.
  • Legitimate interest. Operational logs and abuse prevention, kept narrow and short.
  • Legal obligation. Invoices and tax records for payments.

What read-only connections can see

  • Analytics. Aggregate visit counts for the property you connect. Not individual visitors, not their identities, not their behaviour.
  • Payments. Revenue totals. Not customer names, not email addresses, not individual transactions, not payout details.
  • The scopes we request are read-only. We cannot write, refund, change settings or act on your behalf in either system.
  • We store the resulting total and the date. We do not keep a copy of the underlying reports.
  • You can revoke either at any time from the provider. The level drops at the next weekly re-check and the stored totals are deleted.

What is published

  • Your verified status, and the evidence line behind it, with a source and a date.
  • Traffic as a banded figure. Revenue as a band only — never an exact number.
  • Your listing copy, your maker profile name and avatar, and your public activity on the board.
  • Never: your customers, your email address, or any raw figure from a connection.
  • Published pages also appear in our RSS and markdown feeds, the sitemap, and search engine and AI crawler indexes. Assume anything public is copied elsewhere.

Who processes it for us

We use a small number of vendors. Each one gets the minimum it needs, and none of them get your data to use for their own purposes.

  • Database and authentication — stores your account, listing and verification records.
  • Hosting and CDN — serves the site and terminates requests; sees request metadata.
  • Payment processor — handles checkout and holds the card data we never touch.
  • Email — sends sign-in links, receipts and the newsletter.
  • Some of these operate outside your country. Transfers rely on the standard contractual protections those vendors publish.

Cookies

We set a session cookie when you sign in and remember your theme choice. Nothing for advertising, so no banner. The full list is on the cookie policy.

How long we keep it

  • Account and listings — until you delete them.
  • Verification totals — until the connection is revoked or the listing is removed, then deleted at the next weekly pass.
  • Archived weeks — the historical board stays up as a public record. Delete your listing and it leaves the archive too.
  • Operational logs — days, not months.
  • Invoices — as long as tax law requires, typically several years.

Your rights

  • Delete your account from settings and everything goes with it — listings, connections and stored totals.
  • Ask us what we hold about you and we will send it, in a portable format, within 30 days.
  • Ask us to correct anything wrong, or to stop a particular use.
  • Withdraw consent for any connection at the provider, at any time, without asking us.
  • Complain to your data protection authority if we get this wrong. We would rather you told us first.
  • We do not sell data, and there is nobody to sell it to.

Children

The site is not for people under 16. We do not knowingly collect their data, and we delete it if we find it.

Breaches

If data is exposed in a way that could affect you, we will tell the people affected and the relevant authority, describe what happened, and say what we changed. No quiet patches.

Data questions: hello@rankcert.com. If our practices change, the change is logged in the changelog before it takes effect.