Rank Mascot logoRank Mascot

Privacy

Privacy Policy

Effective 10 August 2026 · Last updated 10 August 2026 · Version 1.0

Summary

This summary is provided for convenience. The full policy below governs.

1. Who we are

Rank Mascot is a search engine optimisation auditing and content platform currently in development. This policy applies to the website at rankmascot.com and to the pre-launch waitlist operated on it.

For the purposes of the EU and UK General Data Protection Regulation, we act as the data controller in respect of the personal data described in this policy. Under the Digital Personal Data Protection Act, 2023 of India, we act as the data fiduciary.

Operator: [LEGAL ENTITY NAME]
Registered address: [REGISTERED ADDRESS]
Privacy contact: privacy@rankmascot.com

2. Personal data we collect

We collect personal data in two circumstances, described below. This website does not request your name, company, telephone number, postal address, or payment details.

2.1 Waitlist registration

If you submit the waitlist form, we record the following:

DataDescription and purpose
Email addressThe address you provide. Used to notify you when the product becomes available.
Date and time of submissionUsed to contact registrants in order of registration and to apply any early-access terms.
Originating page pathThe path of the page from which the form was submitted, for example /. Used to assess which pages generate registrations. This is a single path value and not a record of your browsing activity.
Browser user-agent stringThe browser and operating system identifier transmitted by your browser with each request. Used to identify and prevent automated abuse of the form.

This record is stored in a single file on our server. It is not transferred to a customer relationship management system, marketing platform, or email service provider.

2.2 Server logs

Our web server maintains standard access logs. Each entry may contain your IP address, the date and time of the request, the resource requested, the response status code, the referring page, and your browser user-agent string. These logs are generated automatically as a technical necessity of operating a web server and are used solely to maintain the availability, integrity, and security of the service.

In addition, IP addresses are held temporarily in server memory in order to apply rate limits to the waitlist form and prevent automated bulk submissions. These records are not written to persistent storage and are cleared at least once per hour.

3. Technologies we do not use

The following statements describe the current configuration of this website and can be verified using the developer tools available in any modern browser.

4. Purposes and legal bases

PurposeLegal basis
Notifying you when the product becomes availableConsent, Article 6(1)(a) GDPR, given by submitting the waitlist form. Consent may be withdrawn at any time.
Maintaining the availability and security of the service and preventing abuseLegitimate interests, Article 6(1)(f) GDPR, in operating a secure and functioning service.
Assessing which pages generate registrationsLegitimate interests, Article 6(1)(f) GDPR, in evaluating and improving our own website using the minimum data necessary.

Under the Digital Personal Data Protection Act, 2023, processing of your email address is carried out on the basis of the consent given at the point of registration, for the specified purpose of notifying you about the product's availability.

5. Storage location

All personal data described in this policy is stored on a dedicated server operated by us and hosted by Hetzner Online GmbH in Helsinki, Finland, within the European Union and the European Economic Area.

As the data remains within the EEA, no supplementary transfer mechanism is required in respect of its storage. Where you are located outside the EEA, submission of your email address involves a transfer of that data to Finland for storage.

6. Retention periods

DataRetention period
Waitlist recordRetained until the launch notification has been sent and a reasonable follow-up period has elapsed, or until you request erasure, whichever occurs first. If the product is discontinued, all records are deleted.
Server access logsRetained for 14 days, after which they are automatically overwritten. No archival copies are kept.
Rate-limiting recordsHeld in memory only and cleared at least hourly. Not written to persistent storage.

7. Recipients and disclosures

Personal data is not disclosed to third parties except as set out below.

We may disclose personal data where required to do so by law or in response to a valid and binding order from a competent authority.

8. Your rights

Subject to the conditions and exemptions in applicable law, you have the following rights. We apply these rights to all users, irrespective of their jurisdiction.

No fee is charged for exercising these rights, and doing so will not result in any detriment.

9. Exercising your rights

Requests may be sent to privacy@rankmascot.com, preferably from the email address used at registration. No account or web form is required.

We aim to respond within 7 days and will respond within the one-month period prescribed by Article 12(3) GDPR. Where we are unable to verify that a request originates from the data subject, we may request further information reasonably necessary to confirm identity.

10. Security measures

We implement technical and organisational measures appropriate to the nature and volume of the personal data processed, including:

No method of transmission or storage is entirely secure, and we cannot guarantee absolute security. Suspected security issues may be reported to privacy@rankmascot.com.

11. Cookies

This website does not use cookies. It does not write to browser local or session storage, does not register a service worker, and does not employ device fingerprinting. As no consent is required, no cookie consent banner is displayed. Should this change, this policy will be updated and, where consent is legally required, it will be obtained before any such technology is deployed.

12. Children

This website is intended for business users and is not directed at children. We do not knowingly collect personal data from children. The Digital Personal Data Protection Act, 2023 requires verifiable parental consent in respect of individuals under 18 years of age, and the GDPR sets the applicable age between 13 and 16 depending on the member state. If you believe that a child has submitted personal data to us, please contact us and it will be deleted.

13. Automated decision-making

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.

14. Scope of this policy

This policy covers the website and the pre-launch waitlist only. The Rank Mascot product has not been released.

When the product is released, it will process further categories of data on behalf of its customers, including website crawl data, data from connected Google Search Console and Google Analytics accounts, and content drafts. That processing will be governed by a separate product privacy policy and a data processing agreement, under which we will act as a processor on behalf of our customers. Nothing in this policy authorises the use of waitlist data for those purposes.

15. Changes to this policy

We may update this policy from time to time. The version number and effective date at the head of this page will be revised accordingly. Where a change materially affects how personal data already collected is used, we will notify affected registrants by email before the change takes effect. Personal data will not be processed for purposes materially different from those set out here without a further lawful basis.

16. Contact and grievances

Enquiries, requests under section 8, and complaints may be addressed to:

Email: privacy@rankmascot.com
Grievance Officer (Digital Personal Data Protection Act, 2023): [GRIEVANCE OFFICER NAME]
Postal address: [REGISTERED ADDRESS]

If you are not satisfied with our response, you may lodge a complaint with the competent supervisory authority: in the EEA, your national data protection authority; in the United Kingdom, the Information Commissioner's Office; in India, the Data Protection Board of India.