This policy explains what personal data RankMoss collects, how we use it, the legal bases we rely on, and your rights. RankMoss is a marketing/SEO content platform that generates and delivers content to the websites you connect.
Who we are
RankMoss is a trading name of NTUK Ltd, a company registered in England and Wales (company number 08765474), registered office Office 7, 35-37 Ludgate Hill, London, England, EC4M 7JN. NTUK Ltd is the data controller for the personal data described here. Contact us via our contact form.
What we collect
- Account data - your name, email address and a hashed password when you register, and the team members you invite.
- Project data - the sites, positioning, keywords, brand details and content you create in the platform.
- Connection credentials - API tokens/keys for the sites you connect (WordPress, Shopify, Webflow, Ghost, GitHub). These are encrypted at rest (AES-256-GCM) and used only to deliver your approved content to your own site. We never log them.
- Analytics data (read-only) - when you connect Google Search Console and GA4, we read aggregate performance data (keywords, pages, positions, traffic). We do not read your visitors' personal data.
- Usage & billing data - how you use the service, and, if you subscribe, billing details handled by our payment processor.
- Support data - messages you send us via the contact form or support email.
Shopify data (for connected Shopify stores)
When you connect a Shopify store, we want to be explicit about what we do and do not touch:
- We request only the `write_content` scope - enough to create blog articles. We do not access your customers, orders, products, or any customer personal data.
- The Shopify access token is encrypted at rest and used only to publish content you have approved.
- We implement Shopify's mandatory privacy webhooks. On app uninstall or a shop-redact request, we delete the stored connection/token for that shop. We hold no Shopify customer data, so customer data-request/redact webhooks are acknowledged with nothing to return.
How we use your data & our legal bases (UK GDPR)
- To provide the service - generate content, run safety checks, deliver approved content (performance of our contract with you).
- To operate, secure, support and improve the platform (our legitimate interests).
- To communicate about your account - e.g. password resets, service notices (contract / legitimate interests).
- To meet legal and tax obligations (legal obligation).
- Where required, on the basis of your consent, which you may withdraw at any time.
Service providers (sub-processors)
We share data only as needed with providers that help us run the service:
- Supabase - database & authentication. Vercel and Render - hosting & background processing.
- Anthropic - AI content generation (your positioning/prompts are processed to generate content).
- Google - Search Console & Analytics APIs (read-only, when you connect them), and Google Analytics on our own site to measure usage (only if you accept analytics cookies).
- The site platforms you connect (WordPress, Shopify, Webflow, Ghost, GitHub) - to deliver your approved content to your own site, using credentials you provide.
- Resend - transactional & support email. Stripe - payments (if you subscribe).
- Cloudflare - Turnstile bot protection on our sign-up form (verifies you're human; no tracking cookies).
Some providers may process data outside the UK/EEA; where they do, we rely on appropriate safeguards (e.g. the UK IDTA / EU Standard Contractual Clauses).
Content delivery & your domain
RankMoss does not host or serve your website. We deliver content you have approved to the channel you configured; you remain responsible for what is published on your own domain.
Data retention
We keep your data while your account is active and for a reasonable period afterwards to meet legal, security and accounting needs. You can delete projects at any time; deleting your account removes your project data, and connection credentials are removed when you disconnect a site or uninstall the app.
Security
Each account's data is isolated (row-level security), connection credentials are encrypted, and we never log secrets. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.
Your rights
Under UK data protection law you may request access to, correction or deletion of your data, object to or restrict certain processing, request portability, and withdraw consent. Use our contact formto exercise these rights. If you are unhappy with our response you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
Changes
We may update this policy; material changes will be posted here with a new “last updated” date.