Skip to content

Rankora SEO AI

Privacy Policy

Last updated: August 29, 2026

Data controller and contact

Rankora SEO AI is operated by SHERWOOD CONSULTING, Bosch 135, 1780 Wemmel, Belgium. Privacy requests and data protection questions should be sent to privacy@francke-services.be.

What Rankora processes

Rankora SEO AI accesses the Shopify store information required to provide its SEO workflows, including product, collection, image, locale, market, publication and app-installation information covered by the permissions granted during installation. It can modify supported product SEO fields, collection SEO content and image ALT text only when a merchant explicitly publishes reviewed content.

Authentication and security data

Shopify installation, access and refresh tokens are processed to authenticate the app and call Shopify APIs. Tokens are encrypted at rest and are not shown to merchants or included in normal application logs.

AI processing

Content selected for generation can be sent to OpenAI as an AI service provider. Rankora sends only the information needed for the requested generation workflow. Merchants remain responsible for reviewing generated content before publishing it.

Operations, billing and logs

Rankora stores merchant configuration, generated drafts and revisions, job state, credit and billing records, security and audit events, and technical logs needed to operate, secure and support the service. The app does not require customer or order data for its current SEO workflows.

Retention and deletion

Uninstalling disables the matching app installation, invalidates its tokens and stops app-specific work. Shopify sends a shop/redact privacy request after uninstall; Rankora schedules deletion of the affected app data and keeps minimal deletion evidence for a limited operational period. Routine webhook receipts are pruned after 30 days and minimal deletion tombstones after 90 days. Records that must legally be retained may be kept only for the required period.

To prevent duplicate 30-day allowances after refresh, reinstall or operational erasure, we retain a pseudonymous store-and-app digest with the allowance period and granted allowance. Expired period receipts become eligible for pruning 30 days after the period ends and are pruned during allowance maintenance. Historical eligibility receipts from the discontinued introductory-credit program remain for credit audit and are not used to grant new introductory credits. These limited receipts contain no store content or access tokens and are separate from operational data deleted after uninstall. Privacy requests concerning them can be sent to the contact above.

Your rights

Merchants may request access, correction or deletion of personal data, object to or restrict certain processing, and exercise other rights available under applicable data protection law. Send privacy requests directly to privacy@francke-services.be and identify the Shopify store concerned. We may need to verify authority before acting on a request.

International processing

Service providers may process data in countries outside the merchant’s country. Where required, appropriate contractual or legal transfer safeguards are used.

Security contact

Security and privacy matters can be reported to privacy@francke-services.be. Do not include passwords, Shopify access tokens, API secrets or payment credentials in a report.