Privacy Policy
Effective date: July 21, 2026
This Privacy Policy explains how KJR Novelty & Concessions LLC ("we," "us") collects, uses, and shares information when you use seorankreport.com (the "Service"). We keep this simple and honest: we collect what we need to make your reports and run your account, and nothing else.
1. Information We Collect
- Account information: your email address, name (optional), and a securely hashed password. If you sign in with Google, we receive your name and email address from Google — never your Google password.
- Order information: the website URL you ask us to analyze, the report options and format you choose, and your answers to the intake questionnaire (business name, industry, location, keywords, competitors, goals).
- Payment information: handled entirely by Paddle, our reseller and Merchant of Record. You enter your card details with Paddle, not with us. We receive confirmation of payment and the amount — we never see or store your card number.
- Website analysis data: to build your report we fetch publicly available data about the website you submit (its pages, robots.txt, sitemap, public performance metrics). If you purchased the Competitive Intelligence upgrade, we fetch the same public data for the competitor websites you list.
- Connected Google account data (optional): if you choose to connect Google Search Console, Google Analytics, or Google Merchant Center, we read a limited, read-only slice of that account so your report can state verified facts instead of educated guesses. Specifically — from Search Console: the list of properties your account owns, and for the one matching the site you asked us to audit, its clicks, impressions, click-through rate and top search queries for the last 28 days; from Google Analytics: the list of properties and web data streams your account owns, and for the one matching your site, its session, active-user and event counts for the last 28 days; from Merchant Center: the accounts your account owns, and for the one registered to your site, how many products are approved, disapproved or awaiting review, and the reasons Google gives. We never create, modify, or delete anything in your Google accounts. We only read the account you explicitly connect, and only for the website you asked us to audit. Connecting is entirely optional — every report works without it.
- Technical basics: a session cookie to keep you signed in, and standard server logs (IP address, request time) kept by our hosting provider for security and reliability.
- Usage analytics: we measure aggregate traffic using two privacy-preserving tools, both configured so they set no cookies and cannot follow you across other websites. Plausible Analytics records anonymous page views on our public pages. Google Analytics 4 runs on those same public pages — including this one — and on your signed-in dashboard, with browser storage disabled; on the dashboard it also records when a purchase completes, including the order reference and amount, but not your name, email, or card details. Neither tool runs on the sign-in, checkout, account, or password-reset pages.
- Advertising measurement (Meta Pixel): we advertise on Facebook and Instagram, and our pages carry the Meta Pixel so we can tell which adverts lead to sales. Unlike the analytics above, this one is an advertising tool: it is provided by Meta, it sets its own cookie (
_fbp) on your device, it reports the pages you view, when you create an account, and when a purchase completes, and Meta may combine that with what it already knows about you to attribute the sale and to build advertising audiences. We do not send Meta your name, email address, card details, the website you asked us to audit, or the contents of your report. You can limit this in your Meta ad settings, or block it with any standard tracker-blocking extension — the Service works normally either way.
We do not sell any personal information, and we never use the contents of your reports, your intake answers, or any connected Google account data for advertising. Our own analytics (Plausible and Google Analytics 4) are cookieless. The one exception to all of this is the Meta Pixel described above, which is an advertising tool and does set a cookie — it is there so we can measure which adverts work, and it is the only third party we allow to place an identifier on your device.
2. How We Use Information
- To generate and deliver the reports you purchase;
- To operate your account, process payments, and provide support;
- To secure the Service and prevent fraud or abuse;
- To contact you about your order or, if you opt in, about our services. Reports you purchase include information about our professional services; contacting us about those is always your choice.
3. Service Providers We Share Data With
We share data only with the processors required to run the Service:
| Provider | Purpose | What they receive |
|---|---|---|
| Paddle | Merchant of Record: payment processing, invoicing, and sales-tax/VAT handling | Your email and payment details (entered directly with Paddle), plus the order amount and product purchased |
| Cloudflare | Hosting, database, and file storage | All Service data (encrypted in transit and at rest) |
| Resend | Sending our email. Most of it is transactional: your receipt, the notice that your report is ready, expiry reminders, refund notices, password resets, and email confirmation. Two are reminders rather than transactions, and you can switch them off — a nudge if you leave a checkout unfinished, and a one-time reminder before your report expires that you can re-audit the site. Both stop as soon as you untick the newsletter box in Account settings, and every one of them carries a one-click unsubscribe | Your email address and the contents of each message — which includes the website being audited, your order reference and the amount paid, your report's score, and a short excerpt of its written summary. Never your password, your card details, or the report file itself |
| MailWizz | Running our newsletter list — only if you tick the newsletter box when you sign up or in Account settings, or submit one of our Facebook or Instagram lead forms. This is our own newsletter software, running on our own server | Your email address, and your name if you gave one. Nothing about your order, the website you asked us to audit, or your report. Untick the box in Account settings and we remove you from the list; deleting your account removes you as well |
| Anthropic | AI-assisted report analysis | Public content from the analyzed website, your intake answers (business details, keywords, competitors), and — if you connected a Google account — the summary figures described in section 1 (for example "61 clicks, 1,753 impressions", "96 sessions", "0 of 10 products approved"), so the written analysis reflects your real data instead of guessing. Never your account credentials, payment data, or Google access tokens. Under Anthropic's commercial API terms this content is not used to train their models |
| Optional sign-in; public PageSpeed data; business-listing lookup | Sign-in: standard OAuth exchange. PageSpeed: the analyzed website's URL. Places API (Local SEO module only): the business name and service area from your intake, used to check whether a Google Business Profile exists for your site | |
| Google (connected accounts) | Reading your own Search Console, Analytics, and Merchant Center data — only if you connect them | Nothing about you is sent to Google beyond the standard OAuth exchange and the read requests themselves. This row describes data we receive from Google on your behalf — see section 6 |
| Google Analytics 4 | Aggregate usage analytics on our public pages and on the signed-in dashboard | Page views and, on the dashboard, a purchase event containing the order reference and amount. Configured with browser storage disabled, so no cookie is set and no cross-site identifier is created |
| Plausible Analytics | Aggregate usage analytics on public pages | Anonymous page views and referrer. No cookies, no personal identifiers, no cross-site tracking |
We may also disclose information if required by law, or as part of a business transfer (e.g., merger or acquisition), in which case this policy would continue to apply.
4. Data Retention
- Report files: automatically and permanently deleted 6 months (180 days) after generation.
- Account and order records: kept while your account is active and as needed for tax, accounting, and legal purposes.
- Connected Google accounts: we keep only the access and refresh tokens needed to make the read-only calls described in section 1, plus the email address of the connected account so you can see which one is linked. We do not maintain a separate database of your Google data: the figures are fetched fresh each time a report is generated, and the only place they persist is inside that report itself, where they are deleted with it after 180 days. When you disconnect a service we delete our stored token for it immediately, so we can no longer read that service at all. Because Google issues a single authorisation covering every service you've connected, revoking it with Google would also disconnect the ones you kept — so we revoke with Google at the point it can do no collateral damage: when you disconnect your last remaining service, or delete your account. You can also revoke us directly at any time at myaccount.google.com/permissions.
- Account deletion: delete your account from Account settings, or email us at the address below. We delete your account and everything attached to it — your orders and intake answers, your report files, any feedback you left, and any unredeemed promotional credit or Facebook/Instagram lead-form record held under your account's email address — along with any connected-account tokens (revoking them with Google as above), and we remove you from our newsletter list. The only exception is records we are legally required to keep (e.g., payment records).
5. Cookies
We use a small number of essential cookies, and nothing else of our own: rr_session keeps you signed in; rr_reset carries your password-reset link for one hour so the reset code never has to travel in a web address; a short-lived cookie prevents forgery attacks while you are being redirected to Google, Facebook or Apple — both when you sign in with them and when you connect Search Console, Analytics or Merchant Center; and, for administrators only, a short-lived two-factor cookie. All are HttpOnly — no script on the page can read them — and none is used to track you or shared with anyone. Our own analytics are deliberately cookieless: Plausible sets no cookies by design, and Google Analytics runs with browser storage and advertising signals switched off, so neither can place an identifier on your device.
One third-party cookie is set: the Meta Pixel places _fbp to attribute advertising. If you would rather it did not, block it with a tracker-blocking extension or your browser's tracking protection — nothing on the Service depends on it.
6. Google User Data and Limited Use
This section applies only if you choose to connect a Google account. Connecting is optional, every report works without it, and you can disconnect at any time.
SEO Rank Report's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The permissions we request, and exactly why each one is needed:
| Permission | What it lets us read | Why the report needs it |
|---|---|---|
.../auth/webmasters.readonly(Search Console) | Your list of verified properties, and the search performance of the one matching your site | To report your real clicks, impressions, click-through rate and top queries instead of estimating them. Search Console is a private account we cannot see from your website |
.../auth/analytics.readonly(Google Analytics) | Your list of GA4 properties and web data streams, and the session/user/event totals of the one matching your site | To confirm your analytics is not just installed but actually recording. A tag can be present and silently collecting nothing — a page scan cannot detect that, and a connected account can |
.../auth/content(Merchant Center) | Your list of Merchant Center accounts, and the product approval status of the one registered to your site | To show which products are approved, disapproved, or awaiting review and why, instead of inferring it from on-page markup |
- We only read. None of these permissions is used to create, change, or delete anything in your Google accounts.
- We use it only to build your own reports for the website you asked us to audit — the user-facing feature you connected the account for.
- We never sell it, use it for advertising or ad targeting, build profiles from it, use it to train AI models, or share it with anyone beyond the processors named in section 3 (Cloudflare for storage, Anthropic to write the analysis in your report, and Resend to email you that the report is ready — that email quotes a short excerpt of the analysis, which may repeat a figure drawn from your connected account).
- No humans read it except where you ask us to for support, or where required by law or to investigate abuse or a security issue.
- Tokens are stored in our Cloudflare database, encrypted at rest, and used solely to make the read-only calls above.
- You can revoke access at any time — press Disconnect on your dashboard, which deletes our stored token for that service immediately, so we can no longer read it at all. Because Google issues a single authorisation covering every service you've connected, revoking that authorisation would also disconnect the ones you kept — so we revoke it with Google when you disconnect your last remaining service, or delete your account, as described in section 4. You can also revoke it yourself at any time at myaccount.google.com/permissions.
7. Security
Passwords are hashed with an industry-standard algorithm (PBKDF2) and never stored in plain text. All traffic is encrypted with HTTPS. Report files are stored in access-controlled storage and are only downloadable by the purchasing account. No system is perfectly secure, but we design conservatively: we simply don't collect data we don't need.
8. Your Rights
Depending on where you live (for example, under the GDPR in Europe or the CCPA/CPRA in California), you may have rights to access, correct, delete, or export your personal information, and to object to certain processing. We honor reasonable requests from anyone, regardless of location — just email us. California residents: we do not sell or "share" personal information as defined by the CCPA. We do not knowingly collect information from children under 18; the Service is for business use by adults.
9. International Users
The Service is operated from the United States and data is processed in the United States (and on Cloudflare's global network). By using the Service you consent to this processing.
10. Changes
We may update this policy; the effective date above reflects the latest version. Material changes will be indicated on this page.
11. Contact
KJR Novelty & Concessions LLC
Support email: support@seorankreport.com
Phone: (352) 263-3793
Self-service: change email/password, download all your data, or delete your account from Account settings.