Legal

Privacy Policy

Last updated: July 15, 2026

RankingAI OÜ ("we", "us", "our", or "RankingAI") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, and protect personal information when you use our services or visit rankingai.com (the "Service").

As an Estonian data controller, we process personal data under the EU General Data Protection Regulation (GDPR), applicable Estonian law, and other data-protection rules that apply to the relevant service. The UK Data Protection Act 2018 applies where a UK processing activity falls within its territorial scope.

1. Data Controller

The data controller for personal information collected through this Service is:

  • Name: RankingAI OÜ
  • Registry code: 17512460
  • Registered office: Tartu mnt 67/1-13b, Tallinn 10115, Estonia
  • Website: https://rankingai.com
  • Telephone: +86 137 7186 1896
  • Contact: privacy@rankingai.com

2. Information We Collect

2.1 Information you provide

  • Account information (name, email address, phone number)
  • Payment information (processed by third-party payment processors)
  • Domain watchlists and target lists
  • Communications with our support team

2.2 Information collected automatically

  • Server and security log data (IP address, browser type, requested pages, and timestamps)
  • Technical request data (operating system, device type, and error information)

The current public website does not load advertising, behavioural tracking, or analytics cookies.

2.3 Information from third parties

  • Public WHOIS / RDAP data for monitored domains, where available
  • Domain registry technical responses

3. Legal Basis for Processing

We process personal data on the following legal bases under GDPR Article 6:

  • Contract performance — to provide the services you have subscribed to
  • Legal obligations — to comply with applicable law
  • Legitimate interests — to operate, improve, and secure our services
  • Consent — for marketing communications and optional cookies

4. How We Use Your Information

  • To deliver domain monitoring, dropcatch, and registration services
  • To process payments and manage your account
  • To send service notifications and respond to support requests
  • To improve and optimize our platform
  • To detect and prevent fraud, abuse, and security incidents
  • To comply with legal obligations including registry compliance, tax law, and AML

5. Data Sharing

We may share your information with:

  • Domain registries (including Traficom for .fi, DOMREG / the .lt registry, SWITCH for .ch and .li, Registry .MX / NIC Mexico for .mx and .com.mx, Punktum.dk, AFNIC, EURid, DENIC, and others where applicable) when registering or managing domains on your behalf - only the data required by registry rules and the requested procedure
  • Payment processors for billing
  • Cloud infrastructure providers (Frankfurt, Germany) for hosting
  • Legal authorities when required by applicable law

We do not sell your personal data to third parties.

6. International Transfers

Your data is primarily processed within the European Economic Area (EEA). When data must be transferred outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.

7. Data Retention

We retain personal data only as long as necessary:

  • Account data: for the duration of your account, plus 7 years for accounting compliance
  • Transaction records: 7 years (required by applicable tax law)
  • Domain order & backorder evidence: registrant/contact details and the acceptance record you submit through our domain request and backorder forms are stored privately and retained to provide the service, evidence registry acceptance, and meet registry and legal record-keeping requirements. For .mx and .com.mx registration and management requests, we retain the customer instruction, registry-rule acceptance, registrant/contact data, billing and payment records, nameserver and DNSSEC/DS instructions, transaction records, support history, and related Registry .MX evidence for as long as needed to provide the service, maintain the domain relationship, comply with Registry .MX procedures, handle support, billing, abuse, security, complaints, disputes, audit, accounting, and legal obligations. For .ch and .li registration and management requests, we retain the customer instruction, registry-rule acceptance, holder/contact data, nameserver and DNSSEC/DS instructions, transaction records, support history, and related SWITCH registry evidence for as long as needed to provide the service, maintain the domain relationship, comply with SWITCH procedures, handle support, billing, abuse, security, disputes, audit, accounting, and legal obligations. For .dk registrations and backorders, agreement acceptance evidence is retained for at least one year from the acceptance timestamp, and longer where necessary for registry compliance, billing, dispute handling, abuse handling, tax/accounting, or legal obligations. For .lt registration and management requests, we retain the customer instruction, registry-rule acceptance, contact/holder data, DNSSEC/DS instructions, transaction records, support history, and related registry evidence for as long as needed to provide the service, maintain the domain relationship, comply with DOMREG procedures, handle support, billing, abuse, security, disputes, audit, accounting, and legal obligations. Backorders that are cancelled or not caught, and their personal data, are deleted once they are no longer needed for those purposes.
  • Marketing data: until you unsubscribe
  • Log data: typically 90 days, longer for security incidents

8. Your GDPR Rights

You have the following rights regarding your personal data:

  • Right of access — request a copy of your data
  • Right to rectification — correct inaccurate data
  • Right to erasure — request deletion ("right to be forgotten")
  • Right to restriction — limit how we process your data
  • Right to data portability — receive your data in a machine-readable format
  • Right to object — object to processing based on legitimate interests
  • Right to withdraw consent — for any processing based on consent
  • Right to lodge a complaint — with your local data protection supervisory authority

To exercise any of these rights, contact us at privacy@rankingai.com. We will respond within 30 days.

9. Security

We implement industry-standard technical and organizational measures to protect your personal data, including:

  • TLS 1.3 encryption for all data in transit
  • Encrypted storage at rest
  • Access controls and authentication
  • Regular security audits and updates
  • Incident response procedures

10. Registrar Data Processing

Where RankingAI provides or prepares registrar services, we may process domain holder, administrative, technical, billing, nameserver, account, support, abuse, and transaction data. Depending on the relevant registry or registrar agreement, such data may be shared with domain registries, escrow providers, dispute providers, ICANN where applicable, technical providers, law enforcement, courts, or competent authorities.

Registrar data may be retained for registry, ICANN, legal, accounting, abuse-prevention, security, and audit purposes. Public WHOIS or RDAP publication will follow applicable law and the policy of the relevant registry or accreditation framework.

For .lt services, RankingAI may process and transmit domain holder, registrant account, technical contact, nameserver, DNSSEC/DS, support, payment, and registry procedure data to DOMREG / the .lt registry and to relevant technical providers where needed to register, renew, transfer, trade, update, secure, support, or otherwise manage a .lt domain. DOMREG may process that data in its Domain Administration System and may issue registrant account activation or procedure notices directly to the domain holder or contact email address.

Before a manual .lt service request is accepted, RankingAI requires the customer to acknowledge the applicable .lt rules and consent to the data processing needed to perform the requested registry procedure.

For .ch and .li services, RankingAI may process and transmit domain holder, contact, nameserver, DNSSEC/DS, support, payment, and registry procedure data to SWITCH and to relevant technical providers where needed to register, renew, transfer, update, secure, support, or otherwise manage a .ch or .li domain. SWITCH may process that data according to its official rules, procedures, privacy requirements, and applicable law.

Before a manual .ch or .li service request is accepted, RankingAI requires the customer to acknowledge the applicable SWITCH rules and consent to the data processing needed to perform the requested registry procedure.

For .mx and .com.mx services, RankingAI may process and transmit registrant, administrative, technical, billing, nameserver, DNSSEC/DS, support, payment, and registry procedure data to Registry .MX / NIC Mexico and to relevant technical, billing, support, dispute, or compliance providers where needed to register, renew, transfer, update, secure, support, or otherwise manage a .mx domain.

Registry .MX / NIC Mexico may process, publish, transfer, or disclose domain and contact information according to its official rules, WHOIS/RDDS practices, privacy notices, registry procedures, dispute processes, competent-authority requests, court orders, law enforcement requests, and applicable law. Registry .MX may also notify registrants or contacts directly about domain procedures. Customers are responsible for keeping all .mx domain data correct, complete, accurate, and current.

Before a manual .mx or .com.mx service request is accepted, RankingAI requires the customer to acknowledge the applicable Registry .MX rules and consent to the data processing and international transfer needed to perform the requested registry procedure.

For .fi services, RankingAI may process and transmit domain holder, contact, billing, nameserver, DNSSEC/DS, support, payment, abuse, lawful-information-request, and registry procedure data to Traficom and to relevant technical, billing, support, dispute, or compliance providers where needed to register, renew, transfer, update, secure, support, or otherwise manage a .fi domain.

RankingAI verifies .fi domain-user information using reliable methods such as company-register checks, contact confirmation, authorization checks, identity or representative-authority evidence, and other documentary checks where appropriate. Traficom may process, publish, transfer, or disclose .fi domain information through its domain search / WHOIS service, OData interface, competent-authority processes, dispute procedures, or other lawful channels according to Traficom rules and applicable law.

Before a manual .fi service request is accepted, RankingAI requires the customer to acknowledge the applicable Traficom rules and consent to the data processing needed to perform the requested registry procedure. Lawful requests for .fi domain information are assessed for requester authority and data-protection compliance before disclosure.

11. .eu / EURid Registration Data

For .eu services, RankingAI may process and transmit registrant, contact, eligibility, nameserver, DNSSEC, support, payment, abuse, security, and transaction data to EURid and relevant technical or dispute-resolution providers where needed to register, renew, transfer, update, secure, support, or otherwise manage a .eu domain.

Before submitting a .eu registration or management transaction, RankingAI records the customer's specific instruction and evidence that the applicable EURid terms and policies were accepted. We may verify identity, contact details, eligibility, and representative authority using reliable sources or supporting documents. Customers must keep their registration data accurate and provide a functioning email address.

EURid processes .eu registration data as a separate controller under its own privacy policy and may validate, publish, restrict, disclose, or otherwise process data according to applicable law and EURid rules. See the EURid Privacy Policy, the EURid Document Repository, and our Registration Data Policy.

12. Cookies

The current public website does not load analytics, advertising, or other optional cookies. Essential storage may be used only where it is technically necessary to provide a feature requested by you. Because no optional cookies are currently loaded, the website does not display a consent banner.

If we introduce optional cookies in the future, we will update this notice and obtain any consent required by law before those cookies are loaded. A preference control will then be made available.

13. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Significant changes will be notified by email or through the Service where appropriate. Each version is effective from the date stated at the top of this page.

15. Contact

If you have questions about this Privacy Policy or our data practices, please contact us:

  • Email: privacy@rankingai.com
  • General inquiries: hello@rankingai.com
  • Telephone: +86 137 7186 1896
  • Address: RankingAI OÜ, Tartu mnt 67/1-13b, Tallinn 10115, Estonia

This document is provided in English. In case of conflict, the English version shall prevail.