RankShield ("RankShield", "we", "us") is a website-and-advertising fraud-protection service operated by SEO Elite Agency, Naples, Florida, USA. This policy explains what data we process, why, and your rights. It covers the RankShield WordPress plugin and the RankShield service it connects to (the "Service"). Questions: [email protected].
For the website owner who installs RankShield, SEO Elite Agency acts as a data processor handling visitor data on the site owner's behalf; the site owner is the controller for their visitors' data. For your own account and billing information, SEO Elite Agency is the controller.
To detect bot traffic, CTR-manipulation attacks, and ad click fraud, the plugin sends the following to the Service for each relevant request:
gclid, wbraid, gbraid, msclkid, fbclid) and the campaign name, so click fraud can be scored.Legal basis: the legitimate interest of the site owner in protecting their site and ad budget from fraud. IP addresses are processed for security and fraud-prevention and are not used to build advertising profiles.
If you choose to connect Google Search Console, Google Analytics 4, or Google Ads, you grant read-only access via Google OAuth. We store the OAuth tokens securely and request only the data needed to display your dashboards (rankings/impressions/clicks, conversions/engagement, and ad cost/CPC respectively). You can disconnect at any time, which revokes our access.
When the plugin challenges suspicious traffic, it sets one functional cookie, rs_pass, in the visitor's browser (about 24 hours) so a verified real browser is not re-challenged. It contains a one-way verification token, not personal data. RankShield sets no advertising or cross-site tracking cookies.
Each processes data only to provide their function to us. We do not sell personal data.
Behavioral and event data is retained only as long as needed for fraud detection and reporting and is then aggregated or deleted. Account and billing records are kept for the life of the account and as required by law (e.g. tax). You may request deletion as described below.
Data is transmitted over TLS and access is restricted. API keys and OAuth tokens are stored server-side and are never exposed to website visitors. No method of transmission or storage is 100% secure, but we take commercially reasonable measures to protect your data.
Depending on your location (including under GDPR and the CCPA/CPRA), you may have the right to access, correct, delete, or port your data, to object to or restrict processing, and to withdraw consent. To exercise any right, email [email protected]. We will respond within the time required by applicable law.
We are based in the United States and our providers may process data in the US and other countries. Where required, transfers are made under appropriate safeguards.
The Service is for businesses and is not directed to children under 16, and we do not knowingly collect their personal data.
We may update this policy; material changes will be reflected by the "Last updated" date and, where appropriate, by notice. Continued use after changes constitutes acceptance.