Privacy Policy

Last updated: June 16, 2026

RankShield ("RankShield", "we", "us") is a website-and-advertising fraud-protection service operated by SEO Elite Agency, Naples, Florida, USA. This policy explains what data we process, why, and your rights. It covers the RankShield WordPress plugin and the RankShield service it connects to (the "Service"). Questions: [email protected].

1. Who is the data controller

For the website owner who installs RankShield, SEO Elite Agency acts as a data processor handling visitor data on the site owner's behalf; the site owner is the controller for their visitors' data. For your own account and billing information, SEO Elite Agency is the controller.

2. What we collect and why

a) From your website's visitors (via the plugin)

To detect bot traffic, CTR-manipulation attacks, and ad click fraud, the plugin sends the following to the Service for each relevant request:

Legal basis: the legitimate interest of the site owner in protecting their site and ad budget from fraud. IP addresses are processed for security and fraud-prevention and are not used to build advertising profiles.

b) Your account & billing

c) Connected Google accounts (optional)

If you choose to connect Google Search Console, Google Analytics 4, or Google Ads, you grant read-only access via Google OAuth. We store the OAuth tokens securely and request only the data needed to display your dashboards (rankings/impressions/clicks, conversions/engagement, and ad cost/CPC respectively). You can disconnect at any time, which revokes our access.

Google API Limited Use disclosure. RankShield's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide and improve the user-facing features in RankShield; we do not transfer it to others except as necessary to provide the Service, for security, or to comply with law; we do not use it for advertising; and we do not allow humans to read it except with your consent, for security, or as required by law.

3. Cookies

When the plugin challenges suspicious traffic, it sets one functional cookie, rs_pass, in the visitor's browser (about 24 hours) so a verified real browser is not re-challenged. It contains a one-way verification token, not personal data. RankShield sets no advertising or cross-site tracking cookies.

4. Service providers (sub-processors)

Each processes data only to provide their function to us. We do not sell personal data.

5. Data retention

Behavioral and event data is retained only as long as needed for fraud detection and reporting and is then aggregated or deleted. Account and billing records are kept for the life of the account and as required by law (e.g. tax). You may request deletion as described below.

6. Security

Data is transmitted over TLS and access is restricted. API keys and OAuth tokens are stored server-side and are never exposed to website visitors. No method of transmission or storage is 100% secure, but we take commercially reasonable measures to protect your data.

7. Your rights

Depending on your location (including under GDPR and the CCPA/CPRA), you may have the right to access, correct, delete, or port your data, to object to or restrict processing, and to withdraw consent. To exercise any right, email [email protected]. We will respond within the time required by applicable law.

8. International transfers

We are based in the United States and our providers may process data in the US and other countries. Where required, transfers are made under appropriate safeguards.

9. Children

The Service is for businesses and is not directed to children under 16, and we do not knowingly collect their personal data.

10. Changes

We may update this policy; material changes will be reflected by the "Last updated" date and, where appropriate, by notice. Continued use after changes constitutes acceptance.