Privacy Policy
Last updated: 28/06/2026
This Privacy Policy explains how the RankStandings platform handles personal data across its website, admin dashboard, integrations, webhooks, imports, reports and operational communications.
1. Roles in data processing
When a company uses the platform to record reps, customers, sales, products, targets or CRM integrations, that company is responsible for deciding which data is sent and for ensuring it has a legal basis for that processing. The platform acts as a service provider and processes that data on the customer company's instructions, in order to run leaderboards, reports, permissions, auditing, support and security.
2. Data we process
We may process data entered directly by users or received through authorised integrations, including:
- account data, such as name, email, company, access profile and authentication details;
- sales data, such as reps, customers, sales, products, targets, leaderboards and performance history;
- integration data, such as external identifiers, webhook payloads, logs, sync status and errors;
- technical data, such as IP address, browser, sessions, security events and audit records;
- billing data, such as plan, subscription status, invoices, payments and related communications.
3. Purposes
Data is used to build leaderboards and reports, authenticate users, enforce permissions, process integrations, send essential messages, prevent abuse, maintain audit trails, meet legal obligations and improve the reliability of the service.
4. Sharing
Data may be shared with providers needed for hosting, databases, storage, email delivery, payment processing, security and the integrations requested by the customer company. We do not sell personal data. We may also share data where necessary to comply with the law, respond to an order from a competent authority, defend legal rights or prevent fraud.
5. Integrations and webhooks
The customer company decides which external systems are connected and which events are sent. Integration payloads may contain personal or commercial data. The platform uses that data to run the integration, maintain traceability, reprocess failures and protect the service against misuse.
6. Retention and deletion
We keep data for as long as necessary to provide the service, meet legal obligations, maintain security, resolve disputes and preserve audit records. The customer company may request correction or deletion of data in line with its contract and applicable law, subject to legal obligations and technical backups.
7. Security
We apply technical and administrative controls to reduce risk, including authentication, role-based permissions, CSRF protection, webhook signing, audit logs, upload validation, backups and per-company data segregation.
8. Data subject rights
Subject to applicable law, data subjects may request access, confirmation of processing, correction, deletion, portability, information about sharing, and review of certain decisions. Where a request concerns data controlled by a customer company, we may direct the request to that company.
9. International transfers
Providers of infrastructure, email, storage, payments or integrations may operate outside the user's country. Where that is the case, we will apply measures consistent with applicable law and with the purpose of providing the service.
10. Contact
For questions about privacy or security, or to make a data subject request, contact us at contact@rankstandings.com.