This Privacy Policy explains how RankRack collects, uses, shares and protects personal data when you browse the platform, create an account, publish or respond to a review, claim or manage a provider profile, purchase a membership, contact us, use an integration or otherwise interact with our services.
Controller: RankRack Ltd, trading as RankRack
Company details: Registered in England and Wales | Company no. 17378395
Privacy contact: [email protected]
ICO registration: ZC215753
RankRack is an independent platform for reviews and comparisons of game-server hosting, web hosting, VPS/VDS, dedicated servers, cloud hosting and related services.
1. Who we are and when this policy applies
RankRack Ltd ("RankRack", "we", "us" or "our") is a company registered in England and Wales. Our registered office is 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. For the personal data described in this policy, RankRack will usually be the data controller, meaning we decide why and how that data is used.
This policy applies to Rank-Rack.com, related RankRack pages, customer and provider accounts, review and moderation services, provider memberships, APIs, invitations, Discord or other integrations, support channels and communications that link to this policy. A third party's own privacy policy applies when it independently decides how to use personal data, for example, a payment processor, Discord, a hosting provider being reviewed, or a website that displays RankRack content through our data feeds.
RankRack's core data-protection framework is the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), and those laws as amended by the Data (Use and Access) Act 2025. The Information Commissioner's Office (ICO) regulates UK data protection. Where mandatory overseas privacy laws apply to a particular person or activity, we will also respect those requirements.
2. Personal data we collect
The data we collect depends on how you use RankRack. We aim to collect only what is relevant and necessary.
- Account and identity: Legal name, display name, email address, password hash, authentication records, date of birth (accounts are 18 or over), postal address and notification preferences.
- Review and public content: Ratings, review headlines and text, the guided answers shown on your review, service type, provider, dates of experience, edits and provider replies. Reports you make and helpful votes you cast are held privately and shown only as counts.
- Verification and moderation: The order and invoice references, purchase date and billing email typed into the review form's verification step, support correspondence, IP and device signals, fraud indicators, appeal information and moderation decisions.
- Provider and business accounts: Business name, company number, domain, address, professional contact details, role or authority, claim evidence, team members, profile content, invitations, integration settings, analytics and account activity.
- Payments and transactions: Membership tier, billing contact, country, tax or VAT information, transaction status and limited payment metadata. Card details are handled by our payment processor and never reach RankRack.
- Technical and usage data: IP address, device and browser type, timestamps, session records, approximate country derived from your network address, and the anonymous daily visit counts the Cookie Policy describes. We do not keep browsing logs, referring URLs or crash-reporting profiles.
- Communications: Support emails, complaints, data-rights requests and records of our responses. If you link a Discord account, we hold the link and use it only to show your Discord name and manage roles in our own server.
- Information from third parties: Provider information from public business sources, the email address a provider supplies when inviting a customer to review, payment status from our payment processor, and information another user submits about an interaction involving you.
Please do not place passwords, API keys, full payment-card details, private IP addresses, precise server credentials, government identity documents, health information or other unnecessary sensitive data in a public review. Purchase details for verification belong in the verification step of the review form, never in the review text.
3. Public information and hosting reviews
RankRack is a public review platform. Your display name, profile image, rating, review, date of experience, service category, edits and other content identified as public may be visible worldwide. Provider replies and provider-profile information may also be public. Public content may be indexed by search engines, cached, quoted, linked to, displayed on other websites through RankRack APIs, and viewed by the provider concerned.
We do not make private verification evidence public merely because it supports a review. We may provide a provider with limited information needed to identify a genuine transaction, such as an order reference, where this is lawful, proportionate and explained when the evidence is collected. We will not normally disclose the underlying document itself without a valid reason or your permission.
If you delete your account or a review, copies may remain temporarily in backups, search-engine caches, third-party archives or content already lawfully republished outside our control. We will act on valid requests relating to data we control, but cannot guarantee deletion by independent third parties.
4. Why we use personal data and our lawful bases
UK data-protection law requires a lawful basis for each use. The principal purposes and bases RankRack expects to rely on are below. The exact basis may differ where local law applies.
- Create and operate accounts; publish reviews and replies; supply memberships, APIs, data feeds and requested integrations. We use account, review, provider, transaction and usage data. Our lawful basis is performing a contract or taking steps at your request before entering into one.
- Moderate content; verify experiences; investigate fake reviews, conflicts, manipulation, abuse and security incidents. We use review content, evidence, communications, technical data and fraud signals. Our lawful basis is our legitimate interests in platform integrity, safety and fraud prevention, or a legal obligation where applicable.
- Process payments, accounting, tax, refunds and debt management. We use transaction, business and contact data. Our lawful bases are contract, legal obligation and legitimate interests.
- Provide support and resolve complaints, appeals and data-rights requests. We use account, communications, moderation and verification data. Our lawful bases are contract, legal obligation and legitimate interests.
- Improve reliability, accessibility and product performance, and understand aggregate use. We use usage, device, crash and feedback data. Our lawful basis is legitimate interests, or consent where required for cookies or similar technologies.
- Send service notices and important platform communications. We use account and contact data. Our lawful bases are contract, legal obligation and legitimate interests.
- Send marketing and measure campaigns. We use contact, preference and engagement data. Our lawful basis is consent where required; otherwise, we rely on legitimate interests subject to PECR and your right to object.
- Establish, exercise or defend legal claims, and comply with regulators, courts or lawful authorities. We use relevant account, content, transaction, evidence and technical data. Our lawful bases are legal obligation, legitimate interests and recognised legitimate interests where applicable.
5. Reviews, invitations and providers
A provider may invite a customer to review its service. Depending on how the invitation works, the provider may supply an email address, name, order reference or service information to RankRack, or may send the invitation itself using RankRack tools. The invitation screen should explain which organisation supplied the data and the roles each organisation has.
Providers are independent controllers for personal data they collect for their own customer relationship, billing, support, marketing and invitation decisions. RankRack is not responsible for a provider's independent privacy practices. Providers must not use reviewer information obtained through RankRack for unrelated marketing, retaliation, profiling or harassment.
Provider profile information may be created from public business records, provider websites or user submissions. If it contains professional personal data, we use it to identify, categorise and contact the provider, maintain accurate listings, prevent impersonation and operate the review service. A person may contact us to correct inaccurate professional information.
6. Moderation, fraud detection and automated tools
We may use rules, statistical signals, matching technology or automated tools to flag suspicious reviews, accounts, invitations, payments or activity. Signals may include unusual posting patterns, duplicate content, network and device information, account history and links between reviewers and providers. These tools support, not replace, our moderation work.
Unless we tell you otherwise and provide the safeguards required by law, RankRack will not make a decision based solely on automated processing that produces legal effects or similarly significant effects for you. Where a moderation or account decision materially affects you, you may ask for an explanation, submit relevant information and request human review through [email protected].
7. Who we share personal data with
We may disclose only the data reasonably needed to the following recipients:
- Service providers acting on our instructions: our hosting supplier and our content delivery network. Our database, email sending and moderation run on RankRack's own infrastructure.
- Payment, billing and fraud-prevention providers, which may act as independent controllers for parts of their services.
- The provider you reviewed, where information is public or limited information is necessary to verify an experience, investigate a report or resolve a dispute.
- Integration and API partners you choose to connect, and websites that display public RankRack content through a permitted API.
- Professional advisers, auditors, insurers and finance providers subject to appropriate confidentiality duties.
- Courts, regulators, law-enforcement bodies and public authorities where disclosure is required by law or is necessary and proportionate to protect rights, prevent crime or respond to a lawful request.
- A buyer, investor, lender or successor in connection with a proposed or completed restructuring, financing, merger or sale, subject to confidentiality and data-protection safeguards.
We do not sell private personal data for money. If RankRack later engages in advertising, data licensing or other activity that is treated as a "sale", "sharing" or targeted advertising under an applicable US state law, we will give affected users the required notice and opt-out mechanism before that activity begins.
8. International data transfers
RankRack is based in the United Kingdom, but users, providers and service suppliers may be located elsewhere. Personal data may therefore be accessed or stored outside the country where it was collected.
For a restricted transfer from the UK, we will use a lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, or a permitted exception. Where safeguards are used, we will carry out the assessment required by law and apply supplementary technical or organisational measures where appropriate.
You can contact us for more information about the transfer mechanism relevant to your personal data. We may redact confidential commercial terms from copies of contractual safeguards.
9. Data retention
We keep personal data only for as long as it is reasonably needed for the purpose it was collected for, to meet legal and accounting duties, to resolve disputes, and to protect RankRack and its users from fraud or abuse. The schedule below describes what the platform actually does.
- Account and registration details: For the life of the account. When you confirm account deletion, the account record and the registration details we hold (including date of birth and postal address) are deleted straight away, your notifications are deleted, and your reviews are anonymised: the text stays, the name comes off and the link to the account is cut. Deletion is refused while the account still runs a provider page; ask us to close the page first.
- Published reviews and replies: For as long as they remain published, as part of the public review record. A review you delete yourself is purged from our records 24 months after you delete it. A review we remove for breaking the rules is kept as the record of that decision, and is anonymised if the account is later deleted.
- Verification and purchase details: The order details supplied to verify a review (order and invoice numbers, purchase date, billing email) are removed 24 months after the check is decided, or sooner if the review itself is purged first. The outcome of the check stays with the review. Details still being checked are kept until the decision.
- Moderation records: Flags raised on a review, automatically or by a reader, are removed 24 months after they are decided. Appeals and their outcomes are kept as the record of the decision. Our internal log of staff actions is kept for the life of the platform and identifies staff by an internal id rather than a name.
- Review invitations: The record that an invitation was sent, including the address it went to, is kept for 24 months from sending; after that the address is removed and only the counts remain.
- Support and complaints: Correspondence is kept while a matter is open and afterwards as the record of how it was handled. The platform's own log of the emails it has sent expires after 90 days.
- Billing: We store only the identifiers that link a provider page to its subscription. Invoices and payment details are held by our payment processor, and accounting records are kept for as long as UK tax and company law require, normally six years.
- Sign-in sessions: A session lasts 7 days, refreshed while you use the site, and expired session records are cleared.
- Sign-in places for provider accounts: Where an account that manages a provider page has signed in from - the country, a broad description of the device, and the most recent network address - is kept so we can tell you when your account is used from somewhere new. A place unused for 12 months is deleted.
- Visit counting: The coded daily token that tells visitors apart is destroyed within 26 hours, as the Cookie Policy describes. What remains are anonymous daily totals per provider page.
An open appeal, an active investigation or a legal claim can extend a period above for the records it concerns, for as long as that matter needs. When retention ends, we delete, securely destroy or irreversibly anonymise the data. Information that has been anonymised and can no longer identify anyone may be kept for statistics and service improvement.
10. Cookies, analytics and electronic marketing
RankRack uses cookies and browser storage for signing in, security and preferences you set yourself. We do not use pixels, tags, device fingerprinting or any third-party analytics technology, and advertising technologies would arrive only after this policy is updated and any consent the law requires is in place. Our analytics is our own, on-platform measurement: visits are counted on our servers with nothing stored on your device, and what providers see are aggregate figures about activity on the Platform, including, where offered, aggregate comparisons with similar pages - never raw events, and never anything that follows a person outside the Platform. Strictly necessary technologies operate without consent where the law permits; anything beyond them gets valid consent where PECR or another applicable law requires it, with controls to reject or withdraw it.
The Cookie Policy identifies each technology we use, who sets it, its purpose, duration and category. Withdrawing consent is as easy as giving it. Browser settings may also block cookies, but doing so can affect functionality.
If we send marketing emails, they will identify RankRack and include an unsubscribe method. You may opt out at any time. We may still send non-marketing messages needed to administer your account, provide a purchased service, address security, or notify you of important policy or service changes.
11. Your privacy rights
Depending on the law and our reason for processing, you may have the right to:
- ask whether we process your personal data and obtain a copy of it;
- correct inaccurate or incomplete personal data;
- ask us to delete personal data in circumstances recognised by law;
- restrict how we use personal data;
- receive certain data in a structured, commonly used and machine-readable format and transmit it to another controller;
- object to processing based on legitimate interests and object at any time to direct marketing;
- withdraw consent at any time, without affecting processing already carried out lawfully;
- challenge qualifying solely automated decisions and request human intervention; and
- complain to RankRack and to an appropriate data-protection authority.
Your right to object: You may object at any time to direct marketing. You may also object to processing based on legitimate interests. We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.
To exercise a right, email [email protected]. We may ask for information reasonably needed to verify identity and authority. We will respond without undue delay and within the period required by applicable law. UK requests are normally answered within one month, subject to lawful extensions. Rights are not absolute; if we refuse or limit a request, we will explain why and describe available complaint or appeal routes.
12. Privacy complaints and the ICO
Send a data-protection complaint to [email protected] with enough information for us to understand the issue. We will acknowledge receipt within 30 days, investigate without undue delay, keep you informed of progress, and explain the outcome and any further review route. This complaints process does not affect your right to contact a regulator.
In the UK, you may complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint or by telephone on 0303 123 1113. We would appreciate the opportunity to address your concern first, but you do not have to contact us before approaching the ICO. If you live elsewhere, you may also have the right to complain to your local privacy or data-protection authority.
13. Additional information for users outside the UK
European Economic Area and Switzerland
Where the EU GDPR or equivalent Swiss law applies, the lawful bases, rights and transfer protections described above apply as required by that law. Users may complain to the supervisory authority where they live, work or believe an infringement occurred. RankRack will publish any required EEA or Swiss representative details in this section before actively targeting those markets.
United States
Residents of US states with applicable comprehensive privacy laws may have rights to know/access, correct, delete and obtain a portable copy of personal data, and to opt out of qualifying sale, sharing, targeted advertising or certain profiling. They may also have a right to appeal a refused request and to use an authorised agent. RankRack will not discriminate against a person for exercising an applicable privacy right. Requests may be sent through the contact methods in section 17.
RankRack does not currently intend to sell personal data for money or use sensitive personal data to infer characteristics. Before any activity legally classed as sale, sharing or targeted advertising begins, RankRack must update this policy and provide the required opt-out or universal opt-out signal support. US rights and definitions vary by state and apply only where statutory scope and eligibility requirements are met.
Canada, Australia and other jurisdictions
Where Canadian, Australian or another mandatory privacy law applies, RankRack will provide the access, correction, complaint, consent, deletion or other rights that law requires. If local law gives you stronger protection than this policy, the stronger mandatory protection applies to RankRack's handling of your data in that jurisdiction.
14. Security and personal-data breaches
We use proportionate technical and organisational measures designed to protect personal data, including access controls, password hashing, least-privilege permissions, logging, backups, supplier review, encryption in transit and, where appropriate, encryption at rest. No internet service is completely secure, and we cannot guarantee absolute security.
If a personal-data breach occurs, we will contain and assess it, preserve appropriate records, notify the ICO or another regulator where legally required, and inform affected people without undue delay where the breach is likely to result in the level of risk that triggers notification. If you believe your RankRack account or data has been compromised, contact [email protected] immediately.
15. Children
RankRack accounts and review-submission features are intended only for people aged 18 or over. We do not knowingly allow a person under 18 to create an account or publish a review. If we learn that we collected a child's personal data contrary to this rule, we will investigate and delete or restrict it as appropriate. Contact us if you believe a child has supplied personal data to RankRack.
16. Third-party links and services
RankRack may link to provider websites, social networks, Discord, payment services or other independent services. Their operators decide how they use personal data and their privacy notices apply. A link, ranking, profile or integration does not make RankRack responsible for the other organisation's privacy or security practices.
17. Contact details
- Data controller: RankRack Ltd, trading as RankRack.
- Registered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.
- Company number: 17378395, registered in England and Wales.
- Privacy and rights requests: [email protected].
- Security reports: [email protected].
- General support: https://discord.gg/rankrack or https://rank-rack.com/
- ICO registration: ZC215753
RankRack is not required to appoint a statutory Data Protection Officer merely because it handles personal data. If a DPO is appointed, their contact details will be published here. In the meantime, the privacy contact above is responsible for coordinating privacy enquiries.
18. Changes to this policy
We may update this policy when RankRack's services, suppliers, business model or legal obligations change. We will publish the revised version with a new "last updated" date. If a change materially affects how we use personal data or a person's rights, we will provide a prominent notice and, where appropriate, contact account holders or seek fresh consent.