Privacy Policy
Last updated: May 13, 2026
This Privacy Policy describes how wRanks, a product operated and managed by OhMySaaS ("we", "us", "our"), collects, uses, discloses, and protects information when you install and use the SEO & AI GEO Suite app ("the App"). This policy complies with the GDPR, CCPA, and Shopify's API and Partner requirements.
1. Data Controller
OhMySaaS (operating as wRanks)
Email: hello@wranks.com | Website: wranks.com
2. Information We Collect
2.1 Store Data (via Shopify API)
When you install the App, we access the following data through the Shopify API with your explicit authorization:
- Products: titles, descriptions, images, prices, variants, and SEO metadata
- Collections: titles, descriptions, and SEO metadata
- Pages: titles, body content, and SEO metadata
- Blog articles: titles, body content, authors, and SEO metadata
- Theme data: theme files for structured data and meta tag injection
- Store information: store name, domain, owner email, and locale settings
2.2 Google Search Console Data
If you choose to connect Google Search Console, we access search performance data (clicks, impressions, CTR, average positions) through Google's OAuth 2.0 API with read-only permissions. We do not store your Google credentials.
2.3 Usage Data
- Feature usage patterns and credit consumption history
- Optimization history and audit results
- App performance and error logs
2.4 Personal Data
We collect the Shopify store owner's name and email address as provided by Shopify during installation. We do not collect any personal data from your store's customers. The App does not process, store, or access any customer data, payment information, or order details.
3. Legal Basis for Processing (GDPR)
- Contract performance (Art. 6(1)(b)): Processing necessary to deliver the App's services.
- Consent (Art. 6(1)(a)): For optional integrations like Google Search Console.
- Legitimate interest (Art. 6(1)(f)): For service improvement and security monitoring.
4. How We Use Your Information
- To generate AI-optimized SEO content (titles, descriptions, blog articles)
- To perform SEO audits and provide actionable recommendations
- To display search performance data from Google Search Console
- To track keyword rankings and competitor analytics
- To monitor AI platform mentions of your brand across 8 platforms
- To process billing through Shopify's billing API
- To improve and maintain the App's functionality
5. Third-Party Services
We share limited data with third-party services solely to provide the App's functionality:
| Service | Purpose | Data Shared |
|---|---|---|
| OpenRouter | AI content generation, multi-model queries | Product/page content; prompt text |
| DataForSEO | Keyword tracking, competitor data | Keywords and domain names |
| Google APIs | Search Console, Indexing API | Store domain and page URLs |
| Shopify | Billing, authentication, store data | Subscription events, store metadata |
We do not sell, rent, or trade your personal data to any third party.
6. Data Retention
- Active installations: Data retained while the App is installed.
- After uninstallation: All store data deleted within 30 days.
- Billing records: Retained up to 7 years per tax regulations.
- OAuth tokens: Revoked and deleted on disconnection or uninstallation.
7. Data Security
- All data transmitted over HTTPS/TLS encryption
- API keys and credentials encrypted at rest
- Production access restricted to authorized personnel
- Regular security audits performed
- Google credentials never stored; OAuth 2.0 tokens only
8. International Data Transfers
Our servers may be located outside the EEA. When data is transferred outside the EEA, we ensure appropriate safeguards (Standard Contractual Clauses) are in place per GDPR requirements.
9. Your Rights (GDPR / CCPA)
- Right of access (Art. 15): Request a copy of your personal data.
- Right to rectification (Art. 16): Correct inaccurate data.
- Right to erasure (Art. 17): Request deletion ("right to be forgotten").
- Right to data portability (Art. 20): Receive data in machine-readable format.
- Right to restrict processing (Art. 18): Limit data processing.
- Right to object (Art. 21): Object to legitimate interest processing.
- Right to withdraw consent: Disconnect optional integrations at any time.
- Right to lodge a complaint: File with your local Data Protection Authority.
To exercise any right, email hello@wranks.com. We respond within 30 days.
10. Cookies and Tracking
The App operates within the Shopify admin and does not set cookies on your storefront or track your customers. We do not use third-party analytics or advertising pixels on your store.
11. Shopify Compliance
- Shopify API Terms of Service and Partner Program Agreement
- Shopify's mandatory privacy requirements for apps
- Shopify's data protection addendum (DPA)
- GDPR mandatory webhooks: customers/redact, shop/redact, customers/data_request
12. Contact Us
OhMySaaS (operating as wRanks)
Email: hello@wranks.com | Website: wranks.com
Response time: Within 30 days of receipt