Privacy Policy
Last Updated: January 28, 2026Digital Macaroni
1. Introduction
RankLadder ("we," "our," or "us") is a service provided by Digital Macaroni, located at 30 N Gould St Ste N, Sheridan, WY 82801. This policy explains our data governance framework.
Status: Data ControllerClients: The business owners using RankLadder. RankLadder is the Data Controller for your account data, billing information, and EIN.
Status: Data ProcessorCustomers: The end-users of our Clients. RankLadder acts as a Data Processor acting strictly on Client instructions for review requests and analytics.
1.5 European Economic Area (EEA) Users
For users in the EEA, we process personal data in accordance with the EU General Data Protection Regulation (GDPR). Digital Macaroni acts as:
  • Data Controller for your account information and usage data.
  • Data Processor for customer lists you upload (you are the controller).
Lawful Basis: Contract performance (providing the Service), legitimate interests (security, analytics), and consent (where required). Your GDPR rights include access, rectification, erasure, restriction, portability, and objection. See Section 9 for exercise instructions.
EU Representative: iubenda s.r.l., Via San Raffaele, 1 – 20121 Milan (Italy)
Email: info@iubenda.com
1.6 California Residents (CCPA/CPRA)
For California residents, we comply with the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
  • We do not "sell" or "share" personal information as defined under CCPA/CPRA.
  • Rights: Know what data we collect, delete it, correct it, and opt-out of profiling (if applicable). You can exercise your right to erasure through our Data Deletion Request form.
2. Information We Collect
CategoryData PointsLegal Basis
AccountName, Email, Business EINContractual Necessity
ReviewGoogle API Data, AI ResponsesLegitimate Interest
CustomerContact Info, Phone NumbersClient Consent
UsageIP Address, Device ID, LogsSecurity/Optimization
PaymentBilling Address, Stripe TokenLegal Compliance
Information You Provide to Us
  • Account Information: Name, email address, password, business name, business address, EIN (for 10DLC verification).
  • Payment Information: We use Stripe for payment processing. We do not store your full credit card number.
  • Customer Data: If you upload customer lists (names, phone numbers) for review requests, you act as the data controller, and we act as the data processor.
Information Collected Automatically
  • Usage Data: IP address, browser type, operating system, device information, and logs to help us optimize the service and ensure security.
  • Cookies: We use cookies to maintain your session and preference settings.
3. Google API Services (Limited Use Disclosure)
RankLadder uses Google APIs to provide review management features. Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
  • What we access: We access your Google Business Profile reviews and business location data to display analytics and allow you to reply to reviews.
  • How we use it: We use this data solely to provide the RankLadder service to you. We do not sell this data.
  • AI Processing: We may process review content through AI models (e.g., OpenAI, Google Gemini) to generate sentiment analysis and suggested responses. This data is not used to train third-party AI models.
4. Data Usage
We utilize collected information to:
  • Provide and maintain the Service.
  • Authenticate your access.
  • Calculate review targets and analytics.
  • Generate AI-driven responses (at your request).
  • Comply with A2P 10DLC regulations for SMS messaging.
Aggregated Data: We reserve the right to use de-identified, aggregated statistics based on platform trends for product improvement and industry reporting.
5. SMS Disclosure (A2P 10DLC)
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
We only share your business information with The Campaign Registry and our telephony provider (Telnyx) for the sole purpose of verifying your business identity to allow you to send SMS messages.
6. Third-Party Infrastructure
We leverage industry-standard sub-processors:
  • Google: Business Profile API.
  • Stripe: Payment processing.
  • Telnyx: SMS delivery.
  • Vercel/AWS: Hosting and infrastructure.
  • OpenAI/Google Gemini: AI processing.
Data Processing Agreement (DPA): By using RankLadder, you enter our standard DPA for processing your uploaded customer data. Available upon request at hello@digitalmacaroni.io.
International Transfers: Data is processed in the U.S. EU users' data is protected by Standard Contractual Clauses (SCCs) with our U.S. sub-processors to ensure GDPR compliance.
7. Data Retention
We retain personal data only for as long as necessary to provide the Service or comply with legal obligations. Financial transaction data is kept for 7 years per US tax regulations. If you delete your account, your data is purged from our active systems within 30 days. You can initiate a formal deletion request at any time via our Data Deletion Portal.
8. Security
We implement SOC 2 compliant data center practices, TLS 1.3 encryption for data in transit, and restricted role-based internal access to protect against unauthorized data exposure. While we strive to protect your data, no method of transmission over the Internet is 100% secure.
9. Your Rights
Depending on your location, you have specific rights regarding your personal data:
GDPR (EEA)
  • Access your data
  • Rectify inaccuracies
  • Erasure ("Right to be forgotten")
  • Restriction of processing
  • Data portability
  • Objection to processing
CCPA (California)
  • Right to know what we collect
  • Right to delete
  • Right to correct
  • Right to non-discrimination
  • Right to limit sensitive data use
Response Time: We respond to all requests within 45 days. No fee applies unless requests are excessive. To exercise these rights, please contact our support team or use our automated deletion request form. Verification of identity/account ownership will be required.
10. Children's Privacy
RankLadder is not intended for users under 18. We do not knowingly collect data from minors.
11. Contact Information
Digital Macaroni
30 N Gould St Ste N
Sheridan, WY 82801
digitalmacaroni.io
hello@digitalmacaroni.io