Privacy Policy
Effective September 24, 2026
RankRadius is operated by Michiana Dev LLC, an Indiana limited liability company (“RankRadius,” “we,” “us”). RankRadius turns completed jobs at on-location service businesses into location-aware content that is published on the business’s own website. This policy explains what information we collect, how we use and share it, and the choices you have. It applies to our website at rankradius.io, our client dashboard, and the embeddable project widget we provide.
Most of the people whose information passes through RankRadius are the customers of our clients (for example, a homeowner whose roof was repaired), not our clients themselves. For that information, our client decides what to enter or import and we handle it on their behalf, as described in section 8.
1. Information we collect
Information our clients give us
- Account and business details: business name, website, address, phone number, business email, and the email address and password used to sign in to the dashboard. Passwords are stored only as a one-way hash.
- Job details: the job address, a description of the work (a “field note”), the completion date, and photos. We convert the address to map coordinates and reduce it to a neighborhood-level location; we do not save the street address itself in our database, only that neighborhood-level result.
- Homeowner details, if provided: a homeowner’s name and phone number, which are kept with the job record. The homeowner’s name helps us match Google reviews to the right job. Neither is ever shown on a client’s public website.
- Connections a client sets up: a CRM API key, a Zapier webhook URL, and a Google account connection, each described below.
Information from a client’s CRM or job-management software
If a client connects their CRM or job-management software to RankRadius (for example, by entering an API key from that system), we retrieve that account’s projects, project notes, and project photos, including the customer name and phone number recorded on each project, and create draft entries from them. We use the API key only to make those requests on the client’s behalf.
Information from Google, if a client connects their Google account
A client may choose to connect their Google account so we can pull in the reviews on their Google Business Profile and show them how their listing is performing. If they do, we receive and store:
- the email address of the Google account they connected;
- a refresh token that lets us keep accessing their Business Profile until they disconnect;
- the names and IDs of the business locations that account manages, and the “write a review” link Google publishes for the chosen location;
- the reviews for the chosen location: reviewer display name, star rating, comment, and the date of the review; and
- daily performance totals for the chosen location (calls, website clicks, direction requests, and how often it appeared in Google Search and Maps). These are counts only, with no information about the people involved, and are kept briefly in memory rather than stored in our database.
We request the Google permission “Manage your Business Profile” (business.manage), along with basic sign-in scopes (openid, email) used only to show which Google account is connected. Section 4 explains exactly how we use this data.
Information you send us
If you use the contact form on our website, we receive the name, email address, business type, and message you enter. We store your message in our database and email it to ourselves through Amazon SES so we can reply. We don’t record your IP address with it.
Billing information
If you subscribe to a paid plan, payments are handled by Stripe. We store a Stripe customer ID, subscription ID, and payment status. We do not receive or store full card numbers.
Technical information
Our servers receive your IP address and standard request information when you use the site. We use IP addresses to limit abuse, and we keep server logs for security and troubleshooting. When someone views a client’s website that uses our widget, their browser also requests project data and images from our servers, so we receive that visitor’s IP address and standard request information; we use it only to operate and secure the service. The widget also reports basic, anonymous usage events back to us — that the widget was viewed, that a map pin, photo, or Google review link was clicked, and which neighborhood it concerned — so we can show our client how their widget performs. We do not store the visitor’s IP address with these events; we store only a one-way hash of it combined with a secret value that we discard every day, so an event can never be traced back to an IP address. We use a single session cookie to keep you signed in to the dashboard (see section 9).
2. How we use information
- To provide the service: turn field notes into written project descriptions, place jobs on a map at neighborhood level, hold drafts for the client’s approval, and publish approved jobs to the client’s website widget.
- To match Google reviews to the jobs that likely earned them, so the client can confirm them.
- To manage accounts and billing, send account, notification, and password-reset emails, and keep the service secure.
- To provide support. When a client asks us for help, we may view their dashboard in a read-only mode that cannot change anything.
- To improve and troubleshoot the service, and to comply with the law.
We do not sell personal information, and we do not use it for advertising.
3. What appears publicly
Nothing appears on a client’s website until that client approves it. An approved job may show: an approximate, neighborhood-level location on a map; the written description; the client’s selected photos; work-type tags; the completion date; and, if the client has confirmed one, a matched Google review (reviewer name, star rating, comment, date). Homeowner names and phone numbers, and the original field note, are never part of the public feed, and the map location is snapped to the neighborhood rather than the job’s exact coordinates. Because the written description is text that the client reviews, can edit, and chooses to publish, clients should not include a homeowner’s name, phone number, or street address in it.
Uploaded photos are kept in cloud storage at unguessable web addresses that are publicly readable, so that they can display on a client’s website. That includes photos a client has uploaded but not chosen to publish; someone would need the exact address to view one. Photos imported from a CRM are copied into our own storage; if a copy fails, the photo may be displayed from that system’s storage instead.
4. Google user data and the Limited Use requirements
RankRadius’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, for data we receive through the Google Business Profile APIs:
- Purpose. We use it only to show the connected client their own reviews, suggest which job each review belongs to (by comparing the reviewer’s display name with the customer name recorded on each job), and, once that client confirms a review, display it on that client’s own website, and show that client their own listing’s performance figures in their dashboard. We do not use it for any other purpose.
- Client control. Only 4- and 5-star reviews are imported. A review is never published until the client confirms it, and the client can unpublish it at any time.
- No sale or advertising. We do not sell Google user data, and we do not use or transfer it for serving ads, including retargeting, personalized, or interest-based advertising.
- No AI training or model input. We do not use Google user data to develop, improve, or train any AI or machine-learning model, and we do not send reviews or other Google user data to the AI service described in section 6.
- No human access to Google user data except (a) with the client’s consent for a specific support request (for example, viewing their dashboard at their request), (b) where necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) for our internal operations, where the data is aggregated and anonymized.
- Transfers. We share it only with the service providers that host and operate RankRadius (section 6), as needed to provide the features above, or where the law requires.
5. Homeowner phone numbers
If a client enters a homeowner’s phone number, or it is imported from the client’s CRM, we store it with the job record. We do not currently send text messages or otherwise contact homeowners. If we add that in the future, we will update this policy first, and it will only be used as directed by the client and in line with applicable consent rules. A homeowner who wants their number removed can contact us using the details in section 12.
6. Who we share information with
We use the following service providers to operate RankRadius. Each receives only what it needs for its role.
| Provider | Purpose | What it receives |
|---|---|---|
| Railway | Application hosting and database | All data we store |
| Amazon Web Services (S3, SES) | Photo storage; account, password-reset, client notification, and contact-form email | Uploaded photos; recipient email addresses; contact-form messages sent to us |
| Anthropic (Claude API) | Turning a field note into a written description | The field note text, with phone numbers, email addresses, and street addresses removed first, and the neighborhood name. Not Google reviews or other Google user data. Anthropic does not use this data to train its models. |
| Mapbox | Address lookup and maps | Job addresses and coordinates; visitors’ map requests on client websites |
| Stripe | Subscription billing, for clients on a paid plan | Client billing and contact details |
| Zapier | Optional social posting, only if the client sets up their own Zap | An approved job’s photo, caption, and hashtags, sent to the client’s own webhook |
We may also disclose information if required by law, to protect the rights, safety, or security of our users or the service, or as part of a merger, acquisition, or sale of assets (in which case we will require the recipient to honor this policy).
7. Retention and deletion
- Disconnecting Google. A client can disconnect their Google account at any time from Settings in the dashboard. We then revoke our access at Google and delete the stored refresh token, connected email address, and chosen location. Reviews already imported remain in the client’s Reviews tab, where they can be unpublished; on request we will delete them as well. A client can also remove our access directly at myaccount.google.com/permissions.
- Deleting an account. When a client account is deleted, we delete the client’s profile, jobs, tags, and imported reviews from our database. On request, we will also delete uploaded photo files and any related backups within a reasonable period.
- Other data. We keep information for as long as the account is active or as needed to provide the service, meet legal obligations, resolve disputes, and enforce our agreements. Password-reset links expire after 30 minutes. Contact-form messages are kept until we no longer need them to follow up; ask and we’ll delete yours.
8. Homeowner and other end-customer information
Our clients decide which job and homeowner information to enter or import, and we process it on their behalf to provide the service. If you are a homeowner and want to see, correct, or delete information about you, please contact the business that served you; you can also contact us and we will help route or fulfil the request.
9. Cookies
We use one essential session cookie to keep clients and administrators signed in to the dashboard. We do not use advertising or third-party analytics cookies. Our pages load fonts from Google Fonts, and the map widget loads map software and tiles from Mapbox, so those providers can see your IP address when a page loads. A CRM photo that could not be copied into our storage may load from that system’s servers.
10. Security
We use HTTPS, store passwords only as salted hashes, restrict dashboard access by role so each client can reach only their own data, limit repeated requests to sensitive endpoints (including sign-in attempts), and keep third-party credentials such as Google refresh tokens and API keys on the server, encrypted in our database (AES-256), and out of the browser and our API responses. No system is perfectly secure, so we cannot guarantee absolute security. If we learn of a breach affecting your information, we will notify you as the law requires.
11. Your rights and children
Depending on where you live, you may have the right to access, correct, delete, or obtain a copy of your personal information, and to object to or restrict certain uses. Clients can update most account information in Settings. To make any other request, contact us using the details below. We will not discriminate against you for exercising a privacy right.
RankRadius is a business service and is not directed to children under 13. We do not knowingly collect information from children.
12. Changes and contact
We may update this policy from time to time. If we make a material change, we will update the date at the top and, for clients, notify you through the dashboard or by email. Questions, requests, or concerns can be sent to joe@michiana.dev or through our contact form.
Michiana Dev LLC
Indiana, United States
joe@michiana.dev