Privacy Policy ยท GDPR + CCPA Compliant ยท 2026

Your Privacy,
Plainly Explained.

This is the full WhichRanks privacy policy โ€” written without legal jargon wherever possible. We cover what data we collect, why we collect it, what we do with it, who else sees it, and exactly how you exercise your privacy rights.

12
Policy Sections
0
Data Sold to Brokers
30d
Request Response
100%
GDPR + CCPA Compliant
Read The Policy Your Rights
Last Updated: May 14, 2026 ยท Version 4.1 ยท Effective Immediately ยท Reviewed Quarterly

The 30-Second Version.

If you don't have time to read the full policy, here's what you actually need to know. The detailed sections below back up every claim with specifics.

N

We Never Sell Data.

Your data is never sold to data brokers, advertising networks, or third parties for marketing. This is non-negotiable.

M

We Collect Minimally.

Email (if you subscribe), basic site analytics (anonymized), and what you explicitly submit via forms. Nothing more.

R

You Have Full Rights.

Access, correction, deletion, portability, and opt-out โ€” all available to every user, regardless of where you live.

C

Cookie Choice.

Essential cookies only by default. Analytics and marketing cookies require explicit consent โ€” managed via the cookie banner.

Contents
What's In This Policy.
01
Section One

Introduction & Scope.

This Privacy Policy explains how WhichRanks.com ("WhichRanks", "we", "us", "our") collects, uses, stores, and shares your personal information when you visit our website, subscribe to our newsletter, submit content through our contact forms, or otherwise interact with our services.

WhichRanks is operated by WhichRanks Inc., a Delaware corporation with its principal place of business at 234 Atlantic Avenue, Brooklyn, NY 11201, United States. We're committed to handling your data with the same care, transparency, and honesty that defines our editorial work.

"If we wouldn't be comfortable explaining how we use your data to your face, we shouldn't be doing it. That's the operating rule."

What This Policy Covers

  • Our website at whichranks.com and all its subdomains, including the homepage, category pages, comparisons, reviews, and blog.
  • Our newsletter โ€” the email lists you can subscribe to via the newsletter page.
  • Our contact and feedback forms on the contact page and embedded throughout the site.
  • Our user-submitted content channels, including ratings, reviews, and tip submissions described in our editorial policy.

What This Policy Does Not Cover

This policy does not cover the privacy practices of third-party services we link to โ€” like the brands we review, the payment processors used during affiliate purchases, or external sites linked from our comparisons. Each of those operates under its own privacy policy, which we encourage you to review.

02
Section Two

Information We Collect.

We collect three broad categories of information: information you provide directly, information collected automatically, and information from third parties. Below is the full inventory of each.

Information You Provide Directly

Data Type When We Collect It Why
Email address Newsletter signup, contact form, feedback submission To send newsletter, respond to inquiries, send confirmations
Name (first, last) Contact form, brand suggestion, press inquiry To address you personally in responses
Company / organization Optional contact form field To route brand or press inquiries appropriately
Message content When you submit any form on the site To respond to your specific request
Category preferences Newsletter signup (optional) To send only category-relevant emails
Ratings & reviews When you submit reader ratings or reviews To display alongside our editorial scoring

Information Collected Automatically

When you visit our site, we automatically collect limited technical information through cookies and similar technologies (see Section 04). This includes:

  • Device & browser data โ€” browser type, operating system, screen resolution, language preference
  • Usage data โ€” pages visited, time spent on pages, links clicked, referring URL
  • IP address & approximate location โ€” country and city-level only (not street-level)
  • Date and time of your visit and session duration
Important Note

We do not collect personally identifiable information about you automatically. The data above is aggregated and used for site analytics โ€” we cannot use it to identify you individually without additional information you've explicitly provided.

Information From Third Parties

We may receive limited information from third-party services when you interact with our site through them โ€” for example, when you submit a form via reCAPTCHA, or when our analytics provider reports aggregated traffic patterns. We do not purchase data from data brokers, ad networks, or marketing list providers.

03
Section Three

How We Use Your Information.

We use the information we collect only for the specific purposes listed below. We do not use your data for purposes outside this list, and we do not sell, rent, or trade your information to any third party.

Purposes We Use Data For

  • Delivering the service. Loading pages, displaying reviews and comparisons, processing form submissions, sending newsletter emails you've subscribed to.
  • Communication. Responding to your contact inquiries, sending newsletter content you've signed up for, sending account-related notifications (e.g., subscription confirmations).
  • Improvement. Understanding which content readers find most useful, identifying broken pages, improving site speed and navigation. All such use is based on aggregated, non-personally identifiable data.
  • Editorial work. Considering reader-submitted corrections, brand suggestions, and editorial concerns โ€” these directly inform our methodology and content updates.
  • Legal & security. Preventing fraud, abuse, or violations of our Terms of Service; complying with applicable legal obligations (e.g., subpoenas, court orders).
  • Aggregated analytics. Publishing aggregated, anonymized insights (e.g., "X% of readers compared Brand A vs Brand B last month") โ€” never tied to identifiable individuals.

Legal Bases (GDPR Users)

For users in the European Union and EEA, we process your data under one of the following legal bases:

  • Consent โ€” for newsletter subscriptions, optional cookies, and non-essential marketing communications.
  • Contract โ€” to deliver services you've explicitly requested (e.g., responding to a contact form submission).
  • Legitimate interests โ€” for site analytics, fraud prevention, and improving our content โ€” where these don't override your privacy rights.
  • Legal obligation โ€” where required by applicable law (rare, but possible for tax records, legal compliance, etc.).
04
Section Four

Cookies & Tracking Technologies.

We use cookies and similar tracking technologies (web beacons, pixel tags, local storage) to operate our site, understand how readers use it, and respect your preferences across visits. By default, only essential cookies are active โ€” everything else requires your explicit consent via our cookie banner.

Categories Of Cookies We Use

  • Essential / strictly necessary cookies. Required for the site to function โ€” these enable basic navigation, form submission, and security features. Always active and cannot be disabled.
  • Analytics cookies. Help us understand which pages are read, where readers come from, and what content needs improvement. Anonymized and aggregated. Active only with consent.
  • Preference cookies. Remember your settings โ€” like cookie consent choices, language preference, or whether you've dismissed banners. Active only with consent.
  • Affiliate tracking cookies. Set by our affiliate partners when you click affiliate links (see Section 06 below). Active only when you click an affiliate link.
No Advertising Cookies

Unlike most comparison sites, we do not use third-party advertising cookies (e.g., Google Ads, Meta Pixel, retargeting cookies). We don't run remarketing campaigns and you won't be "followed around the internet" by ads after visiting our site.

Managing Cookies

You can manage your cookie preferences three ways:

  • Cookie banner. When you first visit, the cookie banner lets you accept all, reject all (except essential), or customize by category.
  • Site footer link. At any time, click "Cookie Preferences" in the site footer to re-open your settings and change what's active.
  • Browser settings. All modern browsers (Chrome, Firefox, Safari, Edge) let you block or delete cookies at the browser level. This may break some site functionality.

For more on the privacy-first analytics tools we use ourselves, see our analytics comparisons and methodology.

05
Section Five

Third-Party Services & Sharing.

We use a small number of trusted third-party service providers to operate the site. Each one has access only to the data necessary to perform their specific function, and each is contractually bound to handle your data in compliance with applicable privacy laws (GDPR, CCPA, etc.).

Service Providers We Use

Service Type What They Do Data Shared
Web hosting Host the WhichRanks website and database All site data (encrypted at rest)
Email service provider Deliver newsletter emails you've subscribed to Email address, subscription preferences
Analytics platform Aggregate, anonymized site usage data Anonymized usage events (no personal data)
Form processing Process contact & signup form submissions Form contents you submit
CDN & security Speed up site loading, prevent attacks IP address, browser fingerprint (anonymized)
Anti-spam Prevent automated form spam Form metadata (not message contents)

When We Disclose Data To Others

Outside of the service providers above, we disclose your personal data to others only in very limited circumstances:

  • Legal requirement. When required by law, court order, or government request โ€” and only after verifying the request is legally valid.
  • Fraud / safety. To investigate or prevent fraud, security incidents, or threats to safety.
  • Business transition. If WhichRanks is involved in a merger, acquisition, or asset sale, your data may transfer to the new entity โ€” but the new entity is bound by this same policy or must give you advance notice and opt-out.
  • With your explicit consent. If you specifically ask us to share data with a third party (e.g., authorizing a press inquiry).
"We sell our work โ€” not our readers. Every revenue stream has to clear that bar before it goes anywhere near the editorial team."
06
Section Six

Affiliate Links & Tracking.

WhichRanks earns revenue through affiliate partnerships with some of the brands we review. When you click an affiliate link (marked "Ad" or with rel="sponsored"), the destination brand may set tracking cookies on your device to attribute the click to us. Here's how that works and what you can do about it.

How Affiliate Tracking Works

  • You click an affiliate link on WhichRanks (clearly labeled "Ad" or "Sponsored").
  • The brand's affiliate network sets a cookie on your device that identifies the link came from us.
  • If you make a purchase within a tracking window (typically 24 hours to 90 days), we earn a small commission โ€” at no extra cost to you.
  • The brand's affiliate cookie tracks only that purchase event. We do not receive your personal data (name, email, address) from the brand.

What We Do With Affiliate Data

We receive aggregated affiliate reporting from our partners โ€” typically anonymized conversion counts and commission amounts. We do not receive individual purchase details, customer names, or personally identifiable information. The data we receive helps us understand which content is most useful to readers, but does not identify you personally.

Reminder: Affiliate Links Don't Influence Rankings

The fact that we earn commissions from certain brands does not influence our editorial rankings. Our scoring is finalized before any commercial conversation, and the editorial team operates under firewalls described in our editorial policy. If a lower-paying brand is the better pick, we recommend the lower-paying brand.

Opting Out Of Affiliate Tracking

  • Block affiliate cookies. Your browser settings let you block third-party cookies, which prevents affiliate networks from tracking clicks.
  • Use a privacy-focused browser. Browsers like Brave, Firefox (with strict tracking protection), and Safari block most affiliate cookies by default.
  • Visit brands directly. If you'd rather not click our affiliate links, simply type the brand's URL directly into your browser โ€” you'll get the same product/service without our tracking.
07
Section Seven

Data Retention & Deletion.

We retain your personal data only as long as necessary to fulfill the purposes outlined in this policy โ€” or as required by applicable law. Different data types have different retention windows, listed below.

Retention Schedules By Data Type

Data Type Retention Period Then What
Newsletter subscriber email Until you unsubscribe Deleted within 90 days of unsubscribe
Contact form submissions 24 months from last interaction Permanently deleted
Site analytics (anonymized) 14 months Aggregated and personal data deleted
Cookie consent preferences 12 months You're re-prompted for consent
User-submitted reviews / ratings Indefinite (with attribution as set) Removed on request via contact form
Legal records (taxes, compliance) 7 years (legal requirement) Permanently deleted

How To Request Deletion

You can request deletion of your personal data at any time by emailing privacy@whichranks.com or using the contact form with subject "Data deletion request." We will:

  • Acknowledge receipt of your request within 5 business days.
  • Verify your identity to prevent unauthorized deletion.
  • Complete the deletion within 30 days of verified request (often much sooner).
  • Confirm completion in writing, including which data was deleted.

Note: certain data may be retained beyond your deletion request where we have a legal obligation (e.g., financial records, fraud prevention). Where this applies, we'll tell you exactly what's retained and why.

08
Section Eight

Data Security.

We take reasonable technical and organizational measures to protect your personal data from unauthorized access, alteration, disclosure, or destruction. While no system is 100% secure, the practices below describe the controls in place at WhichRanks as of May 2026.

Technical Safeguards

  • HTTPS encryption across the entire site, with TLS 1.3 minimum and automatic certificate renewal.
  • Encryption at rest for all stored personal data, using industry-standard AES-256 encryption.
  • Encrypted database connections between our application servers and the database โ€” no unencrypted internal traffic.
  • Hashed passwords using bcrypt with salt for any account-related credentials (applies to internal staff accounts).
  • Regular security audits โ€” quarterly internal review and annual third-party penetration testing.
  • DDoS protection & WAF via our CDN provider to mitigate denial-of-service and application-layer attacks.

Organizational Safeguards

  • Access controls. Only staff with a specific work need can access personal data. Access is logged and reviewed quarterly.
  • Two-factor authentication required for all staff accounts that touch personal data.
  • Background checks for staff with access to user data.
  • Annual privacy training for all employees handling personal data.
  • Vendor due diligence โ€” third-party service providers are vetted for security practices before integration.

Breach Notification

In the unlikely event of a security breach affecting your personal data, we will notify affected users without undue delay โ€” typically within 72 hours of confirming the breach, in line with GDPR requirements. Notification will include the nature of the breach, what data was affected, what we've done in response, and what you can do to protect yourself.

Report A Security Issue

If you discover a security vulnerability in WhichRanks, please report it responsibly to security@whichranks.com. We acknowledge reports within 24 hours and aim to validate or remediate within 14 days for confirmed issues. We do not currently offer a public bug bounty program but recognize researchers who report responsibly.

09
Section Nine

Your Privacy Rights.

Depending on where you live, you have specific rights regarding your personal data. We extend most of these rights to all users globally, regardless of jurisdiction โ€” not just those in the EU or California.

Rights We Honor For All Users

  • Right to access. You can request a copy of the personal data we hold about you, in a portable format. We respond within 30 days.
  • Right to correction. You can ask us to correct any inaccurate or incomplete information we have about you.
  • Right to deletion. You can ask us to delete your personal data (subject to legal retention requirements outlined in Section 07).
  • Right to data portability. You can request your data in a machine-readable format (typically JSON or CSV) to take it elsewhere.
  • Right to opt out. You can unsubscribe from our newsletter with one click at any time, and opt out of non-essential cookies via our cookie banner.
  • Right to object. You can object to specific uses of your data โ€” for example, asking us not to use your testimonial publicly.

Additional Rights For EU/UK Residents (GDPR)

  • Right to restriction of processing โ€” you can ask us to limit how we use your data while we investigate a concern.
  • Right to withdraw consent โ€” for any processing based on consent, you can withdraw that consent at any time.
  • Right to lodge a complaint with your local Data Protection Authority if you believe we've violated GDPR.
  • Right against automated decision-making โ€” we do not make automated decisions that produce legal effects about you.

Additional Rights For California Residents (CCPA / CPRA)

  • Right to know what specific personal information we've collected, used, disclosed, or sold about you in the past 12 months.
  • Right to opt out of sale. We do not sell personal data, so this right doesn't change anything in practice โ€” but it's yours regardless.
  • Right to non-discrimination. We won't deny you service, charge different prices, or provide a different experience because you exercised your privacy rights.
  • Right to limit use of sensitive information for purposes beyond what's reasonably necessary.

How To Exercise Your Rights

To exercise any of these rights, contact us at privacy@whichranks.com or use the contact form with subject "Privacy rights request." We'll respond within 30 days (often much sooner). For some requests, we may need to verify your identity to prevent fraudulent requests on someone else's data.

10
Section Ten

International Data Transfers.

WhichRanks is operated from the United States, with offices in Brooklyn (NY), Austin (TX), and London (UK). When you submit personal data through our site, it may be transferred to and processed in the United States, the United Kingdom, the European Union, or other jurisdictions where our service providers operate.

Safeguards For International Transfers

  • EU-to-US transfers rely on the EU-U.S. Data Privacy Framework (DPF) where our service providers are certified, or on Standard Contractual Clauses (SCCs) approved by the European Commission.
  • UK-to-US transfers rely on the UK Extension to the DPF, or on the UK International Data Transfer Agreement (IDTA).
  • All vendors handling personal data of EU/UK users are bound by GDPR-compliant data processing agreements.

If you're located outside the United States, please be aware that data protection laws in your country may differ from those in the US. By using WhichRanks, you consent to the transfer of your information to the United States and other jurisdictions where we and our service providers operate.

11
Section Eleven

Children's Privacy.

WhichRanks is not directed at children under 16, and we do not knowingly collect personal information from anyone under that age. Our content โ€” reviews, comparisons, guides โ€” is intended for adult consumers and business buyers making purchasing decisions.

If you are under 16, please do not submit any personal information through our forms, subscribe to our newsletter, or otherwise interact with parts of the site that collect personal data. If you are a parent or guardian and believe your child has provided personal information to us without your consent, please contact us at privacy@whichranks.com and we will promptly delete it.

We comply with the U.S. Children's Online Privacy Protection Act (COPPA) and the relevant provisions of GDPR regarding children's data. Under no circumstances do we knowingly process the personal data of children under 13 for any purpose.

12
Section Twelve

Updates & Contact Info.

We may update this Privacy Policy from time to time โ€” to reflect changes in our practices, new legal requirements, or improvements to clarity. When we make material changes, we'll notify you in one or more of the following ways:

  • Last Updated date. The date at the top of this page reflects the most recent revision.
  • Version number. Each material change increments the version number (currently v4.1).
  • Email notification. For material changes, we'll email subscribers at least 30 days before the changes take effect.
  • Site banner. A prominent banner will appear on the site for at least 14 days following a material change.
  • Historical versions. Previous versions of this policy are available on request at privacy@whichranks.com.

Contact Information

If you have questions about this Privacy Policy, want to exercise your rights, or have any other privacy-related concerns, you can reach us through several channels:

  • Email: privacy@whichranks.com (monitored daily by our privacy team)
  • Postal mail: WhichRanks Inc., Attn: Privacy Officer, 234 Atlantic Avenue, Brooklyn, NY 11201, United States
  • EU representative: For EU residents, our EU-based data protection representative can be reached at eu-privacy@whichranks.com
  • UK representative: Our UK office handles UK-specific privacy inquiries at uk-privacy@whichranks.com
  • Contact form: Use our contact page with subject "Privacy inquiry"
"Privacy isn't a checkbox we add at the bottom of the page. It's a commitment we operate under every single day."

For broader information about how WhichRanks operates, see our About page. For our editorial standards and independence framework, see the editorial policy. For details on how we test and rank brands, see our methodology.

Two Direct Channels.

For anything privacy-related โ€” questions, rights requests, security concerns, or just clarifications โ€” these are the two routes that get you straight to the right team within 5 business days.

P

Privacy Inquiries.

General questions about this policy, how your data is handled, or how to exercise your privacy rights. We respond to all credible privacy inquiries within 5 business days, with rights requests fulfilled within 30 days.

Contact Privacy Team
S

Security Reports.

Discovered a vulnerability or security concern? Report it responsibly via security@whichranks.com. We acknowledge reports within 24 hours and remediate confirmed issues within 14 days.

Report Security Issue

Explore The Policies.

This privacy policy works alongside our editorial policy, terms of service, and methodology โ€” together they cover how WhichRanks operates, handles your data, and produces the rankings you read.