Effective August 25, 2026
Privacy
How Rank21 handles listing, payment, analytics, and security data.
What Rank21 collects
Rank21 stores submitted URLs or X handles, normalized listing details, internal and Waffo order identifiers, payment status, issued and active RP, refund status, administrative actions, and security logs needed to operate and protect the service.
A Founding application stores the submitted product name, category, tagline, description, normalized target, review state, and a one-way hash of its private status token. The raw token is returned once and is not stored. The Founding flow does not request an email, account, uploaded logo, or remote website preview.
We do not intentionally store card numbers. Waffo Pancake hosts checkout and independently processes payer and billing information as merchant of record. Rank21 minimizes webhook data and does not retain buyer email when it is not needed for the service.
How information is used
We use data to create quotes and orders, verify completed payments, calculate public rankings, process refunds and chargebacks, prevent abuse, respond to support requests, and reconcile payment records.
We also use Founding submission data to review, publish, revise, reject, withdraw, and moderate the requested profile. Rank21 does not fetch submitted websites to build listing details. Analytics data is not used to determine leaderboard rank, and Rank21 does not publish visitor or click counts as ranking signals.
Analytics and session insights
Rank21 uses Plausible Analytics and Google Analytics 4 to understand audience, traffic sources, pages, sessions, devices, approximate location, and site usage. Plausible is configured as a privacy-friendly, cookieless analytics service. Google Analytics may set or access analytics identifiers and first-party cookies and processes technical and usage data under Google’s terms and privacy policies.
Rank21 uses Microsoft Clarity to diagnose usability and page performance through interaction analytics, heatmaps, and session replay. Clarity may record clicks, scrolling, mouse movement, and page rendering, and may set or access first- and third-party analytics identifiers and cookies. Clarity masks input contents under its standard masking controls and processes data under Microsoft’s terms and privacy policies.
Public information
Normalized destinations, derived names, sponsored status, active RP, rank, and Genesis badges are public. Do not submit a target you are not comfortable displaying publicly.
For an approved Founding Profile, the reviewed product name, normalized target, category, tagline, description, Founding status, and update time are public. Pending, rejected, and withdrawn submissions are not published as profiles.
The temporary editorial seed list uses only publicly available product names, canonical website links, categories, and short factual descriptions. Seed references are not stored as owner submissions, orders, paid listings, or RP records and can be corrected or removed through support.
Security and retention
Necessary infrastructure may process IP addresses and technical request data for rate limiting, fraud prevention, and security logs. Founding application rate limits store only a server-secret HMAC bucket, not the raw IP address, and those abuse events expire within 30 days. Cloudflare and Waffo may use essential cookies or storage to provide and protect the service and checkout; Google Analytics and Microsoft Clarity may use analytics cookies or identifiers as described above.
Rejected and withdrawn Founding submissions are deleted after 90 days; approved public profile content is retained while the profile remains published. Minimal review audit entries retain the action, target identifier, controlled reason code, a fixed non-personal system role required by the shared audit schema, and time without application text or tokens. Operational and payment audit records are retained as reasonably needed for reconciliation, disputes, legal obligations, security, and the integrity of the fixed-supply issuance history. Secrets and full payment credentials are not placed in public pages or application logs.
Contact
For privacy questions or applicable data-rights requests, contact support@fingerframeai.com. Waffo’s own privacy terms apply to information it processes in hosted checkout.
This is a clear operational draft. The operator should complete final entity- and jurisdiction-specific legal review and keep it current while operating production payments.