Legal
Privacy Policy
Rank Forge is an on-page SEO audit & fix app for Shopify. It reads only your store content and public page markup to score on-page SEO, and — only when you ask — writes back a single field: the SEO meta description. It never touches orders, customers or checkouts.
LAST UPDATED: 12 JULY 2026
Who we are
This policy describes how the Rank Forge Shopify app (“Rank Forge”, “we”, “us”) handles data for the merchant (“you”) who installs it. It covers only the app; it does not govern the Shopify platform itself. Questions: privacy@syncerp.work.
What data we access
Rank Forge requests the minimum access scopes needed to audit and improve on-page SEO — and no more:
read_products · write_products
Product & collection titles, descriptions and SEO meta. We read them to audit; we write only one field — the SEO meta description — and only after you approve the fix.
read_content · write_content
Pages, blogs and policies. We read them to audit; the only write is a page’s meta description tag (global.description_tag), applied only after your explicit approval.
Public storefront
Your sitemap.xml and rendered page HTML — read like any visitor, to run the on-page audit (title, meta, H1, alt coverage, canonical, Open Graph, JSON-LD, content depth).
Operational records
Your shop domain, the encrypted Shopify access token (in the app’s session store), audit results/scores, and a snapshot of each meta description we write (so a change can be reverted).
What we never access — Protected Customer Data Level 0
Orders, customers, checkouts, or any personally identifiable customer data. Rank Forge does not request read_orders, read_customers or related scopes, so it is structurally unable to read them. See Protected customer data.
No AI, no third-party content processing
The audit is a deterministic parse of your page markup — the same input always produces the same score. When you approve a meta-description fix, the text is generated deterministically from that resource’s own title and description and length-clamped for search results. No large language model is used, and none of your content is sent to any third-party AI or content provider.
How we use the data
- To run the on-page SEO audit and compute per-page and store-wide scores.
- To generate and, on your approval, write back a grounded SEO meta description — and to record the exact prior value so you can revert it.
- To re-audit after changes and after Shopify product-update webhooks, keeping scores fresh.
- To manage your subscription (Free, Pro, Scale) via Shopify Billing.
Storage, processors and security
Data is stored on our managed server infrastructure (application database and job/queue store) used to run the app. The Shopify access token lives only in the app’s session storage. We do not sell your data, and we do not share it for advertising. All Shopify Admin API access is over HTTPS.
Retention & deletion
- On uninstall: your shop is marked uninstalled and paid features stop.
- On shop redaction (Shopify’s shop/redact request, ~48h after uninstall): all of your shop’s records — including audit data, applied-fix snapshots, and the stored access token — are deleted.
- Customer data requests/redaction: because Rank Forge holds no customer data (Level 0), the GDPR customers/data_request and customers/redactwebhooks are answered truthfully — there is nothing to return or erase.
Your rights & contact
You can request access to, correction of, or deletion of your app data at any time — the simplest route is to uninstall, which triggers Shopify’s redaction flow. For any privacy request or question, contact privacy@syncerp.work.
We may update this policy; material changes will be reflected here with a new “last updated” date.