Effective date: August 21, 2026
This Privacy Policy explains how Devtech, LLC, an Ohio limited liability company doing business as Local SEO Ranker (“Devtech,” “we,” “us,” or “our”), collects, uses, shares, and protects personal information when you use our website at mylocalseoranker.com, our web application at app.mylocalseoranker.com, our iOS and Android mobile apps, and related services (together, the “Service”). It also explains the choices and rights you have.
This Policy covers three groups of people: Customers (businesses and agencies, and their team members, who have accounts with us), End Customers (the customers and contacts of our Customers, whose information Customers upload to or collect through the Service, including people who receive review requests or text messages), and Visitors (people who browse our website or contact us). Where we process End Customer information on a Customer’s behalf, the Customer is the data controller (or “business” under U.S. state privacy laws) and we act as a processor or service provider; if you are an End Customer with questions about how a business uses your information, please contact that business directly, and we will assist them in responding.
1. Information we collect
Information you provide to us
- Account and profile information: name, email address, phone number, company name, job title, password (stored only as a salted hash), profile photo, and preferences.
- Business and location information: business names, addresses, phone numbers, hours, categories, service areas, descriptions, and other details about the business locations you manage.
- Job photos, videos, and content: photos and videos of completed jobs and projects that you capture or upload, along with captions, descriptions, tags, service type, and the posts generated from them. Photos and videos may contain embedded metadata such as the date, time, device model, and GPS location where they were taken (see “Location information” below).
- End Customer information: names, phone numbers, email addresses, service or appointment details, and consent records for the customers and contacts you add to the Service to send review requests, follow-ups, or campaigns.
- Messages and communications: the content of SMS, email, and review responses you send through the Service; replies from End Customers; and communications with us (support requests, contact form submissions, survey responses).
- Payment information: when you subscribe on the web, your payment card details are collected directly by Stripe; we receive only a token, the card brand, last four digits, expiration date, and billing address. In-app purchases are handled by Apple or Google, and we receive transaction identifiers and subscription status (via RevenueCat), not your payment details.
Information from connected third-party accounts
- Google account and Google Business Profile data: when you sign in with Google or connect a Google Business Profile, we receive your basic profile (name, email, profile picture) and, for the locations you authorize, listing details, posts, photos, reviews and review replies, Q&A, and performance insights (such as searches, views, calls, direction requests, and website clicks). See Section 4 for our Google API commitments.
- Social media accounts: when you connect accounts such as Facebook, Instagram, LinkedIn, X, TikTok, YouTube, or Nextdoor to syndicate content, we receive the page or profile identifiers, name, and the access tokens needed to publish posts and retrieve post performance on your behalf. We do not access your personal social feeds or friends lists beyond what is required to publish.
- Website integrations: if you connect your own website (for example via our WordPress plugin, embed script, or API) to display job photos, reviews, or posts, we receive your site URL and an integration key.
- Review platforms: public review content and ratings from platforms you connect or that we monitor (Google, Facebook, Yelp, and others).
- CRM and marketing platforms: if you connect a CRM or marketing automation platform (for example HighLevel / GoHighLevel), we exchange contact records, tags, and activity data as configured by you.
Information collected automatically
- Usage and device data: IP address, browser type and version, operating system, device identifiers, app version, language, pages and features used, actions taken, timestamps, referring URLs, and crash and performance diagnostics.
- Location information: (a) the approximate location inferred from your IP address; (b) with your permission, precise location from your mobile device, which our app uses to geotag job photos and videos, to associate jobs with service areas, and to generate location-relevant posts; and (c) GPS and other metadata embedded in photos and videos you upload. You can disable location access in your device settings at any time; some features (such as automatic geotagging) will then be unavailable.
- Camera, microphone, and photo library: with your permission, our mobile app accesses your camera and microphone to capture job photos and videos and your photo library to upload existing media. We access only the media you choose to capture or select.
- Push notifications: with your permission, we send push notifications about new reviews, messages, post status, and account activity. You can turn these off in your device settings.
- Cookies and similar technologies: see Section 9.
Information from other sources
We may receive information from our payment processors (payment status), carriers and Twilio (message delivery status and carrier opt-out signals), public sources (business listings, public reviews), and analytics and fraud-prevention providers.
2. How we use information
We use personal information to:
- Provide and operate the Service, including creating and managing accounts; publishing job photos, videos, and posts to your Google Business Profile, connected social media accounts, and your website; tracking local search rankings; monitoring and responding to reviews; sending review requests and other messages you initiate; and generating analytics and reports.
- Process payments and manage subscriptions, trials, invoices, and refunds.
- Communicate with you about your account, security, support requests, service updates, and changes to our terms and policies.
- Send marketing communications to Customers and Visitors about our own products and features, which you can opt out of at any time (Section 8). We do not send marketing to End Customers on our own behalf.
- Personalize and improve the Service, including understanding how features are used, developing new features, and training internal models on aggregated or de-identified usage patterns. We do not use Google user data or End Customer data to train generalized machine-learning or AI models (see Section 4).
- Provide AI-assisted features, such as suggested post captions and review replies. When you use these features, the relevant content (for example a photo description or review text) is sent to our AI service provider to generate a suggestion; the provider is contractually prohibited from using it to train its models.
- Ensure security and prevent fraud and abuse, including detecting unauthorized access, enforcing our Terms and Messaging Terms, and protecting carriers and third-party platforms.
- Comply with legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims.
Legal bases (EEA/UK/Switzerland). Where these laws apply, we process personal information (a) to perform our contract with you; (b) for our legitimate interests (operating, securing, and improving the Service and marketing to business customers), balanced against your rights; (c) with your consent, where required (for example, precise location, camera access, and marketing cookies); and (d) to comply with legal obligations.
3. How we share information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share personal information only as follows:
- At your direction, to the platforms you connect. When you publish content, we send your photos, videos, posts, business details, and review replies to Google, your connected social networks, and your website. Content published to those platforms is governed by their terms and privacy policies and may be publicly visible.
- Service providers that process data on our behalf under contracts that restrict their use of the data, including: cloud hosting and database providers (Supabase and its underlying cloud infrastructure; DigitalOcean; Netlify; Hostinger for this website); Stripe (payments); Apple, Google Play, and RevenueCat (in-app subscriptions); Twilio (SMS and voice); email delivery providers (such as SendGrid); Google Maps Platform (address verification, maps, Street View); analytics, error-monitoring, and customer-support tools; and AI service providers for AI-assisted features.
- Within your organization. Information is visible to other users of your account according to the roles and permissions set by the account owner. If you are an agency client, your agency can see the data in the accounts it manages.
- CRM and marketing integrations you enable, such as HighLevel, according to the settings you choose.
- Professional advisors such as lawyers, auditors, and insurers, under confidentiality obligations.
- Legal and safety. When we believe disclosure is required by law, subpoena, or legal process, or is necessary to protect the rights, property, or safety of Devtech, our customers, or the public, or to enforce our agreements.
- Business transfers. In connection with a merger, acquisition, financing, or sale of all or part of our business, subject to this Policy and notice to you.
- With your consent or at your direction for any other purpose.
Mobile opt-in and text messaging data: mobile phone numbers and SMS consent information are never shared with or sold to third parties or affiliates for their marketing purposes. They are shared only with Twilio and carriers to the extent necessary to deliver messages.
4. Google API Services and Limited Use
Local SEO Ranker’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We request only the Google scopes needed for the features you use (Google Sign-In for authentication; Business Profile APIs to read and manage the locations, posts, media, reviews, and insights you authorize).
- We use Google user data only to provide and improve user-facing features of the Service that are visible and prominent to you, such as publishing photos and posts to your Business Profile, displaying and replying to reviews, and showing performance insights.
- We do not transfer Google user data to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition with notice to you.
- We do not use Google user data to serve advertisements, including retargeting, personalized, or interest-based advertising.
- We do not allow humans to read Google user data unless (a) we have your affirmative agreement for specific data, (b) it is necessary for security purposes such as investigating abuse, (c) it is necessary to comply with applicable law, or (d) the data has been aggregated and anonymized for internal operations.
- We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine-learning models.
You can revoke our access at any time from your Google Account permissions page or by disconnecting Google in the Service’s Settings. When you disconnect, we stop syncing and delete the Google data associated with the connection within 30 days, except as needed for legal compliance.
5. Data retention
We keep personal information for as long as your account is active or as needed to provide the Service. After an account is closed or a subscription is cancelled, we retain account data for 30 days so you can reactivate, then delete or de-identify it within a further 60 days (90 days total), except that we may retain: billing and transaction records for 7 years as required by tax and accounting law; SMS consent and opt-out records for at least 4 years as required by the TCPA and carrier rules; security logs for up to 12 months; and information needed to resolve disputes, enforce our agreements, or comply with legal obligations. Content you have published to third-party platforms (for example a photo posted to your Google Business Profile) remains on those platforms under their terms until you remove it there. Backups are overwritten on a rolling basis within 35 days. See our Account & Data Deletion Policy for how to delete your account.
6. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS 1.2+) and at rest, hashed passwords, optional two-factor authentication, role-based access controls, row-level security in our database, least-privilege access for staff, audit logging, and vendor due diligence. No system is completely secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and regulators as required by applicable law, including Ohio Revised Code § 1349.19.
7. International transfers
We are based in the United States and process information on servers located in the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S., where privacy laws may differ from those in your jurisdiction. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum for transfers from the EEA, UK, and Switzerland.
8. Your choices
- Account information: update it anytime in Settings.
- Marketing emails: click “unsubscribe” in any marketing email or adjust preferences in Settings. We will still send transactional and account messages.
- Text messages from us: reply STOP to opt out.
- Push notifications, location, camera, microphone, and photos: manage permissions in your device settings.
- Connected accounts: disconnect Google, social, website, or CRM integrations in Settings or from the third party’s own permissions page.
- Cookies: see Section 9.
- Delete your account: see our Account & Data Deletion Policy.
9. Cookies and tracking technologies
We use cookies, local storage, software development kits (SDKs), and similar technologies for the following purposes:
- Strictly necessary: authentication, session management, security, load balancing, and remembering your preferences. These cannot be disabled.
- Analytics and performance: understanding how the website and app are used so we can improve them (for example, Google Analytics via Google Site Kit on this website, and product analytics and crash reporting in the app). Data is aggregated where possible.
- Marketing (website only): measuring the effectiveness of our own advertising campaigns. We do not permit third parties to use cookies on our site to build advertising profiles of you for use on other sites.
You can control cookies through your browser settings and, where we display a cookie banner, through the choices it offers. Our website responds to Global Privacy Control (GPC) signals by treating them as an opt-out of any sharing that would qualify as a “sale” or “sharing” under state law. We do not currently respond to “Do Not Track” browser signals, for which no standard has been adopted.
10. Your privacy rights
Depending on where you live, you may have some or all of the following rights regarding your personal information: to access or obtain a copy of it; to correct inaccuracies; to delete it; to port it to another service; to restrict or object to certain processing; to withdraw consent where processing is based on consent; to opt out of sales, sharing for targeted advertising, and certain profiling (we do none of these); and to not be discriminated against for exercising your rights.
How to exercise your rights. Customers can access, export, and correct most data in Settings and can delete their account as described in the Account & Data Deletion Policy. Anyone may submit a request by emailing info@mylocalseoranker.com with the subject “Privacy Request,” by calling (216) 296-3191, or by writing to the address below. We will verify your identity (typically by confirming control of the email address or phone number on file) and respond within 45 days (or the shorter period required by your local law), extendable once where permitted. You may authorize an agent to make a request on your behalf; we will require proof of authorization. If we deny your request, you may appeal by replying to our response with “Appeal” in the subject line; we will respond to appeals within 45 days. Residents of certain states may also contact their state Attorney General if they are dissatisfied with the result.
End Customers. If a business you interacted with uses our Service, that business controls your information. Please direct requests to the business. If you contact us, we will forward your request to the relevant business and assist them in responding.
U.S. state residents (California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, and others). In the preceding 12 months we collected the categories of personal information described in Section 1 (identifiers; commercial information; internet and device activity; geolocation; audio and visual information; professional information; and inferences drawn from the above) for the purposes in Section 2, and disclosed them to the categories of recipients in Section 3 for business purposes. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use or disclose sensitive personal information for purposes other than those permitted by law. We have no actual knowledge of selling or sharing information of consumers under 16.
EEA, UK, and Switzerland. You may lodge a complaint with your local supervisory authority. Our legal bases are described in Section 2. We have not appointed an EU or UK representative because we do not target or monitor individuals in those regions; if that changes, we will update this Policy.
Canada. You may request access to and correction of your personal information, and may withdraw consent subject to legal and contractual restrictions. You may contact the Office of the Privacy Commissioner of Canada with concerns.
11. Children’s privacy
The Service is for business use and is not directed to children under 13 (or under 16 where a higher age applies). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
12. Third-party links and platforms
The Service links to and publishes content on third-party platforms (Google, social networks, review sites, app stores). Their privacy practices are governed by their own policies, which we encourage you to read. Content you publish through the Service to those platforms may be publicly visible and indexed by search engines.
13. Data Processing Terms for Customers
To the extent we process End Customer personal information on behalf of a Customer that is subject to the GDPR, UK GDPR, or U.S. state privacy laws, the following terms apply and form part of our agreement with that Customer:
- Roles. The Customer is the controller/business and Devtech is the processor/service provider. We process End Customer data only on the Customer’s documented instructions (which include these Terms and the Customer’s use of the Service’s features) and for no other purpose, except as required by law.
- Restrictions. We will not sell or share End Customer data, retain, use, or disclose it outside the direct business relationship with the Customer or for any purpose other than providing the Service, or combine it with data from other sources except as permitted by law. We will notify the Customer if we determine we can no longer meet our obligations.
- Confidentiality and security. Our personnel are bound by confidentiality obligations, and we maintain the safeguards described in Section 6.
- Sub-processors. The Customer authorizes the service providers listed in Section 3 as sub-processors. We will provide at least 15 days’ notice of new sub-processors (by updating this Policy and notifying account owners), and the Customer may object on reasonable grounds, in which case the parties will work in good faith to resolve the objection or the Customer may terminate the affected feature.
- Assistance. We will reasonably assist the Customer with data subject requests, security assessments, and data protection impact assessments, and will notify the Customer without undue delay of a personal data breach affecting End Customer data.
- Deletion and return. Upon termination, we will delete or return End Customer data as described in Section 5 and the Account & Data Deletion Policy. Customers can export their data at any time.
- Audits. We will make available information reasonably necessary to demonstrate compliance and, no more than once per year (or after a confirmed breach), allow audits by the Customer or an independent auditor subject to reasonable confidentiality and scheduling terms.
- Transfers. Transfers from the EEA/UK/Switzerland are governed by the Standard Contractual Clauses (Module 2, controller-to-processor) and UK Addendum, which are incorporated by reference.
Customers who require a signed Data Processing Agreement may request one at info@mylocalseoranker.com.
14. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify Customers by email or in-app notice at least 14 days before they take effect and update the effective date above. Continued use of the Service after the effective date constitutes acceptance.
15. Contact us
Devtech, LLC (Local SEO Ranker)
Attn: Privacy
3414 Erhart Road
Litchfield, Ohio 44253, USA
Phone: (216) 296-3191
Email: info@mylocalseoranker.com