Privacy Policy
Version 2.0 — Last updated 15 April 2026
1. Who we are and how to contact us
Clean Ranking is operated by Ben Elers, Scholerpark 17, 10715 Berlin, Germany ("we", "us", "our"). Ben Elers is the data controller responsible for personal data collected through cleanranking.com.
Contact for data protection matters:
Email: info@cleanranking.com
Post: Ben Elers, Scholerpark 17, 10715 Berlin, Germany
2. What data we collect and why
2.1 Using the ranking tool (no account required)
When you use Clean Ranking anonymously, we collect your pairwise comparison choices and the resulting ranking scores. These are not linked to your identity unless you choose to provide your email address.
Legal basis: Art. 6(1)(b) GDPR — processing necessary to provide the service you have requested.
2.2 Requesting results by email
If you choose to receive your results by email, we collect your email address and use it solely to send that email. Your email is then retained for 30 days and permanently deleted.
Legal basis: Art. 6(1)(a) GDPR — your explicit consent, given when you submit the email form.
2.3 Marketing opt-in
If you tick the "Keep me updated about Clean Ranking" checkbox, we add your email address to our mailing list (managed via Mailchimp — see section 5). You can withdraw this consent at any time by using the unsubscribe link in any marketing email or by contacting us directly.
Legal basis: Art. 6(1)(a) GDPR — explicit opt-in consent.
2.4 Creating an account
If you register for an account, we collect your first name, last name, email address, and organisation name. We use this to provide your account, manage your sessions, and send session-related notifications.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
2.5 Facilitator session data
When you create a group session, we collect and store the session configuration, the items being ranked, participant responses, and any participant fields you have added. This data is visible to you as the facilitator and to us as the platform operator. It is not shared with any other party.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
2.6 Contact form
If you submit a message via our contact form, we collect your name, email address, and message content. We retain this for up to 12 months and use it solely to respond to your enquiry.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in responding to enquiries.
2.7 Analytics cookies (with consent)
We use Google Analytics 4 (GA4) to understand how the platform is used in aggregate. GA4 sets cookies on your device and may collect your IP address (anonymised), browser type, device type, pages visited, and session duration. GA4 is only loaded after you have given your consent via our cookie consent banner. If you decline, no analytics cookies are set and no data is sent to Google.
Legal basis: Art. 6(1)(a) GDPR and §25 TTDSG — explicit consent.
2.8 Essential cookies
We use session cookies that are strictly necessary for the site to function. These do not track you and do not require consent under §25(2) TTDSG.
3. Cookies
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
| laravel_session | Maintains your login session | Essential | Until browser closes |
| XSRF-TOKEN | Security protection for form submissions | Essential | Until browser closes |
| cookie_consent | Stores your cookie preference | Essential | 365 days |
| _ga, _ga_* | Google Analytics — usage statistics | Analytics (consent required) | Up to 2 years |
You can manage or withdraw your cookie consent at any time by clicking Cookie settings in the footer.
4. Operator access to your data
As the platform operator, we have technical access to all data stored on the platform, including session content, items, and ranking results. This is inherent to how the platform works — results are aggregated and displayed server-side. We do not access, read, or use your data for any purpose other than providing and maintaining the platform. We do not sell or share it with any third party except as described in section 5.
5. Third-party processors
| Processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting and storage | Germany (EU) | No transfer outside EU |
| Resend Inc. | Transactional email delivery | USA | Standard Contractual Clauses |
| Mailchimp (Intuit Inc.) | Marketing email list (opted-in users only) | USA | Standard Contractual Clauses |
| Google LLC | Analytics (consented users only) | USA | Standard Contractual Clauses |
| Sentry (Functional Software Inc.) | Error monitoring | USA | Standard Contractual Clauses |
6. International data transfers
Some processors listed above are based in the United States. All such transfers are made under Standard Contractual Clauses approved by the European Commission, providing appropriate safeguards as required by Art. 46 GDPR.
7. How long we keep your data
| Data | Retention period |
|---|---|
| Email address (results delivery) | 30 days, then permanently deleted |
| Contact form submissions | 12 months |
| Account data | Until account deletion, then 30 days |
| Session and ranking data | Until deleted by the facilitator or on account deletion |
| Marketing email address | Until unsubscribe or deletion request |
| Analytics data (GA4) | 14 months |
| Server logs | 14 days |
8. Your rights under GDPR
- Right of access (Art. 15) — you may request a copy of the personal data we hold about you.
- Right to rectification (Art. 16) — you may request correction of inaccurate data.
- Right to erasure (Art. 17) — you may request deletion of your personal data. Participants can use the "Delete my data" link on their results page. Account holders can delete their account from account settings.
- Right to restriction (Art. 18) — you may request that we restrict processing of your data in certain circumstances.
- Right to data portability (Art. 20) — you may request your data in a structured, machine-readable format where processing is based on consent or contract.
- Right to object (Art. 21) — you may object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at info@cleanranking.com. We will respond within one month and may ask you to verify your identity.
9. Right to lodge a complaint
If you believe your data protection rights have been violated, you may lodge a complaint with the supervisory authority responsible for us:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Friedrichstr. 219, 10969 Berlin
mailbox@datenschutz-berlin.de
www.datenschutz-berlin.de
10. Data security
All data is transmitted using TLS encryption (HTTPS). Data is stored on servers hosted by Hetzner in Germany. We maintain daily encrypted database backups with 14-day retention. Access to production systems is restricted to the platform operator.
11. Children
Clean Ranking is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us and we will delete it promptly.
12. Changes to this policy
We may update this policy from time to time. We will notify registered users of material changes by email. The version number and date at the top of this page always reflects the current version.