Home

Echo Aligned — Privacy Policy

Last updated: 21 July 2025

1. Who We Are

Echo Aligned (“we”, “our”, “us”) is operated as a sole-proprietor business subject to the small-business exemption. We are committed to safeguarding your personal information.

2. Scope

This Policy explains how we collect, use, disclose, and protect data when you visit www.echoaligned.com or use any related application, API, or service (collectively, the “Platform”).

3. Why We Collect Data

See the table below for purpose, legal basis, and typical data.

PurposeLegal basis (GDPR)Typical data
Account creation & loginContract performanceEmail, hashed password, Clerk user ID
Influencer-vetting featuresContract performanceSearch criteria, vetting requests, results
Payments & subscriptionsContract performanceStripe customer ID, plan details, last 4 card digits (never full card number)
Support enquiriesLegitimate interestName, email, message (FormCarry)
Security & fraud preventionLegitimate interestIP address, device/browser data, activity logs
Ad-conversion measurementLegitimate interestPseudonymous Google conversion IDs, ad-click metadata
Legal compliance (tax, accounting)Legal obligationInvoices, transaction metadata

We never sell or rent your personal data, and we collect only what is necessary.

4. Where Your Data Lives

Our sub-processors and retention periods are listed below.

Sub-processorData storedRetention & deletion
Clerk (identity & auth)Credentials, profile, session tokens (never full password)Erased within 30 days of account deletion
Firebase (database)Vetting requests, results, logsRemoved when you delete the request or your account
Stripe (payments)Payment tokens, invoices, subscription status10 years (tax & accounting)
FormCarry (support forms)Name, email, message contentDeleted within 30 days after ticket resolution
Google Ads (conversion tracking)Pseudonymous conversion IDs, ad-click info, timestamp, browser/device metadataConversion cookie ~90 days; logs per Google Ads Data Processing Terms

All providers have Data-Processing Agreements with us and rely on EU Standard Contractual Clauses (SCCs) for cross-border transfers where required.

5. Cookies & Local Storage

• Essential cookies – session tokens (Clerk) and CSRF protection. • Conversion-tracking cookie – _gcl_* from Google Ads, set only after a successful purchase to measure campaign effectiveness. • No analytics or behavioural-advertising cookies beyond the above.

6. Data Sharing

We share data only with: 1) the sub-processors in Section 4; 2) authorities or courts when legally compelled; 3) a successor entity if we undergo a merger or acquisition (you will be notified in advance and may delete your data).

7. International Transfers

Data may be processed in the EU, and the United States. Transfers use Standard Contractual Clauses or equivalent safeguards.

8. Security Measures

• End-to-end TLS (HTTPS) and HSTS. • AES-256 encryption at rest in Clerk, Firebase, and Stripe. • Role-based access and audit logging. • Continuous vulnerability scanning and annual third-party penetration tests. While we apply industry-standard safeguards, no system is perfectly secure; you use the Platform at your own risk.

9. Your Rights

If you are in the EEA, UK, or a similar jurisdiction, you may: • Access, correct, erase, or port your data. • Restrict or object to certain processing. • Withdraw consent where we rely on it. • Complain to a supervisory authority. Email support@echoaligned.com to exercise any right. We respond within 30 days.

10. Children’s Privacy

The Platform is not directed to anyone under 16. If you believe a minor has provided personal data, contact us so we can delete it.

11. Contact

Data-Protection Lead: N/A – small-business exemption Email: support@echoaligned.com Postal address: Not applicable – operating online-only

12. Policy Changes

We may revise this Policy from time to time. Material changes will be announced by email or in-app at least 14 days before they take effect. Use of the Platform after that date constitutes acceptance.

13. Future Services

If we later add privacy-respecting analytics (e.g., Plausible) or other third-party tools, we will update Section 4 before they go live.

Loading...

Loading authentication...