EchoBrain Data Privacy Policy

Last updated: December 2025

EchoBrain (“EchoBrain,” “we,” “us,” or “our”) is committed to protecting your privacy and handling data transparently and responsibly. This Data Privacy Policy explains how we collect, use, store, share, and protect personal data when you use our website, web application, integrations, and services (collectively, the “Services”).

This policy applies to:

  • Creators, merchants, and businesses that install or use EchoBrain
  • End customers who submit reviews, forms, or other content through EchoBrain-powered widgets
  • Visitors to our website

1. Who We Are

EchoBrain is a software-as-a-service (SaaS) platform that enables online shops and creators to collect verified reviews, visitor-submitted reviews, custom forms, and structured data, and to optionally process or analyze that data using automation and AI-based services.

EchoBrain acts primarily as a data processor on behalf of creators and merchants, and in limited cases as a data controller (for example, for our own website analytics, account administration, and billing).


2. Data We Collect

2.1 Data Collected from Creators & Merchants

When a creator or merchant uses EchoBrain, we may collect:

  • Account information (name, email address, login credentials)
  • Shop or platform identifiers (e.g., Fourthwall store IDs)
  • Configuration settings (review timing, email preferences, form fields)
  • Billing-related metadata (subscription status, plan type — we do not store full payment card details)
  • Technical data such as IP address, browser type, and system logs

2.2 Data Collected from End Customers

When end customers interact with EchoBrain-powered forms or review widgets, we may collect data defined by the creator, including:

  • Name or username
  • Email address
  • Order or purchase reference (for verified reviews)
  • Review content (text, ratings, images, videos)
  • Responses to custom form fields
  • Device and submission metadata (IP address, timestamp, browser)

EchoBrain only collects end-customer data as instructed by the creator or merchant.

2.3 Automatically Collected Data

We may automatically collect limited technical data such as:

  • Log files
  • Usage metrics
  • Error and performance data

This data is used to maintain, secure, and improve the Services.


3. How We Use Data

We use collected data for the following purposes:

  • To provide, operate, and maintain the EchoBrain Services
  • To collect, display, and manage reviews and form submissions
  • To verify purchases when creators enable verified reviews
  • To send transactional emails on behalf of creators (e.g., review requests)
  • To provide dashboards, analytics, and insights to creators
  • To prevent fraud, abuse, and spam
  • To comply with legal obligations

AI & Automated Processing

If enabled by the creator, EchoBrain may process review or form content using AI-based services for purposes such as:

  • Review moderation
  • Sentiment analysis
  • Summarization or categorization

AI processing is optional and configurable. EchoBrain does not use customer data to train public or generalized AI models.


Where applicable, EchoBrain processes personal data under one or more of the following legal bases:

  • Performance of a contract
  • Legitimate interests (service improvement, security, fraud prevention)
  • Consent (where required for specific features)
  • Compliance with legal obligations

Creators are responsible for ensuring they have the appropriate legal basis to collect and submit end-customer data to EchoBrain.


5. Data Sharing & Subprocessors

EchoBrain does not sell personal data.

We may share data only with trusted subprocessors necessary to provide the Services, including:

  • Cloud infrastructure and hosting providers
  • Email delivery providers (e.g., transactional email services)
  • Analytics and logging services
  • AI service providers (only when AI features are enabled)

All subprocessors are contractually obligated to protect data and process it only according to our instructions.


6. Data Retention

  • Creator and merchant account data is retained while the account is active.
  • End-customer data is retained according to creator configuration or until deleted upon request.
  • Log and technical data is retained for a limited period for security and troubleshooting purposes.

Creators may delete reviews, submissions, or customer data at any time through the EchoBrain dashboard.


7. Data Security

EchoBrain implements industry-standard security measures, including:

  • Encrypted data transmission (HTTPS/TLS)
  • Restricted access controls
  • Secure cloud infrastructure
  • Regular monitoring and logging

No system is 100% secure, but we take reasonable and appropriate steps to protect personal data from unauthorized access, loss, or misuse.


8. International Data Transfers

EchoBrain may process data in countries other than where you are located. When we transfer data internationally, we rely on appropriate safeguards such as standard contractual clauses or equivalent protections.


9. Your Rights

Depending on your location, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of data
  • Restrict or object to processing
  • Request data portability

End customers should contact the creator or merchant they interacted with. Creators may contact EchoBrain for assistance fulfilling data subject requests.


10. Cookies & Tracking

Our website may use cookies or similar technologies for basic functionality, analytics, and security. Detailed cookie information may be provided separately.

EchoBrain widgets embedded on creator sites do not place tracking cookies for advertising purposes.


11. Children’s Privacy

EchoBrain is not intended for use by children under the age of 13. We do not knowingly collect personal data from children.


12. Changes to This Policy

We may update this Data Privacy Policy from time to time. Changes will be posted on our website and, where appropriate, notified within the app.


13. Contact Us

If you have questions about this Data Privacy Policy or our data practices, you may contact us at:

Email: privacy@echobrain.app


By using EchoBrain, you acknowledge that you have read and understood this Data Privacy Policy.