Skip to content
Legal

Privacy policy

What EchoBD collects, why, and who can see it — for the merchants who use us, and for the customers we call on their behalf. Written to be read, not skimmed past.

Last updated: 5 August 2026

Who this policy covers

EchoBD is a service for online stores in Bangladesh: a merchant sends us a new order, we call their customer in Bangla, and the customer confirms or cancels with a keypress. That means two very different groups of people show up in our systems, and this policy treats them separately.

Merchants are our customers. You create the account, read the dashboard, and pay the bills — we collect your data directly and decide how it is handled.

Your customers are the people we call. We never have a relationship with them: their name, number and order reach us only because you sent them, we use them only to place the call you asked for, and you remain responsible for having the right to share them. In data-protection terms, the merchant is the controller of customer data and EchoBD is the processor.

What we collect from merchants

When you sign up and run a shop on EchoBD, we collect:

  • Account details — your name, email address, phone number, password (stored hashed, never in plain text), and your shop's name and platform.
  • Verification documents — the identity and business documents you upload during KYC review, used only to verify the account.
  • Billing records — your plan, minute balance, top-ups and invoices. Card and mobile-banking details are handled by our payment gateway (SSLCommerz); we never see or store full payment credentials.
  • API keys — stored as hashes only. A key is shown to you exactly once at creation; after that not even we can read it back.
  • Usage and support — call volumes, webhook delivery logs, and anything you send us when you ask for help.

Customer data we process for you

Each order you send us carries what the call needs and nothing more: the customer's name, phone number, delivery address, and the order's items and amount. During the call we record what happened — which keypress the customer chose, how long the call ran, and the result (confirmed, cancelled, forwarded, no answer).

We use this data to place the call, speak the order back, deliver the result to your webhook, and show the call log in your dashboard. We do not use your customers' data to market to them, build profiles of them, or contact them for any reason you did not ask for.

How we use it

Everything we do with data falls under one of these:

  • Running the service — placing calls, delivering webhooks, rendering your dashboard.
  • Billing — metering minutes against your balance and processing top-ups.
  • Keeping the service safe — spotting abuse, fraud, and misdialled or harassing call patterns.
  • Support — answering you when you write to us, with access to only what the question needs.
  • Legal obligations — what Bangladeshi law requires us to keep or disclose.

Google account access

Two parts of EchoBD ask for access to your Google account. Both are optional, both are yours to revoke at any time, and neither touches your Gmail, Drive, Calendar or Contacts.

Signing in with Google. We read your name, email address and profile picture to identify your EchoBD account. We do not read your inbox, and we do not receive your Google password — Google confirms who you are and tells us nothing else.

Connecting Google Tag Manager. Shops on a platform we have no plugin for can let EchoBD install its order-collection tag for them. With your permission we list your Tag Manager accounts and containers so you can choose one, then create a single tag and a single trigger inside a workspace named “EchoBD” in the container you picked, and publish it. We do not read, change or delete any other tag, trigger, variable or workspace in your container, and we do not access any container you did not choose.

We keep the permission Google issues so we can keep that one tag up to date when you change how your order page is read — otherwise a correction you make in your dashboard would never reach your live site. It is stored encrypted, used for nothing else, and destroyed when you disconnect.

EchoBD’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We never sell Google user data, never use it for advertising, and never let a human read it except with your explicit consent or where the law requires it.

You can withdraw either permission from your EchoBD dashboard, or from your Google account at myaccount.google.com/permissions. Withdrawing Tag Manager access stops us updating the tag; the tag itself stays in your container until you remove it there, because revoking our permission is precisely what stops us doing it for you.

Who we share it with

We do not sell data — merchant or customer — to anyone, and we do not share it for advertising. Data leaves our systems only to the parties that make the service physically work:

  • Telephony carriers — the customer's phone number and the call audio must reach the network that connects the call.
  • SSLCommerz — our payment gateway, which handles the payment details of your top-ups under its own policy.
  • Infrastructure providers — the hosting and storage the service runs on, bound by their own security commitments.
  • Authorities — if the law compels us, and only to the extent it compels us.

How long we keep it

Merchant account data lives as long as the account does. When you close your account we delete it, except for the billing records the law requires us to retain.

Order and call data is kept so your call log and webhook history stay useful, and deleted or anonymised when it no longer is. If one of your customers asks you to erase their data, tell us and we will erase our copy — that request flows through you, because the customer's relationship is with your store, not with us.

How we protect it

Data moves over encrypted connections. Passwords and API keys are stored as hashes. Webhook deliveries are signed so your server can verify they came from us. Access inside EchoBD is limited to the people who need it to run the service or answer your ticket, and nothing more.

No honest security section ends without this sentence: no system is unbreakable. If a breach ever affects your data, we will tell you what happened and what we are doing about it, promptly and plainly.

Your rights

Merchants can read and correct almost everything we hold about them directly in the dashboard. For anything you cannot reach yourself — a copy of your data, a correction, or deletion — email us and we will do it.

If we called you and you are not a merchant: the store you ordered from asked us to. We hold only what that call needed. Ask the store to correct or erase your details, or write to us directly and we will pass the request to them and erase our copy.

Cookies and local storage

The site sets one cookie that matters: your session, so the dashboard knows it is you. Your theme choice (light or dark) is kept in your browser's local storage and never sent anywhere.

Our public pages — the home page, pricing, docs, sign-up and sign-in — load Google Tag Manager so we can measure which of them bring people to EchoBD. It sets Google's own analytics cookies and tells us nothing that identifies you personally.

It is deliberately absent from the dashboard. Those screens show your customers' names, phone numbers and orders, and no analytics tool of ours runs where that data is on display. We do not advertise to you or your customers, and nothing on this site is a third-party advertising tracker.

Changes, and how to reach us

If this policy changes in a way that matters, we will say so on this page and update the date at the top — we will not quietly swap the words under you. Questions, requests, or complaints: [email protected].

The other half of the agreement

This policy explains what happens to data; the terms of service explain everything else the account signs up to.