Privacy policy
What EchoBD collects, why, and who can see it — for the merchants who use us, and for the customers we call on their behalf. Written to be read, not skimmed past.
Last updated: 5 August 2026
Who this policy covers
EchoBD is a service for online stores in Bangladesh: a merchant sends us a new order, we call their customer in Bangla, and the customer confirms or cancels with a keypress. That means two very different groups of people show up in our systems, and this policy treats them separately.
Merchants are our customers. You create the account, read the dashboard, and pay the bills — we collect your data directly and decide how it is handled.
Your customers are the people we call. We never have a relationship with them: their name, number and order reach us only because you sent them, we use them only to place the call you asked for, and you remain responsible for having the right to share them. In data-protection terms, the merchant is the controller of customer data and EchoBD is the processor.
What we collect from merchants
When you sign up and run a shop on EchoBD, we collect:
- Account details — your name, email address, phone number, password (stored hashed, never in plain text), and your shop's name and platform.
- Verification documents — the identity and business documents you upload during KYC review, used only to verify the account.
- Billing records — your plan, minute balance, top-ups and invoices. Card and mobile-banking details are handled by our payment gateway (SSLCommerz); we never see or store full payment credentials.
- API keys — stored as hashes only. A key is shown to you exactly once at creation; after that not even we can read it back.
- Usage and support — call volumes, webhook delivery logs, and anything you send us when you ask for help.
Customer data we process for you
Each order you send us carries what the call needs and nothing more: the customer's name, phone number, delivery address, and the order's items and amount. During the call we record what happened — which keypress the customer chose, how long the call ran, and the result (confirmed, cancelled, forwarded, no answer).
We use this data to place the call, speak the order back, deliver the result to your webhook, and show the call log in your dashboard. We do not use your customers' data to market to them, build profiles of them, or contact them for any reason you did not ask for.
How we use it
Everything we do with data falls under one of these:
- Running the service — placing calls, delivering webhooks, rendering your dashboard.
- Billing — metering minutes against your balance and processing top-ups.
- Keeping the service safe — spotting abuse, fraud, and misdialled or harassing call patterns.
- Support — answering you when you write to us, with access to only what the question needs.
- Legal obligations — what Bangladeshi law requires us to keep or disclose.
Google account access
Two parts of EchoBD ask for access to your Google account. Both are optional, both are yours to revoke at any time, and neither touches your Gmail, Drive, Calendar or Contacts.
Signing in with Google. We read your name, email address and profile picture to identify your EchoBD account. We do not read your inbox, and we do not receive your Google password — Google confirms who you are and tells us nothing else.
Connecting Google Tag Manager. Shops on a platform we have no plugin for can let EchoBD install its order-collection tag for them. With your permission we list your Tag Manager accounts and containers so you can choose one, then create a single tag and a single trigger inside a workspace named “EchoBD” in the container you picked, and publish it. We do not read, change or delete any other tag, trigger, variable or workspace in your container, and we do not access any container you did not choose.
We keep the permission Google issues so we can keep that one tag up to date when you change how your order page is read — otherwise a correction you make in your dashboard would never reach your live site. It is stored encrypted, used for nothing else, and destroyed when you disconnect.
EchoBD’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We never sell Google user data, never use it for advertising, and never let a human read it except with your explicit consent or where the law requires it.
You can withdraw either permission from your EchoBD dashboard, or from your Google account at myaccount.google.com/permissions. Withdrawing Tag Manager access stops us updating the tag; the tag itself stays in your container until you remove it there, because revoking our permission is precisely what stops us doing it for you.
How long we keep it
Merchant account data lives as long as the account does. When you close your account we delete it, except for the billing records the law requires us to retain.
Order and call data is kept so your call log and webhook history stay useful, and deleted or anonymised when it no longer is. If one of your customers asks you to erase their data, tell us and we will erase our copy — that request flows through you, because the customer's relationship is with your store, not with us.
How we protect it
Data moves over encrypted connections. Passwords and API keys are stored as hashes. Webhook deliveries are signed so your server can verify they came from us. Access inside EchoBD is limited to the people who need it to run the service or answer your ticket, and nothing more.
No honest security section ends without this sentence: no system is unbreakable. If a breach ever affects your data, we will tell you what happened and what we are doing about it, promptly and plainly.
Your rights
Merchants can read and correct almost everything we hold about them directly in the dashboard. For anything you cannot reach yourself — a copy of your data, a correction, or deletion — email us and we will do it.
If we called you and you are not a merchant: the store you ordered from asked us to. We hold only what that call needed. Ask the store to correct or erase your details, or write to us directly and we will pass the request to them and erase our copy.
Changes, and how to reach us
If this policy changes in a way that matters, we will say so on this page and update the date at the top — we will not quietly swap the words under you. Questions, requests, or complaints: [email protected].
The other half of the agreement
This policy explains what happens to data; the terms of service explain everything else the account signs up to.