Echo & Impact Privacy Policy

Echo & Impact Privacy Policy

Effective Date: January 1, 2025
Entity: Echo & Impact Inc. (Echo & Impact, we, us, our)
Contact:
Email: info@echoandimpact.com
Address: 5225 Main St, Buffalo, NY 14221
Phone: +1 (844) 591-ECHO

1. Scope and Roles

1.1 Scope. This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with our websites (including www.echoandimpact.com), portals, communications, studios, and business operations (collectively, Sites), and in connection with services we provide to clients (Services).

1.2 Controller Role. We act as a business/controller when we collect personal information about website visitors, prospects, vendors, studio/podcast guests we book, and client personnel.

1.3 Processor Role. When we process personal information on your behalf in connection with an Order, including but not limited to marketing, ecommerce, analytics, creative or development services, we act as your processor/service provider. Processing is governed by Echo & Impact’s Privacy Policy and Terms & Conditions.

2. Personal Information We Collect

Depending on your interactions, we may collect the following categories:

2.1 Identifiers and Contact Data, including but not limited to name, email address, phone number, employer, job title, postal address, government identifiers, precise geolocation and unique identifiers.

2.2 Commercial and Billing Data, including but not limited to order details, invoices, limited payment identifiers, processor-issued tokens, and transaction metadata. Our processors do not store full payment card numbers or CV. Any card or banking details shared by the client will be processed as stated in section 7.3.

2.3 Professional/Role Data, including but not limited to industry, team, permissions, and training records.

2.4 Usage and Device Data, including but not limited to IP address, cookie identifiers, advertising identifiers, pages viewed, links clicked, session duration, referrers, approximate location, and diagnostics.

2.5 Audio/Visual Content, including but not limited to photo, video, and audio captured in studio/podcast sessions or at events, subject to releases and the applicable Order.

2.6 Support and Communications, including but not limited to messages, requests, and survey responses.

3. Sources

We collect personal information from:
(a) You directly, including but not limited to forms, emails, calls, contracts, studio bookings;
(b) Automated means, including but not limited to cookies, pixels, SDKs, logs, and similar technologies;
(c) Service providers and advisers, including but not limited to payment processors, analytics, CRM and email tools, hosting, and professional advisers;
(d) Platforms you connect, including but not limited to advertising platforms and analytics tools pursuant to your configuration.

4. Purposes of Use

We use personal information to:
(a) provide, operate, and secure the Sites and Services; set up and manage accounts and projects;
(b) communicate with you regarding support, notices, training, billing, and updates;
(c) perform services agreed in any signed Orders;
(d) plan, capture, and deliver creative studio/podcast work;
(e) process payments and prevent fraud or abuse;
(f) analyze usage, improve features, and develop new offerings;
(g) market our Services where permitted and measure campaign performance; and
(h) comply with law, enforce agreements, and protect rights, safety, and property.

5. SMS/MMS Authorization

5.1 Collection of Phone Numbers. We collect business phone numbers directly from you, including, but not limited to, numbers provided in contracts, intake or online booking forms, support requests, emails, and calls.

5.2 Purpose of Use. We use phone numbers solely for transactional and conversational SMS/MMS necessary to provide the Services or execute an Order, including, but not limited to, account or project, scheduling and coordination, project updates, and support communications. By providing a number on our website, you consent to us calling or sending messages to you.

5.3 Promotional Use. Echo & Impact does not sell or share your phone number with third parties for marketing purposes. We do not use phone numbers for internal marketing or promotional messaging.

5.4 Consent and Opt Out. By providing a phone number and engaging with us, you authorize us to send SMS/MMS for the purposes described in Section 5.2. You may opt out at any time by sending us an email at support@echoandimpact.com or replying STOP to the message, Reply HELP for further information. Message frequency varies. SMS and MMS may incur charges from your mobile carrier. Your rights in Section 9 remain available.

5.5 Sharing. We disclose phone numbers only to service providers that support message delivery and operations under contracts that limit use to our instructions, and to our affiliates and offshore teams to perform Services as described in this Policy, consistent with Section 6.

5.6 Retention and Suppression. We retain phone numbers and related message logs consistent with Section 8. If you opt out, we will suppress your number from further SMS/MMS while retaining limited records necessary to honor the opt out and for compliance, audit, and fraud prevention.

6. Cookies, Analytics, and Advertising

We and our partners use cookies and similar technologies including but not limited to GA4 and tags from platforms such as Meta, TikTok, and Google to operate the Sites, measure performance, and, where permitted, deliver or measure advertising. You can manage preferences via browser settings and our cookie controls. 

7. Disclosures of Personal Information

We disclose personal information to:
(a) Service providers/processors that support our operations, including but not limited to hosting, analytics, payment processing, communications, ticketing, security, and logistics;
(b) Affiliates and offshore teams (including Karachi, Pakistan) to perform Services under our instructions;
(c) Professional advisers, including but not limited to accounting, legal, and insurance;
(d) Business transfer participants, including but not limited to merger, acquisition, financing, or asset sale;
(e) Legal/safety recipients to comply with law or protect rights; and
(f) Parties you direct us to share with, including but not limited to connecting accounts or publishing podcast episodes.

We may share de-identified or aggregated data that does not identify an individual. We do not sell personal information for money. We may “share” or “process for targeted advertising” under state privacy laws when using third-party advertising or analytics tools; see section 9 for opt-out rights.

8. Payment Information

8.1 Processors. Payments are processed by third-party payment processors and banking partners. Those providers store and secure payment card and bank account data; we do not have access to full card numbers or CVV codes stored by them.

8.2 What We Retain. We may retain limited, masked payment identifiers, processor-issued tokens, and transaction metadata for billing, reconciliation, fraud prevention, and chargeback handling.

8.3 Direct Collection (if required). If we need to collect card or banking details directly, we will do so only through secure collection methods we designate. Access to any such information is restricted to designated billing personnel under confidentiality obligations and least-privilege access controls, with logging and encryption at rest. We do not intentionally collect or store full payment card numbers or CVV codes in our systems until it is required to perform services in the order. If you transmit payment information outside our approved secure methods, we may delete it upon receipt and require re-submission through an approved channel.

8.4 Deletion/Redaction. Upon project closure or upon your written request, we will delete or irreversibly redact any bank details we hold to the extent commercially reasonable, while retaining processor tokens and legally required records, including but not limited to masked identifiers and transaction records, for tax, audit, and compliance purposes.

9. Retention

We retain personal information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Typical retention ranges:
(a) Marketing leads: twenty-four (24) to thirty-six (36) months from last interaction;
(b) Project/account records: the project term and up to seven (7) years thereafter for tax/audit;
(c) Studio/podcast project files: seven (7) years post-delivery unless otherwise agreed. We may retain de-identified data for longer periods.

10. Your Privacy Rights

Depending on your state, you may have rights to access, correct, delete, receive a portable copy, and opt out of: (a) sharing for cross-context behavioral advertising, and/or (b) targeted advertising. You may also have the right to limit use/disclosure of sensitive personal information and to appeal if we deny a request.

10.1 How to submit a request. Email (info@echoandimpact.com) or submit (www.echoandimpact.com) with your name, email, state, and request type.

10.2 Verification. We may require reasonable verification, including but not limited to email confirmation or additional details. Authorized agents must provide proof of authority; we may verify directly with the consumer.

10.3 Appeal. If we decline your request, you may appeal by replying to our decision with “Appeal” in the subject line. We will respond within the period required by applicable law.

10.4 Non-discrimination. We will not discriminate against you for exercising privacy rights, subject to lawful differences tied to program participation or account features.

10.5 Opt-out of sharing/targeted advertising. You may send us an email with “Do Not Share My Personal Information” in the subject line; we will treat eligible emails as an opt-out where required.

California Notice (CCPA/CPRA)

For California residents, the categories collected include identifiers, commercial information, internet activity, professional information, and inferences; purposes and disclosures are described in sections 4 and 6. We do not sell personal information for money. We may “share” personal information for cross-context behavioral advertising. You may exercise the rights listed above via the methods provided. We do not knowingly sell or share personal information of consumers under sixteen (16).

11. International Users; Transfers

We are a United States company with offshore operations in including but not limited to Karachi, Pakistan. If you access the Sites or Services from outside the United States, your information may be transferred to and processed in the United States and Pakistan. Where required, we use appropriate safeguards for cross-border and implement technical and organizational measures appropriate to the risk.

12. Security

We maintain commercially reasonable administrative, technical, and physical safeguards designed to protect personal information. No method of transmission or storage is entirely secure, and we cannot guarantee absolute security.

13. Children

Our Sites and Services are not directed to children under sixteen (16), and we do not knowingly collect personal information from them. If you believe a child has provided personal information to us, contact (info@echoandimpact.com) and we will take appropriate steps.

14. Third-Party Links and Platforms

Our Sites may include links to third-party sites, platforms, or features. We are not responsible for their practices. Review those providers’ privacy policies before interacting.

15. Changes to This Policy

We may update this Policy from time to time. The Effective Date at the top indicates the latest version. Material changes will be posted on this page. Your continued use of the Sites or Services after an update constitutes acknowledgment of the updated Policy.

16. Contact Us

Questions or requests can be sent to info@echoandimpact.com