CounterEcho Acceptable Use & Security / Safety Policy
1. Purpose
This policy sets the rules for how CounterEcho may and may not be used, and how customer feedback data is handled and protected. It applies to everyone who uses the Service: business owners and staff ("Business Users") and the customers who scan a QR code to submit feedback ("Reviewers").
2. How customer feedback data is handled and protected
- The business is the controller of its own feedback data; CounterEcho is a processor. Feedback (rating, comment, optional email/phone) belongs to the customer who submitted it, and is delivered to the business whose QR code was scanned — nothing else.
- We do not sell feedback data. We do not use it for advertising. We do not share it with review platforms: a happy reviewer is redirected in their own browser to the business's public review page; we do not transmit the feedback to the platform.
- Consent: Reviewers are asked to consent where required (GDPR consent for EU/UK/EEA reviewers; TCPA opt-in before any SMS is sent to a phone number). Consent flags are recorded on every submission and never pre-checked.
- Protection measures in place: encrypted transport (TLS); Row-Level Security in the database so each tenant can only see its own rows; short-lived, single-use QR tokens (24-hour expiry); rate limiting on abuse-prone endpoints; secrets stored in environment variables only, never in client code; audit logging of sensitive operations.
- Retention: feedback is kept only as long as the Data Retention Policy allows, and is deletable on request.
3. Prohibited conduct — Business Users
You must not:
- Buy, sell, incentivize, or manufacture reviews or ratings, or pressure customers to leave positive reviews (this includes discounts/rewards conditioned on 5-star ratings) — this violates FTC guidelines and most review platforms' rules;
- Post or solicit fake, misleading, or AI-generated reviews posing as real customers;
- Use feedback data for purposes the reviewer did not agree to, or to harass, defame, or discriminate against anyone;
- Attempt to access another tenant's data, forge QR tokens or feedback sessions, or defeat the Service's security, authentication, or rate limits;
- Scrape, bulk-harvest, or resell customer feedback data;
- Send SMS or email through the Service without required consent (TCPA/A2P for SMS; CAN-SPAM for email) or without honoring opt-outs (e.g. SMS "STOP");
- Upload or transmit illegal content, malware, or content that violates third-party rights.
4. Reviewer conduct
Reviewers must submit only genuine feedback about their own experience. Submitting false, abusive, or illegal content may result in removal of the submission.
5. Security responsibilities of Business Users
- Keep account credentials confidential; use strong passwords.
- Only invite staff you are authorized to give access; remove access for staff who leave.
- Report suspected unauthorized access, a lost device, or a compromised account to support@beyondx.llc immediately.
- You are responsible for activity on your tenant account, including by staff you invite.
6. SMS
No SMS is sent without Twilio A2P 10DLC brand + campaign approval (see SMS Compliance doc). SMS sending stays disabled until that approval is confirmed, and every SMS requires prior recipient consent with a working opt-out (STOP).
7. Enforcement
- We may suspend or terminate access, with notice where practicable, for violation of this policy.
- We may remove content, decline to process feedback, and report serious violations (e.g. fraud, abuse of minors) to authorities.
- If your account is terminated for violation, no refund is owed (see Refund & Cancellation Policy).
8. Vulnerability reporting
If you discover a security issue in the Service, contact security@beyondx.llc before disclosing publicly. We respond to verified reports and do not take action against good-faith researchers who follow responsible disclosure.
9. Questions
support@beyondx.llc · privacy@beyondx.llc · Effective date: September 1, 2026
---
*In plain language: use CounterEcho for genuine feedback only — no fake reviews, no misusing customer data, no spam. Keep your password safe, and tell us immediately if something looks wrong.*