← All policies

CounterEcho Privacy Policy

1. Who we are

CounterEcho operates a QR-based customer feedback and reputation platform for businesses. Legal entity: BeyondX LLC, based in Olympia, Washington. This policy applies to (a) business owners and staff who create accounts ("Business Users") and (b) their customers who submit feedback through a QR code ("Reviewers").

2. What we collect

### From Business Users

  • Account data: name, email address, password (stored hashed by our authentication provider, Supabase Auth), business name, business slug, brand colors and logo URL.
  • Subscription/billing data: plan type, subscription status, and payment details — payment card data is handled entirely by Stripe; we never see or store full card numbers.
  • Review platform links you configure (e.g. your Google/Yelp/Facebook URL).
  • Invite data: email addresses of staff you invite (stored in staff_invites).
  • Usage data: audit logs, analytics events, and subscription history used to operate the Service.

### From Reviewers (customer feedback)

  • Rating (1–5 stars) and comment text you submit.
  • Optional email address and optional phone number, only if you choose to provide them.
  • A record of your consent choices (GDPR consent flag; TCPA consent if a phone number is provided).
  • The QR session token used to submit, which is single-use and expires within 24 hours of generation.

### Automatically

  • IP address (used only for abuse/rate-limit protection in our edge functions), request metadata, and usage/error logs.

3. How we use it

  • To operate the feedback flow: receive your feedback, route it to the business, and (where configured) queue a draft response for the business's approval.
  • To send the business alerts and weekly summaries by email.
  • To send SMS messages only where you have given explicit consent (see the SMS Compliance addendum).
  • To bill Business Users for paid plans (via Stripe).
  • To prevent abuse (rate limiting) and to keep the Service secure.
  • We do not sell personal data. We do not use it for advertising.

4. Who we share it with

  • The business you reviewed — your rating and comment are delivered to the business whose QR code you scanned, together with your email/phone if you provided them. The business is the controller of that feedback data.
  • Service providers (as processors): Supabase (database, auth, hosting), Stripe (payments), a transactional email provider, Twilio (SMS — only after A2P 10DLC approval), and error/analytics tooling.
  • Authorities — only where legally required.
  • Review platforms (e.g. Google): when a happy reviewer (rating 4–5) is redirected to the business's review page link, the reviewer's browser goes there directly; we do not transmit your feedback data to any review platform ourselves.

5. Data retention

See the separate Data Retention Policy. In summary: feedback is retained for 24 months after submission, or 90 days after account termination; QR session tokens are purged shortly after expiry; logs are kept ~90 days; and billing records are kept per applicable tax law (7 years).

6. Your rights

  • Reviewers: you may request access to, correction of, or deletion of the feedback you submitted by contacting the business you reviewed (first) or us at privacy@beyondx.llc. We will act on verified requests within 30 days.
  • Business Users: you can update your profile in Settings; you may request account deletion at privacy@beyondx.llc. We will delete or de-identify your data within 30 days, subject to legal retention (e.g. tax records).
  • Residents of the EU/UK/EEA: see GDPR section. California residents: see CCPA/CPRA section.

7. Consent & children

  • We rely on explicit consent where required (GDPR consent checkbox and TCPA consent for phone numbers on the feedback form).
  • The Service is not directed to children under 16, and we do not knowingly collect their data.

8. Security

We protect data with industry-standard measures including: encrypted transport, Supabase Row-Level Security on your tenant data, secrets stored in environment variables (never in client code), short-lived single-use QR tokens, and rate limiting on our edge functions. No system is perfectly secure; you use the Service at your own risk to the maximum extent permitted by law.

9. International transfers

Data is hosted by our sub-processors in the United States (Supabase project region: US West — Oregon). If data is transferred outside your jurisdiction, we rely on appropriate safeguards.

10. Changes

We will post changes to this policy and notify Business Users by email when material.

11. Contact

Support: support@beyondx.llc · Privacy: privacy@beyondx.llc · BeyondX LLC, Olympia, Washington

---

*In plain language: we collect the minimum needed to run the feedback card — business account details, and the rating/comment/contact info a customer chooses to give. We never sell it. You can ask us to delete your data anytime.*

Effective 2026-09-01. Provided for information only — not legal advice. For the latest versions, contact support@beyondx.llc.