Privacy Policy

Last updated: May 30, 2026

1. Introduction

Echo Service Solution ("we," "our," or "us") respects your privacy and is committed to protecting personal information you provide when using our platform and services (the "Services"). This Privacy Policy explains what we collect, why we collect it, how we use and share it, and the choices you have. This policy applies to the website, the customer dashboard, and any hosted instances we operate on your behalf.

We comply with applicable privacy laws, including Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and the Alberta Personal Information Protection Act (PIPA).

2. Information We Collect

2.1. Account Information

  • Name, email address, and password (stored as a one-way hash by our auth provider)
  • Company name, billing address, and phone number where you provide them
  • Profile photo or avatar where you choose to upload one

2.2. Billing Information

  • Subscription plan, status, renewal date, and payment history
  • Credit card details are processed and stored by Stripe; we do not store full card numbers on our servers

2.3. Operational Data Inside Your Instance

When you use the Services to manage your business operations, your hosted instance stores data you input, including:

  • Customer records, contact details, and job sites
  • Job requests, estimates, invoices, payments, and field-service records
  • Product, service, equipment, subcontractor, and permit catalogue
  • Attachments, photos, signatures, and documents you upload
  • Chatter messages, internal notes, and activity history

You retain ownership of this operational data. We process it on your behalf as your data processor.

2.4. Usage and Technical Data

  • IP address, browser type, device type, and operating system
  • Pages visited, features used, and timestamps
  • Error logs and diagnostic data when something fails

2.5. Communications

  • Support tickets, emails, and chat conversations you send us
  • Survey responses and feedback you choose to provide

3. How We Use Your Information

  • To provide, operate, and maintain the Services
  • To process payments and manage your subscription
  • To send transactional emails (receipts, password resets, service notifications)
  • To send service-related announcements (planned maintenance, security advisories, feature updates)
  • To provide customer support and respond to your inquiries
  • To monitor uptime, diagnose technical issues, and improve performance
  • To prevent fraud, abuse, and security incidents
  • To comply with legal obligations and respond to lawful requests

We do not sell your personal information. We do not use the operational data inside your instance for marketing purposes or to train machine-learning models.

4. Sub-Processors and Third-Party Services

We use the following third-party services to operate the platform. Each is bound by their own privacy policies and applicable data-protection agreements:

  • Vercel (United States) — hosts our website and dashboard
  • Supabase (United States, with EU regions available) — authentication and dashboard database
  • Amazon Web Services (AWS Lightsail) (Canada / United States) — hosts customer Odoo instances and backups
  • Stripe (United States, Canadian entity for CAD) — payment processing
  • Resend (United States) — transactional email delivery
  • Twilio (United States) — SMS notifications when enabled
  • Google reCAPTCHA (United States) — bot prevention on signup forms

Where data is processed outside of Canada, it remains subject to the privacy and security standards described in this policy. We update this sub-processor list when material changes occur.

5. Where Your Data Is Stored

  • Customer Odoo instances and their daily backups are hosted in AWS data centres, primarily in Canadian or U.S. regions depending on your selected location
  • Account, billing, and authentication data is stored in Supabase
  • Payment data is stored by Stripe under their PCI-DSS Level 1 compliance
  • Operational backups are retained for 7 days locally on the hosting server and longer in encrypted off-site storage

6. How Long We Keep Your Information

  • Account information: for as long as your account is active, plus up to 12 months after closure for accounting and legal records
  • Operational data inside your instance: for the lifetime of your subscription. After cancellation, you have 30 days to export your data, after which we permanently delete the instance and its backups
  • Billing records: for the period required by Canadian tax law (currently 6 years)
  • Support communications: up to 24 months after the ticket is closed
  • Server logs and diagnostic data: typically 30 days, longer if required for security investigations

7. Your Rights

Subject to applicable law, you have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Delete your account and request deletion of associated personal information
  • Export a copy of your operational data before account closure
  • Withdraw consent for non-essential processing (such as marketing communications)
  • File a complaint with the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada

To exercise any of these rights, contact us at contact@echoservicesolution.com. We will respond within 30 days.

8. Cookies and Tracking

We use cookies and similar technologies to keep you signed in, remember your preferences, and understand how the platform is used. Essential cookies (authentication, session, security) cannot be disabled without breaking the platform. Analytics cookies, where used, are limited to aggregate usage statistics and do not identify individual users.

You can clear cookies through your browser settings. Doing so will sign you out of the platform.

9. Security

  • All connections to the platform use TLS encryption (HTTPS)
  • Passwords are hashed using industry-standard one-way algorithms
  • Customer instances are isolated in separate Docker containers with separate databases
  • Backups are encrypted at rest in our off-site storage
  • Access to production systems is restricted to authorized personnel and logged

No system is perfectly secure. If we become aware of a security incident affecting your data, we will notify you and, where required, the relevant authorities in accordance with applicable law.

10. Children's Privacy

The Services are intended for use by businesses and are not directed at children under 18. We do not knowingly collect personal information from individuals under 18. If you believe we have collected information from a minor, contact us and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or sub-processors. The "Last updated" date at the top of this page indicates when the latest changes took effect. Material changes will be communicated by email or through the platform.

12. Contact Us

For privacy questions, data requests, or complaints, contact us at:

  • Email: contact@echoservicesolution.com
  • Address: Rocky Mountain House, Alberta, Canada
  • Phone: 403-895-0373

You may also contact the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada if you believe your privacy rights have been violated.

By using Echo Service Solution, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your personal information as described.