Marketing Command Center

Privacy Policy

Effective date: September 1, 2026

Who we are

The Echo Water Marketing Command Center ("MCC", "we", "us") is a marketing analytics and operations platform operated by Echo Technologies ("Echo"). MCC connects a business's own marketing, analytics, and commerce accounts into a single operator dashboard used by that business's authorized team members. Questions about this policy: [email protected].

What MCC does

MCC reads performance and account data from platforms a business connects — for example Google Ads, Google Analytics 4, Google Search Console, Meta, Klaviyo, Shopify, and similar services — and presents that data as reports, alerts, and analysis to the business's own operators. MCC is not a consumer product and does not build profiles of, market to, or make automated decisions about individual consumers.

Information we collect

How we use information

We do not sell personal information, do not share connected-platform data with third parties for their own purposes, and do not use it for advertising or ad targeting by us or anyone else.

Google user data — Limited Use disclosure

MCC accesses Google services (such as Google Ads, Google Analytics, and Google Search Console) only with the account owner's authorization, and only to provide the reporting and analysis features described above to that owner's operators.

MCC's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we only use Google user data to provide and improve the user-facing features of MCC; we do not transfer it except as necessary to provide those features, to comply with law, or as part of a merger or acquisition with prior notice; we do not use it for advertising; we do not allow humans to read it except with the account owner's consent, for security purposes, to comply with law, or when aggregated for internal operations; and we do not use Google user data to train generalized artificial-intelligence or machine-learning models.

You can revoke MCC's access to your Google data at any time from your Google account permissions page.

Storage and security

Data is hosted on infrastructure in the United States. Platform credentials and API tokens are envelope-encrypted at rest with AES-256-GCM; access to decrypted credentials is logged. All data moves over TLS. Operator access is role-based, and administrative actions are recorded in an audit log.

Retention and deletion

We retain connected-platform data while the connection remains active, so operators can see performance history. When a business disconnects a platform or closes its account — or emails us a deletion request at [email protected] — we delete the associated credentials and stored data within 30 days, except where a longer period is required by law.

Service providers

We use a small set of processors to run the service: Railway (application and database hosting), Twilio (SMS notifications to operators), and SendGrid (email notifications to operators). Each processes data only on our instructions to provide the service.

Changes

We will post any changes to this policy on this page and update the effective date above. Material changes will be communicated to account owners directly.

Terms of service