Privacy policy
2026-07-privacy-v1
01Controller and scope
The controller is {{LEGAL_ENTITY_NAME}}, tax ID {{LEGAL_TAX_ID}}, at {{LEGAL_ADDRESS}}, operating under the Echoris brand. These markers must be replaced with verified details before production. To exercise rights or ask a privacy question, write to support@echorisapp.com; if a data protection officer is appointed, their dedicated channel will also be published.
This policy covers the website, mobile app, audio-tour marketplace, purchase library, creator tools and live local mode. External services opened outside Echoris may apply their own policies; we identify them where they act as independent controllers.
02Data we process
We may process account data such as uid, email, name, photo, language, roles and marketplace access status. We also process guide and tour data, such as public profile, bio, languages, social links, images, audio, city, price, publications and review status.
For purchases we store purchase, tour and publication identifiers, amount, currency, status, Stripe identifiers and library entitlements. For reviews we store the rating, text, moderation status and the relationship with the purchased or claimed tour.
For security, support and quality we may process technical data such as usage events, screens visited, errors, traces, app version, device and operational logs. In live local mode the app may use the microphone, the camera for QR codes, the local network, WiFi/hotspot and the location permissions Android requires for WiFi APIs; Echoris does not sell this data nor use it for invasive advertising.
Support requests include their message, attachments and related correspondence. For creators we may process identity, tax residence and ID, payout account, activity, verification documents, agreements, sales and settlements. We do not request full payment-card details; the payment provider receives them directly.
03Processing purposes
We use data to authenticate users, create and maintain accounts, display profiles, publish tours, process purchases, deliver library access, manage refunds and settlements, moderate content, provide support, send transactional messages and retain evidence of acceptances and specific consents.
We also protect accounts, prevent fraud and abuse, investigate incidents, diagnose failures, maintain continuity, respond to authorities, comply with tax and accounting duties and defend claims. We do not use payment, location, microphone or private-content data for behavioural advertising.
04Legal bases
Contract performance supports processing needed to authenticate, operate an account, deliver content, manage purchases and provide support. Legal obligation supports tax, accounting and lawful requests. Legitimate interests may support proportionate security, fraud prevention and diagnostics after balancing rights and honouring objections.
Where a feature is not required for the contract and law requires consent, we request it separately, specifically and transparently. You may withdraw it as easily as it was given without affecting prior processing. Accepting terms is not consent to marketing, optional tracking, device permissions or unrelated purposes.
05Providers and recipients
We work with the providers needed to deliver the service: Firebase/Google for authentication, database and storage; Stripe for payments and checkout; Resend for transactional emails; and hosting, security and observability providers. In the mobile app we additionally use Firebase analytics and crash reporting with technical data, with no advertising identifiers and no cross-app tracking; the website loads no third-party analytics or trackers. We only share the data necessary for each purpose.
We may disclose data to public bodies, tax authorities, courts, law enforcement, professional advisers or a buyer in a corporate transaction where there is a valid basis, confidentiality duty and suitable safeguards. We do not sell personal data or let processors repurpose it incompatibly.
06International transfers
Some providers may process information outside the European Economic Area. Before enabling a transfer we verify the relevant mechanism, such as an adequacy decision, standard contractual clauses or another lawful safeguard, and assess supplementary measures where needed.
You can ask about applicable safeguards at support@echorisapp.com. The final provider list, locations and transfer mechanisms must be validated in the processing record and GDPR agreements before production; this draft is not that review.
07Retention
We keep account data for as long as you maintain an active account. Purchases, billing, entitlements and audit records are kept for the periods needed to operate the service, resolve incidents and comply with legal obligations. Technical logs and crash reports are kept only for as long as needed for diagnostics and security. Local live tour reaction data is aggregated or anonymized where possible and deleted periodically.
After a retention period, information is deleted or anonymised unless legal hold or a specific claim requires continued storage. Agreements, consents, invoices and settlements may remain for the tax, commercial and consumer-protection periods confirmed by professional advisers.
08Security and internal limits
Sensitive operations are validated on the server. Purchases, entitlements, Stripe events, legal acceptances, authorisation flags and audit logs are server-only. Controls include authentication, roles, transport encryption, secret management, backups, traceability and review of critical operations.
Stripe webhooks are signature-verified and processed idempotently. Logs minimise personal data and redact secrets, tokens, passwords, emails and sensitive identifiers where unnecessary. No system is infallible; we assess and notify breaches where law requires it.
09Children
Echoris is not directed to children who cannot validly contract or consent under applicable law. We do not knowingly request children's data outside permitted circumstances. Parents and guardians should supervise use and must not provide accounts or payment methods without authority.
If you believe we received a child's data without a valid basis, write to support@echorisapp.com with enough information to locate the account, without sending unsolicited sensitive documents. We will assess deletion, restriction or authorisation as appropriate.
10Your rights
You may request access, rectification, erasure, objection, restriction and portability and withdraw consent where applicable by writing to support@echorisapp.com. Identify the right and account and provide only what is needed to verify identity.
We respond within the legal period and may seek clarification for complex requests or third-party rights. Some information cannot be erased immediately because of retention duties, pending claims or legal exceptions; we explain why and restrict use where appropriate.
11Complaints and supervisory authority
If you think we handled data incorrectly, contact us so we can investigate. Internal review does not limit your right to complain to the competent supervisory authority, including the Spanish Data Protection Agency where applicable, or to seek a judicial remedy.
You will not be penalised for exercising rights in good faith. We retain only what is needed to process the request, demonstrate our response and meet accountability obligations.
13Changes to this policy
We update this policy when processing, providers, rights or legal requirements change. We publish the date and version and give prominent notice before a material change takes effect. A privacy policy provides information; acceptance or consent is requested only where a specific legal reason requires it.
Previous versions and evidence of material changes are retained as needed for transparency. Questions about an update may be sent to support@echorisapp.com.
A question these pages don't answer?
Write to support