Privacy Policy
Last updated:
This policy describes the EchoLens Digital learning and operations platform, identified in company materials as EchoLens (SMC-Private) Limited, Pakistan. Registered business address: Cheema Road, Opposite Garden Town, Gujranwala, Punjab, Pakistan. Contact for privacy questions: info@echolens.digital or Contact & Support.
Information collected and its purpose
The information requested depends on your account role and the features you use. Browsing the course catalogue does not require a learner account.
- Identity, contact and education: name, email, username, registration number, phone/WhatsApp, city, address, institute/university, degree/program, study year, career goals and marketing preference. Profile or onboarding workflows can also include date of birth, gender, CNIC/B-form, parent/guardian and emergency-contact details. These support account administration, enrollment, learner support and applicable staff onboarding.
- Authentication: password hashes, Google account identifiers when Google sign-in is used, session credentials and temporary verification/reset credentials. These support sign-in, account security and recovery; passwords are stored as hashes.
- Admissions and payments: course registrations, referral information, contact details, notes, challan amounts, discounts, deadlines, payment status, references and proof of payment. Staff onboarding can include bank/payout documentation. These support admissions, fee verification and finance. Payments use challans and manual bank/payment verification.
- Learning and assessment: enrollments, attendance, quiz answers, submitted code and execution output, assignment/capstone notes, evidence links and files, grades, feedback, AI reports, course progress and compiler interaction/activity records. Gems, badges, streaks and certificates support learning progress and gamification.
- Uploaded material: avatars, signatures, resumes, coursework/evidence, project images, department/task attachments, signed contracts and onboarding documents, including identity and qualification documents where requested. Files support the specific workflow in which you upload them.
- Communications and operations: support requests and replies, course/event/job chats and comments, feedback, announcements, moderation, staff/employment records, departments, tasks, ambassador referrals and commission records, and audit logs. These support communication, administration and accountability.
- Talent Marketplace and recruitment: profiles, skills, education, experience, employment preferences, availability, salary visibility choices, social links, resumes and projects; recruiter/company details, searches, shortlists, notes, contact requests, messages and reports. These support recruitment features and abuse review.
- Technical and usage information: IP addresses used for request limiting, browser/device and request information, page/referral and interaction data handled by analytics and service providers. These support security, delivery and understanding website usage. Browser storage also preserves filters and drafts.
Who can see your information
Private course evidence, payment files, tickets and department records are available to the account holder and authorized staff according to the feature's permissions. Certificate verification exposes certificate authenticity details and learner/course information. Public learner-profile URLs expose selected name, course and gamification information to visitors who know the URL; this is separate from publishing a Talent profile.
Talent profiles and projects become public when published. Published fields include the profile description, skills, education, experience, employment preferences, links and verified learning information. Salary is displayed only if its visibility option is enabled. Email, phone and resume are withheld from public Talent pages and are revealed to an approved recruiter only after you accept that recruiter's specific contact request. Recruiter searches and contact disclosures are audited. Unpublishing removes the profile from public/search views, but does not erase prior disclosures or their audit history. Published Showcase posts can make their images, descriptions and related project information public.
External services
Always in use: Render for hosting, Supabase for database storage, Google Fonts and Google Analytics on every page, the cdnjs and jsDelivr libraries the browser compiler loads, Compiler Explorer for native-language compilation, and the privacy-enhanced YouTube player wherever a course provides a video. Live classes always involve a third-party video service - 8x8 JaaS when it is configured, and the public Jitsi Meet service otherwise. Google sign-in, Groq and Google Gemini for AI features, Brevo for bulk email, Cloudflare R2 for Showcase images, and the transactional email provider are used only when enabled; when they are not configured, the related feature is unavailable rather than routed elsewhere. Google Analytics loads only after you accept analytics cookies. Providers can process information in countries other than Pakistan according to their infrastructure and terms.
Render
Application hosting and persistent-disk storage for private uploads and operational files. Provider privacy information.
Supabase (PostgreSQL hosting)
Database storage for account, learning and operational records, hosted in the ap-southeast-1 (Singapore) region.
Google OAuth
When enabled and chosen, Google sign-in supplies an account identifier, name and email. Local password sign-in is handled by EchoLens. Provider privacy information.
Zoho ZeptoMail
Transactional emails such as verification, password recovery, enrollment, reminders, grades and tickets. ZeptoMail is the provider in use. If its token is not configured the application instead sends through a generic SMTP server set in its own configuration; the provider is chosen once at startup, and there is no automatic switch between the two during sending. Provider privacy information.
Brevo
When configured for live sending, bulk announcements and outreach using recipient contact details; bulk sending defaults to dry-run. Provider privacy information.
Groq / Google Gemini
When configured, AI assistance and assessment process prompts, submitted work, output and relevant evidence. Avoid placing unrelated personal information in AI prompts. Provider privacy information.
8x8 JaaS / Jitsi Meet
Live-class audio, video and meeting participation. The app uses 8x8 JaaS when configured, with Jitsi Meet as a fallback. Provider privacy information.
Google YouTube
Embedded course videos use the privacy-enhanced YouTube player. Loading or playing embedded media involves requests to Google and can involve provider storage. Provider privacy information.
Google Analytics 4
Google tags embedded on existing site pages measure visits and usage, with browser/device, referral and technical information. The deployed Google settings determine further processing. Provider privacy information.
Google Fonts
Delivers website fonts; browser requests disclose connection and request information to Google. Provider privacy information.
Cloudflare R2
When configured, stores public Showcase image uploads. Other private uploads use the application upload directory. Provider privacy information.
Cloudflare cdnjs / jsDelivr
Deliver browser libraries, including compiler runtimes. Their servers receive connection and request information when libraries are loaded. Provider privacy information.
Compiler Explorer (godbolt.org)
Remote compilation receives source code, associated files and execution input for supported native-language runs. Provider privacy information.
WhatsApp / Meta
Only when you choose the WhatsApp contact link, contact messages and account/connection data are handled by that service. Provider privacy information.
Google Gemini, OAuth, YouTube, Analytics and Fonts use Google's privacy information. Jitsi's fallback service provides its own privacy information; cdnjs delivery is covered by Cloudflare's information. Provider links explain provider practices; they are not a claim that every supported integration is currently enabled.
Cookies, analytics and advertising
See our Cookie Policy for session cookies, analytics and browser draft storage. Existing site pages contain Google Analytics tags.
If Google advertising is enabled, third-party advertising vendors, including Google, use cookies to select ads using your earlier visits to EchoLens and other websites. Google's advertising cookies allow Google and its partners to personalize ads using visits across sites. You can opt out of personalized advertising through Google Ads Settings. You can also manage participating vendors' personalized-advertising choices at aboutads.info/choices. Opting out of personalization does not necessarily stop all advertisements or essential cookies. Any additional ad networks must be identified here before being introduced.
Retention, correction and deletion requests
Account, assessment, admissions, support, uploaded-file and audit records are retained by the application's storage and backup systems. An incomplete free-course enrollment expires after its three-calendar-month window; this does not delete submissions, grades or certificates. Talent contact-reveal audit history is retained even after unpublishing. The application does not implement a comprehensive automatic personal-data deletion schedule.
What the platform actually does today: records are kept for as long as the account and its operational history exist. There is no scheduled purge. The one automatic removal is the free-course window — an incomplete free enrollment is removed after three calendar months, and the submissions, grades and certificates from it are preserved. The activity/audit trail, including Talent recruiter contact-reveal history, is append-only and is not trimmed. Database backups follow the hosting provider's own schedule and retention.
An administrator can delete a learner account. That removes the user record and its course enrollments; it does not by itself remove submissions, grades, certificates, gem history, support tickets, uploaded files or audit entries already recorded elsewhere. There is no self-service account-deletion button in the application.
To request access, correction or deletion, email info@echolens.digital or use the support form and choose the Account category. EchoLens aims to respond within 30 days. Each request is handled manually against the records described above; records that must be kept for finance, certificate-verification or abuse-review purposes are identified in the response rather than silently retained.
Request access, correction or deletion by emailing info@echolens.digital or submitting the support form, identifying the account and the information involved. Do not send passwords or full identity documents in your initial request. The team may need to verify account ownership. Account removal alone does not guarantee that every related file, payment record, certificate or audit record has been erased.
Children and account eligibility
EchoLens is an educational platform for school and university learners, and there is no minimum age for holding a learner account. Under-18s are expected users, not an exception.
A learner under 18 must have a parent or guardian's permission to enroll. At signup every learner ticks a required declaration confirming they are 18 or older, or that a parent or guardian has given permission. This is a self-declaration made by the person filling in the form. EchoLens does not verify it, does not contact the parent or guardian, and has no way to confirm that permission was actually given. The declaration wording and the date you agreed to it are stored with the account.
A parent or guardian can ask to see, correct or delete their child's data by emailing info@echolens.digital or using the support form. Describe the learner's account and your relationship to them; we may ask questions to establish that before acting, and we will explain any record that has to be kept for the reasons set out above.
Identity numbers - a B-form or CNIC number - are collected only where enrollment or certification requires them, and are stored as numbers. We do not collect images or scans of identity documents, and an identity number is never shown on a public profile, a published Talent profile, a certificate verification page or anywhere else a visitor can reach.
Policy updates
The last-updated date above identifies this policy's revision. Privacy questions or concerns can be sent to info@echolens.digital.