EchoCraft Haven Privacy Policy

Effective Date: [October 15, 2025]

This Privacy Policy ("Policy") governs the collection, use, storage, protection, and disclosure of personal information ("Personal Information") by EchoCraft Haven ("we," "us," or "our"), a company operating the website https://www.echocrafthaven.com (the "Website") and related services (collectively, the "Services"). This Policy applies to all visitors, users, and customers ("you" or "your") who access or use our Services. By accessing or using the Services, you acknowledge that you have read, understood, and agree to the terms and conditions of this Policy, including our collection and use of your Personal Information as described herein. If you do not agree to this Policy, please do not access or use our Services.

1. Information We Collect

We collect Personal Information and non-personal information to provide, maintain, and improve our Services, fulfill your orders, communicate with you, and ensure the security of our platform. The information we collect falls into the following categories:

1.1 Personal Information You Voluntarily Provide

When you interact with our Services, you may choose to provide us with Personal Information that allows us to identify you. This includes, but is not limited to:

  • Account Registration Information: When creating an account on our Website, you may provide your full name, email address, phone number, and a password. This information is used to authenticate your identity, manage your account, and send you important account-related communications.
  • Order and Transaction Information: To process your purchases, you will need to provide shipping information (such as your full name, delivery address, and contact phone number) and payment information (such as credit card details, debit card information, or payment gateway account details). We do not store full credit card information; instead, this data is processed by our third-party payment processors in compliance with Payment Card Industry Data Security Standard (PCI DSS) requirements.
  • Communication Information: When you contact our customer support team via email, phone, or the Website’s contact form, you may provide additional Personal Information relevant to your inquiry, such as order numbers, product details, and any other information necessary to resolve your issue.
  • Subscription Information: If you subscribe to our newsletter or marketing communications, you will provide your email address. You may opt out of these communications at any time by following the unsubscribe instructions included in each message.

1.2 Information Automatically Collected

When you access or use our Services, we may automatically collect certain information about your device, browsing behavior, and interaction with the Website. This information is collected using cookies, web beacons, and other similar tracking technologies, and may include:

  • Device Information: Details about your device, such as your device type (e.g., computer, smartphone, tablet), operating system, browser type and version, unique device identifiers (e.g., IP address, MAC address), and network connection information.
  • Browsing and Usage Data: Information about your activities on the Website, including the pages you visit, the products you view or search for, the links you click, the time and duration of your visits, and the frequency of your interactions with specific content. We also collect information about the source of your visit (e.g., which website or search engine directed you to our Website).
  • Cookie Data: Cookies are small text files stored on your device that help us improve your user experience. We use both session cookies (which expire when you close your browser) and persistent cookies (which remain on your device for a specified period) to remember your account preferences, track your browsing activity, and optimize the performance of the Website. You can manage your cookie preferences through your browser settings, but disabling certain cookies may limit your ability to access or use certain features of the Services.

1.3 Information from Third Parties

In limited circumstances, we may collect Personal Information about you from trusted third-party sources, such as:

  • - Payment processors, to verify payment details and process transactions securely.
  • - Shipping and logistics partners, to track delivery status and update you on the progress of your orders.
  • - Social media platforms, if you choose to register or log in to your account using a social media account (e.g., Facebook, Instagram). In such cases, we will collect the Personal Information that you have authorized the social media platform to share with us, such as your name, profile picture, and email address.

We only collect information from third parties if we have a legal basis to do so, and we ensure that these third parties have obtained your consent to share your Personal Information with us.

2. How We Use Your Information

We use the information we collect for legitimate business purposes that are consistent with the provision of our Services and your expectations as a user. The specific uses of your information include:

2.1 To Provide and Maintain the Services

We use your Personal Information to process and fulfill your orders, including verifying your identity, processing payments, arranging for shipping, and sending you order confirmations and delivery updates. We also use this information to manage your account, provide customer support, and resolve any issues related to your use of the Services.

2.2 To Improve and Personalize the Services

We analyze the browsing and usage data we collect to understand how users interact with our Website, identify areas for improvement, and optimize the user experience. This includes tailoring product recommendations, customizing the content and layout of the Website, and developing new features or services that meet your needs.

2.3 To Communicate with You

We use your contact information to communicate with you about your account, orders, and inquiries. This includes sending important administrative messages (such as order confirmations, shipping notifications, and account updates) that are necessary for the use of the Services. We may also send you marketing communications about our products, promotions, and special offers, but only if you have consented to receive such messages. You can unsubscribe from marketing communications at any time.

2.4 To Ensure Security and Prevent Fraud

We use your information to monitor and prevent fraudulent activities, unauthorized access to your account, and other security breaches. This includes verifying your identity when you log in to your account, detecting unusual transaction patterns, and taking appropriate measures to protect your Personal Information and our Services.

2.5 To Comply with Legal Obligations

We may use or disclose your Personal Information to comply with applicable laws, regulations, legal processes, or governmental requests. This includes responding to subpoenas, court orders, or other legal requirements, and cooperating with law enforcement authorities in the investigation of potential crimes.

3. Storage and Protection of Your Information

We take the security of your Personal Information seriously and implement appropriate technical, administrative, and physical safeguards to protect it from unauthorized access, disclosure, alteration, or destruction. Our security measures include:

3.1 Data Storage Practices

Your Personal Information is stored on secure servers located in the United States and the European Union, depending on your geographic location. We use encrypted databases and secure cloud storage services to ensure the confidentiality of your data. We retain your Personal Information only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws and regulations. Once your information is no longer needed, we securely delete or anonymize it to prevent unauthorized access.

3.2 Security Measures

We implement industry-standard security technologies, such as encryption (including SSL/TLS encryption for data transmitted between your device and our Website), firewalls, and access control systems, to protect your Personal Information. We also restrict access to your Personal Information to authorized employees, contractors, and third-party service providers who have a legitimate need to access it and who are bound by confidentiality obligations.

3.3 Your Role in Protecting Information

You are responsible for maintaining the security of your account credentials, such as your password. Please do not share your password with others, and choose a strong, unique password that is difficult to guess. If you believe your account has been compromised, please contact our customer support team immediately so we can take appropriate action to secure your account.

4. Sharing and Disclosure of Your Information

We do not sell your Personal Information to third parties for commercial purposes. We may share your information with the following categories of third parties, but only for the purposes described below and in compliance with applicable privacy laws:

4.1 Third-Party Service Providers

We engage trusted third-party service providers to assist us in operating our Services, such as payment processors (e.g., PayPal, Stripe), shipping and logistics partners (e.g., FedEx, UPS), email marketing platforms (e.g., Mailchimp), and analytics providers (e.g., Google Analytics). These service providers may have access to your Personal Information only to perform the specific services on our behalf, and they are prohibited from using or disclosing your information for any other purpose. We ensure that all third-party service providers comply with this Policy and applicable privacy laws.

4.2 Business Transfers

In the event of a merger, acquisition, sale of assets, or other business transaction involving EchoCraft Haven, your Personal Information may be transferred to the acquiring or successor entity as part of the business assets. We will notify you of any such transfer via email or a prominent notice on the Website, and we will ensure that the acquiring entity adheres to the terms of this Policy.

4.3 Legal Requirements and Safety

We may disclose your Personal Information if we believe in good faith that such disclosure is necessary to: (a) comply with applicable laws, regulations, or legal processes; (b) protect the rights, property, or safety of EchoCraft Haven, our users, or the public; (c) prevent or investigate fraud, unauthorized access, or other illegal activities; or (d) enforce our Terms of Service or other agreements.

4.4 With Your Consent

We may share your Personal Information with third parties if we have obtained your explicit consent to do so. For example, if you agree to participate in a joint promotion with one of our partners, we may share your information with that partner to fulfill the promotion’s requirements.

5. Your Rights Regarding Your Information

Under applicable privacy laws (such as the General Data Protection Regulation (GDPR) for users in the European Union and the California Consumer Privacy Act (CCPA) for users in California), you have certain rights regarding your Personal Information. We aim to make it easy for you to exercise these rights, which include:

5.1 Right to Access

You have the right to request access to the Personal Information we hold about you. Upon receiving a valid request, we will provide you with a copy of your information in a commonly used, machine-readable format.

5.2 Right to Correction

If your Personal Information is inaccurate or incomplete, you have the right to request that we correct or update it. You can also update most of your account information directly through your account settings on the Website.

5.3 Right to Erasure ("Right to Be Forgotten")

You have the right to request that we delete your Personal Information, subject to certain exceptions (e.g., if we need to retain the information to comply with legal obligations or resolve disputes). We will process your request within a reasonable timeframe and notify you once the deletion is complete.

5.4 Right to Restrict Processing

You have the right to request that we restrict the processing of your Personal Information in certain circumstances, such as if you dispute the accuracy of the information or if the processing is unlawful. If we restrict processing, we will only process your information with your consent or for legal purposes.

5.5 Right to Data Portability

You have the right to request that we transfer your Personal Information to another data controller in a structured, commonly used, and machine-readable format. This right applies only to information that you have provided to us and that is processed based on your consent or for the performance of a contract.

5.6 Right to Withdraw Consent

If we process your Personal Information based on your consent (e.g., for marketing communications), you have the right to withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of processing based on consent before its withdrawal.

5.7 How to Exercise Your Rights

To exercise any of the above rights, please contact our privacy team at k69765325@gmail.com. We may request additional information from you to verify your identity and ensure that the request is legitimate. We will respond to your request within 30 days (or within the timeframe required by applicable law) and will notify you if we need additional time to process your request.

6. Policy Updates

We may update this Policy from time to time to reflect changes in our business practices, technological developments, or applicable laws and regulations. When we make material changes to the Policy, we will notify you by: (a) sending an email to the email address associated with your account; (b) posting a prominent notice on the Website; and (c) updating the "Last Updated" date at the top of this Policy. The updated Policy will take effect immediately upon posting, unless otherwise specified. We encourage you to review this Policy regularly to stay informed about how we collect, use, and protect your Personal Information. Your continued use of the Services after the effective date of the updated Policy constitutes your acceptance of the changes.

7. Children’s Privacy

Our Services are not intended for use by children under the age of 13, and we do not knowingly collect Personal Information from children under 13. If we become aware that we have collected Personal Information from a child under 13 without the consent of a parent or legal guardian, we will immediately delete that information from our systems. If you believe that we may have collected information from a child under 13, please contact us at k69765325@gmail.com.

8. International Data Transfers

If you are accessing our Services from outside the United States, your Personal Information may be transferred to, stored, and processed in the United States or other countries where our servers and service providers are located. These countries may have different privacy laws than your country of residence. We ensure that all international transfers of Personal Information comply with applicable privacy laws, including by using standard contractual clauses (SCCs) approved by the European Commission for transfers to countries outside the European Economic Area (EEA) that do not have an adequacy decision.

9. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your Personal Information, please contact our privacy team at:

Email: k69765325@gmail.com

If you are located in the EEA, you also have the right to lodge a complaint with a data protection authority in your country of residence if you believe that our processing of your Personal Information violates applicable data protection laws.