Privacy Controls

Privacy Controls: built in, not bolted on.

Administrators have full control over what data is captured, how long it's kept, and how it's deleted — at the field level, the user level, or across the entire account.

Choose which fields are not captured — including for anonymous users
Deletion actions at user, field, and account level
Configurable retention periods with automated purging

Data field controls

Admin only
emailPII
not captured
full_namePII
not captured
user_id
captured
country
captured

Consent tracking

u_2841·grantedvia SDK
u_0944·grantedvia SDK
u_1192·pending

User data deleted

u_3374 · all fields purged · logged

Done

How it works

Full control. Nothing hidden.

Privacy Controls gives administrators granular oversight over every piece of data encatch touches — from what is recorded in the first place to how long it is kept and who can act on it.

Decide exactly what gets recorded.

Administrators can inspect every field encatch collects and choose to mask it, exclude it entirely, or allow it through. Settings apply uniformly — including to anonymous visitors. No data should slip through because someone forgot to configure it.

  • Mark any field as PII — it will not be captured. Applies to all users including anonymous.
  • Anonymous user data is subject to the same controls as identified users.
  • Changes take effect immediately across all future data ingestion.

User data field settings

emailPII
not captured
full_namePII
not captured
user_id
captured
plan
captured
ip_addressPII
not captured

Applies to all users, including anonymous visitors — no exceptions.

Accountability and identity

Keep control throughout the data lifecycle.

Audit actions, manage retention and exports, and protect the voice behind each response.

A complete history of every admin action.

Every deletion, field change, retention update, and scheduled purge is written to an immutable audit log — recording who triggered it, what was affected, and when. Gives compliance teams the paper trail they need without any extra work.

  • All data actions are logged with actor email, action type, and timestamp.
  • Covers manual deletions, field changes, retention updates, and system purges.
  • Immutable — the log cannot be edited or deleted by administrators.

Audit log

field_deleted

admin@acme.com · email

2m ago

user_purged

admin@acme.com · u_3374

14m ago

retention_updated

admin@acme.com · 90 → 30 days

1h ago

scheduled_purge

system · 438 records

6h ago

Immutable log — all admin actions on user data are recorded and timestamped.

Zero-data segmentation · Segmentation Engine

Qualify users for feedback without their data touching encatch.

Pair the encatch Segmentation Engine's webhook mode with your CDP or identity system to run targeted feedback campaigns without ingesting any personal data. Your first-party data stays where it belongs — encatch only receives segment membership signals.

Full capabilities

Every privacy lever. One place.

Privacy Controls gives administrators the tools to honour user rights, meet compliance requirements, and keep sensitive data under tight control — at every level of the system.

PII field masking

Mark any field as PII — it will not be captured at all. Applies to anonymous visitors too.

Anonymous user controls

Control what is recorded even for users with no identity — device context, session data, and more.

Cookie-less mode

Manual feedback forms continue to work for visitors who decline cookies — no session tracking required.

User deletion

Purge all data for a specific user in one action — responses, traits, and session records.

Field-level deletion

Remove a specific field from all responses across the entire account — surgical, audited, irreversible.

Retention periods

Set how long response data is kept. When the window expires, records are purged automatically.

Daily data export

Schedule daily exports to your own storage before the retention window closes. Your data, your archive.

Audit log

Every admin action on user data — deletions, field changes, retention updates — is logged with actor and timestamp.

Consent tracking

Application developers can signal consent status via SDK. encatch records when and how consent was provided.

Segmentation webhook mode

Use CDPs for first-party segmentation and send only membership signals to encatch — zero PII crosses systems.

Admin-only controls

All privacy settings are gated to administrator roles — team members see only what they need to.

Immediate effect

Deletion and masking actions take effect immediately — no queues, no overnight batch jobs.

Stylometry anonymisation

AI neutralises writing style in free-text responses — protecting identity in small groups without losing a word of meaning.

Product journey

Keep following the signal.

A little more detail

Privacy Controls, answered

Common questions about data capture, retention, and deletion controls in encatch.

What do Privacy Controls let admins configure?

Exactly what data is captured, how long it's retained, and how it's deleted — at the field, user, or account level.

Does encatch support cookie-less feedback collection?

Yes — Privacy Controls include a cookie-less mode so feedback collection still works without tracking cookies.

Can I control which fields are recorded?

Yes, PII and data-field controls let admins decide exactly which fields get recorded per form.

Your next step

Collect feedback with confidence.

Privacy Controls gives your team the tools to handle user data responsibly — from field-level masking to full account deletion — all audited and in your hands.