PEPLEFREVER

Legal

Privacy notice

What we collect, why, and what you can do about it. Draft for review before launch.

What we collect

  • Account details: name, email address, password (hashed), and, if you sign in with Google, Facebook, X or Apple, the identifier and profile picture they give us.
  • What you add: profiles, photos, videos, tributes, replies, candles and the country a candle was lit from (worked out from your connection and kept as a two-letter code).
  • Giving: your name, email, amount and message. Card details go straight to Stripe and never touch our servers.
  • Technical: server logs with IP addresses, kept for 30 days for security.

Why

To run the service you asked for, to email you about activity you chose to hear about, to send receipts, and to keep the site safe. Our legal bases are contract, consent (marketing and reminder emails), and legitimate interests (security, moderation).

People who have died

Data protection law does not apply to the deceased, but we treat their profiles with care. Living people mentioned on a profile can ask us to remove information about them.

Who we share with

Stripe (payments), Resend (email), Google Cloud (hosting, in London), Google reCAPTCHA (spam protection), and the platforms whose posts and videos are embedded on profiles, which may set their own cookies when an embed loads. We never sell personal data.

Your rights

Access, correction, deletion, portability and objection. Change your emails in Settings, unsubscribe from any email in one click, or write to contact@peopleforever.com. You can complain to the ICO at ico.org.uk.

Retention

Profiles are kept for as long as the service exists. Accounts are deleted on request; contributions to profiles stay, attributed to “a former member”, unless you ask for them to be removed. Donation records are kept for 7 years for accounting law.

Cookies

One cookie keeps you signed in, one remembers your chosen look, and reCAPTCHA sets its own. We use no advertising or tracking cookies.