Privacy
This working page describes the product’s intended privacy approach. It must be reviewed and completed with the operating company’s legal details before launch.
Information handled by the service
This can include account and contact details, memorial content, private tribute contact details, provider application information, service-order details, payment references, device-session records, and limited technical or security logs. Raw card details are not stored by Forever & Always.
Families decide what is shared
Memorial owners control whether a memorial is public and which contributions appear. A contributor’s email address and private moderation notes are not shown on the public memorial page.
Information used to provide a service
When someone requests flowers or grave care, the selected provider receives only the details needed to assess, schedule and fulfil that request. Payment, mail, hosting and app-delivery suppliers may process limited information under their own contractual safeguards once those services are activated.
QR visits
A scan opens the memorial page and increments an aggregate scan count. The platform does not provide families or visitors with a list of who scanned a code, precise scan locations, or a visitor-to-visitor contact channel. Limited security logs may be kept for fraud prevention and service reliability.
Security and access
Mobile sessions use expiring, revocable device tokens. Sensitive family actions require a verified email address, and administrators can use authenticator-app multi-factor authentication. No internet service can promise absolute security, so suspected incidents should be reported promptly.
Your choices
Living users can correct account details, export a portable copy of their information, and request deletion in the app. Deletion normally follows a 30-day grace period and may be deferred for an open order or limited legal retention. See Delete an account for the current process.
Contact
Privacy questions can be sent to privacy@qrforeverandalways.com.