Privacy Policy

Last Updated: March 2026
Effective Date: March 2026
NeverForgotten Memorials
Ireland
Email: [email protected]

1. Introduction

Welcome to NeverForgotten Memorials ("we," "our," or "us"). NeverForgotten Memorials is operated by Paul McManus Dowdall, a sole trader based in Ireland, who is the data controller for the personal data described in this policy. We are committed to protecting your privacy and handling your personal data with care and respect. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our memorial creation and management services at neverforgottenmemorials.ie.

As an Ireland-based service, we comply with the General Data Protection Regulation (GDPR) and the Data Protection Acts 1988–2018 (Ireland). By using our services, you agree to the practices described in this policy.

2. Information We Collect

2.1 Information You Provide Directly

  • Account Information: Email address, password (stored as a secure hash, never in plain text), and name when you register
  • Google Sign-In: If you use Google OAuth to create an account, we receive your name and email from Google. We do not receive or store your Google password.
  • Memorial Content: Names, biographies, dates, photographs, video slideshows, stories, tributes, and other content you add to memorial pages
  • Contributor Content: Tributes and stories submitted by visitors to memorial pages, including contributor name and message. All submissions are subject to approval by the memorial owner before being displayed publicly.
  • Payment Information: Billing details are processed entirely by Stripe. We do not receive, see, or store your card number or full payment details.
  • Communications: Messages sent through our contact forms or support channels

2.2 Information Collected Automatically

  • Technical Data: IP address, browser type, operating system, device information
  • Usage Data: Pages visited, time spent, memorial interactions, feature usage
  • Session Data: Authentication tokens and session cookies required for the site to function

2.3 Data About Third Parties in Memorial Content

Memorials contain personal data about deceased individuals (names, dates, photographs) and may reference living people. You are responsible for ensuring that any personal data you include about living individuals is handled sensitively and with their knowledge where appropriate.

2.4 Cookies and Tracking Technologies

We use the following cookies:

Cookie Type Purpose Duration
Essential Cookies Session management, security (CSRF protection), site functionality. Required for the site to work. Session or up to 2 weeks
Analytics Cookies Google Analytics: understanding how visitors use our site. Only active with your consent. Up to 2 years
Preference Cookies Remembering your cookie consent choice 1 year
Cookie Consent: We only use non-essential cookies (like analytics) after obtaining your explicit consent through our cookie banner. Essential cookies for site functionality are always active.

3. How We Use Your Information

Purpose Legal Basis (GDPR)
Creating and operating your account Contract (Art. 6(1)(b))
Hosting and displaying memorial pages Contract (Art. 6(1)(b))
Processing payments and managing subscriptions Contract (Art. 6(1)(b))
Sending subscription, billing and account emails Contract (Art. 6(1)(b))
Sending subscription lapse and content deletion warnings Legitimate interests (Art. 6(1)(f))
Notifying memorial owners of new tributes and stories for approval Contract (Art. 6(1)(b))
Customer support and responding to enquiries Legitimate interests (Art. 6(1)(f))
Security monitoring and fraud prevention Legitimate interests (Art. 6(1)(f))
Improving our services Legitimate interests (Art. 6(1)(f))
Sending newsletter / marketing emails Consent (Art. 6(1)(a))
Legal compliance Legal obligation (Art. 6(1)(c))

4. Public Memorial Pages

Memorial pages are publicly accessible by default. This means:

  • Anyone with the URL or QR code can view the memorial without creating an account
  • Memorial pages may be indexed by search engines such as Google
  • Content you add (photographs, biography, tributes) may be seen by anyone on the internet

You should consider this carefully before adding sensitive personal information to a memorial. Content submitted by visitors (tributes and stories) is subject to approval by the memorial owner before being displayed publicly.

5. Third-Party Services

We use the following third-party services that may process your data:

Service Purpose Data Processed Privacy Policy
Stripe Payment processing Billing email, payment confirmation, subscription status stripe.com/ie/privacy
Cloudinary Image, video and media storage All uploaded media (photos, videos, audio, QR codes) cloudinary.com/privacy
Heroku (Salesforce) Application and database hosting All user and memorial data stored in our database salesforce.com/privacy
Google OAuth Social login (optional) Name and email (only if you sign in with Google) policies.google.com/privacy
Google Analytics Website analytics (with consent only) Anonymised usage data policies.google.com/privacy
Data Transfers: Some services (like Stripe and Cloudinary) may store data outside the EU/EEA. We ensure they provide adequate safeguards through Standard Contractual Clauses approved by the European Commission. We do not sell your personal data to any third party.

6. Data Retention

Data Type Retention Period
Account data (name, email) Until account is deleted, or 2 years after last login if inactive
Memorial content (active subscription) Retained for the duration of an active subscription
Memorial content (lapsed subscription) Retained for 6 months after subscription lapses, then permanently deleted. Name, dates, profile picture and QR code are retained permanently.
Payment records 7 years as required by Irish Revenue / tax law (held by Stripe)
Contact form messages Up to 2 years or until the matter is resolved
Server logs 30 days for security monitoring
Newsletter subscriber data Until you unsubscribe
Analytics data Up to 26 months (Google Analytics)

Please note that public memorial content may remain in search engine caches for a period beyond our control after deletion.

7. Your Data Protection Rights (GDPR)

Under GDPR, you have the following rights. To exercise any of them, email us at [email protected]. We will respond within 30 days.

Right Description How to Exercise
Right to Access Receive a copy of your personal data Email request with identity verification
Right to Rectification Correct inaccurate or incomplete data Edit in account settings or email request
Right to Erasure Request deletion of your data. Note: deleting your account will permanently delete all associated memorials. Delete account in settings or email request
Right to Restriction Limit processing of your data in certain circumstances Email request
Right to Data Portability Receive your memorial data in a structured, machine-readable format Email request: we will provide data within 30 days
Right to Object Object to processing based on legitimate interests, including marketing Email request or adjust cookie preferences
Right to Withdraw Consent Withdraw consent at any time where processing is consent-based (e.g. newsletter, analytics) Unsubscribe link in emails or email request

Response Time: We will respond to all legitimate requests within 30 days.

Supervisory Authority
If you have concerns about our data practices, you have the right to lodge a complaint with the Irish Data Protection Commission:
Website: www.dataprotection.ie
Address: 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland

8. Children's Privacy

You must be at least 16 years old to create an account, in line with Ireland's Digital Age of Consent under GDPR. We do not knowingly collect personal data from anyone under 16 without parental consent. We acknowledge that:

  • Memorials may be created for children who have passed away
  • Children may be included in memorial photographs
  • The content of such memorials is the responsibility of the account holder who creates them

If you believe a person under 16 has created an account without parental consent, please contact us at [email protected] and we will take appropriate action.

9. Data Security

We implement appropriate technical and organisational measures to protect your data:

  • All data transmitted between your browser and our servers is encrypted using HTTPS/TLS
  • Passwords are stored using industry-standard hashing, never in plain text
  • Payment data is handled entirely by Stripe and never touches our servers
  • Media files are stored securely on Cloudinary
  • Our application is hosted on Heroku with regular security patching
  • Access to personal data is limited to what is necessary for operation

No system is completely secure. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours and will notify affected users without undue delay, as required by GDPR Articles 33–34.

10. International Data Transfers

Some of our third-party service providers are based outside the EEA. We ensure such transfers comply with GDPR through Standard Contractual Clauses approved by the European Commission, or other valid transfer mechanisms under GDPR Chapter V.

11. Memorial-Specific Considerations

Given the sensitive nature of our services, we acknowledge these particular circumstances:

  • Multiple Contributors: Memorials may have multiple contributors. Tributes and stories are subject to approval by the memorial owner before being displayed publicly.
  • Public Memorials: Memorials are publicly accessible by default. Consider privacy carefully when adding content about living individuals.
  • Legacy Access: We currently have no mechanism for transferring memorial ownership in the event of the account holder's death. Family members may contact us at [email protected] to discuss options.
  • Emotional Data: Memorial content is deeply personal. We handle it with extra care and respect.
  • Content After Subscription Lapses: If a subscription lapses, memorial content (gallery, biography, stories, tributes, video slideshow) is retained for 6 months and then permanently deleted. Name, dates, profile picture and QR code are retained permanently so the memorial link and headstone QR code never become a dead end.
  • Right to be Forgotten: We balance deletion requests with the sensitivity of memorial preservation and will work with you to find an appropriate solution.
Important Notice About Service Continuity: While we are committed to long-term service, we cannot guarantee perpetual operation. In the unlikely event of service discontinuation, we will provide at least 6 months notice to all active account holders and will provide tools to export your memorial data. Name, dates and QR codes will be maintained for as long as technically possible.

12. Newsletter and Marketing

We operate an optional newsletter. You may subscribe on our homepage. We will only send marketing emails if you have explicitly opted in. You may unsubscribe at any time using the unsubscribe link in any email or by contacting us. We do not send third-party advertising.

13. Changes to This Privacy Policy

We may update this Privacy Policy periodically. We will notify you of significant changes by posting the updated policy on this page with a new "Last Updated" date and sending an email notification to registered users at least 14 days before changes take effect. Your continued use of our services after changes take effect constitutes acceptance of the updated policy.

14. Contact Information

For questions, concerns, or to exercise your data protection rights:

NeverForgotten Memorials | Data Protection
Ireland
Email: [email protected]

This Privacy Policy is effective as of March 2026 and complies with the GDPR, the Irish Data Protection Acts 1988–2018, the ePrivacy Directive, and other applicable Irish and EU law.