EverEcho

Legal

Privacy Policy

Last updated: 14 April 2026

1. Who we are

EverEcho Ltd is the data controller for the personal information processed through this platform. We are registered in England and Wales and comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

To contact us about data protection matters: privacy@everecho.co.uk

2. What personal data we collect

Account dataName, email address, password (hashed)When you register
Payment dataName, billing address, last 4 digits of card (via Stripe)When you purchase
Memorial contentPhotographs, written text, video, life datesWhen you build a memorial
Usage dataIP address, browser type, pages visitedAutomatically via our servers
CommunicationsEmails you send us, support requestsWhen you contact us

We do not sell personal data to third parties. We do not use your data for advertising.

3. Legal basis for processing

Providing the ServicePerformance of contract (Art. 6(1)(b) UK GDPR)
Processing paymentPerformance of contract; Legal obligation
Sending service emailsLegitimate interests (service communication)
Marketing emailsConsent (you may withdraw at any time)
Security and fraud preventionLegitimate interests

4. How we use your data

  • To create and manage your account and memorials
  • To process payments and issue receipts
  • To send service-related notifications (memorial published, plaque dispatched, etc.)
  • To respond to your support requests
  • To detect and prevent fraud and abuse
  • To comply with our legal obligations

5. Third-party services

We use the following trusted third-party providers to operate the Service:

Supabase (US)Database and authenticationDPA in place; EU/UK SCCs
Stripe (US)Payment processingPCI-DSS compliant; EU/UK SCCs
Cloudflare R2 (EU)Media storage (photos, video)GDPR-compliant infrastructure
Resend (US)Transactional email deliveryDPA in place; EU/UK SCCs

Each provider is bound by contractual safeguards (Standard Contractual Clauses) where data transfers outside the UK occur.

6. Data retention

We retain your personal data for as long as your account is active, plus a further 6 years for legal and financial record-keeping obligations. Memorial content (photographs, text) is retained permanently as part of the Service unless you request deletion.

If you close your account, we will delete your personal profile data within 90 days. Published memorials will be taken offline unless a family member assumes ownership.

7. Your rights under UK GDPR

Right of accessRequest a copy of the data we hold about you
Right to rectificationCorrect inaccurate or incomplete data
Right to erasureRequest deletion of your personal data ("right to be forgotten")
Right to restrictionAsk us to limit how we process your data
Right to portabilityReceive your data in a machine-readable format
Right to objectObject to processing based on legitimate interests
Right to withdraw consentWithdraw marketing consent at any time

To exercise any of these rights, email privacy@everecho.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Cookies

We use strictly necessary cookies to maintain your login session. We do not use advertising or tracking cookies. A session cookie is set when you log in and is deleted when you close your browser or log out.

9. Security

All data is transmitted over HTTPS. Passwords are hashed using bcrypt and never stored in plain text. Access to production data is restricted to authorised personnel. We conduct regular security reviews.

10. Changes to this policy

We will notify you by email of any material changes to this Privacy Policy at least 30 days before they take effect. The current version will always be available at everecho.co.uk/privacy.