Privacy
QR Forever & Always handles personal information to provide memorial pages, QR-code access, family tools, provider tools, support, security, and optional real-world service requests.
Information handled by the service
This can include account and contact details, memorial content, private tribute contact details, provider application information, service-order details, payment references, device-session records, notification preferences, and limited technical or security logs. Raw card details are not stored by QR Forever & Always.
Families decide what is shared
Memorial owners choose public discovery, an unlisted direct link, or private family-only access, and control which contributions appear. A contributor’s email address and private moderation notes are not shown on visitor-facing memorial pages.
Information used to provide a service
When someone requests flowers or grave care, the selected provider receives only the details needed to assess, schedule and fulfil that request. Payment, mail, hosting and app-delivery suppliers may process limited information under their own contractual safeguards once those services are activated.
QR visits
A scan opens the memorial page and increments an aggregate scan count. The platform does not provide families or visitors with a list of who scanned a code, precise scan locations, or a visitor-to-visitor contact channel. Limited security logs may be kept for fraud prevention and service reliability.
Remembrance calendars
If a family enables a subscription calendar, it contains only selected yearly remembrance dates and the public memorial link. Calendar links use a hard-to-guess token, but anyone with the link may be able to subscribe, so families should share it only with people they want to receive those reminders.
Photos and uploads
The app uses the camera only for QR scanning and uses the photo library only when a user chooses a memorial image or completion-evidence photo. Uploads are re-encoded before storage where supported by the service.
Security and access
Mobile sessions use expiring, revocable device tokens. Sensitive family actions require a verified email address, and administrators can use authenticator-app multi-factor authentication. Information is sent over HTTPS. No internet service can promise absolute security, so suspected incidents should be reported promptly.
Your choices
Living users can correct account details, export a portable copy of their information, and request deletion in the app. Deletion normally follows a 30-day grace period and may be deferred for an open order, fraud-prevention, safety, support, accounting, or other limited legal-retention reason. See Delete an account for the current process.
Contact
Privacy questions, deletion questions, and content concerns can be sent to privacy@qrforeverandalways.com or through the support page.