good. GratefulStackTrack / sign in

Privacy & Data Care

Privacy Policy

Last updated: 5 September 2026

We know that tribute, recipient, location, and delivery information can carry unusual emotional weight. This notice explains how we handle that information and how to contact us about it.

Overview

This privacy notice explains how GratefulStack and GratefulD collect, use, retain, and protect information across public pages, tribute and memorial flows, customer areas, supplier and delivery workflows, partner interactions, and related operational services.

GratefulStack and GratefulD are operated by PronoiaUK Limited (Company No. 16602248). We handle personal information with particular care where it relates to tributes, delivery locations, photographs, messages, family relationships, or other emotionally sensitive contexts.

Data we collect

We may collect account and contact data such as names, email addresses, login identifiers, support messages, organisation details, and communication records when you create an account, request access, contact us, or use related workflows.

We may collect tribute, order, and location data such as recipient details, memorial or tribute content, delivery notes, addresses, mapping or location inputs, checkout information, fulfilment requests, operational notes, and related status records.

We may collect supplier, florist, delivery, operator, or partner data such as application details, business details, availability, capability, assignment records, proof-of-delivery material, quality-control notes, and support or review history.

How we use data

We use data to operate the service, manage access, process tribute and order requests, support suppliers and delivery fulfilment, maintain customer and partner communications, prevent misuse, investigate operational issues, and keep business and support records.

We may also use information to review coverage, routing, quality, fraud, abuse, safety concerns, system health, and other operational risks connected to the service.

Legal bases and information about recipients

The legal basis we rely on depends on the particular processing. It may include taking steps to provide a service or perform a contract with a customer, our legitimate interests in operating and protecting the service and arranging a requested delivery, compliance with a legal obligation, or consent where the law requires consent.

A customer may give us information about a living recipient who has not dealt with GratefulD directly, for example their name and delivery address so that a requested gift or tribute can be delivered. In that situation we use recipient information only where reasonably necessary to arrange, route, verify, support, or protect that requested fulfilment. We do not use a recipient’s delivery details for unrelated marketing simply because another person supplied them for an order.

A recipient can contact gratefulstack@gratefulstack.com to ask about information we hold about them, object to relevant processing, or exercise other applicable data-protection rights. We will consider the circumstances and any legal or operational reasons that affect the request.

Cookies and similar technologies

We may use cookies or similar technologies for sign-in state, security, session continuity, preference storage, analytics, and service performance. Essential technologies are used where needed for the service. Optional analytics stays off unless you choose to allow it, and you can change that choice through Cookie Settings.

Payments and third-party processors

Where payments are offered, payment details may be processed by third-party payment processors rather than stored directly by us in full. We may still receive transaction status, limited billing metadata, customer identifiers, and records needed to reconcile orders, subscriptions, fraud review, or support handling.

We also use service providers for hosting, databases, communications, storage, mapping or location support, and other operational functions. Those providers may process information on our behalf or under their own privacy terms where applicable.

Retention and security

We keep information for as long as reasonably needed for service delivery, account management, order handling, support, fraud prevention, dispute review, operational records, legal compliance, or other legitimate business needs. Retention periods vary by data type and workflow, and some operational records are automatically expired or pseudonymised according to their purpose.

We use technical and organisational measures intended to reduce misuse, loss, and unauthorised access. These include access controls and, for relevant access or tracking credentials, expiry and hashed token storage. No internet-based system can be guaranteed to be completely secure or immune from failure.

Your choices, rights, and contact

Depending on the nature of the data and applicable law, you may have rights to ask for access to your personal data, correction, deletion, restriction, portability, or to object to certain processing. Some rights are subject to legal or operational exceptions.

Customers and recipients can request help with privacy rights or deletion using the contact details below. We may need to verify identity before acting on a request in order to protect customer, recipient, and tribute information.

Privacy questions or requests can be sent to gratefulstack@gratefulstack.com.

We use essential cookies to keep GratefulD secure. Optional analytics helps us understand how the site is used and stays off unless you accept it.