Privacy Policy

Last Updated: March 13, 2026

1. Introduction

This Privacy Policy explains how we, Heavenly Tribute Private Limited ("we", "us", "our"), collect, use, disclose, store, and protect your personal information when you use our Online Memorial and Obituary Management Platform ("Service", "Platform", or "Website").

We are committed to protecting your privacy and handling your personal information in accordance with:

  • Information Technology Act, 2000
  • Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
  • Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
  • Digital Personal Data Protection Act, 2023 (DPDP Act)

By using our Service, you consent to the collection and use of your information as described in this Privacy Policy. If you do not agree with this policy, please do not use our Service.

2. Information We Collect

2.1 Personal Information You Provide

When you register or use our Service, we collect:

  • Account Information: Name, email address, mobile number
  • Authentication Data: OTP verification data, passwords (for admin accounts, stored encrypted)
  • Memorial Content: Information about deceased individuals including names, dates, photographs, videos, audio recordings
  • Payment Information: Billing details, transaction records (credit card data is processed by third-party payment gateways and not stored by us)
  • Communication Data: Condolence messages, support inquiries, correspondence with us
  • AI-Generated Content: Memorial audio tributes (AI-generated memorial songs) created and stored on your behalf

2.2 Sensitive Personal Data or Information (SPDI)

As defined under Indian law, we may collect and process Sensitive Personal Data or Information including:

  • Financial information (payment and billing data)
  • Photographs and videos
  • Biometric information (if any, through uploaded media)

We handle all SPDI with enhanced security measures and in accordance with applicable legal requirements.

2.3 Information We Collect Automatically

  • Device Information: IP address, browser type, operating system, device identifiers
  • Usage Data: Pages visited, time spent, features used, access times and dates
  • Cookies and Tracking: Session cookies, authentication tokens, analytics data
  • Log Files: Server logs including IP addresses, timestamps, and actions performed

2.4 Information from Third Parties

We may receive information from payment processors, authentication services, and analytics providers to facilitate our Service.

2.5 IP Address Collection for Guest Orders

When you place a guest order for flowers or memorial services on our platform without logging in:

  • IP Address Collection: We collect your IP address at the time of checkout
  • Purposes: Fraud detection, security monitoring, and legal compliance
  • Storage: Your IP address is stored securely alongside your order details
  • Retention: IP addresses are retained for 1 year. After one year, they are anonymized for privacy protection
  • Security: IP addresses are not used for marketing or user tracking purposes

This information is essential for protecting both our platform and our users from fraudulent activity while respecting your privacy.

2.6 IP Address Collection for Abuse Reports

When you submit a report about a memorial page through the "Report this memorial" feature:

  • IP Address Collection: Your IP address is logged at the time of report submission
  • Purposes: Preventing abuse of the reporting system, duplicate report detection, and legal compliance
  • Retention: Retained for 1 year, then anonymized
  • Security: Not used for marketing or general user tracking

3. How We Use Your Information

We use your personal information for the following purposes:

3.1 Service Provision

  • Creating and managing your account
  • Processing OTP authentication for login
  • Hosting and displaying memorial pages
  • Processing payments and managing subscriptions
  • Generating QR codes for memorial sharing
  • Moderating and publishing condolence messages

3.2 Communication

  • Sending service-related notifications (OTPs, payment confirmations, subscription expiry alerts)
  • Sending WhatsApp notifications for condolence approvals, order status updates, and anniversary reminders (where you have provided your WhatsApp-enabled mobile number)
  • Responding to your inquiries and support requests
  • Sending important updates about our Service
  • Marketing communications (with your consent, and with opt-out option)

3.3 AI Content Processing

When you use our AI-powered features (biography generation, AI memorial song creation), the text content you submit (biographical information, memories, achievements) is transmitted to our AI sub-processors for processing:

  • OpenAI (USA): Processes text to generate biographical content and song lyrics
  • Suno API: Processes lyrics and style parameters to generate audio memorial songs

These providers act as data sub-processors bound by data processing agreements. Content submitted for AI generation is not retained by these providers beyond the generation request. Generated content is stored on our platform on your behalf.

3.4 Service Improvement

  • Analyzing usage patterns to improve functionality
  • Conducting research and development
  • Troubleshooting technical issues
  • Enhancing security and fraud prevention

3.5 Legal and Safety

  • Complying with legal obligations and court orders
  • Enforcing our Terms and Conditions
  • Protecting against fraud, security threats, and illegal activities
  • Resolving disputes and enforcing agreements

4. Legal Basis for Processing

We process your personal information based on:

  • Consent: You have given explicit consent for specific purposes
  • Contract Performance: Processing is necessary to fulfill our service agreement with you
  • Legal Obligation: We must process data to comply with Indian laws
  • Legitimate Interest: Processing is necessary for our legitimate business interests (fraud prevention, service improvement)

5. How We Share Your Information

We do not sell your personal information. We may share your information with:

5.1 Service Providers

  • Payment Processors: To process subscription payments securely
  • SMS Gateways: To send OTP authentication codes
  • Cloud Hosting (AWS): To store data, media files, and host the Service (servers in India and USA)
  • OpenAI (USA): AI biography generation and memorial song lyric creation
  • Suno API: AI audio memorial song generation
  • Meta (WhatsApp Business API): WhatsApp notifications for condolence approvals, order updates, and anniversary reminders
  • Cloudflare (Turnstile): Bot detection and form security verification
  • Google (Analytics & Tag Manager): Aggregated website usage analytics and tag management
  • Google Maps: Location display on memorial pages

All service providers are bound by confidentiality agreements and process data only as instructed by us.

5.2 Legal Requirements

We may disclose your information when required by law, court order, or government authority, or when necessary to protect our rights, property, or safety, or that of our users or the public.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.

5.4 Public Memorial Pages

Information you publish on memorial pages (obituary details, photos, condolences) is publicly accessible by anyone with the memorial page link or QR code.

6. Data Storage and Security

6.1 Data Storage Location

Your data is stored on secure servers located in India and/or other countries with adequate data protection standards. We ensure that cross-border data transfers comply with applicable Indian laws.

6.2 Security Measures

We implement reasonable security practices and procedures as required under the IT Act, 2000, including:

  • Encryption of data in transit (SSL/TLS) and at rest
  • Secure authentication mechanisms (OTP, password hashing)
  • Regular security audits and vulnerability assessments
  • Access controls and employee training
  • Backup and disaster recovery procedures
  • Firewall and intrusion detection systems

6.3 Data Retention

We retain your personal information for as long as:

  • Your account is active and subscription is valid
  • Necessary to provide you with our Service
  • Required by law (typically 3-7 years for financial records)
  • Needed for legal claims or dispute resolution

Upon account termination, your access to the Service will cease but data may be retained for legal compliance purposes. Free and Lifelong memorial pages are hosted permanently and do not expire.

7. Your Rights and Choices

Under Indian law, you have the following rights:

7.1 Access and Correction

You have the right to access, review, and update your personal information through your account settings or by contacting us.

7.2 Data Portability

You may request a copy of your personal data in a structured, machine-readable format.

7.3 Withdrawal of Consent

You may withdraw your consent for data processing at any time. However, this may affect your ability to use certain features of the Service.

7.4 Account Deletion

You may request deletion of your account and associated data, subject to our legal retention obligations.

7.5 Marketing Opt-Out

You can opt out of marketing communications by clicking the "unsubscribe" link in emails or contacting us. Service-related communications cannot be opted out of while you use the Service.

7.6 Complaint to Authority

If you believe your privacy rights have been violated, you may file a complaint with the appropriate authority under the IT Act, 2000, or contact our Grievance Officer (details below).

8. Cookies and Tracking Technologies

8.1 Types of Cookies We Use

  • Essential Cookies: Required for authentication and core functionality
  • Performance Cookies: Collect anonymous usage statistics via Google Analytics and Google Tag Manager
  • Functional Cookies: Remember your preferences and settings (e.g., draft obituary data stored in localStorage/IndexedDB)
  • Security Cookies: Cloudflare Turnstile sets a cookie for bot-detection verification on forms

8.2 Managing Cookies

You can control and delete cookies through your browser settings. However, disabling essential cookies may affect the functionality of the Service.

9. Third-Party Links and Services

Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.

10. Children's Privacy

Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a minor without parental consent, we will take steps to delete such information.

11. International Data Transfers

Your information may be transferred to and processed in countries outside India. When we transfer data internationally, we ensure appropriate safeguards are in place, such as:

  • Standard contractual clauses
  • Adequacy decisions by Indian authorities
  • Certification under recognized privacy frameworks

12. Data Breach Notification

In the event of a data breach that compromises your personal information, we will notify you and relevant authorities as required by law, within the timeframe specified under the IT Act, 2000 and applicable rules.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons.

We will notify you of material changes by:

  • Posting a notice on our Website
  • Sending an email to your registered email address
  • Displaying a prominent notification when you log in

Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.

14. Grievance Redressal Officer

In accordance with the Information Technology Act, 2000 and rules made thereunder, we have appointed a Grievance Officer to address your privacy-related concerns:

Grievance Officer Contact Details:

Email: privacy@heavenlytribute.in

Response Time: We will acknowledge your complaint within 24 hours and endeavor to resolve it within 15 days of receipt.

You may contact the Grievance Officer for queries regarding:

  • Access to your personal information
  • Correction or deletion of data
  • Privacy concerns or complaints
  • Data breach notifications
  • Withdrawal of consent

15. Contact Information

For privacy-related inquiries, please contact us:

Company Name: Heavenly Tribute Private Limited

Email: privacy@heavenlytribute.in

Website: https://heavenlytribute.in

Your Consent

BY USING OUR SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ THIS PRIVACY POLICY, UNDERSTAND IT, AND CONSENT TO THE COLLECTION, USE, AND DISCLOSURE OF YOUR PERSONAL INFORMATION AS DESCRIBED HEREIN. IF YOU DO NOT CONSENT, PLEASE DO NOT USE OUR SERVICE.