Privacy Policy
Who We Are
Lasting Aftercare provides a managed aftercare communications service to licensed funeral homes. In privacy terms, each funeral home is the data controller for the family information it enrolls; Lasting Aftercare acts as a data processor, handling that information only to deliver the aftercare program on the funeral home's behalf and under its instructions.
Data We Collect
We process information provided by funeral homes at the time of case intake: the deceased's name, date of birth, date of death, and service date; and the primary family contact's name, mailing address, email address, phone number, and relationship to the deceased. We also keep operational records of what the program did (cards scheduled and mailed, opt-outs) so the funeral home can see the care delivered. We do not collect payment information from families, and we never request or store the content of anyone's personal communications.
How We Use It
Data is used solely to deliver the aftercare program on behalf of the enrolling funeral home: scheduling and mailing physical cards, reporting program activity back to the funeral home, and honoring opt-out requests. We do not sell personal information, we do not use it for advertising, and we do not use it to train AI models. Each funeral home's family data is logically isolated and inaccessible to other funeral home accounts.
Service Providers (Subprocessors)
To run the service we share the minimum necessary data with a small set of infrastructure providers acting under contract:
- Amazon Web Services — application hosting and infrastructure (United States).
- Supabase — managed database and authentication (hosted on AWS, United States).
- Cloudflare — DNS, content delivery, and bot protection.
- Print & mail fulfillment partners — recipient name and mailing address only, for the physical production and delivery of cards.
- Google (Places API) — used only to read a funeral home's own public business rating for monthly reports; no family data is ever sent to Google.
We will update this list before adding a new subprocessor that handles family data, and funeral home clients are notified of material changes.
Where Data Lives & How It's Protected
All data is stored in the United States. Data is encrypted in transit (TLS) and at rest. Access is restricted to authorized operators, every funeral home account is tenant-isolated at both the application and database layer, and physical-mail actions are recorded in an append-only audit trail.
Breach Notification
If we become aware of a breach of security affecting personal information, we will notify the affected funeral home(s) without undue delay after confirming the incident, with enough detail for them to meet their own notification obligations.
Data Retention
Family data is retained for the duration of the aftercare program (12 months from intake) plus 30 days. Upon account cancellation, all data is deleted within 30 days (a managed, verified process during the pilot). Funeral homes may request earlier deletion at any time.
Your Rights
Bereaved families may stop all communications at any time by contacting their funeral home or us directly; opt-outs are honored immediately and permanently. Funeral home administrators may request access to, correction of, or deletion of their account data by contacting us. We honor applicable state privacy rights (including deletion and access requests) for all individuals whose data we process.
Contact
For privacy-related questions or requests, contact us at [email protected].