Privacy Policy
1. Introduction
This Privacy Policy explains how we collect, use, store, disclose, and protect your personal information when you use the Letter of Wishes website and related services at letterofwishes.app (the “Service”). The Service is operated by Ryan McMillan trading as “Exactly That” (ABN 25 733 940 257) (“we”, “us”, “our”). We are the data controller responsible for your personal information.
The Service is available internationally. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (“APPs”) and, where they apply to you, the UK and EU General Data Protection Regulation (“UK GDPR” and “EU GDPR”), the Data Protection Act 2018 (UK), and other data protection laws that apply to our handling of your personal information.
2. The information we collect
Depending on how you use the Service, we may collect:
- Account information: your name and email address, and authentication identifiers.
- The content of your letter of wishes: this is highly personal information that you choose to enter, and may include your funeral and memorial preferences, the reasons behind your decisions, the location of your Will and the identity of your executors, guidance about your online accounts and subscriptions, details about your pets, messages to specific people, practical and household details, and any other wishes you record.
- Information about other people: the names and contact details of people you include, such as family members, intended recipients, executors, carers, and other contacts.
- Payment information: where you make a payment, it is collected and processed by Stripe. We do not collect or store your full card details.
- Contact information: if you contact us, the content of your message and your email address.
- Technical and usage information: such as device and browser type, IP address, pages viewed, and interactions with the Service, collected through analytics and similar technologies.
3. Sensitive and special category information; your responsibilities
The content of a letter of wishes is inherently personal, and may include information treated as “sensitive information” under Australian law or “special category data” under the GDPR, such as your religious or philosophical beliefs (for example, your funeral or service preferences) and information about health. We do not ask you for this information directly; you provide it only if you choose to include it in your letter. Where the law that applies to you requires it, we rely on your explicit consent to process the sensitive information you choose to provide, for the sole purpose of providing the Service to you. You can withdraw that consent at any time by deleting the relevant content or your account, although this will not affect processing carried out before withdrawal.
You must not enter passwords, PINs, full financial account numbers, or similar credentials into the Service. Where you provide information about other people, you are responsible for ensuring you are entitled to do so.
4. How we collect information
We collect information directly from you when you use the Service, create or use an account, enter content, make a payment, or contact us, and automatically through cookies and analytics when you interact with the Service.
5. How we use information
We use personal information to:
- provide, operate, and maintain the Service;
- create and manage your account and authenticate you;
- save and export your letter of wishes;
- process payments;
- provide support and respond to your enquiries;
- send you communications about the Service and, only where you have consented or we are otherwise permitted by law, occasional updates (you can opt out of non-essential communications at any time);
- understand and improve the Service;
- protect the security and integrity of the Service and prevent misuse; and
- comply with our legal and regulatory obligations.
6. We do not sell your information
We do not sell your personal information to third parties.
7. Lawful bases (where the GDPR applies)
Where the GDPR applies to you, we process personal data on one or more of these bases: performance of a contract with you; our legitimate interests in operating and improving the Service; compliance with legal obligations; and your consent, where required (including in relation to the sensitive nature of your content and to non-essential analytics cookies).
8. Cookies and analytics
We use cookies and similar technologies, including Google Analytics, to understand how the Service is used and to improve it. Google Analytics may set cookies and collect information such as your IP address and usage data, which is processed by Google under its own policies.
Some cookies are strictly necessary for the Service to function (for example, to keep you signed in or to remember your progress). You can control or block cookies through your browser settings, and you can opt out of Google Analytics using Google’s opt-out browser add-on.
Where the law that applies to you requires prior consent for non-essential cookies (such as in the UK and EU), we will obtain that consent, or will not set such cookies for you, before doing so.
9. Data storage, hosting, and international transfers
We store and process personal information using third-party infrastructure, including Supabase (authentication, database, and file storage) and its underlying cloud hosting, Stripe (payments), Google (analytics), and our contact-form provider. Some content may also be stored locally in your browser on your device.
These providers, and therefore your information, may be located or processed outside your country, including in Australia, the United States, and elsewhere, in countries whose data protection laws may differ from your own.
Where we transfer personal information overseas, we take reasonable steps to ensure it remains protected in accordance with the privacy laws that apply to us. Where the UK or EU GDPR applies and we transfer personal data to a country not recognised as providing an adequate level of protection, we will put in place an appropriate safeguard, such as standard contractual clauses, where one is required.
We recommend that you export and safely store a copy of your completed letter rather than relying solely on continued access to the Service.
10. Third-party services
The Service relies on third parties including Supabase, Stripe, Google, and our contact-form provider, each of which operates under its own privacy policy. We are not responsible for the privacy practices of third parties, but we take reasonable steps to use reputable providers.
11. Data retention
We retain personal information only for as long as reasonably necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. When information is no longer required, we take reasonable steps to delete or de-identify it.
12. Security and data breaches
We take reasonable technical and organisational measures to protect personal information. However, no method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.
Where a data breach occurs that is likely to result in serious harm or risk to your rights, we will notify affected individuals and the relevant regulator as required by law, including under the Notifiable Data Breaches scheme in the Privacy Act 1988 (Cth) and, where the GDPR applies, the breach-notification requirements of the UK and EU GDPR.
13. Your rights
Subject to the law that applies to you, you may request access to, or correction of, the personal information we hold about you, and you may ask us to delete it. Where the UK or EU GDPR applies, you also have rights to rectification, erasure, to restrict or object to processing, to data portability, and to withdraw consent at any time (without affecting processing carried out before withdrawal). We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
To make a request, contact us through our contact page. We may need to verify your identity before actioning a request, and we will respond within the time required by applicable law.
14. Account deletion
You may request deletion of your account and associated data by contacting us. Deletion is permanent and irreversible. Some information may remain in backups, logs, or where retention is required by law or for legitimate business purposes, for a limited period.
15. Children’s privacy
The Service is intended for people aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take reasonable steps to delete it.
16. International users
If you access the Service from outside Australia, you acknowledge and agree that your personal information will be transferred to, stored, and processed in Australia and other jurisdictions, which may have different data protection laws to your own.
17. Complaints
If you have a concern or complaint about how we handle your personal information, please contact us first so we can try to resolve it. You may also lodge a complaint with your local data protection authority. In Australia, this is the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. In the United Kingdom, this is the Information Commissioner’s Office (ICO) at ico.org.uk. In the EU, you may contact the supervisory authority in your country.
18. Changes to this Policy
We may update this Privacy Policy from time to time. Changes take effect when published on the Service. Your continued use of the Service after changes are published constitutes acceptance of the updated Policy.
19. Contact
You can contact us about privacy through our contact page.