Privacy notice
Last updated September 20, 2026
This notice explains what Forever a Star does with personal data, and what you can do about it. It covers the website and the iOS app.
Who runs this site
Forever a Star is operated by Namic BV, a company registered in Belgium with its registered office in Bierbeek, enterprise number KBO 0824.010.149, VAT BE0824.010.149. We are the data controller for everything described here. You can reach us at [email protected].
What we collect
To create an account we need, and require:
- your email address — to verify the account and to send you password resets;
- a password, which we store only as a hash and never in a readable form;
- a display name, and a username we generate from it — both shown publicly on memorials you create.
- your confirmation that you are at least 16. Creating an account is that confirmation, as the line beside every sign-up button says; we do not ask for your date of birth.
You may optionally add a profile photo. It is not needed to use the site, and you can remove it at any time from your account settings.
We also record the country your account was created in, worked out from your IP address at the moment you signed up. We do not ask you for it and you cannot change it. It is a country and nothing finer — never a city, never an address — and the IP address itself is not kept for this. It is shown to you in your own settings and to our moderators, who use it to spot a run of abuse coming from one place. It is not shown to other visitors.
When you use the site we also store:
- the memorials you create — the pet's name, dates, species and breed, your description and any photo you upload;
- guestbook messages you write and the memorials you have hearted;
- reports you file about other people's content, and blocks you place on other users;
- ordinary server logs (IP address, browser, requested page) that every web server keeps, used to keep the site running and to spot abuse.
Why, and on what legal basis
- To give you an account and show your memorials — necessary to perform our agreement with you (Art. 6(1)(b)).
- Your profile photo — your consent (Art. 6(1)(a)), which you withdraw by removing it.
- The country your account was created in — our legitimate interest (Art. 6(1)(f)) in being able to see where abuse comes from. You did not choose to give it, which is exactly why it is not published to anyone else, and why we keep only the country.
- Moderation, rate limiting and abuse prevention — our legitimate interest in a site that is safe to use (Art. 6(1)(f)).
- Verification and password-reset emails — necessary to perform our agreement with you. We do not send marketing email.
How long we keep it
- Your account and its content stay until you delete them.
- When you ask us to delete your account it is deactivated immediately and permanently erased after 30 days. During that window you can still change your mind; after it, the data is gone and cannot be restored. Your name is replaced with "a former member" everywhere it appeared, from the moment you ask, not at the end of the window.
- You choose at that point whether your memorials and guestbook messages are deleted with the account or left in place under "a former member".
- Email verification and password-reset links expire, and expired ones are deleted automatically.
- Reports about content are kept even after that content is removed, so that a moderation decision cannot be erased by deleting what it was about.
- Server logs, including IP addresses, are kept for 30 days.
Cookies
We set four cookies. Each one does something you asked for, which is why you are not being asked to consent to them:
- A session cookie that keeps you signed in. It lasts for 30 minutes of inactivity, or for 30 days if you ticked “Remember me” when signing in.
- A token (XSRF-TOKEN) that protects forms and buttons against cross-site request forgery.
- A language cookie (fas_lang), kept for one year, that remembers the language you chose so the site opens in it next time.
- A short-lived cookie (fas_google_nonce), set only while you sign in with Google, that ties that sign-in to the browser that started it. It is removed as soon as the sign-in ends.
There is no analytics, no advertising, and no third-party tracker on this site. Our fonts are served from our own servers rather than from Google, so loading a page does not tell anyone else that you visited.
Who else sees your data
- Our hosting provider, DigitalOcean, which operates the servers your requests reach and the storage that holds the photographs you upload.
- Cloudflare, which sits in front of our servers, so every request to the site passes through it, and which also delivers our email (with Resend as a fall-back). As email provider it receives your address solely to deliver the mail we send you, such as verification and password-reset mail.
- Google, only if you choose to sign in with Google. The sign-in button is loaded from Google on the sign-in and registration pages alone; Google then tells us your email address and name, and learns that you signed in here. If you never open those pages, nothing is loaded from Google.
- Stripe, only if you pay for premium. The sale is made by Stripe as merchant of record, on Stripe’s own pages: Stripe collects your name, email address, billing address and card details itself, and they never reach us. We receive a reference to the payment and the memorial it was for. Stripe sends you the receipt and the invoice and handles refund requests, under its own privacy policy.
- Apple (Apple Distribution International Ltd., Ireland), only if you buy premium in the iOS app. Apple takes the payment in its App Store under its own privacy policy; your payment details never reach us. We receive a reference to the purchase and the memorial it was for.
DigitalOcean, Cloudflare and Resend act on our instructions only, and we do not sell personal data; Google handles the sign-in, and Stripe the payment, under their own privacy policies. All of them are US-headquartered, so some processing may happen outside the EEA; where it does we rely on the European Commission's Standard Contractual Clauses, which each of them incorporates into its data processing agreement. All of them are also certified under the EU-US Data Privacy Framework, but the Clauses stand on their own and do not depend on that certification staying in force.
Anything you publish — a memorial, a guestbook message, your display name and username — is visible to anyone who visits the site, including people who are not signed in.
Your rights
You can ask us for a copy of your data, correct it, delete it, restrict or object to how we use it, or receive it in a portable form. Deleting your account is self-service in your settings; for anything else, email [email protected] and we will answer within one month.
If you think we have handled your data badly, you can complain to the Belgian data protection authority: Gegevensbeschermingsautoriteit / Autorité de protection des données, Drukpersstraat 35, 1000 Brussels, gegevensbeschermingsautoriteit.be.
Children
Forever a Star is not intended for children under 16. If you believe a child has created an account, tell us and we will remove it.
Changes
If we change this notice we will update the date at the top, and tell you directly if the change materially affects you.