The current local prototype does not send or save form entries, photos or payment details. The practices below describe the intended production service and are not effective until the missing business, provider, transfer and contact details are completed.
1. Status and scope
This notice is intended to cover the Auromise Pet Sympathy Gifts website, future checkout and secure intake flow, production communications, purchaser delivery and private sharing features at petsympathy.auromise.com.
Intended launch markets: the United States, European Union and United Kingdom. The European Union and United Kingdom are assessed separately for legal, tax and consumer-rights purposes.
The service is designed for a purchaser creating a sympathy gift for a friend, colleague or family member. The finished gift is delivered to the purchaser first. We do not intend to contact the grieving recipient directly unless the recipient independently contacts us.
This notice does not cover a third-party website or service that publishes its own privacy notice, including a payment provider’s hosted checkout.
2. Who is responsible
Auromise Pet Sympathy Gifts is operated by Halo Living LLC, the business intended to be responsible for this service, with a mailing address at 30 N Gould St Ste N, Sheridan, WY 82801, United States.
Privacy contact: [PRIVACY CONTACT EMAIL]. If an EU or UK representative becomes legally required, its identity and contact details must be added here before launch.
3. Information we expect to collect
| Category | Examples | Source |
|---|---|---|
| Purchaser and delivery details | Name, email address and support messages | Purchaser |
| Order and payment references | Selected gift, price/currency shown at checkout, payment status and processor reference; not full card details | Purchaser and payment provider |
| Creative intake | Pet name, type, age, pronouns, personality words, memories, message style and purchaser note | Purchaser |
| Photos and files | One to five pet photos and approved finished derivatives | Purchaser and our production process |
| Consent and operations records | Photo-permission confirmation, imaginative-content acknowledgment, terms acceptance, revision and delivery history | Purchaser and service records |
| Technical and security data | IP address, timestamps, request metadata, limited logs and necessary security identifiers | Browser, host and service providers |
Please do not submit a cause of death, medical or veterinary records, diagnosis details, home address, phone number, government identifier, financial account information, precise location or social-media login. The launch form should be configured to minimize free-text collection.
4. How we intend to use information
We expect to use information to:
- verify payment and provide secure intake access;
- create, human-review, revise and deliver the purchased personalized gift;
- respond to support, refund, access, correction and deletion requests;
- protect the service, prevent misuse and maintain limited operational records;
- meet accounting, legal, dispute and regulatory obligations; and
- use customer work in public examples only after a separate, optional, post-delivery permission.
For people in the EU or UK, the intended legal bases are performance of a contract, compliance with legal obligations, legitimate interests in operating and securing a low-volume service, and consent where consent is legally required. The final purpose-by-purpose lawful-basis assessment must be confirmed during legal review before this notice becomes effective.
Optional marketing and public-example permission must never be bundled into purchase or creative-production consent. A person may withdraw an optional consent prospectively without affecting earlier lawful processing.
5. Pet photos and information about other people
The purchaser must have permission or another lawful basis to provide each photo and any information concerning another person. Only materials reasonably necessary for the gift should be submitted.
Original photos, intake notes and recipient contact information are not intended to appear on a share page. Only a human-approved finished derivative and purchaser-approved text may be made available through a private, revocable link.
We will not use customer photos or stories to advertise the service, publish an example or train a public model unless the purchaser later gives separate, explicit permission for the specific use. A future permission flow must identify what will be published, where and for how long.
6. Service providers, AI tools and transfers
The production service is expected to rely on carefully selected providers for hosting, payment processing, transactional email, private file handling and AI-assisted creative production. Before launch, this section must name or categorize the actual providers, confirm their contractual role and settings, and document where they process data.
Current planned or unresolved provider details:
- hosting and database: Hostinger, subject to final production configuration;
- payment processing: Stripe account and checkout method [FINAL DETAILS PENDING];
- transactional email provider: [PROVIDER PENDING];
- AI-assisted image/video providers and no-training settings: [PROVIDERS AND SETTINGS PENDING];
- international transfer safeguards, where required: [MECHANISM PENDING LEGAL REVIEW].
We do not intend to sell personal information or share it for cross-context behavioral advertising. The current static prototype contains no third-party advertising or analytics tracker. If a production provider can collect personally identifiable information over time and across different websites, or if the response to browser “Do Not Track” or a legally recognized opt-out signal changes, this notice and any required control must be updated before the change.
Information may also be disclosed when reasonably necessary to comply with law, protect rights and safety, investigate fraud or obtain professional legal, accounting or security advice.
7. Retention and deletion
- Original photos: intended to be deleted within 30 days after delivery unless a documented legal or support hold applies.
- Approved finished files: intended to be retained for 90 days after delivery unless support grants a documented extension.
- Private share link: intended to expire after 30 days and may be revoked immediately if exposed or misdirected.
- Incomplete intake: access is intended to expire 14 calendar days after verified payment; the deletion period for any partially submitted information remains a launch blocker.
- Order, payment, consent, tax and security records: [FINAL RETENTION SCHEDULE REQUIRED].
Deletion from backups, provider systems and incident/legal holds must be reconciled in the final retention schedule. We will not describe a file as deleted until the production deletion and recovery process has been tested.
8. Privacy choices and rights
Depending on location and applicable law, a person may have rights to request access, correction, deletion, restriction, objection, portability, information about disclosures, or withdrawal of consent. California residents may also have rights to know, delete, correct, opt out of sale or sharing, limit certain sensitive-information uses and receive non-discriminatory treatment if the law applies to the business.
We intend to offer a practical privacy-request route even where a specific law does not require every listed right. We may need limited information to verify the requester and protect another person’s privacy. Some records may be retained when required for legal, accounting, fraud-prevention or dispute purposes.
Submit a request to [PRIVACY CONTACT EMAIL]. Final response time, identity-verification steps, appeal route and EU/UK supervisory-authority details must be added before launch.
9. Children
The service is intended for adults purchasing a personalized digital gift. It is not directed to children under 13, and we do not intend to knowingly collect personal information from a child under 13. The production terms should require the purchaser to be at least 18 or the age of legal majority where they live.
Do not upload a child’s identifiable image or personal information. If we learn that such information was submitted without an appropriate legal basis, we will take steps to restrict and delete it.
10. Security
The intended safeguards include HTTPS, server-side payment verification, private storage outside the public web root, validated uploads, authenticated encryption for selected intake fields, limited operator access, expiring tokens, human review and scheduled deletion. No method of storage or transmission is completely secure.
These controls were tested only with synthetic data in an isolated runtime. Production secrets, logs, backups, email, Stripe integration and deletion jobs must pass separate review before real photos are accepted.
11. Contact, complaints and changes
Privacy questions and requests: [PRIVACY CONTACT EMAIL]
Mailing address: 30 N Gould St Ste N, Sheridan, WY 82801, United States
Where applicable, a person may also complain to the privacy or data-protection authority in their location. EU/UK authority and representative details must be added if required after the target-market assessment.
When this notice changes, the effective date will be updated and material changes will be communicated as required. An effective notice must accurately match the production providers, forms, cookies, retention jobs and operational practices in use at that time.