EU-first baseline
OurEchoes.org applies a GDPR-aligned baseline by default. We process personal data only where there is a lawful basis, and we limit collection to what is needed to operate memorial services and moderation.
Data we collect
- account data such as name, email, and authentication identifiers;
- member contributions such as tribute messages, media uploads, and comments;
- operational and security logs, including moderation reason codes and timestamps;
- limited technical diagnostics required for reliability and abuse prevention.
How we use data
We use data to provide memorial pages, enable contribution workflows, maintain platform safety, and enforce policy obligations. Abuse is not tolerated, and account suspension may occur immediately where policy or safety violations are detected.
Cookies and analytics
OurEchoes.org uses two categories of cookies and similar technologies:
- Essential — required for authentication, security, and core memorial site functionality. These are always on and do not require consent.
- Analytics — provided by Google Analytics 4 (loaded through Google Tag Manager) and PostHog. These help us understand aggregated platform usage so we can keep memorial sites running smoothly.
Until you grant analytics consent, OurEchoes.org operates under Google Consent Mode v2 defaults: Google tags fire only as cookieless, redacted pings (no advertising identifiers, URL passthrough only) and PostHog runs with memory-only persistence, no session recording, and no identified profile. The legal basis for these anonymized signals is our legitimate interest in platform reliability and abuse prevention.
After you grant analytics consent, Google Analytics may set its standard cookies (`_ga`, `_ga_*`), PostHog may set its `ph_*` cookies and localStorage entries, and — when you are signed in — we may associate events with your Supabase user id so we can debug issues and analyze feature usage. The legal basis for this identified analytics is your consent.
We do not show advertising on OurEchoes.org. The Marketing category exists only as a future-proof toggle and is off by default.
Manage your cookie choices
You can change your cookie and analytics preferences at any time using the control in the site footer. Withdrawing consent stops further identified collection, opts you out of PostHog capture, and clears stored PostHog identifiers from this browser. Your choice is stored in a first-party cookie (`oe_consent`) for 180 days; we will re-prompt after that window or if our consent model changes.
Retention and access
We retain personal data only for as long as necessary for service delivery, legal compliance, dispute handling, and safeguarding obligations. Access is restricted by role and least-privilege principles. Analytics retention follows the providers' defaults (see Google's and PostHog's policies linked above); we do not extend retention beyond what each provider requires for the service.
Your rights
Depending on location, you may request access, correction, deletion, objection, restriction, and portability of your personal data. You may also request a review of moderation outcomes, and you may withdraw analytics consent at any time via the Cookie preferences control above.
Last updated: 26 April 2026