On its way to us
Every page of PartingWishes.com is served over an authenticated, encrypted connection using 256-bit Transport Layer Security, so anything sent from your computer is unintelligible to anyone who intercepts it. Your browser shows a padlock beside the address whenever that connection is in place, which is your own way of checking rather than ours.
Once it is here
Sensitive personal information is encrypted before it is written to our servers, and those servers are in Canada. Only you, and anyone you have expressly authorised, can reach what you have entered.
Our support team ask your permission before opening your account, and only to help with something you have raised. Every time they do is recorded, you can read that record on My security, and you can withdraw the permission at any time.
Some things can only be done with your information decrypted, for as long as it takes to do them. Publishing a memorial is the clearest example: what you wrote is decrypted so that it can be shown on the page you asked us to publish.
Signing in
We offer two-factor authentication and we recommend turning it on. It asks for one more thing beyond your UserID and password, something only you have, such as your phone or your own email address, so knowing your password is no longer enough to get in.
Every attempt to sign in to an account, successful or not, is recorded with its date, time, and the address it came from. We keep those records and use them to look into anything that seems wrong, and to protect the accounts of the people it was aimed at.
If you think someone has been in your account, tell us and change your password. Turning on two-step sign-in is the strongest thing you can do yourself, and you can do it now on My security: it means your password on its own stops being enough to get in.
Paying
We do not hold your card. Payments go through a specialist payment provider, and the card details you type are used for that payment and reach neither our website, our databases, nor our servers.
Keeping it running
Every server is backed up daily, so a failure on any one of them does not put your information at risk. Our database is scanned weekly and our web servers monthly, so that a vulnerability found anywhere in the world is one we have already looked for here.
The people behind it
The most important part of any service is the team running it. Ours is employed, in-house, and local. We use no temporary staff, nothing is outsourced or offshore, and every line of this website was written by the people who look after it.