Privacy Policy
Last updated: August 27, 2026
1. Information We Collect
Account information. When you create a CemeteryBase account, we collect your name, email address, and cemetery information. New accounts must confirm their email address before accessing the service.
Cemetery records and files. Cemetery staff upload burial, plot, owner, and deed records; custom-field values they define; photographs; private documents (PDFs and images) attached to plots, records, and owners; scanned or photographed ledger pages submitted for AI transcription; and aerial or drone imagery and map files used as map layers. See Sections 2, 3, and 4 for how each is handled.
Information from families and visitors. Searching a public grave search page or viewing a public map requires no account and no personal information. Families provide personal information only when they choose to submit it: a deed request form (name, email, phone, relationship to the deceased), an online plot reservation (name, email, phone), or our contact form (name, email, message). This information is delivered to the cemetery it was submitted to.
Payment information. Payments are processed by Stripe. Card details are handled entirely by Stripe and never touch our servers.
Technical information. We process IP addresses and basic request data for security purposes only — rate limiting, usage quotas, abuse prevention, and bot protection on our signup and contact forms. We do not use this data for advertising or profiling.
2. Cemetery Records & Information About the Deceased
Burial records, deed records, and related documents are uploaded and controlled by each cemetery. The cemetery is responsible for the accuracy of its records and for having the authority to maintain and publish them; CemeteryBase processes this data on the cemetery's behalf.
Records may include information about deceased persons and contact details for next of kin. Next-of-kin names and contact information, owner names, prices, internal notes, custom fields, and attached documents are never shown on public pages — they are visible only to the cemetery's own signed-in staff. If you are a family member with a question about a record, please contact the cemetery that manages it; we will assist where we can.
Cemeteries must not enter health or cause-of-death records, Social Security numbers, payment card numbers, or government ID numbers into the service — in any field, custom field, document, or scan.
3. AI-Assisted Transcription of Scanned Records
Cemetery staff can photograph or scan paper ledgers and have an AI model read them into draft records. This section explains exactly what happens to those pages.
What is sent, and to whom. When a staff member starts a read, the uploaded page images or PDF pages, any layout hint the staff member typed, the cemetery's name, and our extraction instructions are sent from our servers to our AI provider — currently Google LLC, through the Gemini API, processed in the United States. The provider does not receive the staff member's identity, the cemetery's other records, or anything that was not submitted to the feature. Photos are downscaled before sending. Our provider credentials never leave our servers.
No training on your pages. We use the provider's paid API terms, under which the provider states that it does not use submitted content to train or improve its models, does not share it with other customers, and retains it only for a limited period to detect abuse and meet legal obligations. We never use your pages, records, or AI output to train any model of our own.
What comes back and where it goes. The provider returns draft text rows (names, dates, plot references, funeral home, next-of-kin details as written on the page, and a confidence estimate). Those drafts go to a review screen; nothing is saved to the cemetery's records until a staff member reviews and commits them. The uploaded scans themselves are stored in the cemetery's private document storage with its other files, and records created from a scan keep a link back to the source page. Each read is logged in the cemetery's audit trail (who ran it, which document and pages, which model, token counts, and an estimated cost) — the log never contains the page content.
Only if you use it. No other part of CemeteryBase sends data to an AI provider. A cemetery that never uses the scanned-records feature never has any data sent to one. We may change the AI provider or model; the current provider is always listed in the Master Services Agreement's subprocessor schedule, and we give 30 days' notice before changing it.
4. Maps, Aerial Imagery & Location
Base maps. Map tiles, satellite imagery, address search, and static map pictures come from Mapbox. When you view a map, your browser connects to Mapbox directly and Mapbox receives the usual web request data (IP address, browser details, the map area requested); Mapbox's own privacy policy governs that data. Mapbox may also collect anonymous map-usage telemetry from its map library as described in its policy.
Aerial imagery a cemetery supplies. A cemetery may supply its own aerial or drone imagery as a map layer. To display it at full resolution we may host it as a tileset on Mapbox under our account; a reduced-resolution copy may be stored with the cemetery's other files. The cemetery is responsible for having the right to use and publish that imagery and for anything it incidentally depicts. Hosted imagery is removed when the cemetery's account is deleted.
Public burial-location maps. If a cemetery chooses to show plot locations publicly, a visitor who finds a record can see a picture of the grave's position, an interactive map, and a directions link. The location picture is generated by Mapbox from the plot's coordinates and outline — so those coordinates are included in the image request your browser sends to Mapbox. Directions links open Google Maps or Apple Maps under those services' terms. If you tap the “locate me” control on a public map, your device position is used only within your browser to draw a marker; it is never sent to or stored by CemeteryBase. Your browser will ask your permission first, and you can decline.
5. How We Use Your Information
We use your information to:
- Provide and maintain the CemeteryBase service, including storing your records, documents, and imagery
- Transcribe scanned pages you submit to the AI feature, as described in Section 3
- Process plot reservations, deed payments, and subscriptions
- Send transactional emails — account confirmation, password reset, team invitations, deed payment links, and billing notices
- Respond to support requests and perform assisted-setup services you have ordered
- Protect the service against abuse, fraud, and unauthorized access, and enforce usage allowances
- Improve our product using aggregate, non-identifying usage information
We do not sell, rent, or share your personal information with third parties for marketing purposes, we do not send marketing email without your consent, and we do not use your data to train AI models.
6. Data Storage & Security
Your data is stored on Supabase (PostgreSQL) infrastructure hosted in the United States. All data is encrypted in transit (TLS) and at rest. Security measures include:
- Row-level security so each cemetery can only access its own data — including on every new database table by default
- Private storage for documents and scans: no public URLs; staff open files through links that expire within minutes
- AI provider and map-upload credentials held only on our servers, never in the browser
- Mandatory email verification for new accounts
- Optional two-factor authentication (authenticator app) for any user, recommended for administrators
- An audit trail recording who created, changed, or deleted records, plots, deeds, payments, and documents, who exported data, and who ran an AI transcription
- Durable rate limiting, per-user usage quotas, and bot protection on public-facing forms
- Strict browser security headers (HSTS, frame blocking, content security policy)
7. Service Providers
We share data only with the providers required to run the service, each bound by their own privacy commitments and by a data-processing agreement with us:
- Supabase — database, authentication, and file storage, including documents, scans, and images (US)
- Vercel — application hosting and server-side processing (US)
- Stripe — subscription billing and payment processing
- Resend — transactional email delivery
- Cloudflare — bot protection (Turnstile) on signup and contact forms
- Upstash — rate-limiting and quota counters (IP- or user-ID-derived keys only, expiring automatically)
- Mapbox — map tiles, address search, and static map pictures your browser requests directly; hosting of aerial imagery tilesets cemeteries supply (US)
- Google (Gemini API) — reads scanned ledger pages a cemetery chooses to submit to the AI transcription feature; nothing is sent unless that feature is used (US)
The full subprocessor list, with notice and objection rights, is in the Master Services Agreement.
8. Public Grave Search & Public Maps
When a cemetery enables its public page, burial record fields it has marked as public (typically name, dates, and plot location) become accessible to anyone with the cemetery's URL. The cemetery controls which fields are visible through its dashboard settings, and those choices are enforced at the database level — hidden fields are not delivered to visitors at all. Next-of-kin details, owner information, prices, internal notes, custom fields, and private documents are never public.
If the cemetery shows plot locations, visitors can also see where a grave is on a map, browse the cemetery map, and share a link to a plot. The map shows only what the public record already shows; it never reveals owners, prices, or reservation details. A cemetery may also publish a downloadable map file; that file is public for as long as the cemetery keeps it published.
9. Data Ownership, Export & Retention
You own all cemetery records, maps, imagery, documents, and scans you upload to CemeteryBase, and the records you create from AI transcription. You may export your data at any time: individual lists as CSV, or everything as a single archive (CSV, GeoJSON, settings, and a manifest of your documents). If you cancel your subscription, you have 30 days to export your data before it — including documents, scans, imagery, and any tileset hosted for you on Mapbox — is permanently deleted. Content already processed by the AI provider is subject to that provider's short abuse-monitoring retention and is not retrievable by us. Security and audit logs are retained for a limited period for fraud prevention and then deleted.
10. Cookies
We use essential cookies for authentication and session management. The Cloudflare Turnstile bot check on our signup and contact forms may set a temporary cookie strictly to distinguish humans from bots. We do not use tracking cookies or third-party advertising cookies.
11. Your Rights
You may request access to, correction of, or deletion of your personal information by emailing us. Cemetery staff can manage their own account and enable two-factor authentication from dashboard settings. Family members whose information appears in a cemetery's records — including in a scanned ledger page — should contact that cemetery first, as the cemetery controls its records; we will support the cemetery in fulfilling such requests.
12. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any material changes via email or through the application, and we give 30 days' notice before adding or changing a provider that processes your records.
13. Contact
CemeteryBase is operated by PRAAM Enterprise LLC, a Montana limited liability company, in the United States. If you have questions about this privacy policy, contact us at support@cemeterybase.com or visit our Contact page.
The full contract governing use of the service, including our Data Processing Addendum and the list of subprocessors, is the Master Services Agreement.