Privacy notice
Some of what you keep here is the most private thing you will ever type into a website. This page says exactly what we hold, why we hold it, who else can see it, and how to make us delete it.
Last updated 20 September 2026
Who is responsible for your data
The data controller is Acorn Reserve Ltd, trading as DeathTree, a company registered in England & Wales under company number 13242218. Registered office: Queen Street Chambers, 68 Queen Street, Sheffield, South Yorkshire, S1 1WR, England.
For anything in this notice — a copy of your data, a correction, a deletion — email privacy@deathtree.co.uk. For everything else, hello@deathtree.co.uk reaches the same small team.
What we collect, and why
We ask for as little as we can. There is no password to store, no marketing list you are added to by default, and no advertising network anywhere on this site.
| What we hold | Why | Lawful basis |
|---|---|---|
| Your email address | To create your account, sign you in with an emailed link, and send order, dispatch and care emails. | Performance of a contract. Legitimate interests for account security. |
| Your name, if you give us one | To address you properly in emails and on your certificate. | Performance of a contract. |
| Order details — the tree, the package, whether you added care, the price you paid, our order number and Stripe’s payment reference | To fulfil your order, answer questions about it later, and keep our accounts. | Performance of a contract. Legal obligation for accounting records. |
| Delivery name, address and postcode | Returned to us by Stripe Checkout so we can send a living tree to the right door. | Performance of a contract. |
| Your tree record — the name you give the tree, any dedication, photographs, heights and growing notes | This is the record you bought. It exists so your tree has a story attached to it. | Performance of a contract. |
| The private location of your tree — the place, the detail, how to get to it, whether it is potted or planted, and the planting date | So you, and one day whoever you choose to tell, can find the tree. Never shown on a public page. | Performance of a contract. |
| Your wishes, and the nominated contact’s name, relationship, email address and your note about them | So your record is complete for whoever eventually reads it. Nothing is ever sent to that person — see below. | Performance of a contract. Explicit consent where you choose to include anything sensitive. |
| Photographs you upload | To build your tree’s timeline. They are stored in a private bucket and served only to you through an authenticated route. | Performance of a contract. |
| A public certificate page, if you switch one on | To let you share your tree. It is off unless you turn it on, and turning it off takes the page down. | Consent, which you can withdraw at any time. |
| Enquiries and Return to Care messages you send us | To answer you, and to quote for managed care where you have asked us to. | Legitimate interests in answering enquiries, and performance of a contract once you order. |
| Sign-in tokens | To let you sign in without a password. Only a SHA-256 hash of the token is stored, and it is single use. | Performance of a contract. Legitimate interests in account security. |
| Rate-limit counters — a hashed key derived from your request, and a count | To stop forms and sign-in being abused by bots. | Legitimate interests in keeping the site working and secure. |
| An action log of administrative changes — who did what, to which order or tree, and when | So a dispatch, refund or correction can be accounted for. | Legitimate interests in accountability. Legal obligation where it concerns an order. |
| Server logs held by Cloudflare — IP address, browser user agent, the page requested and the time | To keep the site available, block attacks and diagnose faults. | Legitimate interests in security and reliability. |
Your card details are never collected by us. They are entered on Stripe’s checkout and held by Stripe, which handles them as a controller in its own right for payment processing, fraud prevention and its own legal duties. We keep only Stripe’s reference for the payment.
More about our lawful bases
- Performance of a contract. Most of what we hold exists because you bought a tree and a record to go with it, and we cannot provide either without it.
- Legitimate interests. Running a small shop safely — stopping bot abuse, keeping logs, being able to account for an administrative change. We have weighed these against your privacy and kept them narrow; you can object at any time.
- Consent. Switching on a public certificate page, and choosing to sign in with Google or Apple instead of an emailed link. Both are yours to withdraw.
- Legal obligation. Keeping order and payment records for the period company and tax law requires.
Your wishes, and the nominated contact
The wishes on your record are the most sensitive content on this platform, and they are stored in a table of their own so that a mistake in one part of the site cannot expose them through another. They are never shown on a public certificate page, never used for marketing, and never sent anywhere.
We never contact a nominated person automatically. There is no code anywhere in this site that emails, writes to or telephones them. There is no death detection and no inactivity trigger: nothing is released because you have not signed in for a while. If someone tells us you have died, a person here handles it by hand, with your family.
We do not ask for health information, religious beliefs or anything else in the special categories of data, and we would rather you did not put more in your wishes than you need to. Where you do choose to include something like that, you are giving us your explicit consent to store it as part of your record, and you can delete it yourself at any time.
A small number of people at DeathTree can reach the database in order to fulfil orders and help you when something goes wrong. Access is limited to what the job needs and administrative actions are logged.
Who else processes your data
These are the only third parties involved, and each one is used for one job:
- Cloudflare — hosting, and the database (D1), file storage (R2) and session store (KV) behind this site. Everything you save here is stored on Cloudflare’s infrastructure.
- Stripe — card payments, the DeathTree Care subscription and refunds. Stripe passes us the delivery address you give it and a payment reference.
- Resend — sending our emails: sign-in links, order confirmations and dispatch notices.
- Google and Apple — only if you choose to sign in with them. They tell us the email address on the account you signed in with. If you use an emailed link instead, neither company is involved at all.
We do not sell or share personal data with anyone else, and we do not use it to train anything.
Analytics, and why there is no cookie banner
We measure how many people visit with Cloudflare Web Analytics. It is cookieless, it sets nothing on your device, it collects no personal data and it cannot follow you across sites. That is exactly why we chose it, and why this site does not need to ask you to accept anything under the Privacy and Electronic Communications Regulations.
At the moment the beacon is not even switched on, so no analytics script loads on this site at all. If we switch it on it will be the cookieless product described above, and this notice will say so.
The two cookies we do set are strictly necessary ones. They are described in the cookie notice.
How long we keep things
- Orders and payment records: six years after the end of the accounting year they fall in, because company and tax law requires us to keep them.
- Your account and tree records: for as long as your account exists. Ask us to delete a tree record and it goes, along with its wishes, updates and photographs. Where an order behind it must be kept for tax, we anonymise the order rather than keep your details in it.
- Photographs: deleted from storage when the update or the record they belong to is deleted. They are not kept in a backup of their own.
- Sign-in tokens: twenty minutes, single use, and only ever stored as a hash. A used or expired token is worthless.
- Rate-limit counters: transient. They exist for the length of the window they are counting and are not a record of you.
- Emails between us: kept while we need them to answer you and for a reasonable period afterwards in case you come back to the same question.
- The administrative action log: kept so a dispatch, refund or correction can still be explained years later.
Your rights
Under the UK GDPR you can ask us to:
- give you access to the personal data we hold about you;
- correct anything inaccurate or incomplete;
- erase your data, which we will do except where we must keep an order record for tax — in that case we anonymise it;
- port your data. You do not have to ask: every tree record has an export button that gives you the whole record as a JSON file;
- restrict what we do with your data while a dispute or a correction is being sorted out;
- object to processing we do on the basis of legitimate interests;
- withdraw consent where consent is the basis — for example by switching a public certificate page back off.
Email privacy@deathtree.co.uk and we will reply within one month. We will only ask you to prove who you are if we genuinely cannot tell, and it costs you nothing.
If we get it wrong, you can complain to the Information Commissioner’s Office at ico.org.uk, or by telephoning their helpline. We would rather you told us first so we can fix it, but you do not have to.
Sending data outside the UK
Cloudflare, Stripe, Resend, Google and Apple are all United States companies with worldwide infrastructure, so your data may be processed outside the UK. Where it is, the transfer relies on the safeguards the UK GDPR requires: the International Data Transfer Addendum to the European Commission’s standard contractual clauses, or the UK extension to the EU–US Data Privacy Framework where the provider is certified under it.
How we keep it safe
- Everything travels over an encrypted connection.
- Photographs live in a private storage bucket with no public address. They are served only through a route that checks you are signed in and that the photograph is yours.
- There is no password to steal. Sign-in tokens are stored as SHA-256 hashes, expire in twenty minutes and work once.
- The session cookie holds nothing but an opaque identifier. It is HttpOnly, so scripts cannot read it, and the session contents stay on the server.
- No card details ever reach our servers.
- Public certificate data and private owner data are kept in separate tables, so a mistake in one cannot leak the other.
- Administrative access is limited to named email addresses and is logged.
Children
This shop is meant for adults. We do not knowingly create accounts for under-18s, and if you tell us we hold a child’s data we will delete it.
Changes to this notice
If what we collect or who processes it changes, we will update this page and the date at the top of it. If a change materially affects you, we will email you rather than hope you notice.