Privacy Policy
Last updated: May 2026
1. Data Controller
Armin GallikerSchürmatte 15
6027 Römerswil
Switzerland
info@lastpizza.com
2. What Data We Collect
When you create a pet memorial, we collect the information you enter into the form:
- Your pet's name, birth date, and date of passing (required)
- A photo — either selected from our curated library or uploaded by you
- Optional: condolence address
- Your email address (optional) — only if you choose to provide it, to send you an admin link for managing your memorial or to verify your identity for photo uploads
We do not use tracking cookies, analytics tools, or third-party advertising services.
3. Photo Uploads
If you upload your own photo, your email address is verified first to help keep the platform safe. Uploaded photos are:
- Stored privately in AWS S3 (Frankfurt, Germany) until reviewed
- Reviewed by the operator before being displayed publicly
- Rejected photos are deleted from our storage immediately
- If a photo is reported by users and reviewed, it may be removed at the operator's discretion
4. How We Use Your Data
- To create and display the memorial you submitted
- To send an admin link to your email so you can manage your memorial (only if you provided an email)
- To verify your email before allowing photo uploads
- To count how many times a memorial has been viewed (aggregated counter only — no personal data is stored for this)
5. Legal Basis
Processing is based on Art. 6(1)(b) GDPR (performance of a service you requested) and Art. 6(1)(f) GDPR (our legitimate interest in operating the service and keeping it safe). For Swiss users, the applicable law is the Swiss Federal Act on Data Protection (nDSG).
6. Data Retention
Memorials and all associated data are retained for 6 months from the date of creation, after which they are permanently deleted. You can delete your memorial at any time using the admin link sent to your email address.
7. Data Processors
Your data is stored on servers operated by Amazon Web Services (AWS) in the EU (Frankfurt, Germany, eu-central-1 region). AWS acts as a data processor under a data processing agreement and complies with GDPR. No data is transferred outside the EU/EEA. AWS services used: DynamoDB (data storage), S3 (photo storage), and SES (email delivery).
8. Cookies and Browser Storage
No tracking or analytics cookies are used on this website.
Session storage (view deduplication): To prevent your view from being counted more than once, a temporary session identifier is stored in your browser's sessionStorage. This identifier is never transmitted to us and is automatically cleared when you close the browser tab. This is not a cookie.
Admin session cookie: If you access the admin dashboard, a functional HTTP-only cookie is set for the duration of your admin session (valid for 24 hours). This cookie is strictly necessary for the admin function to work and does not require your consent under applicable law.
9. Your Rights
Under the GDPR and Swiss nDSG you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Restrict or object to processing
- Data portability
To exercise these rights, contact us at info@lastpizza.com. To delete a memorial directly, use the admin link sent to your email.
10. Supervisory Authority
You have the right to lodge a complaint with your local data protection authority. In Switzerland: Federal Data Protection and Information Commissioner (FDPIC), www.edoeb.admin.ch. In the EU, contact your national data protection authority.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, request deletion, and opt out of the sale of your data. We do not sell or share personal data with third parties for commercial purposes. To exercise your rights, contact us at info@lastpizza.com.
12. Changes to This Policy
We may update this privacy policy from time to time. The current version is always available on this page.