Everything a bridal appointment inquiry sends us, and how long we keep it.
SPINA Bride is a bridal shop in NYC. The only data we hold about you comes from the inquiry form, the salon chat, the server logs and the advertising click that brought you here. This notice says what each of those is, who else touches it, and how to have it erased.
This notice takes effect on 30 September 2026
That is the date this version replaced the one before it. Where a date matters in a dispute, it is that one. If you sent an inquiry earlier than that date, the retention periods below still apply to it, because they describe what the database does rather than what was promised at the time.
We do not version this document behind a login or keep a private changelog. The date sits at the top of the page and in the panel beside the headline.
Who is responsible for the data
Spinabride, trading at spinabride.us, decides what is collected here and why. In the language of the GDPR that makes us the controller; under US state law it makes us the business.
The postal address in full: 132 10th Ave, New York, New York 10011, United States. Phone +1 646-630-7052. Email [email protected]. The stylists who run the floor answer the mailbox. There is no separate privacy department and no ticket queue.
Governing law is the law of New York, United States, and disputes are heard in the courts of New York.
Not a site for children
Bridal appointments are a contract, and the site is written for adults booking one. We do not knowingly take data from anyone under 16, we have no feature aimed at children, and nothing here is advertised to them. If a child has sent us an inquiry, write to [email protected] and we delete the record on sight rather than asking for proof first.
How a change gets announced
When this notice changes, the effective date at the top changes with it and the old text is replaced outright. Small edits, a corrected typo or a renamed processor, go up without further noise. A change that widens what we collect or who receives it gets a plain line at the top of this page for 30 days, and anyone with an open inquiry in the system hears about it by email at the address they gave us.
We will not quietly extend a retention period. If 24 months becomes something longer, that is the kind of change that gets the notice at the top.
Reaching a person about this
Email [email protected] with "privacy" anywhere in the subject line and a stylist reads it the same day the salon is open. Phone +1 646-630-7052 during appointment hours if you would rather say it out loud, though anything that changes a record has to be confirmed in writing so there is something to point at later.
Post reaches us at 132 10th Ave, New York, New York 10011, United States. Mark the envelope for the attention of the salon manager.
Every category of data this site takes
Four sources, and no fifth. The inquiry form, the salon chat, the web server, and the advertising click that carried you in.
The inquiry form
When you send the appointment request from the contact page or the home page, tevu84d.php writes your name, phone number, email address, the address or city you typed, the kind of inquiry you picked, your message, the specification you asked for, and the fact that you ticked the consent box. Two hidden fields travel with it: the moment the page was rendered and two unlabelled decoy fields that only automated submitters fill in. If a decoy comes back filled, the message is discarded without being read.
Automatically alongside it: your IP address, the browser's user-agent string, the referring URL, the moment the form was rendered and the moment it was sent. Those five exist to tell a real bride from a script.
The salon chat
feke9e0.php keeps the conversation you have with a stylist and a token in your own browser so that reopening the widget shows the same thread instead of starting a blank one. If you type a name, a phone number or an email into the chat intro, those sit with the transcript. Nothing in the chat is analysed by a machine for profiling. A person reads it and answers.
Technical and log data
The web server records requests in the ordinary way: IP address, timestamp, the file requested, the response code, the user-agent, the referrer. That log is how a broken image or a flood of junk traffic gets found.
Cookie identifiers and click identifiers
Your consent choice is stored in your browser under site_consent_v2. That key, and the chat token, are the only things this site persists on your device by its own hand. The advertising click identifiers, gclid, msclkid and fbclid, arrive on the end of the link when you come from an ad. The cookie notice lists every key with its lifetime.
No account, no password, no payment and no card data. Nothing is sold on this site and no payment is taken here. A gown is ordered in the salon, in person, and the money side of it never touches this website.
What each category is used for
Inquiry data exists so a stylist can call you back and hold a 90-minute slot with your name on it. The address or city tells us whether you are flying in, which changes how we schedule fittings. The specification field tells the stylist which samples to pull off the rail before you arrive, so the hour is not spent hunting.
Chat transcripts exist so the next person to pick up the conversation does not make you repeat the silhouette, the date and the budget you already gave. They are also how we settle a disagreement about what was said.
Server logs exist for security and for keeping the site up. They are read when something breaks, not browsed for interest.
Advertising data exists to tell whether a click that cost money produced an appointment request. That is measurement, and with your permission it is also how the ad platforms are told which campaign worked. Decline, and the measurement stops at counting page views on our own server.
| Category | Used for |
|---|---|
| Inquiry form fields | Answering you, booking the appointment, preparing the rail |
| Form metadata (IP, user-agent, timestamps) | Spam defence and proof of when a request arrived |
| Chat transcript and token | Continuing the same conversation, resolving disputes |
| Server logs | Security, fault-finding, keeping the site online |
| Consent record | Proving what you chose and honouring it on the next visit |
| Click identifiers | Attributing an inquiry to the ad that produced it |
The legal basis under each purpose
Said plainly, one purpose at a time, because "we process data lawfully" is not an answer.
- Answering an inquiry and arranging an appointment — steps taken at your request before a contract, and performance of that contract once a gown is ordered. GDPR Article 6(1)(b).
- The consent tick on the form — consent, Article 6(1)(a). It is the permission to reply by phone and email, and you can withdraw it by saying so.
- Spam defence, security and server logs — legitimate interest, Article 6(1)(f). Our interest is a working site and a mailbox that is not full of junk; the data used is the minimum that achieves it.
- Advertising and measurement cookies, and the consent signals sent to the platforms — consent, Article 6(1)(a), given through the banner and revocable in the same place.
- Keeping a record of what you consented to — legal obligation and legitimate interest together. Without the record we cannot show we honoured the choice.
Where consent is the basis, nothing fires before you give it and withdrawal takes effect on the next page load. Where legitimate interest is the basis, you can object and we will weigh it; a log line that keeps the site up is a harder objection to win than an analytics count, and we will say which we think it is.
How the data is protected
The site is served over HTTPS only; a plain HTTP request is redirected before anything is sent. The inquiry database sits on the hosting provider's server behind a password that is not reused anywhere else, and the operator's mailbox is protected by two-factor authentication.
Access is limited to the people who run the salon. There is no shared login, no exported spreadsheet of inquiries passed around, and no copy of the database on a laptop. Transcripts and inquiries are deleted by an automatic job when they reach the ages listed under retention, not when somebody remembers.
We will not pretend a small salon's website is impregnable. If a breach happens that puts you at risk, you hear about it from us by email at the address you gave, and the relevant authority hears about it within 72 hours.
Paid clicks bring people to this bridal shop in NYC
Google Ads and Microsoft Advertising run traffic to spinabride.us today, and Meta Ads may send visitors from Facebook and Instagram as well. Many of the people searching "wedding dresses new york" or "bridal boutique chelsea" arrive here through one of those ads. That is how a small salon gets found next to the department-store names.
Each platform attaches its own click identifier to the link it sends you through:
gclid— Google Ads. Sometimeswbraidorgbraidinstead, on iOS app traffic.msclkid— Microsoft Advertising, which covers Bing search results.fbclid— Meta Ads, on Facebook and Instagram placements.
Those parameters sit in the page URL when you land. They are what lets a platform match "somebody clicked this ad" to "somebody asked for an appointment", without anyone sending your name across. Strip them out of the address bar if you prefer; the site works identically without them and the form still sends.
No platform has reviewed, approved or verified this site or the gowns on it, and nothing here should be read as saying otherwise. They sell us clicks. That is the whole relationship.
Consent Mode v2, and what is denied before you choose
This site runs Google Consent Mode v2. On the first page load, before the banner is touched, all four signals are held denied:
ad_storage— deniedad_user_data— deniedad_personalization— deniedanalytics_storage— denied
In that state no advertising or analytics cookie is written on your device. Tags that load at all load in a cookieless mode which sends an anonymous, aggregated ping and nothing that identifies you.
Press Allow on the banner and all four are updated to granted, in that moment, and the advertising tags begin storing and reading their own identifiers. Press Decline, or press Allow today and withdraw tomorrow through Cookie settings in the footer, and all four are set back to denied the moment you do it. Withdrawal is not a request we process at our leisure. It is a state change in your browser on the next page load.
Your choice lives in your browser under site_consent_v2 and nowhere else on this site. Clear your browser storage and the banner asks again, because the record of the answer went with it.
Global Privacy Control is honoured
If your browser or extension sends the Global Privacy Control signal — the Sec-GPC header — this site reads it as a valid opt-out of the sale or sharing of personal information and of targeted advertising. The four Consent Mode signals stay denied, the banner does not nag you for a different answer, and no advertising identifier is written.
You do not have to tell us separately, and we do not ask you to confirm it in a second dialogue. The signal is the instruction.
What we do not do with advertising data
We build no audience list from the people who fill in the inquiry form. We do not upload your email address or phone number to any platform for customer matching. We do not run a retargeting pixel that follows you around other websites with a gown you looked at for nine seconds. The only thing the platforms get back from us, with your permission, is the fact that a click turned into an inquiry.
The full cookie and storage inventory, with lifetimes, is in the cookie notice.
Who else touches this data, named
Four kinds of recipient, and we can name each one rather than writing "trusted partners".
- Google Ireland Ltd / Google LLC — Google Ads. It attaches
gclidto a click and receives the Consent Mode signals described above. With your permission it also receives the fact that a conversion happened. - Microsoft Ireland Operations Ltd — Microsoft Advertising, which attaches
msclkid. Its own handling of what it collects is covered by the Microsoft privacy statement at privacy.microsoft.com/privacystatement. - Meta Platforms Ireland Ltd — Meta Ads, which attaches
fbclid, where a campaign is running there. - The hosting provider that serves this site and stores the inquiry database, and the mail provider that carries the notification into the operator's inbox. Both act on our instructions under a written processing agreement and neither uses the data for anything of their own.
Nobody else. We do not sell inquiry data, we do not swap bride lists with photographers, florists or planners, and we do not pass your number to a designer. If a designer needs your measurements to cut a gown, we send the measurements with your first name and nothing else, after you have ordered.
Data can also be disclosed where a court, a regulator or law enforcement compels it, or where it is needed to establish or defend a legal claim. That is the only other route out.
Data that leaves the country it was collected in
The salon is in New York and the hosting sits in the United States, so for a visitor in the US nothing crosses a border. Inquiries from Europe or the United Kingdom are transferred to the United States when they reach our server, because that is where the database lives.
Those transfers rest on the European Commission's Standard Contractual Clauses with our hosting and mail providers, and on the EU–US Data Privacy Framework where the recipient is certified under it. Google, Microsoft and Meta each contract on Standard Contractual Clauses for the personal data they receive as processors, and each publishes its own transfer documentation.
If you are ordering a gown from a European atelier, the measurement sheet goes to that atelier in the country it cuts in. You are told which country before the order is placed, because the answer is on the order form you sign.
How long each thing is kept
Real periods, counted from the last entry in the record, run by an automatic job.
| What | Kept for | Then |
|---|---|---|
| Inquiries and the email copies of them | 24 months | Deleted from the database and the mailbox |
| Chat transcripts | 6 months | Deleted, token invalidated |
| Server and access logs | 90 days | Rotated and overwritten |
| The record of a consent choice | 12 months | Expires; the banner asks again |
| A data request and our answer to it | 24 months | Deleted |
Two exceptions worth naming. An order file — measurements, the designer, the dates — is kept while the gown is being made and for as long as the sales record has to exist for tax and accounting purposes under New York and federal rules. And anything caught in a live legal claim is held until the claim is closed, however old it is.
Ask for deletion earlier and you get it, unless one of those two exceptions applies, in which case we tell you which one and when it lapses.
If you reach us from Europe: your GDPR rights
These sections are written for visitors in the European Economic Area and the United Kingdom, and we honour them wherever you are, because running two standards is more work than running one. Under the GDPR you have the right to:
- Access — get a copy of the personal data we hold about you, with an explanation of where it came from.
- Rectification — have something wrong corrected. A misspelt name on an order is worth fixing before the gown is cut.
- Erasure — have it deleted, subject to the two exceptions named under retention.
- Restriction — have us stop using it while a dispute about its accuracy or our basis is sorted out.
- Portability — receive what you gave us in a machine-readable file, or have it sent to somebody else.
- Objection — object to anything we do on legitimate interest, including spam scoring and analytics.
- Withdrawing consent — at any time, without giving a reason. Withdrawal does not undo what was lawful before you withdrew.
None of these costs anything. We do not charge a fee for the first request, and a repeat request is only refused if it is plainly excessive, in which case we say so in writing rather than going quiet.
If you are in the United States: state privacy rights
California residents have rights under the CCPA as amended by the CPRA: to know what categories of personal information we collect and why, to a copy of it, to have it deleted, to have it corrected, and to limit the use of sensitive personal information. We do not collect sensitive personal information as that law defines it — no government identifiers, no health data, no precise geolocation, no card numbers.
You also have the right to opt out of the sale or sharing of personal information, where "sharing" means cross-context behavioural advertising. We do not sell personal information for money. Where advertising cookies are allowed, the data flow to Google, Microsoft or Meta can meet the legal definition of sharing, so we treat it as such: decline the banner, use Cookie settings in the footer, or send Global Privacy Control, and the sharing stops.
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and the other states with a privacy law in force have equivalent rights of access, correction, deletion and opt-out, and the right to appeal a refusal. Appeal by replying to our answer with the word "appeal"; a different person reviews it and answers within 45 days.
We do not discriminate against anyone who exercises a privacy right. The appointment is the same appointment, at the same price basis, whether or not you allowed a cookie.
Complaining about how we handled it
Tell us first if you can bear to. It is quicker and we would rather fix it than read about it from a regulator.
If that gets you nowhere, you may complain to your state Attorney General. California residents may also complain to the California Privacy Protection Agency. Visitors from the European Economic Area or the United Kingdom may complain to the supervisory authority in the country where they live or work, or where they believe the problem happened.
You do not need our permission to do any of that and you do not have to tell us you have done it.
How to ask for your data, and what happens next
One route, no form to fill in and no portal to register for. Email [email protected] with "data request" in the subject, or write to Spinabride, 132 10th Ave, New York, New York 10011, United States.
Say which you want: a copy, a correction, deletion, a portable file, restriction, an objection, or an opt-out of sharing. Give the email address or phone number you used when you contacted us, because that is the key the records are found under. If you booked an appointment, the date helps.
We answer within 10 days. Not "within a month as permitted" — 10 days, counted from the day the message lands. If the request is genuinely complicated and needs longer, you hear that inside the same 10 days, with a reason and a date.
Identity check: we match what you send against what is in the record. If the two do not line up, we ask one narrow question whose answer only you would know, usually about the inquiry itself. We will not ask for a scan of a passport or a driving licence to release an inquiry form, and you should be suspicious of anyone who does.
An authorised agent may act for you with written permission signed by you; we will still confirm directly with you before releasing anything.
What you get back for an access request: the inquiry records with every field, the chat transcripts still inside the 6-month window, the consent record, and the log lines tied to your submissions that are still inside the 90-day window. Plain text or CSV, your choice. What you will not get is somebody else's data in the same thread, which is removed before sending.
Deletion is done inside 10 days too, and it covers the database, the mailbox copy and the backup as the backup rotates. Withdrawing advertising consent does not need a request at all — Cookie settings in the footer of every page does it instantly.
Getting into the salon and around the site
The site is built to WCAG 2.2 AA as the target. Every control is reachable by keyboard, the focus ring is a 2px teal hairline that stays visible on every ground, headings run in order, images carry real alt text, and the tabs on this page answer to the arrow keys, Home and End. Text reflows to a 320px screen without a horizontal scrollbar, and nothing is locked to landscape.
Motion is optional. The magnetic buttons and the hover-follow preview on the home page are pointer-only and switch off entirely when your system asks for reduced motion. Nothing on the site autoplays, blinks or moves without you.
Colour is never the only carrier of meaning. Body text sits at 4.5:1 or better against its ground, and the mono labels are sized and tracked to stay legible at 0.75rem.
The physical salon
The salon is at 132 10th Ave, New York, New York 10011. If you or one of your guests uses a wheelchair, a cane or a walker, or cannot stand for long, say so when you book. A stylist will describe the entrance and the fitting room to you honestly before the day, and plan the appointment around what you need rather than asking you to fit around the room.
Appointments run 90 minutes. If you need longer, tell us and we hold two slots rather than rushing you. A gown can be tried seated first, and the hem is pinned wherever you are most comfortable standing.
If something on this site blocks you
Email [email protected] or call +1 646-630-7052 and describe what failed and what you were using. We answer accessibility reports on the same 10-day clock as a data request, and we will read you the information over the phone in the meantime rather than telling you to wait for a fix.
08Still the shortest answer
An appointment is 90 minutes. Most brides know by minute 50.
Nothing in this notice stops you picking up the phone instead. Call the salon, say which silhouette you want to see, and a stylist pulls the samples before you arrive. The rest of the paperwork can wait.
- +1 646-630-7052
- [email protected]
- 132 10th Ave, New York, New York 10011