Last updated: 19 July 2026
This notice explains how Weddings by Design (EA) Ltd trading as Serenity Brides (“we”, “us”, “our”) collects and uses personal data under the UK GDPR and the Data Protection Act 2018, and how cookies on this website are handled under the Privacy and Electronic Communications Regulations (PECR). It applies to our boutique, our website, and our online booking flow.
We are the data controller for the personal data described in this notice.
We have not appointed a statutory Data Protection Officer. For any privacy request, use the contact details above.
We follow data minimisation: we collect only what we need for the purposes below. Most data comes directly from you.
Appointments and enquiries (website, phone, email, in store, or online booking):
Providing your name and contact details is needed so we can arrange and confirm an appointment. If you do not provide them, we cannot book you in.
Purchases and orders:
Card payments are processed by Revolut. We do not store full card numbers on our systems.
Website use (see also our Cookie Policy):
We do not load Google Tag Manager, Google Ads browser tags, or session-replay tools on this website.
We do not intentionally collect special-category data. If you volunteer information about accessibility or similar needs, we use it only to prepare for your visit.
Our services are aimed at adults. We do not knowingly collect personal data from children under 13 via this website.
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Taking and managing appointments; providing bridal boutique services | Art. 6(1)(b) — contract (or steps prior to a contract) |
| Responding to enquiries and contact-form messages | Art. 6(1)(b) and/or Art. 6(1)(f) — legitimate interests (responding to people who contact us) |
| Processing payments and fulfilling orders | Art. 6(1)(b) — contract |
| Keeping sales, order and accounting records | Art. 6(1)(c) — legal obligation |
| Google Analytics (site usage statistics) | Art. 6(1)(a) — consent (withdraw any time) |
| Advertising measurement and attribution (first-party click IDs / campaign labels, and the Meta Pixel for Facebook / Instagram) | Art. 6(1)(a) — consent (withdraw any time) |
| Securing our website and systems; preventing fraud and abuse | Art. 6(1)(f) — legitimate interests (keeping our systems and customers safe) |
Where we rely on legitimate interests, we consider your rights and expect no override of those rights for the limited uses above. You may object — see Your rights.
We do not run a newsletter or marketing-email list and do not use a third-party email marketing platform. We do not sell your personal data.
We do not use automated decision-making (including profiling) that produces legal or similarly significant effects about you.
Non-essential cookies and similar storage are used only with your prior consent, in line with PECR. You choose via our cookie banner and can change your mind at any time via cookie settings.
sb_attr cookie may store paid-click IDs and campaign labels so we can
attribute enquiries and bookings; and we load the
Meta Pixel so Meta can help us measure visits from Facebook /
Instagram and improve our ads (cookies such as _fbp /
_fbc).
Full names, purposes and lifespans are in our Cookie Policy.
We share personal data only where needed for the purposes above:
If you consented to advertising, we may also send conversion events to advertising platforms from our own systems (for example offline conversion import or Meta Conversions API), using click identifiers stored with your consent, in addition to the Meta Pixel in the browser.
Some providers may process data outside the UK (for example Google Analytics or Meta in the United States, or Revolut as payment processor). Where a transfer is not covered by an adequacy decision, we rely on appropriate safeguards such as the UK Extension to the EU–US Data Privacy Framework (where the recipient is certified), the UK International Data Transfer Agreement, or Standard Contractual Clauses with the UK addendum, as applicable.
sb_attr): up to 90 days, or until you withdraw consent_fbp / _fbc): up to 90 days (Meta defaults), or until you withdraw consent / clear cookiessb_consent): up to 180 days, after which we ask againWe may keep data longer if required to establish, exercise or defend legal claims.
We use appropriate technical and organisational measures for the nature of our business, including access controls on our systems, HTTPS on our website, and limiting staff access to appointment and order data to those who need it. No method of transmission or storage is completely secure; if we become aware of a personal-data breach that risks your rights, we will notify the ICO and affected individuals where the law requires.
Under UK data protection law you have the right to:
To exercise any right, email info@serenitybrides.com or write to us at the boutique address. We will respond within one month in most cases. We may need to verify your identity. These rights are free of charge unless a request is clearly unfounded or excessive.
You can change cookie choices any time via cookie settings.
You also have the right to complain to the Information Commissioner’s Office (ICO): ico.org.uk · 0303 123 1113 · Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would appreciate the chance to resolve your concern first.
We may update this notice from time to time. The “Last updated” date above shows when it was last revised. Significant changes will be reflected on this page.
Weddings by Design (EA) Ltd trading as Serenity Brides
16 Short Wyre Street, Colchester, Essex CO1 1LN
info@serenitybrides.com ·
01206 577756
Related: Cookie Policy · Terms & Conditions