Skip to main content
bridesVENUES
Venues
VendorsJournal
Sign inPlan your wedding
Menu
HomeVenuesVendorsJournalConcierge

Destinations

Indonesia85Thailand16Italy3France3
Sign inPlan your wedding

Begin Your Journey to the Perfect Wedding

Curated venues · Bespoke experiences · Timeless memories

Browse VenuesContact Us
bridesVENUES

A curated collection of the world's most extraordinary wedding venues, designed for couples who demand nothing less than perfection.

Company

  • About
  • Contact
  • Get Inspired
  • Get Support – AI
  • Dashboard

Destinations

  • Indonesia

    • Bali
    • Lombok
  • Thailand

    • Phuket
    • Koh Samui
  • Europe

    • France
    • Italy

Categories

  • Beachfront
  • Cliff Front
  • Ricefields
  • Jungle Views
  • Lake Views
  • Historical Landmark

Partners

  • YH | Charter
  • The Luxury Bali
  • The Luxury Leisure
  • Lead Luxury Management

Newsletter

Receive curated venue collections and editorial features directly to your inbox.

TermsPrivacyCookiesCancellations & RefundsHost AgreementVendor Agreement

© 2026 Brides Venues Pte. Ltd. All rights reserved.

hello@bridesvenues.com  |  +62 8227 7727 98

InstagramPinterestFacebook

Legal · Privacy

Your data, quietly held.

This Privacy Policy explains what personal data Brides Venues collects, why we collect it, how we use it, who we share it with, how long we keep it, and the rights you have over it. We write this in plain English wherever we can, and we follow the disclosure standards required by the GDPR (EU), the UK Data Protection Act 2018, the California Consumer Privacy Act (CCPA), and Indonesia’s Personal Data Protection Law (UU 27/2022).

Draft — pending counsel reviewEffective 1 June 2026Last updated 25 May 2026Version 1.0 (Draft for legal review)

Applicable jurisdictions

United States · European Economic Area (GDPR) · United Kingdom · Indonesia (UU PDP)


01Who is the data controller

Brides Venues Pte. Ltd. (“Brides Venues”, “we”) is the data controller for personal data processed through the platform. Our registered office is at [REGISTERED ADDRESS — to be inserted by counsel].

For data subjects in the European Economic Area and the United Kingdom, our representative under Article 27 GDPR / UK GDPR is [EU/UK representative to be appointed]. For data subjects in Indonesia, our Data Protection Officer is [DPO name — to be appointed] and can be reached at privacy@bridesvenues.com.

02What personal data we collect

2.1 Information you provide

  • Identity: name, email, phone, password (hashed), profile photo, optional company name.
  • Wedding planning: wedding date, destination, guest count, vendor preferences, budget signals, dietary requirements, RSVP responses, seating charts.
  • Communications: messages exchanged with venues, vendors, and the Brides Venues concierge through the platform.
  • Payments: billing name, billing address, card brand and last four digits (full card details are tokenised by our payment processors and never touch our servers).
  • Uploaded content: photographs, documents, agreements, and other files you upload to your account.

2.2 Information collected automatically

  • Device and usage: IP address, browser type, device type, operating system, language preference, referring URL, pages visited, time on page.
  • Cookies and similar: see our Cookie Policy for the full list and how to control them.

2.3 Information from third parties

  • Social login providers (Google, Apple) when you choose to sign in with them.
  • Payment processors (Stripe, Xendit) for confirmation that a payment was completed.
  • Vendors and venues you book through us, for the purpose of completing the booking.

03Why we process your data (lawful bases)

PurposeLawful basis (GDPR Art 6)
Creating and operating your accountPerformance of a contract (Art 6(1)(b))
Facilitating inquiries, bookings, and paymentsPerformance of a contract (Art 6(1)(b))
Sending transactional emails (booking confirmations, payment receipts, dispute notices)Performance of a contract (Art 6(1)(b)) / legitimate interest (Art 6(1)(f))
Sending marketing emails about new venues, editorial features, and special offersConsent (Art 6(1)(a)) — opt-in only, with easy unsubscribe
Fraud prevention, security monitoring, audit loggingLegitimate interest (Art 6(1)(f))
Compliance with tax, anti-money-laundering, accounting obligationsLegal obligation (Art 6(1)(c))
Analytics on aggregated, de-identified usageLegitimate interest (Art 6(1)(f)) — opt-out via cookie settings

We do not knowingly process special-category data (health, religion, sexual orientation, etc.) unless you voluntarily provide it (for example dietary restrictions you choose to share with a caterer). In that case we rely on your explicit consent under Article 9(2)(a) GDPR.

04Who we share data with

4.1 Venues and vendors

When you send an inquiry or confirm a booking, the venue (and any vendors you have selected) receives your name, contact details, wedding date, guest count, and the message you sent. They become independent controllers of that data for the purposes of fulfilling your booking.

4.2 Service providers (data processors)

We work with carefully selected processors under written data processing agreements:

ProcessorPurposeLocation
Neon DatabasePrimary database hostingEU / US (region-locked)
VercelApplication hosting, CDNGlobal edge
ResendTransactional email deliveryUS
StripeCard payments, subscriptionsGlobal
XenditSouth-East Asia paymentsSingapore / Indonesia
SentryError monitoring, performanceUS
Cloudflare / S3-compatibleImage storage and deliveryGlobal

4.3 Legal disclosures

We may disclose personal data when required by law, regulation, court order, or to enforce our Terms of Service.

4.4 We do not sell your personal data

We do not sell personal data within the meaning of the CCPA, the UU PDP, or any equivalent regime. We do not share it for advertising targeting outside the platform.

05International transfers

We are headquartered in Singapore and use processors in the EEA, United Kingdom, United States, and Indonesia. When we transfer personal data outside the EEA / UK, we rely on:

  • European Commission adequacy decisions (where they apply), or
  • The Standard Contractual Clauses (2021) supplemented by appropriate technical and organisational measures (encryption in transit and at rest, minimum-necessary access).

A copy of the SCCs is available on request from privacy@bridesvenues.com.

06How long we keep your data

CategoryRetention
Account profileFor as long as the account is active. Deleted within 30 days of account closure unless we are required to keep it for legal reasons.
Booking and payment recordsSeven (7) years after the wedding date, for tax and anti-money-laundering reasons.
MessagesThree (3) years after the related booking concludes.
Marketing consent and preferencesUntil you withdraw consent, plus 90 days for audit.
Server logs (IP, user-agent)Thirty (30) days, then aggregated for analytics.

07Your rights

You have the following rights over your personal data:

Access
You can request a copy of the personal data we hold about you.
Rectification
You can ask us to correct inaccurate or incomplete data.
Erasure (“right to be forgotten”)
You can ask us to delete your data, subject to legal retention obligations.
Restriction
You can ask us to restrict processing while we investigate a request.
Portability
You can ask us to provide your data in a structured, machine-readable format and to transfer it to another controller.
Objection
You can object to processing based on legitimate interests, including profiling and marketing.
Withdraw consent
Where we rely on consent, you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
Lodge a complaint
You may lodge a complaint with your local supervisory authority — e.g. the Information Commissioner’s Office (UK), the CNIL (France), Garante (Italy), or PDP Indonesia.

To exercise any of these rights, email privacy@bridesvenues.com or use the Privacy controls in your account. We respond within thirty (30) days. We will verify your identity before completing your request.

08Children

The platform is not directed at children under sixteen (16). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

09Security

We use industry-standard safeguards: TLS 1.2+ in transit, AES-256 at rest, hashed passwords (Argon2 / bcrypt), role-based access control, audit logging, dependency scanning, and prompt patching of known vulnerabilities. No system is impregnable; if you suspect a breach of your account, email security@bridesvenues.com immediately.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, in accordance with Article 33 GDPR.

10Changes to this Policy

We may update this Policy as the platform evolves. Material changes will be notified by email or an in-app notice at least thirty (30) days before they take effect. The current version, version history, and effective date are always available at /privacy.

11Contact

Privacy questions, rights requests, and complaints can be sent to privacy@bridesvenues.com. Security disclosures should go to security@bridesvenues.com.


Contact our legal team: legal@bridesvenues.com

Companion documents: Terms · Privacy · Cookies · Refund · Vendor · Host