Privacy Policy

Last updated September 24, 2026

This policy explains how Spine handles information used to run the service and how you can ask about your data.

Information we handle

When you create an account, the sign-in system handles your name, email address, sign-in identity, verification status, and session information. If you choose Google sign-in, Google also handles the information needed for that sign-in.

Stores add names, staff memberships and roles, invitations, and inventory records. An inventory record may contain book details, condition, asking price, location, status, notes, and a history of changes with the acting user and time. You may also add an optional profile photo and profile details. We keep transactional email and delivery records for verification and staff invitations.

The application and its providers process technical data such as IP addresses, browser and request information, security events, and operational logs. The public site does not currently run advertising or product analytics.

Why we use it

We use this information to let you sign in, manage store access, operate inventory workflows, send verification and invitation messages, investigate problems, prevent abuse, and recover the service after failures. Store inventory access is checked against store membership and roles.

Where it goes

Spine's primary application services and databases run on operator-managed infrastructure in Raleigh, North Carolina. Cloudflare provides edge, DNS, TLS, and a bot challenge on store creation. Google Cloud provides messaging, offsite backups, and private profile-media storage. Amazon Web Services SES sends transactional email. OpenLibrary supplies bibliographic metadata where available. These providers may process relevant data to provide their services. Their own practices also apply when you use their services, such as Google sign-in.

Cookies and browser storage

Spine uses an essential sign-in cookie. The application also uses tab storage for session and return-navigation state, and local browser storage for an inventory-layout preference. We do not currently use marketing cookies or analytics on the public site. If that changes, this page will be updated before the technology is enabled.

Retention and requests

Account, store, inventory, history, and delivery records do not currently have one automatic deletion date. Backups rotate by backup count, not a promised number of days. Some security, history, and delivery records may need separate handling even when a current inventory item is removed. Spine does not currently offer a self-service account or store deletion control or a bulk store-inventory export.

To ask about access, correction, export, or deletion, email [email protected]. We will verify that you are authorized for the account or store, review what data can be provided or removed, and explain the next steps. See data requests for the current process.

Security and changes

We use store membership and role checks, session controls, private profile-media access, and backups. No online system can promise absolute security. Read Security & data practices for a factual summary. If our practices change materially, we will update this page and its date.

Contact

Send privacy, data, and security questions to [email protected].