← Back to Figrio Studio

Privacy Policy

Last updated: June 2026

This Privacy Policy explains how Figrio Studio ("we", "us", "our") collects, uses, stores, and protects data when you visit figrio.com, interact with security protections, send us a contact inquiry, or sign up for our newsletter. Data processing is carried out in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and the EU rules on terminal equipment storage.


1. Who we are

Figrio Studio is a jewellery micro-manufacturer based in Hungary (Kaposvár, Somogy County, Hungary), operating within the European Union. We act as the data controller for the processing activities described in this notice. For any privacy-related enquiries, please contact us at: [email protected]

2. What data we collect

We collect or process the following categories:

We do not use advertising, profiling, social media tracking, Google Analytics, Meta Pixel, TikTok Pixel, or similar marketing trackers.

3. Cookies, local storage and security technologies

Across figrio.com - both the marketing pages and the shop storefront at figrio.com/shop - only essential, security, or user-requested first-party browser storage is used. The shop entries below are set only when you use the storefront; the shop's account, order, and payment data processing is described in detail in the shop's own privacy notice. Each entry lists its storage type and lifetime:

NameTypeCategoryDurationProviderPurpose
cf_clearanceCookie (HttpOnly, Secure)Strictly necessaryCloudflare-managed (challenge passage period)CloudflareProves your browser passed Cloudflare security checks and reduces repeated bot challenges. Set by the Cloudflare Challenge Platform on the live site.
__cf_bm, _cfuvid, cf_chl_rc_*CookieStrictly necessaryCloudflare-managed (session / short-lived)CloudflareSet only if the related bot-management, rate-limit, or challenge feature is active; used for security, diagnostics, and rate limiting.
figrio_privacy_notice_ackLocal storageFunctional (user-requested)180 daysFirst-party (site)Set only after you press the notice button, so the cookie notice is not shown again. The legacy figrio_cookie_ok value is removed by the current site code.
Cloudflare Web Analytics / RUMCookie-free (no client storage)AnalyticsNoneCloudflareAggregated, cookie-free analytics and performance measurement. Per Cloudflare, no client-side storage or visitor personal data is used.
Cloudflare TurnstileAnti-abuse tokenStrictly necessaryOne-time tokenCloudflareLoaded on the newsletter and contact forms to prevent automated abuse; creates a one-time verification token and may use Cloudflare security signals.
figrio_localeCookieFunctional180 daysFirst-party (shop)Stores your selected shop language; it does not set product currency or market pricing.
figrio_session_hintCookie (Secure)Strictly necessary7 days (expires with your sign-in session)First-party (shop)Records only that this browser has a shop sign-in session, so account pages render the right state without a flash and an expired sign-in can be renewed instead of dropped. It holds no account details, no email address, and no sign-in token, and it is deleted when you sign out.
figrio_deviceCookie (HttpOnly, Secure)Strictly necessary180 daysFirst-party (shop)Recognises this browser as one you have signed in from before, so that a sign-in from an unfamiliar device can be flagged to you by email. It stores a random identifier only - no account details - and the device record is matched by a one-way hash. It deliberately outlives sign-out, because remembering the device is the point.
figrio_cart_countLocal storageFunctionalUntil clearedFirst-party (shop)Shows the cart item count without waiting for a network response.
figrio_cart_changed_atLocal storageFunctionalUntil clearedFirst-party (shop)Signals cart changes between shop views.
figrio_checkout_billingSession storageFunctionalSession (until tab close)First-party (shop)Holds your checkout billing details during the current session.
figrio_pending_couponLocal storageFunctional7 daysFirst-party (shop)Carries a coupon code from the account or cart into checkout.
figrio_wishlist_itemsLocal storageFunctionalUntil clearedFirst-party (shop)Stores wishlist items locally before or alongside account sync.
figrio_market_shipping_countryLocal storageFunctionalUntil clearedFirst-party (shop)Remembers your selected market and shipping-country context.
figrio_perks_config_v1Local storageFunctional1 hourFirst-party (shop)Caches gift and perk configuration for a faster account experience.
figrio_turnstile_bypassLocal storageStrictly necessaryUntil clearedFirst-party (shop)A trusted-device or test helper for the anti-abuse (Turnstile) flow, used only when enabled by the environment.

Because these technologies are essential security measures, user-requested acknowledgement storage, or cookie-free analytics, the site does not present optional marketing or analytics consent categories. If optional cookies or tracking tools are added later, they must be blocked until consent is given.

4. Why we collect your data

Your newsletter email address is collected solely for the purpose of sending you updates about new collections, exclusive offers, and studio news. Contact form data is used solely to answer your inquiry, custom order request, support request, or press message. We will not use your contact form data for newsletter or marketing purposes unless you separately sign up for those communications.

We process newsletter subscriptions on the basis of freely given, specific, and informed consent (Article 6(1)(a) GDPR). We process contact form inquiries on the basis of steps requested before entering into a contract where the inquiry concerns a custom order or purchase discussion (Article 6(1)(b) GDPR), and otherwise on our legitimate interest in responding to messages and operating the studio (Article 6(1)(f) GDPR). We process essential security, anti-abuse, delivery, logging, cookie-free analytics, and crash diagnostics data on the basis of our legitimate interest in operating, securing, and repairing the website (Article 6(1)(f) GDPR). Strictly necessary terminal storage is used only where needed for transmission, security, a service requested by the visitor, or a notice acknowledgement requested by the visitor. You may withdraw newsletter consent at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal.

6. How we store your data

Newsletter email addresses are stored securely in a PostgreSQL database accessed via Cloudflare Hyperdrive, with infrastructure located within the European Economic Area (EEA). Contact form messages are not stored in the website database; they are sent by email through Resend to Figrio Studio's mailbox so we can respond. Crash diagnostics from the shop storefront are stored by Sentry (Functional Software, Inc.) on its European Union infrastructure, in an account created in the EU region. Cloudflare, Resend, and Sentry act as service providers/data processors for the relevant infrastructure, delivery, and diagnostics tasks. Your data is protected by industry-standard encryption in transit and, where stored by our providers, at rest.

7. How long we keep your data

We will retain your email address until the earliest of the following occurs:

Contact form messages are kept only as long as needed to respond and manage the inquiry, normally up to 12 months, unless a longer period is required for a resulting order, legal obligation, dispute, or fraud/security investigation. Crash diagnostic reports are deleted automatically by Sentry after 30 days.

8. Sharing your data

We do not sell, rent, or share personal data with third parties for marketing purposes. Data is accessible only to Figrio Studio and service providers needed to operate the website, contact form, email delivery, newsletter, security, crash diagnostics, and hosting infrastructure, currently including Cloudflare, Resend, and Sentry. Cloudflare may process security cookie data and network/security telemetry in accordance with its privacy documentation and applicable data transfer safeguards. Resend processes outbound email delivery data needed to send contact and transactional emails. Sentry processes the crash diagnostics described in section 2 so that faults in the shop storefront can be found and fixed, and holds that data in the European Union.

9. Your rights under GDPR

As an EU data subject, you have the following rights:

To exercise any of these rights, please contact us at [email protected] and we will respond within 30 days (GDPR Article 12(3)).

10. Unsubscribing from newsletter

You can request removal of your email address at any time by emailing us at [email protected] with the subject line "Unsubscribe". We will delete your data within 5 business days.

11. Changes to this policy

We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated date. In the event of significant changes, we will also notify subscribers by email. We recommend checking this page periodically.


If you have any questions about this Privacy Policy, please contact us at [email protected]