Privacy Policy

Privacy

Last updated: July 2026

This Privacy Policy explains how Figrio Studio ("we", "us", "our") collects, uses, stores, and protects data when you visit figrio.com, interact with security protections, send us a contact inquiry, or sign up for our newsletter. Data processing is carried out in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and the EU rules on terminal equipment storage.

1. Who we are

Figrio Studio is a jewellery micro-manufacturer based in Hungary (Kaposvár, Somogy County, Hungary), operating within the European Union. We act as the data controller for the processing activities described in this notice. For any privacy-related enquiries, please contact us at: support@figrio.com

2. What data we collect

We collect or process the following categories:

  • Email address — when you sign up for our newsletter and exclusive updates
  • Name, email address, message content, and technical request/security data — when you send the contact form
  • Newsletter consent status and technical request data needed to send, confirm, secure, and troubleshoot subscriptions, including Turnstile verification tokens and server security logs
  • Aggregated website usage and performance data through Cloudflare Web Analytics or Cloudflare RUM. According to Cloudflare, these services do not use cookies, localStorage, or visitor personal data for analytics.
  • Crash diagnostics from the shop storefront at figrio.com/shop — when a page fails, an automatic error report is sent to Sentry containing the error message and technical stack trace, the page address, your browser, operating system, language and time zone, and a short trail of the immediately preceding page views, clicks, network requests, and console output. Single-use links (password reset, email verification, email change) and payment secrets are removed from those addresses before the report leaves your browser. Your IP address is not stored in the report, and Sentry does not retain any location derived from it. This uses no cookies and no browser storage. Crash reporting runs only on the shop storefront, not on the marketing pages.

We do not use advertising, profiling, social media tracking, Google Analytics, Meta Pixel, TikTok Pixel, or similar marketing trackers.

3. Cookies, local storage and security technologies

Across figrio.com - both the marketing pages and the shop storefront at figrio.com/shop - only essential, security, or user-requested first-party browser storage is used. The shop entries below are set only when you use the storefront; the shop's account, order, and payment data processing is described in detail in the shop's own privacy notice. Each entry lists its storage type and lifetime:

NameTypeCategoryDurationProviderPurpose
cf_clearanceCookie (HttpOnly, Secure)Strictly necessaryCloudflare-managed (challenge passage period)CloudflareProves your browser passed Cloudflare security checks and reduces repeated bot challenges. Set by the Cloudflare Challenge Platform on the live site.
__cf_bm, _cfuvid, cf_chl_rc_*CookieStrictly necessaryCloudflare-managed (session / short-lived)CloudflareSet only if the related bot-management, rate-limit, or challenge feature is active; used for security, diagnostics, and rate limiting.
figrio_privacy_notice_ackLocal storageFunctional (user-requested)180 daysFirst-party (site)Set only after you press the notice button, so the cookie notice is not shown again. The legacy figrio_cookie_ok value is removed by the current site code.
Cloudflare Web Analytics / RUMCookie-free (no client storage)AnalyticsNoneCloudflareAggregated, cookie-free analytics and performance measurement. Per Cloudflare, no client-side storage or visitor personal data is used.
Cloudflare TurnstileAnti-abuse tokenStrictly necessaryOne-time tokenCloudflareLoaded on the newsletter and contact forms to prevent automated abuse; creates a one-time verification token and may use Cloudflare security signals.
figrio_session_hintCookie (Secure)Strictly necessary7 days (expires with your sign-in session)First-party (shop)Records only that this browser has a shop sign-in session, so account pages render the right state without a flash and an expired sign-in can be renewed instead of dropped. It holds no account details, no email address, and no sign-in token, and it is deleted when you sign out.
figrio_deviceCookie (HttpOnly, Secure)Strictly necessary180 daysFirst-party (shop)Recognises this browser as one you have signed in from before, so that a sign-in from an unfamiliar device can be flagged to you by email. It stores a random identifier only - no account details - and the device record is matched by a one-way hash. It deliberately outlives sign-out, because remembering the device is the point.
figrio_cart_countLocal storageFunctionalUntil clearedFirst-party (shop)Shows the cart item count without waiting for a network response.
figrio_cart_changed_atLocal storageFunctionalUntil clearedFirst-party (shop)Signals cart changes between shop views.
figrio_checkout_billingSession storageFunctionalSession (until tab close)First-party (shop)Holds your checkout billing details during the current session.
figrio_pending_couponLocal storageFunctional7 daysFirst-party (shop)Carries a coupon code from the account or cart into checkout.
figrio_wishlist_itemsLocal storageFunctionalUntil clearedFirst-party (shop)Stores wishlist items locally before or alongside account sync.
figrio_market_shipping_countryLocal storageFunctionalUntil clearedFirst-party (shop)Remembers your selected market and shipping-country context.
figrio_perks_config_v1Local storageFunctional1 hourFirst-party (shop)Caches gift and perk configuration for a faster account experience.
figrio_turnstile_bypassLocal storageStrictly necessaryUntil clearedFirst-party (shop)A trusted-device or test helper for the anti-abuse (Turnstile) flow, used only when enabled by the environment.

Because these technologies are essential security measures, user-requested acknowledgement storage, or cookie-free analytics, the site does not present optional marketing or analytics consent categories. If optional cookies or tracking tools are added later, they must be blocked until consent is given.

4. Why we collect your data

Your newsletter email address is collected solely for the purpose of sending you updates about new collections, exclusive offers, and studio news. Contact form data is used solely to answer your inquiry, custom order request, support request, or press message. We will not use your contact form data for newsletter or marketing purposes unless you separately sign up for those communications.

We process newsletter subscriptions on the basis of freely given, specific, and informed consent (Article 6(1)(a) GDPR). We process contact form inquiries on the basis of steps requested before entering into a contract where the inquiry concerns a custom order or purchase discussion (Article 6(1)(b) GDPR), and otherwise on our legitimate interest in responding to messages and operating the studio (Article 6(1)(f) GDPR). We process essential security, anti-abuse, delivery, logging, cookie-free analytics, and crash diagnostics data on the basis of our legitimate interest in operating, securing, and repairing the website (Article 6(1)(f) GDPR). Strictly necessary terminal storage is used only where needed for transmission, security, a service requested by the visitor, or a notice acknowledgement requested by the visitor. You may withdraw newsletter consent at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal.

6. How we store your data

Newsletter email addresses are stored securely in a PostgreSQL database accessed via Cloudflare Hyperdrive, with infrastructure located within the European Economic Area (EEA). Contact form messages are not stored in the website database; they are sent by email through Resend to Figrio Studio's mailbox so we can respond. Crash diagnostics from the shop storefront are stored by Sentry (Functional Software, Inc.) on its European Union infrastructure, in an account created in the EU region. Cloudflare, Resend, and Sentry act as service providers/data processors for the relevant infrastructure, delivery, and diagnostics tasks. We have entered into a data processing agreement with Sentry under Article 28 GDPR, which incorporates the European Commission's Standard Contractual Clauses for any transfer outside the EEA. Your data is protected by industry-standard encryption in transit and, where stored by our providers, at rest.

7. How long we keep your data

We will retain your email address until the earliest of the following occurs:

  • You unsubscribe or request deletion of your data
  • We discontinue our newsletter service

Contact form messages are kept only as long as needed to respond and manage the inquiry, normally up to 12 months, unless a longer period is required for a resulting order, legal obligation, dispute, or fraud/security investigation. Crash diagnostic reports are deleted automatically by Sentry after 30 days.

8. Sharing your data

We do not sell, rent, or share personal data with third parties for marketing purposes. Data is accessible only to Figrio Studio and service providers needed to operate the website, contact form, email delivery, newsletter, security, crash diagnostics, and hosting infrastructure, currently including Cloudflare, Resend, and Sentry. Cloudflare may process security cookie data and network/security telemetry in accordance with its privacy documentation and applicable data transfer safeguards. Resend processes outbound email delivery data needed to send contact and transactional emails. Sentry processes the crash diagnostics described in section 2 so that faults in the shop storefront can be found and fixed, and holds that data in the European Union.

9. Your rights under GDPR

As an EU data subject, you have the following rights:

  • Right to access (GDPR Article 15) — request a copy of the data we hold about you
  • Right to rectification (GDPR Article 16) — request correction of inaccurate data
  • Right to erasure (GDPR Article 17) — request deletion of your data at any time
  • Right to restriction of processing (GDPR Article 18) — request suspension of data processing
  • Right to withdraw consent (GDPR Article 7) — unsubscribe at any time without consequence
  • Right to lodge a complaint (GDPR Article 77) — with the National Authority for Data Protection and Freedom of Information (NAIH, naih.hu) or the supervisory authority in your country of residence

To exercise any of these rights, please contact us at support@figrio.com and we will respond within 30 days (GDPR Article 12(3)).

10. Unsubscribing from newsletter

You can request removal of your email address at any time by emailing us at support@figrio.com with the subject line "Unsubscribe". We will delete your data within 5 business days.

11. Changes to this policy

We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated date. In the event of significant changes, we will also notify subscribers by email. We recommend checking this page periodically.

If you have any questions about this Privacy Policy, please contact us at support@figrio.com