| cf_clearance | Cookie (HttpOnly, Secure) | Strictly necessary | Cloudflare-managed (challenge passage period) | Cloudflare | Proves your browser passed Cloudflare security checks and reduces repeated bot challenges. Set by the Cloudflare Challenge Platform on the live site. |
| __cf_bm, _cfuvid, cf_chl_rc_* | Cookie | Strictly necessary | Cloudflare-managed (session / short-lived) | Cloudflare | Set only if the related bot-management, rate-limit, or challenge feature is active; used for security, diagnostics, and rate limiting. |
| figrio_privacy_notice_ack | Local storage | Functional (user-requested) | 180 days | First-party (site) | Set only after you press the notice button, so the cookie notice is not shown again. The legacy figrio_cookie_ok value is removed by the current site code. |
| Cloudflare Web Analytics / RUM | Cookie-free (no client storage) | Analytics | None | Cloudflare | Aggregated, cookie-free analytics and performance measurement. Per Cloudflare, no client-side storage or visitor personal data is used. |
| Cloudflare Turnstile | Anti-abuse token | Strictly necessary | One-time token | Cloudflare | Loaded on the newsletter and contact forms to prevent automated abuse; creates a one-time verification token and may use Cloudflare security signals. |
| figrio_session_hint | Cookie (Secure) | Strictly necessary | 7 days (expires with your sign-in session) | First-party (shop) | Records only that this browser has a shop sign-in session, so account pages render the right state without a flash and an expired sign-in can be renewed instead of dropped. It holds no account details, no email address, and no sign-in token, and it is deleted when you sign out. |
| figrio_device | Cookie (HttpOnly, Secure) | Strictly necessary | 180 days | First-party (shop) | Recognises this browser as one you have signed in from before, so that a sign-in from an unfamiliar device can be flagged to you by email. It stores a random identifier only - no account details - and the device record is matched by a one-way hash. It deliberately outlives sign-out, because remembering the device is the point. |
| figrio_cart_count | Local storage | Functional | Until cleared | First-party (shop) | Shows the cart item count without waiting for a network response. |
| figrio_cart_changed_at | Local storage | Functional | Until cleared | First-party (shop) | Signals cart changes between shop views. |
| figrio_checkout_billing | Session storage | Functional | Session (until tab close) | First-party (shop) | Holds your checkout billing details during the current session. |
| figrio_pending_coupon | Local storage | Functional | 7 days | First-party (shop) | Carries a coupon code from the account or cart into checkout. |
| figrio_wishlist_items | Local storage | Functional | Until cleared | First-party (shop) | Stores wishlist items locally before or alongside account sync. |
| figrio_market_shipping_country | Local storage | Functional | Until cleared | First-party (shop) | Remembers your selected market and shipping-country context. |
| figrio_perks_config_v1 | Local storage | Functional | 1 hour | First-party (shop) | Caches gift and perk configuration for a faster account experience. |
| figrio_turnstile_bypass | Local storage | Strictly necessary | Until cleared | First-party (shop) | A trusted-device or test helper for the anti-abuse (Turnstile) flow, used only when enabled by the environment. |