Privacy Policy

This Privacy Policy describes how personal data is processed and how cookies and similar technologies are used in the Fig&Pear online store available at https://figandpear.com.

It applies to the store, customer account, contact forms, newsletter, notifications, order handling, returns, complaints and communication carried out by the Controller online, including on social media.

§1 Data Controller

The controller of personal data is Diana Świtajewska, operating under the Fig&Pear brand, address: ul. Kazimierza Pułaskiego 97, 18-400 Łomża, Poland, VAT ID: PL7181993869, REGON: 522994143, e-mail: shop@figandpear.com.

For matters concerning personal data, you may contact the Controller by e-mail or through the contact form: https://figandpear.com/en/contact/.

The Controller has not appointed a Data Protection Officer.

§2 What Data We Process

The scope of data depends on how you use the store. We may process in particular:

  • identification and contact data: name, company name, VAT ID, e-mail address, telephone number, delivery address and billing address,
  • customer account data: login, e-mail address, order history and account settings,
  • data relating to orders, payments, delivery, returns, complaints and correspondence,
  • technical data: IP address, cookie identifiers, session identifiers, device type, browser, operating system, approximate location derived from technical data, referring page and information about activity in the store,
  • marketing and analytics data, if you have given the relevant consent.

We receive data directly from you, from the operation of the store and the technologies used, from providers handling payments, delivery, login, forms or analytics tools, and from your public activity on our social media profiles. Based on order history, viewed products, traffic sources, clicks and similar information, we may create auxiliary inferences, for example about preferred products, language, delivery country or campaign effectiveness, where we have a legal basis to do so.

§3 Purposes, Legal Bases and Retention

PurposeLegal basisRetention period
Handling orders, payments, delivery, returns and complaintsArticle 6(1)(b) GDPR - performance of a contract or steps before entering into a contractfor the duration of contract performance and then for the period needed to handle returns, complaints, statutory warranty, commercial warranty, chargebacks and legal claims; some data may be retained longer where accounting, tax or legal duties require it
Accounting, tax and settlement obligationsArticle 6(1)(c) GDPR - legal obligationfor the period required by law, usually 5 tax years
Customer account managementArticle 6(1)(b) GDPRuntil the account is deleted and then for the period necessary to defend claims or comply with legal obligations
Customer contact and enquiry handlingArticle 6(1)(f) GDPR - legitimate interest in handling correspondencefor the duration of the matter and then for the period necessary to defend claims
Newsletter, marketing notifications and back-in-stock alerts, where you subscribed to the serviceArticle 6(1)(a) GDPR - consent; for defending claims also Article 6(1)(f) GDPRuntil consent is withdrawn or you unsubscribe, and then for the period needed to prove consent
Cart reminders, product recommendations, surveys, review requests and similar after-sales communicationArticle 6(1)(f) GDPR - legitimate interest in customer service, satisfaction research and promotion of our own similar products; where required by law - consentuntil you object, withdraw consent or the communication purpose ends
Analytics, ad effectiveness measurement, remarketing and ad personalisationArticle 6(1)(a) GDPR - consent to cookies, analytics or marketinguntil consent is withdrawn, cookies are deleted or for the period set by a given tool
Operating social media profiles and handling messages, comments, reactions and ad campaigns in those servicesArticle 6(1)(f) GDPR - legitimate interest in communication, brand promotion and effectiveness analysisfor as long as data is available in the relevant service, for the time needed to handle the matter or until objection, where applicable
Store security, fraud prevention, technical diagnostics and claim protectionArticle 6(1)(f) GDPR - Controller's legitimate interestfor the period necessary for the purpose, usually until claims expire or diagnostics are completed

§4 Recipients and Services Used

Data may be shared with entities that help the Controller operate the store, only to the extent necessary for the relevant purpose. These may include in particular:

  • hosting, infrastructure, security, CDN and technical analytics providers, including Cloudflare,
  • WordPress/WooCommerce platform and service providers, including Automattic,
  • payment operators and payment method providers, in particular Przelewy24, PayPal, Klarna, PayPo and entities handling selected payment methods,
  • delivery and logistics operators, in particular DPD, GLS, FedEx and InPost,
  • sales, order and integration systems, including Base.com/BaseLinker,
  • analytics, behavioural and advertising tool providers, in particular Google, Meta, TikTok and Microsoft Clarity,
  • automation and artificial intelligence tool providers, including OpenAI, where a store function or administrative process requires such a tool,
  • e-mail, newsletter, SMS notification and form handling providers, including Twilio,
  • accounting office, legal, tax and technical advisers and public authorities where required by law.

The Controller does not sell users' personal data.

§5 Transfers Outside the EEA

Some tools used by the store are provided by entities operating globally. Therefore, data may be transferred outside the European Economic Area, in particular to the United States.

Where such transfer takes place, the Controller relies on GDPR-compliant mechanisms such as an adequacy decision, the EU-US Data Privacy Framework, standard contractual clauses or other safeguards required by law.

§6 Cookies and Similar Technologies

The store uses cookies, local storage and similar technologies. Some of them are necessary for the store, cart, checkout, customer account, security and remembering settings. These technologies are used on the basis of the Controller's legitimate interest and to the extent necessary to provide the service.

Analytics, behavioural, advertising and remarketing cookies are used after obtaining your consent, where such consent is required. This applies in particular to Cloudflare Zaraz/Analytics, Google Analytics/Google Ads, Meta Pixel/CAPI, TikTok, Microsoft Clarity and similar measurement and advertising tools.

You can manage consents in the banner or consent panel displayed in the store. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal. You may also restrict or delete cookies in your browser settings, but this may affect store functionality.

You can also open the cookie consent panel here: .

The store may use first-party and third-party cookies. Example purposes include session maintenance, cart handling, remembering choices, security, analytics, conversion measurement, remarketing and ad personalisation.

Below is a description of the most important cookies and similar identifiers that the Controller knows may be used in the store. The actual list may vary depending on device, country, language, consent choices, payment method, login status and current configuration of external tools.

Name or prefixProviderPurposeCategory
woocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_*Fig&Pear / WooCommerceCart, shopping session and checkout handling.Necessary
wordpress_logged_in_*, wordpress_sec_*, wp-settings-*Fig&Pear / WordPressLogin, account security and user settings.Necessary
woocommerce_recently_viewedFig&Pear / WooCommerceRemembering recently viewed products.Functional
fp_consentFig&PearRemembering refusal of analytics/marketing consents in the Zaraz and WooCommerce order attribution integration.Necessary / privacy preferences
fp_extraFig&PearRemembering traffic source, UTM and campaign information where you have given relevant consent or where processing is used within permitted attribution.Analytics / marketing
nl_em_sha256, nl_country_sha256Fig&PearAuxiliary hashed data used for newsletter signup and newsletter event measurement.Marketing / analytics
sbjs_current, sbjs_first, sbjs_session, sbjs_udata, sbjs_*WooCommerce SourcebusterAttribution of order source, campaign, referrer and session. After consent refusal, the store blocks or removes these cookies when the relevant consent integration is active.Analytics / marketing
cf_clearance, __cf_bm, _cfuvidCloudflareSecurity, abuse protection and traffic management.Necessary / security
cfz_*, cfzs_*, _cfa_*Cloudflare Zaraz / Cloudflare AnalyticsConsent handling, analytics, event measurement and integration of external tools through Zaraz.Analytics / marketing, depending on consent
_ga, _ga_*, _gid, _gcl_*GoogleAnalytics, conversion measurement, Google Ads campaign recognition and ad performance.Analytics / marketing
_fbp, _fbcMetaConversion measurement, remarketing and ad matching in Meta services.Marketing
_ttp, ttclid, tt_sessionId, tt_pixel_session_indexTikTokTikTok ad performance measurement, click attribution and remarketing.Marketing
_clck, _clsk, CLID, ANONCHK, MR, MUID, SMMicrosoft Clarity / MicrosoftBehaviour analytics, session statistics, heatmaps, session recordings and usability diagnostics.Analytics / behavioural
Cookies of payment operators, login providers, forms, maps, captcha or embedded contente.g. Przelewy24, PayPal, Klarna, PayPo, Google, Cloudflare, Automattic or other providers used in a given viewPayment processing, deferred payments, form security, anti-spam protection, embedded content or external functions.Necessary, functional or marketing - depending on the service

§7 Profiling and Advertising

If you consent to marketing, analytics or behavioural cookies, data about your activity in the store may be used to measure ad effectiveness, analyse website use, create audiences, run remarketing and adjust advertising communication in systems such as Google, Meta, TikTok and Microsoft Clarity.

The store may also show product recommendations, content or messages adapted to country, language, order history, viewed products, cart or previous communication. Where recommendations rely on analytics or marketing cookies, they are used after obtaining the relevant consent.

These activities do not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.

§8 User Rights

You have the right to access data, rectify data, erase data, restrict processing, data portability, object to processing based on legitimate interest, withdraw consent at any time and lodge a complaint with the President of the Polish Personal Data Protection Office. Information about deleting a Fig&Pear Member account is available here: https://figandpear.com/en/delete-account/.

Requests concerning data may be sent to shop@figandpear.com or through the contact form: https://figandpear.com/en/contact/.

§9 Voluntary Provision of Data

Providing data is voluntary, but may be necessary to enter into and perform a contract, create an account, process an order, delivery, payment, return, complaint or enquiry. Failure to provide data required in a given form may prevent the relevant action from being completed.

§10 Data Security

The Controller uses organisational and technical data protection measures appropriate to the risk, in particular access control, encrypted transmission, infrastructure safeguards, backups and tools limiting abuse and unauthorised access. Access to data is granted only to persons and entities that need it for the described purposes.

§11 Changes to this Privacy Policy

This Privacy Policy may be updated, in particular if laws, store functions or tools used change. The current version is published on this page.