This Privacy Policy describes how personal data is processed and how cookies and similar technologies are used in the Fig&Pear online store available at https://figandpear.com.
It applies to the store, customer account, contact forms, newsletter, notifications, order handling, returns, complaints and communication carried out by the Controller online, including on social media.
§1 Data Controller
The controller of personal data is Diana Świtajewska, operating under the Fig&Pear brand, address: ul. Kazimierza Pułaskiego 97, 18-400 Łomża, Poland, VAT ID: PL7181993869, REGON: 522994143, e-mail: shop@figandpear.com.
For matters concerning personal data, you may contact the Controller by e-mail or through the contact form: https://figandpear.com/en/contact/.
The Controller has not appointed a Data Protection Officer.
§2 What Data We Process
The scope of data depends on how you use the store. We may process in particular:
- identification and contact data: name, company name, VAT ID, e-mail address, telephone number, delivery address and billing address,
- customer account data: login, e-mail address, order history and account settings,
- data relating to orders, payments, delivery, returns, complaints and correspondence,
- technical data: IP address, cookie identifiers, session identifiers, device type, browser, operating system, approximate location derived from technical data, referring page and information about activity in the store,
- marketing and analytics data, if you have given the relevant consent.
We receive data directly from you, from the operation of the store and the technologies used, from providers handling payments, delivery, login, forms or analytics tools, and from your public activity on our social media profiles. Based on order history, viewed products, traffic sources, clicks and similar information, we may create auxiliary inferences, for example about preferred products, language, delivery country or campaign effectiveness, where we have a legal basis to do so.
§3 Purposes, Legal Bases and Retention
| Purpose | Legal basis | Retention period |
|---|---|---|
| Handling orders, payments, delivery, returns and complaints | Article 6(1)(b) GDPR - performance of a contract or steps before entering into a contract | for the duration of contract performance and then for the period needed to handle returns, complaints, statutory warranty, commercial warranty, chargebacks and legal claims; some data may be retained longer where accounting, tax or legal duties require it |
| Accounting, tax and settlement obligations | Article 6(1)(c) GDPR - legal obligation | for the period required by law, usually 5 tax years |
| Customer account management | Article 6(1)(b) GDPR | until the account is deleted and then for the period necessary to defend claims or comply with legal obligations |
| Customer contact and enquiry handling | Article 6(1)(f) GDPR - legitimate interest in handling correspondence | for the duration of the matter and then for the period necessary to defend claims |
| Newsletter, marketing notifications and back-in-stock alerts, where you subscribed to the service | Article 6(1)(a) GDPR - consent; for defending claims also Article 6(1)(f) GDPR | until consent is withdrawn or you unsubscribe, and then for the period needed to prove consent |
| Cart reminders, product recommendations, surveys, review requests and similar after-sales communication | Article 6(1)(f) GDPR - legitimate interest in customer service, satisfaction research and promotion of our own similar products; where required by law - consent | until you object, withdraw consent or the communication purpose ends |
| Analytics, ad effectiveness measurement, remarketing and ad personalisation | Article 6(1)(a) GDPR - consent to cookies, analytics or marketing | until consent is withdrawn, cookies are deleted or for the period set by a given tool |
| Operating social media profiles and handling messages, comments, reactions and ad campaigns in those services | Article 6(1)(f) GDPR - legitimate interest in communication, brand promotion and effectiveness analysis | for as long as data is available in the relevant service, for the time needed to handle the matter or until objection, where applicable |
| Store security, fraud prevention, technical diagnostics and claim protection | Article 6(1)(f) GDPR - Controller's legitimate interest | for the period necessary for the purpose, usually until claims expire or diagnostics are completed |
§4 Recipients and Services Used
Data may be shared with entities that help the Controller operate the store, only to the extent necessary for the relevant purpose. These may include in particular:
- hosting, infrastructure, security, CDN and technical analytics providers, including Cloudflare,
- WordPress/WooCommerce platform and service providers, including Automattic,
- payment operators and payment method providers, in particular Przelewy24, PayPal, Klarna, PayPo and entities handling selected payment methods,
- delivery and logistics operators, in particular DPD, GLS, FedEx and InPost,
- sales, order and integration systems, including Base.com/BaseLinker,
- analytics, behavioural and advertising tool providers, in particular Google, Meta, TikTok and Microsoft Clarity,
- automation and artificial intelligence tool providers, including OpenAI, where a store function or administrative process requires such a tool,
- e-mail, newsletter, SMS notification and form handling providers, including Twilio,
- accounting office, legal, tax and technical advisers and public authorities where required by law.
The Controller does not sell users' personal data.
§5 Transfers Outside the EEA
Some tools used by the store are provided by entities operating globally. Therefore, data may be transferred outside the European Economic Area, in particular to the United States.
Where such transfer takes place, the Controller relies on GDPR-compliant mechanisms such as an adequacy decision, the EU-US Data Privacy Framework, standard contractual clauses or other safeguards required by law.
§6 Cookies and Similar Technologies
The store uses cookies, local storage and similar technologies. Some of them are necessary for the store, cart, checkout, customer account, security and remembering settings. These technologies are used on the basis of the Controller's legitimate interest and to the extent necessary to provide the service.
Analytics, behavioural, advertising and remarketing cookies are used after obtaining your consent, where such consent is required. This applies in particular to Cloudflare Zaraz/Analytics, Google Analytics/Google Ads, Meta Pixel/CAPI, TikTok, Microsoft Clarity and similar measurement and advertising tools.
You can manage consents in the banner or consent panel displayed in the store. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal. You may also restrict or delete cookies in your browser settings, but this may affect store functionality.
You can also open the cookie consent panel here: .
The store may use first-party and third-party cookies. Example purposes include session maintenance, cart handling, remembering choices, security, analytics, conversion measurement, remarketing and ad personalisation.
Below is a description of the most important cookies and similar identifiers that the Controller knows may be used in the store. The actual list may vary depending on device, country, language, consent choices, payment method, login status and current configuration of external tools.
| Name or prefix | Provider | Purpose | Category |
|---|---|---|---|
woocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_* | Fig&Pear / WooCommerce | Cart, shopping session and checkout handling. | Necessary |
wordpress_logged_in_*, wordpress_sec_*, wp-settings-* | Fig&Pear / WordPress | Login, account security and user settings. | Necessary |
woocommerce_recently_viewed | Fig&Pear / WooCommerce | Remembering recently viewed products. | Functional |
fp_consent | Fig&Pear | Remembering refusal of analytics/marketing consents in the Zaraz and WooCommerce order attribution integration. | Necessary / privacy preferences |
fp_extra | Fig&Pear | Remembering traffic source, UTM and campaign information where you have given relevant consent or where processing is used within permitted attribution. | Analytics / marketing |
nl_em_sha256, nl_country_sha256 | Fig&Pear | Auxiliary hashed data used for newsletter signup and newsletter event measurement. | Marketing / analytics |
sbjs_current, sbjs_first, sbjs_session, sbjs_udata, sbjs_* | WooCommerce Sourcebuster | Attribution of order source, campaign, referrer and session. After consent refusal, the store blocks or removes these cookies when the relevant consent integration is active. | Analytics / marketing |
cf_clearance, __cf_bm, _cfuvid | Cloudflare | Security, abuse protection and traffic management. | Necessary / security |
cfz_*, cfzs_*, _cfa_* | Cloudflare Zaraz / Cloudflare Analytics | Consent handling, analytics, event measurement and integration of external tools through Zaraz. | Analytics / marketing, depending on consent |
_ga, _ga_*, _gid, _gcl_* | Analytics, conversion measurement, Google Ads campaign recognition and ad performance. | Analytics / marketing | |
_fbp, _fbc | Meta | Conversion measurement, remarketing and ad matching in Meta services. | Marketing |
_ttp, ttclid, tt_sessionId, tt_pixel_session_index | TikTok | TikTok ad performance measurement, click attribution and remarketing. | Marketing |
_clck, _clsk, CLID, ANONCHK, MR, MUID, SM | Microsoft Clarity / Microsoft | Behaviour analytics, session statistics, heatmaps, session recordings and usability diagnostics. | Analytics / behavioural |
| Cookies of payment operators, login providers, forms, maps, captcha or embedded content | e.g. Przelewy24, PayPal, Klarna, PayPo, Google, Cloudflare, Automattic or other providers used in a given view | Payment processing, deferred payments, form security, anti-spam protection, embedded content or external functions. | Necessary, functional or marketing - depending on the service |
§7 Profiling and Advertising
If you consent to marketing, analytics or behavioural cookies, data about your activity in the store may be used to measure ad effectiveness, analyse website use, create audiences, run remarketing and adjust advertising communication in systems such as Google, Meta, TikTok and Microsoft Clarity.
The store may also show product recommendations, content or messages adapted to country, language, order history, viewed products, cart or previous communication. Where recommendations rely on analytics or marketing cookies, they are used after obtaining the relevant consent.
These activities do not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
§8 User Rights
You have the right to access data, rectify data, erase data, restrict processing, data portability, object to processing based on legitimate interest, withdraw consent at any time and lodge a complaint with the President of the Polish Personal Data Protection Office. Information about deleting a Fig&Pear Member account is available here: https://figandpear.com/en/delete-account/.
Requests concerning data may be sent to shop@figandpear.com or through the contact form: https://figandpear.com/en/contact/.
§9 Voluntary Provision of Data
Providing data is voluntary, but may be necessary to enter into and perform a contract, create an account, process an order, delivery, payment, return, complaint or enquiry. Failure to provide data required in a given form may prevent the relevant action from being completed.
§10 Data Security
The Controller uses organisational and technical data protection measures appropriate to the risk, in particular access control, encrypted transmission, infrastructure safeguards, backups and tools limiting abuse and unauthorised access. Access to data is granted only to persons and entities that need it for the described purposes.
§11 Changes to this Privacy Policy
This Privacy Policy may be updated, in particular if laws, store functions or tools used change. The current version is published on this page.
