Privacy Policy

Last updated: March 14, 2026

Who this policy applies to

This Privacy Policy explains how GPG Figureworks, a Bulgaria-based business, handles personal data when you use the storefront, create an account, place an order, subscribe to the newsletter, or contact us for support.

This policy reflects how the store currently operates. It is intended to be practical and transparent about the personal-data flows used to run the business.

What we collect

Account and profile details

If you register or manage an account, we process the information needed to create and secure it, such as your email address, name, password credentials, saved addresses, and related account preferences.

Checkout and order data

When you place an order, we process details such as your name, email address, phone number, billing and shipping addresses, order contents, prices, shipping selections, discounts, order history, and payment status.

Payment data

Card and payment details are handled by Stripe. We do not store full payment card details ourselves. We may receive limited transaction information needed to confirm payment, handle fraud checks, and support your order.

Newsletter and marketing data

If you sign up for the newsletter, we process your email address, selected market, confirmation status, opt-in timestamps, unsubscribe status, and related delivery state such as bounce or complaint events. Double opt-in confirmation, delivery, and unsubscribe handling are supported through our backend systems and Resend.

Contact and support messages

If you use the contact form or email us directly, we process your name, email address, subject line, and the contents of your message so we can respond and keep a record of the inquiry.

Technical, session, and preference data

Like most online stores, we also process technical data needed to run the site, such as IP address, browser and device information, session and authentication tokens, cart state, market selection, and cookie preferences.

How we use your data

  • To create and manage your customer account
  • To process orders, payments, and shipping
  • To send order, account, password reset, verification, and support emails
  • To run the newsletter signup, confirmation, and unsubscribe flow
  • To respond to contact requests and customer support issues
  • To prevent fraud, abuse, and unauthorized access
  • To operate, secure, and improve the storefront and backend systems
  • To keep records required for tax, accounting, and legal compliance

Depending on the context, we rely on contract performance, legal obligations, legitimate interests, and your consent, especially for newsletter marketing and optional cookie choices.

Cookies and similar technologies

The storefront uses essential cookies and similar storage mechanisms to keep the site functional. These include things like sign-in and session handling, cart and checkout continuity, market selection, and security-related behavior.

We also store your cookie consent preferences. The site presents choices for essential, preference, analytics, and marketing categories. Essential functions stay on because the store would not work without them. Optional analytics or marketing behavior should only be enabled after consent.

Who we share data with

We do not sell your personal information. We share data only where needed to run the store or comply with legal obligations, for example with:

  • payment providers such as Stripe
  • email delivery and newsletter providers such as Resend
  • hosting, infrastructure, and database providers that keep the storefront running
  • shipping or logistics partners where needed to fulfill an order
  • professional advisers or public authorities where legally required

How long we keep data

We keep personal data only for as long as it is reasonably needed for the purpose it was collected, including account management, order fulfillment, support, bookkeeping, fraud prevention, and legal compliance.

  • account and order records may be kept for operational and legal reasons
  • contact messages may be kept for follow-up and customer service history
  • newsletter records may be kept until you unsubscribe, or longer in a limited suppression form if needed to respect opt-out, bounce, or complaint status

Your rights

If applicable under EU or other privacy law, you may have the right to request access to your personal data, correction of inaccurate data, deletion, restriction, objection to certain processing, or withdrawal of consent for marketing.

You can also unsubscribe from the newsletter at any time and adjust optional cookie preferences through the site banner.

If you want to make a privacy request, email hello@gpgfigureworks.com or use our contact page.

Security

We use technical and organizational measures intended to protect personal data used by the storefront and backend systems. However, no online service can guarantee absolute security, and you should also protect your own account credentials and devices.

Related policies and contact

For more on how orders, cancellations, refunds, and replacements are handled, please review our Terms of Service and Refund & Replacement Policy. If you need help with a privacy question, contact us at hello@gpgfigureworks.com or through the contact page.