Privacy Policy
Last updated: 18 July 2026
This Privacy Policy explains how [COMPANY LEGAL NAME], [company registration number / EIK], registered at [registered business address], Bulgaria ("FigForge", "we", "us") collects, uses, shares, and protects personal data when you use the FigForge website and app (the "Service"). We are the data controller for the personal data described below.
If you have questions or want to exercise any of the rights described here, contact us at [privacy contact email].
1. Data we collect
Account data. When you register, we collect your full name, email address, and password (handled by our authentication provider, Supabase — we never see your plaintext password). If you sign up with the marketing checkbox, or opt in later, we record that consent and the date it was given.
Profile data. Username, avatar image (if you upload one), and — if you place a physical order — your shipping name, address, city, postal code, and country.
Payment data. Card details are entered directly into Stripe's secure payment form and processed by Stripe; we never receive or store your full card number. We keep a record of the transaction amount, date, and Stripe's reference for it, needed for receipts, refunds, and accounting.
Content you create. Text prompts, uploaded photos, and the 3D models and images generated from them. If you upload a photo to generate a 3D model, that source photo is automatically deleted from our storage once the 3D model has been generated — we don't keep a long-term copy of the photo itself. Files you upload directly (e.g. an existing 3D model) are kept for as long as your account holds that design.
Order and coin history. Records of print/shop orders, coin purchases and spending, and subscription billing history, needed to provide the Service and required for accounting/tax purposes.
Communications. Messages you send us via the contact form (name, email, subject, message, and — if provided — the related order/design), and email delivery/engagement data from our email provider (e.g. whether a transactional or marketing email was delivered).
Usage and technical data. IP address (used transiently for abuse/rate-limiting and security, via our rate-limiting provider), browser/device information, and — only if you accept analytics cookies via our cookie banner — page views and in-app events, collected through our analytics provider.
Marketing preference. Whether you've opted in to marketing email and when, and whether you've since unsubscribed.
Referral data. If you arrive via a marketing link, we may store the campaign source/medium (UTM parameters) associated with your signup.
2. How we use your data, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) | |---|---| | Creating and managing your account, providing the Service | Performance of a contract | | Generating models, processing print/shop orders, billing subscriptions | Performance of a contract | | Issuing receipts, maintaining accounting/tax records | Legal obligation | | Responding to support/contact requests | Performance of a contract / legitimate interest | | Fraud prevention, rate limiting, abuse detection, securing the Service | Legitimate interest | | Sending transactional emails (order confirmations, receipts, password resets) | Performance of a contract / legal obligation | | Sending marketing emails | Consent (opt-in, withdrawable anytime) | | Analytics cookies / product-usage insights | Consent (opt-in via cookie banner) | | Improving the Service, understanding aggregate usage | Legitimate interest (only where consented analytics data allows this) |
We do not sell your personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects on you.
3. Who we share data with
We share personal data only with service providers who need it to help us run FigForge (our "subprocessors"), under contracts that require them to protect it, and with law enforcement or regulators where legally required. We never sell your data.
| Provider | Purpose | Data involved | |---|---|---| | Stripe | Payment processing, subscription billing | Payment details, billing name/address, transaction data | | Supabase | Database, authentication, and file storage | All account/order/content data described above | | Resend | Sending transactional and (consented) marketing email | Email address, name, email content | | Tripo3D | AI 3D-model generation | Your prompts, uploaded photos (transiently), generated model data | | Black Forest Labs (FLUX) | AI image generation | Your prompts, uploaded photos (transiently) | | Cloudflare (Turnstile) | Bot/spam protection on forms | Technical/device signals, no personal profile | | Upstash | Rate limiting and abuse prevention | IP address (transient) | | PostHog | Product analytics (only if you accept analytics cookies) | Page views, in-app events, anonymised where possible | | Telegram | Internal admin notifications (e.g. new order/signup alerts sent to our own team) | Order/signup summary data — not accessible to Telegram beyond message delivery | | Vercel | Application hosting | Standard web request/traffic data |
International transfers
Some of these providers may process data outside the EU/EEA. Where that's the case, we rely on the provider's own adequacy certification, the EU Standard Contractual Clauses, or another legally recognised transfer mechanism to protect your data.
4. Cookies and similar technologies
We use:
- Strictly necessary cookies — to keep you signed in and secure your session. These can't be switched off, as the Service can't function without them.
- Functional storage — to remember your language preference.
- Analytics cookies (PostHog) — only set if you click "Accept" on our cookie banner. You can decline, or change your mind anytime by clearing site data and revisiting; declining doesn't affect any other part of the Service.
5. Data retention
We keep personal data only as long as necessary for the purposes above:
- Account data — for as long as your account is active.
- Order, receipt, and invoice records — retained for the period required by applicable Bulgarian accounting and tax law (generally several years), even after you delete your account (see below).
- Uploaded source photos used for 3D generation — deleted automatically once generation completes.
- Contact form messages — retained for as long as needed to resolve your enquiry and for a reasonable period afterwards for record-keeping (typically up to 3 years).
- Marketing consent records — retained to demonstrate compliance with consent requirements, even if you later unsubscribe.
What happens when you delete your account
Deleting your account (from Settings) anonymises your personal information — your name, email, avatar, and shipping details are permanently cleared and your login is disabled — rather than deleting every database row outright. We do this because order, receipt, and subscription-invoice records must be retained, by law, for accounting and tax purposes regardless of account deletion; once your personal identifiers are removed from them, those records no longer identify you. Your generated designs, likes, and ratings remain associated with the anonymised account (shown, where applicable, without your name) unless you've already deleted or unpublished them.
To prevent repeated abuse of promotional credit (such as a new-account coin bonus) via delete-and-resignup cycles, we also retain a one-way cryptographic hash of the deleted account's email address, indefinitely. This hash cannot be reversed to reveal your email address and is used solely to recognise a matching future signup — nothing else.
6. Your rights (GDPR)
If you are in the EU/EEA (or another jurisdiction with similar rights), you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data (most of this you can edit yourself in Settings);
- Erase your data — exercised via account deletion (§5 explains the limited retention that survives for legal reasons);
- Restrict or object to certain processing, including direct marketing (you can object to marketing at any time, with immediate effect);
- Port your data to another service, in a structured, machine-readable format;
- Withdraw consent at any time, where processing is based on consent (this won't affect processing carried out before withdrawal);
- Lodge a complaint with your local data protection supervisory authority — in Bulgaria, the Commission for Personal Data Protection (Комисия за защита на личните данни, cpdp.bg).
To exercise any of these rights, email [privacy contact email]. We may need to verify your identity before acting on a request, and some requests (e.g. full erasure of financial records) may be legally limited as explained above.
7. Children's privacy
The Service is not directed at, and we do not knowingly collect personal data from, children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
8. Security
We use industry-standard measures to protect your data, including encryption in transit (TLS) and at rest, role-based access controls limiting staff access to what's needed for their role, and secure, tokenized payment processing via Stripe. No system is completely secure; if we become aware of a data breach affecting your personal data, we will notify affected users and, where legally required, the relevant supervisory authority, within the timeframes required by law.
9. Changes to this policy
We may update this Privacy Policy from time to time. We'll update the "Last updated" date above and, for material changes, make reasonable efforts to notify active users.
10. Contact
For any privacy question or to exercise your rights: [privacy contact email], or by post at [registered business address].