Skip to content
Your browser is out-of-date.
To get the best experience using our site, you’ll need to update to a newer browser.

The FIGS Privacy Policy applicable to U.S. consumers can be found here

FIGS NON-U.S. Privacy and Cookie Policy

Welcome to the FIGS Website (www.wearfigs.com together with any mobile applications available in your jurisdiction, the “Site”), a Site operated by FIGS, Inc., 2834 Colorado Ave, Suite 100 Santa Monica, CA 90404 United States (“FIGS”, “we”, “us”, or “our”).

If you’re reading this, you know that our Site provides users with an opportunity to learn more about and purchase high quality medical apparel (such apparel, our “Products”). We developed this privacy and cookie policy (“Privacy Policy”) to explain how we collect, use, and disclose information about you, whether you are simply visiting our Site, making a purchase, or otherwise interacting with us, as well as your rights and choices regarding such information.

So we are clear about the terminology we are using, when we use the phrase “Personal Information” in this Privacy Policy, we mean any information relating to an identified or identifiable individual, which includes information about an individual that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an individual. This could include name, identification numbers, location data, online identifiers, or factors specific to physical, physiological, mental, economic, cultural or social identity. Personal Information may also include sensitive information such as racial or ethnic origin or health information.

Your use of the site is governed by our Terms of Use applicable to your jurisdiction. If you are a consumer resident within Australia, Canada, EU, Israel, New Zealand or UK, please follow this link to access the Terms of Use that apply to you. If you are a consumer resident outside of the U.S., Australia, Canada, EU, Israel, New Zealand or UK, please follow this link to access the Terms of Use that apply to you. In the process of registering for an account, you are required to accept and agree to be bound by our Non-U.S. Terms of Use in order to complete registration. When you use the site, our collection, use and disclosure practices, and other activities in respect of your Personal Information is as described in this Privacy Policy.

If you have any questions or wish to exercise your rights and choices, please contact us as set out in the “Contact Us” section.

Joint Controllership Statement – FIGS and Global-e

Since we are a US-based business, we have partnered with a cross-border e-commerce provider Global-e US, Inc. (“Global-e”) which operates through its local affiliates in countries across the globe (for a full list of relevant affiliates see Global-e’s Privacy Policy) to ensure effective delivery of our Products to you in your location. We have integrated Global-e’s technical platform into the Site via an Application Programming Interface (“API”) for this purpose, and we co-operate with Global-e through the use of online portals.

In some (but not all) scenarios where we or Global-e are processing your Personal Information, FIGS and Global-e are “joint controllers” for the purposes of applicable data protection laws. This means that in those scenarios, FIGS and Global-e are working together to make decisions about why and how your Personal Information is processed and we are jointly responsible under data protection laws for that processing.

When are we joint controllers?

FIGS and Global-e are joint controllers in the following scenarios:

  • Site localisation and insights: Global-e places tracking technologies on the Site which (i) recognise your location from your Internet Protocol (“IP”) address (a number that is automatically assigned to your device when you use the Internet, which may vary from session to session) and localise aspects of the Site (e.g. the pricing of our Products) so that it is easier for you to use in your location; and (ii) analyse your use of the Site and provides FIGS with insights based on this analysis for FIGS to use for quality improvement and trend analysis purposes. For more information about these uses of cookies, see the “Analytics, Advertising, and other Tracking Technologies” section below and Global-e’s own Privacy Policy. FIGS does not use the insights received from Global-e to identify you as an individual
  • Sales process:When you purchase one of our Products, Global-e manages the checkout page and shares certain Personal Information it collects with FIGS, allowing FIGS to manage the packaging of your order and, if applicable, review and execute refund requests.
    FIGS and Global-e also deal with any complaints, disputes and customer service requests together. In addition, Global-e will share with FIGS your opt-in consent for the purposes of FIGS’ direct marketing (but not Global-e’s).

Our respective responsibilities

FIGS and Global-e have an arrangement in place which allocates responsibilities for the legal obligations arising from processing your Personal Information as joint controllers.

Both parties are responsible for providing you with information about the processing (including each party’s legal basis for processing your Personal Information), and for complying with the key principles of data protection law (including keeping your Personal Information secure).

FIGS and Global-e will respond to any data subject rights requests you submit in accordance with the “Who you can contact” section below. If there is a data breach, Global-e will notify you and the relevant regulator (if required) where the breach relates to its placement of Site localisation and insights cookies. If the data breach relates to Personal Information we process on the online portals we use to manage the sales process, the parties will co-operate to decide who sends the response to the regulator and to data subjects

Who you can contact

If you want to exercise any of your rights under data protection laws (see the “Your Data Subject Rights” section below), make a complaint, or ask a question about FIGS or Global-e’s processing as joint controllers, you should contact:

  • Global-e for questions relating to Global-e’s use of cookies, your use of the refund, customer support and returns portals, and the physical delivery of Products to you. Global-e’s contact details are dataprotection@global-e.com and their EU representative is Rickert Rechtsanwaltsgesellschaft mbH, Colmantstraße 15, 53225 Bonn, art-27-rep-global-e@rickert.law.
  • FIGS for questions relating the general operation of the Site and the purchase of our Products other than the elements of the sales process described in the bullet above. Please use the details in the “Contact Us” section below.

When are we not controllers?

FIGS and Global-e are not joint controllers in other scenarios. For example, when FIGS carries out day-to-day maintenance of the Site, sends you marketing, or processes any job application you make, FIGS will be a controller independently of Global-e. Likewise, where Global-e arranges for your payments to be processed, or manages the logistics of delivering Products to you (separately from its co-operation with FIGS through online portals), Global-e will be an independent controller.

Please see the Global-e Privacy Policy for full details of the processing Global-e carries out. Please see the wording below for details about FIGS’ processing.

FIGS as controller of your Personal Information

How We Collect and Hold Information.

Information You Provide.

We collect Personal Information when you use the Site. The categories of information we collect about you include the following:

  • "Contact Data," including your name, email address, postal address, phone number, and similar information about your employer.
  • "Demographic Data,"including your birth date and month (for offering birthday discounts), gender, country, occupation, and student or military status (for offering student or military discounts, if these are available in your jurisdiction). See also the section on “Discounts” below.
  • "Transaction Data," including information about your purchases. Credit card data will be processed separately by Global-e; please refer to the Global-e Privacy Policy for further details.
  • "Profile Data," including your interests, sizing, preferences, and favorites.
  • "Content,", including content within any messages you send to us (such as feedback and questions to customer support) or publicly post on the Site (such as in product reviews).
  • "Referral Data,", including the name and email address of your friend when you use our “Refer a Friend” feature (to the extent we use this feature in your jurisdiction).
  • "Job Application Data,", including your employment and education history, transcript, writing samples, and references.

You may choose to voluntarily provide other information to us that we do not request.

If you do not provide us with certain information we request, we may not be able to provide you with access to or full use of our websites and/or services.

We collect information in the following circumstances, and hold the information in the following ways:

  • Create an Account. You do not have to create an account in order to browse our Site or place an order. If you choose to create an account, we will collect your Contact Data and Demographic Data. Your password is stored with our service providers and we do not have access to it. We strongly recommend that you do not disclose your password to anyone. We will never ask you for your password. We may allow you to store Profile Data and other information through your account.
  • Discounts. On your creation of an account, we may also collect certain Demographic Data which enables us to offer you discounts (where they are available in your jurisdiction), such as birthday discounts, student discounts or military discounts. This information is optional for you to provide, and your student or military status will always be verified by a trusted third party provider and will not be collected directly by us.
  • When you place an order, you will share your Contact Data and Profile Data with Global-e in the first instance, and Global-e will share this information with us. Global-e will manage the processing of your payments. For more information on these points, see the Joint Controllership Statement above.
  • Advertising and Marketing Communications. If you subscribe to our email mailing list or SMS or MMS messaging list (if such service is available in your jurisdiction, we collect your Contact Data (which is initially obtained by Global-e as part of the checkout process and then shared with us) and we may also use any Profile Data you have provided us with to tailor the marketing communications we send to you. If you have consented we may also use your Contact Data and Profile Data to tailor and deliver advertising to you (or people similar to you) on social media platforms (see the section on “Matched Ads” below).
  • Contests and Promotions. When you enter a contest or participate in a promotion, we collect your Contact Data and any additional information or content required for the contest or promotion. These contests and promotions are voluntary. We recommend that you read the rules for each contest and promotion that you enter.
  • Contact Us. When you contact us with a comment, question or complaint through email, social media, or telephone, you may submit Contact Data along with other information or Content.
  • Surveys and Customer Research. From time to time, we may offer you the opportunity to participate in one of our surveys or other customer research. We may collect your Contact Data and other information you submit.
  • Ambassador Program. When you apply to or participate in our FIGS Ambassador Program, we may collect your Contact Data, Demographic Data, and any additional information or content required for application to or participation in the Ambassador Program. Applying to and participating in the Ambassador Program is voluntary.
  • Refer a Friend. By using this feature (to the extent it is available in your jurisdiction), you acknowledge and agree that you have your friend’s consent for us to use their contact information to fulfil your request and for us to send them an outreach email about our service. We will not send your friend any further emails until they have given us their opt-in consent to marketing.
  • Apply for a Job. When you apply for a job with us, we will collect your Job Application Data as necessary to consider you for job openings
Information Collected Automatically.

In addition, we automatically collect and hold Personal Information when you use the Site. The categories of information we automatically collect include the following:

  • Site Use Data, including data about the features you use, the pages you visit, the searches you make, the Products you view and purchase, the referring/exit pages, the domain name, clickstream data, and the date/time stamp for your visit.
  • Device Connectivity and Configuration Data including data about your browser or device type, your device’s operating system, your Internet service provider (“ISP”), your device’s regional and language settings, your device’s IP address, and other device identifiers.
  • We use various tracking technologies to automatically collect information when you use the Site, including the following:

  • Log Files, which are files that record information automatically in connection with your use of the Site.
  • Cookies, which are small pieces of information stored on your device’s browser that act as a unique tag to identify your browser. We may use both session cookies (which expire once you close your web browser) and persistent cookies (which stay on your device for extended periods of time) to provide you with a more personal and interactive experience on our Site. Cookies allow us to make the Site more useful to you, remember your preferences, support security features, tailor your experience, better understand how you use the Site, and bring you advertising both on and off the Site.
  • Pixels (also known as web beacons), which are pieces of code embedded in a website, video, email, SMS or MMS message or advertisement that sends information about your use to a server. There are various types of pixels, including image pixels (which are small graphic images) and JavaScript pixels (which contains JavaScript code). When you access a website, video, email, SMS or MMS message, or advertisement that contains a pixel, the pixel may permit us or a third party to drop or read cookies on your browser. Pixels are often used in combination with cookies to track activity by a particular browser on a particular device. We use information collected from pixels to analyze trends, administer the Site, track users’ movements around the Site, gather demographic information about our user base as a whole, better tailor our Site to our users’ needs, and bring you advertising both on and off the Site. For example, some of the information may be collected so that when you visit the Site or again, it will recognize you and the information could then be used to serve advertisements and other information appropriate to your interests.
  • Device Fingerprinting, which is the process of analyzing and combining sets of information elements from your device’s browser, such as JavaScript objects and installed fonts, in order to create a “fingerprint” of your device and uniquely identify your browser and device.

For further information on how we use tracking technologies for analytics and advertising (including the cookies we use which are placed by Global-e as part of our partnership with them as described in the Joint Controllership Statement), and your rights and choices regarding them, see the “Analytics, Advertising, and other Tracking Technologies” and “Your Rights and Choices” sections below.

Information from Other Sources.

We also collect and hold Personal Information from other sources. The categories of other sources from which we collect include the following:

  • Data brokers or resellers from which we purchase data to supplement the data we collect.
  • Social networks when you engage with our content, reference our Site, or grant us permission to access information from the social networks.
  • Partners that offer co-branded services, sell or distribute our products, or engage in joint marketing activities. This includes the information that is shared with us by Global-e as part of our partnership with them as described in the Joint Controllership Statement.
  • Customers in connection with us processing their transactions and purchases.
  • Information you have made public, such as information you have posted as part of a review on our Site.

How We Use Information.

We collect, hold and use the Personal Information we collect for business and commercial purposes in accordance with the practices described in this Privacy Policy. Our business purposes for collecting, holding and using information when you use the Site include the following:

  • Operating and managing our Site.
  • Fulfilling your purchases of our Products.
  • Performing services requested by you, such as responding to your comments, questions, and requests, and providing customer service, in collaboration with Global-e.
  • Sending you technical notices, updates, security alerts, information regarding changes to our policies, and support and administrative messages (which will either be sent by us or by Global-e on our behalf).
  • Preventing and addressing breach of policies or terms, and threats or harm.
  • Monitoring and analysing trends, usage, and activities, including aggregating or de-identifying information for these purposes.
  • Conducting research, including focus groups and surveys.
  • Improving and customizing the Site and our other websites, apps, marketing efforts, products and services.
  • Evaluating whether you are a good match for our Ambassador Program and to administer the benefits of the program.
  • Developing and sending you direct marketing, including advertisements and communications about our and other party products, offers, promotions, rewards, discounts, events, and services.
  • Administering your participation in a contest or promotion, including to deliver a prize to you if you are the winner.
  • Providing you advertising.
  • Fulfilling any other business or commercial purposes at your direction or with your consent.
  • Notwithstanding the above, we may use information which is no longer Personal Information under applicable data protection law in your jurisdiction (including, to the extent it falls within such a definition, information that has been aggregated or de-identified as per the above) for any purpose except as prohibited by applicable law.

For information on your rights and choices regarding how we use information about you, please see the “Your Rights and Choices” section below.

Our Legal Basis for Processing.

We rely on different legal bases for collecting and processing your Personal Information, which may include (depending on the circumstances and the requirements of law that apply in the circumstances): (i) as necessary to perform or take steps prior to entering into a contract (e.g., processing and fulfilling purchases, applying discounts to your purchases, administering your participation in contests and promotions, including to deliver a prize to you if you are the winner and performing services requested by you); (ii) as necessary to comply with a legal obligation (e.g., sending you information regarding changes to our policies, responding to data subject rights requests, and preventing and addressing breach of policies or terms and threats or harm); (iii) consent (where you have provided consent as appropriate under applicable law, such as monitoring and analysing trends, usage and activities, providing you with advertising and customizing our marketing efforts, developing and sending you direct marketing, including advertisements and communications about our and other party products, surveys and customer research, offers, promotions, rewards, events, and services, evaluating whether you are a good match for our Ambassador Program and to administer the benefits of the program), and where consent is otherwise required under applicable law; and (iv) as necessary for our legitimate interests.

With respect to our legitimate interests, where applicable, except where such interests are overridden by the interests or fundamental rights and freedoms of you that require protection of Personal Information, such legitimate interests include operating and managing our Site, sending you technical notices, updates, security alerts, and support and administrative messages, responding to and engaging in customer service telephone calls and (in each case only to the extent we are not legally required to obtain your consent to do so): monitoring and analysing trends, usage and activities, conducting research, improving and customizing the Site and our other websites, apps, products and services, developing and sending you some forms of direct marketing, including advertisements and communications about our and other party products, offers, promotions, rewards, events, and services, and fulfilling any other business or commercial purposes at your direction

How We Share Information.

We share the Personal Information we collect in accordance with the practices described in this Privacy Policy. The categories of entities to whom we disclose include the following:

  • Service Providers. Your information may be transferred to service providers who process the information on our behalf, including service providers that host the Site, help with technical support, verify your eligibility for certain discounts, and provide analytics, advertising, and marketing services. Our service providers are only provided with the information they need to perform their designated functions and are not authorized to use or disclose the information for their own marketing or other purposes, although we may permit them to use information which is no longer Personal Information under applicable data protection law in your jurisdiction (including, to the extent it falls within such a definition, information that has been aggregated or de-identified) for any purpose except as prohibited by applicable law. Our service providers may be located in the U.S., Canada, E.U. or other foreign jurisdictions.
  • Analytics and Advertising Technology-Related Vendors and Companies. We share analytics and advertising information with vendors and other companies who facilitate our use of analytics and advertising technology including ad exchange platforms, and social media and search engine providers who advertise our products. Vendors may act as our service providers, or in certain contexts, independently decide how to process your information. For more information on advertising and analytics, see the “Analytics, Advertising, and other Tracking Technologies” section below.
  • Affiliates. To a parent company, any subsidiaries, joint ventures, or other companies under a common control (collectively, “Affiliates”), in the event we have such Affiliates in the future, in order to facilitate the provision of our products to you and to meet our compliance obligations under applicable law.
  • Partners. We share information with our partners in connection with offering co-branded services, selling or distributing our products, providing promotions, or engaging in joint marketing activities. These partners include Global-e, who we co-operate with in accordance with our Joint Controllership Statement.
  • Legal and Compliance. We disclose your information to (i) comply with relevant laws or to respond to requests from public authorities or public entities, law enforcement, regulatory bodies or other government officials relating to investigations or alleged illegal activity (if the request is lawfully made and legally binding), or in response to a subpoena, a search warrant or other legally valid inquiry or order (in each case if lawfully made and legally binding); or (ii) another organization to the extent necessary to investigate a breach of an agreement or contravention of law, or to protect and defend our rights or property or the rights and property of you or third parties.
  • Sale of Business. We may transfer any information we have about you as an asset in connection with a proposed or completed merger, acquisition or sale (including transfers made as part of insolvency or bankruptcy proceedings) involving all or part of FIGS or as part of a corporate reorganization or other change in corporate control.
  • Facilitating Requests. We share information at your request or direction, such as when you use our “Refer a Friend” feature.
  • Consent. We share information in accordance with your consent if you have provided us consent to share information.

Notwithstanding the above, we may disclose information which is no longer Personal Information under applicable data protection law in your jurisdiction (including, to the extent it falls within such a definition, information that has been aggregated or de-identified) except as prohibited by applicable law.

For information on your rights and choices regarding how we share information about you, please see the “Your Rights and Choices” section below.

Social Media and Technology Integrations.

Most browsers accept cookies by default. You can instruct your browser, by changing its settings, to decline or delete cookies. If you use multiple browsers on your device, you will need to instruct each browser separately. Your ability to limit cookies is subject to your browser settings and limitations.

We offer parts of our Site through websites, platforms, and services operated or controlled by separate entities. In addition, we integrate technologies operated or controlled by separate entities into parts of our Site. Some examples include:

  • Links. The Site contains links to other websites that are not owned or controlled by us, including our partner sites and social media websites. These links are not intended as an endorsement of or referral to the linked websites. When you click on such a link, you will leave our Site and go to another site. The linked websites have separate and independent privacy policies, notices and terms of use.
  • Brand Pages and Chatbots. We may offer our content through social media. Any information you provide to us when you engage with our content (such as through our brand page on Facebook or Instagram or via our chatbot on Facebook Messenger) is treated in accordance with this Privacy Policy. In particular, we use the statistical information relating to the use of our brand page on Facebook that Facebook makes available via its “Insights” service in an anonymised form – see here for more information. FIGS is a joint controller with Facebook for these purposes and has entered into a joint controller arrangement with Facebook in order to allocate the parties’ responsibilities under the GDPR between them – see the agreement here, which also contains information about who you can contact and how you can exercise your data subject rights. Also, if you publicly reference our Site on social media (e.g., by using a hashtag associated with us in a tweet or post), we may use your reference on or in connection with our Site.

Please note that when you interact with other entities, including when you leave our Site, those entities may independently collect information about you and solicit information from you. We have no control over, do not review and are not responsible for the privacy policies of or content displayed on such other websites, and therefore to the full extent permitted by law, we have no responsibility or liability in any manner for the manner in which the organizations that operate such websites may collect, use or disclose, secure or otherwise treat information. We recommend that you review the privacy policy of any other website you visit.

Analytics, Advertising, and other Tracking Technologies.

Our analytics and advertising activities

We use tracking and analytics services such as Google Analytics and the insights service offered by Global-e (see the Joint Controllership Statement above for further detail) to track and analyze how visitors use our Site.

In addition, we work with agencies, ad networks, and other advertising companies to place ads for our products on other websites and services. For example, we place ads through Google and Facebook that you may view on their platforms as well as on other websites and services.

Use of analytics and advertising tracking technologies

As part of this process, we may incorporate tracking technologies (including cookies and pixel tags) on our Site in order to provide you with tailored advertisements across the Internet and in order to help us improve or optimise the experience we provide, including by measuring how you interact with the Site and other technical information about your use of the Site. For a detailed summary of the tracking technologies we use and for further information from third parties about the tracking technologies they place on our Site, please see the table in the Appendix which is accessible here. In respect of the Global-e and Google Analytics tracking technologies referenced above, you can visit the following additional sources of information:

Some of these tracking technologies may collect information about your activity across time and services (including on our Site and other websites such as web pages you visit and your interaction with our advertising and other communications) and use this information to make predictions about your preferences, develop personalized content, compile reports and deliver ads that are more relevant to you on other websites (“Interest-based Advertising”). This information may also be used to evaluate the effectiveness of our online advertising campaigns.

We also use audience matching services to reach people (or people similar to people) who have visited our Site or are identified in one or more of our databases (“Matched Ads”). This is done by us uploading a customer list to a technology service (for example a social media or search engine company) or incorporating a pixel or other tracking technology from a technology service into our own Site, and the technology service matching common factors between our data and their data. For instance, we may incorporate the Facebook pixel on our Site and may share your email address with Facebook as part of our use of Facebook Custom and Lookalike Audiences. When Facebook receives this information it uses it to display relevant ads to you (or people similar to you which it has identified). Similarly, we may also incorporate Google pixel tags into our Site which result in relevant ads being displayed to you (or people similar to you) when certain keywords are searched for on Google.

Information about Facebook’s right to use the information it collects through the Facebook pixel and Facebook Custom and Lookalike Audiences can be found as part of Facebook’s Privacy Policy. FIGS will be a joint controller with Facebook in respect of the Personal Information collected by the Facebook pixel, and has entered into a joint controller arrangement with Facebook in order to allocate the parties’ responsibilities under the GDPR between them – see the agreement here, which also contains information about who you can contact and how you can exercise your data subject rights. Information about Google’s right to use the information it collects through Google pixel tags can be found as part of Google’s Privacy Policy.

Use of other tracking technologies

We may also use the following types of tracking technologies, in addition to analytics and advertising tracking technologies:

  • Essential – we place these tracking technologies to enable core functionality. If you disable these tracking technologies certain parts of the Site may not function for you, for example, adding items to your basket and proceeding to checkout.
  • Functional – We place these tracking technologies which are not essential, but enable various helpful features on our Site. For example, these tracking technologies collect information about your interaction with the Site and may be used on our Site to remember your preferences (such as your language preference).

For a detailed summary of the tracking technologies we use, please see the table in the Appendix which is accessible here.

Your choices regarding tracking technologies

Please also see the section “Tracking Technology Choices” below regarding consent requirements for the placement of cookies and other tracking technologies.

As indicated above, vendors and other parties may act as our service providers, or in certain contexts, independently decide how to process your information. We encourage you to familiarize yourself with and consult their respective privacy policies and terms of use.

For further information on the types of tracking technologies we use on the Site and your rights and choices regarding analytics, Interest-based Advertising, and Matched Ads, please see the “Information Collected Automatically” and “Your Rights and Choices” sections.

Your Rights and Choices.

Account Information and Ambassador Program.

If you have an account with us or are a member of our Ambassador Program, you may request access to, updating of, or corrections of inaccuracies to any information you have submitted to us through your account or to our Ambassador Program by emailing us at privacy@wearfigs.com. Where we have reasonable doubts, we may request certain information for the purpose of verifying the identity of the individual seeking access to his or her records.

You may also request deletion of information you have submitted to us through your account or to our Ambassador Program, but please note that we may be required (by law or otherwise) to keep this information and not delete it (or to keep this information for a certain time, in which case we will comply with your deletion request only after we have fulfilled such requirements). When we delete information, it will be deleted from the active database, but may remain in our archives if required by applicable law and subject to appropriate technical and organisational measures. We may also retain information which is no longer Personal Information under applicable data protection law in your jurisdiction (including, to the extent it falls within such a definition, information that has been aggregated or de-identified) about use of our Site and purchase of Products as permitted by applicable law.

Communications.

With your consent, we may send marketing communication to you through various channels, including by email, SMS or MMS message (if available in your jurisdiction) and physical mail.

You can opt out of receiving marketing emails from us at any time by clicking the “Unsubscribe” link at the bottom of each email or emailing us at privacy@wearfigs.com with the word UNSUBSCRIBE in the subject field of the email. Please note that even if you unsubscribe or opt-out, we may still send you transactional, order, Site and Product related communications (e.g., emails related to your orders or comments).

If we offer SMS or MMS messages in your jurisdiction, you can opt out of receiving SMS or MMS messages from us by texting the keyword STOP, END, CANCEL, UNSUBSCRIBE or QUIT to our phone number to cancel. Please visit this link to access our FIGS SMS Terms and Conditions applicable to your jurisdiction.

You can also opt out of receiving physical mail marketing communications by emailing us at privacy@wearfigs.com.

After you opt-out or update your marketing preferences, please allow us sufficient time to process your marketing preferences. Unless otherwise required to process your requests earlier by law, it may take up to 5 business days to process your opt out requests in relation to receipt of electronic marketing materials such as emails, and up to 30 days for all other marketing-related requests.

Tracking Technology Choices.

If you are accessing the Site from the United Kingdom (“UK”) or European Union (“EU”), where legally required, we will request your consent prior to the placement of any functionality, advertising or analytics cookies/other tracking technologies. . In certain other jurisdictions we will also request your consent prior to setting cookies/other tracking technologies and ensure withdrawal of that consent is easily made. You are always able to withdraw your consent to the use of tracking technologies on our Site through accessing the “Non-US Preference Centre” link at the bottom of the Site or emailing us at privacy@wearfigs.com or using other contact details set out in the “Contact Us” section below and specifying the types of tracking technologies you wish to withdraw your consent from.

Most browsers accept cookies by default. As well as being able to adjust your tracking technology settings through the consent management process described above (if applicable), you can instruct your browser, by changing its settings, to decline or delete cookies. If you use multiple browsers on your device, you will need to instruct each browser separately. Your ability to limit cookies in this way is subject to your browser settings and limitations.

Your browser settings may allow you to automatically transmit a “Do Not Track” signal to online services you visit. Note, however, there is no industry consensus as to what site and app operators should do with regard to these signals. We do not monitor or take action with respect to “Do Not Track” signals or other mechanisms. For more information on “Do Not Track,” visit http://www.allaboutdnt.com. Please be aware that if you disable or remove tracking technologies some parts of the Site may not function correctly.

Analytics and Interest-Based Advertising.

In addition to the opt-out functionality offered by the consent management process described above (if applicable), you can withdraw your consent to the processing of certain data collected by Google Analytics, by downloading and installing the browser plug-in available at https://tools.google.com/dlpage/gaoptout.

The companies we work with to provide you with targeted ads are required by us to give you the choice to withdraw your consent to receiving targeted ads. Most of these companies are participants of the Digital Advertising Alliance (“DAA”) and/or the Network Advertising Initiative (“NAI”). For more information about Interest-based Advertising and to understand your options, including how you can opt-out of receiving behavioural ads from participating companies, please visit the DAA website opt-out at http://www.aboutads.info/choices , the DAA of Canada website opt-out at http://youradchoices.ca/choices , or the NAI opt-out at https://www.networkadvertising.org/choices/. Even if you withdraw consent from interest-based advertising by a participant, tracking technologies used on the Site may still collect data for other purposes including analytics depending on the other types of tracking technologies you have consented to, and you may need to separately withdraw your consent to analytics tracking technologies to stop this data collection. You may still see ads from us if you have given your consent to this, but the ads from the participants from whom you have withdrawn your consent will not be targeted based on behavioural information about you and may therefore be less relevant to you and your interests.

Please note that by adjusting your tracking technology/cookie settings through the consent management process described above (if applicable), these changes only apply to the specific web browser you use so you must do so on each web browser on each device you use. To successfully give your consent, you must have cookies enabled in your web browser (see your browser’s instructions for information on cookies and how to enable them). If you delete your browser’s saved cookies, you would need to give your consent to cookies again.

To withdraw your consent from us using your data for Matched Ads, you can either do so using the consent management process described above, or you can contact us as set forth in the “Contact Us” section below and specify that you wish to withdraw your consent from Matched ads. We will request that the applicable technology service not serve you Matched ads based on information we provide to it. Alternatively, you may directly contact the applicable technology service to withdraw your consent.

Beyond our compliance with our own obligations under data protection and privacy laws relating to the provision of an ability to opt out of tracking technologies, we are not responsible for the effectiveness of, or compliance with, any opt out options or programs, or the accuracy of any company statements regarding their opt out options or programs.

Your Data Subject Rights

Where legally required in your jurisdiction, you have the following rights in respect of the Personal Information we process about you:

  • The right to be informed. You have the right to be informed about how and on what basis we process your Personal Information. We have done so through the provision of this Privacy Policy.
  • The right to access. You have the right to request access to or copies of your Personal Information.
  • The right to rectification. You have the right to request that we correct any information you believe is inaccurate or incomplete.
  • The right to erasure. You have the right to request that we erase your Personal Information, under certain conditions.
  • The right to restrict processing. You have the right to request that we restrict the processing of your Personal Information, under certain conditions.
  • The right to object to processing. You have the right to object to our processing of your Personal Information, under certain conditions.
  • The right to data portability. You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
  • The right to withdraw consent. You have the right to withdraw your consent to our processing of your Personal Information at any time where we relied on your consent to process your Personal Information. In some jurisdictions this right may be subject to certain restrictions or limitations. Please note that withdrawal of your consent does not affect our use or processing of your Personal Information prior to your consent being withdrawn.
  • The right to provide us with instructions on the use of your personal data after your death (e.g. retention, erasure and disclosure). You can change or revoke your instructions at any time.

In Australia, under the Australian Privacy Principles contained in the Privacy Act 1988 (Cth), we are required to take the following actions in respect of any Personal Information we hold about you:

  • Take reasonable steps to ensure that the personal information we hold about you is accurate, up-to-date and complete.
  • Take reasonable steps to ensure that the personal information we hold about you is protected from misuse, interference and loss and from unauthorised access, modification and disclosure.
  • If any personal information we hold about you is no longer required by us for any purpose for which the information may be used or disclosed under the law, we will take reasonable steps to destroy the information or ensure that the information is de-identified.
  • Give you access to any information we hold about you at no charge to you.
  • Take reasonable steps to correct any information we hold about you, having regard to the purpose for which it is held, to ensure the information is accurate, up-to-date, complete, relevant and not misleading.

You may contact us as described in the “Contact Us” section below to exercise your rights. Finally, you can always lodge a complaint with your data protection authority if you would feel that we have not acted in accordance with applicable data privacy legislation at the details also set out in the “Contact Us” section below.

Safeguards.

We implement appropriate administrative, technical and physical measures in an effort to safeguard the information in our custody and control against theft, loss and unauthorized access, use, modification and disclosure. Nevertheless, transmission via the internet is not completely secure and we cannot guarantee the security of your information.

International Transfers.

We are based in the U.S. and the information we collect is governed by U.S. law as well as the law of the jurisdiction in which you reside. Please therefore be aware that your information will be processed in the U.S. as well as potentially being disclosed to recipients in other countries. We may disclose personal information outside of the jurisdiction from which it was collected. We may transfer to, hold or access personal information from various countries outside the European Economic Area (“EEA”) or the UK including but not limited to the U.S., Australia, and Canada; as well as within the UK, Germany, Poland, France, Netherlands, Spain, and Italy.

Some of the countries to which data may be disclosed may be countries where data protection laws may be less stringent than the laws in your country or otherwise where an adequacy decision or equivalent has not been granted by the European Commission or the UK government, as applicable. In order to make such transfers, we will implement appropriate technical and organizational safeguards in line with the applicable data protection laws which will generally be the appropriate set of standard contractual clauses (depending on the processing role of the recipient organisation) and the UK addendum to such standard contractual clauses if relevant. If you are based in Australia, prior to disclosing your Personal Information to any overseas recipient, we will take reasonable steps to ensure that the overseas recipient complies with the Australian Privacy Principles.

Access to and Correction of Information.

We will correct, update and/or make our file of your information available to you within a reasonable time from receipt of your request to the contact details as set out in the “Contact Us” section. We will only withhold access where permitted by law.

Retention and Deletion of Information.

Personal information is maintained on secure servers and accessible by authorized employees, contractors and service providers who require access for the purposes described in this Privacy Policy.

We will retain and process your Personal Information only for as long as is necessary for the purposes for which the information is collected, and to the extent necessary to comply with our legal obligations under applicable law.

When we no longer need to use your Personal Information or retain it pursuant to legal obligations in order to exercise our legal rights, we will remove it from our systems and records or take steps to anonymise it so that you can no longer be identified from it in accordance with applicable law. When we delete information, it will be deleted from the active database, but may remain in our archives if required by applicable law and subject to appropriate technical and organisational measures. We may also retain information which is no longer Personal Information under applicable data protection law in your jurisdiction (including, to the extent it falls within such a definition, information that has been aggregated or de-identified) about use of our Site and purchase of Products as permitted by applicable law. We won’t process your Personal Information later on in a manner which is inconsistent with the purpose for which it was originally collected, unless permitted or required by applicable law.

Children.

The Site is not directed to children under the relevant minimum age (or who are otherwise interpreted as “children”) for the purposes of privacy law relating to children which is applicable in each jurisdiction, and we do not knowingly collect personal information from children under such age. If you are a parent or guardian and you believe we have collected personal information from your child, contact us at privacy@wearfigs.com. If we learn that we have collected personal information from a child under the minimum age described above, we will delete the information.

Automated Decision-Making.

We do not use automated decision-making without human intervention, including profiling, in a way that produces legal effects concerning you or otherwise significantly affects you.

Changes to this Privacy Policy.

This Privacy Policy is subject to revision from time to time on a going-forward basis. We will post any revised version of the Privacy Policy on this page. If we make any material changes to it, we will also provide you with additional notice such as sending you notice to the last email address you have provided to us.

Contact Us.

If you have any questions, comments or complaints about this Privacy Policy or the manner in which we handle your personal information, or if you have a disability and would like to access this Privacy Policy in an alternative format, please contact us at privacy@wearfigs.com or by telephone at 424-500-8209.

If you are located in the EEA or the UK and have questions about your personal data or would like to request to access, update or delete it, you may contact our representatives at:

Bird & Bird GDPR Representative Services SRL Avenue Louise 235 1050 Bruxelles Belgium EUrepresentative.FIGS@twobirds.com

Bird & Bird GDPR Representative Services UK 12, New fetter Lane London EC4A 1JP United Kingdom UKrepresentative.FIGS@twobirds.com

If you are located in Canada, you may also contact our Canadian Privacy Officer at dwarner@wearfigs.com.

In most cases, we will ask that you put your request in writing to us. We will investigate your complaint and will respond to you in writing as soon as reasonably possible. If we fail to respond to your complaint or if you are dissatisfied with the response that you receive from us, you might also have the right to make a complaint to the applicable privacy authorities

  • In Australia, this is the Office of the Australian Information Commissioner (www.oaic.gov.au)
  • In Canada, this is the Office of the Privacy Commissioner of Canada (www.priv.gc.ca) or in some cases, the privacy authority in your province of residence
  • In the UK, this is the Information Commissioner’s Office (https://ico.org.uk/)
  • In the EU, see a list of applicable data protection authorities and their contact details here
  • In Germany, the competence for complaints is split among different data protection supervisory authorities and the relevant authority is generally the State Data Protection Authority of the German federal state (Bundesland) you habitually reside in. Competent authorities can be identified according to the list provided here
  • • In the UAE, this is the Data Office which has not yet been established. The details will be updated after the launch of the regulator.

Last updated: November 2, 2022

Appendix: Tracking Technologies Table

Third-Party Cookies

 Cookie

Expiration (up to…)

Platform

Third-Party Cookie Partner

Third-Party Cookie Partner's Privacy Policy

Advertising

90 days

All

LinkedIn

https://www.linkedin.com/legal/privacy-policy

Advertising

Determined by third party

All

LinkedIn

https://www.linkedin.com/legal/privacy-policy

Advertising

7 days

All

LinkedIn

https://www.linkedin.com/legal/privacy-policy

Advertising

Determined by third party

All

Live Intent

https://www.liveintent.com/services-privacy-policy/

Advertising

When session ends

All

Pepperjam

https://www.pepperjam.com/legal

Advertising

60 days

All

Pepperjam

https://www.pepperjam.com/legal

Advertising

60 days

All

Pepperjam

https://www.pepperjam.com/legal

Advertising

1 year

All

Pinterest

https://policy.pinterest.com/en/privacy-policy

Advertising

1 year

All

Pinterest

https://policy.pinterest.com/en/privacy-policy

Advertising

1 year

All

Pinterest

https://policy.pinterest.com/en/privacy-policy

Advertising

1 year

All

Pinterest

https://policy.pinterest.com/en/privacy-policy

Advertising

1 year

All

Pinterest

https://policy.pinterest.com/en/privacy-policy

Advertising

1 year

All

Pinterest

https://policy.pinterest.com/en/privacy-policy

Advertising

1 year

All

Pinterest

https://policy.pinterest.com/en/privacy-policy

Advertising

1 year

All

Pinterest

https://policy.pinterest.com/en/privacy-policy

Analytics

1 year

all

Podsights

https://podsights.com/privacy-policy/

Functionality

2 years

All

Privy

https://www.privy.com/privacy-policy

Functionality

30 mins

All

Privy

https://www.privy.com/privacy-policy

Functionality

1 year

All

Privy

https://www.privy.com/privacy-policy

Advertising

2 Years

All

Reddit

https://www.reddit.com/policies/privacy-policy#policy-h2-1

Advertising

When session ends

All

Reddit

https://www.reddit.com/policies/privacy-policy#policy-h2-1

Essential

1000 days

All

Retention Science

https://www.retentionscience.com/privacy-policy/

Analytics

30 days

All

Rockerbox

https://www.rockerbox.com/privacy

Advertising

30 days

All

Shareasale

https://www.awin.com/us/privacy?utm_source=shareasale-website&utm_medium=text-link&utm_campaign=shareasale-website

Essential

Session

All

Taboola

https://www.taboola.com/policies/privacy-policy

Functionality

1 year

All

Taboola

https://www.taboola.com/policies/privacy-policy

Functionality

1 year

All

Taboola

https://www.taboola.com/policies/privacy-policy

Functionality

1 year

All

Taboola

https://www.taboola.com/policies/privacy-policy

Functionality

1 year

All

Taboola

https://www.taboola.com/policies/privacy-policy

Functionality

30 minutes

All

Taboola

https://www.taboola.com/policies/privacy-policy

Functionality

30 minutes

All

Taboola

https://www.taboola.com/policies/privacy-policy

Analytics

3 hours

All

Taboola

https://www.taboola.com/policies/privacy-policy

Analytics

3 hours

All

Taboola

https://www.taboola.com/policies/privacy-policy

Analytics

50 seconds

All

Taboola

https://www.taboola.com/policies/privacy-policy

Essential

13 months from the day it was first set on a user's browser, or from the date it was last used, whichever is later.

All

Tiktok

https://www.tiktok.com/legal/privacy-policy-us?lang=en

Advertising

13 months from the day it was first set on a user's browser, or from the date it was last used, whichever is later.

All

Tiktok

https://www.tiktok.com/legal/privacy-policy-us?lang=en

Advertising

13 months from the day it was first set on a user's browser, or from the date it was last used, whichever is later.

All

Tiktok

https://www.tiktok.com/legal/privacy-policy-us?lang=en

Analytics

365 days from last access (resets countdown on each pixel hit)

All

tvScientific

https://www.tvscientific.com/privacy-policy/

Essential

30 minutes

All

Zendesk

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

Session

All

Zendesk

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

8 hours.
(Session duration is configurable by the Subscriber using the Session Expiration config in Admin Center > Security Settings. Can be from 5 minutes to 2 weeks. Default is 8 hours.)

All

Zendesk

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

8 hours.
(Session duration is configurable by the Subscriber using the Session Expiration config in Admin Center > Security Settings. Can be from 5 minutes to 2 weeks. Default is 8 hours.)

All

Zendesk

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

8 hours.
(Session duration is configurable by the Subscriber using the Session Expiration config in Admin Center > Security Settings. Can be from 5 minutes to 2 weeks. Default is 8 hours.)

All

Zendesk

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

When session ends

All

Zendesk

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

The storage duration is dependent on the End-User’s browser policy.

All

Zendesk

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

The storage duration is dependent on the End-User’s browser policy.

All

Zendesk

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

The storage duration is dependent on the End-User’s browser policy.

All

Zendesk

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

1 year

All

Zendesk

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Analytics

1 minute

All

Zendesk Help Center

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Analytics

1 day

All

Google

https://policies.google.com/technologies/partner-sites?hl=en-US&hl=en_US

Analytics

Determined by third party

All

Google

https://policies.google.com/technologies/partner-sites?hl=en-US&hl=en_US

Essential

Determined by third party

All

Zendesk Help Center

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

Determined by third party

All

Zendesk Help Center

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

When session ends

All

Zendesk Help Center

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Functionality

Local storage duration is decided by the browser policy.

All

Zendesk Help Center

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Analytics

48 hours

All

Zendesk Help Center

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

When session ends

All

Zendesk Help Center

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

2 hours

All

Zendesk Web Widget

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Functionality

Determined by third party

All

Zendesk Web Widget

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Analytics

20 minutes

All

Zendesk Web Widget

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Analytics

Determined by third party

All

Zendesk Web Widget

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Functionality

Determined by third party

All

Zendesk Web Widget

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Functionality

The storage duration is dependent on the End-User’s browser policy.

All

Zendesk Web Widget

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

Customers can choose to use either local storage or session storage. Duration is decided by the End-User's browser policy.

All

Zendesk Web Widget

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

Customers can choose to use either local storage or session storage. Duration is decided by the End-User's browser policy.

All

Zendesk Web Widget

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

Customers can choose to use either local storage or session storage. Duration is decided by the End-User's browser policy.

All

Zendesk Web Widget

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

1 year

All

Zendesk Live Chat

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

1 year

All

Zendesk Live Chat

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

Determined by third party

All

Zendesk Live Chat

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

When session ends

All

Zendesk Live Chat

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

When session ends

All

Zendesk Live Chat

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Essential

When session ends

All

Zendesk Live Chat

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Functionality

Local storage

All

Zendesk Live Chat

https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

Analytics

13 Months

Web / Mobile App

Heap

https://heap.io/privacy

Analytics

30 Minutes

Web / Mobile App

Heap

https://heap.io/privacy

Analytics

13 Months

Web / Mobile App

Heap

https://heap.io/privacy

Analytics

Should not persist

Web / Mobile App

Heap

https://heap.io/privacy

Essential

2 years

Web

Affirm

https://www.affirm.com/privacy

Essential

1 hour or in year 3000

Web

Affirm

https://www.affirm.com/privacy

Essential

1 year

Web

Affirm

https://www.affirm.com/privacy

Essential

1 year

Web

Affirm

https://www.affirm.com/privacy

Essential

1 year

Web

Yotpo

https://www.yotpo.com/privacy-policy/

Essential

1 year

Web

Affirm

https://www.affirm.com/privacy

Essential

When session ends

Web

Affirm

https://www.affirm.com/privacy

Advertising

3 months, 1 day

Web

Google

https://policies.google.com/technologies/partner-sites?hl=en-US&hl=en_US

Advertising

3 months, 1 day

Web

Meta - Facebook/Instagram

https://www.facebook.com/privacy/policy

Essential

1 month

Web

Affirm

https://www.affirm.com/privacy

Essential

When session ends

Web

Affirm

https://www.affirm.com/privacy

Essential

When session ends

Web

Affirm

https://www.affirm.com/privacy

Essential

2 years

Web

Affirm

https://www.affirm.com/privacy

Essential

2 years

Web

Affirm

https://www.affirm.com/privacy

Analytics

6 months from last page visit, or a period of your choice (per the setCookieExpiration and extendCookieLifetime APIs)

Web

Optimizely

https://www.optimizely.com/legal/privacy-policy/

Analytics

5 seconds

Web

Optimizely

https://www.optimizely.com/legal/privacy-policy/

Analytics

6 months, but the cookie is removed by Optimizely immediately after the set action is successful.

Web

Optimizely

https://www.optimizely.com/legal/privacy-policy/

Analytics

Determined by third party

Web

Optimizely

https://www.optimizely.com/legal/privacy-policy/

Functionality

Determined by third party

Web

Nosto

https://www.nosto.com/privacy-policy/

Functionality

Determined by third party

Web

Nosto

https://www.nosto.com/privacy-policy/

Functionality

Determined by third party

Web

Nosto

https://www.nosto.com/privacy-policy/

Functionality

Determined by third party

Web

Nosto

https://www.nosto.com/privacy-policy/

Functionality

1 hour

Web

Nosto

https://www.nosto.com/privacy-policy/

Functionality

1 hour

Web

Nosto

https://www.nosto.com/privacy-policy/

Functionality

1 hour

Web

Nosto

https://www.nosto.com/privacy-policy/

Functionality

1 hour

Web

Nosto

https://www.nosto.com/privacy-policy/

Advertising

Determined by third party

Web

Amazon

https://www.amazon.com/gp/help/customer/display.html?nodeId=GX7NJQ4ZB8MHFRNJ

Advertising

Determined by third party

Web

Bing - Microsoft

https://privacy.microsoft.com/en-us/privacystatement

Advertising

Determined by third party

Web

Snap

https://snap.com/en-US/privacy/privacy-policy

Advertising

Determined by third party

Web

Twitter

https://twitter.com/en/privacy

Advertising

Determined by third party

Web

Yahoo

https://legal.yahoo.com/us/en/yahoo/privacy/index.html


First-Party Cookies

 Cookie

Expiration (up to…)

Platform

Functional

90 days

Web

Essential

30 days

Web

Essential

30 days

Web

Essential

30 days

Web