This cookie policy is shared by The Fig Group Limited and its subsidiaries, including Fig Technology Ltd, Fig Compliance Ltd and Fig Risk Solutions Ltd. It covers our group websites and services that link to this policy. The tools described below apply to this website; service-specific notices explain any different tools. Cookie choices apply to the website or service where you make them and do not automatically grant permission on every other Fig website or service.
Our website uses essential storage for security, checkout and form state, and to remember your privacy choices. We also collect first-party information for statistical purposes solely to improve the website. This channel counts aggregate page views, approved navigation actions and funnel stages. It does not send a visitor ID, session ID, customer ID, IP address, full referrer, query string or form content, and it stores aggregate counters rather than an individual browsing history. Aggregate statistics are retained for up to 400 days and are not used for advertising or joined to customer identities.
You can object to aggregate statistics immediately by selecting Use essential cookies only, or at any time through Cookie settings in the website footer. Your objection stops subsequent statistical events. Aggregate counts already created cannot identify you and therefore cannot be separated back out by visitor.
Our first-party session and journey analytics only runs after you give analytics consent. It is hosted in Microsoft Azure and helps us understand website journeys, content performance and where people encounter difficulty. It records a random, pseudonymous session identifier and controlled events covering page and route views, navigation, content engagement, form stages, chat stages, product interest and checkout stages. Raw journey event rows are retained for up to 90 days before deletion; longer-term reporting uses aggregated results.
Journey analytics does not collect form field values, chat messages, names, email addresses, phone numbers, postcodes, authentication content, card or payment content, or full URL query strings. Pre-identification activity may be linked to the resulting lead or order if you later identify yourself through a form or purchase, but only where valid analytics consent covered that activity. Any restricted identity bridge is created server-side and not sent to Google Analytics or Microsoft Clarity.
When a visitor arrives through our approved Google Ads Cyber Essentials campaign, our first-party service records only allowlisted campaign, ad-group, creative, device, network, match-type and landing-route categories. It does not retain the visitor's IP address, search terms, full URL, Google click identifier or contact details for this purpose. A signed opaque reference can follow the current checkout in memory and be linked to a completed order for up to 90 days so we can understand whether campaign-labelled visits lead to sales. If you select advertising, that opaque reference may also be retained in browser storage for the same period; it is removed from browser storage when advertising consent is withdrawn.
Microsoft Clarity and the Google Ads tag load in cookieless consent mode before your choice with analytics and advertising storage denied. In that mode they do not set optional analytics or advertising cookies. The Google tag can send consent-state pings without advertising identifiers. After the server verifies a completed payment, the Google tag may also send one limited purchase signal containing an opaque transaction reference, purchase value and currency so Google Ads can provide aggregate conversion reporting and modelling. The limited signal does not contain your name, contact details, advertising click identifier, Stripe reference, enhanced-conversion data or website journey. Clarity cookies, full session features and Google Analytics storage remain disabled unless you select analytics. Advertising storage, advertising personalisation and enhanced conversion user data remain disabled unless you select advertising. You can change or withdraw these choices at any time through Cookie settings. You can object separately to limited advertising measurement there without enabling or disabling any optional cookie category. Withdrawal stops future consented journey events and behavioural linkage, clears optional analytics cookies, and returns Clarity to cookieless denied-storage mode. The rights described above, including access, erasure, objection and withdrawal of consent, apply to personal data used for this analytics processing; legal retention duties may still apply to completed orders and financial records.
If you select advertising and later complete a purchase, we may send Google the retained click identifier or session-attribution value and a one-way SHA-256 hash of the purchaser email address as enhanced-conversion data. This is sent only after Stripe-confirmed payment, with consent recorded as granted, and is used with the same opaque transaction reference to avoid double-counting the browser and server purchase signals. We do not include these fields in the limited cookieless path, and we do not write them to operational logs.