Privacy Policy

Last updated: June 27, 2026

1. Introduction

This Privacy Policy explains how ColoRamp ("ColoRamp", "we", "us", or "our") collects, uses, and protects your personal information when you use our website, Figma plugins (Pigment Lab and Code Hub), and related services (collectively, the "Service").

We are committed to protecting your privacy and handling your data in compliance with the Swiss Federal Act on Data Protection (nDSG) and, where applicable, the EU General Data Protection Regulation (GDPR).

By using the Service, you acknowledge that you have read and understood this Privacy Policy.

2. Data Controller

ColoRamp is the data controller responsible for the processing of your personal data. If you have any questions about how we handle your data, you can contact us at:

ColoRamp
Email: legal@coloramp.ch

3. Information We Collect

3.1 Account Information

When you sign in through Figma OAuth, we receive and store the following information from your Figma account:

  • Full name
  • Email address
  • Profile picture (avatar URL)
  • Figma user ID

3.2 Payment and Billing Information

When you subscribe to a paid plan, our payment processor Stripe collects and processes your payment information (such as credit card details and billing address). We do not store your payment card details on our servers. We store the following billing-related data:

  • Stripe customer ID
  • Subscription details (plan, status, billing period, cancellation status)
  • Invoice records (amount, currency, status, invoice PDF link)

3.3 Automatically Collected Information

When you visit our website, we automatically collect limited technical information through essential cookies and storage (see Section 7).

With your consent, we use PostHog analytics to understand website usage and improve the Service. Analytics is optional and is not loaded unless you accept analytics cookies and storage.

We use Sentry for technical error monitoring, diagnostics, and service security. Sentry may process technical error data such as stack traces, runtime context, browser and device information, request paths, and non-sensitive diagnostic identifiers. We use this information to detect, investigate, and fix bugs and security issues.

With your separate marketing consent, we may collect Google Ads click identifiers (`gclid`, `gbraid`, and `wbraid`), the first and latest stored click identifier, the time when an identifier was captured, your marketing consent status, consent version, and subscription conversion events such as trial starts and first paid subscriptions. For paid subscription conversions, this can include the conversion value and currency.

3.4 Plugin Data

Our Figma plugins (Pigment Lab and Code Hub) operate primarily within Figma's environment. All plugin data — including color palettes, templates, settings, and design tokens — is stored locally in your Figma files using Figma's built-in plugin data storage. This plugin-created content is not stored on our servers. When you sign in, verify access, or use account-related features, the plugins may communicate with ColoRamp and Supabase services to exchange authentication sessions and check your subscription entitlements.

3.5 Email Communication Preferences

We store onboarding email communication preferences so we can honor unsubscribe requests for product onboarding emails. This includes the onboarding email category and the date/time when an unsubscribe request was applied.

4. How We Use Your Information

We use the information we collect for the following purposes:

PurposeData UsedLegal Basis (GDPR)
Account creation and authenticationName, email, avatar, Figma IDContract performance
Subscription management and billingStripe customer ID, subscription and invoice dataContract performance
Plugin authentication and entitlement checksSession code, verifier hash, Figma ID, authentication tokens, account and subscription statusContract performance and legitimate interest
Optional website analyticsPage views, usage events, technical browser data, optional account identifiersConsent
Optional marketing measurementGoogle click IDs (`gclid`, `gbraid`, `wbraid`), consent status and version, hashed email address, subscription conversion events, conversion timestamps, transaction IDs, and paid conversion value/currencyConsent
Customer support and communicationName, emailLegitimate interest
Product onboarding emailsEmail address, name (if available), account creation timestamp, onboarding email preference status, email delivery metadataLegitimate interest
Service security and fraud preventionAccount data, technical data, error logs, stack traces, runtime context, and non-sensitive diagnostic identifiersLegitimate interest
Legal complianceAll relevant dataLegal obligation

5. How We Share Your Information

We do not sell, rent, or trade your personal information. We share your data only with the following third-party service providers and partners as needed to provide, secure, measure, and improve the Service:

ProviderPurposeData SharedLocation
SupabaseDatabase hosting, authentication, plugin auth exchange, entitlement checksAccount data, subscription data, campaign attribution and consent records, temporary plugin auth session dataSwitzerland (Zurich)
StripePayment processingPayment and billing dataMay involve transfers to the United States
FigmaAuthentication (OAuth)Name, email, avatar, Figma IDUSA
PostHogOptional website analyticsUsage events, page views, technical browser dataGermany (EU)
SentryTechnical error monitoring and diagnosticsError logs, stack traces, runtime context, browser and device information, request paths, and non-sensitive diagnostic identifiersMay involve transfers to the United States
Google AdsConversion measurement and ad attributionGoogle click IDs (`gclid`, `gbraid`, `wbraid`), hashed email address, conversion type, conversion timestamp, transaction ID, and paid conversion value/currencyMay involve transfers to the United States
ResendTransactional and onboarding email deliveryEmail address, email content, delivery and engagement metadataUnited States (account data); EU sending region available
VercelWebsite hostingTechnical connection dataGlobal CDN

We may also disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, safety, or property of ColoRamp, our users, or the public.

For Google Ads conversion measurement, email addresses are normalized and hashed with SHA-256 before transmission. Hashing is a pseudonymization measure and does not make the data anonymous. When marketing consent is enabled, a server-side conversion may be sent through the Google Data Manager API if a Google click identifier or a hashed email address is available as a match key.

6. International Data Transfers

Your account data is primarily stored in Switzerland (Zurich) through our database provider Supabase. Our PostHog analytics setup is hosted in Germany (EU). For Resend, region selection controls where emails are dispatched from (for example, Ireland `eu-west-1`) but does not control where customer account data is stored. Resend states that account data (including email metadata, logs, and API records) is stored in the United States. Some other service providers and partners (including Stripe, Figma, Google, Sentry, and Vercel) may also operate in the United States and other countries.

Stripe's legal terms state that providing payment services may require transfers of personal data to Stripe, LLC in the United States and to Stripe affiliates or sub-processors in other jurisdictions.

Google Ads and Google Data Manager API processing may involve transfers of marketing measurement data, including pseudonymized identifiers and conversion metadata, to Google entities or infrastructure outside Switzerland or the EU/EEA.

Where personal data is transferred outside of Switzerland or the EU/EEA, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Addendum where applicable, or reliance on recognized transfer frameworks and adequacy decisions.

7. Cookies and Local Storage

We use essential cookies that are strictly necessary for the Service to function. With your consent, we also use optional analytics cookies and local storage through PostHog to understand how the website is used, and optional marketing technologies through Google Ads to measure subscription conversions and attribute them to ad campaigns.

Cookie / StorageTypeSet WhenDurationPurpose
Cookie Consent PreferenceStrictly necessaryWhen you save your privacy choicesUntil cleared by youStored in local storage to remember your analytics and marketing preferences separately, including the consent version and timestamp.
PostHog AnalyticsOptional analyticsOnly after you accept analytics cookies and storageVaries by PostHog settingHelps us understand page views and product usage so we can improve the website and Service.
PostHog Identity StorageOptional analyticsOnly after you accept analytics cookies and sign in through a plugin flowUp to 30 days or until clearedStores a Figma user identifier in local storage and a cookie so analytics events can be associated consistently after consent.
Google Ads MarketingOptional marketingOnly after you accept marketing cookies and storageUntil cleared by you or consent is withdrawnStores Google click IDs (`gclid`, `gbraid`, `wbraid`) locally and may share those identifiers, conversion metadata, and a hashed version of your email address with Google to attribute trial and paid subscription conversions to ad campaigns.
Supabase AuthStrictly necessaryWhen you sign in to your accountSessionStores your authentication session so you remain signed in while using the Service.
Supabase Auth (refresh)Strictly necessaryWhen you sign in to your accountUp to 7 daysRefreshes your authentication session to keep you signed in across visits without requiring you to sign in again.
Currency PreferenceStrictly necessaryWhen you first visit the website10 yearsStores your preferred currency (CHF or USD) so prices are displayed in the correct currency across visits.
Auth RedirectStrictly necessaryWhen you start sign-in from a protected pageUp to 10 minutesStores the destination page so we can return you there after authentication.
Plugin Auth Code and Figma User IDStrictly necessaryWhen you start sign-in from a Figma pluginUp to 10 minutesTemporarily connects the browser authentication callback with the plugin session that requested sign-in.

Optional analytics and marketing technologies are disabled by default and only start after you enable them in the cookie banner. Strictly necessary cookies cannot be disabled without impairing the functionality of the Service.

8. Data Retention

We retain your personal data as follows:

  • Account data — Retained for as long as your account is active. When you delete your account, we delete your Supabase account data and attempt to cancel and remove associated Stripe customer data, unless we are required to retain certain records for legal obligations.
  • Billing and invoice data — Retained for the period required by applicable tax and accounting laws (typically 10 years under Swiss law).
  • Campaign attribution and consent records — Retained for as long as your account is active, unless you withdraw the relevant consent or request deletion earlier. If you withdraw marketing consent, locally stored ad attribution is cleared and server-side Google Ads click identifiers are removed from your campaign attribution record. Consent status, version, source, and update timestamps may be retained to document your choices.
  • Conversion send records — Retained with your subscription record to prevent duplicate Google Ads conversion sends and to support billing and audit integrity.
  • Plugin authentication sessions — Used only as a short-lived transport for sign-in and normally deleted after the plugin retrieves the session or after expiry.
  • Plugin data — Stored locally in your Figma files and not on our servers. We have no control over this data.

9. Your Rights

Depending on your location, you have the following rights regarding your personal data:

Under Swiss Law (nDSG) and GDPR

  • Right of access — Request a copy of the personal data we hold about you.
  • Right to rectification — Request correction of inaccurate or incomplete personal data.
  • Right to erasure — Request deletion of your personal data, subject to legal retention obligations.
  • Right to data portability — Request a copy of your data in a structured, commonly used, machine-readable format.
  • Right to restriction — Request that we limit the processing of your personal data under certain circumstances.
  • Right to object — Object to processing based on legitimate interests.
  • Right to withdraw consent — Where processing is based on consent, you may withdraw it at any time.

You can withdraw analytics or marketing consent through the Cookie settings link on the website. Withdrawal does not affect processing that lawfully occurred before the withdrawal, and it does not automatically delete conversion data already transmitted to Google.

For California Residents (CCPA/CPRA)

  • Right to know — Request information about the categories and specific pieces of personal information we have collected.
  • Right to delete — Request deletion of your personal information.
  • Right to opt-out — We do not sell your personal information. Where applicable law treats optional Google Ads conversion measurement as "sharing" for targeted advertising, you can opt out by rejecting or withdrawing marketing consent.
  • Right to non-discrimination — We will not discriminate against you for exercising your privacy rights.

To exercise any of these rights, please contact us at legal@coloramp.ch. We will respond to your request within 30 days.

You can also unsubscribe from onboarding emails at any time by using the unsubscribe link included in those emails. This does not affect essential account, security, or billing communications.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit (TLS/SSL), access controls, and secure infrastructure provided by our hosting and database providers.

However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security of your data.

11. Children's Privacy

The Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly. If you believe we have inadvertently collected data from a child, please contact us at legal@coloramp.ch.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you through the Service or via email.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.

13. Contact

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:

ColoRamp
Email: legal@coloramp.ch

If you are located in the EU/EEA and believe that your data protection rights have not been adequately addressed, you have the right to lodge a complaint with your local data protection supervisory authority. If you are in Switzerland, you may contact the Federal Data Protection and Information Commissioner (FDPIC).