FGID Privacy Policy
Applicable Service: FGID (FurryGoods Identity)
Version: First Edition
Publication Date: May 28, 2026
Effective Date: June 7, 2026
Last Updated: May 28, 2026
FGID values your personal data and privacy. This FGID Privacy Policy (the “Policy”) explains how we collect, hold, process, use, share, transfer, retain, and protect personal data when providing unified account registration, login authentication, identity linking, authorisation management, account security, and related services, and how you may exercise your rights.
This Policy is issued by:
- Data User and Service Operator: 香港福瑞谷國際貿易有限公司
- English Name: HONG KONG FURRYGOODS INTERNATIONAL TRADE LIMITED
- Company Registration Number: 80485674
- Official FGID Website: https://id.furrygoods.cc
- Privacy, Personal Data Requests, and Customer Service: [email protected]
- Customer Service Notice: Telephone support is not provided and fixed customer service hours are not published. We generally provide an initial response within seven (7) business days after receiving complete information.
This Policy should be read together with the FGID User Agreement, FGID Cookie Policy, FGID Privacy Choices and Personal Data Request Guide, and the privacy policy of each Integrated Service you use.
Article 1 Scope
1.1 Applicable Services
This Policy applies to the following FGID services:
- unified account registration and management;
- login, single sign-on, and identity authentication;
- passwordless authentication through Steam, Google, X.com, or a Passkey;
- third-party account linking, unlinking, and login authorisation;
- account recovery, risk verification, and identity verification;
- login-device, session, and authorisation management;
- Organisation Account, administrator, and member-permission management;
- the FGID Developer Platform and integration management; and
- customer service, security, audit, and compliance services directly related to the foregoing functions.
1.2 Integrated Services
FurryGoods Shop, FurCore, FurLink, FurCraft, FurryGoodsArt, and other services integrated with FGID may separately collect and process personal data for their business purposes. Such processing is governed by the privacy policy of the relevant Integrated Service.
FGID's provision of an authentication result or user-authorised data to an Integrated Service does not make FGID responsible for all data-processing activities of that service.
1.3 Exclusions
This Policy does not apply to:
- a third-party website or service not integrated with FGID;
- processing independently performed by a third-party account provider;
- data independently collected by an Integrated Service outside the scope of FGID login authorisation; or
- processing for which another person independently determines the purposes and means in accordance with law.
Article 2 Key Definitions
2.1 Personal Data
Information relating to a living individual that can directly or indirectly identify that individual and exists in a form in which access to or processing of the information is practicable.
2.2 Sensitive Personal Information
Information that may create a heightened risk to individual rights and interests if disclosed or misused, including account login credentials, government identifiers, precise location, financial-account information, biometric information, health or sex-life information, information concerning minors, and other sensitive data as defined by applicable law.
2.3 Processing
Any operation performed on personal data, including collection, recording, organisation, storage, access, analysis, use, transmission, disclosure, combination, restriction, deletion, or destruction.
2.4 Integrated Service
A website, application, software program, platform, or function that uses FGID for registration, login, identification, account linking, or authorisation.
Article 3 Personal Data We Collect
We collect data only to the extent necessary for a specified, lawful purpose directly related to the FGID service.
3.1 Registration and Account Data
This may include:
- a system-generated FGID ID that may be displayed publicly;
- a user-editable nickname, avatar, profile, and other public data;
- age confirmation, date of birth, or age range;
- region, language, time zone, and interface preferences;
- a contact email address voluntarily provided by the user or provided under a third-party account authorisation; and
- account-creation time, status, verification level, and organisational relationship.
The FGID ID, nickname, avatar, and data the user makes public may be displayed to an Integrated Service or another user. A contact email address is not an account-password login method.
3.2 Authentication and Security Data
This may include:
- a Passkey public key, credential identifier, signature counter, and device-related authentication information;
- a unique third-party identifier, authorisation status, and necessary token information provided by Steam, Google, or X.com;
- linked login methods, trusted devices, recovery status, and session information;
- login time, IP address, device type, browser, operating system, and approximate region;
- login sessions, access-token identifiers, authorisation records, and anomalous-login records; and
- risk scores, anti-fraud signals, and security-incident records.
FGID does not set or retain account passwords and does not support login using a verification code sent by email or SMS. A Passkey private key is generally retained only on the user's device or by the credential provider; in principle, FGID retains only the public key and credential information necessary for authentication.
3.3 Third-Party Account Data
When you log in to or link FGID through Steam, Google, or X.com, we may obtain, within the scope you authorise:
- a unique user identifier provided by the third-party platform;
- nickname, avatar, public profile data, contact email address, or email-verification status;
- account region, language, or applicable age status;
- authorisation scope, authorisation time, and token status; and
- other data necessary for login, linking, or security verification.
The actual scope is determined by the authorisation page and the content provided by the third-party platform. FGID does not require users to provide us with third-party platform passwords.
3.4 Identity and Organisation Verification Data
For account recovery, a high-risk operation, organisation verification, developer verification, or a legal requirement, we may request:
- name, date of birth, and contact data;
- necessary information from a government-issued identity document;
- organisation name, registration number, business address, and proof of authorisation;
- data concerning an administrator, legal representative, or authorised person; and
- historical data or business records establishing account ownership.
Unless required by law or genuinely necessary, we prioritize verification methods that do not require retention of a complete identity-document copy. If biometric or liveness verification is used, we will provide a separate notice and obtain express consent where applicable.
3.5 Organisation Account Data
This may include the organisation name, member list, positions or roles, invitation records, permission settings, administrator-operation logs, and member affiliations.
3.6 Customer Service, Appeals, and Communications Data
This may include questions, emails, tickets, attachments, appeal materials, reports, customer-service communications, and processing outcomes you submit.
3.7 Developer and Integrating-Party Data
This may include the developer name, company or organisation data, contacts, application information, callback URLs, Interface-call logs, security-assessment materials, settlement data, and compliance records.
3.8 Cookie and Similar-Technology Data
We may process session state, security-verification, preference, performance, and analytics data through Cookies, local storage, pixels, SDKs, logs, or similar technologies. See the FGID Cookie Policy and Cookie settings panel for details.
3.9 Data Obtained from Other Sources
Sources may include:
- you;
- a third-party account provider you authorise;
- an Integrated Service to which you log in or authorise;
- an Organisation Account administrator;
- a security, anti-fraud, identity-verification, or infrastructure provider;
- a judicial authority, regulator, or other competent authority; and
- a public source permitted by law.
Article 4 Purposes for Which We Process Personal Data
We may process personal data for the following purposes.
4.1 Providing and Performing the FGID Service
- creating, maintaining, and managing passwordless accounts and public FGID IDs;
- completing login, single sign-on, and identity authentication through Steam, Google, X.com, or a Passkey;
- linking and unlinking third-party accounts;
- providing an authentication result to an Integrated Service you select;
- maintaining login status, language, theme, and other settings;
- providing Organisation Account and developer functions; and
- processing account closure and withdrawal of authorisation.
4.2 Security and Anti-Fraud
- preventing account theft, impersonation, bulk registration, and credential misuse;
- detecting anomalous login, attacks, malicious automation, and security vulnerabilities;
- performing Passkey, third-party account, device, and risk verification;
- investigating violations, security incidents, and account-ownership disputes; and
- protecting the lawful rights and interests of users, FGID, Integrated Services, and third parties.
4.3 Customer Service and Dispute Handling
- responding to inquiries, complaints, reports, and personal data requests;
- providing account recovery, appeals, and technical support;
- retaining processing records and preventing repetitive or fraudulent requests; and
- handling contractual, liability, and legal disputes.
4.4 Improving the Service
- diagnosing faults and monitoring performance and compatibility;
- measuring service use;
- improving interfaces, processes, and security mechanisms; and
- conducting internal testing, quality assurance, and capacity planning.
We will not read your private communications within an Integrated Service solely for service-improvement purposes unless lawfully authorised or otherwise required by law.
4.5 Compliance and Legal Obligations
- complying with applicable legal, regulatory, tax, audit, and record-retention obligations;
- responding to lawful requests from competent authorities;
- enforcing agreements, protecting rights, or defending legal claims; and
- preventing unlawful activity or material harm.
4.6 Notices and Direct Marketing
We may send necessary account, security, authorisation, agreement-update, and service-change notices.
We send promotional, campaign, or marketing communications only where permitted by applicable law or after obtaining required consent. You may opt out of direct marketing at any time through the unsubscribe method in the communication, account settings, or by contacting us. Opting out does not affect necessary service and security notices.
Article 5 Legal Bases for Processing
Depending on your location and applicable law, we may process data on one or more of the following bases:
- necessity to enter into or perform a contract with you;
- necessity to comply with a legal obligation;
- necessity to protect your or another person's vital interests;
- necessity for our or a third party's legitimate interests, including account security, anti-fraud, service stability, and protection of rights, provided your rights and interests are not improperly prejudiced;
- your consent, including for non-essential Cookies, specific marketing, optional data sharing, or other processing requiring consent; and
- another basis permitted by applicable law.
Where processing relies on your consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal or our continued processing of necessary data on another lawful basis.
Article 6 How We Disclose or Share Data
We do not publicly disclose or arbitrarily provide personal data without purpose. We may disclose or share data as follows.
6.1 To an Integrated Service You Authorise
When you choose to log in to an Integrated Service through FGID, we may provide that service with necessary data in accordance with the authorisation page, such as the unique FGID identifier, authentication status, nickname, avatar, email address, or other data you confirm.
After receiving the data, the Integrated Service may process it as an independent data user or controller. You should review its privacy policy.
6.2 To Affiliates
We may provide data to an affiliate to the extent necessary to operate the FurryGoods service ecosystem, handle unified-account security, provide customer service, or complete a cross-service function you request.
An affiliate shall not use the data for a purpose incompatible with the purpose of collection and shall implement reasonable safeguards.
6.3 To Service Providers
To the extent necessary to provide the service, we may disclose data to service providers in categories including:
- cloud-computing and hosting providers;
- database, backup, and content-distribution providers;
- cybersecurity, anti-fraud, and log-analytics providers;
- email-delivery and SMS-verification providers; and
- identity-verification, customer-service, audit, and professional advisers.
These providers may process data only on our instructions and subject to contractual restrictions and shall not use it for their independent advertising profiles or sale.
6.4 Corporate Transactions
If a merger, acquisition, reorganisation, financing, asset sale, bankruptcy, or similar transaction occurs, data may be disclosed or transferred as part of transaction evaluation or succession. We will take reasonable measures to ensure the recipient continues to comply with applicable privacy obligations.
6.5 Law, Security, and Protection of Rights
We may disclose data where we reasonably believe disclosure is necessary to:
- comply with law, a court order, or a request from a competent authority;
- investigate fraud, an attack, unlawful activity, or a material violation;
- protect the life, property, security, and lawful rights and interests of users, the public, FGID, or a third party; or
- establish, exercise, or defend legal rights.
6.6 With Your Separate Consent
Where data is provided for a purpose beyond those stated in this Policy, we will obtain your separate consent where applicable.
Article 7 Sale, Sharing, Targeted Advertising, and Privacy Choices
7.1 Current Policy
FGID does not sell users' personal information, use it for cross-context behavioural advertising, or display advertising based on user profiling.
We do not use Passkeys, third-party login credentials, identity-verification data, or account-security data to create advertising profiles.
If our practices change, we will update this Policy and provide prominent notice before the relevant processing begins and, where required by applicable law, provide opt-out or opt-in mechanisms.
7.2 Legal Meaning of “Sale” or “Sharing”
The laws of certain jurisdictions define “sale” or “sharing” more broadly than ordinary commercial transactions and may include exchanging data for certain benefits or disclosing it for cross-site advertising. We evaluate activities under applicable law rather than determining the issue solely by whether money is received.
7.3 Privacy Choices Page
Through the “Your Privacy Choices” page, you may:
- submit a Do Not Sell or Share My Personal Information / 请勿出售或共享我的个人信息 request;
- submit a Limit the Use of My Sensitive Personal Information / 限制使用我的敏感个人信息 request;
- opt out of direct marketing;
- manage non-essential Cookies; and
- submit an access, deletion, correction, or other personal-data request.
Even though we do not currently engage in sale or advertising sharing, we provide this page to record your choice and meet applicable regional requirements.
7.4 Global Privacy Control
Where required by applicable law and technically recognizable, we treat a compliant Global Privacy Control (GPC) or other opt-out preference signal as a request to opt out of the sale or sharing of personal information.
When you are logged in, we may associate the choice with your account where reasonably practicable. When you are not logged in, the choice may apply only to the browser or device that sends the signal.
7.5 Sensitive Personal Information
We use sensitive personal information only to provide identity authentication, security, anti-fraud, account recovery, compliance, and services you reasonably expect and do not use it to infer personal characteristics unrelated to the service or for behavioural advertising.
7.6 Minors
We do not knowingly sell, or share for cross-context behavioural advertising, personal information of a user under sixteen (16) years of age. If future processing legally constitutes sale or sharing, we will obtain the minor's or guardian's express opt-in authorisation where applicable.
7.7 Non-Discrimination
We will not deny service, maliciously reduce service quality, or apply unreasonable differential treatment because you lawfully exercise a privacy right. If particular data is necessary to provide the identity service you request, however, deletion or restriction of the data may make the relevant function unavailable.
See the FGID Privacy Choices and Personal Data Request Guide for details.
Article 8 International and Cross-Border Data Transfers
FGID provides services in different countries and regions. Relevant data may be stored or processed in Hong Kong, Singapore, Japan, and other locations in which cloud services operate.
For a cross-border transfer or processing outside the relevant jurisdiction, we take reasonable measures according to the nature and risk of the data and applicable law, including:
- assessing the security and compliance of service providers;
- restricting data use through contracts, access controls, encryption, and audit requirements;
- limiting the transfer to data necessary to provide the service;
- obtaining consent, providing notice, or using a legally required transfer mechanism where applicable; and
- providing channels for access, correction, deletion, export, and complaints.
Article 9 Data Retention
We retain data only for as long as necessary to fulfill the purpose of collection, provide the service, maintain security, handle disputes, and comply with legal obligations.
In setting retention periods, we consider:
- whether the account remains active;
- the category, volume, and sensitivity of the data;
- account-security and anti-fraud needs;
- Integrated Service relationships and outstanding matters;
- complaint, dispute, litigation, and audit periods;
- legal, regulatory, and contractual requirements; and
- the technical feasibility of deletion and backup cycles.
Generally:
- core account data is retained while the account remains active and is processed for a necessary period after closure;
- login, security, and audit logs are retained according to security risk and system cycles;
- authorisation and consent records are retained while authorisation remains valid and for any necessary evidentiary period;
- identity-verification data is retained only as long as necessary to complete verification, handle disputes, or comply with legal obligations;
- customer-service and appeal data is retained as necessary for handling and disputes; and
- backup data is deleted or irreversibly overwritten through ordinary rotation cycles.
When a retention period expires, we delete or anonymize the data or otherwise cease identifying individuals from it.
Article 10 Data Security
We implement technical and organisational measures appropriate to the risk, including:
- encryption in transit and at rest;
- segregated protection of Passkey public keys, third-party tokens, and other authentication Credentials;
- multi-factor authentication and permission controls;
- login-session and token management;
- monitoring for anomalous login, attacks, and fraud;
- least privilege and employee confidentiality controls;
- logging, audit, vulnerability remediation, and backups;
- supplier security requirements; and
- security-incident response and recovery mechanisms.
No internet or information system can be guaranteed absolutely secure. You shall properly protect linked third-party accounts, Passkeys, devices, and recovery credentials and, after discovering an anomaly, immediately terminate sessions, remove affected linked methods, and contact us.
If a security incident may create a risk to individual rights and interests, we will investigate, contain, and remediate it and notify affected users and competent authorities where required by applicable law.
Article 11 Automated Processing and Risk Decisions
FGID may use automated rules, models, or risk scores to identify anomalous login, bulk registration, credential attacks, account theft, or fraud risk.
A related determination may result in additional verification, a temporary restriction, session termination, or manual review. We will not rely solely on automated processing to make a decision producing a significant legal or similarly significant effect on a user unless permitted by law and accompanied by appropriate safeguards.
If you believe a risk determination is incorrect, you may request manual review through the appeal channel.
Article 12 Your Personal Data Rights
Depending on your location and applicable law, you may have some or all of the following rights:
- to be informed how we process data;
- to access or obtain a copy of personal data;
- to correct inaccurate or incomplete data;
- to request deletion;
- to restrict or object to particular processing;
- to withdraw consent;
- to obtain data in a portable format;
- to opt out of sale, sharing, or targeted advertising;
- to limit the use and disclosure of sensitive personal information;
- to opt out of direct marketing;
- to contest an automated decision;
- to appoint an authorised agent;
- to appeal the outcome of a request;
- to complain to a competent regulator; and
- not to be discriminated against for lawfully exercising a right.
Not every right applies in every jurisdiction. Some requests may be limited because of account security, another person's rights and interests, legal obligations, litigation, anti-fraud needs, or another statutory ground.
12.1 Submitting a Request
You may submit a request through:
- the “Privacy and Data” page in the FGID Account Center;
- the “Your Privacy Choices” page;
- [email protected] for privacy, personal-data requests, and customer service; or
- the Official FGID Website at https://id.furrygoods.cc.
We generally provide an initial response within seven (7) business days after receiving complete information. The period for completing a statutory-rights request is governed by applicable law.
12.2 Identity Verification
To prevent unauthorised access to or deletion of data, we may require you to log in, verify a linked Steam, Google, X.com account, or Passkey, confirm a trusted device, or provide other proof proportionate to the request.
For a sale-or-sharing opt-out request, we do not require unnecessary identity data where applicable law does not require verification.
12.3 Authorised Agents
Where permitted by applicable law, you may authorise an agent to submit a request. We may require proof of authorisation and may confirm the agent's authority directly with you.
12.4 Responses and Appeals
We will acknowledge, process, or respond to a request within the period prescribed by applicable law. If we need to extend, refuse, or limit a request, we will explain the reason and available appeal channel to the extent permitted by law.
Article 13 Minors
FGID is not primarily directed to minors, but some Integrated Services may permit minors to use them with guardian consent and guidance.
A user must meet the minimum age required by the law of the user's location. Where applicable law permits use with guardian consent, the guardian shall read this Policy and provide the necessary consent.
We take reasonable age-appropriate measures according to the nature of the service, including restrictions on data collection, marketing, and public display and provision of a guardian-request channel.
If you believe a minor has provided us with personal data without appropriate authorisation, please contact us. After verification, we will take deletion, restriction, or other measures in accordance with law.
Article 14 Third-Party Services and Links
FGID may contain third-party login, links, SDKs, or services. A third party processes data under its own terms and privacy policy, and we cannot control all of its conduct.
Before authorising a third party, review the authorisation scope and third party's privacy policy. You may withdraw authorisation through the FGID Account Center or third-party platform, but withdrawal may not automatically delete data already lawfully retained by the third party.
Article 15 Policy Updates
We may update this Policy because of changes in law, service adjustments, technical upgrades, security needs, or changes in data-processing practices.
A material change may include a new data category or processing purpose, a change in data recipients, commencement of sale or advertising sharing, expansion of sensitive-data uses, or a material effect on user rights.
We will provide notice through an announcement, the Account Center, a pop-up, email, or another reasonable means. A change requiring consent will be implemented only after valid consent is obtained.
Article 16 Contact Us and Complaints
For questions concerning this Policy, personal-data processing, or a privacy request, contact:
- Operator: 香港福瑞谷國際貿易有限公司
- English Name: HONG KONG FURRYGOODS INTERNATIONAL TRADE LIMITED
- Company Registration Number: 80485674
- Official FGID Website: https://id.furrygoods.cc
- Privacy, Personal Data Requests, and Customer Service: [email protected]
- Customer Service Notice: Telephone support is not provided and fixed customer service hours are not published. We generally provide an initial response within seven (7) business days after receiving complete information.
Do not send a third-party account password, Passkey private key, recovery code, or unredacted complete identity document in the body of an ordinary email.
If you are dissatisfied with the outcome, you may appeal in accordance with the FGID Privacy Choices and Personal Data Request Guide or complain to a competent regulator in your location.
Appendix 1: Personal Information Collection Statement and Notice at Collection
The table below summarizes data FGID may collect. The data actually collected depends on the functions you use.
| Data Category | Examples | Principal Purpose | Necessary? | Sale or Advertising Sharing |
|---|---|---|---|---|
| Identifiers and contact data | Public FGID ID, contact email address, region, language | Account management, notices, recovery | Partly necessary | Not sold; not shared for cross-context behavioural advertising |
| Public account data | FGID ID, editable nickname, avatar, profile | Public display, personalization, Integrated Service identification | Partly public and generally editable | Not sold; not shared for cross-context behavioural advertising |
| Authentication-credential data | Passkey public key, Steam/Google/X.com identifier, token status | Passwordless authentication and security | Necessary | Not sold or shared for advertising |
| Network and device data | IP, device, browser, logs, session | Login, security, fault diagnosis | Necessary | Not sold; not shared for cross-context behavioural advertising |
| Third-party account data | Steam, Google, X.com user identifier and authorised data | Third-party login and account linking | Necessary when the method is used | Not sold; provided to an Integrated Service only as authorised |
| Identity-verification data | Necessary identity-document fields, organisation proof | High-risk verification, account ownership, compliance | Necessary in specified cases | Not sold or shared for advertising |
| Authorisation and preference data | Authorisation scope, Cookie choices, privacy choices | Manage consent, authorisation, and rights requests | Necessary | Not sold |
| Customer-service and appeal data | Tickets, emails, attachments, processing records | Support, appeals, dispute handling | Necessary when a request is made | Not sold |
| Developer data | Applications, contacts, Interface logs, security materials | Integration review and developer services | Necessary for developer functions | Not sold |
If you do not provide data marked necessary, we may be unable to provide the corresponding function. When providing data, you shall ensure that you are lawfully entitled to do so and avoid submitting sensitive content unrelated to the request.
香港福瑞谷國際貿易有限公司
HONG KONG FURRYGOODS INTERNATIONAL TRADE LIMITED

