



Privacy & Cookies
How Be a Part collects, uses, stores, and shares personal information.
Last updated:
1. Who is responsible for your data?
Fiolex Software is responsible for the personal data processed through the Be a Part website and platform (referred to as “Fiolex”, “we”, “us”, or “our” in this policy).
- Postal address
- Fiolex Software Reinach AG, Switzerland
- Privacy contact
- Contact form
This policy applies to Be a Part. Services operated by third parties have their own privacy policies.
2. Personal data we process
The information we process depends on how you use the platform and may include:
- Account data: email address, display name, member identifier, account creation date, email-confirmation status, and authentication information. For email/password accounts, we store a password hash rather than your plain-text password.
- Google sign-in data: a Google-issued identity token containing your Google account identifier, email address, email-verification status, and basic profile information such as your name. We use this information to verify your identity and create or link your Be a Part account, as described below.
- Profile data: profile image, country, birthday, settings, level, scores, and other information you add to your profile.
- Public platform activity: profile name, member identifier, artwork, Creations, ownership, collections, Creator or Patron participation, likes, contributions, and community activity.
- Content and communications: uploaded images or artwork, customisation choices, messages, feedback, support requests, and related metadata.
- Updates subscription: your email address and the date you requested updates.
- Orders and transactions: name, delivery and billing details, contact email, selected payment method, order contents, previews, transaction status, and production or delivery information.
- Wallet and blockchain data: wallet addresses, token ownership, offers, purchases, and transactions recorded on public blockchain networks.
- Technical and usage data: IP address, browser-specific visitor identifier, access times, device and browser information, logs, error reports, and security events.
Payment-card details should be processed by the applicable payment provider. We do not intend to retain complete card numbers or card security codes in our platform database.
Account creation and sign-in
You can create an account using an email address and password, or use Sign in with Google when available. Email/password registration requires email confirmation. We process your email address and security tokens to send confirmation messages, verify your address, and handle eligible password-reset requests.
If you choose Google sign-in, Google authenticates you and sends an identity token to our platform. We validate that token and use the Google account identifier to recognise your account. For a new account, we store your email address and use the supplied name as your initial display name; if no name is supplied, we use the part of your email address before the at-sign. Your display name may be public, as explained in section 3. We also store the Google sign-in association and mark the email address as confirmed after verifying Google's confirmation status.
We do not receive your Google password. This sign-in integration does not request access to your Gmail messages, contacts, calendar, or Google Drive files. Although the identity token may contain a profile-image address, the current integration does not copy that image into your Be a Part profile.
If the email address already belongs to an existing Be a Part account, you must sign in with that account's password before we link Google. Matching email addresses alone do not automatically link accounts. A new account created solely through Google sign-in does not have a Be a Part password; the password-reset process applies only to accounts that already have one.
Google sign-in is optional; email/password registration remains available. Google's sign-in library loads with the website, so Google may receive technical connection information even before you choose to sign in. Google's handling of that information is described in its Privacy Policy. For more about the sign-in service, see Google's Sign in with Google overview.
3. Information visible to others
Be a Part is a creative and community platform. Information that you intentionally publish—such as your display name, member identifier, profile image, country, artwork, Creations, ownership, collections, and activity—may be visible to anyone, including people without an account.
Public blockchain records cannot generally be edited or deleted by Fiolex. Avoid publishing personal information that you do not want others to see.
4. Why and on what basis we use data
| Purpose | Typical legal basis |
|---|---|
| Create and manage accounts, authenticate email/password or Google sign-ins, link sign-in methods, and provide profiles, orders, and requested services | Performing our agreement with you |
| Publish content and activity that you choose to share | Performing the requested service and our legitimate interest in operating the community |
| Process payments, deliveries, wallet actions, and transaction records | Performing our agreement and meeting legal obligations |
| Send updates or optional marketing | Your consent, where required |
| Send essential account, transaction, security, or legal messages | Performing our agreement, legal obligations, and legitimate interests |
| Prevent fraud, protect accounts, investigate abuse, and maintain the platform | Legal obligations and legitimate interests in security and reliable operation |
| Establish, exercise, or defend legal claims | Legal obligations and legitimate interests |
Where we rely on legitimate interests, we consider the effect on your rights. Where consent is the basis, you may withdraw it at any time without affecting processing that already occurred.
5. Who receives personal data?
We share data only where necessary for the purposes described above. Recipients may include:
- hosting, database, security, communications, email, support, production, and delivery providers;
- payment providers, wallet services, marketplaces, and public blockchain networks;
- Customily for product customisation;
- Google services, including Sign in with Google (Google Identity Services), Google Analytics, Maps, and externally hosted fonts;
- Microsoft Azure communication or chat services;
- Font Awesome and content-delivery network providers;
- social platforms that you choose to visit, such as YouTube, Instagram, or Discord; and
- courts, authorities, professional advisers, or another business where disclosure is legally required or necessary for a legitimate corporate transaction.
External providers may receive technical data such as your IP address, browser information, requested page, and request time when their resources or services load.
International transfers
Some recipients may process data outside Switzerland or the European Economic Area. Where the destination does not provide an officially recognised adequate level of protection, we use an appropriate legal safeguard where required, such as approved contractual clauses, or rely on another lawful exception.
6. Cookies and browser storage
Cookies are small files stored by a website through your browser. Local storage is a similar browser feature that can retain information without sending it automatically with every web request. Be a Part uses cookies for sign-in and request security, and local storage for other platform functions and preferences. Both email/password and Google sign-in use the same Be a Part authentication cookie.
| Name | Type and purpose | When it is removed |
|---|---|---|
__Host-beapartof.auth | Essential authentication cookie that keeps you signed in. It is sent only over HTTPS and is not readable by JavaScript (HttpOnly). | Configured to expire after seven days, with renewal during active use. Removed on sign-out or when you clear cookies; a session may also become invalid for security reasons. |
.AspNetCore.Antiforgery.* | Essential security cookie used with a request token to protect account actions and other forms against forged requests. The name includes an application-specific suffix. | A session cookie, normally removed when the browser session ends, or when you clear cookies. Browser session-restoration settings may preserve it. |
ClientGuid | Local storage containing a browser-specific identifier used by platform features. | Remains until you clear site data. |
fslightbox-types | Local storage cache used by the image and media lightbox to remember detected media types. | Remains until you clear site data; it may not be created if the lightbox does not need it. |
Third-party cookies and storage
Third-party resources and services loaded by the site may use their own cookies or browser storage under their privacy policies. These can include Google, Customily, Microsoft Azure, Font Awesome, content-delivery networks, wallet or payment services, and social platforms.
The website loads Google Analytics to measure page views and platform events. This is separate from Google sign-in and may involve analytics cookies or identifiers and technical or usage data. Google's processing is described in its Privacy Policy.
Managing stored information
You can inspect, block, or clear cookies and site data through your browser’s privacy settings. Clearing the authentication cookie signs you out; clearing other site data may reset preferences. Blocking essential cookies prevents sign-in from working correctly. Blocking third-party resources may prevent Google sign-in, maps, customisation, chat, media, wallet, or payment features from working correctly.
Signing out of Be a Part does not sign you out of Google or delete either account. To request deletion of your Be a Part account data or ask about its Google sign-in association, use our contact form.
7. How long we keep data
We retain personal data only for as long as needed to provide the relevant service, maintain security and business records, meet tax or other legal obligations, resolve disputes, and establish or defend claims. Retention depends on the type of data and the reason it was collected.
Account identifiers and Google sign-in associations are retained as part of your account records under these retention criteria. Temporary Google sign-in challenges, account-linking tickets, and post-confirmation sign-in tickets expire after five minutes and are removed when consumed. Confirmation and password-reset tokens are validated for the relevant account action.
Some information may remain temporarily in protected backups after deletion. Public blockchain data is maintained by the relevant network and cannot normally be deleted by Fiolex.
8. Security and children
We use reasonable organisational and technical safeguards designed to protect personal data. No online service can guarantee absolute security. Keep your password confidential, use a unique password, sign out on shared devices, and contact us if you suspect unauthorised account access.
Public content may be browsed at any age. Accounts are intended for people aged 16 or older, or younger people with permission from a parent or legal guardian, as explained in our Terms & Legal. A parent or guardian may contact us about a child’s data.
9. Your privacy rights
Depending on the law that applies to you, you may have the right to:
- ask whether we process your personal data and receive access to it;
- correct inaccurate or incomplete information;
- request deletion or restriction of processing;
- object to processing based on legitimate interests or to direct marketing;
- receive certain data in a portable format;
- withdraw consent at any time; and
- complain to the Swiss Federal Data Protection and Information Commissioner or another competent data-protection authority.
These rights may be subject to legal exceptions. We may ask for information needed to verify your identity before responding.
Updates and newsletter
You may withdraw from optional updates at any time using an unsubscribe method included in a message, when available, or by contacting us. We may still send messages required to operate your account, complete a transaction, protect security, or comply with law.
Automated decisions
We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects for users.
10. Changes to this policy
We may update this policy when the platform, our providers, or legal requirements change. The current version and revision date will be published on this page. We will provide additional notice where a change materially affects your privacy and the law requires it.
Use of the platform is also governed by our Terms & Legal. Rules for using Fiolex artwork appear on the License Rights page.
11. Contact us
To exercise a privacy right, ask a question, withdraw a newsletter subscription, or raise a complaint, use our contact form or write to the postal address listed in section 1.

