MrVignette

Privacy Policy

Last updated: 17 July 2026. This policy explains what personal data MrVignette (operated by Funko International AB) processes when you use mrvignette.com, why we process it, how long we keep it, and what rights you have.

We take the protection of your personal data seriously and strictly follow the applicable data protection rules, in particular the EU General Data Protection Regulation (GDPR) and equivalent laws. Personal data means any information relating to an identified or identifiable natural person.

1. Controller

The controller responsible for the processing of personal data on mrvignette.com is:

Funko International AB
Jaktstigen 24, 78450, Borlange, Sweden
ORG NO. 556284-3119
Trading as: MrVignette
Email: hello@mrvignette.com
Website: mrvignette.com

2. Server log files

When you access mrvignette.com your browser automatically transmits certain access data that we store in so-called server log files:

  • browser type and version;
  • operating system;
  • referrer URL;
  • date and time of the request;
  • the IP address currently used by your device (anonymised where possible).

We generally do not link this data to a specific person. Processing is based on our legitimate interest (Art. 6(1)(f) GDPR) in the stability, security and functionality of the site.

3. Data we collect from you directly

  • Order data: email address, first and last name, license plate, country of registration, vehicle category, selected vignettes and start dates, optional Flex Travel selection.
  • Billing data (where required by the destination country): billing address and, for business customers who request one, company name and VAT number.
  • Payment data: processed directly by Stripe (PCI-DSS Level 1). We receive only a masked token and metadata — never your full card number or CVC.
  • Technical data: IP address, browser type, referrer, coarse geolocation derived from IP (country and region only), and the language and currency you selected.
  • Support data: the content of emails you send us and our replies.

4. Purposes and legal bases

  • Performance of a contract (Art. 6(1)(b) GDPR) — to register your vignette with the competent national authority, deliver the confirmation and invoice, provide the Flex Travel service and offer customer support.
  • Legal obligation (Art. 6(1)(c) GDPR) — to retain invoices and accounting records for the period required by applicable tax law.
  • Legitimate interest (Art. 6(1)(f) GDPR) — to prevent fraud, secure our infrastructure and improve the service through aggregated analytics.
  • Consent (Art. 6(1)(a) GDPR) — for optional cookies, marketing emails and abandoned-checkout reminders. Consent can be withdrawn at any time with effect for the future.

5. Recipients & processors

We share personal data only with the recipients listed below, each bound by a written data processing agreement (Art. 28 GDPR) where applicable. We do not sell personal data.

  • National toll authorities — license plate, country of registration and vehicle category are transmitted to the competent authority of the destination country in order to register your vignette. This is the entire point of the service and cannot be opted out of without cancelling the order. Recipients include, among others, the National Toll Payment Services Plc. (Hungary), Národná diaľničná spoločnosť (Slovakia), Státní fond dopravní infrastruktury (Czech Republic), CNAIR – Compania Naţională de Administrare a Infrastructurii Rutiere (Romania), the Bulgarian toll operator, and the Swiss Federal Office for Customs and Border Security.
  • Stripe Payments Europe, Ltd. — payment processing.
  • Zoho Corporation B.V. — transactional email delivery (order confirmations, invoices, support replies).
  • Cloudflare, Inc. — CDN, DDoS protection and DNS.
  • Google Ireland Limited — Google Analytics, Google Tag Manager and Google Ads conversion tracking, activated only after your consent, with IP anonymisation enabled.

Where personal data is transferred outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses and, where relevant, additional technical and organisational measures.

6. Retention

  • Order and invoice records: up to 7 years, as required by tax and accounting law.
  • Support conversations: up to 24 months after the last message.
  • Analytics data: up to 14 months, in aggregated form.
  • Marketing consent records: until you withdraw consent, plus a short audit trail.
  • Server log files: up to 30 days for security purposes.

Once the retention period expires, data is deleted or fully anonymised.

7. Your rights

Under the GDPR you have the right to:

  • access your personal data and receive a copy;
  • request correction of inaccurate data;
  • request deletion ("right to be forgotten"), subject to legal retention obligations;
  • restrict or object to processing based on our legitimate interests;
  • data portability — receive your data in a structured, machine-readable format;
  • withdraw consent at any time (for consent-based processing);
  • lodge a complaint with your national data protection authority.

To exercise any of these rights, email hello@mrvignette.com. We respond within 30 days.

8. Cookies

To make mrvignette.com attractive and to enable certain functions we use cookies — small text files stored on your device. Cookies cannot execute programs or transfer viruses.

  • Strictly necessary cookies (session, cart, security, language and currency preferences) are stored on the basis of our legitimate interest (Art. 6(1)(f) GDPR). Without them the site cannot function properly.
  • Analytics and marketing cookies (e.g. Google Analytics, Google Ads) are set only after your explicit consent via the cookie banner (Art. 6(1)(a) GDPR).

Most of the cookies we use are session cookies that are automatically deleted at the end of your visit. You can change your preferences at any time from the cookie banner or in your browser settings.

9. Web analysis & advertising tools

Google Analytics. We use Google Analytics with IP anonymisation to understand how visitors use the site. The information generated by the cookie about your use of the site (including the shortened IP address) is transferred to a Google server and stored there. Google uses this information on our behalf to compile reports and provide related services. Data at user and event level linked to cookies or advertising IDs is anonymised or deleted after 14 months.

Google Tag Manager. Tag Manager itself is a cookie-less domain that only triggers other tags; it does not access their data. If you decline consent at the domain or cookie level, this applies to all tags implemented through Tag Manager.

Google Ads & conversion tracking. With your consent we use Google Ads to draw attention to our offers on external websites and to measure the success of individual campaigns. A conversion cookie is set when you click a Google ad; it expires after 30 days and is not used to personally identify you.

You can opt out of Google Analytics by installing the browser add-on available at tools.google.com/dlpage/gaoptout. If you delete your cookies, you must set the opt-out again.

10. Contact by email

If you contact us by email or via a contact form, the data you transmit (including your contact details) is stored so that we can process your enquiry and follow up. This data is not passed on without your consent and is deleted when the enquiry has been fully handled and no retention obligations apply.

11. Payment processing (Stripe)

Payments are processed by Stripe Payments Europe, Ltd. When you enter your card details, they are transmitted directly to Stripe over an encrypted connection and are not stored on our servers. Stripe processes your data as an independent controller for the purposes of fraud prevention and as our processor for the purpose of executing the payment. See Stripe's privacy notice at stripe.com/privacy.

12. Transactional email (Zoho Mail)

Order confirmations, invoices and support replies are sent via Zoho Mail. Zoho processes the email address, sender/recipient metadata and message content strictly on our behalf. See Zoho's privacy notice at zoho.com/privacy.

13. Security

All traffic between your browser and our servers is encrypted with TLS 1.3. Data at rest is stored in ISO 27001-certified European data centres. Administrative access is protected by two-factor authentication and audit logging. We regularly review our technical and organisational measures.

14. Children

Our service is not directed at children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided us with data, please contact us and we will delete it.

15. Changes to this policy

We may update this policy from time to time. The date at the top of this page reflects the last revision. Material changes will be highlighted on the homepage and, where legally required, notified to you by email.

16. Contact for privacy matters

For any question relating to this policy or to exercise your rights, email hello@mrvignette.com or write to Funko International AB, Jaktstigen 24, 78450, Borlange, Sweden.