VAPEBUS Privacy Policy
VAPEBUS respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you visit our website or place an order.
Data Controller
VAPEBUS is the data controller responsible for your personal data.
If you have questions about this Privacy Policy or how your data is handled, you can contact us at:
Email: [email protected]
The Personal Data We Collect
We collect information to process your orders, improve our services, and maintain the security of our website.
Information You Provide
You may provide personal data when placing an order, creating an account, or contacting us. This may include:
• Name
• Email address
• Phone number
• Billing address
• Delivery address
• Age verification information
• Account login credentials
• Communication preferences
Information Collected Automatically
When you use our website, certain information may be collected automatically, including:
• IP address
• Browser type and version
• Device information
• Pages visited
• Time spent on pages
• Access dates and times
• Website usage data
This information helps us understand how visitors use our site and improve performance.
Location Data
If you allow location access through your browser or device, we may use this information to improve your shopping experience or provide relevant services.
You can disable location access at any time through your device settings.
Cookies
We use cookies and similar technologies to operate our website and improve user experience.
Types of cookies we use include:
Session Cookies
Help operate essential website functions.
Preference Cookies
Remember your settings and preferences.
Security Cookies
Help protect user accounts and prevent fraudulent activity.
Before placing non-essential cookies on your device, we will request your consent through our cookie banner in accordance with UK privacy regulations.
You can disable cookies through your browser settings, although some features of the website may not function properly.
Age & Identity Verification
VAPEBUS sells vaping products that are restricted to adults.
To comply with UK laws prohibiting the sale of vaping products to individuals under the age of 18, we may perform age verification checks.
We may use third-party age verification services to confirm your identity and age.
If automatic verification fails, we may request a clear photo of your identification document. Once verification is completed, we store your age verification status so that you do not need to repeat the process for future purchases.
How We Use Your Personal Data
We use your personal data to:
• Process and deliver orders
• Provide customer support
• Verify age eligibility
• Improve our website and services
• Monitor usage and detect fraud
• Send service notifications
• Provide order updates
• Send promotional offers or product updates (if you have opted in)
You can unsubscribe from marketing communications at any time by using the unsubscribe link in our emails.
Legal Basis for Processing
Under UK data protection laws, we process personal data based on the following legal grounds:
Contractual Necessity
To process orders and provide our services.
Legal Obligation
To comply with applicable laws, including age verification requirements.
Legitimate Interests
To operate, maintain, and improve our website, prevent fraud, and understand how customers use our services.
Consent
For marketing communications where you have chosen to receive them.
Legitimate Interests
We may process your data where necessary for legitimate business interests, including:
• Operating and improving our website
• Preventing fraud or misuse
• Analyzing customer behavior and website performance
• Communicating with customers regarding products they purchased or showed interest in
We ensure these interests do not override your data protection rights.
Automated Decision-Making
Some of our service partners use automated systems to help ensure secure transactions and regulatory compliance.
These may include:
• Fraud detection checks by payment providers
• Age and identity verification services
• Credit checks when certain payment options are used
Where required by law, you have the right to request human review of automated decisions that affect you.
How Long We Keep Your Data
We retain personal data only for as long as necessary to:
• Provide our services
• Meet legal and tax obligations
• Resolve disputes
• Prevent fraud
When your data is no longer required, it will be securely deleted or anonymized.
Who We Share Your Data With
We only share personal information when necessary and with trusted service providers.
Service Partners
Examples include:
• Website hosting providers
• Ecommerce platform providers
• Email and SMS communication tools
• Customer support systems
• Analytics and search tools
• Order management and logistics providers
• Payment processors
These partners may only process your data on our behalf and must keep it secure.
Legal Requirements
We may disclose personal data when required to:
• Comply with legal obligations
• Respond to lawful requests from authorities
• Protect our rights, customers, or public safety
Payments
Payments on our website are processed through secure third-party payment providers.
We do not store full credit or debit card information.
Payment providers may collect information including:
• Name and contact details
• Billing and delivery address
• Payment card information
• Transaction details
• IP address and device information
These providers follow industry security standards such as PCI DSS to protect payment data and may share data with banks or payment networks to complete transactions and prevent fraud.
Data Security
We take appropriate technical and organisational measures to protect your personal data, including:
• Secure website encryption (SSL)
• Access control systems
• Secure payment processing
• Fraud monitoring systems
While we take reasonable precautions to protect your information, no online system can guarantee absolute security.
International Data Transfers
Some of our service providers may store or process personal data outside the United Kingdom.
When this occurs, we ensure appropriate safeguards are in place, such as:
• UK International Data Transfer Agreement (IDTA)
• Standard Contractual Clauses (SCCs)
These safeguards ensure your personal data remains protected.
Your Rights
Under UK data protection law, you have the right to:
• Access the personal data we hold about you
• Request correction of inaccurate data
• Request deletion of your data
• Restrict or object to certain processing activities
• Receive a copy of your data (data portability)
• Withdraw consent where applicable
• Request human review of automated decisions
To exercise your rights, please contact:
Complaints
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the UK data protection authority.
Information Commissioner's Office
Website: https://ico.org.uk
However, we encourage you to contact us first so we can try to resolve your concern.
Links to Other Websites
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites.
Please review their privacy policies before providing personal information.
Children's Privacy
Our website and services are intended for adults aged 18 or older.
We do not knowingly collect personal data from individuals under 18. If you believe that a minor has provided personal information to us, please contact us so we can remove the data.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time, Any changes will be posted on this page.
We encourage you to review this policy periodically to stay informed about how we protect your personal data.