Privacy policy

1. Overview

We operate vapeveo.com retail & wholesale vape business. This policy explains how we collect, use, store and share your personal data, in compliance with EU GDPR and U.S. CCPA/state privacy laws.

By browsing our site, registering an account or placing orders, you agree fully to this policy. If you disagree, stop using our website immediately.

2. What Personal Data We Collect

2.1 Data you submit voluntarily

  • Name, email, WhatsApp/phone, shipping & billing address
  • Payment info (masked card details, order & invoice records)
  • Wholesale inquiry info, feedback, customer service messages

2.2 Auto-collected technical data

IP address, device model, browser type, website click records, approximate regional location, error logs, cookies and pixel tracking signals.

Fully anonymized statistical data with no individual identification belongs exclusively to VapeVeo for business analysis.

3. How We Use Your Data

We process data only for legal permitted purposes:
  1. Contract performance: Process orders, delivery, payment settlement, after-sales service and wholesale cooperation (mandatory for order completion).
  2. Legitimate business interests (you may object anytime): Account anti-fraud verification, website security maintenance, product optimization, internal sales analysis, risk control to protect our platform and all users.
  3. Your explicit opt-in consent: Send marketing emails/promotions, enable Meta/Facebook retargeting cookies, share limited data with authorized partners for commercial ads. You can withdraw consent via our email at any time with no service penalty.
  4. Legal compliance: Retain transaction records to meet tax, customs and official regulatory requirements.

4. Cookie Rules

  1. Necessary cookies (cart, login, checkout security): Cannot be disabled, required for normal shopping functions.
  2. Analytics & marketing tracking cookies: Only activate if you manually agree on our homepage cookie banner.

    You can delete or block cookies via browser settings at any time; rejecting marketing cookies will not affect normal ordering.

5. Data Sharing & Cross-Border Transfer

5.1 Authorized service partners

We share minimal necessary data with vetted logistics, payment, cloud server and ad service providers under strict data protection agreements. Partners cannot use your data for independent marketing without your separate consent.

5.2 Legal & business transfer exceptions

  • We may disclose data if required by court, law enforcement or government authorities.
  • If our business merges, transfers assets or reorganizes, your data will be transferred as business assets, and we will notify you via website notice in advance.

5.3 Cross-border storage

Your data may be stored outside the EEA. We adopt EU standard contractual clauses (SCCs) to guarantee data protection as required by GDPR.

6. Data Retention

  • Order & tax records: Saved for 7 years to satisfy legal archive requirements.
  • Account personal info: Retained while your account is active; fully erased within 30 days after your account deletion request.
  • Marketing contact data: Stop promotional delivery once you opt out.
  • Device log data: Auto-deleted after 12 months, except anonymized statistical data.

7. Minor Protection

All products and services are for users aged 18+. We will not intentionally collect information from users under 16 (EEA) / 18 (US). If we discover underage personal data, we will delete all records within 72 hours. Contact us immediately if a minor submits data without guardian approval.

8. Your Legal Rights

For EEA users (GDPR rights, free of charge):

Right to access, correct, delete personal data, restrict processing, data portability, object to marketing/legitimate-interest processing, and file complaints with local data protection authorities. We reply to all valid requests within 30 days and may verify your identity before handling applications. We can reject repeated, abusive requests permitted by GDPR rules.

For California US users (CCPA rights):

You may request disclosure/deletion/correction of your personal data, opt out of data sharing for advertising via our website’s dedicated link, and designate authorized agents to submit requests. We will not cut service or discriminate against users exercising privacy rights.

9. Third-Party Liability Exclusion

Our website contains links to third-party social media, payment and logistics sites. We take no responsibility for their privacy rules or data security incidents. This policy only applies to data collected directly by vapeveo.com.

10. Liability Limitation (Favorable to VapeVeo)

  1. We adopt standard industry data security measures, but we do not guarantee absolute zero risk of network leakage. We are not liable for data loss caused by your own improper operation: sharing account passwords, accessing the site via unsafe public Wi-Fi, clicking fake external links, or disclosing personal info in unofficial chat channels.
  2. All privacy-related compensation claims must be submitted within 12 months after discovery of the incident, and our total maximum compensation liability will not exceed the total amount you spent on our store in the past 12 months.

11. Policy Updates

We reserve the right to revise this policy to match updated laws and business adjustments. Material updates will be posted on our homepage for 14 days before taking effect. Your continued use of the website after the update date means you accept the revised terms; stop using our site if you disagree.

12. Contact Us for Privacy Matters

All consent withdrawal, data access/deletion requests, privacy questions:

Email: vape@vapeveo.com