Effective Date: July 18, 2025
1. Introduction
Vapeogram Ltd (“we”, “us”, “our”) operates vapeogram.co.uk. We are committed to protecting your privacy and processing your personal data lawfully and transparently.
2. Scope
This policy explains how we collect, use, disclose, store, and protect your personal data when you visit our website, place orders, subscribe to communications, or contact us.
3. What We Collect
3.1 From You
- Identity & Contact: Name, billing/shipping address, email, phone
- Transactions: Payment details (processed via secure partners)
- Age Verification: To comply with regulations (confirming you are 18+)
- Marketing Preferences: Consent for promotional emails
3.2 Automatically
- Technical & Usage Data: IP address, device/browser identifiers, operating system, browsing patterns, time on site, pages visited
- Cookies & Tracking Technologies: Session, preference, performance, and marketing cookies (see our Cookie Policy for details)
4. How We Use Your Data
We use collected data to:
- Process orders and payments
- Verify age in compliance with regulations
- Communicate about your orders and support queries
- Send newsletters or marketing emails (with your consent)
- Enhance and personalize your site experience
- Analyze performance and user behavior via analytics tools
5. Legal Basis for Processing
- Performance of Contract: To fulfill your orders
- Legal Compliance: Age verification per UK law
- Consent: For marketing communications
- Legitimate Interests: Improving website performance and preventing fraud
6. Sharing Your Data
We share your data only with trusted third parties who assist us, including:
- Payment Processors: Secure order payments
- Delivery Partners: Logistics/couriers like DPD or Royal Mail
- Analytics Providers: Tools such as Google Analytics
- Age-Verification Services: When checking compliance
- Legal/Government Authorities: If legally required
These third parties are obligated to use your data only for the specified services and in line with UK data protection regulations.
7. Data Transfers
We store/process data within the UK or EEA. If any data transfer outside these regions occurs, it is protected via EU/UK-approved safeguards (e.g., Standard Contractual Clauses).
8. Data Retention
We keep data only as long as necessary:
- Order Records: Up to 6 years (for accounting and legal purposes)
- Marketing Consent: Until you withdraw consent
- Other Personal Data: For as long as needed for services provided
9. Security Measures
We take the following steps to keep your data secure:
- SSL encryption (HTTPS) on all site pages
- Secure server storage and access controls
- Regular security reviews
Note: All data transmission carries inherent risk; your access/updates help improve protection.
10. Your Rights
Under GDPR, you have rights to:
- Access your data
- Correct inaccuracies
- Delete your data (“right to be forgotten”)
- Restrict or object to processing
- Data portability (for what you provided to us)
- Withdraw consent (especially for marketing communications)
- Lodge a complaint with the ICO if you have concerns
To exercise any of these rights, contact us at privacy@vapeogram.co.uk or call +44 1234 567890.
11. Children
We only allow sale of products to individuals aged 18+. We do not knowingly collect data from minors. If you’re concerned a minor’s data is stored, please inform us; we will promptly delete it.
12. Third‑Party Links
Our site may include links to other websites (e.g., social media, suppliers). We are not accountable for their practices. Please review their privacy policies.
13. Changes to This Policy
We may update this policy periodically. Major updates will be notified via prominent site banner or email. The revised Effective Date at top marks when changes take effect.
14. Contact Information
Vapeogram
24 High street Bracknell RG12 1LL
Phone: +01344 377945
Email: vapeogram@gmail.com
✅ Privacy at a Glance
- What We Collect: Identity, contact, payment, cookies, site usage
- Why We Use It: Orders, age checks, communication, marketing (with consent), analytics
- Sharing With Others: Only with partners who aid service delivery (payment couriers, analytics, age checks)
- Your Controls: Access, correction, erasure, restrict, object, withdraw consent
Security: SSL, secure servers, encryption—though all digital systems have inherent risks