Privacy policy
How EasyVapor (easyvapor.store) processes personal data when you visit this shop, place a Cash on Delivery order, or contact us.
Last updated: 25 August 2026
1. Data controller
The data controller for this website is the trader that operates the EasyVapor shop at https://easyvapor.store.
Brand / trading name: EasyVapor
Website: https://easyvapor.store
Legal form: not yet published as verified public information
Registered address: not yet published as verified public information
Company registration number: not yet published as verified public information
VAT ID: not yet published as verified public information, where applicable
Privacy email: [email protected]
Customer-service email: [email protected]
Contact form: Get in touch
The full registered legal name, legal form, registered office, company-registration authority, registration number, VAT ID, authorised representative and geographical address will be added here and on the Impressum when they can be shown as verified facts. They will then match invoices, order emails and return instructions.
Until those details are published, the identity disclosure required by GDPR Article 13 is incomplete. We still process personal data as described in this notice. You may exercise your rights using the privacy email or the contact form.
We have not published an EU representative under GDPR Article 27. Whether one is required depends on the controller’s country of establishment, which is not yet published. If a representative is appointed, the name, address and contact details will be added here. We have not appointed a data protection officer under Article 37; if one is later required, that person will be named here.
2. Scope
This notice applies to easyvapor.store, customer accounts, checkout, Cash on Delivery orders, the contact form, email, WhatsApp if you choose to use it, product reviews, and related shop administration. Other websites, courier tracking portals and messaging apps have their own privacy terms.
3. Categories of personal data
Depending on how you use the shop, we may process:
- Identity and contact data: name, delivery address, email, phone number, language preference.
- Account data: username, user ID, login records and a hashed password if you create an account. Guest checkout does not require an account.
- Order data: products, quantities, amounts, order status, notes you add, and Cash on Delivery amount due.
- Delivery and COD data: tracking number, courier status, delivery attempts, refusal or return-to-sender records.
- Refund data: where a COD refund is paid by bank transfer, the account holder’s name, IBAN or account number, bank details if needed, and the refund amount. We do not collect card numbers at checkout. Cash on Delivery is paid to the courier; we do not store only “amount due and order status”.
- Invoice, tax and accounting data: order totals, VAT treatment where applicable, and records needed for bookkeeping.
- Age-verification data: your confirmation on the age gate that you are 18 or over (or the higher local vaping age). We do not ask you to upload identity documents through this website. We typically store only that age was confirmed, not a copy of an identity document. A courier may inspect identification at delivery under its own process.
- Correspondence: emails, contact-form submissions, and WhatsApp messages if you write to us there, including phone number, profile information shown by WhatsApp, message content and metadata.
- Reviews: name, email, review text, rating, and technical data such as IP address used to submit the review.
- Attribution and source data: referrer, landing page, UTM or similar campaign parameters, and device/session identifiers used by WooCommerce order attribution when you have consented to those cookies.
- Technical and security data: IP address, browser type, device information, pages requested, timestamps, and logs used to keep the shop secure and to investigate abuse, duplicate refusals or suspected fraud.
- Cookie and similar-technology data: cookies listed in the Cookie policy, cookie-consent choices, and local storage used for the age gate and dismissed notices.
4. Purposes and legal bases
We process personal data only where a GDPR Article 6 ground applies. Where we rely on legitimate interests, those interests are stated in the table. Non-essential cookies and similar technologies are not treated as “necessary” merely by renaming them.
| Activity | Typical data | Purpose | Legal basis |
|---|---|---|---|
| Accept and fulfil orders | Contact, address, products, amounts | Take, confirm and perform the contract | Art. 6(1)(b) contract |
| Courier delivery and COD collection | Name, address, phone, amount due, tracking | Deliver goods and collect payment on delivery | Art. 6(1)(b) contract |
| Invoices and tax records | Order, identity and amounts | Keep legally required accounts | Art. 6(1)(c) legal obligation |
| Customer service and claims | Correspondence, order, photos you send | Answer queries and handle withdrawal, defects and complaints | Art. 6(1)(b) contract and/or Art. 6(1)(f) legitimate interests in handling claims and defending legal rights |
| COD refunds by bank transfer | Name, IBAN or account, amount | Reimburse you after withdrawal, refusal or an accepted claim | Art. 6(1)(b) contract and Art. 6(1)(c) where accounting rules require a payment record |
| Accounts and login | Username, user ID, password hash, login records | Provide an optional account | Art. 6(1)(b) contract |
| Age gate and adult-only sale | Age-confirmation flag; courier ID check at delivery if required | Prevent sale of nicotine products to minors | Art. 6(1)(c) where a legal age rule applies, otherwise Art. 6(1)(f) legitimate interests in age-restricted retail compliance. We do not use this as marketing consent. |
| Shop security and abuse prevention | IP, logs, order and refusal patterns | Protect the site, staff and other customers against attacks, fraud and repeated unpaid-COD abuse | Art. 6(1)(f) legitimate interests in running a secure shop and preventing abuse. Those interests are not overridden by your interests where the processing is limited to security and abuse control. |
| Product reviews | Name, email, review, IP | Display reviews and send a review invitation after purchase where that feature is used | Art. 6(1)(f) legitimate interests in publishing genuine purchase reviews; Art. 6(1)(a) consent where a review email is optional and requires consent under applicable ePrivacy rules |
| Necessary shop operation | Session, cart, checkout, language, security cookies | Keep the cart, session, login and chosen language working, and protect the site | Art. 6(1)(b) and/or Art. 6(1)(f); strictly necessary cookies under applicable ePrivacy rules do not require consent |
| Order attribution (optional) | Referrer, UTM, landing page, first-party attribution cookies | Understand which link or campaign led to an order | Art. 6(1)(a) consent. These cookies are not activated before you accept them. |
| Marketing email | Email and consent record | Send promotional email if we offer it | Art. 6(1)(a) consent, or another ground allowed by the law of your country for existing customers. We do not currently run a separate marketing-email list on this site. |
We do not sell personal data. Providing order data is required to conclude a contract. You may refuse optional cookies and still place an order.
5. Recipients
We share data only where needed to run the shop. We do not invent extra vendors. Named providers below are those actually used in the current technical setup.
| Recipient | Purpose | Typical data | Region / transfer note |
|---|---|---|---|
| Destination-country couriers (the carrier assigned to your order) | Delivery and COD collection | Name, address, phone, order reference, amount due | The delivery country. Each courier applies its own terms. |
| SiteGround (hosting). Infrastructure is provided on Google Cloud. | Website, database, backups, caching and CDN | Orders, accounts, logs, uploaded content | SiteGround offers EU data-centre options. The exact data-centre used for this account is not published here as a verified public fact. Cached copies and backups may be stored on SiteGround’s network. SiteGround’s data-processing terms and Google Cloud’s terms apply. |
| Email processing via Google (Gmail / Google LLC) | Read and reply to customer-service and privacy mail, including messages sent to the easyvapor.store addresses below | Email addresses, message content, order details you include | Google LLC, United States. Google may process mail outside the EEA under Google’s terms and Google’s data-processing terms, including standard contractual clauses where Google uses them. |
| WhatsApp / Meta Platforms | Customer chat if you contact the number or QR code we publish | Phone number, profile information, messages, metadata | According to WhatsApp’s and Meta’s privacy terms, which may include processing outside the EEA. |
| Your bank (COD refunds) | Pay a refund by transfer when you agree | Name, account/IBAN, amount | The country of the paying and receiving banks. |
| WooCommerce product-review plugin (CusRev / customer-reviews-woocommerce) | Collect and display product reviews; send review invitations if that feature is used | Name, email, order reference, review, IP | If invitations are sent through the plugin provider, that provider’s terms and processing location apply. Reviews displayed on this site are stored with the shop. |
| Shop software providers used on the site: WordPress, WooCommerce, Elementor, Rank Math, WPML and WooCommerce Multilingual | Operate the shop, languages, checkout and SEO metadata | As needed for that function; plugins generally process data on our hosting unless a cloud feature is separately enabled | Primarily on our host. We have not enabled a separate Google Analytics, Meta Pixel or similar marketing tag on this site. |
| Professional advisers and authorities | Legal, accounting or a mandatory request | Only what the matter requires | EEA or the authority’s country. |
Staff who handle orders, returns and support can access data needed for their task. Access is restricted to that purpose.
6. International transfers
Some processing takes place outside the European Economic Area. In particular:
- Google (mail): customer-service and privacy messages sent to [email protected] or [email protected] may be stored and read using Google’s Gmail service. Google LLC is established in the United States. Google states that it uses the EU–US Data Privacy Framework where applicable and/or standard contractual clauses. You can ask us for a copy of the relevant safeguard documents that we are able to share, or see Google’s published terms.
- WhatsApp / Meta: if you choose WhatsApp, Meta processes that communication under its own terms, which may involve transfers outside the EEA, including the United States. Use email or the contact form if you do not want Meta to process the message.
- Hosting / CDN: SiteGround hosting runs on Google Cloud. We do not publish a verified single-country server location for this account. If a cache, backup or support access involves a country without an EU adequacy decision, SiteGround’s and Google Cloud’s data-processing terms, including standard contractual clauses where they use them, are the relevant safeguards.
We do not claim that all data stays “mainly in the EU”. Couriers process delivery data in the destination country. To request a copy of the safeguards we can provide, email [email protected].
7. Retention
We keep data no longer than needed for the purpose, including legal claims and statutory record-keeping. The seller’s country of establishment is not yet published, so a single national accounting period cannot be confirmed here. Consumer-claim periods also differ among the delivery countries.
| Record | Retention |
|---|---|
| Order, invoice and accounting records | For the contract, then for tax, accounting and consumer-claim periods that apply. Until a registered-country period is published, we keep these records for up to six years, or any longer mandatory period that later applies. |
| Customer account | Until you ask us to delete it, or after 24 months of inactivity, subject to order records that must be kept longer. |
| Support email, contact-form messages and WhatsApp messages we retain | While the case is open, then 24 months after closure, unless a claim, chargeback or legal hold requires longer. |
| Defect, return and withdrawal evidence (including photos you send) | Until the relevant legal-guarantee or claim period expires, and any related accounting period. |
| Refund bank details | Deleted or restricted after the refund is paid and reconciled — typically within 90 days — unless a longer accounting or anti-fraud record is required. |
| Security and abuse logs | Typically 90 days, or longer while an incident is investigated. |
| Cookie-consent cookie | 12 months, or until you clear it or change your choice. |
| Cart / session cookies | Session or up to about 48 hours for the WooCommerce session, unless you stay signed in. |
| Abandoned carts | Guest session as above. If an account exists, stored cart data follows the account period unless you empty the cart. |
| Age-gate confirmation | Stored in your browser (local storage) until you clear site data. We do not keep identity-document copies from the website. |
| Product reviews | Until you ask us to remove a review or the listing is removed, subject to any need to keep evidence of published content. |
| Marketing consent records | Not currently collected as a separate mailing list. If collected later: while consent remains valid, plus a short evidence period after withdrawal. |
8. Your rights
You may request access, rectification, erasure, restriction of processing, objection to processing based on legitimate interests, and data portability where the GDPR provides those rights. You may withdraw consent at any time, without affecting the lawfulness of processing before withdrawal. Cookie consent can be changed through the permanently available Cookie settings control.
These rights are not absolute. We may refuse or limit a request where the GDPR allows, for example where we must keep invoices, or where we cannot identify you. We may ask for reasonable information to verify your identity before we act.
We respond without undue delay and normally within one month. Where permitted by GDPR Article 12, this period may be extended by up to two additional months for complex or numerous requests. If we extend the period, we will tell you within the first month and explain why.
Send requests to [email protected] or use the contact form and mark the message as a privacy request.
You have the right to lodge a complaint with a supervisory authority in your country of habitual residence, your place of work, or the place of the alleged infringement. A list of EU authorities is published by the European Data Protection Board: EDPB members. A lead supervisory authority for this shop will be named when the controller’s country of establishment is published.
9. Age verification
This shop sells nicotine products for adults. You must be 18 or over, or older if the delivery country sets a higher vaping age.
On the website we show an age gate. If you confirm you are 18+, your browser stores a local flag (vr_age_ok). That is not marketing consent and is not an identity-document check. We do not ask you to upload a passport, national ID card or driving licence through this website, and we do not intend to keep full copies of identity documents.
The courier may ask to see valid identification at delivery where required. That inspection is operated by the courier. We typically receive only confirmation that delivery could or could not be completed, not a scan of your document. If a target country later requires us to keep additional age-verification evidence, we will limit that to what the law requires and update this notice.
We do not knowingly collect personal data from children. If you believe a minor has ordered or submitted data, email [email protected] and we will delete or restrict that data where the law allows.
10. WhatsApp
The footer and quick-contact control offer WhatsApp via a UK number and QR code. WhatsApp is optional. If you choose it, your phone number, profile information, message content and communication metadata may be processed by WhatsApp/Meta under WhatsApp’s privacy policy.
Do not send identification documents or other sensitive information through WhatsApp unless we specifically request them through an approved secure process. Prefer email or the contact form for privacy requests and identity checks.
Shop staff who handle customer service may read WhatsApp messages sent to the published number. We keep those messages as support correspondence (section 7). Meta’s retention of copies on its systems is outside our control.
11. Cookies and similar technologies
A full list of cookie names, providers, purposes, categories, lifetimes and how to refuse them is in the Cookie policy.
Non-essential cookies and similar technologies are not activated before valid consent is obtained. You may refuse or withdraw consent at any time through the permanently available Cookie settings link in the footer. Refusing optional cookies does not block browsing or Cash on Delivery checkout.
The first layer of the cookie banner offers Accept all and Reject all with equal prominence. Optional categories are not pre-selected. Age-gate confirmation is not cookie consent.
12. Automated decision-making
We do not make decisions producing legal or similarly significant effects based solely on automated processing, unless explicitly described here. Orders may be reviewed where we suspect invalid details, age-restriction problems or abuse (including repeated unpaid COD refusals). A person can review those cases. Security controls such as rate limits may block automated form spam; that is not a credit-style profile of you.
13. Security
We use access controls, encrypted connections (HTTPS), restricted staff access, backups and other proportionate technical and organisational measures. This description is intentionally general so that it does not help attackers.
14. Changes
We will update this notice when processing, vendors or the published controller identity change. The date at the top is the current version. Material changes will be shown on this page.
15. Contact
Privacy requests: [email protected]
Orders and general support: [email protected]
Contact form: Get in touch
Related pages: Cookie policy · Terms of service · Impressum
