Last updated: [18/6/25]
1. Who We Are
This website (https://topvapes.uk) is operated by TopVapes UK Limited (“we”, “our”, “us”). Registered office: Piccadilly Business Centre, Manchester, M12 6AE Contact email: [support@topvapes.uk] Telephone: 0330 5201450
We are committed to protecting your privacy and handling your personal data transparently and securely.
2. What Personal Data We Collect
We may collect and process the following information about you:
- Identity Data: Name, age/date of birth, and contact details.
- Contact Data: Billing address, delivery address, email address, and phone number.
- Account Data: Login details (if you create an account).
- Transaction Data: Details of your orders, payments, and purchases.
- Technical Data: IP address, browser type, device information, and website usage statistics (via cookies and analytics tools).
- Marketing Data: Your preferences for receiving marketing from us and your communication preferences.
We collect your information when you:
- Register for an account
- Place an order
- Subscribe to our newsletter or opt into marketing communications
- Contact us via our contact form, email, or live chat
- Browse our website (via cookies and analytics tools)
3. Why We Collect Your Data and How We Use It
We use your personal data for the following purposes:
- To process and deliver your orders (performance of a contract)
- To manage your account and provide customer support
- To communicate with you regarding your order, delivery, or support request
- To send you marketing (with your explicit consent)
- To improve our website and services through analytics and feedback
- To comply with legal or regulatory obligations
4. Lawful Basis for Processing
We process your personal data under the following lawful bases:
- Contract: Data required to fulfil our contract with you (order processing, customer service).
- Consent: For direct marketing and optional cookies, which require your explicit consent.
- Legal Obligation: For complying with applicable laws and reporting requirements.
- Legitimate Interest: To improve our services, prevent fraud, and maintain our website’s security.
5. Data Retention
We will only retain your personal data as long as necessary to fulfil the purposes we collected it for, including legal, accounting, or reporting requirements. Criteria for data retention includes:
- Order and transaction data: Retained for at least 6 years to comply with UK tax law.
- Account data: Retained while you hold an account with us (and deleted upon request or closure, unless otherwise required by law).
- Marketing data: Retained until you unsubscribe or withdraw consent.
- Technical data (cookies): See below and our cookie policy for retention periods.
6. Your Rights
You have the following rights regarding your personal data:
- Access: Request a copy of your personal data.
- Rectification: Correct inaccurate or incomplete data.
- Erasure (“right to be forgotten”): Request deletion when data is no longer needed, or you withdraw consent.
- Restrict Processing: Request restriction or suppression of your personal data.
- Object: Object to us processing your personal data for direct marketing or legitimate interest reasons.
- Data Portability: Request transfer of your data to another provider.
- Withdraw Consent: At any time, where processing is based on your consent (e.g., marketing).
To exercise your rights, please contact us at [support@topvapes.uk]. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) [https://ico.org.uk/].
7. Sharing Your Personal Data
We only share your data with trusted third parties necessary to provide our services, including:
- Payment processors (for secure payment handling)
- Delivery and logistics providers (for order fulfilment)
- IT/Website support and analytics providers (to help operate our website)
- Email/SMS marketing partners (only with your consent)
- Legal and regulatory authorities if required by law
We do not sell or rent your personal data to any other third parties. When sharing data, we always ensure it is protected and used only for its intended purpose.
8. Data Security
We implement appropriate technical and organisational security measures to protect your data from loss, misuse, or unauthorised access. These include secure servers, encryption, regular reviews, and staff training. Payments are processed using secure gateways and are PCI DSS compliant.
9. International Data Transfers
We aim to store and process your data within the United Kingdom, or in countries with adequate protection as recognised by UK law. If we transfer data outside the UK, we will ensure suitable safeguards are in place (such as appropriate contractual clauses).