Privacy Policy

Greetings and welcome to the privacy notice of Vape Lust. At Vape Lust, we hold a deep respect for your privacy and are dedicated to safeguarding your personal data. The purpose of this privacy notice is to apprise you of how we manage your personal data when you visit our website,, irrespective of your location. We will also outline your privacy rights and elucidate how the law provides protection to you.

The privacy policy consists of

  1. Important Information And Who We Are
  2. The Data We Collect About You
  3. How Is Your Personal Data Collected.
  4. How Do We Use Your Personal Data
  5. Disclosures Of Your Personal Data
  6. International Transfers
  7. Data Security
  8. Data Retention
  9. Your Legal Rights
  10. Glossary

1. Important Information and Who We Are

Purpose of This Privacy Notice

The purpose of this privacy notice is to provide you with information on how Vape Lust collects and processes your personal data when you utilize our website. This includes any data you may provide when registering on our website, subscribing to our newsletter, or purchasing a product from us.

Please note that our website is not designed for individuals under the age of 18, and we do not knowingly collect data regarding persons under the age of 18.

It is vital that you read this privacy notice in conjunction with any other privacy or fair processing notice we may provide on specific occasions when we are collecting or processing personal data concerning you. This will ensure that you have a comprehensive understanding of how and why we are utilizing your data. This privacy notice is intended to complement the other notices and is not intended to supersede them.

Vape Lust is the controller and is accountable for your personal data, referred to collectively as “Vape Lust

,” “we,” “us,” or “our” in this privacy notice.

We have designated a data privacy manager who is responsible for handling inquiries concerning this privacy notice. If you have any questions or requests concerning this privacy notice, including your legal rights, please contact us using the contact information provided on our website.

It is crucial that the personal data we maintain about you is accurate and up to date. Therefore, please inform us if there are any changes to your personal data during your interaction with us.

Additionally, please note that we reserve the right to revise this privacy notice at any time, in accordance with applicable data protection regulations. Any changes made to this notice will be posted on our website, and we recommend that you review this notice periodically to stay informed about how we collect and process your personal data.

Our website may feature links to third-party websites, plug-ins, and applications. By clicking on these links or enabling these connections, you may allow third parties to gather or share data about you. We do not regulate these third-party websites and are not accountable for their privacy policies. Therefore, when you exit our website, we recommend that you peruse the privacy notice of each website you visit.

2. The Data We Collect About You

Personal data or personal information refers to any information about an individual from which that person can be identified. Anonymous data, on the other hand, is not considered personal data as the identity has been removed.

We may collect, use, store, and transfer various kinds of personal data about you, which we have categorized as follows:

  • Identity Data: This includes your first name, last name, email address, title, and Experian Ltd age verification results.
  • Contact Data: This includes your billing and delivery address, email address, and telephone numbers.
  • Transaction Data: This includes details about the products you have purchased from us, returns, refunds, and other relevant information to manage our customer relationship.
  • Technical Data: This includes your internet protocol (IP) address, login information, browser type and version, browser plug-in types and versions, operating system, and platform.
  • Usage Data: This includes information about how you use our website.
  • Marketing and Communications Data: This includes your preferences in receiving marketing from us and your communication preferences.

Additionally, we collect, use, and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated data may be derived from your personal data but is not considered personal data in law, as it does not directly or indirectly reveal your identity. However, if we combine or connect aggregated data with your personal data to directly or indirectly identify you, we treat the combined data as personal data, which will be used in accordance with this privacy notice.

It is worth noting that we do not collect any Special Categories of Personal Data about you. This includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data. Moreover, we do not collect any information about criminal convictions and offences.

3. How is your personal data collected?

Our organization employs diverse techniques to gather information from you and about you. This includes obtaining data through direct interactions. You have the option to disclose your Identity and Contact Data by completing forms or communicating with us via postal mail, phone, email, or other means. This encompasses any personal data that you furnish when performing the following actions:

  • Placing an order for our products
  • Establishing an account on our website
  • Subscribing to our newsletter
  • Providing feedback to us.

Automated technologies or interactions. Our website may gather Technical Data concerning your equipment, browsing actions, and patterns through the employment of automated technologies or interactions. This personal data is collected by utilizing cookies, server logs, and other similar technologies.

Third parties or publicly available sources. Please be advised that we may obtain personal data from various third-party sources as indicated below:

  • We may receive Technical Data from analytics providers such as Google that are located outside the EU, and search information providers such as Google or Bing that are based outside the EU.
  • Contact, Financial, and Transaction Data may be received from technical, payment, and delivery service providers situated in the UK or outside the EU.
  • We may obtain Identity and Contact Data from data brokers or aggregators, such as GB Group, located within the EU.
  • Identity and Contact Data may also be collected from publicly available sources, such as Companies House and the Electoral Register, situated inside the EU.

4. How We Use Your Personal Data

We shall utilize your personal data solely in accordance with the law. Typically, we shall employ your personal data in the following circumstances:

Where it is necessary to execute the contract that we are either about to enter into or have already entered into with you.

Where it is essential for our legitimate interests, or those of a third party, and such interests are not outweighed by your interests or fundamental rights.

Where we are obligated to comply with a legal or regulatory requirement. We generally do not rely on consent as the legal basis for processing your personal data. However, you have the right to withdraw your consent for marketing purposes at any time by contacting us.

Purposes for which we will use your personal data

We have outlined in the table format below a description of all the ways we intend to utilize your personal data, as well as the legal bases we rely on to do so. We have also identified our legitimate interests where appropriate. Kindly note that we may process your personal data for more than one lawful ground, depending on the specific purpose for which we are utilizing your data. If you require more information about the specific legal ground we rely on to process your personal data, please contact us.

Purpose/ActivityType of dataLawful basis for processing including basis of legitimate interest
To register you as a new customer
(a) Identity

(b) Contact
Performance of a contract with you
To process and deliver your order including

(a) Manage payments

(b) Collect and recover money owed to us
(a) Identity

(b) Contact

(c) Financial

(d) Transaction

(e) Marketing and Communications
(a) Performance of a contract with you

(b) Necessary for our legitimate interests (to recover debts due to us)
To manage our relationship with you which will include:

(a) Notifying you about changes to our terms or privacy policy
(a) Identity

(b) Contact

(c) Profile
(a) Performance of a contract with you

(b) Necessary to comply with a legal obligation
To manage our relationship with you which will include:

(a) Notifying you about changes to our terms or privacy policy
(a) Identity

(b) Contact

(c) Profile
(a) Performance of a contract with you

(b) Necessary to comply with a legal obligation
To enable you to partake in a prize draw, competition or complete a survey(a) Identity

(b) Contact

(c) Profile

(d) Usage

(e) Marketing and Communications
(a) Performance of a contract with you

(b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)(a) Identity

(b) Contact

(c) Technical
(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)

(b) Necessary to comply with a legal obligation
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you(a) Identity

(b) Contact

(c) Profile

(d) Usage

(e) Marketing and Communications

(f) Technical
Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy)
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences(a) Technical

(b) Usage
Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)
To make suggestions and recommendations to you about goods or services that may be of interest to you(a) Identity

(b) Contact

(c) Technical

(d) Usage

(e) Profile
Necessary for our legitimate interests (to develop our products/services and grow our business)


Our aim is to offer you choices concerning certain uses of your personal data, particularly in relation to marketing and advertising.

Promotional offers from us

We may utilize your Identity, Contact, Technical, Usage, and Profile Data to create an understanding of what products, services, and offers may be of interest or relevant to you (referred to as marketing). You will continue to receive marketing communications from us unless you have requested us to stop sending them.

Opting out

You have the option to ask us to cease sending you marketing messages by utilizing the opt-out links included in any marketing message you receive or by contacting us directly at any time. Please note that opting out of marketing messages will not affect personal data provided to us as a result of a product you have purchased or other transactions.


It is possible to adjust your browser settings to refuse all or some browser cookies, or to receive alerts when websites attempt to set or access cookies. However, please be aware that disabling or rejecting cookies may cause certain parts of our website to become inaccessible or function improperly.

Our “remember me” feature enables an automatic login process by generating a unique login ID, which is stored in a cookie. This eliminates the need to enter login details during subsequent visits to our site. If you share your computer with others, we advise against selecting this option, as it may grant other users access to personal or member-only information.

The cookies we use are categorized as “analytical” cookies. They enable us to identify and quantify the number of visitors to our website and track their movements while using it. This helps us to enhance the website’s functionality, for example by ensuring that users can locate the information they require with ease.

Change of purpose

We will only use your personal data for the purposes for which we collected it, unless we believe that we need to use it for another reason that is compatible with the original purpose. If you require clarification as to how the processing for the new purpose is compatible with the original purpose, please contact us.

If we need to use your personal data for a purpose that is unrelated to the original purpose, we will inform you and explain the legal basis that enables us to do so.

Please note that we may process your personal data without your knowledge or consent, in accordance with the aforementioned regulations, where this is required or permitted by law.

5. Disclosures of your personal data

  • We take the protection of your personal data seriously and may share it with third parties only for specific purposes as outlined in our privacy notice. These third parties may include internal parties as defined in our Glossary, external parties also defined in our Glossary, and third parties that we may sell, transfer, or merge parts of our business or assets. In the event of a business change, the new owners may use your personal data in the same way as set out in this privacy notice.
  • We ensure that all third parties who receive your personal data respect its security and treat it in accordance with the law. We do not permit our third-party service providers to use your personal data for their own purposes and allow them to process it only for specified purposes and in accordance with our instructions.

6. International Transfers

We do not transfer your personal data outside the European Economic Area (EEA).

7. Data Security

We have implemented suitable security measures to prevent any unintended loss, unauthorized use, access, alteration, or disclosure of your personal data. Moreover, we restrict access to your personal data to only those employees, agents, contractors, and third parties who require it for business purposes. They will process your personal data only based on our directives and are bound by confidentiality obligations.

We have established processes to address any suspected personal data breach and will inform you and the ICO of such breach as required by law.

8. Data Retention

We will only retain your personal data for the period necessary to fulfil the purposes for which we collected it, such as complying with legal, accounting, or reporting requirements. To establish an appropriate retention period for your personal data, we consider various factors, including the quantity, nature, and sensitivity of your personal data, the potential risk of unauthorized use or disclosure, the purposes for which we process your personal data, and whether we can attain those purposes through other means. Moreover, we also consider relevant legal requirements.

By law, we must maintain fundamental customer information, such as Contact, Identity, Financial, and Transaction Data, for six years after they cease being customers for tax purposes.

You may request us to delete your data in some circumstances. Furthermore, we may anonymize your personal data for research or statistical purposes, in which case we may use it indefinitely without further notice to you.

9. Your Legal Rights

Under specific circumstances, you have rights under data protection laws concerning your personal data. Please refer to the glossary below to learn more about these rights:

  • Request access to your personal data
  • Request correction of your personal data
  • Request erasure of your personal data
  • Object to the processing of your personal data
  • Request restriction of processing your personal data
  • Request transfer of your personal data
  • Right to withdraw consent

If you want to exercise any of the rights mentioned above, please contact us.

No fee is usually required

There are no charges for accessing your personal data or exercising your rights as mentioned above. However, if your request is clearly unfounded, repetitive, or excessive, we may charge a reasonable fee. Alternatively, we may decline to comply with your request in such situations.

What we may need from you

To confirm your identity and guarantee your right to access your personal data or exercise any other rights, we may need to ask for specific information from you. This is a security measure to ensure that personal data is not disclosed to unauthorized individuals. We may also contact you for additional information related to your request to expedite our response.

Time limit to respond

We endeavour to respond to all legitimate requests within one month. However, in some instances, it may take longer than a month, especially if your request is complex or involves multiple requests. In such cases, we will inform you and keep you updated on the status of your request.

10. Glossary

Lawful Basis

The term “Legitimate Interest” refers to the interest of our business in managing and conducting our operations to provide you with the best services/products and a secure experience. We ensure that we assess and balance any potential impact (both positive and negative) on you and your rights before processing your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you, unless we have your consent or are required or permitted by law. You can contact us for further information on how we evaluate our legitimate interests regarding specific activities and their potential impact on you.

“Performance of Contract” means processing your data when it is necessary for fulfilling a contract to which you are a party or to take necessary steps before entering into such a contract at your request.

“Complying with a legal or regulatory obligation” means processing your personal data when it is necessary for complying with a legal or regulatory obligation to which we are subject.

Third Parties

External Third Parties

The following are the categories of third parties with whom we may share your personal data:

  • Service providers acting as processors based in the UK who provide cloud computing, web design, and system administration services.
  • Professional advisers, including lawyers, bankers, auditors, and insurers based in the UK who provide consultancy, banking, legal, insurance, and accounting services.
  • HM Revenue & Customs, regulators, and other authorities based in the United Kingdom who require reporting of processing activities in certain circumstances.
  • Service providers based outside of the European Economic Area who provide email newsletters and other marketing services.
  • Different payment providers.
  • Couriers based in the UK who provide delivery services.

Your Legal Rights

These are your rights as a data subject under the GDPR:

  • Right of access: You have the right to obtain confirmation as to whether or not personal data concerning you is being processed, and, where that is the case, access to the personal data and information regarding the processing.
  • Right to rectification: You have the right to obtain the rectification of inaccurate personal data concerning you and to have incomplete personal data completed.
  • Right to erasure (‘right to be forgotten’): You have the right to obtain the erasure of personal data concerning you without undue delay in certain circumstances.
  • Right to restriction of processing: You have the right to obtain restriction of processing of your personal data in certain circumstances.
  • Right to data portability: You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from us.
  • Right to object: You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on the legitimate interests pursued by us or a third party, including profiling based on those provisions. We shall no longer process the personal data unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims.
  • Right to withdraw consent: If we process personal data based on your consent, you have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Have no product in the cart!
  • Sign Up
Lost your password? Please enter your username or email address. You will receive a link to create a new password via email.