1. Introduction
Welcome to Puff Puff Vape Shop. We are committed to protecting your privacy and handling your personal data in a transparent and secure way.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you visit or make a purchase from puffpuffvape.co.uk
We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Age Restriction
Our website and products are intended only for individuals aged 18 or over (or the legal age for vaping in your jurisdiction). We do not knowingly collect personal data from anyone under this age. If we discover that we have collected data from a minor, we will delete it immediately.
3. Information We Collect
a. Personal Information
When you use our Website, we may collect:
- Full name
- Billing and shipping address
- Email address
- Phone number
- Order details and purchase history
- Payment information (processed securely by third-party payment providers; we do not store card details)
b. Technical and Usage Information
- IP address
- Browser and device type
- Operating system
- Pages visited and interactions on the Website
Cookies and similar tracking technologies
4. How We Use Your Information
We use your personal data to:
- Process and fulfil orders made through WooCommerce
- Verify age and comply with legal obligations
- Communicate with you about orders, delivery, or customer service enquiries
- Send marketing communications (only where you have given consent)
- Improve our Website, products, and customer experience
- Detect and prevent fraud or misuse
- Comply with legal and regulatory requirements
5. Legal Basis for Processing (UK GDPR)
We process your personal data under the following legal bases:
- Contract: To fulfil your orders and provide services
- Legal obligation: To comply with laws relating to age-restricted products, taxation, and accounting
- Legitimate interests: To operate and improve our business and Website
- Consent: For marketing communications and certain cookies (where required)
6. WooCommerce & Third-Party Services
Our Website is powered by WooCommerce, which collects data necessary to process orders and manage customer accounts.
We may share your data with trusted third parties, including:
- Payment processors (e.g. card payment providers)
- Delivery and courier services
- Age-verification services
- Website hosting providers
- Analytics services (e.g. Google Analytics)
- Email and marketing platforms (with consent)
- All third parties are required to handle your data securely and in accordance with UK data protection laws.
7. Cookies
We use cookies to:
- Enable core website functionality
- Remember your preferences
- Analyse website traffic and performance
- You can manage or disable cookies through your browser settings. Please note that disabling cookies may affect how the Website functions.
8. How We Store and Protect Your Data
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. Your data is stored securely and only accessible to authorised persons.
We retain personal data only for as long as necessary for the purposes outlined in this policy or to meet legal requirements.
9. Your Rights Under UK GDPR
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request deletion of your personal data
- Restrict or object to processing of your data
- Withdraw consent at any time (where processing is based on consent)
- Request data portability
- Lodge a complaint with the Information Commissioner’s Office (ICO)
To exercise your rights or discuss anything in this policy, please contact us.
10. Third-Party Links
Our Website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites. Please review their privacy policies separately.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Last updated” date.

