Privacy policy
This policy explains what personal data we collect when you use this website, why we are allowed to collect it, how long we keep it, and what you can ask us to do with it.
1. Who is responsible
VAPEXXL GmbH, Landsberger Allee 117, 10407 Berlin, Germany, is the controller responsible for the processing described here. You can reach our data protection contact at vapexxl0660@outlook.com.
2. What we collect and why
| Data | Why | Legal basis |
|---|---|---|
| Date of birth entered at the age gate | To prevent access by minors, as required for this product category | Legal obligation; substantial public interest |
| Name, delivery address, email, phone | To process and deliver your order | Performance of a contract |
| Company name, registration number, VAT number | To invoice correctly and apply the reverse charge where valid | Legal obligation; contract |
| Order history and correspondence | To handle support, returns, warranty and statutory retention | Contract; legal obligation |
| IP address, device and browser data | Security, fraud prevention, rate limiting and error diagnosis | Legitimate interests |
| Cookie and consent choices | To remember what you agreed to | Consent; legal obligation |
| Analytics data | To understand how the site is used and improve it | Consent only — never loaded before you agree |
3. Age verification
Because we sell nicotine products, entry to the site requires a date of birth rather than a simple confirmation. We store only the fact that a valid adult check was completed and when — not the date itself — in a cookie on your own device. At checkout the check is repeated and recorded against the order, because we must be able to demonstrate that we did not sell to a minor.
4. Who we share data with
We share personal data only where it is necessary to fulfil an order or where the law requires it. Typical recipients are:
- Hosting provider — servers located in the European Union.
- Carriers — name, address and phone for delivery, and for age verification on the doorstep where required.
- Payment providers — to process the payment route you choose. Card processing is handled by a licensed acquirer.
- Email service provider — transactional order and shipping messages.
- Bookkeeping and tax advisers — where legally required for accounting.
- Analytics provider — only if you have consented.
We do not sell personal data, and we do not share it for third-party advertising.
5. Where data is stored
Our website and database are hosted on servers inside the European Union, which keeps the compliance position simple. Where a processor transfers data outside the EEA, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses, and we hold a data processing agreement with that processor.
6. How long we keep it
- Order and invoice records: 10 years, as required by German commercial and tax law.
- Age verification records: retained with the order for the same period, as evidence of compliance.
- Account and contact data: for as long as the account is active, then deleted after 24 months of inactivity.
- Support correspondence: 24 months.
- Consent records: until withdrawn, plus 3 years as evidence.
- Server and security logs: 30 days, unless needed to investigate an incident.
7. Your rights
Under the GDPR you have the right to:
- be informed about the processing and to access a copy of your data;
- have inaccurate data corrected;
- have data erased where we no longer have a lawful reason to keep it;
- restrict processing while a dispute is resolved;
- receive your data in a portable format or have it transferred;
- object to processing based on legitimate interests;
- withdraw consent at any time, without affecting processing carried out before withdrawal;
- lodge a complaint with a supervisory authority.
To exercise any of these, email vapexxl0660@outlook.com. We acknowledge within 72 hours and answer within 30 days. We may ask you to confirm your identity before acting, because acting on the wrong request would itself be a data breach.
8. Cookies
We use strictly necessary cookies for the cart and the age check, and — only with your consent — analytics and marketing cookies. See the cookie policy for the full list and for how to change your choice.
9. Security
Traffic is encrypted with TLS. Access to the administration area requires strong credentials and two-factor authentication. We apply access controls, keep software updated, take daily backups and review security events. No system is perfect; if a personal data breach creates a risk to your rights we will notify affected individuals and the competent supervisory authority as required.
10. Changes
We update this policy when our processing changes. The date below shows the current version. Material changes are announced on the website.
Version 1.0 · Last updated 10 September 2026.