Privacy Policy
Vape Shopify Migration (“VSM”, “we”, “us” or “our”).
We collect only the information we need to answer your enquiries and migrate your store, and we never sell your personal data. When we handle your store’s customer data during a migration, we act only on your instructions, and your store logins and working copies are deleted once the migration is signed off. You have rights to access, correct, delete and opt out, and we honour them under the EU/UK GDPR and US state privacy laws. To exercise a right, email contact@vapeshopifymigration.com.
Who we are
VapeShopifyMigration is a done-for-you migration service. We help vape, e-cigarette/ENDS, kratom and CBD retailers, and other high-risk merchants, move their online stores off Shopify and onto platforms they fully control — primarily WordPress and WooCommerce, and also Magento (Adobe Commerce) and BigCommerce.
This Privacy Policy explains how we collect, use, share, protect and retain personal information across our website and throughout our migration service, and the choices and rights you have.
Scope of this policy and our two data roles
Because of what we do, your data reaches us in two different ways, and our responsibilities differ in each:
For the information you give us as a visitor or lead — name, email, phone, store URL and enquiry — we decide why and how it is used. This policy governs it.
For your store’s data (your products and your customers’ personal information), you remain the controller and we act only on your instructions. A DPA is available on request.
This policy describes both roles. Where a section applies only to one role, we say so.
Information we collect
- Lead and contact data. Your name, business name, email, phone, store URL/platform and enquiry details — provided via our forms, WhatsApp, email or calls.
- Project and account data. Information needed to plan and deliver your migration: current platform, catalogue size, apps in use, hosting details and requirements.
- Store credentials and access. Admin logins, API keys and hosting access you provide so we can perform the work. Used only for your migration and deleted/revoked after sign-off.
- Migrated store data (processed on your behalf). Products, images, categories, orders, customer accounts and your customers’ personal information, reviews, blog posts and pages.
- Payment information. Handled by our payment provider; we receive limited transaction details but do not store your full card details.
- Website and usage data. IP address, device/browser type, pages viewed and similar analytics, collected via cookies (see Section 7).
We do not intentionally collect “sensitive” personal information about our website visitors. Any age-verification data in a store we migrate is handled only as part of that migration, on your instructions (see Section 15).
How we use your information
We use personal information to:
- respond to enquiries, provide quotes and scope your migration;
- plan, perform, test and support your migration;
- set up and manage your account and our working relationship;
- take payment and keep records for accounting and tax;
- provide customer support and post-launch assistance;
- secure our systems, prevent fraud and troubleshoot problems;
- improve our website, services and content;
- send service-related communications; and
- comply with legal obligations and enforce our terms.
With your consent or where permitted, we may send marketing about our services; you can opt out at any time. We do not sell your personal information, and we do not use your customers’ data for our own marketing.
Where the GDPR applies, our legal bases are: performance of a contract; your consent; our legitimate interests (balanced against your rights); and compliance with legal obligations.
Store and customer data we process during a migration
When we migrate your store, we act as your data processor. This means:
- we process your store data only on your documented instructions and to deliver the migration you request;
- we use least-privilege access — only the access needed to do the work;
- we build and test your new store in an isolated/parallel environment;
- we do not use your customers’ data for any purpose of our own, and never sell or share it;
- once your migration is signed off, we revoke your access and delete our working copies; and
- a Data Processing Agreement (DPA) is available on request.
As the controller of your store’s data, you remain responsible for having a lawful basis to migrate it and for your own privacy notices to your customers.
Payment information
We use a third-party payment provider to process payments for our services. Your card details are handled by that provider under their own security standards; we do not store your full payment card data.
Payment processing for your own store (for example, the high-risk gateway you connect for vape, ENDS, kratom or CBD sales) is provided by the processor you choose. PCI-DSS compliance for those transactions is the responsibility of that gateway and of you as the merchant; we help you connect a compliant gateway but do not store your customers’ cardholder data.
Cookies and tracking technologies
Our website uses cookies and similar technologies to make the site work, remember preferences, understand usage and support marketing. Broad categories:
- Essential — needed for the site to function and stay secure;
- Analytics — help us understand and improve how the site is used;
- Marketing — may be used to measure and improve advertising.
Where required, we ask for your consent before setting non-essential cookies, and you can change your choices anytime via our cookie settings or your browser.
Global Privacy Control. We recognise opt-out preference signals, including the Global Privacy Control (GPC), where required by US state law. If your browser sends a GPC signal, we treat it as a request to opt out of the “sale” or “sharing” of personal information for that browser.
How and with whom we share information
We do not sell your personal information or “share” it for cross-context behavioural advertising. We disclose information only as follows:
a. Service providers and sub-processors. Trusted third parties that help us operate, under confidentiality and data-protection obligations. Our current sub-processors include:
- [Hosting / cloud provider] — [purpose, e.g. servers for migration and our website]
- [Email / communications] — [purpose]
- [Analytics provider] — [purpose]
- [Payment provider] — [purpose]
- [Scheduling / CRM] — [purpose]
b. Legal and safety. Where required to comply with law, respond to lawful requests, enforce our terms, or protect rights and safety.
c. Business transfers. In a merger, acquisition or sale of assets, information may be transferred as part of that transaction, subject to this policy.
Data retention
We keep personal information only as long as needed, unless a longer period is required by law:
- Lead / enquiry data: while in contact and up to [e.g. 24 months] after our last interaction.
- Project / account data: for the project duration and [e.g. 24 months] afterward.
- Store credentials and access: revoked and deleted once your migration is signed off.
- Migrated store data (as processor): working copies purged after sign-off.
- Billing / transaction records: as required by tax and accounting law (typically [e.g. 6–7 years]).
- Website / analytics data: [e.g. up to 26 months].
When we no longer need information, we securely delete or anonymise it.
Data security
We use appropriate technical and organisational measures to protect personal information, including:
- encryption in transit (and, where applicable, at rest);
- access controls and least-privilege access;
- secure handling and prompt deletion of store credentials after a project;
- staff confidentiality obligations; and
- monitoring and regular review of our practices.
No method of transmission or storage is completely secure, but we work to protect your information. If we become aware of a personal data breach affecting you, we will notify you and the relevant authorities where required by law, and act to mitigate it.
International data transfers
We are based in the United States and may process information in the US and other countries where we or our sub-processors operate. Where we transfer personal information of individuals in the EEA or UK outside those regions, we rely on an appropriate mechanism, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) or another lawful safeguard. Contact us for more information about these safeguards.
Your privacy rights — United States
Depending on your state of residence, you may have some or all of these rights regarding personal information we hold as a controller:
- to know / access the personal information we collected and how we use and disclose it;
- to correct inaccurate personal information;
- to delete your personal information;
- to obtain a portable copy of your personal information;
- to opt out of the sale or sharing of personal information and of targeted advertising; and
- to not be discriminated against for exercising your rights.
We do not sell your personal information. You can still exercise an opt-out preference, including via the Global Privacy Control (Section 7).
Appeals. If we decline your request, you may appeal by contacting contact@vapeshopifymigration.com. These rights apply under laws such as the CCPA/CPRA and the comprehensive privacy laws now in effect in a growing number of US states.
Your privacy rights — EEA and UK (GDPR)
If you are in the EEA or the UK, you have the right to:
- access the personal data we hold about you;
- request rectification of inaccurate data;
- request erasure (“right to be forgotten”);
- request restriction of processing;
- object to processing based on legitimate interests, and to direct marketing at any time;
- request data portability;
- withdraw consent at any time where we rely on it; and
- lodge a complaint with your local supervisory authority.
Unlike the opt-out model common in the US, we rely on an opt-in basis for uses that require consent for EEA/UK visitors.
How to exercise your rights
To make a request, email contact@vapeshopifymigration.com with your name, the email/account associated with your data, and the right you wish to exercise.
- Verification: we will take reasonable steps to verify your identity before acting on a request.
- Authorised agents: you may use an authorised agent where the law allows; we may require proof of authorisation.
- Timing: we respond within the timeframe required by law — generally 30 to 45 days — and will tell you if we need more time.
- No fee: requests are usually free, though we may charge a reasonable fee or decline manifestly unfounded, excessive or repetitive requests, as permitted by law.
If your request concerns data we process as a processor for a merchant (your store’s customer data), we will refer you to, or work with, that merchant as the controller.
Children’s privacy and age-restricted data
Our website and services are intended for adults and businesses, not children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
Because we migrate age-restricted (vape, nicotine, kratom and CBD) stores, a store we migrate may contain age-verification or age-gate data about your customers. We process that data only as part of your migration, on your instructions, and delete our working copies after sign-off. As the merchant, you are responsible for the lawful collection and use of that data and for complying with age-restriction, age-appropriate-design and minors’-data rules that apply to your business.
Automated decision-making and AI
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing, and we do not use your personal information for such automated profiling. Where we use tooling (including any AI-assisted tools) to help operate our website or deliver our service, a human remains responsible for decisions that affect you. If this changes, we will update this policy and provide any disclosures required by law.
Third-party links
Our website may link to third-party sites or services we do not control. This policy does not apply to those third parties, and we are not responsible for their privacy practices. Please review their privacy policies before providing them with personal information.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology or legal requirements. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Previous versions are available on request. We review this policy at least annually.
How to contact us
If you have questions, requests or complaints about this Privacy Policy or your personal information, contact us:
We will do our best to resolve your concern. If you are in the EEA or UK, you also have the right to complain to your local data protection authority.
Glossary (plain-English terms)
- Personal information / personal data: information that identifies, relates to, or could reasonably be linked to you.
- Controller: the party that decides why and how personal data is processed.
- Processor: a party that processes personal data on behalf of, and under the instructions of, a controller.
- Sub-processor: a third party a processor uses to help deliver its service.
- DPA (Data Processing Agreement): a contract setting out how a processor must handle personal data.
- DSAR (Data Subject Access Request): a request to exercise your privacy rights.
- GPC (Global Privacy Control): a browser signal that communicates an opt-out preference automatically.