Shopping Cart
Item

Home / page

Privacy policy

Privacy Policy

⚠️ Age Warning: This website and our services are exclusively for adults who have reached the legal purchasing age for vape products in their jurisdiction (minimum 18 years old, 21 years old in some regions). We do not knowingly collect or process any personal data from minors. If we become aware that we have collected personal data from a minor, we will immediately and permanently delete that data.
 
sfogbar.com is the official online store operated by [ Guangdong BooPower Co., Limited] (“we”, “us”, “our”). We are a nationally certified, fully compliant e-cigarette manufacturer, and we are the Data Controller of your personal data under applicable global data protection laws, including the EU General Data Protection Regulation (GDPR), UK GDPR, and other relevant regional regulations.
 
This Privacy Policy explains what personal data we collect, how we use, store, share and protect it, as well as your legal rights regarding your personal data. This policy applies to all visitors, users and customers of sfogbar.com, including both retail and wholesale clients. By accessing our website or using our services, you confirm that you are an adult of legal purchasing age and agree to the terms of this Privacy Policy.

1. What Personal Data We Collect

We collect personal data that is necessary for us to provide our services, complete your orders, comply with legal obligations, and protect our legitimate business interests. We only collect data that is adequate, relevant and limited to the purposes stated in this policy.

1.1 Data You Provide to Us Directly

  • Order & Transaction Data: When you place an order, we collect your full name, billing address, shipping address, email address, phone number, payment details, order number, and order history. For wholesale clients, we additionally collect your business registration information, tax ID, business license, and cooperation-related documents.
  • Account & Contact Data: When you contact us via email, WhatsApp, or other channels, we collect your name, contact details, and the content of your communication.
  • Age Verification Data: To comply with global vape industry regulations, we may collect data to verify your legal purchasing age, including date of birth or ID verification documents (where required by law).
  • Marketing Consent Data: If you opt in to receive our marketing communications, we collect your email address and marketing preference information.

1.2 Data We Collect Automatically

When you browse our website (hosted on Shoptop Inc.), we automatically collect the following data to optimize our website performance and user experience:
  • Technical Data: Your internet protocol (IP) address, browser type and version, operating system, device type, language preference, and unique device identifiers.
  • Usage Data: Pages you visit, time spent on our website, click-through data, referral source, and other website interaction data.
  • Cookie & Similar Tracking Data: We use cookies and similar tracking technologies in compliance with the EU ePrivacy Directive. For full details, please refer to Section 7 of this policy.

2. How We Use Your Personal Data

We only use your personal data for the purposes we have disclosed to you, in compliance with applicable data protection laws. The legal bases for our data processing are: performance of a contract with you, compliance with our legal obligations, our legitimate business interests, and your explicit consent (where applicable).
 
We use your personal data for the following purposes:
  1. To process and fulfill your orders, arrange shipping and delivery, handle returns, refunds and after-sales services, and complete payment transactions.
  2. To verify your identity and legal purchasing age, comply with global vape industry regulations, and prevent minors from accessing our products and services.
  3. To respond to your inquiries, provide customer support, and resolve any issues related to our products and services.
  4. For wholesale clients: To review your distributor qualification, negotiate business cooperation, provide custom solutions, and maintain long-term business relationships.
  5. To optimize our website performance, improve our products and services, and personalize your shopping experience.
  6. To detect and prevent fraud, unauthorized transactions, security breaches, and other illegal activities, to protect the safety of our website, users and business.
  7. To comply with legal, regulatory and tax obligations, including customs declaration, export control, and judicial or administrative requests.
  8. To send you marketing communications (only with your explicit consent, which you can withdraw at any time).
We will never sell, rent or lease your personal data to any third party for commercial purposes.

3. How We Share Your Personal Data

We only share your personal data with third parties in the circumstances set out below, and only to the extent necessary to achieve the purposes stated in this policy. We require all third parties to implement appropriate security measures to protect your personal data in compliance with applicable data protection laws.

3.1 Service Providers (Data Processors)

We share your data with third-party service providers who perform services on our behalf, including:
  • E-commerce Platform Provider: Shoptop Inc., which provides our website hosting, e-commerce platform and related technical services.
  • Payment Processors: Third-party payment gateways that process your payment transactions, including Visa, Mastercard, and other payment providers we partner with. All payment processors comply with the PCI-DSS Level 1 security standard.
  • **Logistics & Shipping Providers: Third-party logistics companies that fulfill your order delivery and handle cross-border shipping.
  • **Customer Support & Marketing Tools: Third-party service providers that assist us with customer service, email marketing and data analytics (only with your consent for marketing activities).

3.2 Legal Disclosures

We may disclose your personal data if required to do so by applicable law, regulation, judicial order, or government request, including:
  • To comply with customs declaration, export control, tax and other cross-border trade legal obligations;
  • To detect and prevent fraud, security breaches, or other illegal activities;
  • To protect our legal rights, property, or safety, as well as the rights, property and safety of our users and the public.

3.3 Business Transfers

If our company is involved in a merger, acquisition, asset sale, or business transfer, your personal data may be transferred to the new business owner as part of the transaction. We will notify you via website announcement or email before any such transfer, and ensure the new owner complies with this Privacy Policy.

4. Cross-Border Data Transfers

Our website is operated in China, and our service providers may be located in different jurisdictions around the world. This means your personal data may be transferred to and processed in jurisdictions outside of your country of residence, including China.
 
For data transfers from the European Economic Area (EEA) or the UK to countries that have not been granted an adequacy decision by the European Commission or UK government, we use EU Standard Contractual Clauses (SCCs) or other legally recognized mechanisms to ensure adequate protection for your personal data, in compliance with GDPR and UK GDPR. You can request a copy of our SCCs by contacting our Privacy Compliance Officer using the details in Section 10.

5. Data Retention

We only retain your personal data for as long as is necessary to fulfill the purposes for which it was collected, and to comply with our legal, regulatory and accounting obligations.
  • Order & Transaction Data: We retain this data for 7 years after the completion of your order, to comply with tax, accounting and customs legal obligations, and to handle any potential after-sales or legal disputes.
  • Marketing Data: We retain this data until you withdraw your consent to receive marketing communications.
  • Age Verification Data: We retain this data for the duration required by applicable vape industry regulations in your jurisdiction.
  • Website Usage Data: We retain this data for a maximum of 12 months, after which it is anonymized or deleted.
At the end of the retention period, we will either permanently delete or anonymize your personal data, in compliance with applicable data protection laws.

6. Data Security

We are committed to protecting the security of your personal data. We implement industry-standard technical and organizational security measures to protect your data from unauthorized access, disclosure, alteration, destruction or loss, including:
  • Bank-level encryption of payment data via Secure Socket Layer (SSL) technology, with AES-256 encryption for stored sensitive data.
  • Full compliance with the Payment Card Industry Data Security Standard (PCI-DSS) for all payment transactions.
  • Firewall protection, access control systems, and regular security audits of our website and data storage systems.
  • Confidentiality agreements and data protection training for all our employees who have access to your personal data.
  • Regular backup and disaster recovery plans to ensure business continuity and data recovery.
While we implement all reasonable security measures, please note that no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data, and we will notify you and the relevant regulatory authority without undue delay in the event of a data breach that poses a risk to your rights and freedoms, in compliance with applicable laws.

7. Cookies & Similar Tracking Technologies

We use cookies and similar tracking technologies (collectively "Cookies") on our website, in compliance with the EU ePrivacy Directive and applicable data protection laws.

7.1 What Are Cookies

Cookies are small text files that are stored on your device when you visit our website. They help us recognize your device, remember your preferences, provide a smooth user experience, and optimize our website performance.

7.2 Types of Cookies We Use

Cookie Type Purpose Retention Period
Necessary Cookies Essential for the basic operation of our website, including cart functionality, user session management, login authentication, and security features. These cookies cannot be disabled. Session / Up to 24 months
Performance & Analytics Cookies Help us collect data on how users interact with our website, including page views, traffic sources, and user behavior, to optimize website performance and user experience. Up to 12 months
Preference Cookies Remember your language preference, region setting, and other user preferences to personalize your experience on our website. Up to 12 months
Marketing Cookies Track your browsing behavior to deliver relevant marketing communications and advertisements, only with your explicit consent. Up to 24 months

7.3 Your Cookie Preferences

When you first visit our website, you will be presented with a cookie banner that allows you to accept or reject non-necessary cookies. You can also change your cookie preferences at any time through your browser settings. Please note that disabling necessary cookies may affect the basic functionality of our website.

8. Your Legal Rights

Under applicable data protection laws (including GDPR and UK GDPR), you have the following rights regarding your personal data:
  1. Right of Access: You have the right to request access to the personal data we hold about you, and to receive information about how we process it.
  2. Right of Rectification: You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
  3. Right to Erasure (Right to be Forgotten): You have the right to request that we delete your personal data, in circumstances where it is no longer necessary for the purposes for which it was collected, or where you withdraw your consent.
  4. Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, in circumstances where the accuracy of the data is contested, or the processing is unlawful.
  5. Right to Data Portability: You have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and to transmit that data to another data controller, where the processing is based on your consent or the performance of a contract.
  6. Right to Object: You have the right to object to the processing of your personal data that is based on our legitimate business interests, at any time. You also have the right to object to processing for direct marketing purposes at any time.
  7. Right to Withdraw Consent: Where we process your personal data based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
  8. Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority, if you are not satisfied with how we handle your personal data or your rights request.
To exercise any of your rights, please contact our Privacy Compliance Officer using the contact details in Section 10. We will respond to all valid requests within 30 calendar days, in compliance with applicable data protection laws. We may request additional information to verify your identity before processing your request, to protect the security of your personal data.

9. Third-Party Links

Our website may contain links to third-party websites, applications or services that are not operated or controlled by us. This Privacy Policy only applies to our website sfogbar.com. We are not responsible for the privacy practices, content or policies of any third-party websites. We strongly recommend that you read the privacy policy of any third-party website you visit.

10. Changes to This Privacy Policy

We reserve the right to update, amend or modify this Privacy Policy at any time, to comply with changes in applicable laws, regulations or our business operations.
  • Minor updates or clarifications will take effect immediately upon posting on this page.
  • Material changes to this policy will be notified to you via prominent website announcement or email (for existing customers) at least 30 days before the changes take effect.
We recommend that you review this Privacy Policy regularly to stay informed about how we protect your personal data.

11. Contact Us

If you have any questions, concerns or requests regarding this Privacy Policy, your personal data, or to exercise your legal rights, please contact our Privacy Compliance Officer via the following dedicated channels: 782988668@qq.com
 
 
Effective Date: March 1, 2026