PRIVACY POLICY

1.0 Scope, Jurisdiction & Business Details

This operational policy governs data collection, transactional security, and digital/physical infrastructure management for customers located in the United States, in adherence with federal guidelines (FTC Act, PACT Act) and state privacy regulations (including CCPA/CPRA, VCDPA, and CPA).

1.1 Business Identifiers

  • Website Domain: [https://monseyvape.com](https://monseyvape.com) (referred to as “our site”, “website”, or “services”)

  • Operating Entity: MONSEY VAPE (“Company”, “we”, “us”, or “our”)

  • Primary Privacy Contact: Info@monseyvape.com

2.0 Data Collection & Sourcing

We do not intentionally collect, solicit, or market to individuals under the age of 18 (or 21 where required by age-restricted product regulations). If you do not meet the legal age requirements, you are not permitted to use our website or access our products or services.

We collect and process the following categories of data:

2.1 Information You Provide to Us

Information submitted directly via forms on [https://monseyvape.com](https://monseyvape.com), or through email, phone, or direct communications. This includes:

  • Account & Order Data: Name, billing address, shipping address, email address, date of birth, age verification details, phone number, order preferences, and transaction history.

  • Communications & Feedback: Inquiries, customer support tickets, product reviews, survey responses, and marketing opinions.

  • Recruitment Data: If applying for a role at MONSEY VAPE, candidate data provided during the interview process (resumes, work history, equal opportunity information) is used for candidate evaluation. Unsuccessful candidate records may be retained in our talent pool for up to two years pursuant to EEOC guidelines and state privacy notices (including CPRA candidate provisions).

2.2 Information Collected Automatically

  • Technical & Usage Audit Logs: Web server logs, IP addresses, browser types, operating systems, time zone settings, referral URLs, pages viewed, and session interaction metrics. These logs are retained for a maximum of 90 days for security auditing, fraud mitigation, and bot detection.

  • Cookies & Tracking Technologies: Pixels, tags, web beacons, and local storage mechanisms used to maintain site functionality, analyze performance, and deliver targeted advertising.

2.3 Information from Third Parties

Data received from identity and age-verification services, fraud prevention agencies, payment gateways, and third-party advertising or analytics partners.

3.0 Legal Framework, Data Use & Statutory Bases

We process personal information under applicable US federal and state standards, including the FTC Act Section 5, CCPA/CPRA, and relevant state privacy statutes:

3.1 Contract Performance & Order Fulfilment

  • Transactional Services: Processing purchases, managing billing, organizing logistics, and issuing transaction updates.

  • Age Verification (Controlled Products): Where sales involve regulated or age-restricted inventory (such as nicotine or vape products), transactions are conditionally verified prior to order fulfillment using automated identity database cross-referencing (via AgeChecker.net or Veratad) in compliance with the Federal PACT Act and applicable state mandates. (Note: Third-party age verification is deactivated for standard, non-restricted general retail lines).

3.2 Financial Data & Payment Security

  • Primary Processing Infrastructure: All financial transactions are processed using US Level 1 PCI-DSS compliant payment gateways. Supported processing partners include Stripe, Shopify Payments, PayPal, Apple Pay, Google Pay, and Buy-Now-Pay-Later (BNPL) platforms (Klarna and Affirm).

  • Payment Data Security: Payment details are encrypted in transit via TLS 1.3 and tokenized directly by our gateway providers. MONSEY VAPE neither stores, logs, nor accesses raw Primary Account Numbers (PAN) or Card Verification Values (CVV).

3.3 Legitimate Business Interests & Commercial Operations

  • Operating, troubleshooting, and optimizing website infrastructure and user experience.

  • Auditing communications (calls, emails) for quality assurance and training.

  • Preventing, investigating, and reporting security incidents, fraud, or criminal activity.

  • Conducting internal analytics, market research, and targeted promotional campaigns.

3.4 Regulatory Compliance & Sectoral Frameworks

  • Sectoral Disclosures:

    • Healthcare (HIPAA/HITECH): MONSEY VAPE does not operate as a HIPAA covered entity or business associate and does not collect Protected Health Information (PHI).

    • Financial Services (GLBA/FCRA): We are not a financial institution subject to GLBA/FCRA nonpublic personal information provisions.

  • Legal Obligations: Responding to lawful subpoenas, warrants, regulatory inquiries (FTC, State AGs), or maintaining statutory record-keeping.

4.0 Physical Infrastructure, Facilities & Surveillance

  • Pure Play E-Commerce: For standard online fulfillment, physical brick-and-mortar retail customer logs and retail premises CCTV policies are excluded.

  • Fulfillment & Commercial Warehousing: Where physical warehouse or commercial fulfillment facilities are operated, CCTV security footage is recorded strictly for asset protection, physical access monitoring, and workplace safety. CCTV logs are encrypted, access-restricted to authorized security personnel, and automatically purged after a 30-day retention cycle, barring active legal or security investigations.

5.0 Third-Party Tracking, Analytics & Advertising

5.1 Cookies & Analytics

We partner with third-party networks and service platforms to analyze traffic, assess performance, and deliver personalized content.

For detailed information regarding specific cookies, lifespans, and management options, review our dedicated Cookie Policy.

5.2 US State Rights: “Do Not Sell or Share My Personal Information”

Under the CCPA/CPRA and related state privacy statutes:

  • “Sale” refers to disclosing or transferring personal data to a third party for monetary or other valuable consideration.

  • “Sharing” refers to transferring personal data to a third party for cross-context behavioral advertising (targeted advertising).

We do not exchange personal information for cash. However, allowing third-party ad networks and analytics platforms to collect device identifiers and browsing data via cookies on [https://monseyvape.com](https://monseyvape.com) may be classified as “selling” or “sharing” under California and state privacy laws.

Exercising Opt-Out Rights

You may opt out of the sale or sharing of your personal data for targeted advertising through any of the following channels:

  1. Interactive Preference Center: Click the “Do Not Sell or Share My Personal Information” or “Your Privacy Choices” link located in our website footer to toggle off marketing cookies.

  2. Global Privacy Control (GPC): We recognize universal browser opt-out signals. If your browser broadcasts an active GPC signal, our system automatically treats it as a valid opt-out request for that specific browser and device.

  3. Email Request: Submit a direct request to Info@monseyvape.com with the subject line “US Privacy Opt-Out Request”.

We will not discriminate against any consumer for exercising their legal privacy rights.

6.0 Data Retention & Security Standards

6.1 Retention Schedules

  • General Tax & Financial Records: Retained for 7 to 10 years in accordance with IRS regulations (26 CFR § 1.6001-1), statutory contract limitations, and standard corporate accounting compliance.

  • Technical Audit Logs: Retained for up to 90 days for fraud detection and security diagnostics.

  • Recruitment & Candidate Data: Retained for up to 2 years pursuant to EEOC (29 CFR § 1602.14) / OFCCP guidelines and state privacy candidate disclosure frameworks.

  • CCTV Surveillance Logs: Purged every 30 days, unless required for an ongoing investigation.

6.2 Safeguards & International Transfers

  • Security Controls: We implement physical access restrictions, secure IT infrastructure, multi-factor authentication, network firewalls, and TLS 1.3 encryption for data in transit.

  • Cross-Border Transfers: Where data originates outside the US (e.g., EU/UK/Swiss users), inbound transfers are managed under the EU-U.S. Data Privacy Framework (DPF), Standard Contractual Clauses (SCCs), or the UK Addendum.

  • Vendor Safeguards: Vendor agreements enforce explicit statutory restrictions (e.g., CCPA Service Provider terms) prohibiting vendors from selling, sharing, or retaining data outside the specified contractual scope.

7.0 Consumer Rights & Data Subject Requests

Subject to your state of residence, you may exercise the following rights regarding your personal data:

  • Right to Know / Access: Request details regarding the categories and specific pieces of personal data collected, used, or disclosed.

  • Right to Deletion: Request deletion of personal data collected from you, subject to legal retention exceptions (e.g., IRS tax records, active contract fulfillment).

  • Right to Correction: Request correction of inaccurate or incomplete personal records.

  • Right to Opt-Out: Direct us to stop selling or sharing your data for cross-context behavioral advertising.

7.1 State-Specific Disclosures (CCPA / CPRA & US State Privacy Acts)

  • Categories of Personal Information Collected: Identifiers (name, email, IP address), commercial information (purchase history), internet activity (cookies, browsing habits), and approximate geolocation data.

  • Sensitive Personal Information: We do not collect or process sensitive personal information (such as Social Security numbers, precise geolocation, or genetic data) to infer characteristics about consumers.

  • Authorized Agents: You may designate an authorized agent to submit a request on your behalf by providing written proof of authorization and verifying your identity directly with us.

To submit a request, contact us at Info@monseyvape.com. Requests are verified against account credentials or identity documentation and processed within standard statutory timelines (typically 45 days).

8.0 Updates to This Policy

We reserve the right to modify this Privacy Policy periodically to reflect operational, legal, or regulatory updates. Any changes will be posted directly to this page with an updated “Effective Date.”

  • Last Updated: August 7, 2026