What personal data does Dojo Vape collect?
At checkout we collect: name, billing address, shipping address, email, phone (optional), and government-issued ID for age verification (held by the third-party verifier, not by us long-term). Payment information goes directly to the payment gateway and is not stored in our system. Order history, support emails, and account login activity are stored in your customer profile.
Does Dojo Vape sell my personal data?
No. We do not sell, rent, or trade personally identifiable customer data to third parties. We share order data only with the carriers required to deliver the package, the payment gateway required to process the transaction, and the federal age-verification provider required by law.
How long does Dojo Vape keep my data?
Order records: 7 years (US tax and regulatory requirement). Customer account profiles: until you delete the account. Age-verification records: 30 days at the third-party verifier (we don't retain copies). Marketing email subscription: until you unsubscribe. Payment data: never stored on our servers — it's tokenized by the gateway at checkout.
What are my CCPA and GDPR rights at Dojo Vape?
California residents under CCPA: right to know what we've collected, right to delete, right to opt out of sale (we don't sell anyway), right to non-discrimination for exercising rights. EU residents under GDPR: same rights plus data portability and the right to rectification. Email privacy@dojo-vapes.com with your request — we respond within 30 days.
Does Dojo Vape use cookies?
Yes — strictly necessary cookies for cart and checkout (you can't disable these without breaking the site), analytics cookies for traffic measurement (Google Analytics 4, can be disabled in your browser or via opt-out), and conversion cookies for ad attribution (used only for our own paid channel reporting, not third-party retargeting).
Who does Dojo Vape share data with?
Three categories: (1) shipping carriers (USPS, UPS, FedEx) — name, address, and phone; (2) payment gateway (Authorize.net) — tokenized payment data; (3) federal age-verification provider (Veratad or equivalent) — government ID for the verification call only. We do not share with marketing aggregators, data brokers, or social platforms.