Privacy Policy

This Privacy Policy explains how LIGHT 'EM UP LTD (“LEU”, “we”, “us”, “our”) collects, uses, stores, and protects your personal data when you use:

  • lightemuphumidor.com (online store)

  • lightemupworld.com (general website)

  • lightemupgo.com and app.lightemupgo.com (web app with user-generated content)

We are committed to safeguarding your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.


1. Contact Details & Legal Entity

Data Controller:
LIGHT 'EM UP LTD
84 Spyrou Kyprianou, 4004 Limassol, Cyprus
Reg. No.: HE 424976
Email: christian@lightemupworld.com


2. Scope of This Policy

This policy applies to:

  • Visitors of our websites

  • Customers of our online store

  • Registered users of our web app

  • Newsletter subscribers

  • Users interacting with LEU via third-party platforms (e.g. Google, Facebook)

By using our services, you agree to the collection and processing of your data as described.


3. Legal Basis (GDPR Art. 6)

We process personal data only when legally permitted. Common legal bases include:

Purpose Legal Basis
Processing orders Contract (Art. 6(1)(b))
Sending newsletters Consent (Art. 6(1)(a))
Age verification Legal obligation (Art. 6(1)(c))
Improving our platform Legitimate interest (Art. 6(1)(f))
Handling customer support Contract / Legitimate interest
Fraud prevention, legal compliance Legal obligation / Legitimate interest

4. Age Verification & Youth Protection

We do not sell or ship tobacco to anyone under 21 years of age.

Before purchasing or accessing restricted content on lightemuphumidor.com, you must verify your age using VerifyMyAge, which reviews official ID (e.g. passport, driver’s license) through AI and manual checks.

For their privacy practices, see:
👉 VerifyMyAge Privacy Policy


5. What We Collect

a. Automatically Collected Data

  • IP address and location estimate

  • Browser, device type, OS

  • Referrer URLs and usage behavior

  • Time and duration of visit

b. Data You Provide

  • Full name, email address, phone number

  • Shipping and billing address

  • Login credentials or social account details (no passwords stored)

  • Uploaded content (e.g. photos, reviews, voice recordings)

  • Optional: Instagram handle, birth date, gender

We collect only what’s needed for functionality, legal compliance, or improvements.


6. Newsletter Subscription

When you subscribe via lightemuphumidor.com or other channels, we collect your:

  • Email address (mandatory)

  • Name (optional)

We use this only to send updates, product news, or promotions. Subscription might require double opt-in consent and can be withdrawn at any time via the unsubscribe link or by contacting us.

We use GDPR-compliant tools (e.g. Mailchimp) for newsletter delivery.


7. Cookies & Shopify Consent System

Our platforms use cookies and similar technologies to operate and optimize performance.

Cookies may be placed by:

  • Shopify (our e-commerce platform)

  • Analytics tools (e.g. Google Analytics)

  • Marketing services (e.g. Facebook Pixel, if integrated)

  • Functional services (e.g. login sessions, age-gate popups)

Cookies help us:

  • Remember your preferences

  • Improve navigation and checkout

  • Track how visitors use our services

We rely on Shopify’s built-in cookie banner and consent system to comply with GDPR and ePrivacy requirements. You can manage or block cookies via your browser settings.

Shopify’s cookie info:
👉 Shopify Cookie Policy


8. Data Sharing

We only share data when necessary and with trusted partners, including:

  • Payment processors (e.g. Shopify Payments, Stripe)

  • Age verification providers (e.g. VerifyMyAge)

  • Logistics/shipping providers

  • Newsletter/email platforms

  • Analytics and hosting providers

  • Legal authorities if required

All partners are bound by data processing agreements and security obligations. We do not sell personal data.


9. International Data Transfers

Some data may be transferred outside the EU/EEA (e.g. to Shopify’s servers or email providers). We ensure protection through:

  • Adequacy decisions

  • Standard Contractual Clauses (SCCs)

  • Other GDPR-approved safeguards

By using our services, you consent to such transfers.


10. Data Retention

Data Type Retention Period
Orders, invoices 6–10 years (legal requirement)
Newsletter data Until you unsubscribe
User-generated content Until account is deleted or deactivated
Customer support data 12 months (or longer if legally required)

You can request deletion or restriction at any time.


11. Your Rights (GDPR Art. 15–22)

You have the right to:

  • Access your data

  • Rectify incorrect data

  • Erase your data (where legally allowed)

  • Restrict or object to processing

  • Withdraw newsletter consent

  • Port your data to another provider

To exercise these rights, email: tech@lightemupworld.com
If you believe your data rights are violated, you may lodge a complaint with your local data protection authority.


12. Data Security

We take appropriate technical and organizational measures to protect your data, including:

  • SSL encryption

  • Access restriction

  • Secure third-party platforms

  • Regular backups

In case of a data breach, we’ll notify affected users and regulators where legally required.


13. Children’s Privacy

Our services are not directed to individuals under the age of 21. We do not knowingly collect data from minors. If we become aware of such data, it will be deleted immediately.


14. Changes to This Policy

We may update this Privacy Policy to reflect platform, legal, or operational changes. You will be notified of major changes. Continued use implies acceptance of the revised policy.

In the case of a merger or acquisition, your data may be transferred under equivalent protection terms.

Version 1.0
Last updated: June 25, 2025