When you use the App and Website or interact with us offline we collect and use information about you in the course of providing you with our products and services and with customer support. We may collect some or all of the information listed below to help us with this:
We also automatically collect information about how visitors use our Website by using cookies and similar technologies if, where they are not essential to make the Website work, you have consented to their use. To learn more about how we use cookies and how to switch them off please see our Cookies Notice. Some of the personal information we collect from you is required to enable us to fulfil our contractual duties to you or to others. For example, when buying products from us, we need to collect your financial bank details in order to be able to process your payment and we need to verify your age to comply with laws that apply to us. Other items may simply be needed to ensure that our relationship can run smoothly.
Depending on the type of personal information in question and the legal grounds (i.e. the ‘lawful bases’) on which we may be processing it, should you decline to provide us with such data, we may not be able to fulfil our contractual requirements or, in extreme cases, may not be able to continue with our relationship with you.
We may receive personal information about you from third party data providers including your contact details and your status as a smoker or vaper. Where possible, we will contact you with details of the personal information we have received from such providers, together with that provider’s details.
For details of the lawful bases that we rely on to be able to use and process your personal information, please see How we use your information.
The purposes for which we use your personal information and the lawful basis under data protection laws on which we rely to do this are explained below.
Where you have provided CONSENT
We will rely on your consent, in certain cases, to send you the following where we invite you to opt-in on the App and Website:
We may also rely on consent to use your name and image for publicity purposes. For example, we may rely on consent to feature winners in advertising for future competitions or prize draws.
You may withdraw your consent at any time. Please see the Marketing section below for further details.
Where it is required to complete or, at your request, take steps to enter into, a CONTRACT
The use of your personal information may be necessary to perform a contract that you have with us or perform steps you request to enter into a contract. For example, when you buy products from us, we need to use your personal information to process your order, to send you the product, for billing purposes and to respond to any requests you may have. We also need to use your personal information to enable you to use some parts of the App and Website, and to notify you about changes to our services.
Where there is a LEGAL REQUIREMENT
We will use your personal information to comply with our legal obligations, including where the law requires us:
Where it is in your VITAL INTERESTS
We will use your personal information to notify you of any product safety or product recall issues.
Where there is a LEGITIMATE INTEREST
We may use and process your personal information where it is necessary for us to pursue the following legitimate interests (whether ours, in connection with our business, or that of a third party), for the following purposes:
Processing necessary for us to promote our business, brands and products and measure the reach and effectiveness of our campaigns
Processing necessary for us to support App and Website visitors and customers with their enquiries
Processing necessary for us to respond to changing market conditions and the needs of our guests and visitors
Processing necessary for us to operate the administrative and technical aspects of our business efficiently and effectively
As this App and Website relates to vaping and vaping products, we are legally obliged to make sure that users paying by debit card only are verified on the App and Website and are aged 18 years or over. Failing age verification will mean you cannot complete a purchase. In some cases, we may need to ask for further information in order to verify your age. If this is necessary, we will contact you to explain why.
We may collect your preferences to receive marketing information directly from us by email or SMS in the following ways:
From time to time, we may ask you to refresh your marketing preferences by asking you to confirm that you consent to continue receiving marketing information from us.
You have the right to opt-out of our use of your personal information to provide marketing to you in any of the ways mentioned above at any time. Please see Your rights below for further details on how you can do this.
We may monitor your use of the App and Website and record your IP address, operating system and browser type for system administration purposes.
We collect aggregated statistics data about visitors to the App and Website and sales and traffic patterns. This information does not identify users in any personal capacity and we do not use this information to build profiles on individual users: it just contains generalised information about the users of the App and Website.
A cookie (and other technologies like pixels and beacons) is a small data file that is placed on your browser or the hardware of your computer or other device to allow a website to recognise you as a user when you return to the website.
We use non-strictly necessary cookies when you consent for us to do so and strictly necessary cookies on the Website. Please see our Cookies Notice for more information about the type of cookies and tracking technologies that we use on the Website and why, and how to accept and reject them.
We may make automated decisions about you based on your personal information to verify your age when you attempt to buy vaping products from us (see the explanation above for further information about this). We are legally required to verify your age in respect of the vaping products we make available for sale.
We do not make any other automated decisions about you which have a legal or other significant effect on you.
We will share your information primarily to ensure that we provide you with the most exciting and up to date products. We may share your information with any of the following groups:
SagePay Privacy Policy PayPal Privacy Policy;
We may share the non-personal aggregated statistics data about visitors to the App and Website with third parties for analytics and statistical purposes.
Your personal information may be transferred outside of the UK and the European Economic Area (EEA) to the third parties described in Sharing your information with third parties.
We want to make sure that your personal information is stored and transferred in a way which is secure. We will therefore only transfer data outside of the UK and EEA where it is compliant with data protection legislation and the means of transfer provides adequate safeguards in relation to your data, for example:
Where we transfer your personal information outside the UK and EEA and where the country or territory in question does not maintain adequate data protection standards, we will take all reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Notice. You can ask to see these by contacting us using the contact details below.
We care about protecting your information. That's why we put in place appropriate measures that are designed to prevent unauthorised access to, and misuse of, your personal information.
We are committed to taking all reasonable and appropriate steps to protect the personal information that we hold from misuse, loss, or unauthorised access. We do this by having in place a range of appropriate technical and organisational measures, including encryption measures and disaster recovery plans.
If you suspect any misuse or loss of or unauthorised access to your personal information please let us know immediately by contacting our Head of Legal using the details provided at the end of this notice.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will apply our normal procedures and comply with legal requirements to protect your information, we cannot guarantee the security of your information transmitted to the App and Website and any transmission is at your own risk.
The App and Website may from time to time contain links to and from other apps or websites. If you follow a link to any of those apps or websites, please note that those sites ought to have their own privacy policies and that we do not accept any responsibility or liability for those sites or for their privacy policies. Please check those privacy policies before you submit your information to those apps or websites.
We will keep your information relating to orders you have placed with us as required by law or other regulation (for example, because of a request by a tax authority or in connection with any anticipated litigation).
If you have registered an account with us: we will store your personal information for as long as your account is open. If you no longer wish to hold an account with us, you can email us at supportmybatrewards@bat.com and request that your account is deleted. By doing so, we will delete your account and remove you from our mailing list if you are on there. However, as noted above, we may still retain details of orders you have placed with us for legal or regulatory reasons.
If you have signed up to receive email or SMS marketing from us: we will store your personal information for as long as you are subscribed to our email or SMS marketing list (unless your account has been closed). If you unsubscribe or are otherwise removed from our marketing list, we will keep your email address or telephone number on our suppression list to ensure that we do not send you marketing emails or SMS.
If you have contacted us with a complaint or query: we will store your personal information for as long as is reasonably required to resolve your complaint or query.
The exceptions to the above are where:
When it is no longer necessary to retain your data, we will delete the personal information that we hold about you from our systems (either by erasing or anonymising that data). After that time, we may retain aggregated data (from which you cannot be identified) and retain it for analytical and statistical purposes.
You have a number of rights in relation to your information under data protection law. In relation to certain rights, we may ask you for information to confirm your identity and, where applicable, to help us to search for your personal information. Except in rare cases, we will respond to you within one month from either: (i) the date that we have confirmed your identity; or (ii) where we do not need to do this because we already have this information, from the date we received your request.
Right to object
This right enables you to object to us processing your personal information where we do so for one of the following reasons:
Except for the purposes for which we are sure we can continue to process your personal information, we will temporarily stop processing your personal information in line with your objection until we have investigated the matter. If we agree that your objection is justified in accordance with your rights under data protection laws, we will permanently stop using your personal information for those purposes. Otherwise we will provide you with our justification as to why we need to continue using your personal information.
Right to withdraw consent
Where we have obtained your consent to process your personal information for certain activities (for example, for marketing), you may withdraw this consent at any time and we will cease to use your personal information for that purpose unless we consider that there is an alternative legal basis to justify our continued processing of your data for this purpose, in which case we will inform you of this condition. If you withdraw your consent, our use of your personal information before you withdraw is still lawful.
Right of access (‘Data Subject Access Requests’)
You may ask us for a copy of the information we hold about you at any time, and request us to modify, update or delete such information. If we provide you with access to the information we hold about you, we will not charge you for this unless permitted by law. If you request further copies of this information from us, we may charge you a reasonable administrative cost. Where we are legally permitted to do so, we may refuse your request. If we refuse your request we will always tell you the reasons for doing so.
If you would like to request access to your information, it would assist us with dealing with your request if you could use the subject heading ‘Data Subject Access Request’, or quote this over the phone, when contacting us. Please note that this is not mandatory and we will still deal with any requests without this reference.
Right to erasure
You have the right to request that we erase your personal information in certain circumstances. Normally, this right exists where:
We would only be entitled to refuse to comply with your request for erasure in limited circumstances and we will always tell you our reason for doing so.
When complying with a valid request for the erasure of data we will take all reasonably practicable steps to delete the relevant data.
Right to restrict processing
You have the right to request that we restrict our processing of your personal information in certain circumstances, for example if you dispute the accuracy of the personal information that we hold about you, you object to our processing of your personal information for our legitimate interests or you require us to keep it in connection with legal proceedings. If we have shared your personal information with third parties, we will notify them about the restricted processing unless this is impossible or involves disproportionate effort. We will, of course, notify you before lifting any restriction on processing your personal information.
We may only process your information whilst its processing is restricted if we have your consent or are legally permitted to do so, for example for storage purposes, to protect the rights of another individual or company or in connection with legal proceedings.
Right to rectification
You have the right to request that we rectify any inaccurate or incomplete personal information that we hold about you. If we have shared this personal information with third parties, we will notify them about the rectification unless this is impossible or involves disproportionate effort. You may also request details of the third parties to whom we have disclosed the inaccurate or incomplete personal information. Where we think that it is reasonable for us not to comply with your request, we will explain our reasons for this decision.
You can access and update certain parts of your information by logging into your account on the App and Website.
Right of data portability
If you wish, you have the right to transfer your personal information between service providers where we rely on your consent or the performance of your contract as the lawful basis to use that information. In effect, this means that you are able to transfer the details we hold on you to another third party. To allow you to do so, we will provide you with your data in a commonly used machine-readable format so that you can transfer the data. Alternatively, we may directly transfer the data for you if technically possible.
Rights relating to automated decisions
In certain circumstances, you may contest a decision made about you based purely on automated processing and where the processing is not required by law. You may also ask us to stop making such decisions using automated processing alone.
Right to complain
You have the right to lodge a complaint with your local supervisory authority which is the Information Commissioner's Office in the UK. You can contact them in the following ways:
How to exercise your rights
If you would like to exercise any of these rights, please contact us on the details provided under How to contact us. Please note that we may keep a record of your communications to help us resolve any issues that you raise.
We may make changes to this Privacy Notice at any time by posting a copy of the modified notice on the App and Website or, where appropriate, by sending you an email with that notice. Any changes will take effect 7 days after the date of our email or the date on which we post the modified terms on the App and Website, whichever is the earlier.
If you have any queries about this Privacy Notice, including your rights in relation to your personal information, please contact Head of Legal by post at:
British American Tobacco UK Limited
Building 7, 566 Chiswick High Road,
London,
W4 5YG.
If you wish to contact us with any general queries or concerns, you can contact your local BAT sales Representative or email us at supportmybatrewards@bat.com.
When contacting us by email or post, please use the subject heading ‘Data protection query’ so that we can direct your query to the appropriate department and deal with it promptly.
UPDATED 6 APRIL 2021
Your browser version is not compatible with BAT loyalty platform. Please raise your device to recommended technical specifications: Google Chrome & Safari (Android 4.4 or latest, iOS 9 or latest)