Privacy Policy

Updated: January 2024


Big Oak Smoke Shop and or its affiliates (Big Oak) provide website features and other products and services to you when you visit or shop on our site. By using this site, you agree, on behalf of yourself and any and all others who use any feature, product, or service under your account, to the following conditions. 

Privacy Policy

This Privacy Statement describes how we collect, use, store, and share your Personal Data, both offline and online, and your rights and choices in connection with your Personal Data. If you are an employee, contractor, or job applicant, your Personal Data collected in those contexts will be subject to a separate privacy notice that we provide to you where and when appropriate. 

Although we encourage you to read this entire Privacy Statement, this is a summary of some of the more important aspects of the Privacy Statement:

  • We may collect both Personal Data and other information about you through a variety of sources, including Personal Data we have collected directly from you and your sources (including information from your publicly available social media profiles), and other third parties. 
  • We will not use or share your Personal Data except as described in this Privacy Statement 
  • The failure to provide us with your accurate and up-to-date information may interfere with our ability to conduct business with you, such as processing your transactions.
  • Where applicable, we honor opt out instructions from you for certain uses of your Personal Data under this Privacy Statement, such as when you opt out of receiving marketing email communications from us or request us to delete your Personal Data. 
  • We use technical and organizational controls designed to secure and protect your Personal Data, but we cannot ensure or warrant that your Personal Data will be completely secure from misappropriation by hackers or from other nefarious or criminal activities. 


General Principles

Personal data will be collected, stored, processed, and transmitted in accordance with Big Oak ’s established policies and applicable federal, state, and local laws, rules, and regulations. 

The principles of Big Oak with regard to the processing of Personal Data are as follows:

  • Personal Data will be processed fairly and lawfully
  • Personal Data will be collected for specified, explicit, and legitimate purposes and not further processed for incompatible purposes, 
  • Personal Data collected by Big Oak will be adequate, relevant, and not excessive in relation to the purposes for which it is collected, 
  • Personal data collected by Big Oak will be accurate and, where necessary, kept up to date to the best of our ability
  • Personal data will be protected against unauthorized access and processing using appropriate technical and organizational security measures and controls
  • Personal data collected by Big Oak will be retained as identifiable information for no longer than necessary to serve the purposes for which it was collected.

If Big Oak engages in the processing of Personal Data for purposes other than those specified in this Privacy Statement, Big Oak will provide a notice of these changes, the purposes for which the Personal Data will be used, and the recipients of Personal Data. 


Collection of Information

Big Oak may collect Personal Data about you from a variety of sources, including, directly from you, from our service providers, from third-party information providers, from our Subsidiaries, and through operation of the Website.

Personal Data collected by or on behalf of Big Oak includes, depending on the nature of your interactions with us:

  • “Identity Data” such as first name, last name, username or similar identifier, title, company name, and government issued identification number.
  • “Contact Data” such as billing address, shipping address, email address, and telephone numbers. 
  • “Financial Data” such as bank account, payment card details, and credit history. 
  • “Transaction Data” such as details about payments to and from you and other details of products and services you have purchased from us. 
  • “Technical Data” such as internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our Website. 
  • “Profile Data” such as your username and password to access the Website, account number, purchase or orders made to you, your interests, preferences, feedback, and survey responses. 
  • “Usage Data” such as information about how you use our Website, products and services, as well as information about what you type into web chats and form fields on our Website, as well as your keystrokes and mouse movements on our Website. 
  • “Preference Data” such as your preferences in receiving marketing from us and our third parties, and your communication preferences. 
  • “Professional Data” such as your company affiliation, job title, office location, and professional contact information if you interact with us on behalf of a business customer or vendor. 
  • “Sensitive Personal Data” such as government issued identification number, username and password to access a Big Oak account, bank account information, and payment card details. This information may be subject to additional protections and privacy rights, as described below.
  • Other information that we collect with your consent as needed. 


Cookies & Website Usage

The Website, our digital content, and our emails may also monitor and collect information about how you access, use, and interact with them automatically through cookies and other automated tracking technologies. 


Generally, the cookies that are used on the Website can be broken down into:

  • Strictly necessary cookies, which are needed for proper functioning of the website
  • Analytical/ performance cookies, which are used to monitor performance of the website and improve your experience
  • Functional/tracking cookies, which enable us to recognize repeat visitors to our website
  • Targeting cookies, which record your visit, including pages you have visited and links you have followed, to be used for making displayed advertising more relevant to you


To learn how to change your cookie settings, please see the “Your Privacy Rights” section below. 


Use of Personal Data

Big Oak uses Personal Data we collect to operate our business. We may use data to communicate with you, for example, informing you about your account and product information. Depending on the nature of your interactions with us, Big Oak may use your Personal Data, including Sensitive Personal Data, for a variety of purposes including to:

  • Register you as a customer.
  • Provide, maintain, and improve the Website, including to operate certain features and functionality of the Website.
  • Understand user preferences to enhance users’ experience with Big Oak.
  • Research and analyze the effectiveness of the Website and the marketing, advertising, and sales efforts of Big Oak including through the use of automated systems that analyze data using machine learning and other analytic techniques.
  • Collect account receivables owed by customers of Big Oak.
  • Process orders, deliveries, and payments made through the Website.
  • Comply with a legal obligation or respond to lawful requests by public authorities (including national security or law enforcement requirements).
  • Manage our everyday business needs.
  • Enforce compliance with our Conditions of Use and applicable law.
  • Prosecute and/or defend a court, arbitration or similar legal proceedings.
  • For security and safety purposes, such as protecting the Website and our company against cyber threats, protecting our rights and the rights of our customers, and detecting, investigating, and preventing fraud or other illegal activities.
  • Communicate directly with you by sending you newsletters, surveys, promotions, and special offers or information about new products and services on an ongoing basis in accordance with your marketing preferences. You can unsubscribe at any time.
  • Communicate directly with you by phone to respond to customer service inquiries or comments through the Website, and to discuss issues relating to your account or the Website, and to provide customer service. 
  • Monitor and record your call, emails, text messages, social media messages, chat box, and other communications (as permitted by local law) in relation to your dealings with us.
  • Verify your identity before responding to privacy requests you make regarding your Personal Data.
  • Comply with our contractual or legal obligations to share data with credit reference agencies, fraud prevention agencies, and law enforcement agencies. 
  • Compile aggregated statistics about the operation and use of our Website and to better understand the preferences of the visitors of our Website.
  • Other purposes: to carry out other legitimate business purposes, as well as other lawful purposes about which we notify you. 


We will only use your Personal Data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us. If we need to use your Personal Data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. 

Please note that we may process your Personal Data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law. 


Credit Reference Checks, Fraud Prevention, and Denied Parties

The Personal Data that we have collected from you when setting up an account may be shared with credit reference, fraud prevention, and denied party agencies who use it to prevent fraud and money laundering and to verify your identity. We may access and use information from credit reference and denied party agencies when you open your account and periodically to:

  • Manage and take decisions about your account, including assessing creditworthiness.
  • Prevent criminal activity, fraud, and money laundering. 
  • Check your identity and verify the accuracy of the information you provide to us.
  • Trace debtors and recover debts. 


Application decisions may be taken based solely on automated checks of information from credit reference agencies and internal records. We will continue to share information with credit reference agencies about how you manage your account including any default in making payments, while you have a relationship with us. 

If false or inaccurate information is provided and/or fraud is identified or suspected, details will be passed to fraud prevention agencies, law enforcement agencies and other organizations that may access and use this information. If we, or fraud prevention agencies, determine that you pose a fraud or money laundering risk, we may refuse to provide services to you. A record of any fraud or money laundering will be retained by the fraud prevention agencies and may result in others refusing to provide services or financing to you. Fraud prevention agencies can hold your information for different periods of time. When credit reference, fraud prevention, and denied party agencies process your information, they do so on the basis that they have a legitimate interest in preventing fraud and money laundering, and to verify identity, in order to protect their business and to comply with laws that apply to them. 


Personal Data Sharing

We share your Personal Data with your consent or as necessary to complete any transaction. Depending on the nature of your interactions with us, we may disclose your Personal Data, including Sensitive Personal Data, as follows:

  • With Vendors: Big Oak may share your Personal Data with the third-party vendors that work alongside us. For example, we may share your Personal Data with a third-party vendor if you purchase or access an offering through us, or a Big Oak reseller/ distributor, and that vendor requires verification of an offering purchase in order to register that offering. We may also share your Personal Data with a third-party vendor if that vendor co-sponsors a marketing activity with us to verify your participation in the marketing activity. 
  • With Subsidiaries and Business Units: Big Oak may share your Personal Data with our Subsidiaries and other business units. Our Subsidiaries and business units will use your Personal Data we share with them in a manner consistent with this Privacy Statement. 
  • With Service Providers: Big Oak may provide your Personal Data to vendors that provide services to assist us with running our business and operating the Website. For example, these service providers may include providers of customer service, payment processing, email and messaging support, management, maintenance, information analysis, offering fulfillment or delivery, or other services we may receive on an outsourced basis.
  • With Law Enforcement and Safety: Big Oak may share your Personal Data with any competent law enforcement, regulatory, government agency, court, other governmental officials, or other third-party where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person.
  • With Others: We may share your Personal Data with any other person with your consent to the disclosure

We may also share aggregated, anonymized data with third parties for other purposes. Such information does not identify you individually, but may include usage, viewing and technical information we collected through your use of our Website. If we are required under applicable law to treat such information as Personal Data, then we will only disclose as described above. 


Your Privacy Rights

Where provided for by the applicable privacy laws in your state, United States residents may be entitled to exercise some or all of the following privacy rights:

  • Access / Right to Know: You may have the right to confirm whether we process Personal Data about you and to request that we disclose to you the following: (i) the categories of Personal Data that we have collected about you (including Sensitive Personal Data); (ii) the categories of sources from which we have collected Personal Data about you; (iii) the business or commercial purpose for collecting your Personal Data; (iv) the categories of Personal Data that we have disclosed about you for our business purposes and the categories of service providers to whom the Personal Data was disclosed; (v) a portable copy of the specific pieces of Personal Data that we have collected about you; and (vi) information about the logic involved in any automated decision-making processes used by us (if applicable), as well as a description of the likely outcome of the process with respect to you. 
  • Correct or update your Personal Data: You may have the right to request that we correct, update, or modify the Personal Data we maintain about you. 
  • Delete your Personal Data: You may have the right to request that we delete the copies of your Personal Data that we maintain, subject to certain exceptions and limitations. 
  • Opt-out of automated decision-making: You may have the right to request to opt-out of any profiling or automated decision-making, to the extent we engage in those processing activities and subject to any limitations under applicable privacy laws. 
  • Limit the use of my Sensitive Personal Data: In relation to the Sensitive Personal Data identified above, you may be able to request that we limit our use and sharing of such data to those purposes specified under applicable privacy laws. 


For the purposes of California privacy law, California residents should note the following:

  • We collect and use the following categories of personal information for the business and commercial purposes described in this Privacy Policy: identifiers and personal information categories listed in Cal. Civ. Code § 1798.80(e) (such as your name, contact information, government identification numbers, and IP address); commercial information (such as details of the offerings and services your purchase, your marketing preferences, and your survey response); internet or other electronic network activity information (such as interactions with our Website); geolocation data (but not precise geolocation); professional information (such as your company affiliation and job title); Sensitive Personal Information (namely, your payment card details, Big Oak account login details, and government identification numbers); and inferences. 
  • We use the above-described categories of personal information for our compliance, business, and commercial purposes. 
  • We collect these categories of personal information from the following categories of sources: directly from you, automatically from your Devices; from other users of the Website, from our service providers, from third-party information providers, from our Affiliates and Subsidiaries, and through operation of the Website.
  • We disclose each of the foregoing categories of personal information to our Affiliates and Subscribers, to our service providers who help us run our business, to advertisers who advertise our Platform, to data analytic providers, with legal entities for legal compliance purposes. 
  • We may share some of the following categories of personal information: identifiers, personal information categories listed in Cal. Civ. Code § 1798.80(e); commercial information; internet or other electronic network activity, and geolocation data. We do not knowingly share the personal information of minors.
  • We do not use or disclose sensitive personal information for purposes other than those specified under applicable California privacy regulations. 


California’s “Shine the Light” law also provides that California residents have a right to request that businesses tell them how their personal information has been shared with third parties for their direct marketing purposes. There is an exception to this requirement for businesses that have adopted and disclosed, in their privacy policy, a policy of not disclosing a person’s personal information to third parties for direct marketing purposes if that person has exercised an option to opt-out of the disclosure of their Personal Data to third parties for such purposes. We have adopted a policy of allowing you to opt-out of the disclosure of your personal information to third parties for direct marketing purposes and thus fall within this exception. To opt-out of the sharing of personal information to third parties for direct marketing purposes or otherwise exercise your rights under their section, please contact us.


Retention Period

We retain each of the categories of Personal Data (including Sensitive Personal Data) for as long as we have an ongoing legitimate business need to do so (for example, to provide you with an offering you have requested or to comply with applicable legal, tax, or accounting requirements). The criteria we use to determine whether we have an ongoing legitimate business need to retain Personal Data include among others:

  • Regulatory requirements that we are subject to. Including laws and regulations related to tax, employment, accounting, and securities. 
  • Whether a legal claim might be brought against us, for which Personal Data would be relevant.
  • The necessity of Personal Data to provide ongoing services to our customers. 
  • The types of sensitivity of Personal Data being processed. 

We have no ongoing legitimate business need to process your Personal Data, we will either delete or anonymize it or, if this is not possible (for example, because your Personal Data has been stored in backup archives), then we will securely store your Personal Data and isolate it from any further processing until deletion is possible. 


Not for Children

The Website is intended solely for use by individuals 21 years of age or older and thus is not directed to children under 21 years of age. Big Oak does not knowingly solicit or collect Personal Data from children under 21 years of age. 


Third Party Websites

In addition to providing access, the Website may include links to other websites and web services. This Privacy statement does not apply to those websites and services and the privacy practices of those websites and services may differ from those described in this Privacy Statement. If you submit Personal Data to any of those other websites or services, your Personal Data is governed by privacy policies applicable to those websites and services. Big Oak encourages you to carefully read the privacy policy of any website or web service you visit. 


Revisions and Updates to this Privacy Statement

Big Oak may from time to time revise this Privacy Statement in its sole and absolute discretion to reflect changes in our business practices or new disclosure requirements under applicable privacy laws. If we revise this Privacy Statement, we will notify you by posting the updated Privacy Statement on this Website and/or by sending you a notification by email, as required by applicable privacy laws. Changes to this Privacy Statement will become effective and will apply to the information collected starting on the date Big Oak posts the revised Privacy Statement on the Website. If we are required by applicable data protection laws to seek your consent to any changes in use of your Personal Data described in our updated Privacy Statement, then we will do that. 


Questions & Contact Information

If you have any questions or concerns about this Privacy Statement, the privacy practices of Big Oak, our collection or use of your Personal Data, or you wish to exercise privacy rights with respect to your Personal Data, please contact us at [email protected]. You can also make a request about your Personal Data by calling (314) 472-2233.