SUMMER SPECIAL
Up To 38% OFF SiteWide
00
:05
:00
You must be 21 years of age or older to view this site.
Sorry, you must be 21 or older to access this site.
By entering this site you certify that the above statement is true.
Effective Date: September 10, 2026
Last updated: September 10, 2026
This Privacy Policy (“Policy”) describes how UAVA Labs (“UAVA,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes personal information in connection with uavalabs.com (the “Site”), our mobile application (the “UAVA App” or “App”), our hardware products including the UAVA Bluetooth-enabled vaporizer battery and any successor or related device (each, a “Device”), and any related services (collectively, the “Services”).
By using the Services, you acknowledge that you have read and understood this Policy. This Policy is incorporated by reference into our Terms & Conditions.
We may update this Policy from time to time to reflect changes in our practices, our Services, or applicable law. We will post the revised Policy on the Site and update the “Last updated” date. Where a change materially alters how we collect, use, or disclose personal information, we will present the updated Policy in the App and ask you to accept it before you continue using the Services. Each acceptance is recorded together with the version of the text shown to you, and an acceptance recorded against an earlier version does not constitute acceptance of a later material change.
The Services are intended exclusively for individuals who are at least 21 years of age. We do not knowingly collect personal information from anyone under 21. If we learn that we have done so, we will take reasonable steps to delete it. If you are the parent or legal guardian of a minor whom you believe has provided personal information to us, contact us at help@uavalabs.com.
When we use the term “personal information,” we mean information that identifies, relates to, describes, or can reasonably be associated with you, as defined under the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA”) and other applicable state privacy laws. The categories we collect, and have collected in the preceding twelve months, are described below. The specific information within each category varies depending on how you interact with us and may change as our Services develop.
When you pair a Device with the App, the App collects information generated by the Device and by your use of the App (“Device Data”). Device Data falls into the following categories:
We handle location in two distinct ways, and we keep them separate.
Approximate location associated with Device Data. If you grant the App location permission, the App reduces your location on your phone to a broad geographic area covering several square kilometers before any information leaves your phone. Only that area identifier is transmitted with Device Data. Precise coordinates are discarded on your phone and are not included in Device Data. Where you have not granted location permission, we may infer an approximate region from your IP address.
Precise location associated with the locate-your-Device feature. If you use the feature that helps you find a misplaced Device, we record the Device’s last known position as precise coordinates and store it with your account information. This feature cannot work with an approximate area. This information is visible only to you when signed in, is held separately from Device Data, and is not combined with Device Data or included in any dataset we license or disclose. It is deleted when you delete your account. You can withdraw location permission at any time in your phone’s settings.
Precise location is sensitive personal information under the CCPA. We use it only to provide the locate feature you have asked for, and for the related purposes permitted under California Civil Code Section 1798.121. See “Sensitive Personal Information” below.
We and our service providers and advertising and analytics partners use cookies, software development kits, pixels, mobile advertising identifiers, server logs, and similar technologies (“Tracking Technologies”) to collect information about your interaction with the Services, including internet and network activity information, device and browser information, IP address, and advertising identifiers. Some Tracking Technologies are operated by third parties, including major analytics and advertising platforms, which may receive information about your use of the Services and combine it with information from other sources.
We obtain information from service providers and partners who support our Services, including hosting and e-commerce providers, payment processors, age and identity verification vendors, shipping and fulfillment partners, marketing and analytics providers, social media platforms, retailers and distributors, and publicly available sources. Information we obtain from third parties is handled in accordance with this Policy.
We use personal information for the purposes disclosed at the point of collection, for any purpose to which you consent, and for the following business and commercial purposes:
features, and designing and developing new ones.
We disclose personal information in the following circumstances:
We produce datasets from Device Data and other information collected through the Services and license or otherwise disclose them to third parties, which may include research organizations, commercial and industry partners, analytics providers, investors and prospective acquirers, and other commercial parties. Datasets we license outside UAVA are de-identified or aggregated before disclosure. De-identification means we remove or transform identifiers and apply technical and organizational safeguards, including minimum group sizes for published statistics, so that the data cannot reasonably be linked to you. Datasets never contain your name, contact information, account credentials, payment information, precise location, or Device hardware identifiers. We commit publicly to maintaining and using de-identified data only in de-identified form and not to attempt to re-identify it, and we require the same commitment by contract from every recipient. Recipients are further required by contract not to combine the data with other datasets for the purpose of identifying any individual, not to transfer it onward, to use it only for the purposes we agree, and to apply security controls no less protective than our own.
Once data has been de-identified or aggregated it is no longer personal information under applicable law, and we may use, retain, license, sell, and disclose it without restriction. It is not subject to access or deletion requests, because it can no longer be associated with any individual. UAVA owns all right, title, and interest in the datasets it produces.
Where the law of your state requires opt-in consent, a separate authorization, or a specific disclosure before information of the kind we collect may be sold, shared, or licensed, we obtain that consent or authorization in the form that law requires, or we exclude your information from the relevant dataset. Acceptance of this Policy or of our Terms & Conditions is not, by itself, such an authorization. Where we are required to register as a data broker, we register and honor deletion requests submitted through any applicable state mechanism.
Under the CCPA, disclosing personal information for monetary or other valuable consideration may be a “sale,” and disclosing it for cross-context behavioral advertising may be “sharing.” In the preceding twelve months we have sold or shared identifiers, internet and network activity information, commercial information, approximate geolocation information, demographic information, inferences, and Device Data.
We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age. We do not sell or share sensitive personal information for the purpose of inferring characteristics about a consumer.
You may opt out of the sale or sharing of your personal information at any time using the “Your Privacy Choices” link on the Site or by contacting us. An opt-out also excludes your information from datasets we produce going forward.
Depending on where you live, you may have some or all of the following rights. These rights are not absolute, apply only in certain circumstances, and in some cases we may decline a request as permitted by law.
Stopping collection. You can stop Device Data collection at any time using the data sharing setting in the App, or by disconnecting your Device. When collection is off, the App stops reading new information from your Device and stops transmitting information that has not already been sent. Stopping collection does not by itself delete information already collected.
Deleting Device Data. To delete Device Data, contact us at help@uavalabs.com and we will tell you what is needed to complete your request. Because Device Data is stored under randomly generated identifiers rather than under your name or account, we cannot locate it from your name, email address, or phone number alone, and completing a deletion request requires information available to you in the App. We will confirm when your request has been carried out, and we retain a dated record that it was received and honored.
Deletion removes your Device Data from our systems and excludes it from every dataset we produce from that point forward. Datasets already de-identified, aggregated, or delivered to recipients cannot be recalled, because that data can no longer be associated with you; recipients remain contractually barred from attempting to identify any individual.
Account information is held separately from Device Data and can be located and deleted using your account details. Deleting your account also deletes the location information associated with the locate-your-Device feature.
You may opt out of marketing emails using the unsubscribe link, opt out of marketing text messages by replying STOP, and control push notifications in your device settings. We may continue to send transactional and service communications regardless of your marketing preferences.
Email help@uavalabs.com or use the request mechanism available on the Site or in the App. Authorized agents may submit requests with appropriate written authorization. We may need to verify your identity before acting. We respond within the periods required by applicable law, generally within 45 days of a verifiable request, with an extension where permitted.
California residents may request, once per calendar year, a list of the categories of personal information we disclosed to third parties for those third parties’ own direct marketing purposes in the preceding calendar year, together with the names and addresses of those third parties, under California Civil Code Section 1798.83. California residents under 18 who are registered users may request removal of content they have publicly posted, under California Business and Professions Code Section 22581. Email help@uavalabs.com with the subject line “Shine the Light Request” or “Minor Removal Request.”
Some information we collect may be sensitive personal information under the CCPA or comparable state laws, including precise location associated with the locate-your-Device feature and account credentials in combination with passwords. We collect and use sensitive personal information only for the purposes permitted under California Civil Code Section 1798.121, including providing the services you would reasonably expect, detecting security incidents, resisting fraudulent or malicious activity, performing services on our behalf, and maintaining the quality of our Services. We do not use sensitive personal information to infer characteristics about you, and we do not sell or share it. You may ask us to limit our use of sensitive personal information as described under “Your Rights.”
UAVA designs, manufactures, and sells consumer hardware. We do not provide health care services, do not make medical claims, and do not collect information for the purpose of assessing, measuring, or learning about any person’s health. The Services are not intended to diagnose, treat, cure, or prevent any disease or condition. Information about how a Device was operated records the use of consumer hardware and is not a clinical measurement.
Several states define consumer health data broadly, and information of this kind may fall within those definitions depending on how it is used. Rather than rely on that question being resolved in our favor, we apply the state-law limits described under “Datasets We License” above. If you reside in a state with a consumer health data law and wish to exercise rights under it, email help@uavalabs.com.
We use automated systems for purposes including fraud detection, eligibility and identity verification, personalization, advertising delivery, and analytics. We do not use automated decision-making to produce legal or similarly significant effects on you without human involvement. Where applicable law provides the right, you may request information about such processing, object to it, or seek human review.
We use Tracking Technologies to operate and improve the Services, remember your preferences, authenticate users, prevent fraud, run analytics, and deliver advertising. Where required by law, we obtain consent before deploying non-essential Tracking Technologies, and you can manage your preferences through the cookie preferences center on the Site or through your browser or operating system settings. Where required by law, we treat a Global Privacy Control signal from your browser as an opt-out of sale and sharing for that browser. We do not otherwise respond to Do Not Track signals.
If you use the App on an Apple device, you may be asked whether you permit tracking across apps and websites owned by other companies. If you decline, we will not request your advertising identifier for cross-context behavioral advertising, and we will continue to collect the information described in this Policy as permitted by applicable law and App Store rules.
We may offer financial incentives or price differences connected to our collection, retention, or sale of personal information, such as loyalty, referral, or subscription programs. Where we do, we will provide a notice of financial incentive at the point of collection describing the material terms, the categories of personal information involved, the value of that information to us, and how to opt in and withdraw. Participation is voluntary and you may withdraw at any time.
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, network controls that prevent direct public access to our databases, and access limited to authorized personnel who need it for their role. No system is perfectly secure and we cannot guarantee absolute security. In the event of a breach involving your personal information, we will notify you and applicable regulators as required by law.
We retain personal information for as long as necessary for the purposes described in this Policy, and then delete, de-identify, or aggregate it. Because the length of time necessary varies, we apply the following criteria rather than a single fixed period:
Account, order, and transaction records are generally retained for the period required by tax, accounting, and consumer protection law. Records of your acceptance of our terms and policies are retained for the duration of your relationship with us plus the applicable limitations period. De-identified and aggregated data may be retained indefinitely, as it can no longer be associated with any individual. We review our retention practices periodically and delete information that no longer meets the criteria above.
If you provide your mobile number and consent to receive text messages, you agree to receive recurring marketing and transactional messages from UAVA at that number. Consent is not a condition of any purchase. Message frequency varies. Message and data rates may apply. Reply STOP to opt out or HELP for assistance. Carriers are not liable for delayed or undelivered messages.
The Services are not intended for children and we do not knowingly collect personal information about children. We do not have actual knowledge that we sell or share the personal information of individuals under 16. If you are the parent or legal guardian of a child who has provided us information, contact us and we will take reasonable steps to delete it.
The Services may link to or interoperate with websites, applications, and platforms operated by third parties. We do not control and are not responsible for their privacy or security practices, and we encourage you to review their policies.
We operate in the United States and intend the Services for users in the United States and other jurisdictions where we make them available. We do not knowingly target the Services to residents of the European Economic Area or the United Kingdom. If you access the Services from outside the United States, your information may be transferred to and processed in the United States and other countries whose data protection laws differ from those where you live. Where required, we rely on appropriate safeguards for such transfers.
If you have difficulty accessing this Policy or any part of the Services, or need this Policy in an alternative format, contact us at help@uavalabs.com.
Questions about this Policy or requests to exercise your rights may be directed to:
UAVA Labs
Attn: Privacy
7770 Regents Rd, Suite 113-540
San Diego, CA 92122
Email: help@uavalabs.com
For purposes of applicable data protection law, UAVA Labs is the controller of your personal information.