The latest version: June 19, 2021
Tuya Global Inc. and its Affiliates (as hereinafter defined) (“we”, “us”, “our”, or “Tuya”) are committed to protecting your privacy. Tuya Smart Privacy Policy (this “Policy”) describes our practices in connection with information privacy on Personal Data (as hereinafter defined) we process through your use of our services, products, and the Tuya Smart Mobile Application (the “App”) and related mobile applications (collectively, the “Services”).
Before you use the Services, please carefully read this Policy and understand our purposes and practices of collection, processing of your Personal Data, including how we use, store, share and transfer Personal Data. In this Policy you will also find ways to execute your rights of access, update, delete or protect your Personal Data.
When you accept this Policy when you register with your Personal Data, or if you start to use the Services and does not expressly object to the contents of this Policy, we will consider that you fully understand and agree with this Policy. If you have any question r regarding this Policy, please do not hesitate to contact us via:
Tuya Customer Service Department: 400-881-8611 or service@tuya.com
Tuya Privacy Office: privacy@tuya.com
In this Policy:
*Affiliate* means any company, firm or legal entity that: (1) is directly or indirectly controlled by Tuya; or (2) directly or indirectly controls Tuya; or (3) jointly with Tuya, controls the same company; or (4) is, directly or indirectly, under common control of the same company with Tuya. Affiliates shall include, without limitation, Tuya’s parent companies, subsidiaries, or such subsidiaries under common control of the same parent company as Tuya.
*Personal Data* means information generated, collected, recorded and/or stored, electronically or otherwise, that can be used to identify an individual or reflect the activity of an individual, either from that information alone, or from that information and other information we have access to about that individual.
*Personal Sensitive Data* includes personal biometric information, communication records and contents, health information, transaction information, and precise location information. When we collect Personal Sensitive Data from you, we will generate an explicit notification for your consent before we collection personal sensitive data about you.
*Smart Devices* refers to those computing devices produced or manufactured by hardware manufacturers, with human-machine interface and the ability to transmit data that connect wirelessly to a network, including: smart home appliances, smart wearable devices, smart air cleaning devices, etc.
In order to provide the Services to you, we will ask you to provide necessary Personal Data that is required to provide those Services. If you do not provide your Personal Data, we may not be able to provide you with the Services.
If you do not want to provide your profile data when you start to use any of the Services, you may use the App without login or creating an account, and you may still use certain Tuya services, such as searching and browsing any features on the Services. At this moment, we will not collect Personal Data about account or profile, and the collected data will be limited to those you have authorized to be collected for purpose of using the additional functions of the App and/or the Smart Devices, as well as corresponding usage information. However, if the Services you request or purchase are based on your account, please go to the registration/login page for guidance.
l Account or Profile Data: When you register an account with us, we may collect your account name and contact details, such as your email address, phone number, user name, and login credentials. During your interaction with the Services, we may further collect your nickname, profile picture, country code, language preference or time zone information into your account.
If you authorize login to the Services with a third party account, we will obtain from such third party your account information (such as portrait, nickname, region, gender, etc.) which may be bound with your Tuya account for quick login. We will ensure compliance with applicable data protection laws and regulations, as well as agreements, policies or documentations agreed with such third party regarding sharing personal information, in processing your Personal Data.
l Feedback: When using feedback and suggestion features in the Services, we will collect your email address, mobile phone number and your feedback content to address your problems and solve device failures on a timely basis.
l Information based on additional functions:
In order to offer you with more convenient and higher-quality Services with optimized user experiences, we may collect and use certain information if you consent to use additional functions in the App. Please note, if you do not provide such information, you may continue to use basic Services of the App and connected Smart Devices, but certain features based on these additional functions may not be available. These additional functions may include:
1) Additional functions based on location information:
When you enable the location-based functions through permission settings on your mobile device, we will collect and process your location information to enable these functions, such as pairing with your Smart Devices. Also, we may collect information about your real-time precise or non-precise geo-location when you use certain Smart Devices or the Services, such as robot cleaner and weather service.
Based on your consent, when you enable the geo-fence feature, your location information will be generated and shared with Google Maps services. Please note that Google has corresponding data protection measures, which you may refer to Google Data Protection Terms for more details: https://privacy.google.com/businesses/gdprservices/. You may reject such use of your location information by managing the permission settings in the Services, upon which we will cease to collect and use your location information.
2) Additional services based on camera:
You may use the camera to scan the code by turning on the camera permission to pair with a Smart Device, take video, etc. Please be aware that even if you have agreed to enable the camera permission, we will only obtain information when you actively use the camera for scanning codes, video recording, etc.
3) Additional services for accessing and uploading pictures/videos based on photo albums (picture library/video library):
You can use this function to upload your photos/pictures/videos after turning on the photo album permission, so as to realize functions such as changing the avatar, reporting device usage problems by providing photo proofs, etc.. When you use the photos and other functions, we will not recognize this information; but when you report a device usage problem, we may use the photos/pictures you upload to locate your problem.
4) Additional services related to microphone-based service:
You can use the microphone to send voice information after turning on the microphone permission, such as shooting videos, waking up the voice assistant, etc. For these functions, we will collect your voice information to recognize your command. Please be aware that even if you have agreed to enable the microphone permission, we will only obtain voice information through the microphone when you voluntarily activate the microphone in the App.
5) Additional services based on storage permissions:
The purpose is to ensure the stable operation of the App by utilizing the storage permission. After you give or indicate the permission to read/write your mobile device’s storage, we will access pictures, files, crash log information and other necessary information from your mobile device’s storage to provide you with functions, such as information publications, or record the crash log information locally.
Please note that if you turn on any permission, you authorize us to collect and use relevant personal information to provide you with corresponding Services. Once you turn off any permission, we will take it as canceling the authorization, and we will no longer continue to collect Personal Data based on the corresponding permissions, and the related functions may be terminated. However, your decision to turn off the permission will not affect the previous collection and use of information based on your authorization.
l Mobile Device Information: When you interact with our Services, in order to provide and maintain the common operation of our services, improve and optimize our service, and protect your account security as well, we automatically collect device information, such as mobile device model number, IP address, wireless connection information, operating system type and version, mobile hardware serial number (a unique mobile identifier, which is a string representing the device manufacturer coded in the mobile device), Android ID, application version number, push notification identifier, log files, and mobile network information.
l Usage Data: During your interaction with our websites and Services, we automatically collect usage data relating to visits, clicks, downloads, messages sent/received, and other usage of our websites and Services.
l Log Information: When you use the App, the system and exception log may be uploaded.
Please note that one cannot identify a specific individual by using device information or log information alone. However, if these types of non-personal information, combined with other information, may be used to identify a specific individual, such non-personal information will be treated as Personal Data. Unless we have obtained your consent or unless otherwise provided by data protection laws and regulations, we will anonymize and desensitize such non-personal information.
l Basic Information of Smart Devices: When you connect your Smart Devices with the Services, we may collect basic information about your Smart Devices such as device name, device ID, online status, activation time, firmware version, and upgrade information.
l Information Reported by Smart Devices: Depending on the different Smart Devices you elect to connect with the Services, we may collect different information reported by your Smart Devices. For example, smart weights or fitness trackers may report your height, weight, body fat mass (BFM), BMI and skeletal muscle mass (SMM); smart cameras may report images or videos captured by it. *Particularly*, *when you proactively consent to the Services* connecting with third party Health platform to enable the fundamental feature for you (such as Apple Health, Google Fit, Fitbit, etc), we will share your health data (exclusively to your BMI, height, weight and body fat%) with them for the sole purpose of measuring and analyzing heath related indicators about you. We will not disclose such health data to any other third party. You may disconnect the Services with third party Health platform at any time by managing your health settings on your mobile device.
The purpose for which we may process information about you are as follows:
l Provide You Services: We process your account and profile data, device information, usage data, location information, and Smart Device related information to provide you with the Services and Services that you have requested. The legal basis for this processing is to perform our contract with you according to our Terms of Use.
l Improve Our Services: We process your device information, usage data, location information and Smart Device related information to ensure the functions and safety of the Services, to develop and improve the Services and Services, to analyze the efficiency of our operations, and to prevent and trace fraudulent or inappropriate usage. The legal basis for this processing is to perform our contract with you according to our Terms of Use.
l Non-marketing Communication: We process your Personal Data to send you important information regarding the Services, changes to our terms, conditions, and policies and/or other administrative information. At the same time, we will also send you notifications related to the services you have purchased, such as alert services. You can check the “App Notification” in the App (“Me > Settings on the upper right corner > App Notification > Notification Setting”) to manage these communications. When you decide not to enable the Notifications function, we will no longer process your information for such purpose. The legal basis for this processing is to perform our contract with you according to our Terms of Use.
l Data analysis: In order to analyze the usage of the products we provide and improve your user experience, we will analyze the data you voluntarily provide and report to us, we need to check your problems when you encounter any malfunctions during the usage of the product, and analyze data about how you interface with the product or under particular scenarios so that you can better enjoy the convenience brought by our Services. If you do not agree to data analysis of your data, you can enter the privacy settings of Tuya App (“My > Settings at the upper right corner > Privacy Settings > Data Analysis”) to opt-out your selection. The legal basis for such processing is based on your consent.
l Personalization: We may process your account and profile data, usage data, device information to personalize product design and to provide you with services tailored for you, such as recommending and displaying information and advertisements regarding products suited to you, and to invite you to participate in surveys relating to your use of the Services. If you do not allow us to process your Personal Data for personalization, you may opt out when you enter the App, or by changing your preferences in “Privacy Settings” (“Me> Settings at the upper right corner > Privacy Settings > Personalization” in the App. The legal basis for this processing is your consent.
l Legal Compliance: We may process your Personal Data as we believe to be necessary or appropriate:
a) to comply with applicable laws and regulations;
b) to comply with legal process;
c) to respond to requests from public and government authorities;
d) to enforce our terms and conditions;
e) to protect our operations, business and systems;
f) to protect our rights, privacy, safety or property, and/or that of other users, including you; and
g) to allow us to pursue available remedies or limit the damages that we may sustain.
l If there is any change in the purposes for processing your Personal Data, we will inform such change to you via email and/or a prominent notice on our website of such changes of purposes, and choices you may have regarding your Personal Data.
At Tuya, we only share Personal Data in ways that we tell you about. We may share your Personal Data with the following recipients:
l To our third-party service providers who perform certain business-related functions for us, such as website hosting, data analysis, payment and credit card processing, infrastructure provision, IT services, customer support service, e-mail delivery services, and other similar services to enable them to provide services to us.
l To our customers and other business partners who provide you, directly or indirectly, with your Smart Devices, and/or networks and systems through which you access and use our websites and Services.
l To an Affiliate or other third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including without limitation in connection with any bankruptcy or similar proceedings). In such an event, you will be notified via email and/or a prominent notice on our website of any change in ownership, incompatible new uses of your Personal Data, and choices you may have regarding your Personal Data.
l As we believe to be necessary or appropriate:
a) to comply with applicable laws and regulations;
b) to comply with legal process;
c) to respond to requests from public and government authorities, including public and government authorities outside your country of residence;
d) to enforce our terms and conditions;
e) to protect our operations, business and systems;
f) to protect our rights, privacy, safety or property, and/or that of other users, including you; and
g) to allow us to pursue available remedies or limit the damages that we may sustain.
l To Affiliates to carry out regular business activities.
Except for the third parties described above, to third parties only with your consent.
Tuya will comply with applicable data localization requirements in corresponding jurisdictions with respect to storage of data. To facilitate our operation, we may transfer, store and process your Personal Data in jurisdictions other than where you live. Laws in these countries may differ from the laws applicable to your country of residence. When we do so, we will ensure that an adequate level of protection is provided for the information by using one or more of the following approaches:
l Agreement on the basis of approved EU standard contractual clauses per GDPR Art. 46. For more information, see https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc/standard-contractual-clauses-international-transfers_en.
If you would like to know more about the storage location of your Personal Data, please visit https://www.tuya.com/rule . Or if you would like further detail on the safeguards we have in place, you can contact us directly as described in this Policy.
We respect your rights and control over your Personal Data. You may exercise any of the following rights:
l Via the “Me > Settings > Account and Security” or via “Me > FAQ&Feedback” in the Services (for Product version 3.2 and later).
l By emailing us at privacy@tuya.com (for Product version before 3.2)
You do not have to pay a fee for executing your personal rights. Subject to applicable data protection laws in relevant jurisdictions, your request of personal rights will be fulfilled within 15 business days, or within 30 calendar days due to different response requirement.
If you decide to email us, in your request, please make clear what information you would like to have changed, whether you would like to have your Personal Data deleted from our database or otherwise let us know what limitations you would like to put on our use of your Personal Data. Please note that we may ask you to verify your identity before taking further action on your request, for security purposes.
You may:
n Request access to the Personal Data that we process about you;
n Request that we correct inaccurate or incomplete Personal Data about you;
n Request deletion of Personal Data about you;
n Request restrictions, temporarily or permanently, on our processing of some or all Personal Data about you;
n Request transfer of Personal Data to you or a third party where we process the data based on your consent or a contract with you, and where our processing is automated;
n Opt-out or object to our use of Personal Data about you where our use is based on your consent or our legitimate interests.
l *Withdrawal of consent*: We will exercise your privacy right to withdraw consent through the following approaches:
1) For privacy permissions acquired through device system settings, your consent can be withdrawn by changing device permissions, including location, camera, photo album (picture library/video library), microphone, Bluetooth settings, notification settings and other related functions;
2) You may opt-out the non-marketing communication through “Me > Settings at the upper right corner > Notification Settings” to manage your selection;
3) You may opt-out the data analysis features through “Me > Settings at the upper right corner > Privacy Settings”;
4) You may opt-out the Personalization feature through “Me > Settings at the upper right corner > Privacy Settings > Personalization”;
5) Unbind the Smart Device through the App, and the information related to the Smart Device will not be collected;
6) By using product with the visitor mode, we will not collect any profile data about you.
When you withdraw your consent or authorization, we may not be able to continue to provide you with the products or services correspondingly. However, your withdrawal of your consent or authorization will not affect the processing of personal information based on your consent before the withdrawal.
About Deletion of the Account: You can find the Delete function through “Me > Settings at the upper right corner > Account and Security > Delete Account” (“Deactivate Account” for the App version under 3.16.5).
We use commercially reasonable physical, administrative, and technical safeguards to preserve the integrity and security of your Personal Data. Tuya provides various security strategies to effectively ensure data security of user and device. As for device access, Tuya proprietary algorithms are employed to ensure data isolation, access authentication, applying for authorization. As for data communication, communication using security algorithms and transmission encryption protocols and commercial level information encryption transmission based on dynamic keys are supported. As for data processing, strict data filtering and validation and complete data audit are applied. As for data storage, all confidential information of users will be safely encrypted for storage. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any account you might have with us has been compromised), you could immediately notify us of the problem by emailing privacy@tuya.com.
We process your Personal Data for the minimum period necessary for the purposes set out in this Policy, unless there is a specific legal requirement for us to keep the data for a longer retention period. We determine the appropriate retention period based on the amount, nature, and sensitivity of your Personal Data, and after the retention period ends, we will destruct your Personal Data. When we are unable to do so for technical reasons, we will ensure that appropriate measures are put in place to prevent any further such use of your Personal Data.
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third-party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.
Protecting the privacy of young children is especially important to us. The Services are not directed to individuals under the age of thirteen (13) (or such other age provided by applicable law in your country/region of residence), and we request that these individuals do not provide any Personal Data to us. We do not knowingly collect Personal Data from any child unless we first obtain permission from that child’s parent or legal guardian. If we become aware that we have collected Personal Data from any child without permission from that child’s parent or legal guardian, we will take steps to remove that information.
We may update this Policy to reflect changes to our information practices, at least on an annual basis. If we make any material changes we will notify you by email (send to the e-mail address specified in your account) or by means of a notice in the mobile applications prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.
If you have any questions about our practices or this Policy, please contact us as follows:
Tuya Global Inc.
Postal Mailing Address: 3979 Freedom Circle, Suite 340, Santa Clara, CA 95054, USA
Email: privacy@tuya.com.
For European Union or United Kingdom data subjects, you have the right to lodge a complaint with a supervisory authority concerning Tuya’s data processing activities. For questions, or to exercise your rights as an EU or UK data subject, please contact our EU/UK Representative here:
Name: Rickert Rechtsanwaltsgesellschaft mbH
Email: art-27-rep-hangzhoutuya@rickert.law
Emailing Address: Colmantstraße 15, 53225 Bonn, Germany