Last updated on: July 28, 2022
Thank you for having signed up for a HeyTap Account. When you use your HeyTap Account to access products and services that integrate the HeyTap Account SDK, we may collect and use your personal information. Personal information refers to all information that is recorded electronically or otherwise and can be used alone or in combination with other information to identify a specific natural person.
Agreeing to this Privacy Notice only means that you are aware of the features of our products or services and agree to our collection of your personal information necessary for running the features. It does not mean that you have agreed to us collecting additional personal information. If we need to collect additional personal information, we will do so only with your authorization after separately asking for your prior consent during your use of the features.
- 1. How We Collect and Use Your Personal Information
- 2. How We Retain Your Personal Information
- 3. How We Share, Transfer or Publicly Disclose Your Personal Information
- 4. How We Protect Your Personal Information
- 5. Your Rights to Your Personal Information
- 6. How We Process Children's Personal Information
- 7. How Your Personal Information Is Transferred Globally
- 8. How This Privacy Notice Is Updated
This Privacy Notice will help you understand:
1. How We Collect and Use Your Personal Information
We collect personal information to operate more efficiently and provide you with an optimal user experience. We collect information about you in three primary ways:
(1) directly from you;
(2) automatically from your use of your HeyTap Account; and/or
(3) from third parties.
The information we collect depends on the products you use, the environment in which you interact with us, and the choices you make, including your privacy settings and the products and features you use. Our products or services provide basic and additional features. When it comes to our HeyTap Account services, If you do not provide the personal information necessary for running the basic features, then these features may not be available to you. For additional features, you may choose whether or not to agree to our collection of your personal information. If you do not agree, the required additional features may not be available to you. This, however, does not affect your use of the basic features. Please note that if you do not agree to our collection and use of your personal information needed to provide additional features, please do not turn on such features.
1.1 How We Collect and Use Your Personal Information
(1) For OPPO, realme, and OnePlus devices
If your device brand is OPPO, realme, or OnePlus, the HeyTap SDK is only used to trigger the auto launch of the HeyTap Account management app on your device. To ensure that the account management app can be launched successfully, the SDK will access your list of installed apps to obtain the version of the account management app when you open an app that integrates the SDK. For information on how such apps collect and process your personal information, please refer to the respective privacy notices.
(2) For devices of other brands
If your device is of a different brand, the HeyTap Account SDK will provide you with services such as sign-up, sign-in, account security verification, address management, real-name authentication, and notifications and push services. We will collect your personal information as described below.
a. Sign-up and sign-in services
When you sign up or sign in to your HeyTap Account, we may collect your phone number or email address, password, and the sign-up SMS message to sign you up and assist you in signing in to your account to use related services. We may also use the date of birth you provided during the sign-up process to determine the age of the HeyTap Account holder and provide age-appropriate services so as to comply with our legal obligations for child protection. Such information is essential for the sign-up and sign-in features. If you do not provide such information, we will not be able to provide you with the sign-up or sign-in service. We will share your phone number with our SMS service provider so that they can send you verification codes during the sign-up or sign-in process, thus allowing you to complete the process.
After you have signed up for a HeyTap Account, you may choose whether to provide us with information such as your username, profile picture, gender, name, contacts for manual account recovery, and real-name authentication information to complete your account details. You are not obliged to provide such information to use account services. If you do not provide it, you can still use the sign-up and sign-in services.
We may contact you using the aforementioned information for research or promotional purposes. Please note that you can and are encouraged to sign up for an account with your own phone number. When you sign up with your own phone number, your device will automatically send an SMS message to us to verify your phone number, which may incur carrier costs.
We will collect and sync the reward points, membership information, and other relevant data of your HeyTap Account within our HeyTap products as well as the products and services provided by our affiliates or third parties that are accessible with your HeyTap Account, and display them in the account information page. This is to sync your user benefits such as reward points and membership information across different products.
B. Account security verification (when your account is signed in on an unknown device)
When your account is signed in on an unknown device, to ensure the security of your account, we need to collect the MAC address, serial number, name, and OpenID (or IMEI) of the device, the IMSI number stored on the device, the location where the account was registered, the name of the connected Wi-Fi network, and information about your telecom carrier. Such information is necessary to perform account security verification. If you refuse to provide the information, you can still sign in to your account, but we will not be able to ensure the security of the environment in which your account is signed in.
c. Phone number verification (in case you use a recycled phone number for sign-up)
When we detect that the phone number you use to sign up for a HeyTap Account was a recycled phone number and has been linked to a HeyTap Account by its previous user, we will provide you with guidance on how to sign up for a new HeyTap Account with this phone number. To check whether you are using a recycled phone number, we need to collect your phone number, the IMSI number stored on your device, and information about your telecom carrier. Such information is necessary to perform this function. If you refuse to provide it, you may fail to complete the sign-up process since your phone number might have already been linked to a HeyTap Account.
d. Address management
When you add a shipping address on a relevant service page or in the online store, you may need to provide us with information about your contacts. The shipping address you entered will be synced to your HeyTap Account. We collect the aforementioned information to help you quickly enter the receiver's name and phone number.
e. Real-name authentication
If applicable laws and regulations in your country require real-name authentication, we will collect your real-name information such as your name and ID card number. If you refuse to provide such information, we may not be able to provide you with the required products or services.
f. Notifications and push services
After you have signed up for a HeyTap Account, we may use information about your device, such as the device name, device model, IMEI number or OpenID, MAC address, serial number, IP address, and operating system version, and the phone number and email address linked to your account to provide you with content pushes or notifications relating to our HeyTap products or third-party services, including app updates and installations, sales and promotional messages, etc. You may opt out of receiving our sales and promotional messages by SMS or email, or by turning off the notification feature through "Settings - Notifications". Please note that the operation path may vary by phone model or version.
1.2 Required App Permissions
(1) When you use the HeyTap Account SDK on an Android device, we may request certain app permissions to collect your personal information and provide you with the features or services you request. Specifically, we may request the following permissions.
Required Permission | Intended Feature/Service | Purpose | Ask Before Turning It On? | Can the User Turn It Off? | Impact of Turning Off/Denying Permission |
External storage data | Changing profile pictures; downloading files | To let you download files to and store pictures on your SD card so that you can select the desired one as your profile picture | Yes | Yes | Caching profile pictures will fail, and you cannot change your profile picture or download files. |
Camera | Changing profile pictures | To let you take pictures with your device's camera and select the desired one as your profile picture | Yes | Yes | You cannot take pictures with your device's camera and, as a result, cannot select the desired picture as your profile picture. |
Display over other apps | Upgrading the HeyTap Account management apps | To allow you to perform an upgrade in a HeyTap Account management app | No | Yes | You cannot upgrade the HeyTap Account SDK within the app integrating the SDK |
(2) When you use the HeyTap Account SDK on an iOS device, we may also request certain app permissions to collect your personal information and provide you with the features or services you request. Specifically, we may request the following permissions.
Required Permission | Intended Feature/Service | Purpose | Ask Before Turning It On? | Can the User Turn It Off? | Impact of Turning Off/Denying Permission |
Camera | Changing profile pictures | To let you take pictures with your device's camera and select the desired one as your profile picture | Yes | Yes | You cannot take pictures with your device's camera and, as a result, cannot select the desired picture as your profile picture. |
Reading or saving pictures from or to Photos | Changing profile pictures | To let you access from and save pictures to Photos and select the desired one as your profile picture | Yes | Yes | You can neither access from nor save pictures to Photos and, as a result, cannot select the desired one as your profile picture. |
(3) Please note that the app permissions that can be used by the HeyTap Account SDK are limited to those requested by and granted to the apps integrating the SDK with your consent. The SDK will not be able to use the app permissions not granted to those apps or beyond the scope of your authorization. You may go to the Settings app on your device at any time to turn off the app permissions used by the HeyTap Account SDK. After the permissions are turned off, the corresponding features may not work properly.
The operation paths to manage app permissions may vary by phone model and OS version. For the actual operation paths, please refer to your phone. We undertake that we will not use your app permissions without your authorization or consent, or use your personal information collected based on the app permissions in scenarios to which you have not given your authorization or consent.
1.3 We May Collect or Use Your Personal Information Without Your Authorization or Consent
You are fully aware that under applicable laws, we may collect and use your personal information without your authorization or consent in the following circumstances:
- (1) as necessary to fulfill any of our obligations under laws and regulations;
- (2) as necessary to protect national security or national defense;
- (3) as necessary to protect public security, public health, or significant public interests;
- (4) as necessary for criminal investigations, prosecution, trials, or the enforcement of judgments;
- (5) as necessary to safeguard the significant legitimate rights and interests (such as life and property) of you or others, but it is difficult to obtain your authorization or consent;
- (6) the personal information involved is made public by you;
- (7) as necessary to enter into a contract with you or perform a contract entered into between you and us;
- (8) the personal information is collected from legally publicly-disclosed information, such as legal news reports and government information disclosures;
- (9) as necessary for us to maintain the secure and stable operation of the HeyTap Product, such as identifying or handling product or service faults;
- (10) as necessary for a news agency to deliver a legal news report;
- (11) as necessary for an academic or research institution to produce statistics or conduct academic research based on public interests, and the personal information contained in the results is de-identified before the results are published.
2. How We Retain Your Personal Information
The personal information we collect will be retained for the minimum period needed to fulfill the purposes for which it is collected as described in this Privacy Notice, unless otherwise specified by applicable laws or regulations. We will completely delete or anonymize your personal information upon the expiration of the retention period or when it can be deleted.
If we stop some or all of our products or services for any special reason, we will promptly inform you and stop the collection and processing of your personal information in connection with such products or services. We will also delete or anonymize such information that we hold unless otherwise specified by laws and regulations.
3. How We Share, Transfer or Publicly Disclose Your Personal Information
3.1 How We Share and Transfer Your Personal Information
- (1) Sharing with our affiliates: In order for us to provide services to you based on your account, we may share your personal information with our affiliates. We will only share the necessary personal information. If we or our affiliates intend to change the purpose for which your personal information is used and processed, we will obtain your authorization or consent again.
-
(2) Sharing with our authorized partners: Some of our services will be provided by our authorized partners only for the purposes stated in this Privacy Notice. Therefore, we may share some of your personal information with such partners in order to provide services to you and improve your user experience. Specifically:
-
a. In certain circumstances, we will entrust a third party to process your personal information on our behalf. For example, companies that send SMS messages or emails or that provide technical support on our behalf are allowed to use your personal information only to provide you with the required services.
- (3) When we are in the process of a merger, acquisition, or bankruptcy liquidation, and if such process requires the transfer of your personal information, we will request the new company or organization that holds your personal information to continue to be bound by this Privacy Notice; otherwise, we will require this company or organization to obtain your authorization or consent again. If the process does not involve the transfer of personal information, we will adequately inform you and delete or anonymize all your personal information under our control.
We may, from time to time, share certain personal information with our affiliates and the strategic partners who work with us to provide the required products and services or otherwise share or transfer your personal information in order to provide the products or services you request.
We will share or transfer your personal information only for legitimate, proper, necessary, specific, and explicit purposes, and we will only share personal information which is necessary for the provision of the required services. In addition, we will require the above-mentioned third parties to take appropriate confidentiality and security measures during their processing of your personal information by means of agreements or other appropriate measures.
3.2 Our Cooperation with Third-Party Software Development Kit (SDK) Providers
The HeyTap Account SDK for Android devices may contain SDK plugins provided by our authorized partners. These third-party plugins may collect and process relevant personal information about you. See the table below for details.
SDK Type | Plugin Name | Functionality/Scenario | Name of SDK Provider | Personal Information That May Be Collected/Used | Required Permission | Privacy Policy of the SDK Provider |
Functionality | Glide | This SDK provides the image loading functionality. | bumptech | Personal files in storage | 1. Read external storage 2. Write to external storage | https://bumptech.github.io/glide/ |
The HeyTap Account SDK for iOS devices does not integrate any third-party SDK that collects personal information or requires sensitive app permissions.
We have also integrated other SDKs to implement certain features. Please be aware that such SDKs do not collect any personal information or require any sensitive app permissions.
The independent and direct collection and use of personal information by the SDKs listed above is governed by their own privacy terms. As for your personal information collected by the above SDKs as our data processors and shared with the SDK providers by us, its processing (including but not limited to transfer, storage, and usage) is also governed by the privacy terms of the SDK providers. We will carefully review the purpose for which the SDK providers use your personal information, assess their security capabilities, and bind them to a legal cooperation agreement. We will implement strict security monitoring to protect data security. In order to ensure the security of your information, you are strongly recommended to read the privacy terms for any third-party SDKs before using the services provided by such SDKs. If you find any risks associated with such SDKs or other similar apps, you are recommended to immediately stop using them and promptly contact us in order to safeguard your legitimate rights and interests.
3.3 How We Publicly Disclose Your Personal Information
We will publicly disclose your personal information only in the following situations:
- (1) After obtaining your explicit consent; or
- (2) Legal disclosure: Should we be legally required to comply with subpoenas or other legal procedures, litigations, or mandatory requirements of government authorities, we may disclose your personal information if we sincerely believe that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud or respond to government requests.
3.4 We May Share, Transfer, or Publicly Disclose Your Personal Information Without Your Authorization or Consent
You are fully aware that under applicable laws, we may share, transfer, or publicly disclose your personal information without your prior authorization or consent in the following circumstances:
- (1) as necessary to fulfill any of our obligations under laws and regulations;
- (2) as necessary to protect national security or national defense;
- (3) as necessary to protect public security, public health, or significant public interests;
- (4) as necessary for criminal investigations, prosecution, trials, or the enforcement of judgments;
- (5) as necessary to safeguard the significant legitimate rights and interests (such as life and property) of you or others, but it is difficult to obtain your authorization or consent;
- (6) the personal information involved is made public by you;
- (7) the personal information is collected from legally publicly-disclosed information, such as legal news reports and government information disclosures.
4. How We Protect Your Personal Information
4.1 How We Protect Your Personal Information
We adopt technical and organizational measures that are reasonable and actionable to protect the information we collect in connection with our services. We have introduced safeguards that meet industry standards to protect the personal information provided by you from unauthorized access, disclosure, use, or alteration, or from damage or loss. We take all reasonable and actionable measures to protect your personal information. For example:
- (1) We use mainstream security means such as SSL to encrypt many of our services. We regularly review our practices regarding information collection, storage, and processing (including physical security measures) to protect our systems from unauthorized access or alteration.
- (2) We strictly control access to personal information and only grant access permissions to our employees and those of an authorized service provider who need access to personal information in order to help us process such information. These employees are subject to strict contractual confidentiality obligations. If they fail to perform these obligations, they may be held legally liable or be terminated. Personal information access logs will be kept and audited periodically.
- (3) The security of your information is very important to us. Therefore, we will continue our efforts to protect the security of your personal information and implement safeguards such as encrypting stored data and using end-to-end encryption during transmission to protect your information from unauthorized access, use, or disclosure. In addition, certain encrypted data is inaccessible to anyone other than the user.
- (4) When transmitting and storing your personal information of special types, we will use security measures such as encryption. When storing your personal biometric information, we will take technical measures to process it, such as only storing a summary of your personal biometric information.
- (5) We carefully select business partners and service providers and include our requirements for personal information protection in our business contracts, audits, or assessments.
- (6) We conduct security and privacy protection training, tests, and publicity activities to raise our employees' awareness of the importance of personal information protection.
- (7) We use international and industry-recognized standards to protect your personal information and actively acquire security and privacy protection certifications.
4.2 Notification and Response to Personal Information Security Events
Please note that although we take reasonable measures to protect your information, no websites, internet transfers, computer systems, or Wi-Fi connections are 100 percent secure. In the event of any security breach of your personal information, we will promptly inform you of the event in accordance with applicable laws and regulations, including the situation and the possible impact of the event, the measures taken or to be taken by us, suggestions on how you can prevent and reduce risks, and remedies available to you. We will promptly inform you of such information by email, letter, phone, or push notification. When it is difficult to inform each personal information subject concerned, we will publish an announcement in a reasonable and effective manner. We will also report the handling of the event in accordance with the requirements of regulatory authorities.
5. Your Rights to Your Personal Information
We respect your rights to your personal information. The following lists your rights under the law and explains how we will protect your rights.
5.1 Right to Be Informed
We inform you of how we process your personal information by publishing this Privacy Notice and, where required by laws and regulations, by posting a notice or contacting you by SMS or email. We are committed to staying transparent about how we use your personal information. You can regularly check this Privacy Notice, receive emails and SMS messages which contain a description of the updates to this Privacy Notice, and contact us in the manner disclosed in this Privacy Notice to learn about our collection and use of your personal information.
5.2 Right of Access
In the products or services integrating the HeyTap Account SDK, you may sign in to your HeyTap Account at any time and go to the relevant user interfaces to directly query or access your HeyTap Account information (if any). For details, please refer to the privacy notices separately developed for these products or services.
You may also go to id.heytap.com to view information relating to your account.
If you are unable to query or access your personal information on your own, or if you encounter any problems while exercising your right to access data, you can request access by contacting us in the manner disclosed in this Privacy Notice.
5.3 Right to Rectification
In the products or services integrating the HeyTap Account SDK, you may go to the relevant user interfaces to correct your HeyTap Account information (if any). For details on the account information available for your modification, please refer to the privacy notices separately developed for these products or services.
You may also go to id.heytap.com to correct information relating to your account.
For personal information that has not been made available for your modification, you can contact us in the manner disclosed in this Privacy Notice to have such personal information corrected or completed.
5.4 Right to Erasure
In the products or services integrating the HeyTap Account SDK, you may go to the relevant user interfaces to delete your HeyTap Account information (if any). For details on the account information available for your deletion, please refer to the privacy notices separately developed for these products or services.
For personal information that has not been made available for your deletion or personal information that you believe to have been collected or used in violation of the agreement between you and us, you can contact us in the manner disclosed in this Privacy Notice to have such personal information deleted.
5.5 Right to Delete Your Account
- (1) Please refer to the privacy notices separately developed for the products or services integrating the HeyTap Account SDK to see whether these products or services provide an option for account deletion.
- (2) You may also go to https://id.heytap.com/profile.html. After signing in to your HeyTap Account, you can select "Personal Data Management", tap "Delete Account", and then submit an account deletion request following the prompted steps.
We grant you the right to delete your HeyTap Account.
After you submit an account deletion request, we may need to manually review your request in order to make sure that you satisfy the conditions for deleting your account. We will assist you with the deletion of your account within 15 workdays after you submit your request. After your request is approved, we will delete or anonymize all your relevant personal information, unless otherwise specified by laws and regulations. After your account is deleted, we will no longer be able to provide you with products or services that are only accessible with a HeyTap Account.
5.6 Right to Withdraw Consent
The performance of each service function requires certain basic personal information (see the "How We Collect and Use Your Personal Information" section of this Privacy Notice). You can change the scope of the personal information you authorize us to collect or withdraw your authorization by deleting information, turning off app permissions, changing settings on the product or feature settings page, or deleting your account. Specifically:
- (1) You may go to the Settings app on your phone to turn off relevant app permissions so as to withdraw your consent to our use of these permissions and our collection of your personal information based on these permissions.
- (2) The advertising messages or marketing notifications we send to you contain information on how to unsubscribe. You may unsubscribe in the manner as described therein.
If you withdraw your consent, we will no longer be able to provide you with the related services. We will also no longer process related personal information, but the withdrawal of your consent shall not affect the lawfulness of data processing based on consent before its withdrawal.
5.7 Right to Complain
You have the right to file complaints by contacting us in the manner disclosed in this Privacy Notice. We will respond within 15 workdays from the date we receive your complaint. If you are not satisfied with our reply, particularly if our processing of your personal information damages your legitimate rights and interests, you can also file a complaint or report it to regulatory authorities such as the Cyberspace Administration of China, a relevant public security organ, and the State Administration for Market Regulation, or file a lawsuit with the court with jurisdiction.
Please note that for security reasons, we may verify your identity before handling your request. In general, we do not charge a fee for handling your reasonable requests. For repeated requests beyond a reasonable limit, however, we may charge a fee to cover the costs of handling such requests depending on the actual situation. We may reject unreasonably repeated requests, requests that require excessive technical means (such as developing a new system or fundamentally changing existing practices), requests that present risks to the legitimate rights and interests of others, or very unrealistic requests. If we do so, we will state the reason in our reply. In addition, we may not respond to your request if it directly involves any issues that directly concern public interests such as national security, national defense, public health, and criminal investigations, or if it may result in serious damage to the legitimate rights and interests of you or any other individual or organization.
6. How We Process Children's Personal Information
We attach great importance to the protection of children's personal information. If you are a child (a minor under the age of 14), you and your parent or guardian together must carefully read this Privacy Notice and the HeyTap Privacy Notice for Children before you use our services. In addition, you must obtain their consent before using our products or services or providing information to us. For child protection purposes, child users may only use child accounts. Parents or guardians shall create a child account for their child to use our products or services.
7. How Your Personal Information Is Transferred Globally
If you are located in the Chinese mainland, your personal information will be stored on our server deployed in the Chinese mainland.
8. How This Privacy Notice Is Updated
We reserve the right to update or modify this Privacy Notice from time to time. We will send you update notices through different channels. If you have provided us with your email address, we will notify you of any material changes to this Privacy Notice by email prior to the entry into force of such changes. We will also push a notification to you through your device.
This Privacy Notice is subject to adjustments, but without your express consent, we will not diminish your rights under this Privacy Notice.
If you do not agree to this Privacy Notice, we will not be able to collect and use the information necessary to provide you with the services you request.
This Privacy Notice shall enter into force as of the date it is updated.
If you have any questions or concerns about this Privacy Notice or our processing of personal information, you may contact our Data Protection Officer through our Data Subject Rights Platform to exercise your right to privacy. We will respond to your request within the time limit specified by laws and regulations. Data Subject Rights Platform: https://brand.heytap.com/privacy-feedback.html.
If you have any complaints, you may contact us by email at Privacy@heytap.com.