Controller: Raywise Technologies Co., Limited, a company incorporated in Hong Kong, with its registered office at Room 12, 3/F, Yau Lee Centre, 45 Hoi Yuen Road, Kwun Tong, Hong Kong. We can be reached at support@ruiyusmart.com for general privacy matters and at liujunchuan@ruiyusmart.com for key-account and data-protection matters.
1. Introduction & Scope
This Privacy Policy explains how Raywise Technologies Co., Limited ("Raywise", "we", "us") collects, uses, discloses, and protects personal data in connection with:
- the website at ruiyusmart.com (the "Website");
- the mobile management applications published by Raywise on Google Play and the Apple App Store (the "Apps"), covering the nine business lines set out in section 8.3 of the Terms of Service — Smart Control Systems, Industrial Automation Products, IoT Device R&D & Technical Services, Software Development, Automation Equipment Sales, Electronic Components Sales, Technology Transfer & Consulting, Business Information Consulting, and Import & Export of Goods and Technology; and
- the related services described on the Services page (collectively, the "Services").
This Privacy Policy applies to all of the above. It does not apply to third-party websites, services, or applications that we do not own or control — including the Apple App Store and Google Play, which are operated by Apple Inc. and Google LLC respectively. Please review their own policies.
2. Definitions
- Personal Data — any information that identifies, or can reasonably be used to identify, a natural person.
- Processing — any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
- Controller — the entity that determines the purposes and means of Processing (in our case, Raywise).
- Processor — an entity that Processes Personal Data on behalf of the Controller.
- Service — the Website, the Apps, and the related business offerings.
- App — any of the mobile management applications published by Raywise on Google Play or the Apple App Store.
- SDK — a Software Development Kit, a third-party library linked into the App.
- End User — a natural person who installs or uses an App, or who otherwise interacts with the Services.
- Device — the smartphone, tablet, or other hardware on which an App is installed.
- Advertising ID — a device-level identifier used for advertising personalisation: the Google Advertising ID ("GAID") on Android, and the Identifier for Advertisers ("IDFA") on iOS.
- IP Address — the public network address assigned to a Device by its network provider.
- Cookie — a small text file placed on a Device by a website.
- Sensitive Data — Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data, health data, sex life or sexual orientation, or similar categories defined by applicable law.
- Child — a person under 13 (US COPPA), under 16 (EU GDPR Art. 8 / UK AADC), or under the age defined as a minor by the law of their habitual residence.
- Sale / Share / Targeted Advertising — the terms used in the California CCPA/CPRA to describe (a) the exchange of Personal Data for monetary or other valuable consideration, (b) the sharing of Personal Data for cross-context behavioural advertising, and (c) advertising selected on the basis of Personal Data collected across services.
3. Information We Collect
3.1 Information you provide directly
When you contact us through the Website, write to support@ruiyusmart.com, or write to liujunchuan@ruiyusmart.com, we collect the information you choose to give us — typically your name, work email, company, phone number, postal address, and the contents of your message. We use this information only to respond to your enquiry and to keep a record of our correspondence.
3.2 Information collected automatically when you visit the Website
The public Website itself does not load advertising tags, analytics tags, or third-party cookies. Our web server nevertheless records a minimum set of log data for security and operational purposes: your IP address, user agent string, referring URL, the pages you view, the approximate country derived from your IP address, and the timestamps of your requests. This log data is retained for 12 months and is then either deleted or aggregated.
3.3 Information collected automatically when you use our Apps
When you install and use an App, we (and the third-party SDKs listed in section 6) collect:
- Device model, manufacturer, and form factor;
- Operating system and version (e.g. iOS 17, Android 14);
- App version and build number;
- Language, locale, and time zone;
- A per-install random identifier (a UUID generated by us, not tied to your name);
- Advertising IDs (GAID on Android, IDFA on iOS), subject to your consent and the operating-system opt-out controls;
- Session timestamps, in-app actions, screen views, and feature usage;
- Crash logs, diagnostic data, and performance metrics;
- Network type (Wi-Fi, cellular, none) and carrier;
- IP address and a coarse location derived from it (country and city);
- Screen size, free storage, free memory, and battery level.
3.4 Information collected by third-party SDKs in our Apps
The third-party SDKs that load inside our Apps — ad networks, mediation layers, attribution providers — collect their own data as described in section 6. The list there is the authoritative reference; the data above is what is common across all of them.
3.5 Information collected by the App Stores
Apple and Google independently collect download, install, crash, in-app purchase, and account telemetry. They are separate controllers for that data. Their respective policies apply: Apple Privacy Policy and Google Privacy Policy.
3.6 Information we do NOT collect
We do not collect government-issued ID numbers, payment card numbers, biometric data, health data, contacts lists, photos, microphone audio, or precise (GPS) location. If a future feature ever needs any of these, we will update this Policy and obtain the consent required by law before collecting it.
4. How We Use Your Information (Purposes & Lawful Bases)
For each purpose below, the lawful basis we rely on (where applicable) is indicated. In the EU/UK we rely on Article 6 of the GDPR / UK GDPR. In the US we rely on the CCPA/CPRA "business purpose". In China we rely on Article 13 of the PIPL. In Brazil we rely on Article 7 of the LGPD. In Canada we rely on Principle 4 of PIPEDA. In Australia we rely on APPs 3 and 5. In Singapore we rely on Part 4 of the PDPA.
4.1 To provide and operate the Services
Contract necessity. We process the information you give us so that we can answer your enquiry, fulfil your order, or operate the feature you are using.
4.2 To respond to your enquiries
Contract necessity (the enquiry is itself the contract) and legitimate interest (GDPR Art. 6(1)(f); UK GDPR; PIPL Art. 13(1)(vi); LGPD Art. 7(IX)).
4.3 To maintain and improve the Services
Legitimate interest in the EU/UK, "business purpose" in the US, legitimate interest under PIPL Art. 13(1)(vi) and LGPD Art. 7(IX), compliance with the APPs in Australia, and compliance with the PDPA in Singapore.
4.4 To show advertisements in our Apps
Consent in the EU/UK, China, Brazil, Australia, and Singapore. Opt-out (CCPA/CPRA "Do Not Sell or Share") in the United States. The App's first-launch consent dialog lists every ad SDK that loads, and no SDK initialises until the user has made a choice. (Apple App Store Review Guideline 5.1.1(iv); Google Play User Data Policy.)
4.5 To measure ad performance
Consent in the EU/UK, China, Brazil, Australia, and Singapore. Business purpose in the US. Sub-service providers (mediation layers, mobile measurement partners) are listed in section 6.
4.6 To detect fraud, abuse, and security incidents
Legitimate interest in all regions; legal obligation where required by sectoral regulation (e.g. telecommunications).
4.7 To comply with law, enforce our Terms, and respond to legal process
Legal obligation, vital interest, or public interest (GDPR Art. 6(1)(c) and (d); UK GDPR; equivalent provisions in other regional laws).
4.8 With your consent — for any other purpose
For any purpose not listed above, we will obtain your consent at the point of collection. You can withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
5. Cookies, SDKs, and Similar Technologies
5.1 Cookies on the Website
The Website uses strictly necessary cookies only. There are no marketing, analytics, or third-party cookies, and there are no ad tags, pixels, or trackers loaded by the public site.
5.2 Local storage in the Apps
The Apps use platform-provided local storage (NSUserDefaults on iOS, SharedPreferences / DataStore on Android) to remember your preferences, your most recent screens, and your consent choices. No remote code loads into the Apps.
5.3 Software Development Kits (SDKs) in the Apps
See section 6 for the full list. Each SDK is governed by its own terms and privacy policy; using an App is treated as accepting those terms in addition to this Policy.
5.4 Mobile Identifiers
GAID (Android) and IDFA (iOS) are device-level identifiers used by ad networks to deliver and measure interest-based advertising. You can reset your Advertising ID at any time: on Android, Settings → Google → Ads → Reset advertising ID; on iOS, Settings → Privacy → Tracking → toggle off "Allow Apps to Request to Track". Opting out does not stop ads from appearing; it stops them from being personalised.
6. Advertising & Ad Networks (Apps)
The Apps monetise through advertising. The 21 ad platforms listed below are the platforms that may load in any given App, depending on the App's category, the user's region, and the mediation auction outcome. The Apps integrate a real-time mediation layer (typically AppLovin MAX, Unity LevelPlay, Appodeal, or BidMachine) that runs an auction across multiple demand sources; the user is not directly tracked by every network, but the networks may receive a bid request when an ad slot is being filled.
Each row below tells you what the SDK does in our Apps, the data it collects, the lawful basis we rely on, and how to manage your preferences.
| # | Platform | Behaviour | Data collected | Lawful basis | Opt-out / Privacy |
|---|---|---|---|---|---|
| 1 | Google AdMob | Banner, interstitial, rewarded video, native; ad serving & basic measurement. | GAID, IDFA, IP, device info, app session, coarse location, ad interaction events. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | adssettings.google.com · policies.google.com/privacy |
| 2 | Google Ad Manager (GAM) | Header bidding / direct-sold ad serving. | GAID, IDFA, IP, user agent, cookie-equivalent identifiers, ad events. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | adssettings.google.com · policies.google.com/privacy |
| 3 | Meta Audience Network | Banner, interstitial, rewarded video; uses Meta login state if available. | GAID, IDFA, IP, device info, coarse location, ad events, Meta cookies if logged in. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | facebook.com/adpreferences · facebook.com/privacy/policy |
| 4 | Unity Ads | Banner, interstitial, rewarded video, playable ads. | GAID, IDFA, IP, device info, coarse location, session events. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | unity.com/privacy |
| 5 | AppLovin MAX | Mediation layer + direct ads; banner, interstitial, rewarded, native. | GAID, IDFA, IP, device info, app session, ad events, attribution events. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | applovin.com/privacy |
| 6 | ironSource / Unity LevelPlay | Mediation + direct; banner, interstitial, rewarded, offerwall. | GAID, IDFA, IP, device info, install events, ad events. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | is.com/privacy-policy |
| 7 | Pangle (ByteDance) | Banner, interstitial, rewarded, native; strong APAC presence. | GAID, IDFA, IP, device info, app session, coarse location, ad events. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | pangleglobal.com/privacy |
| 8 | Vungle (Liftoff) | Interstitial, rewarded, banner; lightweight SDK. | GAID, IDFA, IP, device info, ad events, session duration. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | liftoff.io/privacy-policy |
| 9 | Chartboost (Inmar / Vespa Media) | Interstitial, rewarded, banner, direct deals. | GAID, IDFA, IP, device info, session, ad events. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | chartboost.com/privacy |
| 10 | InMobi | Banner, interstitial, rewarded, native; APAC focus. | GAID, IDFA, IP, device info, coarse location, ad events. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | inmobi.com/privacy-policy |
| 11 | Tapjoy | Offerwall, rewarded video. | GAID, IDFA, IP, device info, reward events, in-app currency events. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | tapjoy.com/privacy-policy |
| 12 | Mintegral (Mobvista) | Banner, interstitial, rewarded, native; strong APAC / LATAM presence. | GAID, IDFA, IP, device info, coarse location, ad events. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | mintegral.com/privacy-policy |
| 13 | Digital Turbine / AdColony | Interstitial, rewarded; merged stack. | GAID, IDFA, IP, device info, ad events, session. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | digitalturbine.com/privacy-policy |
| 14 | Liftoff / Viant | Interstitial, rewarded, CTV, programmatic direct. | GAID, IDFA, IP, device info, session, ad events. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | liftoff.io/privacy-policy |
| 15 | Moloco | Programmatic bidding, banner, interstitial, rewarded, native. | GAID, IDFA, IP, device info, ad events. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | moloco.com/privacy-policy |
| 16 | Yahoo / Verizon Media | Native, banner, video; legacy Verizon Media SDKs. | GAID, IDFA, IP, device info, ad events, audience segments. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | legal.yahoo.com/privacy |
| 17 | Smaato | Header bidding, real-time programmatic, banner, interstitial, video. | GAID, IDFA, IP, device info, ad events. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | smaato.com/privacy |
| 18 | Start.io (Startapp) | Banner, interstitial, rewarded, native; SDK. | GAID, IDFA, IP, device info, app session, ad events. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | start.io/privacy-policy |
| 19 | Appodeal | Mediation layer (aggregator); banner, interstitial, rewarded, native. | GAID, IDFA, IP, device info, ad events, bid requests. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | appodeal.com/privacy-policy |
| 20 | BidMachine | Header bidding, mediation, banner, interstitial, rewarded, native. | GAID, IDFA, IP, device info, ad events. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | bidmachine.io/privacy-policy |
| 21 | AdColony (Digital Turbine) | Interstitial, rewarded video; legacy name retained for SDK compatibility. | GAID, IDFA, IP, device info, ad events, session. | Consent (EU/UK/CN/BR/AU/SG); opt-out (US). | digitalturbine.com/privacy-policy |
6.1 Mediation
The Apps use a mediation layer (typically AppLovin MAX, ironSource / Unity LevelPlay, Appodeal, or BidMachine) that runs a real-time auction across the ad networks above. The mediation SDK is the auctioneer; the winning network serves the ad. The user is not directly tracked by every network, but the networks may receive a bid request when an ad slot is being filled. Bid requests include your Advertising ID, IP, and a coarse location, even if you have opted out of personalised ads — this is the standard "non-personalised bid" flow.
6.2 Frequency capping, session resets, per-user limits
The Apps apply frequency caps on a per-user basis. A typical interstitial cap is one ad per 60–120 seconds; a typical rewarded-video cap is five per session. Caps are stored in the SDK and are reset on app reinstall.
6.3 EU/UK consent flow
The Apps display a Consent Management Platform (CMP) at first launch that gates any non-essential SDK. The CMP is integrated with the IAB Transparency and Consent Framework (TCF) v2.2, and produces a TC string that all consent-gated ad SDKs read on initialisation. The user can revisit their choices at any time through the in-app "Privacy choices" menu. (ePrivacy Directive 2002/58/EC; EDPB Guidelines 05/2020 on consent.)
6.4 China (PIPL) consent flow
The Apps are not currently distributed in mainland China. If we change that, we will add a separate, affirmative, granular consent for each ad SDK, and any SDK that does not have a PIPL-ready consent pipeline will be geo-fenced out.
6.5 California (CCPA/CPRA) "Do Not Sell or Share" link
The App's Settings menu surfaces a "Do Not Sell or Share My Personal Information" toggle. When enabled, the App sets the IAB US Privacy String to 1YYN and forwards it to all consent-gated ad SDKs. The opt-out is honoured for at least 12 months and re-prompted after.
6.6 Privacy-preserving APIs (iOS / Android)
On iOS, every SDK that reads IDFA is gated by the App Tracking Transparency (ATT) prompt. We use Apple's SKAdNetwork for conversion attribution where possible, and Privacy Manifests for every SDK that has a "Required Reason" API entry. (Apple App Store Review Guideline 5.1.1(i).)
On Android, the SDKs honour RESET_AD_ID and the Google Play Services Ads Preference controls. We use Google's Privacy Sandbox on Android (Topics, Attribution Reporting) for forward compatibility. (Google Play Developer Program Policy — User Data.)
7. Ad Formats
Apps integrate four ad formats. Each format is described below with the data it triggers, its consent model, and the design rules that prevent bad UX.
7.1 Open-screen / Splash ads
Full-screen ad shown during App cold-start, before the first interactive screen. Typically 3–8 seconds, with a "skip" button after 5 seconds. Data triggered: Advertising ID, app session ID, timestamp, app package name, IP, and (for floor pricing, not targeting) coarse location. Consent: the splash slot is requested only after the CMP/ATT gate; if the user opts out, no SDK initialises and no splash is shown. Frequency: one splash per cold-start; one per session warm-up. Failure mode: if no ad is available, the splash is skipped; no fallback ad is requested from another network within the same splash slot.
7.2 Rewarded video ads
Full-screen video, opt-in only. The user taps a clearly labelled "Watch ad" button, watches the full video, and receives an in-app reward (e.g. extra lives, a discount code, a temporary premium feature). The button must be accompanied by a one-line description of the reward. The reward is granted server-side to prevent client-side cheating. The ad does not auto-play. The ad is not shown to known-child traffic (COPPA). (COPPA Rule; Apple Guidelines 1.4.3; Google Play Ads Policy.) Data triggered: Advertising ID, app session ID, impression event, completion event (started / completed / skipped), reward event.
7.3 Interstitial ads
Full-screen ad shown at a natural break in the App flow (between levels, after a save, before a content page). 5–15 seconds; some are skippable after 5. The slot is not triggered on the first screen, not stacked back-to-back, and not triggered mid-task. Frequency cap: 1 interstitial per 60–120 seconds. Data triggered: Advertising ID, session ID, ad impression, click event, install / conversion event (post-tap).
7.4 Banner ads
Small rectangular ad embedded in a defined slot at the top or bottom of a screen; auto-refreshes every 30–60 seconds. The slot is clearly differentiated from the App's native UI, does not overlap navigation, and is removable by the user. A "Remove Ads" upgrade may be offered (where the App is free with ads). Data triggered: Advertising ID, session ID, ad impression, click event, viewability event (IAB / MRC standard).
8. How We Share Your Information
We do not sell Personal Data for money. The categories of recipients are:
- Service providers / processors — hosting, email, and (if we ever add them) analytics providers, all bound by data-processing agreements.
- Ad networks and mediation partners — the 21 platforms listed in section 6.
- App Stores — Apple and Google act as independent controllers for download and install telemetry.
- Professional advisers — lawyers, accountants, auditors under NDA.
- Law enforcement, courts, regulators — only on valid legal process, and only the minimum necessary.
- Corporate transactions — merger, acquisition, asset sale, with notice to users.
- With your consent — for any other purpose disclosed at the time of consent.
Some US state laws (notably the CCPA/CPRA) still treat "sharing for cross-context behavioural advertising" as a "sale". California residents (and residents of substantially similar US states) can opt out — see section 15.
9. International Data Transfers
Raywise is seated in Hong Kong. Data we collect in the EEA, the UK, Switzerland, the United States, Canada, Brazil, Australia, Singapore, and elsewhere may be transferred to and processed in Hong Kong, the United States (where many ad networks and their sub-processors are located), Singapore, and other jurisdictions where our service providers operate.
9.1 EEA / UK / Switzerland to Hong Kong
We rely on the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the UK International Data Transfer Addendum for transfers from the EEA/UK, and on the Swiss FDPIC's standard contractual clauses for Switzerland. (GDPR Ch. V; UK GDPR; Swiss FADP.)
9.2 Hong Kong to ad network jurisdictions
Many ad networks are US-based or use global sub-processors. The SCCs in section 9.1 cover EEA→US onward transfers, and our data-processing agreements require onward processors to provide equivalent protection.
9.3 Other regions
For transfers from the United States, Canada, Brazil, Australia, and Singapore, we rely on contractual safeguards, consent, or the equivalent regional mechanism. Where local law requires an adequacy mechanism, we use one.
9.4 Data localisation in China (PIPL)
The Apps are not currently distributed in mainland China. If we ever change that, we will add a PIPL data-localisation statement here, and we will obtain the cross-border transfer approval required by PIPL Arts. 38–39.
9.5 Government access requests
We do not voluntarily disclose Personal Data to government authorities. Where we receive a binding legal request, we will challenge it where possible, narrow it where we cannot, and notify the affected user where we are permitted to do so.
10. Data Retention
We retain Personal Data for as long as needed to provide the Services and to comply with our legal obligations. Specifically:
- Contact-form and email enquiries — 24 months from the last contact.
- Server logs (Website) — 12 months, then aggregated or deleted.
- App usage logs and ad-impression logs — 13 months (the industry default for ad attribution).
- Crash reports — 24 months, then aggregated or deleted.
- Support tickets — 36 months.
- Backups — 90-day rolling retention, then overwritten.
Data is deleted when the purpose for which it was collected ends, when consent is withdrawn (and we have no overriding legitimate ground), or when the user objects and we have no overriding legitimate ground.
11. Your Rights & Choices
11.1 EEA / UK / Switzerland — GDPR rights
You have the right to access, rectify, erase, restrict, port, and object to the processing of your Personal Data, and the right to lodge a complaint with your national supervisory authority. We respond to such requests within 30 days. (GDPR Arts. 15–22; UK GDPR; Swiss FADP.)
11.2 California — CCPA / CPRA rights
You have the right to know what categories of Personal Information are collected, the right to delete Personal Information, the right to correct inaccurate Personal Information, the right to opt out of the sale or sharing of Personal Information (including sharing for cross-context behavioural advertising), the right to limit the use of sensitive Personal Information, and the right to non-discrimination. We do not sell Personal Information for money. We respond to verifiable consumer requests within 45 days, extendable by an additional 45 days. (CCPA §§1798.100–1798.199.100.)
11.3 Other US states
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Delaware (DPDPA), Iowa (ICDPA), Tennessee (TIPA), Indiana (INCDPA), Minnesota (MCDPA), New Hampshire (NHPA), New Jersey (NJPDPA), Maryland (MODPA), and Rhode Island (RIDPA) have substantially similar rights: access, delete, correct, portability, and opt-out of targeted advertising / sale / profiling. We respond to verifiable requests within 30–45 days, depending on the state.
11.4 China — PIPL rights
You have the right to know, to access, to correct, to delete, to withdraw consent, to obtain an explanation of automated decision-making, and to lodge a complaint with the relevant authority. We respond within 30 days. (PIPL Arts. 44–50.)
11.5 Brazil — LGPD rights
You have the right to confirmation of the existence of processing, access, correction, anonymisation, portability, deletion, information about sharing, information about the possibility of denying consent and the consequences, and withdrawal of consent. We respond within 15 days. (LGPD Art. 18.)
11.6 Canada — PIPEDA / Quebec Law 25
You have the right to access and correct your Personal Information, to withdraw consent, and to lodge a complaint with the Office of the Privacy Commissioner of Canada (federal) or the Commission d'accès à l'information (Quebec). We respond within 30 days. (PIPEDA s.8; Quebec Law 25.)
11.7 Australia — Privacy Act 1988 (Cth)
You have the right to be informed about the collection of Personal Information (APP 5), to access your Personal Information (APP 12), to correct your Personal Information (APP 13), and to complain to the Office of the Australian Information Commissioner (OAIC). We respond within 30 days. (Privacy Act 1988 (Cth); APPs 3, 5, 12, 13.)
11.8 Singapore — PDPA
You have the right to be informed of the purpose of collection (Consent Obligation, s.13), the right to access and correct your Personal Data (ss.21–22), the right to withdraw consent, and the right to opt out of receiving telemarketing messages via the Do Not Call (DNC) registry. We do not engage in telemarketing. We respond within 30 days. (PDPA Part IV.)
11.9 How to exercise any of the above
Email support@ruiyusmart.com with the subject line "Privacy Request". Tell us which right you wish to exercise and provide enough information to verify your identity. We may need to follow up for additional verification before we can act on your request.
12. Children's Privacy
The Services are not directed to children. We do not knowingly collect Personal Data from children under 13 (US COPPA), under 16 (EU GDPR Art. 8 / UK AADC), or under any other age defined by applicable local law. If a parent or guardian notifies us that their child has used the Services and provided Personal Data, we will delete that data within 30 days. The Apps do not serve interest-based advertising to known-child traffic. (COPPA 16 C.F.R. Part 312; GDPR Art. 8; ICO Age-Appropriate Design Code; Data Protection Act 2018 s.123.)
12.1 COPPA (US)
We do not knowingly collect Personal Information from children under 13. Our Apps are not directed to children, and our Apps do not serve interest-based advertising to known-child traffic. Parents can contact us at support@ruiyusmart.com to request deletion.
12.2 GDPR-K (EU)
Article 8 of the GDPR provides that, where information society services are offered directly to a child, the processing of Personal Data is lawful only if the child is at least 16 (member states may lower to 13). Our Apps are not directed to children. If we learn that we have inadvertently collected Personal Data from a child below the applicable national age, we will delete that data within 30 days.
12.3 UK AADC
The Information Commissioner's Office Age-Appropriate Design Code applies to online services likely to be accessed by children in the UK. Our Apps are not designed for children; however, our consumer-facing Apps may be used on family devices, and we apply the AADC standards where the ICO's "likely to be accessed" test is triggered: best interests of the child, age-appropriate language, transparent information, no detrimental use of data, no profiling by default, geolocation off by default, no nudge techniques aimed at extending session time, parental controls visible, no dark patterns, and a Data Protection Impact Assessment on file.
13. Security
We use administrative, technical, and physical safeguards designed to protect Personal Data against unauthorised access, use, disclosure, alteration, or destruction.
13.1 Technical measures
TLS 1.2+ in transit; AES-256 at rest; hashing and salting for credentials; signed App builds; certificate pinning in the Apps for our own endpoints.
13.2 Organisational measures
Least-privilege access; NDA-bound personnel; role-based access; vendor due-diligence before engaging a new processor.
13.3 No security is absolute
No system is perfectly secure. If we become aware of a security incident affecting your Personal Data, we will notify you and the applicable regulators as required by law.
14. International Users (Residence-Specific Disclosures)
14.1 EEA / UK (GDPR)
For users in the European Economic Area and the United Kingdom, the lawful basis for processing Personal Data is set out in Article 6 of the GDPR / UK GDPR. Where processing is based on consent (Art. 6(1)(a)), the consent is freely given, specific, informed, and unambiguous; it is collected through a Consent Management Platform integrated with the IAB Transparency and Consent Framework (TCF) v2.2. International transfers from the EEA/UK to Hong Kong (our seat) are governed by the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the UK International Data Transfer Addendum. We do not currently appoint an Article 27 EU representative because we do not target EU/UK users; if that changes, this section will be updated.
14.2 California (CCPA / CPRA)
For users in California, the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA), applies. Categories of Personal Information collected in the last 12 months: identifiers (GAID/IDFA, IP), commercial information (ad interactions), internet activity (in-app actions), geolocation (coarse, country/city), inferences (ad-personalisation segments). Categories of sensitive Personal Information collected: none. "Shine the Light" (Cal. Civ. Code §1798.83) — we do not disclose Personal Information to third parties for their direct marketing purposes.
14.3 China (PIPL)
For users in the People's Republic of China, the Personal Information Protection Law (PIPL), in force since 1 November 2021, applies. Cross-border transfer of Personal Information out of mainland China is subject to additional requirements: a security assessment by the Cyberspace Administration of China, standard contractual clauses filed with the provincial CAC, or Personal Information protection certification. We do not currently distribute our Apps in mainland China; the Apps are available in Hong Kong, which is not subject to PIPL. Hong Kong has its own Personal Data (Privacy) Ordinance (PDPO), which we comply with.
14.4 Brazil (LGPD)
For users in Brazil, the Lei Geral de Proteção de Dados (LGPD), Law No. 13.709/2018, applies. We appoint a Data Protection Officer ("encarregado") in line with Article 41 of the LGPD; contact via support@ruiyusmart.com. International transfers from Brazil to Hong Kong are governed by standard contractual clauses or other mechanisms recognised by the Autoridade Nacional de Proteção de Dados (ANPD).
14.5 Canada (PIPEDA + Quebec Law 25)
For users in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) applies to commercial activities in all Canadian provinces except those that have adopted substantially similar legislation. Quebec's Law 25 adds explicit consent, data portability, privacy impact assessments for high-risk processing, breach notification to the Commission d'accès à l'information (CAI) and to affected individuals, and a designated person responsible for Personal Information. International transfers from Canada to Hong Kong are governed by contractual safeguards consistent with the OPC's guidance.
14.6 Australia (Privacy Act 1988 (Cth))
For users in Australia, the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) apply. The Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act requires us to notify the OAIC and affected individuals of eligible data breaches that are likely to result in serious harm. International transfers from Australia to Hong Kong are governed by APP 8 (disclosure to overseas recipients) — we take reasonable steps to ensure the recipient handles the Personal Information in a manner consistent with the APPs.
14.7 Singapore (PDPA)
For users in Singapore, the Personal Data Protection Act 2012 (PDPA) applies. The user can complain to the Personal Data Protection Commission (PDPC). International transfers from Singapore to Hong Kong are governed by the Transfer Limitation Obligation (s.26) — we ensure the recipient is bound by legally enforceable obligations that provide comparable protection.
15. "Do Not Sell or Share" / "Limit Use of My Sensitive Personal Information"
California residents (and residents of substantially similar US states) have the right to opt out of the sale or sharing of their Personal Information. We do not sell Personal Information for money; however, "sharing" under the CCPA/CPRA includes sharing for cross-context behavioural advertising — which is the technical mechanism used by the ad networks in section 6.
You can exercise this right in two ways:
- In the App — open the App's Settings, then "Privacy choices", and toggle on "Do Not Sell or Share My Personal Information". The App will set the IAB US Privacy String to
1YYNand forward the opt-out to all consent-gated ad SDKs. - By email — write to support@ruiyusmart.com with the subject line "Do Not Sell or Share". We will honour the request across all of our Services and across all of the ad networks we use.
The opt-out is honoured for at least 12 months and re-prompted after.
16. Changes to This Policy
We will post material changes to this Policy on the Website at least 30 days before they take effect, and (for App users) in the next App launch. Non-material changes will be reflected in the "Last updated" date above. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
17. Contact Us
For any privacy question, complaint, or request, contact us at:
- General privacy matters: support@ruiyusmart.com
- Key-account and data-protection matters: liujunchuan@ruiyusmart.com
- Postal address: Raywise Technologies Co., Limited, Room 12, 3/F, Yau Lee Centre, 45 Hoi Yuen Road, Kwun Tong, Hong Kong
For users in the EEA / UK, we currently do not appoint a local Article 27 representative because we do not target EU/UK users; if that changes, this section will be updated. UK users can complain to the Information Commissioner's Office (ICO) at ico.org.uk; EEA users can complain to their national supervisory authority.
California users can also contact the California Attorney General at oag.ca.gov/privacy. Brazilian users can contact the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd. Australian users can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. Singapore users can contact the Personal Data Protection Commission (PDPC) at pdpc.gov.sg. Canadian users can contact the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca or, in Quebec, the Commission d'accès à l'information (CAI) at cai.gouv.qc.ca.
© 2026 Raywise Technologies Co., Limited. All rights reserved.