YTLock Privacy Policy
Effective Date: April 10, 2026
Shenzhen Jieyitong Biometric Technology Co., Ltd. (hereinafter referred to as "we" or "us") take your privacy seriously. This policy explains how we collect, use, store, and protect your personal information and device data when you use the YTLock IoT service.
1. Information We Collect and How We Use It
We follow the principle of "data minimization" and only collect the following information necessary to provide our IoT smart device services:
1.1 Account Registration Information
- Phone Number (Optional): Used for account verification and password recovery. Declining to provide this information does not affect core device control features.
- Email Address (Optional): Used for receiving account security notifications and password recovery. Declining to provide this information does not affect core device control features.
- WeChat Nickname / Avatar: If you log in via WeChat authorization, we obtain your WeChat nickname and avatar to display your account information within the app.
1.2 Device Connection Information
To establish communication between your phone and smart devices, we collect the following:
- Bluetooth Permissions & Device Identifiers: When using Bluetooth to connect to a device, we require Bluetooth permissions and the device's MAC address / Bluetooth ID to discover nearby smart devices, establish connections, and send control commands.
- Wi-Fi Network Information: When configuring device networking, we obtain the device's Wi-Fi SSID and signal strength to complete network setup. We do not collect your Wi-Fi password in plain text.
- Device Metadata: Including device model, firmware version, and serial number (SN), used for device identification, firmware upgrades, and troubleshooting.
1.3 Sensor Data
Depending on the types of smart devices you bind, we may collect the following sensor data to deliver corresponding features:
- Environmental Sensors: Temperature, humidity, barometric pressure, ambient light, air quality (PM2.5 / CO₂ / VOC), used for environmental monitoring and automated scene triggers.
- Motion Sensors: Passive infrared (PIR) detection, door/window magnetic contact status, used for security alerts and smart automation triggers. We only record "motion detected / no motion" and the trigger timestamp — no images or video are captured.
- Electrical Sensors: Voltage, current, power, and energy consumption, used for energy statistics and electrical safety alerts.
- Water Leak / Smoke / Gas Sensors: Leak detection status and alarm events, used to push real-time safety notifications.
• Important Notice: Sensor data is used solely to deliver device features (such as real-time monitoring, alarm notifications, and scene automation). It is never used for user profiling or advertising.
1.4 Device Operations and Log Data
- Operation Records: Commands you send to devices (on/off, adjustments, schedules) and their timestamps, used for operation history and automation execution.
- Device Runtime Logs: Online/offline events, error alerts, and firmware upgrade status, used to ensure device stability and support after-sales troubleshooting.
- Automation Scene Configurations: Scheduled tasks, linkage rules, and alert thresholds you set, used to execute smart scene logic.
1.5 Push Notifications
To promptly deliver device alerts (such as anomaly alarms and low-battery reminders) and system notifications, we use WeChat template messages or Mini Program subscription messages. You can disable non-essential notifications at any time within the app.
2. Data Storage and Security
2.1 Storage Location and Retention
- Your personal information and device data are stored on cloud servers located within the People's Republic of China.
- Account information is retained for the duration of the account's existence. Device data is deleted or anonymized within 30 days of device unbinding or account deletion.
- Real-time sensor data is retained for 90 days by default and automatically purged upon expiry; alarm event records are retained for 180 days.
2.2 Security Measures
- Communication between devices and the cloud is encrypted via TLS/SSL to prevent interception or tampering during transmission.
- Device control commands undergo mutual authentication and command signature verification to prevent unauthorized operations.
- Account passwords (if applicable) are stored using salted hashing and are never saved in plain text.
- Data access is governed by the principle of least privilege — only authorized personnel may access data when operationally necessary.
3. How We Share, Transfer, and Disclose Your Information
We do not share your personal information or device data with third parties, except in the following circumstances:
- With your explicit authorization (e.g., when you share a device with family members);
- As required by laws, regulations, or administrative/judicial authorities (e.g., complying with law enforcement investigations);
- When necessary to protect public safety (e.g., smoke/gas alarms triggering coordination with fire departments).
In the event of a merger, acquisition, or bankruptcy involving data transfer, we will require the receiving party to remain bound by this privacy policy; otherwise, your consent will be obtained anew.
4. Your Rights
You have the following rights regarding your personal information and device data:
- Access and Export: View your phone number, email, and other account details in the "Profile" section of the app. You may also request an export of your device operation records.
- Correction and Supplementation: Modify account information, device names, and automation scene configurations at any time.
- Data Deletion: Delete individual operation records within the app, unbind a device (which deletes all historical data associated with that device), or request full account data deletion.
- Withdrawal of Consent: Manage permissions via WeChat "Settings" → "Privacy" → "Personal Information and Permissions", or disable Bluetooth and notification permissions within the app.
- Account Deletion: Upon account deletion, all your personal information and device data will be deleted or anonymized within 30 days, except where otherwise required by law.
5. Protection of Minors
If you are under 14 years of age, please use this service under the guidance of a parent or legal guardian. We do not proactively collect personal information from minors. If such collection is identified, the data will be promptly deleted upon verification.
6. Updates to This Policy
We may update this Privacy Policy from time to time. When material changes are made, we will notify you via an in-app pop-up or push notification and update the effective date on this page. Continued use of the service following an update constitutes acceptance of the revised policy.
7. Contact Us
If you have any questions, comments, or suggestions regarding this privacy policy, please contact us through the following channels:
• Company: Shenzhen Jieyitong Biometric Technology Co., Ltd.
• Phone: 13641403391
• Email: jyt2023@163.com