Introduction
This Privacy Policy explains how Snacking Pte. Ltd. (together with its affiliates, HearlingU, we, us, or our) collects, uses, discloses, stores, and protects your personal data when you use the HearlingU smart ring and its companion mobile application, websites, and related services (collectively, the Services).
We are committed to protecting your privacy and handling your personal data in accordance with applicable data protection laws, including the Singapore Personal Data Protection Act 2012 (PDPA), the EU/UK General Data Protection Regulation (GDPR), and the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), where applicable to you.
Please read this Policy carefully before using the Services. By creating an account or using the Services, you acknowledge that you have read and understood this Policy. Because the smart ring collects health and physiological data, which is treated as sensitive/special-category personal data, please pay particular attention to the sections describing that data.
This Policy will help you understand:
- What personal data we collect
- How and why we use your data (and our legal bases)
- Sensitive health data
- How we share and disclose your data
- Third-party SDKs and service providers
- International data transfers
- How long we keep your data
- How we protect your data
- Your privacy rights
- Children's privacy
- Cookies and similar technologies
- Changes to this Policy
- How to contact us
1. What Personal Data We Collect
We collect the following categories of personal data:
(a) Account and profile data
- Third-party sign-in only. You create and access your account exclusively through a supported third-party provider (Apple Sign In or Google Sign-In). We do not offer email/phone/password registration and do not collect or store a password for you. When you sign in, we receive the basic profile information you authorize that provider to share, such as a name, email address, and a provider user identifier. Apple Sign In may allow you to hide your real email via a private relay address.
- Optional profile details you choose to add in the app: nickname, avatar, gender, date of birth, height, weight, used to personalize your health metrics.
(b) Health and physiological data (sensitive) — see Section 4
- Heart rate, resting heart rate, heart rate variability (HRV)
- Blood oxygen saturation (SpO2)
- Sleep data (sleep/wake times, duration, stages)
- Skin/body temperature
- Activity data (steps, distance, calories, active minutes)
- Stress and readiness indicators
- Optional self-logged data, such as menstrual cycle or dreams
(c) Device and connectivity data
- Ring device information: model, serial number/identifier, firmware version, battery level, connection status
- Mobile device information: model, operating system and version, device identifiers, language and region settings, app version
- Bluetooth connection data required to pair and sync with your ring
(d) Usage and log data
- App interactions, features used, session duration
- Log data, crash reports, IP address, timestamps, and diagnostic information
(e) Support and communications data
- Information you provide when you contact customer support, submit feedback, or participate in surveys
We do not knowingly collect data we do not need. Where a field is optional, you may choose not to provide it, though some features may be unavailable as a result.
2. How and Why We Use Your Data (Legal Bases)
We use your personal data for the following purposes. Where GDPR applies, the relevant legal basis is indicated.
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and manage your account; authenticate logins via Apple/Google | Performance of a contract |
| Connect, pair, and sync your ring; deliver firmware updates (OTA) | Performance of a contract |
| Collect and display health metrics, reports, trends, and insights | Your explicit consent (sensitive data) |
| Provide reminders and notifications | Consent / legitimate interests |
| Provide customer support and respond to requests | Performance of a contract / legitimate interests |
| Maintain security, prevent fraud, debug and improve the Services | Legitimate interests |
| Send service or, with your consent, marketing communications | Consent / legitimate interests |
| Comply with legal obligations | Legal obligation |
You may withdraw consent at any time (see Section 10). Withdrawal does not affect processing carried out before withdrawal.
3. Sensitive Health Data
The health and physiological data listed in Section 2(b) is sensitive personal data, also called special category data under GDPR.
- We collect this data only after you connect your ring and give your explicit consent to health monitoring.
- The Services and this data are for general wellness and fitness purposes only. HearlingU is not a medical device and does not provide medical advice, diagnosis, or treatment. The data may contain inaccuracies and must not be relied upon for any medical decision. Always consult a qualified healthcare professional regarding your health.
- You can stop the collection of this data at any time by disabling the relevant feature or disconnecting your ring, and you can delete this data via the app or by contacting us.
4. How We Share and Disclose Your Data
We do not sell your personal data. We share personal data only in the following circumstances:
- Service providers / processors: with vendors who process data on our behalf, such as cloud hosting, push notifications, analytics, crash reporting, and customer support, under contracts requiring them to protect your data and use it only for our instructions. See Section 6.
- With your consent or at your direction: where you ask us to share data, such as exporting to a third-party health platform you connect.
- Legal and safety: where required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of you, us, or others.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this Policy or seek your renewed consent.
5. Third-Party SDKs and Service Providers
Our app may integrate third-party SDKs to provide certain features. These providers process data under their own privacy policies. We assess their security and require compliance with applicable law. The SDKs we may use include (final list to be confirmed by engineering):
| Provider / SDK | Purpose | Data involved | Privacy policy |
|---|---|---|---|
| Cloud hosting (Google Cloud) | Data storage and processing | Account and health data (encrypted) | Google Privacy Policy |
| Analytics (Firebase) | Usage analytics and product improvement | Device info, usage/log data | Google Privacy Policy |
| Push notifications (Firebase Cloud Messaging) | Deliver notifications | Device info, push token | Google Privacy Policy |
| Apple Sign In | Third-party login / authentication | Authorized profile info, provider user identifier | Apple Privacy Policy |
| Google Sign-In | Third-party login / authentication | Authorized profile info, provider user identifier | Google Privacy Policy |
6. International Data Transfers
We are based in Singapore, and your data may be processed in Singapore and in other countries where we or our service providers operate. These countries may have data protection laws different from those in your jurisdiction.
Where we transfer personal data internationally, including from the EEA, UK, or Switzerland, we implement appropriate safeguards required by law, such as the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum, together with additional technical and organizational measures.
7. Data Retention
We retain your personal data only for as long as necessary to provide the Services and for the purposes described in this Policy, unless a longer retention period is required or permitted by law. When you delete your account, we will delete or anonymize your personal data within a reasonable period, except where we are required to retain it, for example to comply with legal, tax, or accounting obligations.
8. How We Protect Your Data
We implement technical and organizational measures appropriate to the risk, including encryption in transit (TLS/SSL), encryption at rest for health data, access controls, and security monitoring. In the event of a personal data breach, we will notify affected users and the relevant supervisory authorities where required by applicable law and within the timeframes it prescribes.
9. Your Privacy Rights
Subject to applicable law, you may have the following rights over your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your data ("right to be forgotten").
- Restriction / Objection — restrict or object to certain processing.
- Portability — receive your data in a structured, machine-readable format, or have it transferred to another provider.
- Withdraw consent — where processing is based on consent, including health monitoring.
- Lodge a complaint — with a supervisory authority.
How to exercise your rights: contact us using the details in Section 14. We may need to verify your identity before responding. We will respond within the timeframe required by applicable law, generally within 30 days under GDPR and within 45 days under CCPA, extendable as permitted. You may authorize an agent to make a request on your behalf.
10. Children's Privacy
The Services are intended for adults (18+) and are not directed to children. We do not knowingly collect personal data from children under the age of 16, or the minimum age required in your jurisdiction. If you believe a child has provided us with personal data without appropriate consent, please contact us and we will delete it.
11. Cookies and Similar Technologies
Our websites and app may use cookies, local storage, and similar technologies to operate the Services, remember your preferences, and analyze usage. You can manage cookies through your browser or device settings; disabling some cookies may affect functionality. Where required, we will request your consent before setting non-essential cookies.
12. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you through the app, by email, or by other appropriate means before the changes take effect. The "Effective" date at the top indicates when this Policy was last updated. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
13. How to Contact Us
If you have any questions, requests, or complaints regarding this Policy or your personal data, please contact us:
- Contact (Data Protection & Support): contact@hearlingu.co
HearlingU