Effective Date: April 30, 2018
If you have questions regarding this U.S. Privacy Notice, please contact us at:
Privacy Office SmartThings, Inc. 665 Clyde Avenue Mountain View, California 94043
Or via email at: firstname.lastname@example.org Or via phone at: 1-800-726-7864
What information does SmartThings collect?
Information You Provide To Us
If you have provided us with a means of contacting you, we may use such means to communicate with you. For example, we may send you updates about our services, informational updates, surveys or promotional offers (either on our own behalf, or on behalf of other businesses), or communicate with you about your use of the Services. Also, we may receive a confirmation when you open a at the bottom of the email you received. Please note that you may not be able to opt out of certain message from us. This confirmation helps us make our communications with you more interesting and improve our services. If at any time you decide you do not want to receive promotional communications from us, you canplease indicate your preference by clicking 'unsubscribe from this list' or 'update subscription preferences' service-level communications that we deem critical to your use of the Services.
Information Collected Automatically
Whenever you interact with our Services (whether via a mobile application, our IoT plug-in, third party service, SmartApp, browser, or other application, connecting a physical device to our services, connecting a third party service to our services, or otherwise), we automatically receive and record information on our servers, logs and databases from your browser, application, services or device(s). In particular, our Services isare designed to allow you to connect various physical devices (e.g., the SmartThings Hub, and associated SmartThings and third party sensors and other devices) to the Services. While connected to the Services, these devices automatically report information to our servers (including information that you may have provided when setting up or configuring that device), which may include Personal Information. For example, if you connect a temperature sensor to the Services, the temperature information from that sensor will be transmitted to the Services, along with any identifying information that you have chosen to associate with that sensor (e.g., the device name, group name, and location name that you have assigned to the sensor within the Services). The type of information that is collected from each device will vary depending on the device type.
Will SmartThings share any of the personal information it receives?
We share your Personal Information with third parties as described in this section:
Aggregated Personal Information that's no longer personally identifiable. We may anonymize your Personal Information so that you cannot be individually identified, and provide that information to our partners such as Samsung or use that information forin marketing or promotional items (“aggregate information”). We may also provide aggregate information to our partners, who may use such information to understand how often and in what ways people use our Services. However, except as described below, we do not disclose aggregate information to a partner in a manner that would identify you personally, as an individual.
Advertisers: We may allow advertisers and/or merchant partners, including Samsung ("Advertisers") to choose the users who will see their advertisements and/or promotional offers. You agree that we may provide any of theaggregate information we have collected from you in non-personally identifiable form to an Advertiser, in order for that Advertiser to select the appropriate audience for those advertisements and/or offers (“Targeted Advertising”). For example, we might use the fact you are located in San Francisco to show you ads or offers for San Francisco businesses, but we will not tell such businesses who you are. In addition to the foregoing, if you have not opted out of our targeted advertising feature as described below, you agree that we may share your personally identifiable information with Advertisers in order to deliver specific targeted advertising or offers to you ("Targeted Advertising"). For example, we might share with our Advertisers the fact that a moisture sensor that you have connected to our Services has detected a flood in order to show you ads or offers for local plumbing services. If we enable Targeted Advertising for our users by default, you will be able to opt out of Targeted Advertising at any time by changing your personal settings.
We may deliver a file to you through the Services (known as a "web beacon") from an ad network. Web beacons allow ad networks to provide anonymized, aggregated auditing, research and reporting for us and for advertisers. Web beacons also enable ad networks to serve targeted advertisements to you when you visit other websites. Because your web browser must request these advertisements and web beacons from the ad network's servers, these companies can view, edit, or set their own cookies, just as if you had requested a web page from their site.
To learn about your options regarding cookies and other technologies, as well as how to opt-out of Targeted Advertising, scroll down to - What choices do I have?
Partners, Affiliated Businesses and Third Party Websites We Do Not Control: In certain situations, partners, businesses or third party websites we're affiliated with ("Affiliated Businesses") may sell items or provide services to you through the Services (either alone or jointly with us), including reselling or providing SmartThings devices free of charge, providing third party devices, or delivering unique or custom SmartApps. You can recognize when an Affiliated Business is associated with such a transaction or service based on the presence of their brand or a transaction you are conducting directly with that Affiliated Business. We will share your Personal Information with that Affiliated Business only to the extent that it is related to such transaction or service, and to the extent that you have explicitly accepted incremental terms with that Affiliated Business whereby you acknowledge and authorize us to share your Personal Information. These incremental terms may be presented as part of promotional offers (either on the Affiliated Businesses' site or on SmartThings-branded properties including our commerce site at shop.smartthings.com, or within customized setup steps that appear in the Services. We have no control over the policies and practices of Affiliated Businesses as to privacy or anything else, so if you choose to take part in any transaction or service relating to an Affiliated Business, please review all such business' or websites' policies. If you decide you no longer want to share Personal Information with an Affiliated Business, you may no longer be entitled to receive certain benefits from the Affiliated Business or have access to the Services without establishing a new account or relationship with SmartThings.
User Profiles and Submissions: Certain user profile information, including without limitation a user’s name, location, and any content that such user has uploaded to the Services, may be displayed to other users to facilitate user interaction within the Services or address your request for SmartThings’s Services. Your account privacy settings may allow you to limit the other users who can see the Personal Information in your user profile and/or what information in your user profile is visible to others. Any content you upload to your public user profile, along with any Personal Information or content that you voluntarily disclose online in a manner other users can view (on discussion boards, in messages and chat areas, etc.) becomes publicly available, and can be collected and used by others. Your user name may also be displayed to other users if and when you send messages or comments or upload content through the Services and other users can contact you through messages and comments. Additionally, if you sign into the Services through a third party social networking site or service, your list of "friends" from that site or service may be automatically imported to the Services, and such "friends,"" if they are also registered users of the Services, may be able to access certain non-public information you have entered in your Services user profile. Again, we do not control the policies and practices of any other third party site or service.
Business Transfers: We may choose to buy or sell assets. In these types of transactions, customer information is typically one of the business assets that would be transferred. Also, if we (or our assets) are acquired, or if we go out of business, enter bankruptcy, or go through some other change of control, Personal Information would be one of the assets transferred to or acquired by a third party.
Protection of SmartThings and Others: We reserve the right to access, read, preserve, and disclose any information that we reasonably believe is necessary to comply with law or court order; enforce or apply our conditions of use and other agreements; or protect the rights, property, or safety of SmartThings, our employees, our users, or others. This includes exchanging information with other companies and organizations for fraud protection and credit risk reduction.
Is personal information about me secure?
Your account is protected by a password or a PIN number for your privacy and security. If you access your account via a third party site or service, you may have additional or different sign-on protections via that third party site or service. You must prevent unauthorized access to your account and Personal Information by selecting and protecting your password, PIN number and/or other sign-on mechanism appropriately and limiting access to your computer or device and browser or application by signing off after you have finished accessing your account.
We endeavor to protect the privacy of your account and other Personal Information we hold in our records, but we cannot guarantee complete security. Unauthorized entry or use, hardware or software failure, and other factors, may compromise the security of user information at any time.
What Personal Information can I access?
Through your account and Service settings, you may be able to access, and, in some cases, edit or delete the following information you’ve provided to us, which may include:
- name and password/PIN number
- shipping address
- billing address
- credit card information
- email address
- location, group and device information
- user profile information
- SmartApp information
The information you can view, update, and delete may change as the Services change. If you have any questions about viewing or updating information we have on file about you, please contact us at email@example.com.
Children’s Personal Information
Certain SmartThings products and services are intended for use by children under the age of 13. Through these SmartThings products and services, SmartThings may collect device identifiers (e.g., device model name, serial number, IMEI number, SIM card number and WiFi-MAC address), device settings and logs, and geolocation information from children under the age of 13. SmartThings provides this information to the parent holder of the SmartThings Account associated with the SmartThings device. SmartThings may combine the information collected from children under age 13 with information associated with the parent’s SmartThings app and the parent’s SmartThings Account. SmartThings may share the geolocation information collected from children under age 13 with the parent’s wireless carrier to provide customer service. SmartThings also may share information collected from children under age 13 with its subsidiaries and affiliates and with its service providers.
A parent may review and/or request to have deleted the child’s personal information collected by SmartThings and may refuse to permit its further collection or use. To exercise these choices, please contact us as specified in the How To Contact Us section of this U.S. Privacy Notice.
Your California Privacy Rights
Under California Civil Code Sections 1798.83-1798.84, California residents are entitled to ask us for a notice identifying the categories of Personal Information which we share with our affiliates and/or third parties for marketing purposes, and providing contact information for such affiliates and/or third parties. You may also ask us to refrain from sharing your personal information with third parties for their marketing purposes If you are a California resident and would like a copy of this notice or wish to make a request that we refrain from sharing your information with third parties for their marketing purposes, please submit a written request to:
SmartThings, Inc. 665 Clyde Ave, Mountain View, CA 94043
What choices do I have?
Cookies. If you want to stop accepting the use of certain cookies, the “help” feature of most browsers will help you disable existing cookies and stop receiving future cookies.
Targeted Advertising. If you do not want to receive Targeted Advertising on other websites or select your preferences about the third party Advertisers and advertising network programs that provide you with Targeted Advertising, you can opt-out by visiting the:
- NAI Opt-Out Page: http://www.networkadvertising.org/choices/, and
- Ad Choices Opt-Out Page: http://aboutads.info/choices/
Please note that if you opt-out of Targeted Advertising you may still receive advertisements from SmartThings and others; however, these ads will not be displayed due to Targeted Advertising.
Communications. If at any time you decide you do not want to receive promotional communications from us, you can indicate your preference by clicking 'unsubscribe from this list' or 'update subscription preferences' at the bottom of the email you received.
Services. You can always opt not to disclose information to use, but keep in mind some information may be needed to register with us or to take advantage of some of our special features or the Services in any form.
You may be able to add, update, or delete information as explained above. When you update information, however, we may maintain a copy of the unrevised information in our records. You may request deletion of your account by emailing us at firstname.lastname@example.org. Please note that some information may remain in our records after your deletion in order meet certain business needs and / or comply with retention requirements. of such information from your account. We may use any anonymized or aggregated data derived from or incorporating your Personal Information after you update or delete it, but not in a manner that would identify you personally.
What if I have questions about this policy?
What if I logged in with my Samsung account?
SmartThings takes the security of our systems seriously, and we value our relationship with our customers and the security community. The responsible disclosure of security vulnerabilities helps us ensure the security and privacy of our users.
We require that all researchers:
- Avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data during security testing;
- Perform research only within the scope set out below; and
- Use the identified communication channels to report vulnerability information to us; and
In the interest of the safety of our users, staff, the Internet at large and you as a security researcher, the following test types are excluded from scope:
- Findings from physical testing such as office access (e.g. open doors, tailgating)
- Findings derived primarily from social engineering (e.g. phishing, vishing)
- Denial of Service (DoS/DDoS) vulnerabilities
Things we do not want to receive and will not consider:
- Personally identifiable information (PII)
- Credit card holder data
- Out of scope issues
If you follow these guidelines when reporting an issue to us, we commit to:
- Not pursue or support any legal action related to your research;
- Work with you to understand and resolve the issue quickly;
Scope & Reporting a Security Vulnerability
SmartThings has partnered with BugCrowd to help security researchers and our users test for, and alert our security team to, discovered vulnerabilities. The BugCrowd platform allows us to host, triage, and respond to reports in an efficient and effective manner, helping SmartThings continuously improve the security of our products.
To get started: