ZASO SmartCare

ZASO (知尔爽) Privacy Policy

Privacy Policy for ZASO SmartCare.

Version
2026.07.15.2
Effective date
2026-07-15
Published date
2026-07-15
Language
en-US
Content source
Public backend API

About This App and the Personal Information Processor

This Privacy Policy applies to the “ZASO (Chinese brand name: 知尔爽)” App (the “App”). The App is developed and operated by Jiangxi Hongwang Technology Co., Ltd. (江西省宏旺科技有限公司), which is the personal information processor for the App.

If you have questions, comments, or complaints about this Privacy Policy, our processing of personal information, or the exercise of your personal information rights, contact us through Me - Contact Customer Support or Feedback in the App, or email info@aidiaper.net. We will respond in accordance with applicable law after verifying your identity.

1. Information We Collect

To provide smart care services, we may collect account information, device information, care and event records, notification settings, order and after-sales information, and necessary operational logs.

2. How We Use Information

We use this information for account login, device binding, event reminders, record display, order processing, customer support, security verification, and service improvement.

3. Device and Event Data

Device event data is used to display records in the App, trigger reminders, and help caregivers respond to events. Standby device events may be retained as records but are not used for intrusive reminders.

4. Location and Push SDK Notes

The App does not use geographic location as a core feature and does not use it for advertising tracking or user profiling. Android 11 and earlier may require location permission for Bluetooth scanning; Android 12 and later use Nearby Devices permission. The current iOS version does not actively request system location permission.

We initialize JPush SDK and request system notification permission only after you agree to this Privacy Policy and actively enable notification services. On Android, the SDK may process device identifiers (including Android ID, GAID, OAID, UAID, AAID, and Boot ID), software installation and running-app lists, push registration identifiers, device hardware information, operating system information, network type, carrier information, IP address, DHCP, Wi-Fi status, and push-message logs. Processing is limited to generating a unique device identifier, maintaining push-channel compatibility and service stability, and delivering messages. Optional features including link regulation, intelligent push, data insights, auto wake-up, GPS, SSID, BSSID, and base-station collection are disabled. This information is not used for advertising tracking, user profiling, geofence marketing, or personalized recommendations. When notification services are disabled, we stop the SDK push service and revoke the local push identifier.

Basic Information About Third-Party SDKs

  • Alipay App Payment Client SDK (com.alipay.sdk): Developed by Alipay (Hangzhou) Information Technology Co., Ltd.; SDK Privacy Policy. When you actively select Alipay, it may process the order number, payment amount, payment status, transaction identifier, and device- and network-related information to initiate App payment, confirm payment results, process refunds, and perform transaction-security checks.
  • WeChat OpenSDK for Android (com.tencent.mm.opensdk): Developed by Shenzhen Tencent Computer Systems Co., Ltd.; SDK Privacy Policy. When you actively select WeChat Pay or WeChat sharing, it may process order information, payment status, sharing results, and device- and network-related information for payment-result processing and sharing.
  • JPush SDK for Android (cn.jpush.android): Developed by Shenzhen Hexun Huagu Information Technology Co., Ltd.; SDK Privacy Policy. Only after you actively enable notification services may it process the device identifiers, software lists, push registration identifiers, device hardware information, operating system information, network information, and push-message logs described above for push compatibility, stability, and delivery.

5. Personalized Recommendations, Advertising, and Profiling

The App currently does not use your personal information for targeted advertising, commercial personalized recommendations, or user profiling, and does not use device events, child information, or order information for advertising tracking. If such features are added, we will provide separate notice before launch. You may enable or disable personalized recommendations under Me - Privacy and Security - Personalized Recommendations. Disabling them does not affect essential services.

6. Children and Minors

Account registration, device binding, orders, and after-sales operations must be performed by adults, parents, or other legal guardians. Child nicknames, birthdays, care records, and device events may be personal information of children or minors. We process it only with guardian authorization and only as necessary to provide care services. Guardians may modify or delete related information, unbind devices, or request access, correction, or deletion.

Minors must not independently register, sign in, or submit personal information without guardian consent. Guardians who discover unauthorized processing may contact us, and we will verify and handle the request in accordance with applicable law.

7. Information Sharing

Payment, push notification, cloud storage, and similar functions may require sharing the minimum necessary information with service providers. We do not sell personal information.

8. Your Rights

You may update your profile, adjust notification preferences, unbind devices, withdraw non-essential authorizations, or request account deletion. We respond to requests for access, copies, correction, deletion, account cancellation, and complaints in accordance with applicable law.

9. Account Deletion Process and Data Handling

Go to Me - Privacy and Security - Delete Account in the ZASO App, review the effects, and submit a request after mobile-number verification. The account immediately enters pending-deletion status, login credentials become invalid, and a 7-day cooling-off period begins. To withdraw the request or restore the account during this period, use Contact Customer Support or Feedback. When the period ends and no lawful suspension applies, deletion is completed.

After deletion, we delete or anonymize account profile data, login credentials, child profiles, device binding relationships, notification preferences, and other information that is directly associated with the account and no longer necessary. Order, payment, refund, after-sales, invoice, tax, security-audit, and risk-control records may be retained for necessary periods under law, regulatory requirements, transaction security, or dispute resolution. During retention they are not used for routine business, marketing, or personalized recommendations.

10. Account Deletion Assistance

If deletion cannot be completed in the App, submit a request through Contact Customer Support or Feedback. Current instructions are also published at https://legal.aidiaper.online/account-deletion.

11. Entrusted Processing, Sharing, Transfer, and Public Disclosure

  • Entrusted processing: Cloud storage, SMS, push notification, payment, logistics-query, and similar providers may process information necessary for their functions under contracts, access controls, and security requirements.
  • Sharing: We share only the minimum information necessary when you actively use payment, shared-care, logistics-query, or similar functions, or when required by law. We do not sell personal information.
  • Transfer: We do not transfer personal information in principle. If a merger, division, restructuring, or similar transaction requires a transfer, we will provide notice and require the recipient to continue fulfilling this Policy.
  • Public disclosure: Except for content you actively publish or as otherwise required by law, we do not publicly disclose personal information. Where disclosure is necessary, we provide separate notice and obtain authorization as required.

12. Storage Location and Retention Periods

Our business servers and databases are located within the People’s Republic of China. Account, device, and care information is retained while services are provided and the account remains active. After account deletion, information that is no longer necessary is deleted or anonymized. We retain transaction records for at least three years and network operation and security logs for at least six months, unless law requires otherwise.

13. Security Safeguards

We use transport encryption, access controls, least-privilege permissions, masking or encryption of sensitive fields, audit logging, backup and recovery, and security-incident response. If an incident may affect your rights or interests, we take remedial measures and provide notices or reports as required by law.

14. Your Rights and Our Response

You may exercise rights of access, copying, correction, deletion, withdrawal of consent, device unbinding, and account cancellation through Profile, Device Management, Shared Care, Notification Settings, Privacy and Security, Delete Account, Contact Customer Support, and Feedback. We generally respond or complete processing within 15 working days after verifying your identity, unless law provides otherwise.

15. Policy Updates and Effective Date

This version was published and became effective on July 15, 2026. If there is a material change to processing purposes, methods, information categories, retention periods, or third-party SDKs, we will update this Policy and obtain consent again as required by law.

Additional Personal Information Processing Details

Accounts, Devices, and Care Services

  • Account and profile data: Mobile number, SMS verification code, nickname, avatar, language, and time zone are used for registration, login, account security, profile display, and localization.
  • Device and care data: Device identifiers, binding relationships, online status, firmware version, temperature and humidity, wetness, bowel movements, care times, care notes, and reminder status are used for device management, care records, exception reminders, and shared care. These may reflect an infant’s health or care status and are sensitive personal information processed only after guardian binding, entry, or authorized sharing.
  • Shared care: When you invite a caregiver, we process the invitation relationship, member account identifiers, and device access permissions. Members can be removed and sharing can be exited in the App.

Local Bluetooth Provisioning and Network Information

When you provision a device, the App scans nearby Bluetooth devices and sends the selected Wi-Fi name (SSID) and password to the device over a local Bluetooth connection. The Wi-Fi password is not uploaded to or stored on our cloud servers. The device stores network credentials locally until reset or re-provisioning. App logs record only necessary connection stages and field lengths, not plaintext SSIDs or passwords.

Identity Verification and Payout Accounts

  • Identity verification: For experience-partner services requiring identity checks, we process real name and identity-card number for eligibility, consistency checks, and dispute handling. The server stores the real name, masked identity-card number, and an irreversible value produced with a server-side key, not the full plaintext number.
  • Payout accounts: For withdrawals or payout setup, we process account type, account holder name, and payout account number. The server stores the account name, masked account number, and an irreversible verification value, not the full plaintext number. Information is not submitted to an external payout institution before payout capability is enabled and separate notice is provided.

Refusing these sensitive information items does not affect basic device-care functions but prevents the relevant eligibility review or withdrawal service.

Store, Logistics, and User-Submitted Content

We process product browsing and search, favorites, orders, payment status, invoices, recipient, contact number, delivery address, tracking number, reviews, and uploaded images or evidence for transactions, delivery, after-sales support, content display, and activity eligibility.

File Storage and Access

Avatars and public product images selected for public display are stored for that purpose. Non-public materials such as experience-partner evidence use private object storage and time-limited or signed access URLs. We do not generate permanent public links for non-public materials.

Other Third-Party Services

  • Alibaba Cloud SMS (server-side): Provided by Alibaba Cloud Computing Co., Ltd.; Privacy Policy. Our server provides a mobile number, verification-code template parameters, and scenario information to send identity-verification messages for login, registration, mobile-number changes, password recovery, or account deletion. This is not an embedded App SDK.
  • Alibaba Cloud Object Storage Service (server-side): Provided by Alibaba Cloud Computing Co., Ltd.; Privacy Policy. It stores avatars, product images, review images, and user-uploaded evidence for storage, backup, and controlled access. This is not an embedded App SDK.
  • Kuaidi100 API: Provided by Shenzhen Qianhai Baidi Network Co., Ltd.; Privacy Policy. For logistics queries, our server may provide carrier code, tracking number, origin and destination regions, and the recipient contact number necessary for the query.
  • Google ML Kit Barcode Scanning: Developed by Google LLC; Terms and Privacy. Enabled only when you open a scanning page; camera frames and recognized values are processed locally and are not uploaded to Google for barcode recognition. The component may communicate with Google for updates and process device/app information and performance or diagnostic metrics. Where cross-border processing involves personal information, we will provide notice and obtain consent as required by law.