Last Updated: June 26, 2026
HO Smart Ring ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our mobile application, website, and related services (collectively, the "Services").
By using our Services, you agree to the collection and use of information in accordance with this policy.
Data Controller:
Data Protection Contact: service@ho-ring.com
We collect the following health metrics from your HO Smart Ring device:
| Data Type | Purpose | Legal Basis (EU) |
|---|---|---|
| Heart rate | Health monitoring, trend analysis | Explicit consent (GDPR Art. 9) |
| Blood oxygen (SpO2) | Health monitoring | Explicit consent (GDPR Art. 9) |
| Heart rate variability (HRV) | Stress and recovery analysis | Explicit consent (GDPR Art. 9) |
| Sleep stages (deep/light/REM) | Sleep quality analysis | Explicit consent (GDPR Art. 9) |
| Steps / activity | Activity tracking | Explicit consent (GDPR Art. 9) |
| Stress index | Wellness monitoring | Explicit consent (GDPR Art. 9) |
| Exercise/GPS track | Activity mapping | Explicit consent (GDPR Art. 9) |
We do NOT:
All overseas user data is stored in our EU (Frankfurt, Germany) data center; the applicable privacy law is determined by your region of residence:
Storage Location: European Union (Frankfurt, Germany)
Legal Basis: General Data Protection Regulation (GDPR)
Data Controller (EU): Shanghai Shunpu Internet Technology Co., Ltd. (上海顺扑互联网科技有限公司, D-U-N-S 444046595)
Data is processed in the EU by Alibaba Cloud (Frankfurt) acting as our data processor (GDPR Art. 4(8)), not as a controller.
Storage Location: Frankfurt, Germany (EU)
Legal Basis: Applicable local privacy laws
Note: US and other non-EU user data is stored in our Frankfurt (Germany, EU) data center.
Cross-Border Access Safeguards: Your data is stored in the EU (Frankfurt) and isolated per region at the storage layer. Because our data controller is established in China, the following cross-border access scenarios apply, safeguarded under GDPR Art. 44–49:
We do not transfer EU/EEA user data to China for storage or processing, except for the limited controller-access scenario described above.
We use the following third-party services. Each service provider acts as a data processor under our instruction:
| Service | Provider | Purpose | Data Shared | Region |
|---|---|---|---|---|
| Cloud Hosting (Global) | Alibaba Cloud Europe | Server infrastructure | All user data | EU (Germany) |
| Authentication | Google / Apple | Social login | Identity token | US/EU |
| Push Notifications (Android) | Firebase (Google) | Push messaging | Device token | US/EU |
| Push Notifications (iOS, Global market) | Apple APNs (direct, no third-party relay) | Push messaging | Device token | EU (Frankfurt) |
| Analytics (Optional) | Firebase Analytics | App usage analytics | Aggregated, anonymized | US |
Important: We do not share your health data with any third party for advertising or profiling purposes.
No In-App Payments: The HO Smart Ring app does not process any payments. Ring hardware is purchased through external channels (our official website or partner channels), not within the app. We do not collect or process any payment card or billing information through the app.
When you enable Couple Space or Family Care features, the following health data may be shared with users you authorize (your partner, friends, or family members) — not with MoRing employees or third-party companies:
Sharing conditions:
Legal basis (EU): Your explicit consent (GDPR Art. 9(2)(a)). Consent is voluntary, specific, and revocable; it is never bundled with relationship creation.
| Data Type | Retention Period | Deletion Trigger |
|---|---|---|
| Account information | Until account deletion | Account deletion request |
| Health data | Until account deletion | Account deletion request |
| Device logs | 90 days | Automatic purge |
| Crash logs | 90 days | Automatic purge |
| Backup data | 90 days after account deletion (backup cycle) | Automatic purge |
We implement the following security measures:
Our app and website use the following:
We do not use third-party advertising cookies or tracking pixels.
Our Services are not intended for children under 16. We do not knowingly collect data from children under 16. If you believe we have collected data from a child, please contact us immediately. See our separate Children's Privacy Policy for details.
We may update this Privacy Policy from time to time. We will notify you of any changes by:
For questions about this Privacy Policy or to exercise your rights:
EU Representative (Art. 27 GDPR): Pursuant to Art. 27 of the GDPR, Shanghai Shunpu Internet Technology Co., Ltd. — a controller not established in the Union — is in the process of appointing an EU/EEA-based representative to act on its behalf regarding data protection matters for EU/EEA users. The representative's name and contact details will be published in this section once appointed.
Interim contact for EU/EEA users: Until the EU Representative is appointed, EU/EEA users may direct all data protection enquiries — including requests to exercise their rights under this Policy — to service@ho-ring.com, and we will respond without undue delay and in any event within one month (Art. 12(3) GDPR).
EU/EEA users may also lodge a complaint with the supervisory authority in their country of residence (see §13).
Under the General Data Protection Regulation, you have the following rights:
Data Protection Contact: service@ho-ring.com
EU Supervisory Authority: You have the right to lodge a complaint with the supervisory authority in your country of residence. A list of EU data protection authorities is available at: EDPB Members
California Residents (CCPA/CPRA):
Other US States: Residents of Virginia, Colorado, Connecticut, and Utah may have similar rights under state privacy laws. Contact us for details.
Important Notice: We do not sell your personal information to any third party.
If you are located outside the EU and the US, you generally have the right to:
Please contact us at service@ho-ring.com to exercise these rights.
In accordance with GDPR Art. 20 (right to data portability) and Art. 12(3) (one-month response window), you may request a complete export of your personal data in a structured, machine-readable format (JSON). As in-app self-service export is not available in the current version, requests are handled manually:
We will provide your data within 30 days.
You may delete your account and all associated data at any time:
Upon deletion: