← Back to edgeiot.online
EdgeIOT
Mobile App Privacy Policy
This Mobile Application Privacy Policy explains how EdgeIOT Systems collects, uses, and protects your information when you use the EdgeIOT mobile application. This policy supplements our website privacy policy. By using the App, you agree to the collection and use of information as described in this policy.
Section 1 — Data Controller
Section 2 — Data We Collect
a) Account Information
- Login email address
- When you choose to configure SMS recovery, a verified recovery phone number
- Authentication tokens (stored securely on-device for session management)
- Temporary security state, which may include verification codes, recovery challenges, pending email-change state, and reset authorizations
We use account and recovery information for authentication, account security, verification of sensitive account changes, and password or account recovery. Recovery phone numbers are not used for advertising or marketing.
b) Location Data
- Tracked-device GPS coordinates used for monitoring, mapping, alerts, history, analytics presented to you, and device or fleet functionality
- If you grant the App permission to use your handset’s location, it is used while the App is in active use for application functionality such as positioning you relative to tracked assets
- The App does not collect your handset’s location in the background
Location information is not used for advertising.
c) IoT Device Data
- Device serial numbers and other device identifiers
- Tracked-device GPS coordinates and sensor telemetry readings (such as temperature, speed, and battery)
- Device status, timestamps, alert and event data, and device history
- Alert rules and alarm events you configure
d) Network & Technical Data
- API requests to EdgeIOT backend servers for device data retrieval
- No analytics SDKs or crash-reporting tools collect data from this App
Section 3 — Why We Collect This Data
- Authentication and account security: to verify your identity, maintain a secure session, verify sensitive account changes, and provide password or account recovery
- Device monitoring and mapping: to display real-time status, location, and sensor readings
- Alerts: to notify you when devices trigger configured alarm conditions
- Analytics presented to you: to show historical performance, trip data, and usage patterns
- Device and fleet functionality: to provide the monitoring, history, mapping, and configuration features you request
We do NOT collect data for advertising, marketing profiling, or any purpose beyond the direct operation of the EdgeIOT platform.
Section 4 — Third-Party Services
- Amazon Web Services (AWS) — cloud infrastructure for data storage and processing; AWS SNS or other AWS messaging services process transactional SMS for verification, account security, and recovery, and AWS email services process verification or security email where applicable. Destination phone numbers or email addresses and relevant delivery metadata are processed to deliver the requested security communication. EdgeIOT does not direct AWS to use this information for EdgeIOT advertising.
- Apple Maps (iOS) / Google Maps (Android) — map rendering only; your device data is not transmitted to Apple or Google
- Expo / React Native — app framework; no analytics collected
We do NOT integrate advertising networks, social media trackers, or behavioral analytics tools.
Section 5 — Data Storage & Security
- All data stored on AWS infrastructure with AWS security standards
- Data in transit protected with TLS encryption
- Data at rest encrypted using AWS encryption (SSE-S3, SSE-KMS)
- Authentication tokens stored securely on-device
- Access controls restrict data to authorized personnel only
Section 6 — Data Retention
- Account data: retained while needed to provide and secure your account, subject to account deletion and applicable retention requirements described below
- IoT telemetry data: retained up to 12 months, then automatically purged
- Authentication tokens: expire automatically and are removed on logout or through account deletion processing
- Temporary verification and recovery state: verification codes, recovery challenges, pending email-change state, and reset authorizations are retained only for their configured security lifecycle and are expired, consumed, or removed according to implemented security controls
- Verified recovery phone: remains associated with your account until it is replaced, changed and reverified, or removed through applicable account deletion processing
Account deletion
You can initiate account deletion from Profile in the App. Account deletion removes account-bound information such as your user profile, sign-in credentials, active sessions, recovery information, preferences, notification registrations, memberships and other direct account associations, and directly owned settings or configuration.
Certain records may be retained where necessary and applicable, including operational device history, billing records, security records, audit records, and records required by law. Account deletion therefore does not necessarily remove operational IoT or device history that must be preserved for these purposes.
Section 7 — Data Sharing
We do NOT sell, rent, or trade your personal data to any third party. We do NOT share your data for advertising or marketing purposes.
- Required to operate AWS infrastructure
- Required by applicable Saudi Arabian law or valid legal process
- Required to protect rights, property, or safety of EdgeIOT Systems or users
Section 8 — Your Rights
- Access: request a copy of the data we hold about you
- Rectification: correct inaccurate or incomplete data
- Erasure: request deletion of your data
- Objection: object to specific processing of your data
- Portability: receive your data in a structured, machine-readable format
In-app account controls
- Change your login email after verification
- Configure, change, or reverify a recovery phone
- Sign out of the App
- Initiate account deletion from Profile in the App
Contact: [email protected] — we respond within 30 days.
Section 9 — Children's Privacy
The App is for business and professional use only. We do not knowingly collect data from individuals under 18. Contact [email protected] immediately if you believe we have done so inadvertently.
Section 10 — Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes via email or in-app notification. The “Last updated” date at the top reflects the most recent revision.
Section 11 — Governing Law
This Privacy Policy is governed by the laws of the Kingdom of Saudi Arabia. Disputes shall be resolved in accordance with Saudi Arabian jurisdiction.
Section 12 — Contact Us