Arozen Mobile App — Privacy Policy
Applies to: The Arozen mobile application (iOS and Android) for controlling Arozen Tuya-based diffusers (the “App”).
Does not replace: The website Privacy Policy at www.arozen.com.au (online store, cookies, and order processing).
Effective date: 22 July 2026
1. Who we are
We are Arozen Pty Ltd trading as Arozen (“Arozen”, “we”, “us”, “our”).
-
Website: www.arozen.com.au
-
Privacy contact: hello@arozen.com.au
-
Postal address: 2 Corporate Drive, Cranbourne West, 3977, Victoria, Australia
-
ABN / company number: 71 676 017 628
For personal data processed through the App, Arozen is the data controller (or equivalent under applicable privacy law).
If you use our online shop, that processing is described in our website Privacy Policy. Account details for the App are not shared with our online store login in the current App version (no shared store sign-on).
2. Scope
This Privacy Policy describes how we collect, use, store, share, and protect personal information when you:
-
download, register for, or use the App;
-
pair, control, or schedule Arozen Tuya-based diffuser devices through the App; or
-
contact us about the App or exercise privacy rights relating to App data.
It applies wherever you use the App. Additional jurisdiction-specific notices appear in section 14.
3. Personal information we collect
3.1 Information you provide
| Category | Examples | When |
|---|---|---|
| Account details | Email address, first name, last name, password | Registration and sign-in |
| Device labels | Nicknames you give your diffuser(s) | Device pairing and settings |
| Schedules & preferences | Days of week, time ranges, misting frequency, countdown settings | Scheduling and control screens |
| Support content | Messages, screenshots, or other details you send us | When you contact support |
Passwords are handled by our authentication provider (see section 6). We do not store your password in readable form in our own databases.
3.2 Information from your devices and the App
| Category | Examples | When |
|---|---|---|
| Account identifiers | Internal user ID | After registration |
| Device / pairing metadata | Device identifiers used to bind your diffuser to your account (e.g. manufacturer device ID, product identifiers), online/offline status, and control-related device state (on/off, misting, countdown, battery level where the device reports it) | Pairing and ongoing use |
| Technical / diagnostic data | App version, device OS type/version, crash or error diagnostics (where enabled) | When the App runs or fails |
| Network data | IP address (typically seen by our cloud providers and the device cloud when the App communicates online) | Whenever the App connects to online services |
3.3 Information we do not keep in durable storage
-
Home Wi‑Fi password: collected only briefly during device setup (Bluetooth provisioning), sent to your diffuser to join your network, then discarded from App memory. We do not save your Wi‑Fi password in our cloud databases.
-
Payment card details: not collected in the App (purchases, if any, are via our website / store).
3.4 Information we do not currently collect in the App
Unless we update this Policy and the App, we do not use the App for:
-
marketing analytics or advertising software development kits (SDKs);
-
push-notification marketing;
-
selling or sharing personal information for cross-context behavioural advertising;
-
online store account linking inside the App.
If we add those features later, we will update this Policy before (or when) they go live.
3.5 Children’s information
The App is intended for adults and household use. We do not knowingly collect personal information from children under 13 (or under 16 where local law sets a higher digital-consent age). If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.
4. How we use personal information
We use App personal information to:
-
Create and manage your account (registration, login, password reset / account recovery).
-
Provide the App service — pair diffusers, show device status, apply on/off, misting frequency, countdown, schedules, and related controls.
-
Restore your devices and settings if you reinstall the App or change phones (account-linked device binding).
-
Secure the service — authenticate you, protect accounts, prevent abuse, and investigate security incidents.
-
Operate and improve reliability — diagnose crashes and errors; maintain service quality.
-
Meet legal obligations — respond to lawful requests; keep records where required.
-
Communicate with you about the App (e.g. security or service notices, responses to your requests). We do not use App data for third-party advertising in the current version.
We do not sell your personal information.
5. Legal bases (where GDPR / UK GDPR or similar rules apply)
Where those laws apply, we rely on one or more of the following:
| Purpose | Typical legal basis |
|---|---|
| Providing the App, pairing, control, schedules, account restore | Contract — performance of our contract with you to provide the App |
| Security, fraud prevention, service integrity | Legitimate interests (and/or legal obligation) |
| Crash diagnostics / reliability | Legitimate interests (reliable service) — or consent where required by local law for certain diagnostic tools |
| Legal compliance, responding to authorities | Legal obligation |
| Optional marketing (if introduced later) | Consent and/or other permitted bases under local law |
Where Australian, New Zealand, Singapore, Malaysian, or US state privacy laws apply, we collect and use personal information for the purposes described above and as otherwise permitted or required by those laws (including with your consent where required).
6. Who we share personal information with
We share personal information only as needed to run the App, as described below, or as you instruct us. We do not sell customer lists.
6.1 Service providers (processors)
| Provider | Role | What they process (summary) |
|---|---|---|
| Google (Firebase / Google Cloud) | Authentication, database, and (where used) cloud functions / crash reporting | Account credentials (via Firebase Authentication), profile fields, device nicknames, schedules, device correlation identifiers, diagnostic logs as configured |
| Tuya (device IoT cloud) | Device pairing session, live device state, and control commands | Opaque device / account identifiers for the device cloud, device data points (e.g. power, misting, timers, battery where available), and technical connection data (e.g. IP). Tuya does not receive your name, email, or password — those stay with our account systems (Firebase) |
We require processors to protect personal information and use it only on our instructions, under agreements appropriate to the service (including data processing terms where required).
6.2 App platforms
Apple App Store and Google Play process information according to their own terms when you download the App or manage your store account. That processing is controlled by Apple or Google, not by Arozen.
6.3 Other disclosures
We may disclose personal information if required by law, court order, or regulator; to protect rights, safety, or security; or in connection with a business transfer (merger, acquisition, or sale of assets), subject to appropriate safeguards.
6.4 How device control works (important)
Commands you send in the App (for example, turn on/off) go:
App → Tuya device cloud → your diffuser
Your profile data held for your Arozen account is not used as the live control channel. This separation helps limit what a failure in one system can expose.
7. International data transfers
The App is designed for users in multiple countries. Personal information may be processed in:
-
the region where our Firebase / Google Cloud project is hosted (we intend to host primary App account data in Australia — Google Cloud region australia-southeast1 (Sydney), unless we notify you of a change);
-
Tuya’s device-cloud region used for the App (currently intended as Central Europe for device control traffic); and
-
other locations where our providers maintain infrastructure or support operations.
If you access the App from outside Australia, your information will be transferred to and processed in Australia and/or the locations above.
Where required (for example under GDPR / UK GDPR), we use appropriate transfer safeguards such as standard contractual clauses, UK international data transfer tools, or other lawful mechanisms, and we assess transfers as required by law. Details of the mechanisms in force can be requested via the contact details in section 15.
Note on expansion: If we later change hosting regions or enable additional Tuya data centres for certain countries, we will update this Policy and, where required, provide additional notice.
8. Retention
We keep personal information only as long as needed for the purposes in this Policy, including:
| Data | Typical retention |
|---|---|
| Account profile and linked device/schedule data | For as long as your account remains open |
| After you delete your account | We delete or anonymise App account data in our systems as described in section 10, subject to short technical backups and any longer retention required by law |
| Security / operational logs that may contain a user ID | Generally short periods (for example, on the order of 30 days for certain backend logs), unless needed longer for security investigation or legal reasons |
| Crash reports | Per the crash-reporting provider’s configured retention (often around 90 days) |
Website / shop order history (if any) is covered by the website Privacy Policy, not this App Policy.
9. Security
We use commercially reasonable technical and organisational measures to protect personal information we hold in connection with the App. Like any online service, absolute security cannot be guaranteed.
10. Your choices and account deletion
10.1 In-app controls
Depending on the App version, you may:
-
update certain device nicknames and schedules;
-
remove (unbind) a device from your account; and
-
delete your account from within the App (Settings → Delete account, or equivalent).
Account deletion is intended to:
-
unbind your devices from the device cloud where supported;
-
delete your App profile and related records in our cloud account systems; and
-
delete your authentication user record.
Some residual logs may age out automatically under our retention rules.
10.2 Other requests
You may also email us (section 15) to request access, correction, deletion, or other rights available under your local law. We may need to verify your identity before responding.
11. Your privacy rights (global overview)
Depending on where you live, you may have rights to:
-
access personal information we hold about you;
-
correct inaccurate information;
-
delete information (including via in-app account deletion);
-
portability of certain information you provided;
-
restrict or object to certain processing;
-
withdraw consent where processing is based on consent;
-
lodge a complaint with a data protection / privacy regulator; and
-
for certain US state residents, rights to know, delete, correct, and opt out of “sale” or “sharing” for cross-context behavioural advertising (we do not sell personal information; see section 14.5).
We will respond within the timeframes required by applicable law. Exercising rights is free of charge except where a law allows a reasonable fee for manifestly unfounded or excessive requests.
12. Cookies and similar technologies
The mobile App does not use website-style browser cookies. The App may store technical data on your device (for example, session tokens in secure storage, cached device images, and local preferences) as needed to operate.
Our website uses cookies and similar technologies as described in the website Privacy Policy.
13. Do Not Track / automated decision-making
The App does not respond to browser “Do Not Track” signals (those apply primarily to websites).
We do not use App personal information for solely automated decisions that produce legal or similarly significant effects about you.
14. Jurisdiction-specific notices
14.1 Australia
We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth), where applicable. You may complain to us first; if unresolved, you may contact the Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au.
14.2 New Zealand
Where the New Zealand Privacy Act 2020 applies, you may complain to us and, if unresolved, to the Office of the Privacy Commissioner — www.privacy.org.nz.
14.3 Singapore
Where the Singapore Personal Data Protection Act 2012 (PDPA) applies, you may contact us using the details in section 15. You may also contact the Personal Data Protection Commission (PDPC) — www.pdpc.gov.sg.
14.4 European Economic Area and United Kingdom
If GDPR or UK GDPR applies to our processing of your personal data:
-
Controller: Arozen (details in section 1).
-
Legal bases: see section 5.
-
Transfers: see section 7.
-
Rights: see section 11, including the right to lodge a complaint with your local supervisory authority (in Germany, your state data protection authority; in the UK, the Information Commissioner’s Office — www.ico.org.uk).
-
EU / UK representative: Not appointed / not required.
14.5 United States (including California)
If you are a resident of California or another US state with a comprehensive privacy law:
-
We collect the categories of personal information described in section 3 for the business purposes in section 4.
-
We do not sell personal information and, in the current App, we do not share personal information for cross-context behavioural advertising.
-
You may exercise applicable rights (know/access, delete, correct, and non-discrimination) by contacting us (section 15) or using in-app account deletion where available.
-
[“Do Not Sell or Share My Personal Information” / appeal process: confirm wording with legal counsel if storefronts include California.]
-
We do not use or disclose sensitive personal information for purposes that require a right to limit under California law beyond what is necessary to provide the App.
14.6 Malaysia
Where the Malaysian Personal Data Protection Act applies, we process personal data for the purposes in this Policy. You may contact us to exercise access and correction rights. You may also contact the Personal Data Protection Department regarding complaints.
14.7 Other countries
If you use the App from another country, local mandatory consumer or privacy rules may give you additional rights. Contact us and we will handle your request in line with applicable law.
15. Contact us
For privacy questions, requests, or complaints about the App:
Email: hello@arozen.com.au
Subject line suggestion: Privacy request — Arozen App
Post: 2 Corporate Drive, Cranbourne West, 3977, Victoria, Australia
Please include enough detail for us to identify your App account (for example, the email address you registered with). Do not send passwords or Wi‑Fi credentials by email.
16. Changes to this Policy
We may update this Privacy Policy to reflect changes to the App, our practices, or legal requirements. We will post the updated Policy (in the App and/or on our website) and change the version date. Where required by law, we will provide additional notice or seek consent.
17. Related public documents
| Document | Covers |
|---|---|
| Website Privacy Policy (www.arozen.com.au) | Site visits, cookies, shop orders, and store-related marketing preferences |
| App Terms & Conditions | Contract terms for using the App (separate document) |
| This Policy | Personal information in the mobile App and linked device-control services |