Effective Date: 05/03/2022
For this Policy, we use the term “personal data” broadly to cover the many privacy and data protection laws applicable to us; generally “personal data” means information related to an identified natural person or that could reasonably be used (by itself or in combination with other data available) to identify a natural person.
This Policy applies to any and all use of the Skyhook Services, including our Precision Location suite of products. It covers the data we may collect from the Skyhook Services, and other data we compile from third parties in order to provide the Skyhook Services.
So that you can better understand the types of Skyhook Services that are available, and how and why data collection is important to the provision of these services, below is a brief description of the main types of products and services offered by Skyhook.
Location Determination: Skyhook offers a software (SDK) and cloud-based technology platform (API) that may be used to calculate the approximate geographic location of a device. See http://www.skyhookwireless.com/products/precision-location. The Skyhook geolocation technology determines the location of a device by interfacing with Global Navigation Satellite Systems (such as GPS), as well as by utilizing the IP address of the device and nearby Wi-Fi access points and cell towers visible to the device. This information is then processed on the device or on Skyhook’s servers to calculate and return the approximate geolocation (i.e., latitude/longitude) of the device. We may also receive or assign a unique device identifier to location requests.
Geofencing: Skyhook’s on-device software may also be used to determine a device’s proximity to nearby points of interest, or whether a device has entered or exited a pre-defined geographic perimeter. For example, geofencing might be used to alert a logistics company that a particular device or shipment has arrived at or departed from a warehouse facility.
When end users engage with mobile devices or customers that use the Skyhook Services (including via SDK, API or otherwise), Skyhook may collect data that may (but does not necessarily) include the following:
Skyhook may also receive information from our partners, which are usually location data aggregators and application developers/publishers. These partners may deliver mobile software and/or location services for your mobile device and, through them, we may receive geolocation information (latitude/longitude), usually including a unique identifier or device ID, a time stamp, and (in some cases) an IP address.
In general, Skyhook uses the information collected in order to operate, maintain and deliver the Skyhook Services and to develop new products, services or datasets. In particular, Skyhook uses the information generated or collected as follows:
To the extent permitted by applicable law, we may combine the various types of personal data that we collect from different sources, including Personal Data we obtain from others. In addition, as specified above, we may de-identify and/or anonymize the personal data we collect such that it no longer can be used to identify you and, in such case, the de-identified and/or anonymized data is no longer subject to this Policy.
Skyhook requires all clients and third parties using Skyhook Services to provide notice regarding data collection and use, and to obtain all opt-ins, consents or permissions required, including without limitation any data such party collects, uses, and/or discloses from its users, the provision of such data to Skyhook, and the other party’s use of such data.
In addition, Skyhook also allows users to directly opt-out from Skyhook’s Services as follows:
Location Information: For users who do not want any location data to be collected, the application, device, or operating system provides controls for disabling all location services. This choice may limit the functionality of the device or installed applications.
Mobile Device ID (e.g., Advertising ID): If you wish to opt out of the Skyhook’s use of your Mobile Device ID for any use, you may opt-out by clicking here. If you choose to opt out your Mobile Device ID(s), Skyhook will delete any collected data directly related to this Mobile Device ID from Skyhook database, and quarantine the Mobile Device ID so that Skyhook does not collect any data directly related to this Mobile Device ID in the future or return or share any information about the Mobile Device ID to API or SDK requests.
Skyhook also respects platform-level controls and restrictions, so that if you disable targeted advertising through controls offered by the application and/or through the iOS or Android “Limit Ad Tracking” or “Opt out of interest-based advertising” settings, we will abide fully by those setting. More information on how to access these settings is provided on the Skyhook opt out page, which can be accessed by clicking here. If a user chooses the “Limit Ad Tracking” or “Opt out of interest-based advertising” settings on iOS or Android, Skyhook will quarantine the Mobile Device ID so that Skyhook does not collect any data about this Mobile Device ID and will not return or share any information about the Mobile Device ID in response to API or SDK requests, instead returning an error code when the Mobile Device ID has been opted out. Skyhook will also delete any encrypted device identified data from the opted-out user’s device.
MAC Addresses: If you wish to opt out of Skyhook’s use of your Wi-Fi access point's MAC address to provide location, you may opt-out by clicking here. If you choose to opt out, Skyhook will (if applicable) delete the positioned record for that MAC address from the Skyhook database and will blacklist that MAC address so that we will not process or use that MAC address information in the future.
IP Addresses: If you wish to opt out of Skyhook’s use of your home IP Address, you may opt-out by clicking here. If you choose to opt out, Skyhook will (if applicable) remove the positioned record for that IP address from the Skyhook database and will blacklist that IP address so that we will not process or use that IP address in the future.
Data on Device: Skyhook may store an encrypted local cache of all Wi-Fi access points and cell towers in a surrounding area on the device to allow the device’s location to be determined without connecting to our servers. A temporary encrypted history of scanned Wi-Fi access points and cell towers nearby may also be kept in memory on the user’s device and later transmitted to our servers. A maximum of 100 historic scans will be retained on device. This encrypted cache information will be deleted from the device the next time the Skyhook technology connects to the Skyhook servers, when the application terminates, or when the device is turned off.
Data Retention: For all device identified data (i.e., location history that is associated with an Advertising ID or another persistent Mobile Device ID, hashed or otherwise), Skyhook will retain such data as follows: (a) for up to two (2) years to provide our services described above, and (b) for internal business purposes (e.g., for developing and bench-marking technical improvements, for regression and quality testing, and for accounting, auditing, or legal purposes) for such period as Skyhook considers reasonably necessary to protect its legal or business interests. After that time, some of the information we have may be aggregated and anonymized for statistical purposes and stored indefinitely. Other anonymous location data that is not associated with a persistent unique identifier, mobile device ID or any other personally identifiable information may be stored indefinitely and used for purposes of improving and maintaining our location service.
Data Security: Skyhook uses a variety of technical, administrative, and organizational measures to protect data, both during transmission and once we receive it. However, no method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, we cannot guarantee the absolute security of all information.
Skyhook may share information that we collect from our Location Services or obtain via partners as follows:
Skyhook may also disclose any of the data we collect to any member of Qualcomm group of companies. Information about Qualcomm group of companies can be found at https://www.qualcomm.com/company/locations. If the disclosure to Qualcomm group companies requires a cross-border data transfer, please see Section 11, below.
The Skyhook Services are not developed or intended for persons under 13 years of age. We do not knowingly solicit or collect any personally identifiable information including from children under the age of 13, nor do we knowingly market our Services to children under the age of 13.
As of May 25, 2018, with respect to individuals in the European Union, the European Economic Area and Switzerland who use the Skyhook Services, the following policies, clarifications and rules also apply.
“Personal Data” means any information relating to an identified or identifiable natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of such natural person.
“Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Purposes and Legal Bases for Processing Personal Data
In general, the lawful bases for Skyhook’s Processing of Personal Data are: (i) informed consent, including as obtained via partners through contractual requirements and/or established consent frameworks or (ii) any other applicable legal bases, such as our legitimate interest.
In particular, with respect to processing, retention and use of any device-identified location data which may constitute Personal Data (i.e., location history that is associated with an Advertising ID or another persistent Mobile Device ID, hashed or otherwise – as opposed to data which is aggregated and not able to associated with any particular device), Skyhook relies upon the informed consent of the end user, as received through our customers and supply partners.
With respect to the collection of the approximate location of wireless hotspot information (MAC address, received signal strength, and location-related information), Skyhook relies upon legitimate interest as a basis for collection and processing.
With respect to the collection of IP addresses and approximate location associated with their use, Skyhook is not an Internet Service Provider (or ISP) providing the connectivity and does not maintain or have access to information linking the IP address to an individual subscriber. Nevertheless, to the extent that such information might constitute Personal Data as Skyhook uses it to develop a coarse (greater than 100m) geolocation position, Skyhook relies among other things on legitimate interest as a basis for processing and collection.
The foregoing statements of legal bases for processing are intended to be non-exhaustive, and do not preclude Skyhook’s reliance on additional legal bases either now or in the future.
Additional Rights for Individuals in Europe
You may have one or more of the following additional rights available to you:
To exercise any of the above-listed rights (with the exception of the right to lodge a complaint with a DPA, which you may do directly to a DPA), please contact us at email@example.com. We will process any requests in accordance with applicable law and within a reasonable period of time. We may need to verify your identity before processing your request.
Skyhook may be required to disclose Personal Data in response to lawful requests by public authorities, including disclosures necessary to meet national security or law enforcement requests or requirements, or pursuant to judicial orders, subpoenas, or similar legal process.
Skyhook is accountable for information that it receives under Privacy Shield and subsequently transfers to a third party, including third parties that Skyhook engages to process this information on its behalf. The Federal Trade Commission has jurisdiction over Skyhook’s compliance with the Privacy Shield.
In accordance with the Privacy Shield Principles (the "Principles"), Skyhook has established procedures to periodically verify its implementation and compliance. Skyhook conducts an annual self-assessment of its practices regarding Personal Information intended to verify that the assertions Skyhook makes about its practices are true and that such practices have been implemented as represented. In addition, in compliance with the Privacy Shield Principles, Skyhook commits to resolve complaints about our collection or use of your personal information. EU and Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact firstname.lastname@example.org or by mail to Qualcomm Incorporated, Attn. Scott Goss, VP, Privacy Counsel, 5775 Morehouse Drive, San Diego, CA 92121.
Skyhook has further committed to refer unresolved Privacy Shield complaints to JAMS, an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please visit here for more information or to file a complaint. The services of JAMS are provided at no cost to you.
For residual complaints not fully or partially resolved by other means, you may be able to invoke binding arbitration as detailed in the Principles available here.
Our privacy practices are aligned with the requirements of the California Consumer Privacy Act (as may be amended from time to time) (CCPA). If you reside in California, we are required to provide additional information to you about how we use and disclose your Personal Information, and you may have additional rights with regard to how we use your Personal Information.
Personal Information. Consistent with section 5 above, we collect certain categories and specific pieces of information about individuals that are (or may be) considered “personal information” under the CCPA. Specifically, we may collect, receive or process the following types of personal information:
Sources. The categories of third parties from whom we may collect or receive the Personal Information described above include the following:
Your Rights. Subject to certain exceptions, as a California resident, you have the right to:
If you are a California resident and wish to exercise any of the rights described in this section, you may use the following methods to submit a request in relation to your Personal Information:
Please note that in order to opt-out your Mobile Device ID, MAC Address or IP Address, you need to provide us with that information or use the “Do Not Sell My Personal Information” link and webpage as we do not have the ability to connect your name with your device(s).
To the extent that you elect to designate an authorized agent to make a request on your behalf, the above methods to submit a request apply. Please note that you are limited by law in the number of requests you may submit per year.
If you have any questions, concerns or complaint regarding our privacy practices, or if you’d like to exercise your choices or rights, you can contact us as follows:
We will make every effort to resolve your concerns.