Eve Privacy Policy (June 17, 2023)

Effective as of June 17, 2023.

Eve Privacy Policy describes how Upward Labs Holdings, Inc. and our affiliates (“Glow“, “we“, “us” or “our“) processes personal information that we collect specifically through the Eve app, that links to this Eve Privacy Policy (including as applicable, social media pages, marketing activities, and other activities described in this Eve Privacy Policy (collectively, “Eve”)). 

As far as Eve is concerned, this Eve Privacy Policy supersedes Glow’s general Privacy Policy, which describes more generally the personal information processed via all Glow’s Services (as defined in the general Privacy Policy). 

Eve enables you to record information about your menstrual cycle for a purpose of your choice (e.g., to track your fertile window, mood, sexual activity, etc.). It also enables you to predict the date of your next period and any associated effects or symptoms, based on the information voluntarily entered.

NOTICE TO EUROPEAN USERS: Please see the Notice to European Users section for additional information for individuals located in the European Economic Area, United Kingdom and Switzerland (which we refer to as “Europe”, and “European” should be understood accordingly) below.

You can download a printable copy of this Privacy Policy here

Index

Personal information we collect

Information you provide to us. Personal information you may provide to us through Eve includes:

  • Account data that you provide to create an account on Eve, including your name, email address, password, date of birth and mobile phone number. 
  • Profile data that you chose to add to your profile on Eve, such as your name, profile photo, location (e.g., city, state, country), relationship status, interests, preferred language, wishlist, gifts sent and received. 
  • Health data that you choose to provide:
    • directly through Eve, such as information about your physical attributes, fertility, menstrual activity, mood, health conditions, and medications; and 
    • through your mobile health apps, such as Apple HealthKit, Samsung Health, Google Fit, MyFitnessApp, which may include any information you chose to store in those apps, subject to your preferences for those apps. 
  • Sex life data, such as information about your sexual activity.
  • Data about others, such as:
    • the names and contact details of the spouses, partners or caregivers to whom you choose to grant access to information in Eve;
    • information in Eve of anyone who has granted you access to it;
    • the email address of anyone you invite to use Eve through features in Eve, and the name of anyone who sent you such an invitation; and
  • Communications that we exchange with you, including when you contact us with questions or feedback, through social media, or otherwise. 
  • Marketing data, such as your preferences for receiving our marketing communications and details about your engagement with them. 
  • User generated content that you upload, generate, transmit, or otherwise make available on Eve, such as profile pictures, photos, videos, images, music, videos, comments, questions, messages, your “likes”, as well as associated metadata. Metadata includes information on how, when, where and by whom a piece of content was created or collected, how that content has been formatted or edited, and the location associated with the creation of the content. 
  • Other data not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection. 

Third-party sources. We may combine personal information we receive from you with personal information we obtain from other sources, such as social media accounts that you use to log into or connect to Eve, which will allow us to collect the information you chose to make available in your settings on that social media account.

Automatic data collection. We, our service providers, and our business partners may automatically log information about you, your computer or mobile device, and your interaction over time with Eve, our communications and other online services, such as:

  • Device data, such as your computer’s or mobile device’s operating system type and version, manufacturer and model, browser type, screen resolution, RAM and disk size, CPU usage, device type (e.g., phone, tablet), IP address, unique identifiers (including identifiers used for advertising purposes), language settings, mobile device carrier, radio/network information (e.g., WiFi, LTE, 3G), and general location information such as city, state or geographic area. 
  • Online activity data, such as pages or screens you viewed, how long you spent on a page or screen, navigation paths between pages, information about your activity on a page, access times, and duration of access, and whether you have opened our marketing emails or clicked links within them.

Cookies. Some of our automatic data collection is facilitated by cookies and similar technologies. For more information, see our Cookie Notice

Data about others. Users of Eve may have the opportunity to refer friends or other contacts to us and share their contact information with us. Please do not refer someone to us or share their contact information with us unless you have their permission to do so.

How we use your personal information

We may use your personal information for the following purposes or as otherwise described at the time of collection:

Service delivery and operations. We may use your personal information to:

  • provide, operate, and improve Eve and our business; 
  • establish and maintain your user profile on Eve; 
  • refer your contacts to join Eve; 
  • communicate with you about Eve, including by sending announcements, updates, security alerts, and support and administrative messages; 
  • understand your needs and interests, personalize your experience with Eve and our communications; and 
  • provide support for Eve, and respond to your requests, questions and feedback. 

Research and development. We may use your personal information for research and development purposes, including to analyze and improve Eve and our business and to develop new products and services. As part of these activities, we may create aggregated, de-identified and/or anonymized data from personal information we collect. We make personal information into de-identified or anonymized data by removing information that makes the data personally identifiable to you. We may use this aggregated, de-identified or otherwise anonymized data and share it with third parties for our lawful business purposes, including to analyze and improve Eve and our other apps, promote our business and will not attempt to reidentify any such data.

Marketing and advertising. We, our service providers and our third-party advertising partners may collect and use your personal information for marketing and advertising purposes:

  • Direct marketing. We may send you direct marketing communications. You may opt-out of our marketing communications by clicking on the “Unsubscribe here” link, at the bottom of our marketing communications.  
  • Personalized advertising. We may engage third-party advertisers or advertising companies to display ads on Eve and other online services. These companies may use cookies and similar technologies to collect information about your interaction (including the data described in the automatic data collection section above) over time across Eve, our communications and other online services, and use that information to serve online ads that they think will interest you. This is called interest-based advertising. We may also share names, email addresses and device identifiers of our users with these companies to facilitate interest-based advertising to those or similar users on other online platforms. You can learn more about your choices for limiting interest-based advertising in the Your choices section of our Cookie Notice. 

Compliance and protection. We may use your personal information to:

  • comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas, investigations or requests from government authorities;
  • protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims); 
  • audit our internal processes for compliance with legal and contractual requirements or our internal policies; 
  • enforce the terms and conditions that govern Eve; and 
  • prevent, identify, investigate and deter fraudulent, harmful, unauthorized, unethical or illegal activity, including cyberattacks and identity theft.  

Retention

We generally retain personal information to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements, to establish or defend legal claims, or for fraud prevention purposes. To determine the appropriate retention period for personal information, we may consider factors such as the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.   

When we no longer require the personal information, we have collected about you, we may either delete it or anonymize it. If we anonymize your personal information (so that it can no longer be associated with you), we may use this information indefinitely without further notice to you.

How we share your personal information

We may share your personal information with the following parties and as otherwise described in this Eve Privacy Policy, in other applicable notices, or at the time of collection.  

Other users and the public. Your name, profile URL, and any location or profile photo that you choose to add to your profile are visible to other users of Eve and the public by default, but you can choose to make your profile private in your account settings. Unless you elect to hide them in your settings, your posts on Eve will be visible to other users of Eve and the public. This information may be seen, collected, used and shared by others. 

Third party apps. You may instruct us to share certain of your personal information with third party apps such as Samsung Health, Apple Healthkit, Google Fit and MyFitnessApp. These parties will use your personal information as described in their respective privacy policies, which are hyperlinked here: Samsung’s privacy policyApple’s privacy policyGoogle’s privacy policy and MyFitnessApp’s privacy policy

Affiliates. Glow, Inc., Heng Yi Technologies, Ltc and our affiliates, for purposes consistent with this Privacy Policy. 

Service providers. Companies and individuals that provide services on our behalf or help us operate Eve or our business (such as hosting, information technology, customer support, email delivery, marketing, and website analytics) to facilitate the provision of such services. 

Payment processors. Any payment card information you use to make a purchase on Eve is collected and processed directly by our payment processors, such as Stripe. Stripe may use your payment information as described in its Stripe’s privacy policy

Advertising partners. Third party advertisers and advertising companies for the interest-based advertising purposes described above. Advertisers whose ads are posted on Eve may be able to infer information about you when you click on those ads (e.g., that you have a newborn if you click on an ad about a newborn product). These parties will use your personal information as described in their respective privacy policies or cookies notices, which are hyperlinked here: Google Ads, Facebook Ads, Nativo, Amazon Publisher Services.

Professional advisors. Professional advisors, such as lawyers, auditors, bankers and insurers, where necessary in the course of the professional services that they render to us. 

Authorities and others. Law enforcement, government authorities, and private parties, as we believe in good faith to be necessary or appropriate for the Compliance and protection purposes described above. 

Business transferees. Acquirers and other relevant participants in business transactions (or negotiations for such transactions) involving a corporate divestiture, merger, consolidation, acquisition, reorganization, sale or other disposition of all or any portion of the business or assets of, or equity interests in, Glow or our Affiliates (including, in connection with a bankruptcy or similar proceedings). 

Security

We are committed to keeping the personal information provided to us secure and we have implemented appropriate information security policies, rules and technical measures to protect the personal information that we have under our control from unauthorized access, improper use or disclosure, unauthorized modification and unlawful destruction or accidental loss.  We have put in place procedures to deal with any suspected breach of personal information and will notify individuals and any applicable regulator of a breach where we are legally required to do so.

Children

Eve is not intended for use by anyone under 16 years of age. If you are a parent or guardian of a child from whom you believe we have collected personal information in a manner prohibited by law, please contact us. If we learn that we have collected personal information through Eve from a child without the consent of the child’s parent or guardian as required by law, we will comply with applicable legal requirements to delete the information.

Changes to this Eve Privacy Policy

We reserve the right to modify this Eve Privacy Policy at any time. If we make material changes to this Eve Privacy Policy, we will notify you by updating the date of this Eve Privacy Policy and posting it on Eve or other appropriate means. Any modifications to this Eve Privacy Policy will be effective upon our posting the modified version (or as otherwise indicated at the time of posting). In all cases, your use of Eve after the effective date of any modified Eve Privacy Policy indicates your acknowledging that the modified content of the Eve Privacy Policy applies to your interactions with Eve and our business.

How to contact us

Upward Labs Holdings, Inc.
580 California St
Suite 1200
San Francisco, CA 94104
United States of America
privacy@glowing.com

Notice to European users

General

Where this Notice to European users applies. The information provided in this “Notice to European users” section applies only to individuals in the European Economic Area (“EEA”), United Kingdom (“UK”) and Switzerland, which we refer to in this notice collectively as “Europe”.

Personal information. References to “personal information” in this Eve Privacy Policy should be understood to include a reference to “personal data” (as defined in the GDPR) – i.e., information about individuals from they are either directly identified or can be identified.   

Controller. Upward Labs Holdings, Inc. is the controller in respect of the processing of your personal information covered by this Eve Privacy Policy for purposes of European data protection legislation (i.e., the EU GDPR and the so-called ‘UK GDPR’ (as and where applicable, the “GDPR”)). See the How to contact us section above for our contact details.

Data Protection Officer. We have appointed a “Data Protection Officer”, this is a person who is responsible for independently overseeing and advising us in relation to our compliance with the GDPR (including compliance with the practices described in this Privacy Policy). If you want to contact our Data Protection Officer directly, you can email: eurepresentative@glowing.com.

Representatives. We have appointed the following representatives in the EEA/UK as required by the GDPR – you can also contact them directly should you wish:

Our representative in the EEA. Our EEA representative appointed under the EU GDPR is VeraSafe Ireland Ltd, North Point Business Park, New Mallow Road, Cork T23AT2P, Ireland.

Our representative in the UK. Our UK representative appointed under the UK GDPR is VeraSafe United Kingdom Ltd., 37 Albert Embankment, London SE1 7TL, United Kingdom. 

Our legal bases for processing

In respect of each of the purposes for which we use your personal information, the GDPR requires us to ensure that we have a “legal basis” for that use. 

Our legal bases for processing your personal information described in this Eve Privacy Policy are listed below.

  • Where we need to perform a contract, we are about to enter into or have entered into with you (“Contractual Necessity”).
  • Where it is necessary for our legitimate interests and your interests and fundamental rights do not override those interests (“Legitimate Interests”). More detail about the specific legitimate interests pursued in respect of each purpose we use your personal information for is set out in the table below.
  • Where we need to comply with a legal or regulatory obligation (“Compliance with Law”).
  • Where we have your specific consent to carry out the processing for the purpose in question (“Consent”).  

We have set out below, in a table format, the legal bases we rely on in respect of the relevant purposes for which we use your personal information – for more information on these purposes and the data types involved, see How we use your personal information section.

PurposeCategories of personal information involvedLegal basis
Service delivery and operations– Account data 
– Profile data 
– Health data 
– Sex life data
– Data about others
– Communications 
– User generated content 
– Device data
– Online activity data
– Contractual Necessity
Direct marketing– Communications 
– Marketing data
– Device data
– Online activity data
– Legitimate Interests. We have a legitimate interest in promoting our operations and goals as an organisation and sending marketing communications for that purpose. You can object to the receipt of further communications by clicking on the “Unsubscribe here” button.

– Consent, in circumstances or in jurisdictions where consent is required under applicable data protection laws to the sending of any given marketing communications.
Interest-based advertising– Device data
– Online activity data
– Consent
Compliance and protection– Any and all data types relevant in the circumstances– Compliance with Law.

– Legitimate interest. Where Compliance with Law is not applicable, we and any relevant third parties have a legitimate interest in participating in, supporting, and following legal process and requests, including through co-operation with authorities. We and any relevant third parties may also have a legitimate interest of ensuring the protection, maintenance, and enforcement of our and their rights, property, and/or safety.
Research and development to create aggregated, de-identified and/or anonymized data– Any and all data types relevant in the circumstances– Legitimate interest. We have legitimate interest, and believe it is also in your interests, that we are able to take steps to ensure that Eves operate as intended.
Further uses– Any and all data types relevant in the circumstances– The original legal basis relied upon, if the relevant further use is compatible with the initial purpose for which the personal information was collected. 

– Consent, if the relevant further use is not compatible with the initial purpose for which the personal information was collected.

Other info

Sensitive personal information. Where the collection of your sensitive personal information is required to operate Eve, we obtain your explicit consent to collect such information about you. Sensitive information includes information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background or trade union membership. You are free to make sensitive information public on the Community Forum (such as your political opinions and religious beliefs) but remember that this information is visible to other users.

Automated Decision-Making and Profiling. We are not making automated decisions about you. We may use profiling in regard to your personal information required to operate some of our services, for example, to the extent needed to predict menstrual health-related effects that you may experience from one month to the other. You can object to such profiling by contacting us at privacy@glowing.com.

Your rights

General. European data protection laws give you certain rights regarding your personal information. If you are located in Europe, you may ask us to take the following actions in relation to your personal information that we hold:

  • Access. Provide you with information about our processing of your personal information and give you access to your personal information.
  • Correct. Update or correct inaccuracies in your personal information.
  • Delete. Delete your personal information where there is no lawful reason for us continuing to store or process it, where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal information to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons that will be described to you, if applicable, at the time of your request.
  • Portability. Port a machine-readable copy of your personal information to you or a third party of your choice, in certain circumstances. Note that this right only applies to automated information for which you initially provided consent for us to use or where we used the information to perform a contract with you.
  • Restrict. Restrict the processing of your personal information, if, (i) you want us to establish the personal information’s accuracy; (ii) where our use of the personal information is unlawful but you do not want us to erase it; (iii) where you need us to hold the personal information even if we no longer require it as you need it to establish, exercise or defend legal claims; or (iv) you have objected to our use of your personal information but we need to verify whether we have overriding legitimate grounds to use it.
  • Object. Object to our processing of your personal information where we are relying on legitimate interests (or those of a third party) and there is something about your particular situation that makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedom – you also have the right to object where we are processing your personal information for direct marketing purposes.
  • Withdraw Consent. When we use your personal information based on your consent, you have the right to withdraw that consent at any time. This will not affect the lawfulness of any processing carried out before you withdraw your consent. 

Exercising These Rights. You may submit these requests by email to privacy@glowing.com or by submitting a request on our website. We may request specific information from you to help us confirm your identity and process your request. Whether or not we are required to fulfill any request you make will depend on a number of factors (e.g., why and how we are processing your personal information), if we reject any request you may make (whether in whole or in part) we will let you know our grounds for doing so at the time, subject to any legal restrictions.  

Your Right to Lodge a Complaint with your Supervisory Authority. In addition to your rights outlined above, if you are not satisfied with our response to a request you make, or how we process your personal information, you can make a complaint to the data protection regulator in your habitual place of residence. 

  • For users in the European Economic Area – the contact information for the data protection regulator in your place of residence can be found here: https://edpb.europa.eu/about-edpb/board/members_en
  • For users in the UK – the contact information for the UK data protection regulator is below:

The Information Commissioner’s Office
Water Lane, Wycliffe House
Wilmslow – Cheshire SK9 5AF
Tel. +44 303 123 1113
Website: https://ico.org.uk/make-a-complaint/

Cross-border data transfer

After collecting personal information directly from you, we further transfer your personal information to some recipients which may be located in countries in respect of which either the European Commission and/or UK Government (as and where applicable) has issued adequacy decisions, in which case, the recipient’s country is recognized as providing an adequate level of data protection under EEA/UK data protection laws (as applicable) and the transfer is therefore permitted under Article 45 of the GDPR.

Some recipients of your personal data may be located in countries outside the EEA and/or the UK for which the European Commission or UK Government (as and where applicable) has not issued adequacy decisions in respect of the level of data protection in such countries (“Restricted Countries”). For example, the United States is a Restricted Country. Where we transfer your personal information to a recipient in a Restricted Country, we will either:

  • enter into appropriate data transfer agreements based on so-called Standard Contractual Clauses approved from time-to-time under GDPR Art. 46 by the European Commission, the UK Information Commissioner’s Office or UK Government (as and where applicable); or
  • rely on other appropriate means permitted by the EU GDPR/UK GDPR, which establish that such recipients will provide an adequate level of data protection and that appropriate technical and organizational security measures are in place to protect personal information against accidental or unlawful destruction, loss or alteration, unauthorized disclosure or access, and against all other unlawful forms of processing.

You can obtain further information or a copy of or access safeguards under which your personal information is transferred outside of Europe by contacting us at privacy@glowing.com.