Fitness Tracker App / Device Privacy Policy

WITHit Privacy Policy - Apps

Effective and Last Updated: September 10, 2026

Applicability: United States only

Related notice: Consumer Health Data Notice (Washington, Nevada, and similar state laws)

Please Read This Policy Together with Our Terms of Use

This Privacy Policy is a transparency notice describing our data practices. It is not a standalone contract and does not, by itself, create an agreement to arbitrate, a warranty, or a license of intellectual property rights. This Policy does not create rights or remedies except as required by applicable law. Failure to restate a statutory exception in this Policy does not waive that exception.

The binding contract that governs your use of the Services---including dispute resolution, arbitration, limitation of liability, intellectual property licenses, and product disclaimers---is the WITHit Terms of Use, which you accept when you create an account. If you do not agree with this Policy or the Terms of Use, do not create an account or use the Services.

This Policy is provided in English. If we make a translation available, the English version controls to the extent permitted by law. If you need this Policy in an alternative format because of a disability, contact us using the information in Section 18.

Who We Are and Where This Policy Applies

Sol-Light, LLC dba WITHit ("WITHit," "we," "us," or "our") provides consumer wellness smartwatches, fitness tracking devices, a companion mobile application, and related technical support (collectively, the "Services," and the hardware as the "Devices"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use the Services in the United States.

We designed the Services exclusively for the United States market. We do not offer the Services to residents of the European Economic Area, United Kingdom, Switzerland, or other non-U.S. jurisdictions, and we do not monitor the Services for compliance with non-U.S. privacy laws. The Services are intended only for individuals located in the United States. We do not knowingly offer the Services to non-U.S. residents. If we reasonably determine that an account is used from outside the United States or belongs to a non-U.S. resident, we may refuse, suspend, or delete the account and associated cloud data. If you access the Services from outside the United States, you do so on your own initiative and are responsible for compliance with local laws.

This Policy covers the Devices, the companion App, Device-related customer support, and cloud accounts created in the App. It does not govern browsing, cookies, or checkout on our online store at withitgear.com. That storefront has a separate privacy policy, which is posted on the store and controls information collected there (including storefront analytics, advertising technologies, and purchase checkout). If you buy a Device on that store and later create an App account, this Policy applies to the App account and Device data; the storefront policy continues to apply to the store transaction.

A short notice of collection is presented in the App at or before the point we collect personal information there. That notice summarizes categories, purposes, our statement that we do not sell or share personal information collected through the Services for cross-context behavioral advertising, and retention, and links to this Policy for the full description.

1. Product and Legal Disclaimers

1.1 Not a Medical Device; Not Medical Advice

The Services and Devices are consumer wellness and fitness products only. They are not medical devices. They are not designed, manufactured, cleared, approved, or intended to diagnose, treat, cure, mitigate, or prevent any disease, illness, or medical condition, and they are not a substitute for professional medical advice, diagnosis, or treatment.

Metrics displayed by the Services---including steps, calories, active minutes, heart rate, sleep staging, and similar outputs---are estimates generated by consumer-grade sensors and algorithms. They may be incomplete, delayed, or inaccurate. Do not change medication, treatment, or emergency plans based on Device or App data. Always consult a licensed physician or other qualified healthcare professional before beginning an exercise program or relying on wellness data. The Services are not an emergency service and will not contact 911 or emergency responders on your behalf.

1.2 Not HIPAA Protected Health Information

WITHit is not a "covered entity" or "business associate" under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") when providing the consumer Services described in this Policy. Information we process is not "protected health information" (PHI) under HIPAA. It may still be classified as "personal information," "sensitive personal information," or "consumer health data" under state law, and we handle it strictly in accordance with this Policy and the Consumer Health Data Notice.

1.3 Health and Sensitive Data --- Limited Operational Processing

Certain metrics---such as continuous heart rate, sleep duration and staging, activity intensity, height, weight, age, and precise workout location---are treated as sensitive personal information or consumer health data under applicable U.S. state laws. We collect and process that information only:

  • To provide the specific tracking features you affirmatively request or enable;
  • To secure and operate the Services;
  • To comply with statutory obligations; and
  • As otherwise explicitly detailed in this Policy and the Consumer Health Data Notice.

We limit personal information to what is reasonably necessary to provide the Services you request. We limit consumer health data, precise workout geolocation, and other sensitive personal information to what is strictly necessary to operate the specific feature you enable. We do not collect sensitive information to infer unrelated characteristics (for example, medical diagnoses, reproductive or sexual status, or protected classifications beyond the optional profile fields you enter).

We do not use sensitive personal information or consumer health data for cross-context behavioral advertising, and we do not sell it. We do not collect continuous background location. Precise geolocation is collected only when you start an outdoor workout and grant location permission, as described in Section 8. Optional features that collect additional sensitive information (such as notification relay) remain off by default until you deliberately enable them in the App or your mobile operating system settings.

2. Information We Collect

We collect information from you, your Devices and the App, your mobile operating system when you grant permissions, and bound service providers supporting the Services. We do not require optional profile fields for basic step tracking.

2.1 Information You Provide

  • Account Information: Email address, phone number, password credentials, and account preferences. If you register through a third-party sign-in provider (such as Apple or Google), we receive identifiers and profile fields authorized by that platform (for example, name or avatar).
  • Profile Metrics You Choose to Enter: Age, date of birth, gender or sex, height, weight, nickname, profile photo, and preferred units of measurement. These fields calibrate metabolic expenditure calculations (such as caloric burn) and personalize dashboards.
  • Support and Communications: Content of emails, in-App chats, call notes, feedback, warranty/return documentation, and diagnostic attachments you send to us.
  • Purchase and Fulfillment Information: If we fulfill a Device or accessory order or a warranty replacement: name, shipping address, phone number, items ordered, and order status. Purchases made on our Shopify storefront are also described in that store's privacy policy. Payment card processing is executed by a third-party payment processor, Shopify, or the mobile app-store operator; we do not store full payment card numbers.

2.2 Information from Devices and the App

  • Fitness and Wellness Activity Data: Steps, distance estimates, active minutes, workout type, duration, and exercise logs synchronized from a paired Device over Bluetooth Low Energy (BLE).
  • Physiological and Sleep Metrics: Heart-rate readings, heart-rate variability, sleep duration, and sleep staging (light, deep, REM) if supported by your Device hardware and firmware.
  • Device State: Battery status, firmware version, pairing state, sensor availability, and watch-face metadata required to maintain synchronization and provide technical support.
  • Precise Geolocation Data (Workout Only): If you initiate an outdoor workout and grant location permissions, the App collects precise GPS coordinates to map routes and calculate pace. We do not use location data to market, build advertising profiles, or geofence healthcare facilities.
  • Technical and Diagnostic Data: Hardware model, OS version, App version, unique persistent installation identifiers, IP address, approximate coarse location derived from IP, Bluetooth logs, crash traces, and performance diagnostics.

2.3 Information We Do Not Collect

We do not collect fingerprints, retina or iris scans, voiceprints, or scans of hand or facial geometry. We do not use profile photos to extract biometric templates or uniquely identify individuals. We do not inspect, intercept, or store the contents of phone calls or text messages; notification relay operates as a transient on-device pass-through (Section 8). We do not collect Social Security numbers, government-issued IDs, precise financial credentials, genetic data, or neural data.

2.4 Inferences

We generate trends, totals, and dashboard summaries from your activity and sleep data (such as weekly sleep-score trends). These inferences are used exclusively to deliver the companion wellness dashboard you requested. We do not use inferences to make automated decisions that produce legal or similarly significant effects regarding credit, insurance, housing, or employment, and we do not sell them.

3. California / CPRA Disclosures (Last 12 Months)

The table below outlines the categories of personal information collected, sources, business purposes, recipients, and specific data retention criteria in compliance with the California Consumer Privacy Act (as amended by the CPRA). We do not sell personal information or share it for cross-context behavioral advertising, and we have no actual knowledge of selling or sharing data of consumers under 16 years of age.

We process sensitive personal information only to provide the Services a reasonable consumer would expect, to resist security incidents, and as otherwise permitted by Cal. Civ. Code § 1798.121(a). We do not use or disclose sensitive personal information to infer characteristics about you beyond delivering the features you enable. Accordingly, a separate "Limit the Use of My Sensitive Personal Information" control is not required for our current practices. If that changes, we will provide the required notice and control.

CPRA Category

Examples of Information Collected

Sources

Disclosed for a Business Purpose To

Retention Period / Criteria

Identifiers

Email, phone, account ID, Device/App ID, IP address, de-identified nickname, profile photo

User; Device/App; sign-in providers

Cloud hosting, communications vendors, customer support platforms, security vendors (processors)

Active account lifecycle; deleted or de-identified from production systems within 45 days of verified account closure, subject to Section 10 exceptions.

Customer Records

Name, account profile, profile photo, shipping address (if provided for a purchase or direct fulfillment), order history we receive, support logs

User; App; fulfillment houses, payment processors, Shopify storefront (if you later link a purchase to an App account), Device support tools

Fulfillment houses, payment processors, customer support platforms

Commerce and order records retained for tax/warranty duties, up to 7 years; support logs retained up to 3 years.

Protected Classifications

Self-reported age/date of birth, biological sex or gender (optional)

User (optional)

Cloud hosting provider (storage only; not used for marketing)

Active account lifecycle; deleted from production systems within 45 days of account deletion, subject to Section 10 exceptions.

Commercial Information

Device purchased, warranty records, in-App feature interactions

User; authorized retailers; Device/App

Cloud infrastructure, warranty management, and diagnostic providers

Up to 7 years, in accordance with consumer protection, tax, and warranty laws.

Internet / Network Activity

Screens viewed, feature flags, crash reports, Bluetooth connection logs

Device/App; diagnostic tools

Cloud hosting, crash analysis, and security infrastructure providers

Diagnostic and security logs retained up to 12 months, unless required longer to resolve a security event or legal hold.

Geolocation Data (Precise)

GPS coordinates and route tracks during outdoor workouts you start

Device/App (with operating-system permission)

Cloud host (storage); mapping-tile APIs (transient rendering only)

Until the workout is deleted by the user, or from production systems within 45 days of verified account closure, subject to Section 10 exceptions.

Inferences

Activity totals, weekly sleep trends, calculated calorie metrics

Algorithmic derivation from collected metrics

Cloud infrastructure provider (processor)

Active account lifecycle; deleted from production systems within 45 days of account deletion, subject to Section 10 exceptions.

Sensitive Personal Information

Account credentials; precise workout GPS; heart-rate, sleep, and metabolic metrics

User; paired Device sensors

Cloud hosting, security, and support infrastructure (processors only)

Active account lifecycle; deleted from production systems within 45 days of verified account closure, subject to Section 10 exceptions.

This table also serves as our California notice-at-collection summary when presented at or before collection, together with the short in-App and website collection notice.

4. How We Use Information

We process personal information exclusively for the following operational business purposes:

  • Core Functionality: Authenticating accounts, synchronizing Device firmware, mapping exercise routes, and presenting historical wellness dashboards.
  • Algorithmic Computations: Estimating calories burned, active duration, sleep cycles, and daily activity trends.
  • Communications: Transmitting transactional messages, account security alerts, multi-factor verification codes, and administrative software updates. We do not send marketing text messages without separate consent. Transactional and security messages may be sent to the email address or phone number associated with your account.
  • Customer Care: Resolving warranty requests, fulfilling hardware replacements, and debugging application crashes.
  • Security & Fraud Prevention: Detecting unauthorized access, mitigating software exploits, investigating abuse, and protecting system integrity.
  • Platform Improvement: Optimizing firmware performance, Bluetooth connectivity, and algorithmic accuracy. We use aggregated or de-identified information for this purpose. We do not use identifiable Consumer Health Data, identifiable heart-rate or sleep-stage data, or precise workout geolocation for general product research or to train models---internally or for third parties---except as needed to debug a problem you report or to secure the Services. We do not use that identifiable data to train general-purpose models, and we do not license, sell, or transfer models trained on identifiable Device metrics.
  • Legal Compliance: Satisfying statutory obligations, establishing or defending legal claims, and cooperating with valid civil or criminal legal process.

We never process personal information or sensitive metrics for automated decision-making that produces legal or similarly significant effects. If this changes, or as new automated decision-making technology regulations (including the California Privacy Protection Agency's ADMT rules, with compliance obligations phasing in beginning January 1, 2027) come to apply to our practices, we will update this Policy and provide any required notice, access, and opt-out rights before those rules take effect.

5. Consumer Health Data Notice (Washington MHMDA, Nevada SB 370, and Similar State Health Laws)

This Section constitutes our Consumer Health Data Notice under the Washington My Health My Data Act (RCW Chapter 19.373), Nevada Senate Bill 370 (NRS Chapter 603A), and comparable state health-data statutes. It applies to personal information that identifies or is used to identify your physical or mental health status. A standalone copy of this Notice is also published for homepage and in-App linking as required by those statutes.

5.1 Categories of Consumer Health Data Collected

  • Bodily Function Telemetry: Real-time, resting, and historical heart-rate readings; heart-rate variability.
  • Sleep Telemetry: Sleep duration, awakenings, and sleep-stage estimations (light, deep, REM).
  • Physical Activity Records: Exercise type, workout cadence, active minutes, and calculated metabolic energy expenditure.
  • Physiological Metrics: Self-reported height, weight, age, and sex/gender to calibrate calorie estimates.
  • Precise Workout Geolocation: Outdoor workout routes combined with heart-rate and cadence metrics.

5.2 Sources of Consumer Health Data

  • You, when you enter profile metrics, start a workout, or submit a support ticket that includes telemetry.
  • Your paired WITHit Device sensors and firmware, when you enable the relevant feature.
  • The companion App and your mobile operating system, when you grant the permissions required for a feature you enable.
  • Sign-in providers, only to the extent a linked account identifier is needed to associate health data with your account.

5.3 Specific Purposes of Health Data Processing

We collect and process Consumer Health Data exclusively to operate the wellness tracking, algorithmic summary, and history features you affirmatively choose to use within the App, to secure those features, and to comply with law. We do not collect, process, or disclose Consumer Health Data for marketing, contextual tracking, or advertising. We do not sell Consumer Health Data.

Where a feature you request cannot function without Consumer Health Data (for example, heart-rate tracking you enable), we collect and process that data as necessary to provide that feature. We still present an unbundled in-App opt-in before first collection from a paired Device. Separate consent is required before we export Consumer Health Data to a third-party platform that is not our processor.

5.4 Processors, Third Parties, and Affiliates

We disclose Consumer Health Data to bound processors providing operational infrastructure. That disclosure is processing on our behalf, not a "share" or "sale" to a third party. We do not share or sell Consumer Health Data to third parties except at your direction. We do not disclose Consumer Health Data to affiliates for the affiliates' own purposes. Sol-Light, LLC dba WITHit does not currently share Consumer Health Data with any affiliate for that affiliate's independent commercial use.

Categories of processors that receive Consumer Health Data:

  • Cloud infrastructure and database hosting vendors (encrypted data storage and compute execution in the United States);
  • Customer-support and diagnostic systems (accessible only if you submit tickets containing telemetry or grant a support specialist access);
  • Security, logging, and crash-analysis vendors, limited to the telemetry needed to investigate an incident you or the system reports;
  • Professional legal or accounting advisors when reasonably necessary to establish, exercise, or defend legal claims or to satisfy an audit or tax obligation.

Mapping tile providers may receive transient coordinates solely to render a route map you requested; they are not authorized to retain Consumer Health Data for their own purposes.

Each processor is bound by written contract to process Consumer Health Data only on our documented instructions and is barred from retaining, using, or disclosing the data for any secondary purpose. If a processor uses Consumer Health Data for its own purposes, that party is no longer acting as our processor for that use.

If you choose to connect third-party platforms (such as Apple Health or Google Health Connect), that transmission occurs solely at your direction (Section 6.3) and is a disclosure to a third party, not a processor, after you give separate consent.

We do not authorize third parties to collect Consumer Health Data over time and across different websites or online services when you use our website or App for those third parties' own purposes.

5.5 Separate, Standalone Opt-In Consent

We do not bundle consent for collecting Consumer Health Data into our Terms of Use or general account creation.

  • Collection: We require an explicit, unbundled affirmative opt-in screen in the App prior to collecting or processing any Consumer Health Data from your paired Device, except to the limited extent collection is necessary to provide a feature you have already requested and enabled.
  • Sharing: We require separate, express consent prior to exporting your data to third-party ecosystems that are not our processors (for example, Apple Health).
  • Withdrawal: You may withdraw consent at any time without fee or penalty via App Settings > Health Data Permissions or by contacting support@withitgear.com. Upon withdrawal, new collection and new sharing for the withdrawn feature cease. Withdrawal does not by itself delete data we already stored; that data remains until you request deletion under Section 5.7 and Section 10, subject to the exceptions in those sections. You may continue to use non-health functions of your Device (clock, alarms, stopwatch).

5.6 Geofencing Ban

We do not implement or use a geofence around any facility that provides in-person healthcare services (including clinics, hospitals, pharmacies, or counseling centers) to identify, track, collect health data from, or target consumers.

5.7 Consumer Health Data Rights

Subject to identity verification and statutory exceptions, you have the right to:

  • Confirm whether we collect, share, or sell your Consumer Health Data;
  • Access a portable copy of that data;
  • Obtain a list of third parties and affiliates with whom we have shared or to whom we have sold your Consumer Health Data, together with an email address or other online mechanism you may use to contact those parties where we have such a mechanism;
  • Withdraw consent for collection or sharing;
  • Request that we stop collecting or sharing your Consumer Health Data; and
  • Request deletion of your Consumer Health Data from our records, including production systems and, on the timeline in Section 5.8, archived or backup systems, and that we notify processors and other recipients to delete it as required by law.

To exercise these rights, email support@withitgear.com with the subject line "Consumer Health Data Request." You may appeal any denial by following the process in Section 14.6.

5.8 Deletion Timing for Consumer Health Data

After we authenticate a Consumer Health Data deletion request, we will delete that data from active production systems and instruct our processors to do the same without undue delay, and in any event within 45 days. Data residing solely on inactive archived or backup systems will be overwritten or otherwise put beyond use in the ordinary backup cycle, not to exceed six months after authentication, except where a longer period is required by law or a documented legal hold. Data you already exported to Apple Health, Google Health Connect, or another platform you control is outside our deletion scope. We will also notify processors, contractors, and other recipients as required by applicable health-data law.

5.9 Material Changes to This Health Data Notice

If we collect new categories of Consumer Health Data, use it for new purposes, or disclose it to new categories of third parties or affiliates not described here, we will update this Notice, provide prominent notice, and obtain any additional consent required by law before applying those changes to historical Consumer Health Data.

6. How We Disclose Information

We disclose personal information only as described below:

6.1 Service Providers and Processors

We share information with vendors that provide infrastructure hosting, transactional messaging (email/SMS), payment processing, crash diagnostics, and professional legal/accounting counsel. These parties are contractually prohibited from selling, retaining, or using personal information for any secondary purpose outside their services for us.

6.2 Cloud Hosting

App backend databases and infrastructure are hosted on enterprise cloud servers located in the United States. Personal information is protected with industry-standard encryption in transit and at rest (currently TLS 1.2 or higher in transit and AES-256 or equivalent at rest). We do not authorize our hosting providers to access or use your personal information for their own commercial purposes.

6.3 Connected Health Platforms

If you elect to link Apple Health, Google Health Connect, Google Fit, or compatible platforms, the App reads and writes only the data categories you select in the operating system's permission dialog, after separate consent where required. Once transmitted, that data becomes subject to the third party's privacy policy, and we are not responsible for that party's practices. You can sever these integrations at any time within App Settings. Enabling an export does not allow us to retrieve or delete the copy held by the third party.

6.4 Corporate Transactions

In the event of a merger, acquisition, corporate reorganization, bankruptcy, or asset sale, personal information may be transferred to the acquiring entity. We will require the successor to handle personal information consistent with this Policy and will provide any statutory advance notice. If applicable health-data law treats the transfer of Consumer Health Data as a share or sale that requires additional consent or authorization, we will not complete that transfer of Consumer Health Data until we can do so lawfully, or we will delete or de-identify the Consumer Health Data instead.

6.5 Legal and Safety Disclosures

We disclose personal information if required in good faith to comply with a valid court order, search warrant, subpoena, or statutory mandate; to enforce our Terms of Use; or to defend against fraud, immediate security threats, or unlawful activity.

6.6 At Your Direction

We disclose data when directed by you---such as exporting a workout summary via email or granting a support specialist access to assist with an open issue.

6.7 De-Identified Information

We may share aggregated or de-identified data that cannot reasonably be linked to an individual. We commit to maintaining and using such information solely in de-identified form and do not attempt to re-identify it (except to validate internal de-identification protocols). We contractually bind all third-party recipients of de-identified data to maintain it in de-identified form and prohibit any re-identification attempts.

7. Sale, Sharing, and Targeted Advertising

For the Services covered by this Policy (the Devices, companion App, cloud account, and related support), WITHit does not sell personal information as "sell" is defined under the CCPA/CPRA or other state privacy laws, does not share that personal information for cross-context behavioral advertising, and does not process that data for targeted advertising. Because those Services do not sell or share personal information, a "Do Not Sell or Share My Personal Information" link is not required on the App for those activities; this Policy states that we do not sell or share information collected through the Services. Practices on our Shopify storefront---including any cookies, pixels, or advertising technologies used there---are described in the storefront privacy policy, not this Policy.

7.1 Opt-Out Preference Signals / Global Privacy Control (GPC)

Because the Services covered by this Policy do not engage in sales, cross-context behavioral advertising, or targeted advertising, opt-out requests are not needed to halt those disclosures for App and Device data. Web pages we control outside the Shopify storefront recognize and honor valid universal opt-out signals, including the Global Privacy Control (GPC), at the browser/device level without requiring account creation. How the Shopify storefront treats GPC and similar signals is described in the storefront privacy policy.

8. Mobile Device Permissions

The App requests mobile operating system permissions strictly to deliver companion features. You may revoke permissions at any time via your smartphone settings:

  • Bluetooth: Required to pair, sync, and maintain hardware connectivity.
  • Location (Precise GPS): Used exclusively when recording an outdoor workout route. Certain Android versions mandate location permissions for local Bluetooth Low Energy discovery; this operating system requirement is not used to track your location. Continuous background location is disabled by default.
  • Notifications: Used to deliver transactional system alerts and goal notifications.
  • Call and SMS Alert Relay (Optional): If enabled, incoming caller ID and SMS previews are relayed across local Bluetooth to your Device screen. This operation is executed as a transient, on-device pass-through. WITHit does not upload, store, or read call audio, call logs, or message text on its cloud servers.

9. Cookies and Analytics

The App employs strictly necessary local storage to maintain authenticated sessions and manage account security. We use first-party analytics and bound processor analytics in the App to evaluate reliability and identify software defects. Those tools operate under written contracts that prohibit advertising use of identifiable personal information. We do not deploy third-party advertising cookies, marketing pixels, or ad-network SDKs in the App.

Cookies, pixels, and analytics on our Shopify storefront are governed by the storefront privacy policy. GPC recognition described in Section 7.1 applies to web pages we control that are not the Shopify storefront; the storefront policy describes how that site treats opt-out signals.

10. Data Retention and Account Deletion

We retain personal information only for the duration necessary to fulfill the business purposes specified in this Policy, satisfy warranty and tax duties, resolve disputes, and comply with legal holds. When retention obligations expire, data is permanently erased or de-identified in accordance with Section 3 and this Section 10.

10.1 Account Deletion Procedure

You can delete your cloud account at any time directly within the App (Settings > Account > Delete Account) or by emailing support@withitgear.com from the address associated with your profile. Following identity verification, your personal and wellness data will be purged or irreversibly de-identified from active production systems within 45 calendar days, except:

  • Records we must keep under tax, warranty, accounting, or other law (for example, commerce records for up to 7 years);
  • Information retained under a documented legal hold, which is deleted when the hold is released;
  • Security and diagnostic logs retained for the periods in Section 3;
  • Consumer Health Data on inactive archived or backup media, which is put beyond use within six months as described in Section 5.8; and
  • Copies you already directed us to send to a third party (including Apple Health, Google Health Connect, a retailer, or an email recipient).

Deleting your cloud account does not erase data saved locally on your physical watch or phone storage. To wipe local hardware, initiate an unpair/factory reset on your Device and clear App storage.

10.2 Guest and Offline Modes

If you utilize the App without creating an authenticated account, your fitness logs remain confined to local device memory. Offline data is never uploaded to our servers, cannot be synced across multiple devices, and cannot be retrieved or remotely deleted by WITHit.

11. Information Security

We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the wellness and account data we process. Safeguards include:

  • Industry-standard encryption of data in transit (currently TLS 1.2 or higher) and at rest (currently AES-256 or equivalent);
  • Multi-factor administrative authentication and role-based access controls;
  • Logging of administrative access to production environments; and
  • Contractual vetting and data-protection mandates for technical vendors.

You are responsible for selecting a unique, complex account password and keeping your mobile operating system updated. If you detect unauthorized activity on your account, notify us immediately at support@withitgear.com.

12. Security Incidents and Breach Notification

We follow applicable state and federal law regarding notification of any breach of security involving your personal information. If a breach involves unsecured PHR identifiable health information, we will also notify affected individuals, the Federal Trade Commission, and others as required by the FTC Health Breach Notification Rule, 16 C.F.R. Part 318. We will not treat a disclosure that you directed (for example, an export you enable to Apple Health) as a breach. We will provide any required notification without unreasonable delay and within the timeframes required by the applicable law.

13. Your Choices and Controls

  • Profile Fields: Profile attributes (height, weight, gender) remain voluntary. Step tracking operates without completing these fields.
  • Hardware Permissions: Revoke location, notification relay, or Bluetooth access in device settings at any time.
  • Email Preferences: Unsubscribe from non-essential emails using the link provided in the message. Transactional security notices and verification messages cannot be disabled while an account remains active.
  • Text Messages: We do not send marketing SMS without separate consent.
  • Incentive Disclosures: We do not operate financial-incentive or "pay-for-privacy" programs.

14. U.S. State Privacy Rights

Residents of states that have enacted comprehensive consumer privacy statutes---including, without limitation, California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island, and any other state law that applies to us---may have some or all of the rights below, as provided by their state's statute and subject to that statute's exceptions, applicability thresholds, and verification rules. Some laws apply when we process sensitive data of even a single resident of that state.

14.1 Summary of Statutory Rights

  • Access and Portability: Request confirmation of data processing and obtain an electronic, machine-readable copy of your personal data.
  • Correction: Request correction of inaccurate personal data we maintain about you.
  • Deletion: Request deletion of personal data collected from or about you, subject to statutory retention exceptions and Section 10.
  • Opt-Out Rights: Opt out of data sales, targeted advertising, and automated profiling that produces legal or similarly significant effects (WITHit does not engage in these activities).
  • Limit Sensitive Data Use (California and similar laws): We process sensitive personal information only to deliver core companion services you request and for permitted security and legal purposes. We do not use sensitive information to infer secondary personal characteristics.
  • Specific Third Parties (Minnesota and similar laws): Where required, you may request a list of the specific third parties to which we have disclosed your personal data or, if we do not keep that information at the consumer-specific level, a list of specific third parties to which we have disclosed any consumer's personal data.
  • Non-Discrimination: We will not deny services, charge different prices, or degrade service quality because you exercise your statutory privacy rights.

14.2 Submitting a Privacy Rights Request

To submit an access, correction, deletion, or recipient-list request, email support@withitgear.com with the subject line "Privacy Rights Request" or call our toll-free line at (800) 701-9484. We may decline a request that we cannot verify, that is manifestly unfounded or excessive, or that seeks information we are not required to retain. We are not required to retain personal information in an identifiable form solely to fulfill future requests.

14.3 Identity Verification

To safeguard your data, we verify identity by matching the email address and profile identifiers you provide against our internal account database, followed by an email-confirmation loop. We will not ask you to upload government identification documents solely for routine verification. If that loop is insufficient (for example, suspected account takeover), we may use another reasonably reliable method.

14.4 Authorized Agents

Where permitted by statute, you may designate an authorized agent to act on your behalf. We require written proof of authorization signed by you and may require direct identity verification before fulfilling the agent's request, unless the agent presents a valid power of attorney executed under applicable state law.

14.5 Response Timelines

We will acknowledge receipt of your request and provide a substantive response within 45 calendar days. When reasonably necessary due to complexity, we may extend the response period by an additional 45 days upon providing written notice explaining the delay, or as otherwise permitted by the applicable statute.

14.6 Appeals and Direct Regulatory Escalation

If we deny your privacy request in whole or in part, you may lodge an administrative appeal by emailing support@withitgear.com with the subject line "Privacy Appeal" within 45 days of the denial. We will evaluate the appeal and issue a written determination within 45 days.

If your appeal is denied or unaddressed, you may have the right to escalate your complaint to your state regulator, including:

  • Washington Residents: Washington State Attorney General, Consumer Protection
  • Nevada Residents: Nevada Attorney General
  • California Residents: California Privacy Protection Agency (CPPA) or the California Attorney General
  • Colorado Residents: Colorado Attorney General
  • Texas Residents: Texas Attorney General
  • Oregon Residents: Oregon Department of Justice
  • Connecticut Residents: Connecticut Attorney General
  • Maryland Residents: Maryland Attorney General
  • All Other States: The Attorney General or comparable privacy regulator of your state of residence, to the extent that state's law provides a right of escalation.

14.7 California Shine the Light Disclosure

California Civil Code § 1798.83 allows California residents to request details regarding disclosures of personal data to third parties for those third parties' direct marketing. We do not share personal data with third parties for their direct marketing purposes.

15. Children and Minors' Privacy

The Services are designed and intended for adults. You must be at least 18 years of age, or the age of majority in your jurisdiction if higher, to create an account or use the cloud features of the Services.

  • We do not knowingly collect personal information from children under 13, and we do not permit account registration by anyone under 18.
  • If you believe a person under 18 has registered an account or synced a Device to our cloud services, notify us at support@withitgear.com. We will close the account and delete associated cloud data as described in Section 10.
  • We do not sell or share personal information of minors and do not use minor data for behavioral advertising or profiling.

16. Modifications to This Policy

We reserve the right to revise this Policy to reflect operational, legal, or technical changes. The updated version will be designated by the "Effective and Last Updated" date at the top.

If we implement material modifications---such as adding new categories of health data, disclosing health data to new non-processor third parties, or altering data-ownership principles---we will deliver prominent advance notice through the App or via your registered account email. Where required by state health or consumer protection laws, we will secure your affirmative opt-in consent prior to applying material expansions to historical data.

17. Non-Waivable Rights and Precedence

Nothing in this Policy waives any consumer privacy right established as non-waivable under state or federal law. In the event of an irreconcilable conflict between this Privacy Policy and the WITHit Terms of Use regarding the handling of your personal information, this Privacy Policy controls. For terms concerning intellectual property licensing, commercial warranties, limitations of liability, or arbitration, the Terms of Use control.

18. Contact Us

For questions, privacy rights requests, health-data inquiries, or security notifications:

  • Legal Entity: Sol-Light, LLC dba WITHit
  • Support and Privacy Email: support@withitgear.com
  • Telephone: (800) 701-9484
  • Mailing Address: 10161 West Park Run Drive, Las Vegas, Nevada 89145 USA

Do not submit unencrypted government identification documents, full payment card numbers, medical records, or Device data exports via email.

© 2026 Sol-Light, LLC dba WITHit. All rights reserved.

WITHit Consumer Health Data Notice

Washington My Health My Data Act • Nevada SB 370 • Similar State Health-Data Laws

Effective and Last Updated: September 10, 2026

This Consumer Health Data Notice is the standalone notice required by the Washington My Health My Data Act (RCW Chapter 19.373), Nevada Senate Bill 370 (NRS Chapter 603A), and comparable state statutes. A regulated entity must post a conspicuous homepage link to this Notice. This Notice is also Section 5 of the WITHit Privacy Policy. If this Notice and the rest of the Privacy Policy conflict on Consumer Health Data, this Notice controls.

Sol-Light, LLC dba WITHit ("WITHit," "we," "us," or "our") provides consumer wellness smartwatches and a companion mobile application (the "Services"). This Notice describes how we collect, use, disclose, and delete Consumer Health Data of U.S. consumers through the Devices and App. It does not govern our Shopify storefront, which has a separate privacy policy.

What is Consumer Health Data

"Consumer Health Data" means personal information that identifies or is reasonably capable of being associated with a consumer and that identifies the consumer's past, present, or future physical or mental health status, including the categories listed below.

Categories Collected and How We Use Them

  • Bodily function telemetry (heart rate and heart-rate variability): to display current and historical heart-rate tracking you enable.
  • Sleep telemetry (duration, awakenings, stage estimates): to display sleep history you enable.
  • Physical activity records (workout type, cadence, active minutes, estimated energy expenditure): to display activity history you enable.
  • Physiological profile metrics you enter (height, weight, age, sex/gender): to calibrate calorie and dashboard estimates.
  • Precise workout geolocation combined with heart-rate and cadence: to map outdoor routes you start and to calculate pace.

We do not collect, use, or share Consumer Health Data for marketing, advertising, or sale. We do not sell Consumer Health Data.

Sources

  • You (profile entries, workouts you start, support submissions);
  • Your paired WITHit Device when you enable a feature;
  • The companion App and operating-system permissions you grant;
  • Account identifiers from a sign-in provider, only to associate data with your account.

Categories Shared and Recipients

We disclose Consumer Health Data to processors under written contracts. That is processing on our behalf, not a "share" or "sale" to a third party. We do not share or sell Consumer Health Data to third parties except at your direction (for example, an export you enable). We do not share Consumer Health Data with affiliates for an affiliate's own purposes. Categories of processors: U.S. cloud hosting and database providers; customer-support and diagnostic tools (when a ticket or authorized support session includes telemetry); security, logging, and crash-analysis vendors; and professional legal or accounting advisors when necessary for claims, audits, or tax obligations. Mapping providers may receive transient coordinates solely to render a route you requested.

We do not authorize third parties to collect Consumer Health Data across other websites or services for those third parties' own purposes when you use our Services. If you export data to Apple Health, Google Health Connect, or a similar platform, that recipient is a third party you directed, not our processor, and that party's privacy policy applies to the exported copy.

Consent

We obtain unbundled, affirmative in-App consent before first collection of Consumer Health Data from a paired Device. Separate consent is required before export to a non-processor third-party health platform. You may withdraw consent in App Settings > Health Data Permissions or by emailing support@withitgear.com. Withdrawal stops new collection and new sharing for the withdrawn feature and does not require a fee. Withdrawal does not by itself delete data already stored; request deletion as described below. Clock, alarm, and stopwatch functions can continue.

Geofencing

We do not implement or use a geofence around any in-person healthcare facility to identify, track, collect health data from, or target consumers.

Your Rights

You may request confirmation of collection, sharing, or sale; access a copy of your Consumer Health Data; obtain a list of third parties and affiliates that received it and a contact mechanism where we have one; withdraw consent; stop collection or sharing; and request deletion. Email support@withitgear.com with the subject line "Consumer Health Data Request." We will verify your identity as described in the Privacy Policy. Appeals follow Privacy Policy Section 14.6.

Authenticated deletion requests are completed in active production systems and processor systems within 45 days. Inactive archive or backup copies are put beyond use within six months after authentication, unless law or a legal hold requires longer. We will notify processors, contractors, and other recipients as required. We cannot delete copies you already exported to a platform you control.

Material Changes

If we add categories of Consumer Health Data, purposes, or recipient categories not described here, we will update this Notice, give prominent notice, and obtain any additional consent required before applying the change to historical Consumer Health Data.

Contact

Sol-Light, LLC dba WITHit

• support@withitgear.com

• (800) 701-9484

• 10161 West Park Run Drive, Las Vegas, Nevada 89145 USA.

© 2026 Sol-Light, LLC dba WITHit. All rights reserved.