IoT Privacy White Paper - Xiaomi

3.3 Mi Scooter and Privacy

Introduction

The Mi scooter provides users with a new means of enjoyment. It has a compact design and is easy to carry, whilst offering power and a fashionable appearance. Users are able to view the scooter's general functions via the display panel, including, speed, gear, on/off light functions and battery BMS system information. It is also possible to check this information in Xiaomi/Mi Home app, which allows for the easy management of MI Scooter devices. Additional functions such as Taillights-always-on and Energy-recovery-intensity are also available via the Xiaomi/Mi Home app.

The device does not have a GPS function, so the specific location information of the device cannot be obtained. Information such as battery info, speed and mileage during use is only transmitted via the Xiaomi/Mi Home app secure protocol between the device and the application end, and will not be uploaded to the server.

Data Collection and Usage

1) Pairing with Device and Synchronizing Data

When you try to register the device, we will collect the Mi Account ID, MAC address and SN of the device to record ownership and to connect you to the device.

2) Basic Functions

We will collect information such as i) electricity usage, ii) remaining mileage, iii) temperature and iv) battery information in the Xiaomi/Mi Home app, which is used to display the status information of the device on the Xiaomi/Mi Home app plug-in. For the lock function, a user-defined PIN Code1 is stored locally in the app and will not be uploaded to the server.

3) Status Record

We will collect the chosen settings of the Taillights-always-on, Energy-recovery-intensity, Cruise-control and other functions to the Xiaomi/Mi Home app to set the above functions on the app side. After disconnecting, the settings information is stored in the device, and the data in the app will be cleared. As with the data used for basic functions, this data is stored locally and will not be uploaded to the server.

4) Data Analysis

We collect product interaction data (e.g., clicks, failed connections, viewing activities) from the Xiaomi/Mi Home app plug-in for statistical analysis on usage of the product and status of these functions. Such data is only collected if you have previously agreed to join the User Experience Improvement Program.

Privacy by Design

The Mi Scooter only collects the necessary information for displaying the speed calculation, scooter gear and any changes made. The data collected by the Xiaomi/Mi Home app, such as: i) battery information, ii) device information and iii) speed/mileage, is processed, calculated and displayed locally without uploading to the server for storage. In addition, a unique lock function switch is also provided. The PIN Code1 required to lock the device is defined by the user and is also stored locally in the app.

Appendix 3: Data Inventory for Mi Scooter

TypeType of DataIdentification QualifierPurposeData Transmission Encryption MeasuresData Storage Encryption MeasuresData Retention Policy
IdentifiersMi Account ID
Identified
App Functionality
Device Functionality
Analytics

HTTPS

No Encryption

Per user's request
MAC
Identified
App Functionality
Device Functionality
Analytics

HTTPS

No Encryption

Per user's request
SN
Identified
App Functionality
Device Functionality

No Transmission
Not StoredNot Applicable
Usage DataProduct Interaction
Identified
Analytics

HTTPS

AES-128

Per user's request
DiagnosticsCrash Data
Identified
Analytics

HTTPS

AES-128

AES-128

Factory Reset

Per user's request
Performance Data
Identified
Analytics

HTTPS

AES-128

AES-128

Factory Reset

Per user's request
Other DataPIN Code1
Identified
App Functionality
Device Functionality

No Transmission

No Encryption

User Unset in App
Basic Functions Information
Identified
App Functionality
Device Functionality
Analytics

BLE

No Encryption

Factory Reset
Status Record Information
Identified
App Functionality
Device Functionality
Analytics

BLE

No Encryption

Factory Reset


Note

1 Certain types of devices may not support this function.