Privacy & Compliance

Privacy-First Proximity Infrastructure

HIVE is built on explicit consent, data minimization, and transparency. We never sell consumer data and enforce strict compliance with global privacy regulations.

Explicit Opt-In

Consumers must actively opt in before receiving any proximity notifications. No implicit consent, no pre-checked boxes.

Encryption Everywhere

AES-256 encryption at rest and TLS 1.3 in transit. All data is encrypted end-to-end between devices and servers.

GDPR Compliant

Full compliance with the General Data Protection Regulation including data portability, right to access, and breach notification.

PIPEDA & CASL

Canadian privacy law compliance with proper consent management, commercial electronic message rules, and data handling.

Right to Delete

Users can request full data deletion at any time. All personal data is permanently removed within 30 days of request.

Breach Protocol

24-hour breach notification protocol with automated detection, impact assessment, and regulatory reporting.

Data Residency

Data is stored in region-specific data centers. Enterprise customers can choose their data residency region.

Audit Logs

Comprehensive audit logging for all administrative actions, data access, and system changes with exportable reports.

Data Handling

What We Collect and Why

Full transparency on data collection, storage, retention, and sharing practices.

CategoryCollectedStored AsRetentionShared
Consumer LocationProximity zone events (enter/exit)Anonymized zone interactions90 days aggregateNever individually
Push EngagementNotification open/dismiss eventsAggregated engagement metrics12 months aggregateBusiness dashboard only
Device InfoOS type, app versionAnonymized device categoriesSession onlyNever
PreferencesInterest categories, opt-in statusEncrypted user profileUntil account deletionNever
Business DataCampaign content, zone configsEncrypted business storageAccount lifetime + 30 daysWith authorized team members
Consumer Rights

Your Data, Your Control

Access Your Data

Request a complete export of all data we hold about you in a machine-readable format.

Correct Inaccuracies

If any data is incorrect, you have the right to have it corrected immediately.

Delete Everything

Request full and permanent deletion of all personal data within 30 days.

Withdraw Consent

Opt out of all proximity notifications at any time through the app or by contacting support.

Security Certifications

HIVE maintains SOC 2 Type II compliance, conducts annual third-party penetration testing, and implements OWASP Top 10 security practices across all systems.

SOC 2 Type II
GDPR
PIPEDA
CASL
OWASP