Privacy & Compliance

Privacy-First Settlement Infrastructure

HIVE is built on data minimization, operator-controlled access, and full audit transparency. We never sell vendor revenue data and enforce strict compliance with global privacy regulations.

Read-Only POS Access

Vendors authorize read-only OAuth access to their POS systems. HIVE never writes to vendor POS data, modifies transactions, or stores card or payment credentials.

Encryption Everywhere

AES-256 encryption at rest and TLS 1.3 in transit. All transaction data and GMV records are encrypted end-to-end between POS provider accounts and HIVE servers.

GDPR Compliant

Full compliance with the General Data Protection Regulation including data portability, right to access, right to erasure, and breach notification requirements.

PIPEDA & CASL

Canadian privacy law compliance with proper consent management and data handling. Supabase data residency options available for Canadian operators.

Data Retention Controls

Verified transaction records retained for the duration of your lease agreement plus 7 years for audit compliance. Operators can request data exports or deletion upon contract end.

Breach Protocol

24-hour breach notification protocol with automated detection, impact assessment, and regulatory reporting to affected operators and vendors.

Data Residency

Canadian operators can elect Supabase Canadian data residency. All data remains within the selected region. Enterprise operators can specify residency requirements.

Audit Logs

Immutable audit trail for all settlement calculations, GMV verifications, and data access events. Exportable for lease compliance and regulatory review.

Data Handling

What We Collect and Why

Full transparency on data collection, storage, retention, and sharing practices.

CategoryCollectedStored AsRetentionShared
Vendor GMV DataTransaction-level gross sales via read-only OAuthEncrypted verified transaction recordsLease term + 7 yearsWith authorized operator accounts only
POS CredentialsOAuth tokens (read-only)Encrypted token vaultUntil vendor revokes accessNever
Settlement RecordsCalculated GR and royalty amountsEncrypted ledger entriesLease term + 7 yearsOperator and vendor parties to lease only
Operator DataLease terms, vendor roster, venue configEncrypted business storageAccount lifetime + 30 daysWith authorized operator team members
Stripe Payment DataDisbursement metadata (no card data)Stripe-held; HIVE stores reference IDs onlyPer Stripe data policyStripe Connect parties only
Data Rights

Operator and Vendor Controls

Export Your Data

Operators and vendors can request a full export of verified GMV records, settlement history, and audit logs in machine-readable format at any time.

Revoke POS Access

Vendors can revoke HIVE's OAuth access to their POS system at any time through HIVE BIZ. Data collection stops immediately upon revocation.

Request Deletion

Upon contract end, operators and vendors may request deletion of all data not required for statutory retention. Deletion completed within 30 days.

Contact Us

Privacy inquiries and data requests can be directed to privacy@hivecertified.com. We respond to all verified requests within 5 business days.

Security Certifications

HIVE is built on a SOC 2 Type II ready architecture, conducts annual third-party penetration testing, and implements OWASP Top 10 security practices across all systems.

SOC 2 Type II Ready
GDPR
PIPEDA
CASL
OWASP