Skip to content
ride.dev
Cookie PolicyPrivacy PolicyHelp center
Log in
← ride.dev

Cookie Policy

This Cookie Policy explains the cookies and similar technologies used on the ride.dev website and its public forms (including the Medicaid Eligibility Form), operated by Hive Management, LLC ("we", "us", or "our"). It describes what each technology does, what data it processes, how long it lasts, and how you control it.

For how we handle personal information and Protected Health Information (PHI) more broadly — including under HIPAA — see our Privacy Policy.

Sites covered by this policy and by your consent

This policy, and the choice you make in the cookie banner, apply to these sites:

SiteWhat it is
ride.dev (and www.ride.dev)Our public website
app.ride.devOperator portal sign-in
admin.ride.devAdministration portal sign-in
school.ride.devSchool portal sign-in
medride.ride.devThe public Medicaid Eligibility Form

Your choice is shared across ride.dev and its portal subdomains, so you are asked once rather than on each site. medride.ride.dev keeps its own separate banner and its own consent record: the Medicaid Eligibility Form is where health information is entered, so we deliberately load no consent-management or analytics provider on it, and a choice made there is not shared with the other sites.

The signed-in areas of the operator portals display no advertising or analytics trackers; the technologies listed in Section 3 (sign-in and security) are what keep them working.

  • Effective Date · 2026-07-02
  • Last Updated · 2026-08-15
01

Our Approach

We keep tracking to the minimum. We use only:

  • a small number of strictly necessary technologies required to run the site and protect it from abuse,
  • one functional convenience — Google Maps address autocomplete — which loads only after you opt in, and
  • one marketing technology — Google Tag Manager, used solely to measure which of our ads lead to ride requests — which also loads only after you opt in.

We run no analytics tools, no social-media pixels, and no cross-site behavioral or personalized advertising. Nothing you type into any form is ever shared with advertisers.

Because loading a third party such as Google can transmit your IP address before you have asked for that help, we do not load any non-essential third party until you give affirmative consent. Strictly-necessary technologies operate on the basis that they are required to deliver a service you requested or to secure it.

02

What Are Cookies and Similar Technologies?

"Cookies" are small text files a website stores in your browser. "Similar technologies" include browser storage and third-party scripts that may set their own cookies or read device/network signals (such as your IP address). We refer to all of these together as "cookies" below.

Cookies may be first-party (set by ride.dev) or third-party (set by a provider whose script we load, such as Cloudflare or Google). They may last only for your session (deleted when you close the browser) or persist for a set period.

03

Strictly Necessary — Always Active

These are required for the site to work or to protect it, and are not subject to the consent toggle. They do not track you across other websites.

Consent record — mr_consent

  • Provider / type: ride.dev (first-party cookie).
  • Purpose: remembers your cookie choices and records that you made a choice — including when. This is both a convenience (so we don't ask again) and our record of your consent.
  • Data stored: a small encoded record containing: that essential cookies are on, whether you enabled the functional and marketing categories, the date and time of your choice, and the policy version you agreed to. It contains no name, contact details, or tracking identifier.
  • Duration: up to 1 year, then you are asked again. It is also refreshed if we change the technologies we use (see Section 8).

Session & sign-in — first-party

  • Provider / type: ride.dev (first-party), backed by Amazon Cognito for authenticated areas.
  • Purpose: keeps signed-in operators logged in and enforces role-based access in the admin and school portals.
  • Data stored: an opaque session identifier.
  • Duration: the browser session or the sign-in period.

Consent record — cookieyes-consent

  • Provider / type: CookieYes (our consent-management provider) on ride.dev and its portal subdomains. Not used on medride.ride.dev.
  • Purpose: the equivalent of mr_consent for those sites — it records your banner choice, and before you answer it records that no choice has been made yet, so we know to keep asking. This is what makes one answer apply across ride.dev and its portals.
  • Data stored: a consent identifier and one yes/no per category. No name, contact details or advertising identifier.
  • When it is set: as soon as the banner loads, before you answer. It has to be — it is the mechanism that remembers your answer, which is why it is strictly necessary rather than something we could ask permission for.
  • Duration: up to 1 year.

Language preference — i18nextLng

  • Provider / type: ride.dev (first-party, browser local storage — not a cookie).
  • Purpose: remembers whether you chose English or Spanish so the site loads in your language.
  • Data stored: a language code such as en or es. Nothing else.
  • Duration: until you clear your browser storage.

Site context — ride-dev:tenant

  • Provider / type: ride.dev (first-party, browser session storage — not a cookie).
  • Purpose: identifies which organization's branding and portal you are viewing, so the right site is shown.
  • Data stored: an organization identifier. It contains nothing about you.
  • Duration: cleared when you close the browser tab.

Security check — Cloudflare Turnstile

  • Provider / type: Cloudflare, Inc. (third-party script, loaded from challenges.cloudflare.com).
  • Purpose: a privacy-preserving "are you human?" challenge that protects the public Medicaid Eligibility Form from bots and abuse. It is required to submit that form.
  • Data processed: your IP address and browser/device signals, used to tell humans from automated traffic. Cloudflare states Turnstile does not use cookies to track users across sites and is not used for advertising.
  • When it loads: only on the page containing the protected form.
  • Duration: the challenge is short-lived and re-issued as needed.
04

Functional — Loads Only With Your Consent

Address & facility autocomplete — Google Maps

  • Provider / type: Google LLC (third-party — the Google Maps JavaScript API).
  • Purpose: suggests addresses and healthcare facilities as you type on the Medicaid Eligibility Form, and fills in the matching city, state, and ZIP for you.
  • Data processed: when active, the characters you type into the address or facility field and your IP address are sent to Google to return suggestions. Once loaded, Google may set its own cookies under the Google Privacy Policy.
  • When it loads: only after both (a) you enable the "Functional" category in the cookie banner or preferences panel, and (b) you place your cursor in the address or facility field. If you decline — or simply take no action — Google is never contacted.
  • If you decline: you type the address manually. The form remains fully usable; nothing is sent to Google.
  • Duration: governed by Google's own cookies and policies once loaded.
05

Marketing — Loads Only With Your Consent

Ad conversion measurement — Google Tag Manager / Google Ads

  • Where it runs: on our public website (ride.dev) only. It is not used on medride.ride.dev — the Medicaid Eligibility Form carries no advertising or measurement tag of any kind. We removed it from that portal deliberately: it is where health information is entered, and we do not put advertising technology on those pages.
  • Provider / type: Google LLC (third-party — Google Tag Manager, loaded from googletagmanager.com).
  • Purpose: measures whether an ad we ran on Google led to a ride request, so we can tell which ads work. This is measurement only — not remarketing, personalized advertising, or analytics.
  • Data processed: when active, Google receives standard tag signals such as your IP address and the page URL. We configure Google Consent Mode so that analytics storage and ad personalization remain denied even after you opt in; only ad-conversion measurement is granted.
  • When it loads: only after you enable the "Marketing" category. If you decline — or take no action — nothing from Google loads. (Because consent requires JavaScript, we deliberately omit Google's no-JavaScript fallback pixel: a visitor who cannot consent is never measured.)
  • If you decline: the site and the form work exactly the same; we simply cannot attribute your visit to an ad.
  • Duration: governed by Google's own cookies and policies once loaded. Withdrawing consent stops it from loading on your next page view.
06

What We Do Not Use

We do not use, and do not load:

  • Analytics or audience-measurement tools (we do not run Google Analytics or any equivalent).
  • Remarketing/retargeting or personalized-advertising cookies (ad personalization is explicitly denied in our Google Consent Mode configuration).
  • Social-media pixels or "like"/share trackers.
  • Cross-site behavioral tracking, device fingerprinting for advertising, or session-replay tools.
  • Any advertising or measurement technology on medride.ride.dev, the site hosting the Medicaid Eligibility Form. That portal loads no third-party advertising, analytics or consent-management provider — only the security check needed to submit the form, and the map autocomplete if you turn it on.

And we never load the consent-gated technologies in Sections 4 and 5 without your consent.

07

Managing Your Choices

  • On your first visit the cookie banner lets you Accept, Reject, or open Preferences — with equal prominence and no pre-ticked boxes.
  • At any time you can reopen the preferences panel from the "Cookie preferences" link in the site footer, and turn the Functional and Marketing categories on or off independently. On ride.dev and its portal subdomains this opens our consent provider's preference center; on medride.ride.dev it opens our own.
  • Rejecting keeps only the strictly-necessary technologies in Section 3.
  • Withdrawing consent stops the functional or marketing service from loading afterward. A third-party script already loaded on the page you are viewing ends when you navigate away or reload.
  • Your browser can also block or delete cookies through its settings. Blocking strictly-necessary cookies may prevent parts of the site — such as staying signed in or submitting the form — from working.
08

Your Consent Record and Re-Prompting

The mr_consent record stores your choice, the time you made it, and the policy version it applies to, so we can honor and evidence it. If we add, remove, or change the technologies or purposes described here, we increase the policy version, which prompts you to review and choose again on your next visit.

09

Do Not Track and Global Privacy Control

Some browsers send a "Do Not Track" or "Global Privacy Control" signal. All non-essential technologies here — the Functional and Marketing categories — are off unless you affirmatively turn them on, so there is nothing loading by default to opt out of.

10

Your Privacy Rights

Depending on where you live, you may have rights over your personal information under laws such as the California Consumer Privacy Act (CCPA/CPRA), the Colorado Privacy Act (CPA), and similar state laws. We do not sell or share personal information for cross-context behavioral advertising. To exercise your rights, or for any question about this policy, contact us using Section 12. See our Privacy Policy for full details, including HIPAA rights.

11

Third-Party Providers

When enabled, the third parties above process data under their own policies:

  • Cloudflare (Turnstile security check): Cloudflare Privacy Policy.
  • Google (Maps autocomplete): Google Privacy Policy and Google Maps Platform terms.
  • Google (Tag Manager / Ads conversion measurement): Google Privacy Policy and How Google uses information from sites that use its services.
  • CookieYes (cookie consent management on ride.dev and its portal subdomains — it presents the banner and stores the record of your choice): CookieYes Privacy Policy. It is not used on medride.ride.dev.
12

Contact Us

For questions about this Cookie Policy or your choices:

Hive Management, LLC 200 Plaza Dr, Suite 260 Highlands Ranch, Colorado 80129 United States

Privacy Contact: support@medrideco.com

13

Changes to This Policy

We may update this Cookie Policy from time to time. The "Last Updated" date above reflects the most recent revision, and material changes to the technologies we use will prompt you to review your choices again as described in Section 8. (2026-08-10: added the consent-gated Marketing category in Section 5 — Google Tag Manager for ad conversion measurement — and bumped the consent-policy version so prior choices are re-asked.) (2026-08-15: listed the sites this policy and your consent cover, declared the two first-party browser-storage keys in Section 3, named our cookie-consent provider in Section 11, declared its cookieyes-consent record in Section 3, and removed the Google Ads conversion tag from the Medicaid Eligibility Form portal entirely — that portal now carries no advertising or measurement technology at all.)

  1. 01Our Approach
  2. 02What Are Cookies and Similar Technologies?
  3. 03Strictly Necessary — Always Active
  4. 04Functional — Loads Only With Your Consent
  5. 05Marketing — Loads Only With Your Consent
  6. 06What We Do Not Use
  7. 07Managing Your Choices
  8. 08Your Consent Record and Re-Prompting
  9. 09Do Not Track and Global Privacy Control
  10. 10Your Privacy Rights
  11. 11Third-Party Providers
  12. 12Contact Us
  13. 13Changes to This Policy
ride.dev

Non-emergency medical transportation, run on one record.

Colorado, USA · est. 2026

© 2026 ride.dev · All rights reserved

Portals

  • Admin portal↗
  • School portal↗
  • MedRide↗

Legal

  • Privacy Policy↗
  • Cookie Policy
  • Accessibility Statement↗
  • Terms & Conditions↗
  • Help center

Platform

  • NorthStar
  • Intake
  • Fleet
  • Reporting