Privacy Policy
Who We Are
This Privacy Policy describes how Hive Management, LLC ("Hive", "we", "us", or "our") collects, uses, and protects information in connection with the ride.dev mobile application and related services (collectively, the "Service"). Hive Management, LLC is a Colorado limited liability company that provides non-emergency medical transportation (NEMT) and school transportation coordination software.
The Service is made available to authorized drivers, guardians, passengers, and administrators of participating organizations (schools, transportation providers, and healthcare coordinators). It is not a consumer-facing application and is not intended for the general public.
HIPAA Notice
Hive Management, LLC operates as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") to covered entities that provide the Service to their patients, clients, and students. We maintain Business Associate Agreements (BAAs) with each covered entity as required by 45 C.F.R. § 164.504(e).
Protected Health Information ("PHI") processed through the Service is handled in accordance with HIPAA's Privacy Rule (45 C.F.R. Part 164, Subpart E) and Security Rule (45 C.F.R. Part 164, Subpart C). Individuals whose PHI is processed through the Service should refer to the Notice of Privacy Practices provided by the covered entity (school, transportation coordinator, or healthcare organization) responsible for their care or transportation.
Information We Collect
3.1 Information provided by covered entities and administrators
Covered entities and administrators provision accounts and records that may include:
- Full name, date of birth, phone number, email, home and pickup/dropoff addresses
- Medicaid ID, Medicare ID, Managed Care Organization member ID, Medical Record Number
- ICD-10 diagnosis codes (when relevant to transportation needs)
- Mobility requirements (wheelchair, stretcher, ambulatory)
- Driver preferences and incident notes
- Guardian/emergency contact details
- Trip itineraries, pickup and dropoff events, and status history
3.2 Information you provide
When you use the Service, we may collect:
- Account credentials (email and password, or federated identity via Google Sign-In)
- Emergency contacts you add to guardian profiles
- Comments, incident notes, or reports you submit
- Support requests and feedback
3.3 Information collected automatically
- Location data (drivers only): while on active shift, we collect real-time geolocation (GPS coordinates) in the foreground and background for trip dispatch, route calculation, geofence-based arrival detection, and sharing with authorized guardians. Background tracking stops when the driver ends their shift.
- Device and technical data: device model, operating system version, app version, language preference, crash and performance telemetry (anonymized). We do not collect IDFA, advertising identifiers, or tracking IDs.
- Authentication logs: sign-in events, IP address at time of authentication, and session activity timestamps, for security auditing.
3.4 Information we do not collect
We do not collect: contacts, calendar, photos, microphone audio, camera imagery (unless you explicitly upload a document), SMS messages, or browsing history.
How We Use Information
We use information only for the following purposes:
- Service delivery: dispatching trips, navigation, real-time tracking, passenger manifest management, and communication between drivers, guardians, coordinators, and administrators.
- HIPAA-permitted disclosures ("TPO"): treatment, payment, and healthcare operations — in each case limited to the minimum necessary and subject to the BAA with the covered entity.
- Safety and compliance: incident reporting, geofence-based auditing, HIPAA audit logging via our
IAuditService, and regulatory compliance (HIPAA, SOC 2, HITRUST, ARC-AMPE). - Security: fraud prevention, authentication, authorization enforcement, and anomaly detection.
- Service improvement: aggregated, de-identified analytics to improve the app. We do not use PHI for marketing or product development.
We do not:
- Sell personal information or PHI.
- Share PHI with advertisers, data brokers, or analytics vendors.
- Use PHI to train machine learning models outside of the direct service provided to the covered entity.
Data Security
We implement administrative, physical, and technical safeguards consistent with the HIPAA Security Rule, including:
- Field-level encryption of PHI at rest (SSN, Medicaid/Medicare IDs, DOB, ICD-10, phone, email, license numbers, and others) using AWS-managed keys via our
IFieldEncryptionService. - Encryption in transit (TLS 1.2 or higher on all client–server connections).
- Role-based access control enforced at the API gateway and enforced by
[Authorize]role checks on every endpoint. - Audit logging of all PHI access events via
IAuditService.LogPhiAccessAsync. - Secrets management via AWS Secrets Manager — no credentials are stored in source code or client devices.
- Authentication via Amazon Cognito with mandatory strong passwords and optional MFA.
- SOC 2 Type II and HITRUST CSF compliance frameworks (in progress; audit reports available to covered entities under NDA).
Drivers are required to keep their device locked, never share screenshots containing PHI, and report lost or stolen devices to their coordinator immediately so that access can be revoked.
Data Retention
- PHI: retained for the period required by the covered entity's retention policy and applicable law (typically a minimum of 6 years under HIPAA, § 164.530(j)).
- Account data: retained while the account is active. On account closure, account data is deleted within 90 days, except where retention is required for legal, audit, or regulatory purposes.
- Location data: real-time GPS pings are retained for 90 days for dispatch audit and incident investigation, then aggregated or deleted.
- Authentication logs: retained for 2 years.
- Backups: encrypted backups may retain deleted data for up to 35 days before rotation.
Your Rights
Rights available to you depend on your role and applicable law.
8.1 Under HIPAA
Individuals whose PHI is processed through the Service have the right to:
- Access their PHI held by the covered entity (45 C.F.R. § 164.524)
- Request amendment of inaccurate PHI (45 C.F.R. § 164.526)
- Accounting of disclosures (45 C.F.R. § 164.528)
- Request restrictions on certain uses and disclosures (45 C.F.R. § 164.522)
Requests under HIPAA should be directed to the covered entity (school, transportation coordinator, or healthcare organization) — not to Hive directly. We will assist the covered entity as required by our Business Associate Agreement.
8.2 Account controls
Regardless of jurisdiction, you may:
- Update your profile information from within the app (Settings → Profile).
- Change or remove emergency contacts (Guardian Profile → Emergency Contacts).
- Change your password through the password reset flow.
- Request account deletion by contacting your coordinator or our privacy team.
8.3 State-specific rights
Residents of California (CCPA/CPRA), Colorado (CPA), Virginia (VCDPA), and other states with comprehensive privacy laws may have additional rights, including the right to know, delete, correct, or opt out of the sale or sharing of personal information. Hive does not sell personal information. To exercise these rights, contact us at the address in Section 13.
Children's Privacy
The Service may process information about minors — specifically, students who are transported to and from school or appointments. This processing is:
- Authorized by the student's parent or legal guardian through the covered entity (school or healthcare organization).
- Limited to transportation coordination and safety.
- Covered by FERPA where the covered entity is an educational agency or institution.
Minors do not create accounts or use the app directly. Accounts are created and managed by adult guardians, drivers, coordinators, or administrators. We do not knowingly collect information directly from children under 13 in violation of the Children's Online Privacy Protection Act (COPPA).
Location Services and Permissions
The Service requests the following device permissions:
- Location (drivers): foreground and background, required to dispatch trips, calculate routes, detect arrival at pickup/dropoff via geofencing, and allow guardians to track their dependent's trip in real time. Collected only while the driver is on an active shift. You can revoke this permission in your device settings at any time, but the driver functionality will be disabled without it.
- Notifications: to alert you of trip status changes, arrivals, and safety events. Can be disabled in device settings.
International Users
The Service is operated in the United States and intended for use within the United States only. If you access the Service from outside the U.S., your information will be transferred to and processed in the United States, where U.S. privacy and healthcare laws apply.
Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated through in-app notification or email before taking effect. The "Last Updated" date at the top of this document reflects the most recent revision. Continued use of the Service after the effective date of changes constitutes acceptance of the updated policy.
Contact Us
For privacy questions, to exercise your rights, or to report a concern:
Hive Management, LLC 200 Plaza Dr, Suite 260 Highlands Ranch, Colorado 80129 United States State of formation: Colorado
Privacy Contact: support@medrideco.com Data Protection Officer: Same as Privacy Contact (support@medrideco.com) General Support: support@medrideco.com
For reports of a suspected HIPAA breach or data incident, email support@medrideco.com.