Skip to content
ride.dev
Cookie PolicyPrivacy PolicyHelp center
Log in
← ride.dev

Privacy Policy

  • Effective Date · 2026-04-22
  • Last Updated · 2026-04-22
01

Who We Are

This Privacy Policy describes how Hive Management, LLC ("Hive", "we", "us", or "our") collects, uses, and protects information in connection with the ride.dev mobile application and related services (collectively, the "Service"). Hive Management, LLC is a Colorado limited liability company that provides non-emergency medical transportation (NEMT) and school transportation coordination software.

The Service is made available to authorized drivers, guardians, passengers, and administrators of participating organizations (schools, transportation providers, and healthcare coordinators). It is not a consumer-facing application and is not intended for the general public.

02

HIPAA Notice

Hive Management, LLC operates as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") to covered entities that provide the Service to their patients, clients, and students. We maintain Business Associate Agreements (BAAs) with each covered entity as required by 45 C.F.R. § 164.504(e).

Protected Health Information ("PHI") processed through the Service is handled in accordance with HIPAA's Privacy Rule (45 C.F.R. Part 164, Subpart E) and Security Rule (45 C.F.R. Part 164, Subpart C). Individuals whose PHI is processed through the Service should refer to the Notice of Privacy Practices provided by the covered entity (school, transportation coordinator, or healthcare organization) responsible for their care or transportation.

03

Information We Collect

3.1 Information provided by covered entities and administrators

Covered entities and administrators provision accounts and records that may include:

  • Full name, date of birth, phone number, email, home and pickup/dropoff addresses
  • Medicaid ID, Medicare ID, Managed Care Organization member ID, Medical Record Number
  • ICD-10 diagnosis codes (when relevant to transportation needs)
  • Mobility requirements (wheelchair, stretcher, ambulatory)
  • Driver preferences and incident notes
  • Guardian/emergency contact details
  • Trip itineraries, pickup and dropoff events, and status history

3.2 Information you provide

When you use the Service, we may collect:

  • Account credentials (email and password, or federated identity via Google Sign-In)
  • Emergency contacts you add to guardian profiles
  • Comments, incident notes, or reports you submit
  • Support requests and feedback

3.3 Information collected automatically

  • Location data (drivers only): while on active shift, we collect real-time geolocation (GPS coordinates) in the foreground and background for trip dispatch, route calculation, geofence-based arrival detection, and sharing with authorized guardians. Background tracking stops when the driver ends their shift.
  • Device and technical data: device model, operating system version, app version, language preference, crash and performance telemetry (anonymized). We do not collect IDFA, advertising identifiers, or tracking IDs.
  • Authentication logs: sign-in events, IP address at time of authentication, and session activity timestamps, for security auditing.

3.4 Information we do not collect

We do not collect: contacts, calendar, photos, microphone audio, camera imagery (unless you explicitly upload a document), SMS messages, or browsing history.

04

How We Use Information

We use information only for the following purposes:

  • Service delivery: dispatching trips, navigation, real-time tracking, passenger manifest management, and communication between drivers, guardians, coordinators, and administrators.
  • HIPAA-permitted disclosures ("TPO"): treatment, payment, and healthcare operations — in each case limited to the minimum necessary and subject to the BAA with the covered entity.
  • Safety and compliance: incident reporting, geofence-based auditing, HIPAA audit logging via our IAuditService, and regulatory compliance (HIPAA, SOC 2, HITRUST, ARC-AMPE).
  • Security: fraud prevention, authentication, authorization enforcement, and anomaly detection.
  • Service improvement: aggregated, de-identified analytics to improve the app. We do not use PHI for marketing or product development.

We do not:

  • Sell personal information or PHI.
  • Share PHI with advertisers, data brokers, or analytics vendors.
  • Use PHI to train machine learning models outside of the direct service provided to the covered entity.
05

How We Share Information

We share information only as follows:

  • With the covered entity (school, transportation coordinator, healthcare organization) that provisioned the account, as required for service delivery.
  • With authorized drivers, guardians, and administrators within the same covered entity, based on role and the principle of least privilege.
  • With Medicaid, Medicaid Managed Care Organizations, and state transportation brokers, solely for payment and eligibility verification, as permitted under 45 C.F.R. § 164.506.
  • With infrastructure subprocessors under signed BAAs:
    • Amazon Web Services, Inc. (hosting, database, authentication, storage)
    • Google LLC (Google Maps Platform — for routing and map display; coordinates only, no identifiers)
    • Firebase / Google LLC (crash reporting, if enabled — anonymized)
  • As required by law: in response to subpoenas, court orders, or other legal process, or to protect rights, safety, or property.
  • In a business transfer: if Hive Management, LLC is acquired, merged, or reorganized, data may transfer to the successor entity subject to the same privacy protections.

Except as listed above, we do not share personal information or PHI with any third party.

06

Data Security

We implement administrative, physical, and technical safeguards consistent with the HIPAA Security Rule, including:

  • Field-level encryption of PHI at rest (SSN, Medicaid/Medicare IDs, DOB, ICD-10, phone, email, license numbers, and others) using AWS-managed keys via our IFieldEncryptionService.
  • Encryption in transit (TLS 1.2 or higher on all client–server connections).
  • Role-based access control enforced at the API gateway and enforced by [Authorize] role checks on every endpoint.
  • Audit logging of all PHI access events via IAuditService.LogPhiAccessAsync.
  • Secrets management via AWS Secrets Manager — no credentials are stored in source code or client devices.
  • Authentication via Amazon Cognito with mandatory strong passwords and optional MFA.
  • SOC 2 Type II and HITRUST CSF compliance frameworks (in progress; audit reports available to covered entities under NDA).

Drivers are required to keep their device locked, never share screenshots containing PHI, and report lost or stolen devices to their coordinator immediately so that access can be revoked.

07

Data Retention

  • PHI: retained for the period required by the covered entity's retention policy and applicable law (typically a minimum of 6 years under HIPAA, § 164.530(j)).
  • Account data: retained while the account is active. On account closure, account data is deleted within 90 days, except where retention is required for legal, audit, or regulatory purposes.
  • Location data: real-time GPS pings are retained for 90 days for dispatch audit and incident investigation, then aggregated or deleted.
  • Authentication logs: retained for 2 years.
  • Backups: encrypted backups may retain deleted data for up to 35 days before rotation.
08

Your Rights

Rights available to you depend on your role and applicable law.

8.1 Under HIPAA

Individuals whose PHI is processed through the Service have the right to:

  • Access their PHI held by the covered entity (45 C.F.R. § 164.524)
  • Request amendment of inaccurate PHI (45 C.F.R. § 164.526)
  • Accounting of disclosures (45 C.F.R. § 164.528)
  • Request restrictions on certain uses and disclosures (45 C.F.R. § 164.522)

Requests under HIPAA should be directed to the covered entity (school, transportation coordinator, or healthcare organization) — not to Hive directly. We will assist the covered entity as required by our Business Associate Agreement.

8.2 Account controls

Regardless of jurisdiction, you may:

  • Update your profile information from within the app (Settings → Profile).
  • Change or remove emergency contacts (Guardian Profile → Emergency Contacts).
  • Change your password through the password reset flow.
  • Request account deletion by contacting your coordinator or our privacy team.

8.3 State-specific rights

Residents of California (CCPA/CPRA), Colorado (CPA), Virginia (VCDPA), and other states with comprehensive privacy laws may have additional rights, including the right to know, delete, correct, or opt out of the sale or sharing of personal information. Hive does not sell personal information. To exercise these rights, contact us at the address in Section 13.

09

Children's Privacy

The Service may process information about minors — specifically, students who are transported to and from school or appointments. This processing is:

  • Authorized by the student's parent or legal guardian through the covered entity (school or healthcare organization).
  • Limited to transportation coordination and safety.
  • Covered by FERPA where the covered entity is an educational agency or institution.

Minors do not create accounts or use the app directly. Accounts are created and managed by adult guardians, drivers, coordinators, or administrators. We do not knowingly collect information directly from children under 13 in violation of the Children's Online Privacy Protection Act (COPPA).

10

Location Services and Permissions

The Service requests the following device permissions:

  • Location (drivers): foreground and background, required to dispatch trips, calculate routes, detect arrival at pickup/dropoff via geofencing, and allow guardians to track their dependent's trip in real time. Collected only while the driver is on an active shift. You can revoke this permission in your device settings at any time, but the driver functionality will be disabled without it.
  • Notifications: to alert you of trip status changes, arrivals, and safety events. Can be disabled in device settings.
11

International Users

The Service is operated in the United States and intended for use within the United States only. If you access the Service from outside the U.S., your information will be transferred to and processed in the United States, where U.S. privacy and healthcare laws apply.

12

Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated through in-app notification or email before taking effect. The "Last Updated" date at the top of this document reflects the most recent revision. Continued use of the Service after the effective date of changes constitutes acceptance of the updated policy.

13

Contact Us

For privacy questions, to exercise your rights, or to report a concern:

Hive Management, LLC 200 Plaza Dr, Suite 260 Highlands Ranch, Colorado 80129 United States State of formation: Colorado

Privacy Contact: support@medrideco.com Data Protection Officer: Same as Privacy Contact (support@medrideco.com) General Support: support@medrideco.com

For reports of a suspected HIPAA breach or data incident, email support@medrideco.com.

  1. 01Who We Are
  2. 02HIPAA Notice
  3. 03Information We Collect
  4. 04How We Use Information
  5. 05How We Share Information
  6. 06Data Security
  7. 07Data Retention
  8. 08Your Rights
  9. 09Children's Privacy
  10. 10Location Services and Permissions
  11. 11International Users
  12. 12Changes to This Policy
  13. 13Contact Us
ride.dev

Non-emergency medical transportation, run on one record.

Colorado, USA · est. 2026

© 2026 ride.dev · All rights reserved

Portals

  • Admin portal↗
  • School portal↗
  • MedRide↗

Legal

  • Privacy Policy↗
  • Cookie Policy
  • Accessibility Statement↗
  • Terms & Conditions↗
  • Help center

Platform

  • NorthStar
  • Intake
  • Fleet
  • Reporting