Documentation
Legal

Privacy Policy

What HiveOps collects about you, why, where it is kept, and your rights

Last updated: September 14, 2026

This policy explains what personal information HiveOps Inc. ("HiveOps", "we", "us") collects, why, where it is kept, who it is shared with, and the rights you have over it. It covers the website at hiveops.io, the console, the HiveOps API and HiveOps Database Service.

We are a Canadian company, and we handle personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, for people in Quebec, Quebec's Act respecting the protection of personal information in the private sector.

1. Who is responsible

HiveOps Inc. is responsible for the personal information described here. Our Privacy Officer answers every question and request about it: [email protected].

The data in your databases is different. What you store in a database is yours, and we host it on your behalf as your service provider. You decide what it contains, and you are responsible for the consent of the people it is about. We do not look at it except as the Terms of Service section 4 describes, and we do not sell it or use it to train AI models.

2. What we collect

When you sign in with Google or GitHub, we receive your name, email address, profile picture and the identifier that provider gives your account. We do not receive your Google or GitHub password.

When you sign up, we also ask for:

  • a mobile number, which we verify with a code sent by text message, and then keep only as a one-way hash, so that each number can be used for one account;
  • a payment card, which you give to our payment processor, Stripe, and never to us. We receive the card's brand, last four digits, expiry date and billing address, and a fingerprint that tells us whether a card has been used for another free organization.

When you use the console and the API, we record your organizations, their members and roles, your databases and their settings, and what each database uses: storage, memory, CPU, connections and data transfer.

For security and to operate the Service, we record IP addresses, browser and device details, and the requests made to our servers, and your browser sends us a report when a page in the console fails.

When you contact us, we keep what you send. Messages from the contact form are delivered to our team's Slack workspace, and the form is protected by Cloudflare Turnstile.

When you visit the website, we count visits with Umami, which we run on our own servers. It sets no cookies, does not follow you to other websites, and gives us totals rather than a profile of you.

3. Why we use it

  • To provide the Service: to sign you in, run your databases, and show you and your organization what you use.
  • To bill you, and to meet our tax and accounting obligations.
  • To keep the Service safe: to stop fraud, automated sign-ups and abuse, which is why sign-up asks for a mobile number and a card.
  • To contact you about your account: security notices, billing, a paused or soon to be deleted database, and changes to these policies.
  • To send you news and offers, only if you have agreed to it. Every such email has an unsubscribe link, and you can withdraw your consent at any time.
  • To improve the Service, using totals rather than information about you.
  • To meet the law, and to respond to lawful requests.

We collect only what these purposes need, and we do not sell personal information.

4. Where it is kept

We keep your personal information in Canada. The platform's own database is in Toronto, and customers' databases are in Montreal, in the region you choose.

Some of the service providers in section 5 are based outside Canada, mostly in the United States, and handle information there. Information held outside Canada is subject to the laws of that country, and may be accessed by its authorities under those laws.

5. Who we share it with

We share personal information only with the service providers who help us run HiveOps, only what each one needs, and under contracts that require them to protect it:

ProviderWhat it does for usWhere
Google CloudHosts the platform's own database, and its encryption keys, secrets and messagingCanada
OVHcloudThe servers customers' databases run onCanada
CloudflareOur domain names, protection from attacks, and Turnstile on our formsWorldwide, based in the United States
StripeCard payments, fraud checks and sales taxUnited States and Canada
GoogleSign in with Google, and our emailUnited States
GitHubSign in with GitHubUnited States
SlackDelivers contact form messages to our teamUnited States
Twilio, our text message providerSends the code that verifies your mobile number, and checks that it is a mobile number rather than a virtual oneUnited States

We may also disclose personal information when the law requires it, to protect the rights and safety of HiveOps, our customers or others, or to a company that acquires our business, which would remain bound by this policy.

6. How long we keep it

  • Your account is kept while it is open. When you close it, your databases are kept for 30 days so that you can export them and are then deleted, and your profile is deleted 30 days after that.
  • Backups are deleted when their plan's retention period ends, which is at most 30 days.
  • A free database that has been paused for 90 days is deleted, after we have warned you.
  • Billing records are kept for six years after the end of the tax year they belong to, as Canadian tax law requires.
  • Server logs are kept for 7 days, and security records for as long as they are needed to investigate an incident.
  • Your mobile number's hash and your card's fingerprint are kept for as long as they are needed to stop the same number or card being used for another free organization.

7. How we protect it

Every connection to HiveOps is encrypted, secrets are encrypted with keys held in a key management service, and access to personal information is limited to the people who need it for their work. No system is perfectly secure. If a breach of your personal information creates a real risk of significant harm, we will tell you and the regulators the law requires us to tell, as quickly as we can.

8. Your rights

You may ask us:

  • for a copy of the personal information we hold about you, including in a structured, commonly used format;
  • to correct it if it is wrong;
  • to delete it, subject to what the law requires us to keep;
  • to stop using it for a purpose you had consented to, such as marketing email.

Email [email protected], and we will answer within 30 days. We may need to confirm your identity first.

If you are not satisfied with our answer, you may complain to the Office of the Privacy Commissioner of Canada, or, if you are in Quebec, to the Commission d'accès à l'information du Québec.

9. Cookies and your browser

We use no advertising or tracking cookies, which is why the site does not ask you about cookies. What your browser does keep for us is what the site needs to work:

  • your signed-in session, so you stay signed in;
  • your preferences, such as the theme and the layout of the console;
  • unsaved queries in the SQL workbench, so a refresh does not lose them.

Cloudflare Turnstile and Stripe may set cookies of their own on the pages that use them, to tell people from bots and to prevent fraud.

10. Children

HiveOps is for people aged 18 and over, and we do not knowingly collect information about anyone younger. If you believe a child has given us personal information, tell us at [email protected] and we will delete it.

11. Changes

We will email the owners of every organization at least 30 days before a material change to this policy takes effect, and the date at the top shows the latest version.

12. Contact

Privacy Officer, HiveOps Inc., [registered address]

[email protected]

On this page