We collect what the console shows
Account details, device inventory and health telemetry, and usage of the service. Nothing more, nothing hidden.
Hive manages devices, which means Hive handles data carefully by definition. Here's exactly what we collect, why, where it goes, and the rights you and your device end users have.
Account details, device inventory and health telemetry, and usage of the service. Nothing more, nothing hidden.
For device data we act as a processor on your instructions. You decide the policies; we carry them out.
Ever. Sharing is limited to the subprocessors that run the service, listed in our legal library.
Access, correction, export, and deletion, for admins and for device end users, under GDPR, CCPA, and friends.
Hive Technologies, Inc. ("Hive", "we", "us") provides a device-management control plane for Android and AOSP fleets. This policy covers our websites, the management console, device agents, and APIs. For questions or requests, contact privacy@hivemdm.com.
Two roles. For data about our customers' admins and website visitors, Hive is the data controller. For data collected from managed devices on a customer's behalf, Hive is a data processor acting on the customer's instructions: the customer is the controller.
We do not sell personal data, and we do not use customer fleet data for advertising.
Where GDPR applies, we process account data to perform our contract with you, on our legitimate interest in securing and improving the service, with your consent where required (for example, marketing emails), and to comply with legal obligations. Device data is processed under the customer's instructions per our Data Processing Addendum.
Data may be processed in the United States, the EU, and Singapore depending on your chosen region. Transfers from the EEA/UK rely on Standard Contractual Clauses. Customers on regional, on-premises, or air-gapped deployments keep data within their chosen boundary. See Platform.
Account data is kept for the life of the account and up to 90 days after closure. Device telemetry follows the customer's configured retention windows. Remote-session recordings default to 30 days. After subscription end, customer data is available for export for 30 days and then deleted from production within 60 days, with backups expiring on a rolling 35-day cycle.
Per-device certificate identity, TLS everywhere, encryption at rest, signed commands and policies, tenant isolation, role-based access control, and immutable audit logs, described in depth in the Trust Centre and on Security & Compliance. Hive is built on a security-first architecture; formal certifications are on our roadmap, and we notify affected customers of personal-data breaches without undue delay.
Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA, and similar), you may have rights to access, correct, export, restrict, object to, or delete personal data, and to complain to a supervisory authority. Write to privacy@hivemdm.com; we respond within 30 days. We don't discriminate against anyone for exercising their rights.
If you use a device managed by Hive, such as a work handheld, a kiosk, or a POS terminal, the organisation that gave you the device controls what is collected from it. Requests about that data go to them; we support them in fulfilling your rights. Managed devices display the management state in Android settings, and Hive agents do not collect the content of personal communications.
The service is for business use and not directed at children under 16; we do not knowingly collect their personal data as a controller.
We'll post updates here and, for material changes, notify account owners by email at least 30 days in advance. The "last updated" date above always reflects the current version.
privacy@hivemdm.com · Hive Technologies, Privacy, Singapore. EU representatives and the DPA are available via the legal library.
The agreement that governs your use of the Hive control plane.
Read the terms →Certifications, security posture, and data residency options in depth.
Visit the Trust Centre →The product-level controls: identity, signing, RBAC, and audit logs.
See the controls →