gethivekeeper.com โ€บ Security Policy

Information Security Policy

Version 1.2 ยท 23 April 2026 ยท Culshaw Consulting Ltd
Summary: HiveKeeper stores your beekeeping data securely using Supabase (UK-based, AES-256 encrypted). We never see your password. Your data is yours โ€” export or delete it any time. We use no ad networks, no tracking, and no third-party analytics.

1. Overview

This Information Security Policy describes how HiveKeeper (operated by Culshaw Consulting Ltd, Company No. 16938477) collects, stores, processes and protects user data. It covers all systems used in the delivery of the HiveKeeper service.

HiveKeeper is a UK beekeeping management application accessible at gethivekeeper.com and via native iOS and Android apps. All processing is conducted in accordance with UK GDPR and the Data Protection Act 2018.

This document should be read alongside our Privacy Policy, which covers your data-protection rights in detail.

2. Systems and Third-Party Processors

SystemProviderPurposeData location
SupabaseSupabase Inc.Database, authentication, file storageAWS eu-west-2 (London, UK)
Cloudflare WorkersCloudflare Inc.API proxy for voice transcription, AI analysis, payments, iCal calendarCloudflare edge (UK/EU primary)
GitHub PagesGitHub Inc. / MicrosoftStatic web hosting for marketing pages โ€” no user data storedGlobal CDN
OpenAI WhisperOpenAI Inc.Voice transcription of inspection notes โ€” processed in real time via paid API, not retainedUS (via Cloudflare Worker)
Anthropic ClaudeAnthropic PBCAI frame analysis and beekeeping advice โ€” processed in real time via paid API, not retainedUS (via Cloudflare Worker)
StripeStripe, Inc. / Stripe Payments UK LtdSubscription payment processingUK / Ireland
ResendResend.comTransactional and marketing email deliveryUS
Open-MeteoOpen-Meteo GmbHLive weather data per apiary โ€” coordinates only, no personal dataEU (Germany)
postcodes.io / NominatimOpen Source / OSMGeocoding apiary locations โ€” no personal dataUK / EU
Leaflet.js / ESRIESRI / OpenStreetMapSatellite map tiles for apiary map โ€” no personal data transmittedGlobal CDN
Google Charts APIGoogle LLCQR code generation โ€” hive URLs only, no personal dataGoogle global CDN
HiveKeeper AnalyticsCulshaw Consulting Ltd (via Supabase)In-app usage analytics โ€” screen views, feature usage, paywall interactions. No third party involved.AWS eu-west-2 (London, UK)
MedianMedian.coNative app wrapper โ€” no user data stored by Median itselfUS

3. Data We Collect

Account data

Apiary and hive data

What we do NOT collect

4. How We Use Your Data

DataHow we use itLawful basis (UK GDPR Art. 6)
Email addressAccount authentication, password reset, service notificationsContract โ€” necessary to provide the service
Apiary and hive dataDisplaying your beekeeping records within the appContract โ€” the core purpose of HiveKeeper
Inspection records and photosBuilding your hive history, health scores, AI analysis (if requested)Contract
GPS coordinates / postcodeLive weather data, nectar calendar, Asian Hornet Watch alerts, satellite mapLegitimate interests โ€” core app functionality
Analytics eventsUnderstanding how the app is used to improve features and fix bugsLegitimate interests โ€” product improvement. No personal content is logged.
Referral dataTracking referral rewards and calculating incentivesContract โ€” part of the referral scheme you opt into
Policy consent timestampRecording that you have agreed to our policiesLegal obligation โ€” UK GDPR compliance
SOS emergency contactSending an alert in an apiary emergencyExplicit consent โ€” you provide this voluntarily

Data minimisation: We only collect data that is directly necessary for the purposes listed above. If we cannot justify collecting a piece of data, we do not collect it.

5. Business Transfer

In the event of a sale, merger, acquisition or transfer of HiveKeeper or Culshaw Consulting Ltd, user data forms part of the business assets and may transfer to the acquiring party. We will notify all registered users by email before any transfer takes effect and give users a minimum of 30 days to export and delete their data. User data will never be sold as a standalone asset.

6. Authentication and Access Control

7. Data Storage and Encryption

8. Data Retention

Data typeRetention
User account and hive dataUntil account deletion is requested
Frame and cover photosUntil deleted by user or account deletion
Voice recordings (OpenAI Whisper)Processed in real time โ€” not retained by OpenAI under paid API terms
Photo data sent for AI analysisProcessed in real time โ€” not retained by Anthropic under paid API terms
SOS emergency contact detailsUntil updated or account deleted
Deleted account dataRemoved within 30 days; backups purged within 90 days
Invoices and subscription records6 years (UK tax and accounting law)
Error logs and security logs90 days
Inactive accountsReviewed at 24 months inactivity โ€” user contacted before any deletion

9. Your Rights (UK GDPR)

RightHow to exercise
AccessRequest a copy of all personal data held โ€” we will provide a CSV export within 30 days
RectificationUpdate data directly in the app, or contact us for corrections
ErasureUse Settings โ†’ Start fresh, or email us for full account deletion
Data portabilityUse Settings โ†’ Export all data to CSV at any time
Object to processingContact us โ€” we will cease processing within 30 days where lawful
Withdraw consentDelete your account at any time โ€” no questions asked

To exercise any right, contact [email protected]. We will respond within 30 days.

10. Data Breach Procedure

11. Referral Scheme Data

12. Analytics

HiveKeeper uses its own privacy-first analytics system built on Supabase. No third-party analytics tools, tracking pixels, cookies or advertising networks are used.

What we record

What we do not record

13. Advertising

14. Age Restrictions

HiveKeeper is intended for users aged 18 or over. By signing up, you confirm that you are at least 18 years old. This reflects that paid subscriptions are processed via standard payment cards, which are generally only available to adults.

We do not knowingly collect personal data from anyone under 18. If you believe a minor has signed up for HiveKeeper, please contact [email protected] and we will delete the account and any associated data as soon as reasonably possible.

15. Changes to This Policy

This policy will be reviewed annually or when significant changes to our systems occur. Users will be notified of material changes via the app and/or by email. The current version is always available at gethivekeeper.com/security-policy.html.

16. Contact and ICO Registration

Data Controller: Culshaw Consulting Ltd
Registered office: 30 Stanion Road, Brigstock, Northamptonshire NN14 3HW
Company No: 16938477
Privacy contact: [email protected]
Website: gethivekeeper.com

๐Ÿ›ก๏ธ ICO Registration No: CSN4273098

Culshaw Consulting Ltd is registered with the Information Commissioner's Office under registration number CSN4273098.