Privacy
Last updated: August 3, 2026
Hivewave Inc. ("Hivewave," "we," "us," or "our") provides Hivewave AI and Growth Bee. This Privacy Policy explains how we handle personal information when you visit our website, create an account, connect a service, upload information, or use Hivewave AI.
For account administration, security, billing operations, our website, and our own business communications, Hivewave generally acts as a controller or business. When we process store, customer, contact, mailbox, content, or outreach data on a merchant's documented instructions, Hivewave generally acts as a processor or service provider. Our Data Processing Addendum provides more detail.
Information we collect
The information we collect depends on the features you choose and the permissions you grant.
- Account, organization, and team information.We process account identifiers, name, email address, organization and brand names, roles, invitations, authentication events, language and theme preferences, and support communications. Authentication may use Google sign-in or email one-time codes.
- Shopify and store information.If you connect Shopify, we access the scopes you authorize. These can include shop identity, products, variants, collections, policies, pages, discounts, customer name and email, order count, amount spent, tags, and email marketing consent. We store mirrored records and selected source payloads needed to provide the service.
- Brand knowledge and uploaded content.We process websites you ask us to crawl, brand instructions, product information, campaign materials, chat or discovery briefs, contact spreadsheets, and files you upload. Website crawling can include pages available under the domain you provide.
- Prospect and outreach information.We obtain business contact information from public web sources and search or enrichment providers, including company and domain, contact name, role, business email, phone number, social profile, verification status, source, and candidate reasoning. We create and store outreach subjects, message bodies, approval status, delivery records, replies, outcomes, and suppression preferences.
- Connected mailbox and communications information.If you connect Gmail or Microsoft Outlook, we store encrypted OAuth credentials and mailbox profile information. Our scanner reads mailbox data needed to identify replies to Hivewave outreach and stores a filtered subset, including sender and recipient, display name, subject, plain-text body, selected message headers, and thread identifiers. Messages that do not pass our capture rules are read transiently and are not retained as inbound-message records. We do not store your mailbox password or full raw MIME.
- Social connections and attribution.If you connect a supported social account, we process connection identifiers, publishing settings, platform results, and performance data. For social attribution links, we can process referrer, user agent, and a one-way hashed IP address.
- Billing information.Stripe processes checkout, subscription, payment method, invoice, billing name, billing email, and postal address information. Hivewave stores Stripe customer and subscription identifiers and related status records, but not full payment card details. Bill-to details are stored by Stripe rather than mirrored in our application database.
- Device, log, cookie, and local-storage information.Our hosting and API infrastructure can create security and access logs that include IP address, user agent, request identifier, route, status, and timing. The product uses essential browser storage for authentication, sidebar state, language, theme, referral attribution, onboarding choices, and saved work-in-progress. The marketing site uses Vercel Web Analytics (cookieless, aggregated pageviews via our host). We do not use third-party advertising cookies or a third-party product analytics SDK on the product frontend.
Sources of information
We receive information directly from you and your organization; from services you connect, such as Shopify, Google, Microsoft, Meta platforms, and Stripe; from public websites; from search and business-contact enrichment providers; from message recipients who reply or opt out; and from our service and infrastructure providers.
For business contact data obtained indirectly, we use the information to provide merchant-requested business outreach, verify contactability, prevent repeat contact, and respond to rights requests. Where applicable law requires an individual notice, we provide or make this notice available no later than the first communication or other required time.
How we use information and our legal bases
Where the GDPR or UK GDPR applies, we rely on the legal bases below. The correct basis depends on the context and local electronic-marketing law.
- Contract.We process account, organization, brand, connected-service, content, outreach, support, and billing information as needed to provide requested services, administer accounts, and perform our agreements.
- Legitimate interests.We process limited information to secure and improve the service, prevent fraud and abuse, operate our business, understand service performance, maintain suppression records, and support relevant business-to-business prospect research and outreach where those interests are not overridden by individual rights. This basis does not replace consent or opt-out requirements under applicable communications law.
- Consent.We rely on consent where required for optional marketing communications, non-essential tracking, or other processing that applicable law requires you to choose. You may withdraw consent at any time without affecting earlier lawful processing.
- Legal obligation and protection.We process information when necessary to comply with law, respond to lawful requests, keep required financial records, establish or defend legal claims, and protect users, Hivewave, and the public.
How Hivewave AI and automated systems process information
Hivewave uses automated search, enrichment, rules, and language models to crawl brand sources, identify and rank business candidates, verify contacts, draft outreach, translate content, classify replies, recommend actions, and attribute outcomes. Depending on configuration, inputs can include brand materials, contact details, outreach messages, and reply content.
Merchant controls, feature settings, approvals, and kill switches apply to sending and other consequential actions. Hivewave does not use solely automated processing to make decisions that produce legal or similarly significant effects about consumers. If this changes, we will update this notice and provide any required controls.
Hivewave does not train its own generalized public AI model on customer, mailbox, or prospect content. We select AI providers and account settings based on the task, available contractual protections, security, quality, cost, and processing location. Provider retention and model-improvement terms can differ. Google Workspace data remains subject to the stricter commitments in the next section.
Google Workspace and Gmail data
If you connect Gmail, Hivewave requests Gmail compose and read-only scopes. We use that access to create or send merchant-approved drafts, identify replies and related sent messages in Hivewave-owned outreach threads, show reply workflows, and maintain connection security. We store encrypted refresh credentials and the filtered message fields described above.
We do not sell Google user data, use it for advertising, transfer it to data brokers, or use it to train generalized AI models. Human access is limited to cases where you give specific permission, where access is necessary for security or abuse investigation, where law requires it, or where access is necessary for internal operations and the data has been aggregated or protected to the extent required by Google policy.
We share Google user data only with service providers necessary to deliver or secure the user-facing features you request, under data-protection obligations. The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When we disclose information
We do not sell personal information or share it for cross-context behavioral advertising. We disclose information only as described below.
- Service providers and subprocessors.We use providers for hosting, databases, authentication, storage, transactional email, connected-platform APIs, payments, AI processing, search, contact enrichment, observability, and security. They receive only information reasonably needed for their role and are subject to contractual or provider terms. Contact contact@hivewave.ai if you need the current provider list for a regulated deployment.
- Connected services and recipients.We send data to services you connect and to business contacts when your authorized workflow creates or sends outreach.
- Legal and safety reasons.We may disclose information to comply with law or legal process, enforce agreements, investigate abuse, or protect rights, property, and safety.
- Business transfers.Information may transfer in a financing, merger, acquisition, reorganization, or sale of assets, subject to applicable notice and data-protection obligations.
Data retention and deletion
We retain each category only for the period or under the criteria needed for the purpose described, to honor suppression choices, and to meet security, accounting, dispute, and legal obligations.
- Accounts and organization data.Retained while the account or organization is active and afterward only as needed to complete a verified deletion request, resolve disputes, prevent fraud, and meet legal obligations.
- Shopify data.Retained while the connection is active and then deleted or deidentified in response to uninstall, shop redaction, customer redaction, or a verified request, except where limited records must be retained by law.
- Mailbox data.OAuth credentials are retained while the connection exists. Removing a sender revokes credentials where supported and deletes the mailbox record and captured inbound messages associated with it. Limited send, suppression, and audit records may remain where needed for safety, compliance, dispute handling, and accounting.
- Uploads and temporary records.Incomplete media uploads expire after 7 days, and soft-deleted media is normally purged after 30 days. Organization invitations and email-sender access requests normally expire after 14 days if not completed.
- Suppression records.Do-not-contact records may be retained for as long as necessary to honor the opt-out and avoid contacting the person again.
- Billing and legal records.Stripe and Hivewave retain transaction and subscription records for the periods required by tax, accounting, fraud-prevention, and other applicable laws.
- Logs, backups, and observability.Retained under provider and environment schedules based on security, reliability, and incident-response needs. We minimize or redact direct identifiers where practical. Deletion from active systems may precede rotation from encrypted backups.
International transfers
Hivewave and its providers may process information in the United States, Canada, the European Economic Area, the United Kingdom, and other countries where our providers operate. If a directly hosted DeepSeek profile is enabled, relevant AI inputs may be processed in China or another location disclosed by that provider. These countries may have different data-protection laws.
Where required, we use an applicable transfer mechanism such as an adequacy decision, the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful safeguard. Contact us to request information about the relevant safeguard. Deployment and model-provider configuration can affect processing locations.
Your privacy rights
Depending on your location and our role, you may have rights to access, correct, delete, restrict, object to processing, receive a portable copy, withdraw consent, opt out of sale, sharing, targeted advertising, or certain profiling, and appeal a denied request. You also may complain to your local privacy or data-protection authority. We will not discriminate against you for exercising a privacy right.
Submit a request to contact@hivewave.ai. Tell us the account, organization, store, mailbox, or business email involved and the right you wish to exercise. We may verify identity and authority, including for an authorized agent, before acting. If Hivewave processes the information only for a merchant, we may direct the request to that merchant or assist the merchant in responding.
United States state privacy disclosures
If a comprehensive US state privacy law applies, the categories collected during the preceding 12 months are those described in Information we collect; the sources are described in Sources of information; the business purposes are described in How we use information; and the recipient categories are described in When we disclose information.
Hivewave has not sold personal information or shared personal information for cross-context behavioral advertising during the preceding 12 months. We do not knowingly sell or share the personal information of people under 16. We use sensitive information such as account credentials, precise message content, and authentication tokens only for permitted service, security, and legal purposes, not to infer characteristics. Because we do not sell or share information for targeted advertising, an opt-out preference signal does not change those practices; we will honor such signals if our practices change and law requires it.
Security
We use administrative, technical, and organizational safeguards designed for the nature of the information, including access controls, encrypted connector credentials, secret management, tenant scoping, logging redaction, and vendor review. No system is completely secure. Please contact us promptly if you believe your account or information is at risk.
Children
Hivewave AI is a business service and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child provided information to us, contact us so we can investigate and delete it where required.
Changes to this policy
We may update this Privacy Policy as our services, providers, or legal obligations change. We will update the date above and provide additional notice or request consent when required for a material change.
Authorized representatives and resellers
Hivewave does not currently authorize any third party to resell Hivewave AI or represent Hivewave for sales, support, or data collection. Verify any claim of authorization with contact@hivewave.ai before sharing information. The operative restriction also appears in our Terms of Service.
Contact us
For privacy questions, rights requests, complaints, or verification of a representative, contact Hivewave Inc. at contact@hivewave.ai.