Privacy Policy
Last updated 17 July 2026
1. Introduction
This Privacy Policy explains how Hive — a business run by a sole trader based in the United Kingdom ("Hive", "we", "us" or "our") — collects, uses, shares and protects information about you when you use our website, Telegram Mini App, Telegram bots, and related services (together, the "Platform"). We are the data controller for the personal data described in this policy.
We are committed to handling your data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy should be read alongside our Terms of Service.
2. Data We Collect
We collect the following categories of information:
- Account & identity data — your Telegram user ID, first name and username, provided to us when you authenticate through Telegram (see Section 3).
- Subscription & billing data — your plan, subscription status, billing history and payment method summary (such as card type and last four digits) as provided to us by Stripe; and, for cryptocurrency payments, the wallet address and transaction details associated with your payment.
- Trading Profile & configuration data — the risk limits, signal sources, trading pairs, direction preferences, position sizing and other settings you configure within the Platform.
- Exchange connection data — API credentials you provide to connect a third-party exchange account, and the trade/position data those credentials allow us to read or act on (see Section 5).
- Usage & performance data — how you use the Platform, including decisions AutoPilot makes on your behalf, Paper Trading results, realised and unrealised performance, and interactions with signals, Hive AI and other features.
- Technical data — IP address, device and browser information, and log data generated automatically as you use the Platform.
- Communications — messages you send us for support, coaching bookings, or other enquiries, including information you choose to share when preparing for a coaching session.
3. Telegram Authentication
You sign in to Hive using Telegram. When you do, Telegram provides us with a small, defined set of information — your Telegram user ID, first name and username — which Telegram itself cryptographically signs so we can verify it genuinely came from you. We use this information solely to identify your account, personalise the interface (such as greeting you by name), and enforce access to the features your subscription includes.
We do not receive, request or have access to your Telegram messages, contacts, phone number, or any other Telegram data beyond what is described above. Telegram's own handling of your data is governed by Telegram's own privacy policy, which we encourage you to review separately.
4. Payment Processing (Stripe)
Card payments are processed by Stripe, a PCI-DSS compliant payment processor. When you subscribe by card, your payment details are sent directly to Stripe — we never receive or store your full card number, expiry date or CVC. We receive limited information back from Stripe necessary to manage your subscription, such as your subscription status, billing history, and a masked summary of your payment method.
Stripe processes this data as an independent controller under its own privacy policy, in addition to acting as our processor for the purposes described here.
5. Exchange Connections
If you connect a third-party exchange account (such as Bitunix or BYDFi), you provide us with an API key that you generate. We store API credentials in encrypted form and use them only to read your account/position data and, where you have configured AutoPilot to do so, to place or manage trades strictly within the parameters of your Trading Profile. We instruct users to issue API keys with trading permissions only, never withdrawal permissions, and we never use exchange credentials to move or withdraw your funds.
6. Cryptocurrency Payments
Where you pay using cryptocurrency, we collect the wallet address and transaction hash associated with your payment so we can confirm receipt. Blockchain transactions are public by design — the payment amount, sending address and receiving address are visible on the relevant public blockchain regardless of anything we do. We do not collect additional identity verification for crypto payments beyond what is described in this policy.
7. How We Use Your Data
We use the data described above to:
- provide, maintain and personalise the Platform, including delivering signals, running the Decision Engine, and operating AutoPilot according to your Trading Profile;
- process payments, manage subscriptions, and handle billing enquiries or disputes;
- generate the performance analytics and dashboards shown to you within the Platform;
- communicate with you about your account, service updates, or in response to your enquiries;
- maintain the security of the Platform, including detecting fraud, abuse and unauthorised access; and
- comply with our legal and regulatory obligations, including financial record-keeping.
Legal basis
Under UK GDPR, we rely on: performance of a contract (to provide the Platform and process payments you've requested); legitimate interests (to secure the Platform, prevent fraud, and improve our services); consent (where you opt in to marketing communications or optional cookies); and legal obligation (for tax, accounting and regulatory record-keeping).
8. Data Sharing
We do not sell your personal data. We share data only with the following categories of recipient, and only as necessary for the purposes described in this policy:
- Stripe, to process card payments and manage subscriptions;
- Telegram, as the platform through which you authenticate and receive messages from us;
- the exchange(s) you connect, solely via the API credentials you provide, to read and manage your own trading account;
- infrastructure and hosting providers who process data on our behalf under contract; and
- regulators, law enforcement or other third parties where required by law, or to protect our rights or the safety of our users.
International transfers
Some of the providers above (including Stripe and Telegram) may process data outside the UK. Where this happens, we rely on appropriate safeguards recognised under UK data protection law, such as Standard Contractual Clauses or an adequacy decision covering the destination country.
9. Cookies
We use a limited number of cookies and similar technologies. Strictly necessary cookies (for example, to keep you signed in and remember your session) are used without requiring consent, as permitted under UK law. Where we use any non-essential cookies — such as analytics cookies — we will only do so with your consent, which you can withdraw at any time through your browser settings or any cookie preferences we make available.
10. Analytics
We use analytics to understand how the Platform is used — for example, which features are used most, general usage patterns, and aggregated performance metrics. This may include page views, feature engagement, and technical data such as device and browser type. Analytics data is used to improve the Platform and is not used to make automated decisions that produce legal or similarly significant effects about you.
11. Data Retention
We retain your data for as long as your account is active, and for a reasonable period afterwards to comply with legal, tax and accounting obligations, resolve disputes, and enforce our agreements. Financial records (such as billing and payment history) are typically retained for at least six years to meet UK tax record-keeping requirements. When data is no longer needed for these purposes, we delete or anonymise it.
12. Data Security
We use appropriate technical and organisational measures to protect your data, including encryption of sensitive data such as exchange API credentials, and access controls limiting who within our team can view personal data. No system can be guaranteed completely secure, and we cannot guarantee the absolute security of information transmitted to us.
13. Your Rights
Under UK GDPR, you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate or incomplete data;
- request erasure of your data, subject to our legal retention obligations;
- request that we restrict or object to certain processing;
- receive a copy of your data in a portable format; and
- withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, contact us using the details in Section 16. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data properly.
14. Children's Privacy
The Platform is not directed at, and must not be used by, anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to the Platform or our legal obligations. Where changes are material, we will make reasonable efforts to notify active subscribers before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
16. Contact
Questions about this policy, or requests relating to your personal data, can be sent to us through our official Telegram channels, including the Hive Subscribe Bot. We will respond to any verified request within the timeframes required by UK data protection law. If you are not satisfied with our response, you can complain to the ICO — see Section 13.