KidHive
Log in

Security Policy

Revision 2.1 · Effective July 12, 2026

This Security Policy describes, in plain terms, how KidHive, LLC. ("KidHive," "we," "us") works to protect the information entrusted to us through the KidHive website and web app (the "Service"). It expands on the security section of our Privacy Policy. No system is perfectly secure, so this policy describes our approach and commitments rather than a guarantee. Questions or concerns: info@KidHive.co.

Our approach

We take a layered approach to security and aim to apply safeguards appropriate to the sensitivity of the information we hold — with particular care for anything that relates to a child. Our security practices are reviewed periodically and updated as the Service and the threat landscape evolve.

How we protect information

In transit and at rest. We use encryption to protect personal information as it travels between your device and our systems, and we protect stored information using industry-standard methods.

Payment data. We do not store full payment card numbers. Card data is handled by our payment processor, Stripe, which maintains PCI-DSS compliance for processing and storing payment information.

Children's data. Information relating to a child (a first name and birth year) is kept to the minimum and protected with row-level access controls so it is visible only to the parent who provided it and, for a specific booking, the Provider hosting it. Access to these records is logged.

Access controls. We limit access to personal information to people who need it to do their jobs, and we use authentication and permission controls to enforce that. Administrative access is restricted, requires multi-factor authentication, and is monitored.

Infrastructure. We host the Service with reputable cloud providers and rely on a combination of network protections, monitoring, and secure configuration to defend our systems. We maintain backups to support recovery.

Development practices. We aim to build security into how we work — including reviewing changes, keeping software and dependencies reasonably up to date, and addressing known vulnerabilities.

Service providers. Vendors who process information on our behalf are contractually required to protect it and use it only for the services we've engaged them to perform.

Data minimization. We collect only what we need, apply high-privacy defaults to information that relates to children, and retain information no longer than necessary (see our Privacy Policy for retention details).

Your part in security

Security is shared. You can help protect your account by choosing a strong, unique password, keeping your credentials confidential, signing out on shared devices, and keeping your browser and device updated. Tell us promptly at info@KidHive.co if you believe your account has been accessed without your permission.

If a security incident occurs

We maintain procedures to detect, investigate, and respond to security incidents. If a breach affects your personal information, we will notify affected users and the appropriate regulators as required by applicable law, without undue delay, and we'll describe what happened and the steps we're taking. We can't promise absolute security, but we commit to acting responsibly and transparently if something goes wrong.

Reporting a vulnerability

If you believe you've found a security vulnerability in the Service, please report it to info@KidHive.co with enough detail for us to reproduce it. We ask that you give us a reasonable opportunity to address the issue before disclosing it publicly, and that you don't access or modify data that isn't yours or disrupt the Service while testing. We appreciate responsible disclosure and will work with you in good faith.

Updates

We may update this Security Policy as our practices change. We'll revise the "Effective" date above and, where appropriate, provide notice in the Service.

Contact

KidHive, LLC.info@KidHive.co