Cookie Policy

Last updated: April 2026 · Effective Date: 30 April 2026

1. Introduction

This Cookie Policy (“Policy”) explains how CareHive Pte Ltd (“CareHive,” “we,” “our,” or “us”) uses cookies and similar tracking technologies when you visit our website at carehive.ai or interact with our web-based platforms (together, the “Site”). It is a companion document to the CareHive Privacy Policy, which describes how we handle personal data more broadly. Where this Policy uses a term defined in the Privacy Policy, that term has the same meaning here unless we say otherwise.

Our intent in publishing this Policy is to be transparent about a part of the web that is often opaque to users. Cookies are not, in themselves, a privacy violation — most websites cannot operate without them — but the way they are used, and the parties to whom they reveal information, matter. The sections below set out what we use, why, and how you can control it.

2. What Are Cookies and Similar Technologies?

Cookies are small text files that a website places on your device — your computer, phone, or tablet — when you visit it. They allow the website to remember your actions and preferences (such as login state, language, or font size) over time, so that you don’t have to re-enter them every time you return or move between pages. Cookies are widely used because, without them, even basic web features such as staying logged in would not work.

Beyond traditional cookies, websites and applications can use a range of similar technologies that achieve comparable purposes. Where this Policy refers to “cookies,” it should be read as covering the following technologies as well:

  • Web beacons and pixels — small, often invisible images or scripts embedded in pages or emails that report back when a page is loaded or an email is opened.
  • Local storage and session storage — mechanisms built into modern browsers that allow websites to store information on your device in a way functionally similar to cookies.
  • Software development kit (SDK) identifiers — used in our mobile applications, where traditional browser cookies do not apply but where comparable identifiers may be used for analytics, crash reporting, and push notification delivery. The mobile-application position is described in Section 8.

3. Categories of Cookies We Use

We group the cookies set on the Site into four categories, distinguished by what they do and the level of consent that applies to them. The specific cookies in each category, including their names, purposes, durations, and providers, are listed in Annex A.

3.1 Strictly Necessary Cookies

These cookies are essential to the operation of the Site. They include the cookies that keep you logged in to your account, that maintain the integrity of a secure session, and that allow core platform functions to work as you move between pages. Because the Site cannot deliver its basic service without them, these cookies are set without a separate consent step — you give your consent by choosing to use the Site itself. They cannot be disabled through our cookie banner, although your browser settings may allow you to block them, in which case parts of the Site may stop working.

3.2 Performance and Analytics Cookies

These cookies allow us to understand how the Site is being used in aggregate — which pages are visited most often, where users encounter difficulty, and how the Site performs across devices and networks. The information is used to improve the Site, not to identify individual users for marketing or other personalised purposes. These cookies are only set after you give consent through our cookie banner, and you can change your mind at any time through the same mechanism.

3.3 Functional Cookies

These cookies remember choices you have made in the past, such as your preferred language, region, or display preferences, so that the Site can present itself in the way you have set it up. Like analytics cookies, they are only set with your consent through the cookie banner, and the consent can be withdrawn through the same mechanism.

3.4 Targeting and Marketing Cookies

These cookies, if used, would record information about your visit to inform advertising or marketing activity. As of the effective date of this Policy, CareHive does not set targeting or marketing cookies on the Site, and Annex A reflects that position. We are including this category in the Policy so that the framework is in place if our marketing approach changes; if we begin to set targeting cookies in the future, we will update Annex A, give visible notice through the cookie banner, and require explicit opt-in consent before any such cookie is set.

4. Consent and How We Obtain It

Our position on consent is straightforward: cookies that are not strictly necessary to operate the Site are set only after you have given consent for them. We rely on an explicit opt-in model rather than implied consent, on the basis that this is the standard most consistent with the direction of travel under the Singapore Personal Data Protection Act and with global expectations under frameworks such as the GDPR.

Consent is obtained through the cookie banner that appears on your first visit to the Site, and that you can re-open at any time through a link in the Site footer. The banner offers:

  • Granular control — you can accept or reject Performance & Analytics, Functional, and Targeting & Marketing cookies independently of one another, rather than only an all-or-nothing choice.
  • Equal prominence of accept and reject — the option to reject non-essential cookies is presented with the same prominence as the option to accept them; we do not use design patterns that bias the choice toward acceptance.
  • Withdrawable consent — you can change your preferences at any time. Withdrawal takes effect immediately for cookies set going forward, and previously-set cookies in the affected category are deleted by the banner where technically possible.
  • Recorded consent — the consent state itself is stored in a strictly necessary cookie so that we can honour your choice on subsequent visits without showing the banner again until your preferences are reset or the policy materially changes.

5. Third-Party Cookies

Some of the cookies on the Site are set not by CareHive directly but by third-party services we use to operate, secure, or improve the Site. The use of these services is necessary to deliver the experience users expect, and we hold each third party we engage to data protection standards consistent with our internal Data Processing Agreement framework. The relationship is, however, a contractual one: we do not control the technical behaviour of third-party cookies once they are set, and the third party’s own cookie and privacy policies apply alongside ours. The third parties whose cookies may appear on the Site are:

  • Google Analytics (Performance & Analytics) — used to understand aggregate Site usage, set only with consent. Google’s cookie policy applies to these cookies; CareHive uses Google Analytics in a configuration that anonymises IP addresses and disables advertising features.
  • Vercel (Strictly Necessary) — our web hosting provider may set diagnostic and routing cookies essential to delivering the Site reliably. These are categorised as strictly necessary and are not used for analytics or marketing.
  • Amazon Web Services (Strictly Necessary) — our cloud infrastructure provider may set cookies relating to load balancing, session affinity, and security. These are operational and not used for analytics or marketing.

A complete and current list of third-party cookies, with the specific cookie names and durations, is provided in Annex A. We review the third-party cookie inventory at each governance review cycle and whenever we add or change a third-party service that may set cookies.

6. Cookie Lifespans and Expiration

Cookies fall broadly into two lifetimes: session cookies, which are deleted automatically when you close your browser, and persistent cookies, which remain on your device for a defined period. We apply the following lifespan principles to limit the duration that cookies remain on a user’s device beyond what is necessary for their stated purpose:

  • Strictly necessary cookies — use the shortest practical lifetime consistent with delivering their function. Session cookies wherever possible; persistent cookies only where required (for example, to remember a logged-in state across browser restarts).
  • Analytics and functional cookies — capped at a maximum of thirteen (13) months of persistence, after which the cookie expires and the user is re-prompted for consent on next visit.
  • Targeting and marketing cookies — if reintroduced in the future, will be capped at a maximum of thirteen (13) months of persistence and will be subject to fresh explicit consent at each renewal.

The specific lifespan of every cookie set on the Site is recorded in the Duration column of Annex A. Where a third-party service sets a cookie with a longer default lifespan than our policy permits, we configure the integration to override that default where possible, or document the limitation in Annex A where it is not.

7. Managing Your Cookie Preferences

You have several layers of control over cookies. The most direct is the CareHive cookie banner described in Section 4, which lets you change your preferences at any time. Beyond that, your web browser provides settings to manage cookies more broadly:

  • Browser-level cookie controls — every major browser allows you to refuse all cookies, refuse third-party cookies only, alert you when websites set cookies, and delete existing cookies. The exact location of these settings differs between browsers; the help section of your browser will provide instructions specific to it.
  • Device-level controls (mobile) — mobile operating systems provide separate controls for advertising identifiers, app tracking, and analytics, which apply to our mobile applications. These controls are described further in Section 8.
  • Opt-out mechanisms for specific third parties — some third-party services we use (for example, Google Analytics) provide their own opt-out mechanisms. Where such mechanisms exist for third parties listed in Annex A, links are provided in the corresponding entry.

Disabling or refusing cookies has consequences for the Site experience. Strictly necessary cookies cannot be disabled without breaking parts of the Site. Disabling functional cookies will remove personalisation. Disabling analytics cookies has no user-visible effect on the Site itself; it simply prevents us from measuring usage. To learn more about cookies generally, including how to inspect what cookies have been set on your device, the resources at www.aboutcookies.org and www.allaboutcookies.org are useful starting points.

8. Mobile Applications and SDK Identifiers

Cookies are a web concept, and our native mobile applications (the iOS and Android versions of HiveLink, HiveOS, HiveVoice, and HiveStory) do not use cookies in the technical sense. They do, however, use comparable technologies for purposes that overlap with the categories described in Section 3. Specifically:

  • Push notification tokens — each device installation generates a token issued by the operating system (Apple Push Notification service or Firebase Cloud Messaging) that we use to deliver notifications such as medication reminders and SOS alerts. These tokens are essential to core functionality and are described in the CareHive Privacy Policy under Device and Technical Data.
  • Crash reporting and diagnostic identifiers — anonymised identifiers that allow us to attribute crash reports and diagnostic events to a specific installation for the purpose of debugging, without identifying the user.
  • Mobile analytics identifiers — used, with consent obtained at first launch through the mobile equivalent of our cookie banner, to understand aggregate usage patterns within the applications. These identifiers respect the operating system’s tracking permission settings (for example, App Tracking Transparency on iOS).

The mobile applications honour the operating system’s privacy and tracking controls. On iOS, this includes App Tracking Transparency; on Android, the Advertising ID controls and the Privacy Sandbox preferences as they become available. Users who have set their device to refuse tracking will not be tracked by the CareHive applications, and we do not seek to circumvent these controls.

9. Do Not Track Signals

Some browsers offer a “Do Not Track” (DNT) signal, which is a header that the browser sends to websites expressing a preference not to be tracked. There is currently no settled legal requirement in Singapore that obliges websites to respond to DNT signals in a specific way, and the technical interpretation of the signal varies between browsers.

Our position is to treat a DNT signal as a strong indication of user preference and to apply it as follows: where a DNT signal is detected, we will not set Performance & Analytics, Functional, or Targeting & Marketing cookies regardless of any prior banner consent, until the signal is no longer present. Strictly necessary cookies will continue to be set, since the Site cannot operate without them. We do not sell or share user-level data with third parties for advertising purposes regardless of the DNT signal.

10. Updates to This Policy

We review this Cookie Policy at least annually and revisit it whenever a material change to our use of cookies, our third-party services, or applicable law makes it necessary. When we make a material change — for example, adding a new category of cookie, engaging a new analytics provider, or changing the way consent is obtained — we will:

  • Update the Effective Date on this page and Annex A so that the change is dated and traceable.
  • Re-prompt for consent through the cookie banner on a user’s next visit, so that the user has a fresh opportunity to review the change and confirm or adjust their preferences.
  • Where the change is significant in scope or affects what data is collected about users, supplement the in-banner notice with a Site-wide announcement giving users sufficient time to review the change.

Non-material changes — such as clarifications of wording, corrections of typographical errors, or technical updates that do not affect what we collect or with whom we share it — are reflected in the published version without separate notice.

11. Contact Us

Questions about this Cookie Policy, requests for further information about a specific cookie or third-party service, or concerns about how cookies are used on the Site should be directed to our Data Protection Officer using the contact details below. The general user rights described in the CareHive Privacy Policy, including the right to lodge a complaint with the Personal Data Protection Commission, apply to cookie-related matters where personal data is involved.

ChannelDetails
Data Protection OfficerActing DPO, pending formal appointment of dedicated DPO in 2026
Emailprivacy@carehive.ai
Postal addressCareHive Pte Ltd, Attention: Data Protection Officer, Singapore
RegulatorPersonal Data Protection Commission (PDPC), Singapore — www.pdpc.gov.sg

Annex A — Cookie Inventory

This Annex sets out the specific cookies and similar technologies set on the Site as of the effective date of this Policy. The inventory is reviewed at each governance cycle and whenever a third-party service that sets cookies is added, removed, or changed. Where a third-party service updates the technical name or purpose of a cookie, the change is reflected in the next published version of this Policy.

A.1 Strictly Necessary Cookies

Cookie NamePurposeDurationProvider
carehive_sessionMaintains an authenticated user session across page loadsSessionCareHive (first-party)
carehive_csrfCross-site request forgery protection token for form submissions and authenticated actionsSessionCareHive (first-party)
carehive_cookie_consentRecords the user’s cookie consent preferences so that the banner is not shown on every visit12 monthsCareHive (first-party)
__vercel_*Routing, load balancing, and security cookies set by our hosting providerSession to 1 yearVercel (third-party)
aws-elb-*Session affinity for AWS load balancing, ensuring requests in a session reach the same backendSessionAmazon Web Services (third-party)

A.2 Performance and Analytics Cookies

Cookie NamePurposeDurationProvider
_gaDistinguishes unique users for aggregate analytics, with IP anonymisation enabled13 monthsGoogle Analytics (third-party)
_ga_*Used by Google Analytics to persist session state for aggregate analytics13 monthsGoogle Analytics (third-party)
_gidDistinguishes users for short-window analytics within a 24-hour period24 hoursGoogle Analytics (third-party)

A.3 Functional Cookies

Cookie NamePurposeDurationProvider
carehive_langRemembers the user’s preferred display language across visits13 monthsCareHive (first-party)
carehive_ui_prefsStores non-sensitive UI preferences such as display density and theme13 monthsCareHive (first-party)

A.4 Targeting and Marketing Cookies

As of the effective date of this Policy, CareHive does not set any targeting or marketing cookies. This Annex section will be populated if and when targeting cookies are introduced, and the change will be subject to the consent and notification mechanism described in Sections 4 and 10.

See also our Privacy Policy and Terms of Service.