HomeField US, Inc., d/b/a Kibu
Last Updated: 2026-07-07
Privacy Policy
HomeField US, Inc., d/b/a Kibu
Last Updated: July 7, 2026
KIBU PRIVACY POLICY
This Privacy Policy explains how HomeField US, Inc., d/b/a Kibu (“Kibu,” “we,” “us,” or “our”), a Delaware corporation with offices at 78 Harvard Ave, Floor 3, Stamford, CT 06902, collects, uses, discloses, and protects information about you in connection with our websites, mobile and device applications, communications (such as emails, calls, and texts), in-person or virtual classes and Studios, and related content and services (collectively, the “Service”). Capitalized terms not defined here have the meanings given in our Terms of Service.
IMPORTANT — HEALTH INFORMATION AND ENTERPRISE SERVICES. Kibu provides software to provider organizations that serve individuals with intellectual and developmental disabilities. When we create, receive, maintain, or transmit protected health information (“PHI”) or other records on behalf of a provider organization through our Enterprise Services, we act as that organization’s service provider and “business associate,” and that information is governed by our Business Associate Agreement and Master Subscription Agreement (“MSA”) with the organization and by the Health Insurance Portability and Accountability Act (“HIPAA”) — not by this Privacy Policy. If you are an individual served by a provider organization (a “Member”) or a Guardian, and you have questions about information held on that organization’s behalf, please contact the organization; it controls that information as the covered entity. This Privacy Policy describes our practices for information for which Kibu acts as a business (a controller), including our websites, marketing, consumer memberships, and account administration.
1. Who This Policy Applies To
This Privacy Policy applies to: visitors to our websites; individuals who purchase or use Kibu’s consumer memberships, classes, and content directly; Members and Guardians who use our consumer content directly; and personnel of provider organizations and other business contacts who interact with our websites, sales, and support. Where we process information as a business associate or service provider on behalf of a provider organization, the MSA, the Business Associate Agreement, and HIPAA govern, and this Policy does not apply to that information.
2. Personal Information We Collect
“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household, or device. Personal Information does not include de-identified or aggregated information or publicly available information, as described below. The categories of Personal Information we collect, the purposes for which we use them, and whether we disclose or “sell”/“share” them are summarized in the table below and described in this Policy.
Some information we collect is “Sensitive Personal Information,” including health or disability-related information and account log-in credentials. We use and disclose Sensitive Personal Information only for the purposes permitted by law and described in this Policy, and you may have the right to limit certain uses as described in “Your Privacy Choices and Rights.” The “*” in the table indicates that health and disability-related information is, in most cases, processed on behalf of provider organizations under HIPAA and the MSA rather than under this Policy.
| Category of Personal Information | Collected | Disclosed to service providers | “Sold”/“Shared” for ads |
|---|---|---|---|
| Identifiers (name, email, phone, address, IP, device/ad IDs, account IDs) | Yes | Yes | Yes – advertising |
| Customer records & commercial info (purchases, subscriptions, support requests) | Yes | Yes | No |
| Protected-class characteristics (age; disability/health status where provided) | Yes | Limited | No |
| Internet/network & device activity (browsing, app usage, interactions) | Yes | Yes | Yes – advertising |
| Approximate geolocation (from IP) | Yes | Yes | No |
| Audio/visual (support recordings; class or activity media) | Sometimes | Limited | No |
| Professional/employment info (provider-staff and business contacts) | Yes | Limited | No |
| Health / disability-related information (Sensitive PI) | Yes* | Limited | No |
| Inferences drawn from the above | Yes | Yes | Yes – advertising |
“Limited” indicates disclosure only to service providers under contract for the purposes described. * See the health-information note above.
3. How We Collect Personal Information
Directly from you — when you register, purchase a membership or product, sign up for classes, contact support, request a demo, or otherwise communicate with us.
Automatically — when you use our websites and apps, we and our service providers and partners collect device and usage information using cookies, pixels, tags, SDKs, and similar technologies, as described in “Cookies and Tracking Technologies.”
From third parties — including provider organizations that arrange access for their Members and staff, our service providers, advertising and analytics partners, identity-resolution partners, and social media platforms.
4. Cookies and Tracking Technologies
We and third parties use cookies, pixel tags, web beacons, software development kits, and similar technologies (“Cookies”) to operate and secure the Service, remember your preferences, analyze usage, and support advertising and marketing. Most browsers let you block or delete Cookies; if you reject some Cookies, parts of the Service may not function.
Analytics. We use analytics providers, including Google Analytics, to understand how visitors use our websites. You can opt out of Google Analytics at https://tools.google.com/dlpage/gaoptout.
Advertising and identity-resolution partners. We work with advertising and identity-resolution partners — currently including LiveIntent (which may load from liadm.com domains), Retention.com, and RB2B — that may associate your activity on our websites with other information about you (including your email address) to help us deliver and measure marketing. Under some state laws, this constitutes a “sale” or “sharing” of Personal Information for cross-context behavioral advertising. You can opt out as described in “Your Privacy Choices and Rights,” including by using an opt-out preference signal (such as Global Privacy Control), and through the partner opt-outs at https://app.retention.com/optout, https://www.rb2b.com/rb2b-gdpr-opt-out, and https://privacy.liveintent.com/.
Automatic collection and your consent. When you load our webpages, your browser automatically sends requests — including your IP address and device and browser identifiers — to Kibu and to the analytics and identity-resolution providers described above, as an ordinary part of delivering and securing the pages. We disclose these technologies in this Policy and, where required, present a cookie or consent notice when you first visit. By adjusting your browser to accept cookies and by continuing to use our websites after being presented with our cookie notice, you consent to the use of these technologies and to the associated collection and transmission of this information. You may decline or withdraw your consent at any time by using our cookie-preferences tool, adjusting your browser settings, or sending a recognized opt-out preference signal, although some parts of the Service may not function without certain technologies.
Opt-out preference signals. We honor recognized browser-based opt-out preference signals (such as Global Privacy Control) as a valid request to opt out of “sale”/“sharing” and targeted advertising for the browser or device from which we receive them.
5. How We Use Personal Information
We use Personal Information to: provide, operate, personalize, and improve the Service and develop new features and offerings; process transactions, memberships, and orders; provide customer and technical support; communicate with you, including service and marketing messages; maintain security, prevent and detect fraud and abuse, and protect our rights and users; power features that use artificial intelligence, subject to our Responsible AI Policy; and comply with legal obligations and enforce our agreements. We do not use Sensitive Personal Information to infer characteristics about you for purposes other than those permitted by law.
6. How We Share Personal Information
Service providers and processors — vendors that perform services for us, such as hosting, storage, payment processing, identity verification, fraud prevention, security, customer support, analytics, communications, and tax and accounting, under contracts that limit their use of Personal Information to providing services to us.
Advertising and analytics partners — as described in “Cookies and Tracking Technologies,” which may be treated as “selling” or “sharing” under state law and is subject to your opt-out.
Provider organizations — where you access the Service through an organization, we share relevant information with that organization; information we process on the organization’s behalf is governed by the MSA and Business Associate Agreement.
Professional advisors, legal, and safety — to our auditors, lawyers, and advisors, and to comply with law, legal process, or government requests, or to protect the rights, property, or safety of Kibu, our users, or others.
Corporate transactions — in connection with a merger, acquisition, financing, reorganization, asset sale, bankruptcy, or similar transaction, Personal Information may be transferred as a business asset.
With your direction or consent — when you ask us to share your information or otherwise consent.
We do not sell your Personal Information for money. However, because “sale” and “sharing” are defined broadly under some state laws to include disclosures for cross-context behavioral advertising, our use of the advertising and identity-resolution partners described above may be considered a “sale” or “sharing,” and you may opt out.
7. De-Identified and Aggregated Data
We may aggregate, anonymize, or de-identify personal and operational information so that it can no longer reasonably be used to identify you, your business, or your device. Where such information is derived from health information or PHI, we de-identify it in accordance with the HIPAA de-identification standard (45 C.F.R. § 164.514) and our agreements with the applicable provider organization, after which it no longer constitutes PHI or Personal Information.
Once information has been aggregated, anonymized, or de-identified in this way, it is not Personal Information, and we may use, license, or sell it to third parties for analytical, research, benchmarking, product-development, or other commercial purposes. We maintain and use such data only in de-identified or aggregated form, will not attempt to re-identify it except as permitted by law to test our de-identification processes, and contractually require recipients not to attempt to re-identify it.
8. Your Privacy Choices and Rights
Depending on where you live, you may have the right to: know about and access the Personal Information we have collected; request correction of inaccurate Personal Information; request deletion of your Personal Information; obtain a portable copy of certain Personal Information; opt out of the “sale” or “sharing” of Personal Information and of targeted advertising; limit our use and disclosure of Sensitive Personal Information; and not receive discriminatory treatment for exercising your rights.
How to exercise your rights. Submit a request by emailing privacy@kibuHQ.com (or hello@kibuHQ.com) or using the request mechanism on our website. To opt out of “sale”/“sharing” and targeted advertising, use our “Do Not Sell or Share My Personal Information” link, submit a request, or send a Global Privacy Control signal. We will acknowledge your request within 10 business days and respond within 45 days (extendable as permitted by law).
Verification and authorized agents. We will take reasonable steps to verify your identity before responding, and may request additional information. You may use an authorized agent to submit a request with your written permission and verification of your identity. Household requests must be made jointly and verified for each member.
Appeals. If we deny your request and you are a resident of a state that provides an appeal right (such as Virginia, Colorado, Connecticut, Texas, Oregon, or Montana), you may appeal by contacting privacy@kibuHQ.com; if we deny your appeal, you may contact your state attorney general.
9. State-Specific Disclosures
California (CCPA/CPRA). California residents have the rights described above, including the right to know, delete, correct, opt out of sale/sharing, and limit Sensitive Personal Information, and the right not to be discriminated against. We do not knowingly sell or share the Personal Information of consumers under 16 without opt-in consent. The categories of Personal Information we collect, disclose, and “sell”/“share” are described in the table above; sources and purposes are described throughout this Policy. California’s “Shine the Light” law: we do not disclose Personal Information to third parties for their own direct marketing without consent.
Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states. Residents of states with comprehensive privacy laws have rights to access, correct, delete, obtain a copy of, and opt out of the sale of Personal Information and of targeted advertising and certain profiling, and (where applicable) to provide or withhold consent for processing Sensitive Data. We obtain consent to process Sensitive Data where required and honor opt-out preference signals.
Nevada. Nevada residents may submit a request that we not make a covered “sale” of certain information. We do not sell such information as defined by Nevada law and will provide notice and choice if that changes.
Do Not Track. Because there is no common standard, we respond to recognized opt-out preference signals (such as Global Privacy Control) but may not respond to other “Do Not Track” signals.
10. Consumer Health and Sensitive Data
In addition to HIPAA (which governs PHI we process on behalf of provider organizations), some states have consumer-health-data laws (such as Washington’s My Health My Data Act, Nevada’s SB 370, and Connecticut’s health-data provisions). Where these laws apply to consumer health data that we control, we will obtain any required consent before collecting or sharing such data, honor applicable rights (including the right to withdraw consent and to have consumer health data deleted), and will not sell consumer health data without your valid authorization. Health and disability-related information is treated as Sensitive Personal Information.
11. Children’s and Minors’ Privacy
Kibu’s consumer websites and marketing are directed to a general adult audience and are not intended for children under 13. We do not knowingly collect Personal Information from a child under 13 through our consumer Service without verifiable parental or guardian consent, and we do not “sell” or “share” the Personal Information of minors under 16 without opt-in consent.
Because Kibu’s content and activities are designed for individuals with disabilities — who may include minors — minors typically access the Service through a provider organization or with the involvement of a parent or Guardian. Where a Member is a minor and uses the Service through a provider organization, the organization is responsible under the MSA for obtaining any legally required parental or guardian consent (including under the Children’s Online Privacy Protection Act), and that information is handled under the MSA and Business Associate Agreement. If you believe a child has provided us Personal Information without appropriate consent, contact privacy@kibuHQ.com and we will take appropriate steps to delete it.
12. Data Retention
We retain Personal Information for as long as necessary to provide the Service, maintain your account, comply with our legal obligations, resolve disputes, and enforce our agreements, after which we delete or de-identify it. Retention of PHI and Customer Data processed for provider organizations is governed by the MSA, the Business Associate Agreement, and the Security Addendum.
13. Security
We maintain administrative, technical, and physical safeguards designed to protect Personal Information appropriate to its sensitivity. No system is perfectly secure, and we cannot guarantee the security of information transmitted over the Internet. You help protect your information by keeping your credentials confidential and logging out of shared devices. Our security program for Customer Data processed under the MSA is described in the Security Addendum to the MSA.
14. International Users
The Service is operated from the United States and intended for users in the United States and Canada. If you access the Service from outside the United States, you understand that your information will be processed in the United States, where privacy laws may differ from those in your location.
15. Third-Party Websites and Services
The Service may link to or integrate third-party websites, platforms, or services that we do not control. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. Please review their policies.
16. Marketing Communications
Subject to applicable law, we may send you marketing emails and, where you have provided any required consent, text messages. You may opt out of marketing emails using the unsubscribe link, and of texts by replying STOP. Service and transactional messages are not promotional and may still be sent.
17. Accessibility
We are committed to making our communications and Service accessible to people with disabilities and strive to conform to recognized accessibility standards. To request an accessible format or report an accessibility barrier, contact privacy@kibuHQ.com or hello@kibuHQ.com.
18. Disputes
Any dispute relating to this Privacy Policy or our processing of your Personal Information is subject to the governing-law, arbitration, and class-action-waiver provisions of our Terms of Service, except where those provisions are unenforceable or where a privacy law provides otherwise.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will post the updated Policy with a revised “Last Updated” date and, where required, provide additional notice. Your continued use of the Service after the changes take effect constitutes acceptance of the updated Policy.
20. Contact Us
If you have questions or requests regarding this Privacy Policy or our processing of your Personal Information, contact us at privacy@kibuHQ.com or hello@kibuHQ.com, or write to: HomeField US, Inc., d/b/a Kibu, 78 Harvard Ave, Floor 3, Stamford, CT 06902, Attn: Privacy / Legal Department.