Table of Contents
Introduction & Scope
This Privacy Policy ("Policy") is published by Pro-Lab Diagnostics USA ("Company," "we," "us," or "our") and describes how we collect, use, disclose, and safeguard information when you use Microbank Marketplace — our SaaS platform, mobile applications (iOS and Android), and website (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this Policy. This Policy is incorporated by reference into our Terms of Service and forms part of the same legal agreement.
Scope: This Policy applies to all users of the Service, including company administrators, laboratory managers, researchers, and any other individuals who create an account or otherwise interact with the Service. It does not apply to third-party websites, services, or applications that may be linked from within the Service.
Information We Collect
2.1 Account & Registration Information
When you create an account, we collect:
- First and last name
- Work email address
- Password (stored as a one-way cryptographic hash — we never store your plaintext password)
- Organization/company name and your role within it
- Phone number (optional)
2.2 Profile & Organizational Data
As you use the Service, we collect data you actively provide:
- Laboratory and freezer/storage unit information you create
- Specimen and vial inventory records, including catalog IDs, biological classifications, storage conditions, volume measurements, and other non-identifying metadata
- Marketplace listings and associated specimen descriptions
- In-app direct messages sent to other users
- Feedback and support inquiries you submit
2.3 Usage & Technical Data
We automatically collect certain technical data when you use the Service:
- IP address and approximate geographic location (city/region level only)
- Device type, operating system, and browser or app version
- Session timestamps, feature usage events, and navigation patterns
- Crash reports, error logs, and performance diagnostics
- Push notification tokens (iOS/Android only, for in-app alerts)
2.4 Payment & Subscription Data
We use third-party payment processors (Stripe for web, RevenueCat/App Store/Google Play for mobile). We do not store or have direct access to full payment card numbers. We may retain subscription status, plan type, billing period, and transaction references for account management purposes.
2.5 Social Login Data
If you sign in using Google or Apple Sign-In, we receive from the identity provider only your name and email address. We do not receive access to your full social profile, contacts, or any other data from those accounts.
How We Use Your Information
We use the information we collect for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Creating and managing your account; authenticating your identity | Contract performance |
| Providing and operating the Service and its features | Contract performance |
| Processing subscription payments and managing billing | Contract performance |
| Sending transactional emails (verification, password reset, billing receipts) | Contract performance |
| Sending service announcements and critical security notices | Legitimate interest |
| Detecting, investigating, and preventing fraud, abuse, and security incidents | Legitimate interest |
| Improving Service functionality, performance, and reliability | Legitimate interest |
| Complying with legal obligations and responding to lawful requests | Legal obligation |
| Enforcing our Terms of Service and other policies | Legitimate interest |
We will not use your information for automated profiling or decisions that produce legal or similarly significant effects without your explicit consent.
Sharing & Disclosure
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We share information only in the following limited circumstances:
4.1 Within Your Organization
If you are part of a company account, your name, email, and role are visible to other members of your organization within the Service. Administrators can view, manage, and revoke access for members of their organization.
4.2 Marketplace Visibility
If you publish specimen listings to the Marketplace, the listing details (specimen metadata, your name, and your organization name) are visible to all authenticated users of the Service. Do not include personally identifiable information in listing descriptions.
4.3 Service Providers
We engage trusted third-party vendors who process data on our behalf under strict data processing agreements:
- Amazon Web Services (AWS) — Cloud infrastructure, database hosting, file storage, and email delivery (SES)
- Firebase / Google — Identity provider for authentication (Google Sign-In, Apple Sign-In via Firebase Auth); we minimize data shared
- Stripe — Payment processing for web subscriptions
- RevenueCat — Mobile in-app purchase management
- Firebase Cloud Messaging (FCM) — Push notification delivery to mobile devices
4.4 Legal Requirements
We may disclose your information if required by law, court order, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, prevent fraud, protect the safety of any person, or comply with a government request.
4.5 Business Transfers
In the event of a merger, acquisition, asset sale, or business restructuring, your information may be transferred as part of that transaction. We will notify you before your personal information is transferred and becomes subject to a different privacy policy.
4.6 Aggregated / De-identified Data
We may share aggregated or de-identified data that cannot reasonably be used to identify you (e.g., platform-wide usage statistics) with partners or the public without restriction.
PHI Prohibition & HIPAA Non-Compliance Notice
All users are strictly prohibited from entering any PHI into the Service. PHI includes any information that identifies — or could be used to identify — an individual in connection with health or medical information. Examples include patient names, dates of birth, social security numbers, medical record numbers, diagnoses, treatment records, insurance information, or any other HIPAA-defined identifier.
Specimen data entered into the Service must be limited to de-identified or anonymous biological material metadata that does not reference any individual. If you have questions about whether specific data qualifies as PHI, consult a qualified HIPAA privacy officer before entering the data.
Any user who enters PHI into the Service does so in direct violation of our Terms of Service, assumes full legal and regulatory liability, and may have their account immediately terminated. We expressly disclaim all liability for PHI entered by users.
Data Security
We implement industry-standard technical and organizational measures to protect your data against unauthorized access, disclosure, alteration, or destruction:
- All data in transit is encrypted using TLS 1.2 or higher
- Data at rest is encrypted using AES-256 on AWS RDS and S3
- Passwords are stored as salted cryptographic hashes (never in plaintext)
- Authentication tokens are short-lived JWTs stored in secure storage on device
- Administrative access to production systems requires multi-factor authentication
- We conduct regular security reviews and maintain audit logs of data access
- Our infrastructure is hosted on AWS within the United States (us-east-2 region)
Despite our efforts, no security measure is 100% foolproof. We cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you as required by applicable law.
Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with the Service. We also retain data as necessary to:
- Comply with applicable legal obligations (including tax, accounting, and regulatory record-keeping requirements)
- Resolve disputes and enforce our agreements
- Maintain audit trails for security and fraud prevention
When you delete your account, we will delete or anonymize your personal information within 90 days, except where retention is required by law or for legitimate business purposes such as fraud prevention, legal proceedings, or financial record-keeping.
Specimen inventory data, marketplace listings, and audit log entries associated with your account will be removed from active systems upon account deletion, subject to any contractual obligations to your organization.
Your Rights & Choices
8.1 Access & Correction
You may access and update your profile information at any time through the Service's Settings screen. If you need to access or correct data not available through the app, contact us at support@pro-lab.us.
8.2 Account Deletion
You may request deletion of your account through the Settings screen ("Delete Account") or by contacting us. Upon deletion, we will remove your personal data in accordance with our retention policy above.
8.3 Data Portability
Upon request, we will provide you with a machine-readable export of the personal data we hold about you. Contact support@pro-lab.us to submit a portability request.
8.4 Opt-Out of Communications
You may opt out of non-essential marketing communications at any time by following the unsubscribe link in any email we send, or by contacting us. You cannot opt out of transactional communications (e.g., account verification, billing receipts, security alerts) that are essential to the operation of your account.
8.5 California Residents
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete, and the right to opt out of the sale of personal information (we do not sell personal information). To exercise these rights, contact us at support@pro-lab.us.
8.6 EEA / UK Residents
If you are in the European Economic Area (EEA) or United Kingdom, you may have rights under the General Data Protection Regulation (GDPR) or UK GDPR, including: access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and the right to object to processing. To exercise these rights, contact us at support@pro-lab.us. You also have the right to lodge a complaint with your local supervisory authority.
Cookies & Tracking Technologies
9.1 Web Application
Our web application uses browser local storage and session storage to maintain your authentication state and user preferences. We do not use third-party advertising cookies or cross-site tracking technologies.
9.2 Essential Functionality
The following storage mechanisms are strictly necessary for the Service to function and cannot be disabled:
- Authentication token — Stores your login session (expires with session or at token expiry)
- User preferences — Remembers settings such as language selection and remembered email
9.3 Analytics
We may collect aggregated, anonymized usage data to understand feature adoption and improve the Service. This data is not linked to your individual identity and is processed server-side from our application logs rather than through browser-level tracking pixels.
Third-Party Services & Links
The Service integrates with and may link to third-party services (Google Sign-In, Apple Sign-In, Stripe, RevenueCat, etc.). These third parties have their own privacy policies, and we encourage you to review them. We are not responsible for the privacy practices of any third-party service.
Links to external websites within the Service (e.g., regulatory guidance, institutional resources) are provided for informational purposes only. We do not control those websites and are not responsible for their content or privacy practices.
Children's Privacy
The Service is intended exclusively for professional use by individuals who are at least 18 years of age. We do not knowingly collect personal information from children under the age of 13 (or the applicable minimum age in your jurisdiction). If you believe we have inadvertently collected information from a minor, please contact us immediately at support@pro-lab.us and we will delete that information promptly.
International Users & Data Transfers
Microbank Marketplace is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, processed in, and stored in the United States, where data protection laws may differ from those in your country.
For users in the EEA or UK, such transfers are made in reliance on standard contractual clauses (SCCs) approved by the European Commission, or other appropriate safeguards as required by applicable law. By using the Service, you consent to this transfer.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. For material changes, we will provide at least 30 days' advance notice by email to your registered address or through a prominent notice within the Service.
The "Last updated" date at the top of this page reflects the date of the most recent revision. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Policy.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
- Email: support@pro-lab.us
- Website: microbank.pro-lab.us
- Company: Pro-Lab Diagnostics USA
We will respond to all privacy-related inquiries within 30 days. For urgent matters, including suspected data breaches or unauthorized access, please mark your email "URGENT — Privacy" for priority handling.