Privacy Policy
Last updated: March 12, 2026
LabStream, Inc. ("LabStream," "we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website at labstream.ai (the "Site") and use our platform services (collectively, the "Services").
1. Information We Collect
Information You Provide
- Account Information: Name, email address, company/lab name, phone number, and job title when you create an account, request a demo, or join our waitlist.
- Communication Data: Information contained in messages you send to us, including support requests and feedback.
- Payment Information: Billing address and payment method details, processed through our third-party payment processor. We do not store full credit card numbers.
Information Collected Automatically
- Usage Data: Pages viewed, features used, click patterns, and time spent on the platform.
- Device Information: Browser type, operating system, device identifiers, and IP address.
- Cookies and Tracking: We use essential cookies for authentication and session management. Analytics cookies are only placed with your consent.
Laboratory Data
When you use our Services, we process laboratory operational data on your behalf, including requisition records, scheduling data, courier logistics information, and billing codes. This data is processed solely according to your instructions and our service agreement. We act as a data processor for your laboratory data and do not use it for any purpose other than providing the Services.
2. How We Use Your Information
- To provide, maintain, and improve our Services
- To process your account registration, demo requests, and waitlist signups
- To send transactional communications (service updates, security alerts, account notifications)
- To respond to your inquiries and provide customer support
- To detect, prevent, and address security incidents and technical issues
- To comply with legal obligations and enforce our terms
- To send marketing communications, only with your explicit consent
3. How We Share Your Information
We do not sell your personal information. We may share your information with:
- Service Providers: Third-party vendors who assist us in operating our Services (hosting, email delivery, analytics, payment processing), bound by confidentiality agreements.
- Legal Requirements: When required by law, regulation, legal process, or governmental request.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to you.
- With Your Consent: When you have given explicit permission to share specific information.
4. Data Retention
We retain your personal information for as long as your account is active or as needed to provide Services. We retain certain data as required for legal, audit, and compliance purposes. Laboratory data is retained according to the terms of your service agreement and applicable healthcare regulations. You may request deletion of your personal data by contacting us.
5. Data Security
We implement industry-standard technical and organizational measures to protect your information, including encryption in transit (TLS 1.2+) and at rest (AES-256), access controls, regular security assessments, and audit logging. For more details, see our Security page.
6. Your Rights and Choices
Depending on your jurisdiction, you may have the right to:
- Access, correct, or delete your personal information
- Object to or restrict certain processing activities
- Data portability — receive your data in a structured, machine-readable format
- Withdraw consent for marketing communications at any time
- Lodge a complaint with a supervisory authority
To exercise these rights, contact us at privacy@labstream.ai.
7. HIPAA Compliance
LabStream is designed to support healthcare organizations subject to HIPAA. We enter into Business Associate Agreements (BAAs) with covered entities as required. Protected Health Information (PHI) processed through our platform is handled in accordance with HIPAA requirements, including the Privacy Rule, Security Rule, and Breach Notification Rule.
8. International Data Transfers
Our Services are hosted in the United States. If you access our Services from outside the United States, your information may be transferred to and processed in the United States. We implement appropriate safeguards for international data transfers in compliance with applicable law.
9. Children's Privacy
Our Services are not directed to individuals under 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our Site with a new "Last updated" date. For significant changes, we will provide additional notice via email or in-platform notification.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
LabStream, Inc.
Email: privacy@labstream.ai
Website: labstream.ai