PRIVACY POLICY
Last Updated: July 17, 2026
LabTested, Co., a Delaware corporation (“LabTested,” “we,” “us,” or “our”), respects the privacy of the individuals whose personal information is processed through our services.
This Privacy Policy applies to https://www.labtested.co, the LabTested merchant dashboard, laboratory portal, embeddable results widget, hosted results pages, barcode and scan pages, application programming interfaces (“APIs”), and related software and services collectively referred to as the “Service.”
The Policy applies to merchants, merchant personnel, laboratory users, prospective customers, support contacts, website visitors, and persons who view a LabTested widget, follow a public results link, or scan a product code. LabTested provides software that organizes and displays information submitted by merchants and third-party laboratories. LabTested does not independently test, verify, authenticate, certify, approve, or guarantee products, laboratory documents, or reported results.
1. Privacy Roles
1.1 LabTested acts as a business or controller when it determines why and how personal information is processed for its own purposes, including account administration, billing, website operation, customer communications, security, fraud prevention, and service improvement.
1.2 Where LabTested processes personal information submitted by or for a merchant, LabTested generally acts as that merchant’s processor, contractor, or service provider. Such processing may include personal information contained in Certificates of Analysis, laboratory reports, uploaded documents, product records, and merchant-controlled integrations.
1.3 Where a LabTested widget, hosted results page, or scan page processes information about visitors on behalf of a merchant, the merchant generally acts as the business or controller, and LabTested acts as its processor or service provider. The merchant’s privacy notice also applies to that processing.
1.4 LabTested may independently process limited widget or scan-page information where necessary to secure the Service, prevent abuse, maintain infrastructure, comply with law, or create aggregated or de-identified service statistics.
1.5 A Data Processing Addendum may supplement this Policy where entered into between LabTested and a merchant.
2. Personal Information We Collect
2.1 Account and identity information. We may collect names, business email addresses, usernames, organization names, job titles, roles, account permissions, profile information, and authentication records.
2.2 Account credentials. Passwords are processed through an authentication provider and stored in protected hashed form. We may also process authentication tokens, session identifiers, API credentials, security questions, and multi-factor authentication information.
2.3 Merchant and laboratory information. We may collect company names, business addresses, laboratory names, business contact information, website details, storefront domains, professional affiliations, and information used to confirm authority to act for a business or laboratory.
2.4 Billing and subscription information. We collect subscription plans, billing contacts, invoice details, transaction identifiers, payment status, renewal dates, app-billing information, and limited payment metadata. Stripe, Shopify, or another payment or billing provider collects and stores applicable payment-card or bank-account details. LabTested does not ordinarily receive or store complete payment-card numbers.
2.5 Product and batch information. Merchants may submit product names, descriptions, images, ingredients, variants, product identifiers, barcodes, GTINs, batch numbers, lot numbers, manufacturing information, testing categories, analytes, reported values, limits, units, and related metadata.
2.6 Laboratory Documentation. Merchants and laboratory users may upload Certificates of Analysis, laboratory reports, testing records, sample information, testing methods, dates, results, signatures, laboratory personnel names, and supporting documents.
2.7 Communications. We collect information contained in customer-support requests, emails, demonstrations, sales inquiries, survey responses, feedback, refund requests, privacy requests, and other communications.
2.8 Service usage information. We may collect dashboard activity, pages viewed, features used, documents uploaded, publication events, edits, downloads, API calls, integration activity, account changes, timestamps, and audit records.
2.9 Device and network information. We may collect IP addresses, browser types, browser versions, device types, operating systems, language settings, referring URLs, request headers, approximate location derived from an IP address, cookie identifiers, and technical logs.
2.10 Widget and scan activity. When a person views a LabTested widget, opens a public results page, or scans a barcode or QR code, we may collect the event type, referring storefront domain, public page viewed, timestamp, device information, IP address, browser information, and engagement activity.
2.11 Integration information. Where a merchant connects Shopify or another service, we may receive product catalog information, storefront identifiers, account identifiers, configuration settings, and information required to provide the requested integration.
2.12 Information from third parties. We may receive information from merchants, laboratory users, payment processors, authentication providers, integrations, analytics providers, security providers, and persons who invite another individual to the Service.
3. Sources of Personal Information
3.1 We collect personal information directly from you when you create an Account, upload information, communicate with us, configure an integration, subscribe, or otherwise use the Service.
3.2 We collect certain information automatically through the Service, cookies, server logs, APIs, widgets, scan pages, and similar technologies.
3.3 We receive information from merchants, laboratories, authorized users, service providers, payment processors, e-commerce platforms, and other integrations.
3.4 Merchants and laboratory users must have the authority and lawful basis required to submit personal information concerning another person.
4. How We Use Personal Information
4.1 We may process personal information to:
4.1.1 create, authenticate, administer, secure, and support Accounts;
4.1.2 provide merchant workspaces, laboratory collaboration, document storage, results pages, widgets, scan functionality, APIs, analytics, and integrations;
4.1.3 organize and extract information from Laboratory Documentation;
4.1.4 enable merchants to review, correct, publish, unpublish, replace, or remove submitted information;
4.1.5 process payments, subscriptions, renewals, refunds, taxes, and billing communications;
4.1.6 respond to inquiries, demonstrations, support requests, complaints, and privacy requests;
4.1.7 send transactional notices, security alerts, service announcements, and permitted marketing communications;
4.1.8 monitor performance, diagnose errors, maintain availability, and improve functionality;
4.1.9 protect Accounts, credentials, APIs, users, merchants, and infrastructure;
4.1.10 detect, investigate, prevent, and respond to fraud, abuse, unauthorized access, malicious activity, and violations of applicable agreements;
4.1.11 create aggregated or de-identified analytics, benchmarking, and category statistics;
4.1.12 comply with legal obligations, lawful requests, court orders, tax requirements, and regulatory duties;
4.1.13 establish, exercise, or defend legal claims; and
4.1.14 conduct a merger, financing, acquisition, restructuring, sale, or transfer involving LabTested.
4.2 Personal information will not be used for materially different, unrelated, or incompatible purposes without any notice or consent required by law.
5. Merchant Content and Published Information
5.1 Merchants control which products, batches, results, and documents are published through their widgets, public links, hosted pages, scan pages, and APIs.
5.2 Published results are public by design. Information appearing within a published laboratory document, including a laboratory employee’s name, professional details, or signature, may become accessible to anyone who opens the applicable page or document.
5.3 Merchants must review and, where appropriate, redact documents before publication. Personal, confidential, proprietary, or restricted information should not be published unless the merchant has authority to make it public.
5.4 LabTested’s display of submitted information does not mean that LabTested has independently verified, authenticated, certified, approved, or guaranteed that information or the related product.
5.5 Requests concerning merchant-controlled content should ordinarily be directed to the merchant that published or submitted it. LabTested will reasonably assist merchants with valid privacy requests where required by applicable law or an executed Data Processing Addendum.
6. Cookies and Similar Technologies
6.1 LabTested may use cookies, local storage, pixels, software development kits, and similar technologies to operate, secure, and analyze the Service.
6.2 Strictly necessary technologies. These technologies support authentication, session management, fraud prevention, security, load balancing, user preferences, and essential platform functions.
6.3 Analytics technologies. LabTested may use analytics technologies to understand traffic, feature usage, errors, and Service performance.
6.4 Advertising technologies. LabTested does not currently use personal information for cross-context behavioral advertising. Before introducing advertising technologies that constitute a sale, sharing, or targeted advertising under applicable law, LabTested will provide required notices and opt-out controls.
6.5 The LabTested Cookie Policy provides additional information about the categories and purposes of cookies used through the Service.
6.6 Browser settings and any available consent-management tool may be used to control non-essential technologies. Disabling necessary cookies may prevent Account access or other essential functions.
7. Automated Processing and Artificial Intelligence
7.1 LabTested may use artificial-intelligence or machine-learning providers to extract structured information from uploaded Laboratory Documentation, including analytes, values, units, dates, and testing categories.
7.2 Extracted information is made available for merchant review. Merchants remain responsible for reviewing and approving information before publication.
7.3 Automated extraction does not independently authenticate a document, verify laboratory work, determine product safety, certify compliance, or make a legal or similarly significant decision concerning an individual.
7.4 LabTested may use automated tools to detect suspicious activity, protect Accounts, identify security threats, enforce technical limits, and flag potentially fraudulent or harmful use. Human review may occur where appropriate.
7.5 Merchant documents and personal information will not be used to train a third party’s general-purpose artificial-intelligence model unless permitted by the applicable agreement, disclosed to the affected merchant, and otherwise lawful.
8. How We Disclose Personal Information
8.1 We may disclose personal information to:
8.1.1 Infrastructure providers: Database, authentication, hosting, storage, content-delivery, and cloud-service providers.
8.1.2 Payment and app-billing providers: Stripe, Shopify, and other providers that process payments, app charges, subscriptions, invoicing, refunds, credits, taxes, and fraud screening.
8.1.3 Artificial-intelligence providers: Providers that process documents to return requested extraction or classification results.
8.1.4 Communication providers: Email, notification, customer-support, scheduling, and customer-relationship providers.
8.1.5 Analytics and security providers: Providers supporting usage measurement, error monitoring, incident response, fraud prevention, and cybersecurity.
8.1.6 Integration providers: Shopify, laboratories, commerce platforms, and other services connected at a merchant’s request.
8.1.7 Merchants and laboratories: Information may be exchanged between a merchant and an invited laboratory to support designated products, samples, orders, and documents.
8.1.8 Professional advisers: Attorneys, accountants, auditors, insurers, consultants, and financial advisers acting under appropriate confidentiality obligations.
8.1.9 Authorities and other parties: Information may be disclosed where reasonably necessary to comply with law, respond to legal process, protect rights or safety, investigate misconduct, or enforce agreements.
8.1.10 Transaction participants: Information may be disclosed in connection with a proposed or completed merger, financing, acquisition, restructuring, bankruptcy, sale of assets, or similar transaction.
8.2 Current providers may include Supabase for database, authentication, and file storage; Vercel for hosting and content delivery; Anthropic for document extraction; Stripe for direct payment processing; Shopify for commerce integration and app billing; and Resend for transactional communications. Providers may be added, removed, or replaced as LabTested’s technical environment changes.
8.3 Service providers are permitted to process personal information only for contracted purposes and subject to applicable privacy and security obligations.
9. Aggregated and De-Identified Information
9.1 LabTested may create aggregated or de-identified information from Service data, published results, and usage information.
9.2 Aggregated or de-identified information may be used for reporting, benchmarking, category comparisons, research, security, product development, and business analysis.
9.3 LabTested will maintain de-identified information in de-identified form and will not attempt to reidentify it except where permitted by law to confirm that de-identification measures remain effective.
10. Data Retention
10.1 Personal information is retained only for as long as reasonably necessary for the disclosed purpose, an ongoing business relationship, legal compliance, security, dispute resolution, or enforcement.
10.2 Account and merchant information is generally retained while the Account remains active and for a reasonable period after closure.
10.3 Product, batch, Laboratory Documentation, and publication records are retained while needed to provide the Service or maintain merchant-selected public results. Merchants may unpublish or delete information subject to applicable plan features, contractual duties, legal requirements, and backup cycles.
10.4 For merchants using the Shopify app, LabTested receives and processes applicable privacy requests through Shopify’s mandatory compliance webhooks, including customers/data_request, customers/redact, and shop/redact.
10.5 Following uninstallation of the Shopify app and receipt of the applicable shop/redact webhook, LabTested deletes Shopify shop data in its possession or control, subject only to applicable legal-retention obligations and ordinary backup cycles. Any information retained under an applicable legal obligation is isolated, restricted to the purpose supporting its retention, and deleted when that obligation ends.
10.6 Uninstalling the Shopify app may not remove metafields, theme settings, or other configuration data stored within the merchant’s Shopify store. Such information remains under the merchant’s control and is subject to the merchant’s own deletion and retention practices.
10.7 Billing and transaction records are retained for applicable tax, accounting, audit, fraud-prevention, and legal periods.
10.8 Security logs, API logs, and technical records are retained for periods reasonably necessary to secure, monitor, and investigate the Service.
10.9 Widget and scan analytics may be retained in identifiable, pseudonymous, aggregated, or de-identified form for reporting and Service analysis.
10.10 Privacy-request and Shopify compliance-webhook records may be retained to document compliance, coordinate responses, and prevent fraudulent or repeated requests.
10.11 Backups are deleted or overwritten according to ordinary backup cycles, unless preservation is required for security, litigation, or legal compliance.
11. Security
11.1 LabTested uses administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, acquisition, destruction, loss, alteration, or disclosure.
11.2 Safeguards may include encryption in transit, encryption at rest, access controls, authentication measures, tenant separation, scoped credentials, logging, monitoring, vulnerability management, backup procedures, and contractual protections.
11.3 No information system, storage method, or internet transmission can be guaranteed to be completely secure.
11.4 Users must protect Account credentials and API keys, maintain appropriate permissions, secure connected systems, and promptly report suspected incidents to hello@labtested.co.
12. Privacy Rights and Choices
12.1 Depending on your location and applicable law, you may have the right to:
12.1.1 confirm whether personal information is being processed;
12.1.2 access or obtain a copy of personal information;
12.1.3 correct inaccurate personal information;
12.1.4 delete personal information;
12.1.5 obtain personal information in a portable format;
12.1.6 opt out of the sale of personal information, sharing for cross-context behavioral advertising, or targeted advertising;
12.1.7 limit certain uses of sensitive personal information;
12.1.8 opt out of certain profiling or automated decision-making activities;
12.1.9 withdraw consent where processing depends upon consent;
12.1.10 appeal the denial of a privacy request; and
12.1.11 receive equal service without unlawful discrimination for exercising a privacy right.
12.2 Requests may be submitted to hello@labtested.co. LabTested operates online and uses this email address as its designated request method. Account holders should submit requests from the email address associated with their Account where possible. Requests concerning Shopify customer or shop data may also be received through Shopify’s mandatory compliance webhooks. Where applicable law requires an additional submission method, LabTested will make that method available through the Service or its website.
12.3 We may request information reasonably necessary to verify your identity, authority, Account relationship, or the scope of the request. Information collected for verification will be used only for verification, security, fraud prevention, and compliance.
12.4 An authorized agent may submit a request where permitted by law. We may require evidence of the agent’s authority and may verify the request directly with the individual.
12.5 Requests will be answered within the period required by applicable law. A request may be denied or limited where an exception applies, identity cannot reasonably be verified, or compliance would adversely affect another person’s rights.
12.6 Appeals may be submitted to hello@labtested.co with the subject line “Privacy Appeal.”
12.7 Marketing communications may be discontinued by using the unsubscribe link in the message. Transactional, billing, security, and Account communications may continue where necessary.
13. California Privacy Disclosures
13.1 During the preceding 12 months, LabTested may have collected the following categories of personal information:
| Category | Examples | Business or Commercial Purposes | Categories of Recipients |
|---|---|---|---|
| Identifiers | Names, email addresses, IP addresses, account IDs, and device identifiers. | Account administration, communications, security, and Service delivery. | Infrastructure, authentication, communication, security, and integration providers. |
| Customer-record information | Business contact details, billing contacts, and professional information. | Customer management, billing, support, and compliance. | Payment, support, professional-adviser, and communication providers. |
| Commercial information | Subscription plans, transactions, products, batches, and service usage. | Billing, analytics, account administration, and Service delivery. | Payment, infrastructure, analytics, and professional-service providers. |
| Internet or electronic activity | Browsing activity, widget views, scan events, API calls, logs, and interactions. | Security, analytics, reporting, debugging, and Service improvement. | Hosting, infrastructure, analytics, and security providers. |
| Professional information | Company, laboratory, role, title, and professional affiliation. | Account authorization, collaboration, support, and merchant administration. | Infrastructure, communication, merchant, laboratory, and integration providers. |
| User-provided content | Laboratory reports, signatures, communications, uploaded files, and product information. | Document processing, publication, support, compliance, and Service delivery. | Infrastructure, AI-processing, merchant, laboratory, and authorized integration providers. |
| Sensitive personal information | Account login credentials and related authentication information. | Authentication, Account access, security, and fraud prevention. | Authentication, infrastructure, and security providers. |
13.2 LabTested does not sell personal information for monetary or other valuable consideration and does not share personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act.
13.3 LabTested does not use or disclose sensitive personal information for purposes that require a right to limit under the California Consumer Privacy Act.
13.4 Where the California Consumer Privacy Act applies, California residents may exercise applicable rights to know, access, correct, or delete personal information, obtain information concerning disclosures, and receive equal service without unlawful discrimination for exercising a privacy right. These rights remain subject to applicable verification requirements, statutory exceptions, and limitations. Requests may be submitted using the methods described in Section 12.
13.5 Because LabTested does not currently sell or share personal information, a “Do Not Sell or Share My Personal Information” link is not presently required for LabTested’s current practices. If those practices change, LabTested will update this Policy, provide any required opt-out method, and honor legally valid opt-out preference signals where required. California regulations require covered businesses that sell or share personal information to recognize qualifying opt-out preference signals.
14. Other United States Privacy Laws
14.1 Residents of states with applicable comprehensive privacy laws may have rights to access, correct, delete, or obtain a copy of personal information, and to opt out of targeted advertising, sale, or qualifying profiling.
14.2 LabTested does not currently sell personal information, conduct targeted advertising using personal information, or use personal information for profiling that produces legal or similarly significant effects concerning individuals.
14.3 Applicable rights may be exercised through hello@labtested.co. Where state law provides an appeal right, appeals may be submitted using the process in Section 12.6.
15. Children’s Privacy
15.1 The Service is intended for businesses and is not directed to children under 13 years of age.
15.2 LabTested does not knowingly collect personal information online from children under 13. Where we learn that such information has been collected without required authorization, we will take reasonable steps to delete it.
15.3 A parent or guardian who believes that a child has submitted personal information may contact hello@labtested.co.
15.4 The Children’s Online Privacy Protection Act and its implementing rule apply to covered online services directed to children under 13 and to certain general-audience services with actual knowledge that they are collecting personal information from a child under 13.
16. International Users
16.1 LabTested is operated from the United States, and personal information may be stored or processed in the United States and other countries where service providers operate.
16.2 The Service is primarily intended for United States businesses and users and is not actively marketed or offered to persons in the European Economic Area or United Kingdom at launch.
16.3 Where a privacy law outside the United States nevertheless applies, LabTested will process personal information and support applicable rights as required by that law and any executed Data Processing Addendum.
16.4 International transfers may be made using contractual, organizational, and technical safeguards required under applicable law.
17. Third-Party Websites and Services
17.1 The Service may contain links to merchant storefronts, laboratories, commerce platforms, payment providers, and other third-party services.
17.2 Third parties independently control their privacy practices. Their collection and processing of personal information are governed by their own privacy notices and agreements.
17.3 Embedding a LabTested widget does not make LabTested responsible for the merchant website’s separate cookies, tracking, advertising, checkout, or customer-data practices.
18. Changes to This Policy
18.1 LabTested may update this Policy to reflect changes in the Service, technology, providers, legal requirements, or processing activities.
18.2 The “Last Updated” date will identify the most recent revision.
18.3 Material changes will be communicated through the Service, by email, or through another legally required method before they take effect where required by law.
19. Contact
19.1 Privacy questions, rights requests, complaints, appeals, security reports, and Data Processing Addendum requests may be directed to:
LabTested, Co.
702 Cedar Street
Santa Monica, CA 90405
United States
Website: https://www.labtested.co
Email: hello@labtested.co