PRIVACY POLICY
Privacy Policy — Centers Laboratory App
Effective date 2026-06-22 Last updated 2026-06-22
This Privacy Policy explains how Centers Laboratory (“Centers Lab,” “we,” “us,” or “our”) collects, uses, shares, and
protects information in connection with the Centers Laboratory mobile application (the “App”) for iOS
and Android.
The App is a workforce tool for authorized Centers Lab employees, phlebotomists, couriers, and partners
(“Users”). It is not a consumer product and is not intended for use by the general
public or by patients. Access requires a valid Centers Lab account; there is no public sign-up.
Scope note. This policy covers the App itself. Information you handle inside the App about patients
(specimen and order data) is Protected Health Information (PHI) that Centers Lab processes as a
healthcare provider/business associate. Patient-facing privacy practices are described in Centers Lab’s separate
Notice of Privacy Practices, not in this document. See Section 6.
1. Information We Collect
a) Account & identity information
You sign in using one of two methods:
- Work email + one-time passcode (OTP). You enter your work email; we send a 6-digit OTP to that
address and you enter it to sign in. We collect your email address and the OTP you submit. Your email may be
remembered on the device for convenience. - Microsoft single sign-on (Microsoft Entra ID / Azure AD). If your organization uses Microsoft
SSO, you can sign in through Microsoft’s hosted login in your device browser. We receive an authorization code
that our backend exchanges for a session token. We do not receive or store your Microsoft
password.
After sign-in we receive and store, on our servers, profile information associated with your account, which may include:
your name, work email, date of birth, phone number, employee ID, organization, role, assigned regions, and
assigned facilities. Session tokens (JWTs) are stored securely on your device using the
operating system’s encrypted keystore (iOS Keychain / Android Keystore) via Expo SecureStore.
b) Location information
With your permission, the App collects your device’s precise location, including in the
background, only while you have an active, self-initiated work shift (“Start My Day”).
Specifically:
- Your live coordinates are streamed to our servers over a secure WebSocket connection while on
shift, so the lab can route specimen pickups, estimate arrival times, calculate distance to facilities, and
maintain operational and chain-of-custody records. - Your coordinates are captured when you start and end a shift and when you check in to a
facility (including the measured arrival distance from the facility). - Background tracking runs via an OS foreground service (a persistent notification is shown on Android, and the
location indicator is shown on iOS) and stops when your shift ends or you log out.
To reduce data volume, the App filters out low-accuracy and stationary readings before transmitting.
c) Camera and photos
With your permission, the App uses your camera and photo library so you can capture
and upload required documentation — for example, specimen images and signed paperwork
associated with an order. Captured/selected still images are uploaded to our servers and attached to
the relevant order. The App captures still images only; it does not record audio or video.
d) Order, facility, and specimen data (including PHI)
To perform your duties, the App displays and lets you update assigned orders, facilities, specimen/tube records, and
facility patient lists. This information includes Protected Health Information (PHI) about patients,
which may include patient name, date of birth, medical record number (MRN), gender,
facility/floor/unit/room/bed, ordered tests, specimen/tube details, collection status and times,
refusal/not-collected reasons, and signatory names and positions. This data is processed on behalf of
Centers Lab and handled in accordance with applicable healthcare privacy laws (see Section 6).
e) Bluetooth
The App uses Bluetooth to discover and connect to nearby label/receipt printers in order to print
specimen labels. Bluetooth is used only to communicate with printers; we do not use
Bluetooth to determine your location or to collect data from other nearby devices.
f) Device, diagnostic, and usage information
We collect limited technical information to operate, secure, and troubleshoot the App, including device platform
(iOS/Android), app version, push notification token, and diagnostic/error logs (event
level and message), which are sent to our servers.
g) Push notifications
We register a push token with Expo’s push notification service, which relays
operational notifications to your device through Apple Push Notification service (APNs) on iOS and
Firebase Cloud Messaging (FCM) on Android. Notification content (e.g., new-order and STAT-order alerts)
may reference order/facility context.
What we do NOT do
- We do not use third-party advertising
- We donot use third-party marketing or product analytics SDKs (e.g.,
GoogleAnalytics, Firebase Analytics, Amplitude, Segment, Mixpanel) — none are present in the App. - We do not use third-party crash-reporting SDKs (e.g., Crashlytics, Sentry).
- We do not track you across other companies’ apps or websites, and we do not
sell or “share” your personal information for cross-context behavioral advertising.
2. How We Use Information
We use the information above to:
- Authenticate you (work-email OTP or Microsoft SSO) and authorize access;
- Assign, route, and manage specimen-pickup orders and field operations;
- Provide live location to dispatch for routing, ETAs, facility check-in, and chain-of-custody during an active
shift; - Calculate driving distance/route to facilities and enable turn-by-turn navigation;
- Capture, upload, and store required specimen and documentation photos;
- Print specimen labels to a connected Bluetooth printer;
- Deliver operational push notifications;
- Maintain the security, integrity, and reliability of the App, including diagnostics; and
- Comply with legal, regulatory, clinical record-keeping, and contractual obligations.
We process this information to perform our services and to meet our legal and contractual obligations. We do
not sell your personal information.
3. How We Share Information
We share information only as needed to operate the App:
- With Centers Lab and its authorized personnel for operational and clinical workflow purposes.
- Service providers / processors that process data on our behalf, including:
- Centers Lab’s backend & cloud hosting provider(s) — store and process order,
location, photo, profile, and log data (first-party API at com). - Microsoft (Microsoft Entra ID) — authentication, if you sign in via
Microsoft SSO. - Expo (Expo Application Services) — delivery of push notifications (receives your push
token and notification content for relay). - Apple (APNs) and Google (Firebase Cloud Messaging, Firebase project
centers-lab) — push notification transport. - Google Maps Platform — to render maps and to compute driving distance/route, the App
sends your device location and the destination facility coordinates to Google’s Directions API. - Apple Maps / Google Maps applications — when you launch navigation, the destination
facility address/coordinates are handed off to the maps app you choose.
- Centers Lab’s backend & cloud hosting provider(s) — store and process order,
- Legal & compliance recipients where required by law, regulation, or legal process, or to
protect rights, safety, and security; and in connection with a corporate transaction (e.g., merger or
acquisition), subject to this policy.
We do not share PHI with parties that are not authorized recipients or that are not contractually bound to protect it.
Apple, Google, Microsoft, and Expo are not BAA-covered recipients of PHI — see Section 6 and the
accompanying review notes regarding keeping PHI out of notification content, logs, and third-party requests.
4. Data Retention
We retain information for as long as needed to provide the App and to meet legal, regulatory, clinical record-keeping,
and contractual requirements, after which it is deleted or de-identified. On-device session tokens are deleted on
logout. Location and operational records are retained according to Centers Lab’s record-retention policies 5 years.
5. Security
We protect information using technical and organizational safeguards, including:
- Encryption of data in transit (HTTPS/TLS for API calls; secure WebSocket (WSS) for live
location); - Secure on-device storage of authentication and duty tokens (iOS Keychain / Android Keystore);
- Access controls limiting data to authorized personnel; and
- Automatic session termination on token expiry or when you sign in on another device.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Health Information (HIPAA)
Centers Lab is a healthcare organization, and the App processes Protected Health Information (PHI)
governed by the U.S. Health Insurance Portability and Accountability Act (HIPAA) and other applicable laws. PHI is
processed solely on behalf of Centers Lab for treatment, payment, and healthcare-operations purposes, and is handled
under applicable Business Associate Agreements (BAAs) with our processors that touch PHI. Users are
responsible for handling PHI in accordance with their training and Centers Lab policies and must not move PHI outside
the App or authorized Centers Lab systems. Patients should refer to Centers Lab’s Notice of Privacy
Practices for information about their rights regarding their health information.
7. Device Permissions
The App requests the following permissions, each only for the stated purpose. You can change permissions at any time in
your device settings; disabling certain permissions may prevent parts of the App from working.
| Permission | Platform | Why it’s used |
|---|---|---|
| Location — precise, foreground & background |
iOS & Android | Live routing, distance/ETA to facilities, shift start/end and facility check-in, and chain-of-custody during an active shift |
| Background location + foreground service | Android | Continue location updates during an active shift with a persistent notification |
| Camera | iOS & Android | Capture specimen images and signed documentation |
| Photo library / media | iOS & Android | Select existing specimen/documentation images to upload |
| Bluetooth (scan & connect) |
iOS & Android | Discover and connect to label/receipt printers |
| Notifications | iOS & Android | Deliver order and operational alerts |
| Vibrate | Android | Alert/notification feedback |
Permissions present but not used for active data collection: A microphone permission
string and the Android RECORD_AUDIO permission are declared by the camera component, but the App records no
audio or video — only still images. See the accompanying review notes; these should be reviewed/removed
before store submission so they are not declared as data collection.
8. On-Device Storage
The App stores the following locally on your device: encrypted session/duty tokens (Keychain/Keystore);
and, in standard app storage, your remembered email, theme preference,
shift/duty status, the last-sent location (for de-duplication), a small buffer
of pending diagnostic logs, and a location-enabled flag. Local data is cleared on logout
where applicable and when you uninstall the App.
9. Your Choices and Rights
Because the App is a workforce tool, your account and most data are managed by Centers Lab. Depending on your
jurisdiction (e.g., California/CCPA-CPRA and other U.S. state privacy laws, or GDPR where applicable), you may have
rights to access, correct, port, or request deletion of your personal information, and to appeal a decision. You can
update certain profile fields (name, date of birth) in the App. To make a privacy request or to request account
and data deletion, contact us at privacy@centerslab.com. Some requests may be limited by legal
record-retention requirements applicable to healthcare data. We will not retaliate against you for exercising these
rights.
10. Children’s Privacy
The App is intended only for authorized adult Users. It is not directed to children, and we do not knowingly collect
personal information from children under 13 (or the minimum age in your jurisdiction).
11. International Users
The App and its servers are operated in the United States AWS EAST. If you access the App from outside
the United States, you understand that your information will be processed in the United States, where data protection
laws may differ from those in your location.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date,
and material changes will be communicated through the App or by other appropriate means.
13. Contact Us
Centers Laboratory 85 Horse Hill Rd CEDAR KNOLLS NJ 07927 Email: privacy@centerslab.com