Legal

Privacy Policy

Last updated: August 18, 2026

Who we are and what this covers

LabPath Logistics (“LabPath”, “we”, “us”) is a medical courier service operating in Greater Houston, Texas. This policy explains what information we collect through our website (labpathlogistics.com) and the LabPath mobile app, how we use it, and the choices you have. Our services are built for healthcare businesses — clinics, laboratories, and pharmacies — not for consumers.

Information we collect

Facility account details. When a facility registers, we collect the business information needed to verify and serve it: facility name and type, National Provider Identifier (NPI), Tax ID (EIN), business address, contact name, email address, phone number, and a password.

Delivery records. Each courier run generates a chain-of-custody record: pickup and drop-off facility names and addresses, service level, package type and temperature range, timestamps, opaque LabPath package-QR identifiers scanned at pickup, the receiving staff member’s name and signature, whether a hand-off photo was captured and, when production live tracking is enabled, the courier’s route position while a run is active.

Courier account details. Courier accounts are provisioned by LabPath and include name, email, phone, vehicle, and license information.

Website inquiries. If you request a rate sheet or save a quote through our website, the business contact details and facility-route information you submit are sent to our server-side lead sheet so our team can follow up. Those details are not retained in your browser after submission. Do not enter patient or specimen information in a website inquiry.

Address estimates. Address text entered into the website estimator is sent through our server to the U.S. Census Geocoder and the public Photon OpenStreetMap service to return suggestions. Results may be held in a bounded server-memory cache for up to ten minutes to reduce repeated provider requests; responses are marked private and no-store for browsers and shared HTTP caches. A production geocoding provider and contract have not been selected yet.

What we deliberately do not collect

The LabPath app contains no patient fields. Deliveries are referenced by opaque order IDs (for example, “LP-8942”), and app notifications are generated from order references and statuses only — they are designed to never contain patient information. A bounded access-notes field exists for facility logistics; users are warned not to enter PHI, and the field is access-controlled, but software cannot guarantee what a person types. Workforce training and sealed-package procedures are required operating controls before live service.

Where your data lives

Website rate-sheet and estimate follow-up requests are forwarded server-side to a restricted business lead sheet when that endpoint is configured; they are not copied into browser local storage. The full app workflow is currently verified against local Firebase emulators. Customer screens and the operational workflow are not deployed to production yet. Before launch, production hosting, access, retention, deletion, logging, and vendor agreements must be reviewed and this policy updated to match the deployed system.

How we use information

We use the information above to verify facilities, dispatch and complete deliveries, maintain chain-of-custody records, send status updates you have enabled, invoice for completed runs, and respond to support requests. We do not sell personal information, and we do not use third-party advertising or cross-site tracking on our website or in our app.

When information is shared

Delivery participants see what they need to complete a run: a when the production workflow is enabled, a facility may see the assigned courier’s operational contact details during an active delivery, and the courier sees the pickup and drop-off contact details required to complete it. Beyond that, we share information only with service providers who help us operate (for example, payment and communications providers), or when required by law.

Retention

Completed delivery and chain-of-custody records are retained as business records to meet audit and compliance obligations. Account profile information is retained while your account is active.

Your choices, including account deletion

The current app design provides profile and notification controls plus an in-app account-deletion path. Those controls must be reverified against the production identity and data stores before launch. In the app, you can request deletion through Settings → Delete account. Deletion permanently removes your sign-in and profile; completed delivery records are retained for chain-of-custody compliance with no personal sign-in attached. For any privacy question or request, email dispatch@labpathlogistics.com.

Security

We limit access to information to the people who need it to operate the service, and we design our notifications and records to avoid patient fields and keep patient information out of normal workflows. No method of storage or transmission is 100% secure, but minimizing what we hold is our first line of defense.

Children

Our website and app are business tools for healthcare facilities and provisioned couriers. They are not directed to, and may not be used by, anyone under 18.

Changes and contact

If we change this policy, we will update the date at the top of this page. Questions or requests: dispatch@labpathlogistics.com — LabPath Logistics, Houston, TX.