Privacy Policy

Last Updated: September 6, 2026

1. Information We Collect

When you submit a request, we collect: contact information (name, phone, email), the ZIP code where service is requested, the type of service you select, whether you have a doctor's order or a test kit (and the kit brand/test name if you provide it), your preferred date and time window, your payment preference, the provider you select or are matched with, optional access/logistics notes, and a record of the terms version you accepted, the time you accepted it, and the browser used, as evidence of consent. While you fill in a request, your entries (except notes and kit details) may be kept in your own browser's local storage for up to 24 hours so an interrupted request can be resumed; they are removed when you submit or when that time passes, and they never leave your device. For site visitors, we collect approximate IP-derived location data, which may include city, state, and ZIP code when available, along with search queries, to improve local provider matching and service coverage.

2. Health-Related Information Boundaries

PhlebFlow is designed as a logistics and matching platform. We ask users only for the limited contact, location, scheduling, service preference, and logistics information needed to connect them with independent providers. We do not request or store lab results, diagnoses, prescriptions, or copies of medical orders through the platform — please share clinical documents and medical instructions directly with your licensed provider, physician, or laboratory, and do not include them in notes. As a safeguard, common medical terms (test names, conditions, medications, diagnosis codes) typed into the notes field are automatically removed before your request is stored or sent; this is a word filter, not a guarantee, so please keep notes to access and logistics. Depending on applicable law and how the service is used, some information we collect may still be considered sensitive health-related information, and we treat it with corresponding care: it is used only to coordinate your request and is shared only as described below.

3. How We Share Information

Your request details are shared with the independent provider you select or are matched with, and with our platform administrators for dispatch, quality, and support purposes. We use service providers to operate the platform, including database hosting (Supabase), website hosting (Cloudflare), email delivery (Resend), SMS delivery (Twilio), and location lookup — IP-based, and ZIP-to-city resolution via api.zippopotam.us to name a searched area. We do not sell your personal information or share it with third parties for behavioral advertising.

Two more services run in your browser. Cloudflare Web Analytics measures page performance and visit counts without cookies and without identifying you. The coverage maps on search and provider pages load map tiles from OpenStreetMap, which receives your IP address when a tile is requested, as any image on the web does. We use no advertising pixels and no third-party analytics that profile you.

Google Analytics 4 runs only after you press Accept on the location notice. It is configured as measurement, not marketing: advertising features and Google signals are off, your IP address is anonymized, and it is used to understand which pages and searches lead to a request. Press “Continue without location” and it never loads.

To protect the request form from bots and abuse, we use Cloudflare Turnstile, which runs a silent verification when you submit a request. Turnstile's handling of end-user data is governed by the Cloudflare Turnstile Privacy Addendum.

4. Provider and Laboratory Listing Information

Provider and laboratory profiles on PhlebFlow are business listings, not patient data. A listing shows the information the provider submitted: business and contact name, city and coverage ZIP codes, services, fees, and credentials. Credentials are self-reported unless a badge explicitly says PhlebFlow verified them. We review every listing before it is published, and providers can edit their information from their portal at any time. To request a correction or removal of a listing, email legal@phlebflow.com.

5. Communications

By submitting a request you consent to be contacted by PhlebFlow and/or independent providers by phone, email, or text message about your request. Consent is not required to purchase services. You may opt out of communications at any time by contacting support@phlebflow.com.

6. Your Privacy Rights

You may request access to, correction of, or deletion of your personal information at any time by contacting legal@phlebflow.com. California residents may have additional rights under the CCPA/CPRA, including the right to know, delete, and correct personal information, and the right to limit use of sensitive personal information. We respond to verified requests within the timeframes required by applicable law.

7. Data Retention

We retain request information only as long as needed to coordinate your request, operate and improve the service, prevent abuse, and meet legal obligations. Patient contact details (name, phone, email, and notes) attached to a booking request are automatically de-identified about six months after the request; the de-identified record (such as ZIP, service type, and dates, without contact details) may be kept for coverage analytics. You may request deletion of your information at any time (see Section 6), and we will honor verified deletion requests except where retention is required by law. Aggregated or de-identified data that no longer identifies you may be retained for service analytics. Site analytics we keep ourselves (approximate visit location, searches, form progress) are deleted after 13 months; outbound email records are deleted 7 days after sending.

8. Consumer Health Data Privacy Policy

This section is our consumer health data privacy policy under Washington’s My Health My Data Act and Nevada’s consumer health data law, and we apply it to everyone who uses PhlebFlow, wherever they live. Asking for a blood draw is, by itself, information about seeking health care. We treat everything below as consumer health data and handle it with the care that implies.

What we collect, and from whom. Only from you, when you submit a request or use the site:

  • Your name, phone number, and email address.
  • Your ZIP code (never your street address; you give that to the provider after they accept).
  • The type of service you request (for example a standard draw, a pediatric draw, or a specialty test kit), whether you have a doctor’s order or a kit, the kit brand if you name it, your preferred date and time window, your payment preference, and whether the request is for you, a family member, someone in your care, or a facility.
  • Access and logistics notes you type. Health terms (test names, conditions, medications, diagnosis codes) are automatically removed from this field before it is stored or sent; the field is for gate codes and parking.
  • The version of the Terms you accepted, when you accepted them, and your browser type, as evidence of consent.
  • If you leave a review: your name (shown publicly as first name and last initial), your rating, and your comment.
  • Site visits: your approximate city, state, and ZIP derived from your IP address (only if you accept the location notice; we never store the IP itself), the page you landed on, and the search terms you type when they look like a place name. Search terms that look like an address, a phone number, an email, or a health term are not stored.

We do not collect diagnoses, test results, prescriptions, medical orders, insurance details, date of birth, or government identifiers, and we ask you not to send them to us.

Why we collect it. To connect your request with an independent provider in your area and let them contact you; to send you the status of your request and let you cancel it; to invite you to review the visit; to see where people are looking for a provider we do not have yet; to prevent abuse; and to keep the records the law requires. We do not use consumer health data for advertising, profiling, or any purpose you would not expect from a request you made.

Who receives it.

  • The independent provider assigned to your request. They see your service type, ZIP, dates, and a masked name until they accept; your name, phone, email, and notes only after they accept. If your request is reassigned, the new provider goes through the same gate. Providers are independent businesses, not our employees, and their use of your information is governed by their own practices.
  • Our service providers, who process data on our behalf and under contract: Supabase (database hosting), Cloudflare (website hosting, request processing, bot protection, and IP-based approximate location), Resend (email delivery), and Twilio (SMS delivery, where enabled). A ZIP code you search or enter may be sent to api.zippopotam.us to name the area; no other detail goes with it. When a map is shown, your browser requests map tiles from OpenStreetMap directly.
  • Our staff who coordinate requests and verify providers, each with access limited to their role.
  • Authorities, only when the law requires it.

We do not sell consumer health data, and we do not share it for advertising. We do not use geofencing around any facility. Optional analytics from Google, if we ever enable them, run only after a separate yes from you, never load on pages that carry your request, and never receive your request details.

How long we keep it. Request contact details are de-identified about six months after the request; deleted requests are removed after 30 days; outbound email records after 7 days; our own site analytics after 13 months; waitlist emails six months after we have told you a provider is available. Reviews stay on the provider’s profile until you ask us to remove them. Copies in backups are deleted on the backup provider’s cycle and no later than six months after the record itself.

Your rights. You may, at any time and free of charge:

  • Confirm and access the consumer health data we hold about you, including a list of the third parties and affiliates it was shared with and their contact information.
  • Withdraw consent to our collection or sharing of your consumer health data. Withdrawing consent for the data needed to fulfil a pending request means we cannot complete that request; we will tell you so.
  • Delete your consumer health data. We delete it from our systems, direct our service providers and any provider we shared it with to delete it, and remove it from backups within six months. Reviews are deleted on request.
  • Appeal a decision we make about your request within 30 days of our answer, by replying to it. We answer appeals in writing within 45 days with the reasons. If we deny your appeal, you may contact the Washington Attorney General or the Nevada Attorney General, or your own state’s consumer protection office.

To exercise any right, email legal@phlebflow.com from the address on your request, or tell us the phone number you used, so we can confirm it is you. We respond within 45 days, and may extend once by 45 days if we tell you why. We will not treat you differently for exercising a right. You may also ask us to remove a review, correct a detail, or stop reminder emails; those requests are handled the same way.

Requests made for someone else. If you submitted a request for a family member, a person in your care, or a minor, these rights belong to that person too, and a parent or legal guardian may exercise them for a minor. We ask that the person the request is for is present at the visit.