Skip to main content
Order by 11 AM ET / 8 AM PT for same-day shipping
GetTested

Privacy Policy

Last updated: 2026-02-06

Applies to: GetTested-operated websites and domains, including gettested.us, and related services such as our account area/portal (the “Portal”).

This Privacy Policy explains how we collect, use, disclose, and protect personal information-including health-related information-when you access or use our websites, the Portal, and when you purchase Products (including rapid tests and collection materials) or Laboratory Services (as defined in our Terms & Conditions).

Important: Independent laboratories and clinicians may have their own privacy practices and notices that apply to their services and records. Where applicable, you may receive or be directed to those notices.

1. Key Concepts and Our Roles

1.1 Our Services and ecosystem

As described in our Terms & Conditions, GetTested provides an online ordering, logistics, and results-delivery platform and may display information relating to your orders and, where applicable, your test-related information in the Portal. We do not provide medical diagnosis or treatment. Independent CLIA-certified laboratories (each, a “Laboratory”) perform laboratory testing, and independent licensed clinicians or clinician groups (each, a “Clinician/Provider”) may authorize orders, review results, and/or provide consultation where applicable.

1.2 Our Role and Responsibilities

Depending on the context and data flow, GetTested may act as (i) the business responsible for operating the Site and Portal and processing typical website, ecommerce, account, and customer support information, and/or (ii) a service provider processing information on behalf of Laboratories and Clinicians to help deliver Laboratory Services. Where applicable, if a Laboratory or Clinician is a HIPAA covered entity and engages GetTested to process protected health information (“PHI”) on its behalf, GetTested will do so under contract (including, where applicable, a Business Associate Agreement).

2. What We Collect

We collect information from (A) you, (B) your devices and browser, and (C) our service providers and partners (including Laboratories/Clinicians involved in your requested services). We collect the categories below.

2.1 Identifiers and contact information

Name, email, phone number, shipping/billing address, date of birth (where needed for eligibility/identity verification), account credentials, and unique kit/test identifiers.

2.2 Commercial and transaction information

Order details (Products/Laboratory Services purchased), purchase history, shipping status, refunds/returns, customer support communications, and service-related messages.

2.3 Health-related information (including “consumer health data” in some states)

Information you provide in connection with Laboratory Services (e.g., intake details where applicable), specimen/kit registration data, and test results/reports displayed in the Portal.

2.4 Internet, device, and usage information

IP address, device identifiers, browser type, operating system, log data, pages viewed, and interactions with our Site/Portal.

2.5 Cookies and similar technologies

Cookies, local storage, pixels/tags (as configured), and similar tools used for functionality, analytics, fraud prevention, and security.

2.6 Payment information

Payments are processed by third-party payment processors. We receive limited payment-related information (e.g., authorization result, transaction IDs, and last 4 digits). We do not store full payment card numbers.

2.7 Identity verification, fraud prevention, and eligibility information

Where permitted by law and as described in our Terms, we and our service providers may collect information used to verify identity/eligibility and reduce fraud (e.g., device risk signals, consistency checks, limited ID verification outputs).

3. Sources of Information

We collect information from:

  • You, including when you create an account, place an order, register a kit, complete intake (if applicable), contact support, or use the Portal.

  • Your devices and browser, including via cookies and server logs.

  • Laboratories and Clinicians involved in your services, such as confirmation that an order is authorized/released (where applicable) and delivery of results/reports to be displayed in the Portal.

  • Service providers, including payment processors, shipping carriers, customer support platforms, fraud/security vendors, identity verification providers, hosting providers, and communications providers (email/SMS).

  • Affiliates and corporate entities (if applicable) for internal administration, security, and corporate governance.

  • Public or third-party sources (limited), where permitted by law, primarily for fraud prevention/compliance.

4. Purposes

We use information for the following purposes:

4.1 Provide and operate the Site and Portal

Account creation, login, security, kit registration, user preferences, and Portal functionality.

4.2 Fulfill orders, ship Products, and provide customer support

Order processing, fulfillment, shipping, returns/refunds, replacements, and customer support operations.

4.3 Facilitate Laboratory Services and results access

Coordinate logistics, enable specimen registration, route information as needed for authorization (if applicable), testing, reporting, and display of results/reports in the Portal consistent with the service you request.

4.4 Communications

Send service-related updates (order confirmations, shipping, results availability, security notices) via email/SMS if you provide those details or enroll. Marketing messages only where permitted and/or you opt in (see Section 13).

4.5 Quality, safety, auditing, and improvement

Quality assurance, internal auditing, troubleshooting, performance analytics, and service improvement.

4.6 Security, fraud prevention, and compliance

Protect our customers, Site, and Portal; detect and prevent fraud and misuse; comply with legal obligations; enforce our Terms & Conditions; and protect rights and safety.

4.7 De-identified and aggregated information

Where permitted by law, we may create de-identified or aggregated information and use it for analytics, service improvement, and business operations. We do not attempt to re-identify de-identified information except as permitted by law.

Targeted advertising limitation: We do not use test results/reports for targeted advertising, and we do not disclose test results/reports to advertising platforms for cross-context behavioral advertising.

5. How We Disclose Information

We disclose information as follows:

5.1 Laboratories and Clinicians/Providers (for Laboratory Services)

We disclose information as needed to provide the services you request, including order processing, eligibility review, test authorization (if applicable), specimen processing, testing, reporting, consultation, and related customer support and compliance.

5.2 Service providers (processors)

We use vendors to help us operate our business and provide services (e.g., hosting, customer support tools, communications providers, shipping carriers, payment processors, fraud/security vendors, identity verification providers). These providers are contractually restricted to processing information to provide services for us.

5.3 Legal, compliance, and safety

We may disclose information to comply with law, respond to lawful requests, protect rights/safety, prevent fraud, and enforce agreements.

5.4 Corporate transactions

We may disclose information in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate protections.

5.5 At your direction

We may disclose information when you request or authorize it (for example, when you ask us to share information with a third party).

6. Cookies, Analytics, and Tracking Controls

6.1 Essential cookies

We use essential cookies for login, security, and core Site/Portal functionality.

6.2 Analytics and performance

We use analytics to understand Site performance and improve services. Where required by law, we provide choices/consent for non-essential cookies.

6.3 Restrictions on advertising pixels and health-content tracking

We do not permit advertising pixels or trackers designed for targeted advertising on pages where you view test results/reports in the Portal. We also take steps to reduce collection of health-related content on sensitive flows (such as results access and certain kit registration/intake workflows).

6.4 Your choices

You may manage cookie preferences through your browser/device settings. Some features may not work without certain cookies.

7. Health Information, HIPAA, and Medical Records (When Applicable)

Some Laboratories and Clinicians may be HIPAA covered entities and may maintain medical/laboratory records subject to HIPAA and their Notice of Privacy Practices (NPP). In connection with certain Laboratory Services, you may receive, be asked to acknowledge, or be directed to a Laboratory’s or Clinician’s NPP as part of that Laboratory’s or Clinician’s processes and legal obligations. GetTested does not control the content of any third-party NPP and is not responsible for a Laboratory’s or Clinician’s privacy practices.

Where GetTested processes protected health information (“PHI”) on behalf of a Laboratory or Clinician in a HIPAA-governed context, we do so under contract (including, where applicable, a Business Associate Agreement) and apply safeguards appropriate to the sensitivity of that information. Requests to exercise HIPAA rights (such as access or amendment of records) may need to be directed to the relevant Laboratory or Clinician that maintains the applicable record.

8. Consumer Health Data Notice (Washington, Nevada, Connecticut, and Similar Laws)

Some state laws regulate “consumer health data” (sometimes defined broadly and not limited to HIPAA PHI). This section applies where such laws apply to you and our processing.

8.1 What “consumer health data” may include

Depending on the circumstances, consumer health data may include information related to your health conditions, test results, health-related intake information, kit registration information, and inferences drawn from such information.

8.2 Categories of consumer health data we collect and why

We collect and use consumer health data to:

  • provide Laboratory Services and Portal access (ordering, kit registration, specimen logistics, results display),

  • provide customer support,

  • conduct quality, safety, auditing, fraud prevention, and security operations, and

  • comply with law and enforce our Terms.

8.3 Sources of consumer health data

We collect consumer health data from:

  • you (including kit registration and intake, where applicable),

  • Laboratories/Clinicians involved in your requested services (e.g., results/report data provided for Portal display),

  • our service providers (limited to operational signals needed for secure delivery and support).

8.4 Sharing consumer health data: categories of recipients

We may share consumer health data with:

  • Laboratories and Clinicians involved in your services,

  • service providers who help us operate (hosting, support, communications, security/fraud, identity verification, shipping, payments), under contractual restrictions,

  • legal/compliance recipients where required by law.

8.5 Consent

Where required by applicable law, we obtain affirmative consent before collecting consumer health data, unless the collection is necessary to provide a product or service you request. We disclose (“share”) consumer health data with Laboratories, Clinicians, and our service providers only as needed to provide the requested product or service, to protect the security and integrity of our services, or as otherwise permitted by law. If we ever share consumer health data in a way that requires opt-in consent for sharing (i.e., beyond what is necessary to provide the requested product or service), we will obtain separate and distinct opt-in consent for that sharing.

8.6 Withdrawal of consent

If we process your information based on your consent, you may withdraw consent by contacting us as described in Section 20 (Contact Us) and indicating “Consumer Health Data - Withdraw Consent” in your message. Withdrawing consent does not affect processing that has already occurred. After withdrawal, we will no longer process your information based on that consent. We may continue to process information where another lawful basis applies, for example to comply with legal obligations, maintain security, prevent fraud, or establish, exercise, or defend legal claims.

8.7 No sale of consumer health data

We do not sell consumer health data.

8.8 Consumer health data rights (access/deletion)

Where applicable, you may request access to or deletion of consumer health data (see Section 10). We will respond as required by law.

9. Data Retention

We retain information as long as reasonably necessary to:

  • provide services and maintain your account,

  • comply with legal, tax, regulatory, and contractual requirements,

  • maintain security, prevent fraud, and resolve disputes.

  • Laboratories and Clinicians may retain records under their own professional and legal obligations. Deletion requests may be limited where retention is required by law or necessary for security/fraud prevention, dispute resolution, or compliance.

10. General U.S. Rights

Depending on your state of residence and applicable law, you may have rights such as:

  • Access: confirm and access personal information we hold about you

  • Correction: correct inaccurate personal information

  • Deletion: request deletion of certain personal information

  • Portability: obtain a copy in a portable format

  • Opt out: opt out of certain processing, such as targeted advertising or certain profiling (where applicable)

  • Appeal: appeal a denial of a rights request (where required)

10.1 How to submit a request

Submit a request by contacting us as described in Section 20 (Contact Us) with the subject line “Privacy Request” and include: (i) your name and the email address associated with your account (if you have one), (ii) your state of residence, and (iii) the specific request you are making (access, correction, deletion, portability, or opt-out).

10.2 Verification

To protect your information, we will take reasonable steps to verify your identity before fulfilling a request. Verification may require you to log in to your account or provide additional information. If we cannot verify your identity, we may deny the request.

10.3 Authorized agents

Where permitted by applicable law, you may submit a request through an authorized agent. We may require proof that the agent is authorized to act on your behalf and may also require you to verify your identity directly with us.

10.4 Response timing

We will respond within the time required by applicable law. We may extend our response time where permitted, and we will notify you if an extension applies.

10.5 Appeals (where required)

If we deny your request and your state law provides an appeal right, you may appeal by contacting us as described in Section 20 (Contact Us) with the subject line “Privacy Appeal” and referencing our decision. We will respond to appeals as required by applicable law.

10.6 Non-discrimination

We will not unlawfully discriminate against you for exercising your privacy rights.

10.7 Limitations

Your rights are subject to certain exceptions. For example, we may retain or use information as required or permitted by law, including for security, fraud prevention, compliance, and dispute resolution.

11. U.S. State-Specific Privacy Rights

This section applies to residents of certain U.S. states that provide privacy rights (for example, California, Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, Virginia, and other states with similar laws) (collectively, “Applicable State Laws”). These laws may provide rights to access, correct, delete, or obtain a copy of your personal information, and to opt out of certain processing such as targeted advertising and certain forms of sale/sharing or profiling.

11.1 Targeted advertising

We do not sell personal information for money. However, like many online businesses, we may permit third-party advertising and analytics partners to collect information from your browser/device about your interactions with our public marketing pages (e.g., pages describing Products and Laboratory Services) to measure and improve advertising performance and, depending on your choices, deliver interest-based ads. Under some state laws, certain disclosures of online identifiers and browsing activity to these partners may be considered “selling,” “sharing,” or processing for “targeted advertising.”

Important health-portal limitation: We do not permit advertising pixels or trackers designed for targeted advertising on pages of the Portal where you view test results/reports, and we do not disclose test results/reports for cross-context behavioral advertising. (See Section 6.3.)

11.2 How to opt out of targeted advertising / sale/share

You may opt out of targeted advertising (and any sale/share of personal information as defined by Applicable State Laws) by:

  • using browser/device controls (including cookie settings), or

  • configuring your browser to send a recognized opt-out preference signal such as the Global Privacy Control (GPC) (see Section 11.3), or

  • contacting us as described in Section 20 (Contact Us) and indicating “Opt Out of Targeted Advertising” in your message.

11.3 Global Privacy Control (GPC)

Where required by applicable law, we treat the GPC signal as a request to opt out of applicable sale/share and/or targeted advertising for the browser/device that sends the signal.

11.4 Nevada residents

Nevada law provides certain residents the right to request that a company not sell certain personal information for monetary consideration. If you are a Nevada resident and wish to submit such a request, contact us as described in Section 20 (Contact Us) and indicate “Nevada Do Not Sell Request” in your message. We will respond as required by applicable law.

11.5 Exercising other state privacy rights

To exercise access, correction, deletion, or portability rights, please submit a request as described in Section 10.

12. California Privacy Notice (CCPA/CPRA)

12.1 “Sale,” “Share,” and targeted advertising

We do not sell personal information for money. We do not share test results/reports for cross-context behavioral advertising. If our use of certain tools were ever interpreted as “sharing” under California law, we will provide and honor a “Do Not Sell or Share” mechanism.

12.2 Sensitive personal information

We use sensitive personal information (including health-related information where applicable) only as necessary to provide the services you request, ensure security, prevent fraud, and comply with law, and not for targeted advertising based on test results/reports.

12.3 Global Privacy Control

Where required, we process the Global Privacy Control (GPC) as an opt-out signal for applicable browsers/devices.

12.4 How to exercise California rights

To exercise California privacy rights, see Section 10. For categories of information we collect and disclose, see Sections 2 and 5. For retention, see Section 9.

13. Washington Consumer Health Data Notice (My Health My Data Act)

This section applies to Washington residents to the extent the Washington My Health My Data Act applies to you.

13.1 Consumer health data

“Consumer health data” is defined broadly under Washington law and may include information that identifies your past, present, or future physical or mental health status, including test results/reports, health-related intake information, and information that can reasonably be linked to you.

13.2 Categories we collect and sources

We collect consumer health data from: (i) you (including when you register a kit, provide intake information where applicable, and access results), (ii) Laboratories/Clinicians involved in your requested services (including results/report information made available in the Portal), and (iii) our service providers that support delivery and security of our services.

13.3 Purposes of collection/use

We collect and use consumer health data to provide the services you request, including facilitating Laboratory Services, kit registration, specimen logistics, results/reports display in the Portal, customer support, quality and safety, fraud prevention, security, and compliance.

13.4 Sharing of consumer health data

We share consumer health data with:

  • Laboratories and Clinicians involved in your services;

  • service providers that help us operate (e.g., hosting, communications, support, security/fraud, identity verification, shipping, payments), under contractual restrictions; and

  • legal/compliance recipients where required by law.

We do not sell consumer health data.

13.5 Consent

Where required by Washington law, we obtain affirmative consent before collecting consumer health data, unless the collection is necessary to provide a product or service you request. If we ever share consumer health data in a way that requires opt-in consent for sharing beyond what is necessary to provide the requested product or service, we will obtain separate and distinct opt-in consent for that sharing. Where required, the consent request will describe the consumer health data involved, the purposes, the categories of recipients, and how to withdraw consent.

13.6 Withdrawal of consent

You may withdraw consent for future collection/sharing of consumer health data by contacting us as described in Section 20 (Contact Us) with subject “Consumer Health Data - Withdraw Consent.” Withdrawal does not affect processing that has already occurred and we may retain/use information as permitted by law (e.g., for security, fraud prevention, compliance, and dispute resolution).

13.7 Washington consumer health data rights

Subject to Washington law, you may request:

  • access to your consumer health data;

  • deletion of your consumer health data; and

  • confirmation of whether we have shared your consumer health data and a list of the third parties and affiliates with whom it has been shared, including contact information for those recipients.

To exercise these rights, contact us as described in Section 20 (Contact Us) with subject “Washington MHMD Request.” We will take steps to verify your request and respond as required by law.

13.8 Geofencing

We do not use geofencing to identify or target consumers based on visits to in-person healthcare facilities for purposes restricted by Washington law.

14. Data Security; Security Incidents; New York SHIELD Act

14.1 Data security safeguards

We maintain reasonable administrative, technical, and physical safeguards designed to protect personal information. These measures may include, for example, access controls, authentication, encryption in transit where appropriate, logging/monitoring, and security training and policies. No system is perfectly secure.

14.2 Vendor and supply-chain security

We require service providers that process information on our behalf to maintain appropriate safeguards and to process information only as permitted under our agreements.

14.3 Security incidents and breach notifications

We maintain a security incident response process. If we become aware of a security incident involving certain information, we will evaluate notification obligations under applicable laws and contracts. Depending on applicable law, a reportable incident may include unauthorized acquisition or unauthorized disclosure of certain information, not only hacking.

14.4 New York residents (SHIELD Act)

If you are a New York resident, New York’s SHIELD Act requires businesses that own or maintain certain private information to implement reasonable administrative, technical, and physical safeguards. Our security program is designed with these principles in mind. Nothing in this section guarantees that unauthorized access will never occur.

15. Marketing Choices

You can opt out of marketing emails via the unsubscribe link or by contacting us. Service and security messages may still be sent.

16. International Transfers

Your information may be processed in the United States and other countries where we or our service providers operate. We use contractual and technical measures designed to protect information during processing.

17. Third-Party Links

We are not responsible for the privacy practices of third-party sites linked from our Site.

18. Children’s Privacy

The Site and services are not intended for individuals under 18. We do not knowingly collect personal information from children under 13.

19. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version and revise the “Last Updated” date. Material changes may be communicated via the Site/Portal or email.

20. Contact Us

Email: hello@gettested.us

Company: Get Tested USA Inc.

Questions? Contact us at hello@gettested.us