Back to LabTrack

Privacy Policy

Last updated: October 3, 2026

1. Who this applies to

LabTrack is an internal laboratory inventory management system used by authorized staff within the organization. It is not a public-facing consumer product and is not available for general signup — access is provisioned by an administrator.

2. What we collect

  • Account data: username, department, role (user/admin), and a securely hashed password (bcrypt). Plaintext passwords are never stored.
  • Activity data: every stock addition, usage, and quantity update is logged with the acting user's username, timestamp, and department, for audit and traceability purposes.
  • Inventory data: reagent and consumable names, lot numbers, quantities, expiration dates, and unit information — laboratory operational data, not personal data about patients or the public.
  • Session data: a session cookie (HttpOnly, Secure, SameSite) identifying your logged-in user to the server. This is cleared on logout, on session timeout after 5 minutes of inactivity, and does not persist beyond the browser tab it was created in.
  • Camera access: if you use the QR/barcode scanner or the label-photo scanner, your browser requests temporary access to your device camera. Captured frames are processed to read the code or label and are not stored as files.

3. Third parties we share data with

We keep this list short and specific, rather than a generic "we may share data with partners" clause:

  • Supabase (our database provider) stores all account, inventory, and activity-log data described above.
  • Google (Gemini API) is used for two optional AI-assisted features: (a) identifying a reagent from a photo taken with the label-scan camera, and (b) generating the plain-language usage/inventory summaries shown on the Insights page. Using these features sends the relevant photo or usage data to Google for processing. The barcode/QR scanner does not use this — it's decoded entirely in your browser and nothing is sent anywhere.

We do not sell data, and we do not use it for advertising.

4. How long we keep it

Account and inventory data is retained for as long as your organization uses LabTrack. Activity logs are kept indefinitely for audit purposes, consistent with standard laboratory record-keeping practice. An administrator can remove a user account at any time; this does not retroactively delete that user's historical activity-log entries, since those form part of the inventory audit trail.

5. Security measures

  • Passwords are hashed with bcrypt; we cannot see or recover your plaintext password.
  • All traffic is served over HTTPS, with HSTS enforced.
  • Sessions use HttpOnly, Secure cookies and expire automatically after inactivity.
  • Admin-only actions are verified server-side against your session, never trusted from the client alone.
  • A Content-Security-Policy and related browser security headers are enforced to reduce the risk of cross-site scripting and clickjacking.

6. Your choices

Camera-based scanning (QR/barcode and label photo) is entirely optional — every workflow in LabTrack that uses it also supports manual search/entry instead. You can decline camera permission in your browser and continue using the app normally.

7. Questions

For questions about this policy or your data, contact your LabTrack administrator or the person who provisioned your account.