1. Overview & Scope
VialRun, Inc. (“VialRun,” “we,” “us,” or “our”) operates an on-demand and STAT specimen-logistics platform that connects clinics and phlebotomists (“operators”) with W-2 couriers who collect laboratory specimens and deliver them to receiving labs. This Privacy Policy applies to:
- The VialRun Operator mobile application for iOS and Android
- The VialRun Courier mobile application for iOS and Android
- The VialRun website at vialrun.com and admin.vialrun.com
- Any related APIs, communications, and customer-support channels
By creating a VialRun account or using the Services, you acknowledge that you have read and understood this Privacy Policy.
2. Who We Are
The data controller responsible for your personal information is VialRun, Inc., a corporation headquartered in the State of Illinois, United States. For privacy questions you can reach our team at privacy@vialrun.com.
3. Information We Collect
We collect the categories of information described below. The exact fields we collect depend on which app you use and which features you choose to enable.
3.1 Information you provide directly
Operator Account
- First name, last name, email address, mobile phone number
- Practice or clinic name and role
- Optional profile photo
- Saved pickup locations and receiving labs (e.g., clinic, draw site, favorites)
- Specimen-handling preferences and standing-order instructions
- Ratings and feedback you submit about couriers and pickups
- Subscription plan selections (Essential, Professional, Enterprise) and preferences
Courier Account
- Full legal name, email address, mobile phone number
- Date of birth and the last four digits of your Social Security Number, used for employment eligibility, payroll, and identity-verification requirements (couriers are W-2 employees)
- Government-issued driver’s license (uploaded photo and number)
- Specimen-handling and bloodborne-pathogen certifications, training records, and other compliance documents tracked in your compliance vault
- Vehicle and equipment information used for cold-chain transport
- Payroll details (including bank account routing and account number) for W-2 wage payments, collected and processed through our payroll provider
- Profile photo used for in-app identification at pickup and at the lab
- Background-check authorization and resulting reports from our screening partner (Checkr)
3.2 Information collected automatically
- Device information: a unique device identifier (via
react-native-device-info), operating system, OS version, app version, language settings, and time zone - Log and usage data: screens viewed, features used, taps and interactions, request timestamps, and crash diagnostics
- Network information: IP address and approximate network-derived location
- Crash and stability data: via Firebase Crashlytics
- Push-notification tokens: via Firebase Cloud Messaging
3.3 Information from third parties
- Identity- and background-check results from Checkr (couriers only)
- Payment-method tokens, charge results, and payout status from Stripe
- Map, routing, and place data from Mapbox in response to addresses and routes you request
- Phone-verification status from Twilio (one-time codes are dispatched server-side; no Twilio SDK runs in the app)
4. How We Use Your Information
We use your information to:
- Create and manage your account and verify your identity
- Match operators’ pickup requests with nearby couriers and dispatch pickups
- Provide turn-by-turn navigation and accurate pickup and delivery ETAs
- Generate chain-of-custody (COC) records, log cold-chain temperatures, and send one-tap SMS delivery confirmations to receiving labs
- Process practice billing and pay courier wages
- Send pickup updates, receipts, and operational notifications
- Provide customer, compliance, and safety support, including responding to incidents and investigating claims
- Detect, investigate, and prevent fraud, abuse, account takeover, and other harmful activity
- Improve the Services, debug crashes, and develop new features (using aggregated or de-identified data wherever possible)
- Comply with legal obligations (tax and payroll reporting, laboratory and HIPAA-related compliance, regulatory requirements, court orders, and law-enforcement requests)
We will not use your personal information for purposes materially different from those listed here without first notifying you.
5. Location Information
Location is central to specimen logistics. We collect precise GPS location through your device’s location services after you grant permission.
Operator App
- We collect foreground location while you are using the app, to confirm your pickup site and show the assigned courier en route.
- We do not perform continuous background location tracking in the Operator app. Limited background processing is used only to deliver pickup status updates and notifications.
- On iOS, the user-facing permission strings are: “VialRun needs location access to confirm your pickup site and show your courier’s arrival.”
Courier App
- While you are on shift and available for pickups, the Courier app collects continuous high-precision location in the foreground and background (approximately every 5–10 seconds) in order to receive pickup requests, navigate to pickup sites and receiving labs, and share live ETAs with operators.
- Background location stops when you go off shift. You can also disable it at any time through your device’s system settings, although doing so will prevent you from receiving pickups.
- On iOS, the user-facing permission strings are: “VialRun Courier needs location access to receive pickup requests and track your location while on shift.”
- On Android, the app uses the
ACCESS_FINE_LOCATION,ACCESS_BACKGROUND_LOCATION, andFOREGROUND_SERVICE_LOCATIONpermissions and runs a foreground service while you are on shift.
Pickup route data (pickup site, receiving lab, and waypoints) is retained as part of your pickup history and chain-of-custody record.
6. Payments & Financial Data
6.1 Operators
Practice billing is processed by Stripe using its mobile SDK. Card numbers and CVCs are sent directly from your device to Stripe and are not stored on VialRun servers. We retain only a payment-method token, the brand and last four digits of your card, billing ZIP, and a transaction record for your subscription plan (Essential, Professional, or Enterprise) and per-pickup fees.
6.2 Couriers
Couriers are W-2 employees, and wages are paid through our payroll provider. Your bank routing number, account number, date of birth, and the last four digits of your SSN are collected to satisfy U.S. payroll, tax-withholding, and employment-eligibility requirements and are transmitted directly to our payroll and verification partners.
8. Third-Party Services & SDKs
The Services rely on the following third-party providers. Each handles personal data only for the purposes described below and is bound by their own privacy policy.
| Provider | Purpose | Data Accessed |
|---|---|---|
| Stripe | Practice billing and identity verification | Card details, billing info, practice name, transaction records |
| Mapbox | Maps, geocoding, routing, navigation | Location, pickup-site/receiving-lab addresses, route requests |
| Firebase (Google) | Push notifications and crash reporting | Device tokens, crash diagnostics, app event metadata |
| Twilio | SMS verification codes and one-tap lab delivery confirmations | Mobile phone number (operators, couriers, and receiving-lab contacts) |
| Checkr | Courier background and motor-vehicle checks | Courier name, DOB, SSN, license number, address |
| Apple / Google | App distribution, biometric auth, in-app payments | App-store identifiers and biometric verification result (no biometric template leaves the device) |
We do not embed third-party advertising SDKs, social-login providers, or cross-app tracking SDKs in either app.
9. Communications & Notifications
We send you operational messages (pickup status, chain-of-custody and delivery confirmations, receipts, account and security notices) by push notification, in-app message, SMS, and email. These cannot be turned off while you have an active VialRun account because they are required to deliver the Services.
Marketing emails and promotional notifications are optional. You can unsubscribe at any time using the link in any marketing email or by adjusting notification preferences in the app.
10. Data Retention
We retain personal information for as long as necessary to provide the Services and to satisfy our legal, tax, accounting, laboratory-compliance, and dispute-resolution obligations. Pickup records, chain-of-custody records, payment records, and tax records are typically retained for a minimum of seven (7) years to comply with U.S. tax, financial, and laboratory recordkeeping requirements.
When personal information is no longer required, we delete it or de-identify it so that it can no longer be associated with you.
11. Security
We use technical and organizational safeguards to protect your information, including:
- TLS encryption for all data in transit between the apps and our servers
- Encrypted storage of credentials and tokens on your device using the platform keychain (
react-native-keychain) - Optional Face ID, Touch ID, and Android biometric login. Biometric templates never leave your device.
- Role-based access controls for employee access to production systems
- Continuous monitoring, logging, and crash reporting
No system is perfectly secure. If you believe your account has been compromised, contact us immediately at privacy@vialrun.com.
12. Your Rights & Choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your personal information
- Receive a copy of your data in a portable format
- Opt out of certain processing activities
- Withdraw consent where processing is based on consent
Residents of California, Colorado, Connecticut, Utah, Virginia, and other U.S. states with comprehensive privacy laws may exercise these rights by emailing privacy@vialrun.com. We will verify your request and respond within the time required by your state’s law.
You may delete your VialRun account at any time from within the app or by emailing us. Some information must be retained for legal, tax, and laboratory-compliance reasons even after account deletion.
13. Children
The VialRun Services are intended for business use by healthcare professionals and are not directed to anyone under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at privacy@vialrun.com and we will delete that information.
Couriers are W-2 employees and must meet all applicable employment-eligibility and age requirements for the state in which they operate.
14. International Users
VialRun is operated from the United States and the Services are intended for use in the United States. If you access the Services from outside the United States, you consent to the transfer of your information to and processing in the United States, where data-protection laws may differ from those in your country.
15. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last Updated” date at the top of this page reflects the most recent revision. When we make material changes, we will notify you in advance through the app or by email. Your continued use of the Services after the effective date of an updated Policy constitutes acceptance of the updated terms.
16. Contact Us
If you have questions about this Privacy Policy or our handling of your information, please contact us: