Privacy Policy
Effective Date: 6 August 2026
This Privacy Policy describes how SwimScore, LLC (“SwimScore,” “we,” “us,” or “our”) collects, uses, discloses, retains, and otherwise processes personal information in connection with our websites, applications, patient portals, online services, communications, testing-coordination services, and related offerings (collectively, the “Services”).
For purposes of this Privacy Policy, “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household. “Health Information” means information relating to health, reproductive health, fertility, testing, specimens, medical history, care, or healthcare services. Some Health Information may be protected health information (“PHI”) under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), while other Health Information may be governed by state consumer-health-data laws or other privacy laws.
Important: SwimScore’s role and the law that applies may depend on how your test or service was ordered. Section 2 explains when SwimScore acts as a business associate of a clinic or provider and when this Privacy Policy applies to information outside HIPAA.
1. Scope of This Privacy Policy
This Privacy Policy applies to Personal Information SwimScore processes through:
- Our public websites and web-based applications;
- Account registration, authentication, patient portals, and dashboards;
- Patient intake, test ordering, specimen-kit fulfillment, shipping, status, and results-delivery workflows;
- Ecommerce, checkout, payment, and refund workflows;
- Customer support, clinic support, and communications by email, SMS, telephone, or secure portal;
- Marketing, educational, and promotional activities; and
- Other interactions with SwimScore where this Privacy Policy is presented or referenced.
This Privacy Policy does not replace the Notice of Privacy Practices issued by an applicable clinic, medical practice, healthcare provider, provider network, or laboratory that is a HIPAA covered entity. When SwimScore processes PHI as a business associate, its uses and disclosures of that PHI are governed by HIPAA, the applicable business associate agreement, and the covered entity’s Notice of Privacy Practices. If this Privacy Policy conflicts with those requirements as to PHI, the HIPAA requirements and applicable agreement control.
Third-party clinics, healthcare providers, laboratories, payment processors, couriers, and other organizations may have their own privacy practices. Their privacy policies and notices govern their independent processing of Personal Information.
2. SwimScore’s Role Under HIPAA
SwimScore does not practice medicine, operate a clinical laboratory, or submit HIPAA-covered healthcare transactions on its own behalf, and is not itself a HIPAA covered entity. SwimScore’s role with respect to Health Information depends on how the service is ordered and the functions SwimScore performs.
Clinic-Ordered Services
A clinic, medical practice, healthcare provider, or provider network that initiates or coordinates your order is referred to as an “Ordering Provider.” To the extent an Ordering Provider is a HIPAA covered entity and SwimScore creates, receives, maintains, or transmits PHI on its behalf, SwimScore acts as that entity’s business associate. The relationship is governed by a written business associate agreement as required by HIPAA.
If an Ordering Provider is not a HIPAA covered entity, information processed through the Services may not constitute PHI under HIPAA, but remains subject to this Privacy Policy and other applicable privacy laws.
Services Ordered Through a Contracted Medical-Network Partner
Where a test or clinical service is ordered or reviewed through a contracted medical-network provider group, and to the extent that provider group is a HIPAA covered entity and SwimScore processes PHI on its behalf, SwimScore acts as that provider group’s business associate. The laboratory remains an independent healthcare provider and is separately responsible for its obligations under HIPAA and other applicable laws, to the extent applicable.
Applicable Notice of Privacy Practices
The Notice of Privacy Practices that applies to PHI is issued by the applicable covered entity, such as the Ordering Provider or the contracted medical-network provider group. SwimScore may make that notice available through the Services as the covered entity’s business associate, but SwimScore does not issue its own HIPAA Notice of Privacy Practices.
Information SwimScore collects or maintains outside its role as a business associate is not PHI merely because it relates to health. Such information is governed by this Privacy Policy, the Federal Trade Commission Act, applicable consumer-health-data laws, breach-notification laws, and other applicable law.
3. Categories of Personal Information We Collect
Depending on how you interact with the Services, we may collect the following categories of Personal Information:
- Identifiers and contact information, including name, email address, telephone number, mailing address, city, state, ZIP code, and account identifiers.
- Account and authentication information, including usernames, passwords, authentication credentials, verification codes, security settings, and account preferences.
- Demographic and eligibility information, including date of birth, age, gender or sex-related information, marital status, and state of residence where relevant to service eligibility or clinical intake.
- Order, transaction, and payment information, including products or services ordered, billing address, payment status, refunds, credits, transaction history, and limited payment-processing information. Full payment-card information is generally collected and processed by our payment processor rather than stored by SwimScore.
- Health and testing information, including medical and reproductive-health history, fertility information, medications, symptoms, questionnaire and intake responses, abstinence and specimen-collection information, requested tests, test orders, laboratory results, semen-analysis information, sperm DNA integrity or fragmentation information, communications concerning care, and information used to coordinate testing or related services.
- Provider, clinic, and care-coordination information, including the identity of your Ordering Provider or Healthcare Provider, referral information, appointment or consultation information, order status, specimen status, and related administrative records.
- Communications and feedback, including support inquiries, telephone or text communications, reviews, survey responses, complaints, and information you choose to submit.
- Internet, device, and usage information, including IP address, browser type, operating system, device identifiers, pages viewed, features used, timestamps, interaction logs, referring URLs, and diagnostic or performance data.
- Location information, generally approximate location inferred from IP address or address information. We collect precise geolocation only where enabled and reasonably necessary for a feature or legal requirement.
- Preferences and marketing information, including communication preferences, consent records, product interests, and interactions with marketing communications.
Depending on applicable law, certain reproductive-health, testing, or sperm DNA integrity information may be treated as sensitive personal information, consumer health data, sexual-health information, or genetic data, even though SwimScore does not perform whole-genome sequencing or inherited-trait testing as part of its standard services.
Unless specifically requested and reasonably necessary, we ask that you not provide Social Security numbers, driver’s-license or passport numbers, financial-account credentials, biometric identifiers used for unique identification, or other highly sensitive information unrelated to the Services.
4. Sources of Personal Information
We may collect Personal Information from the following sources:
- Directly from you, including through registration, intake, checkout, specimen-collection workflows, support interactions, and communications;
- From your Ordering Provider, clinic, medical practice, or referring healthcare professional;
- From a contracted medical-network provider group or other Healthcare Provider involved in ordering, reviewing, or coordinating services;
- From laboratories, specimen-processing vendors, and other healthcare professionals involved in the requested testing or care;
- From payment processors, shipping carriers, fulfillment vendors, communications providers, identity-verification vendors, fraud-prevention vendors, and other service providers;
- Automatically from your browser, device, or interactions with our public websites, portals, emails, or other Services; and
- From another person or organization when you authorize the disclosure or when otherwise permitted by applicable law.
An employer or program sponsor that facilitates access to or payment for the Services may provide limited eligibility or enrollment information. Employers and program sponsors are not treated as Ordering Providers for purposes of receiving identifiable laboratory results or Health Information, except at your express written direction or where otherwise permitted or required by law.
5. How We Use Personal Information
We may use Personal Information as reasonably necessary to:
- Provide, operate, maintain, and improve the Services;
- Create, verify, authenticate, secure, and administer accounts;
- Process intake information, orders, payments, refunds, credits, and transactions;
- Coordinate testing, telehealth or provider services, specimen-kit fulfillment, shipping, laboratory processing, results delivery, and follow-up workflows;
- Make information available to the applicable Ordering Provider, Healthcare Provider, or laboratory as permitted by law and the applicable workflow;
- Communicate about registration, verification, orders, shipping, specimen status, scheduling, results availability, support, security, and service updates;
- Respond to inquiries, provide support, and resolve complaints;
- Detect, investigate, prevent, and address fraud, misuse, security incidents, and illegal activity;
- Maintain records, enforce agreements, protect rights and safety, and comply with legal, regulatory, contractual, and professional obligations;
- Conduct internal analytics, quality assurance, service improvement, and product development using non-PHI information or PHI only where permitted by the applicable business associate agreement and law; and
- Send marketing or promotional communications where you have opted in or where otherwise permitted by law.
PHI and De-Identification
Where SwimScore holds PHI as a business associate, SwimScore uses and discloses that PHI only as permitted by the applicable business associate agreement, HIPAA, and other applicable law. SwimScore may de-identify PHI only to the extent authorized by the applicable business associate agreement and permitted by HIPAA. Any subsequent use of de-identified information remains subject to applicable contractual restrictions and other laws.
Non-PHI Information
For Personal Information that is not PHI, SwimScore may create and use aggregated or de-identified information for internal analytics, security, quality assurance, service improvement, and product development as described in this Privacy Policy and permitted by law. Where separate affirmative consent is required for a particular collection, use, research activity, marketing activity, or disclosure, we will request that consent separately.
6. How We Disclose Personal Information
We do not sell Personal Information for monetary consideration, and we do not disclose Personal Information for cross-context behavioral advertising or targeted advertising as those terms are defined by applicable law. We may disclose Personal Information in the following circumstances:
Ordering Providers, Healthcare Providers, and Laboratories
We may disclose intake information, order and shipment status, specimen information, laboratory results, communications, and other information to your Ordering Provider, a contracted medical-network provider, the testing laboratory, or other healthcare professionals involved in ordering, providing, coordinating, interpreting, or following up on the requested services, as permitted by law and the applicable relationship.
Service Providers and Processors
We may disclose Personal Information to vendors that support the Services, such as providers of cloud hosting, data storage, security, payment processing, identity verification, shipping, fulfillment, communications, customer support, analytics, fraud prevention, and technical maintenance. These providers may use the information only to perform services for us or as otherwise permitted by contract and law. Where a vendor processes PHI, appropriate HIPAA contractual protections are implemented where required.
At Your Direction or With Your Consent
We may disclose information to a person or organization you designate, when you request an integration or service, or when you otherwise authorize or consent to the disclosure.
Employers and Program Sponsors
An employer or program sponsor that pays for or facilitates access to the Services will not receive your identifiable laboratory results or Health Information unless you expressly direct the disclosure in writing or the disclosure is otherwise permitted or required by applicable law. Any employer or sponsor reporting will be limited to information permitted by applicable law and the applicable program documents, such as appropriately aggregated or de-identified utilization information.
Business Partners and Optional Services
We do not disclose Health Information, testing information, authenticated patient-portal activity, or reproductive-health information to third parties for their own advertising or marketing purposes. We may disclose non-health information to a business partner when you specifically request the partner’s service, direct us to make the disclosure, or separately consent to it.
Legal, Safety, and Compliance Purposes
We may disclose Personal Information when we reasonably believe disclosure is necessary or appropriate to comply with law or legal process; respond to government or regulatory requests; protect the rights, property, safety, or security of SwimScore, users, or others; investigate fraud or misuse; or establish, exercise, or defend legal claims.
Business Transfers
We may disclose Personal Information in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable confidentiality, HIPAA, contractual, and legal requirements.
Aggregated or De-Identified Information
We may disclose aggregated or de-identified information that does not reasonably identify you, subject to applicable law, contractual obligations, and any restrictions that apply to information derived from PHI or Consumer Health Data.
7. Consumer Health Data Privacy Notice
This Section supplements the rest of this Privacy Policy and applies to “Consumer Health Data” subject to state consumer-health-data laws, including health information that is not PHI governed by HIPAA and is not otherwise exempt from those laws. Consumer Health Data may include information that identifies or is reasonably capable of being linked to a consumer and relates to physical or mental health status, reproductive or sexual health, fertility, medical interventions, medications, diagnoses, testing, bodily functions, specimens, precise location information that could indicate an attempt to acquire health services, or information inferred from other data.
Categories, Purposes, and Sources
The categories of Consumer Health Data we may collect are described in Section 3, including health and testing information, reproductive-health and fertility information, specimen and laboratory information, provider and care-coordination information, and relevant location or device information. We collect and use this information for the purposes described in Section 5, principally to provide and coordinate Services you request, secure and support the Services, comply with law, and improve the Services as permitted by law. The sources of Consumer Health Data are described in Section 4.
Categories Shared and Recipients
The categories of Consumer Health Data we may share include intake information, order and specimen status, laboratory results, communications, and related care-coordination information. The categories of recipients are described in Section 6 and may include Ordering Providers, Healthcare Providers, laboratories, shipping or fulfillment vendors, payment and communications providers, cloud-hosting and security vendors, and other processors necessary to provide the requested Services. We do not share Consumer Health Data with advertisers for their own marketing or targeted advertising.
Affiliates
SwimScore does not share Consumer Health Data with a corporate affiliate for the affiliate’s own advertising or unrelated commercial purposes. Any affiliate that supports SwimScore’s corporate administration, security, compliance, finance, or operations may process Consumer Health Data only as necessary to provide that support and subject to appropriate contractual and legal safeguards. Before publication, SwimScore should confirm whether any specific affiliate must be identified by name under applicable law.
Consent and Additional Uses
We collect and use Consumer Health Data to the extent necessary to provide a product or service you request and as otherwise permitted by law. Where applicable law requires affirmative consent for collection, use, or sharing beyond what is necessary to provide the requested product or service, we will obtain that consent. We will obtain separate authorization before any sale of Consumer Health Data where required. SwimScore does not sell Consumer Health Data.
Your Consumer Health Data Rights
Depending on where you live and subject to legal exceptions, you may have the right to:
- Confirm whether we collect, share, or sell Consumer Health Data concerning you;
- Access Consumer Health Data and obtain information about the sources and recipients of that data;
- Request correction of inaccurate Consumer Health Data;
- Withdraw consent for future collection or sharing where processing is based on consent;
- Request deletion of Consumer Health Data, including notification to processors or other recipients where required; and
- Appeal a denial of a Consumer Health Data request.
To exercise these rights, email [email protected] with the subject line “Consumer Health Data Request.” Provide enough information for us to verify your identity and understand the request. We will respond within the time required by applicable law. If we deny your request, you may appeal by replying to our decision or emailing the same address with the subject line “Consumer Health Data Appeal.”
Third-Party Collection and Geofencing
We do not permit third-party advertising or retargeting technologies to collect Consumer Health Data from authenticated patient-portal pages, intake forms, test-result pages, or other authenticated health-service areas. We do not use geofences around healthcare facilities to identify, track, collect data from, or send messages or advertisements to consumers based on their location in a manner prohibited by applicable consumer-health-data law.
8. Cookies, Tracking Technologies, and Analytics
Public and Unauthenticated Pages
On public or unauthenticated website pages, we and our vendors may use cookies, pixels, web beacons, SDKs, log files, and similar technologies to provide functionality, remember preferences, analyze performance, measure communications or campaigns, prevent fraud, and improve the website. Depending on the technologies used, certain analytics or advertising vendors may collect browser or device activity over time and across websites. We do not authorize those vendors to receive Health Information, test information, or authenticated patient-portal activity for advertising purposes.
Authenticated Patient-Portal and Health-Service Areas
We do not use third-party advertising or retargeting technologies on authenticated patient-portal pages, intake forms, test-result pages, or other authenticated areas where those technologies could receive Health Information. Any analytics, security, or performance technologies used in authenticated areas are limited to what is reasonably necessary to operate, secure, and improve the Services and are configured and contractually governed to protect Health Information, including through a business associate agreement where required.
You may adjust cookie settings through your browser or any cookie-control tool we provide. Disabling essential cookies may prevent account login or other features from working. We honor legally required browser-based opt-out preference signals where applicable. Because we do not sell Personal Information or use it for cross-context behavioral advertising, such signals do not change those practices.
9. Communications and Messaging
We may use your email address or telephone number to send transactional and administrative communications relating to registration, identity verification, orders, shipping, specimen status, scheduling, care coordination, results availability, security, customer support, and service updates. Standard email and SMS may not be encrypted, and you should avoid sending urgent or highly sensitive medical information through those channels.
Marketing communications are sent only where you have opted in or where otherwise permitted by law. You may unsubscribe from marketing emails using the link in the message and may opt out of marketing texts by replying STOP. Even after an opt-out, we may continue to send non-marketing communications that are necessary for your account or requested Services.
Mobile opt-in data and consent information will not be shared with third parties or affiliates for their own marketing or promotional purposes. We may provide this information to vendors that support delivery of our messaging program, solely as necessary to provide those services, maintain consent records, or comply with law.
10. User Content and Public Areas
Certain features may allow you to submit reviews, comments, survey responses, or other content intended for publication or display in a public or interactive area (“User Content”). Do not include Health Information or other sensitive information in public User Content. Information you choose to make public may be viewed, collected, or used by others. Health Information submitted for testing, care coordination, or support is not treated as public User Content.
11. Data Retention
We retain Personal Information for as long as reasonably necessary to provide and support the Services, complete transactions, maintain security, comply with legal and contractual obligations, resolve disputes, enforce agreements, and fulfill the purposes described in this Privacy Policy. Retention periods may vary by the type of information and the applicable workflow.
Where SwimScore holds PHI as a business associate, retention and return or destruction of PHI are governed by the applicable business associate agreement, HIPAA, the covered entity’s record-retention obligations, and the applicable Notice of Privacy Practices. Laboratories and Healthcare Providers may retain independent medical records under their own policies and legal obligations.
When we honor a deletion request, certain information may remain in backups for a limited period or may be retained where required or permitted by law, including for security, fraud prevention, legal compliance, or the establishment, exercise, or defense of legal claims.
12. Security and Breach Response
We maintain reasonable administrative, technical, and physical safeguards designed to protect Personal Information against unauthorized access, use, alteration, disclosure, or destruction. These safeguards are selected based on the nature and sensitivity of the information, the Services, and reasonably foreseeable risks. No system is completely secure, and we cannot guarantee absolute security.
Where SwimScore acts as a business associate, we follow applicable HIPAA security and breach-notification obligations and notify the applicable covered entity as required. For Health Information outside HIPAA, we provide breach notifications to consumers, regulators, or others when required by the Federal Trade Commission Health Breach Notification Rule, state law, or other applicable law.
13. International Processing and Transfers
The Services are intended for individuals in the United States. We and our service providers may process or store Personal Information in the United States and, where permitted by applicable law and contract, other jurisdictions in which service providers operate. Privacy laws in those jurisdictions may differ from the laws where you live. Where required, we use appropriate safeguards for cross-border transfers.
14. U.S. State Privacy Rights
Residents of certain U.S. states may have rights regarding Personal Information that is not exempt from applicable state privacy laws. Depending on your state and subject to legal exceptions, these rights may include the right to:
- Confirm whether we process Personal Information;
- Access and obtain a portable copy of Personal Information;
- Correct inaccurate Personal Information;
- Delete Personal Information;
- Opt out of the sale of Personal Information, targeted advertising, or certain profiling;
- Limit certain uses or disclosures of sensitive Personal Information;
- Withdraw consent for certain processing; and
- Appeal a denial of a privacy request.
SwimScore does not sell Personal Information and does not process Personal Information for cross-context behavioral advertising or targeted advertising. We do not discriminate against you for exercising applicable privacy rights.
Submitting a Privacy Request
To submit a request, email [email protected] with the subject line “Privacy Rights Request.” You must provide enough information for us to reasonably verify your identity and understand the request. We will use information provided in connection with the request only to verify and respond to the request. An authorized agent may submit a request where permitted by law, but we may require proof of authority and verification of your identity.
We will respond within the period required by applicable law. Where a right to appeal applies, you may appeal by replying to our decision or emailing [email protected] with the subject line “Privacy Rights Appeal.”
California Notice
California residents may request the categories and specific pieces of Personal Information collected, the categories of sources, the business or commercial purposes for collection and disclosure, and the categories of recipients. California residents may also request correction or deletion, subject to exceptions, and may exercise rights concerning sale, sharing, and sensitive Personal Information. SwimScore does not sell or share Personal Information for cross-context behavioral advertising and does not offer financial incentives for disclosure of Health Information.
Nevada Notice
Nevada residents may submit a request concerning the sale of covered information under Nevada law by contacting [email protected]. SwimScore does not sell covered information for monetary consideration. Nevada Consumer Health Data rights are described in Section 7.
15. Children’s Privacy
The Services are not intended for individuals under 18, and we do not knowingly collect Personal Information from children under 18 through the Services. If you believe a child has provided Personal Information to us, contact us so we can review and take appropriate action.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version and revise the Effective Date. If a change is material, we may provide additional notice through the Services, by email, or by another method required by law. Where applicable law requires consent for a new collection, use, or disclosure of Consumer Health Data or other Personal Information, we will obtain that consent before engaging in the new activity.
17. Contact Us
For questions about this Privacy Policy, our privacy practices, or a privacy-rights request, contact:
SwimScore LLC
Email: [email protected]
For account, order, or patient-portal support: [email protected]
Questions concerning PHI rights or the applicable Notice of Privacy Practices should generally be directed to the applicable Ordering Provider or Healthcare Provider identified in the notice. SwimScore may assist with routing a request where it acts as that provider’s business associate.