Legal
What we collect, how it is protected, and who it goes to, in full.
Last updated: October 2, 2026
Who we are
This policy covers Gene Matrix LLC, doing business as GeneMatrix, and the testing service you order through genematrix.io.
What we collect
We collect what your test and your order require:
- Your sample, and the genetic data and test results it produces.
- Your contact and shipping details.
- For each test, the tested person’s legal name, date of birth and sex assigned at birth, and your statement that the test is for you and that you are 18 or older (for GeneBaby, your statement that you are the baby’s parent or guardian, and your baby’s name, date of birth and sex), for the lab’s test request.
- Your payment details, handled by our payment processor ([To be confirmed]: which processor).
- For GenePGx and GeneCancer orders, your answer to whether you have Medicare, Medicaid, TRICARE or another government health plan (an order with one is not taken online).
- For GenePGx orders, any request you make that we not share the test with your health plan.
We collect no other health insurance information: no plan, member number or insurance card. Every order is self-pay today.
We count visits to our information pages with Vercel Web Analytics, which sets no cookies. It records the page viewed (without its query string, apart from campaign tags), the site you came from, and your browser, operating system, device type and country. It never records anything you type, and it never runs on the checkout, order confirmation or portal pages.
Activating your kit
When you activate a kit, we collect:
- the kit ID, and the order it belongs to (the kit is linked to your order when we pack it; you confirm it with your order number or email and the tested person’s date of birth, which we already hold);
- sex assigned at birth, as you confirm or correct it (Female, Male, Intersex, or Prefer not to say);
- the date the sample was taken;
- your answers to two screening questions (a transplant from a donor, and a recent blood transfusion), and for a GeneBaby kit, whether your baby had breast milk in the last hour;
- the time you confirmed that the sample is from the person on the order.
A “yes” to a screening question activates nothing and collects nothing more online. We keep the answer with the kit so our team can talk it through with you; after a donor transplant the kit stays on hold, and the alert our team gets doesn’t say why. Activation data is kept with your order as the lab’s test request. It is never sent to our payment processor, never put in a web address (apart from the kit ID, which your activation card’s QR link and the page confirming your activation carry), and never counted by page analytics, which don’t run on the activation page.
How we use it
We use what we collect to run your test, deliver your results, ship your kit, take payment, and answer you when you write to us.
When your results are ready we email you (the email never names your test) with the lab’s secure link to your report, which asks for the tested person’s details before it opens.
Who it goes to
We never sell your genetic data, and we never share it for marketing or research. It goes only to those who complete your order: the laboratory that runs your tests; for an order shipped to New York, the physician or reference laboratory that completes it; and service providers under contract that store your data or prepare your report for us, including Labrynix and SignalPGx, the laboratory-information and reporting software we use. Once we can bill health plans, and only if you choose to bill our pharmacogenomics (PGx) test to yours, your health plan receives what it needs to process that claim, and for no other purpose. Nutrigenomics and oral microbe results never go to a health plan.
Your contact and shipping details also go to the service providers who deliver kits and take payments on our behalf. The specific providers are [To be confirmed].
Insurers and employers
We do not share your genetic data or test results with employers. Nutrigenomics and oral microbe results are never sent to an insurer.
The one exception for a health plan is described above: once insurance billing opens, and only if you choose to bill our pharmacogenomics (PGx) test to your plan, your plan receives what it needs to process that claim.
Whether any other disclosure to an insurer could ever be required by law is [To be confirmed] by counsel.
Law enforcement
We disclose your data to law enforcement or other government agencies only when the law requires it. Where a state requires a court order or search warrant before we may disclose, we require one too.
How it's protected
Your genetic data is stored in AWS data centres with multiple layers of security, and kept without your demographic details.
Breach notification
If your health information is breached, we follow the HIPAA breach notification rule, and give any additional notice your state’s law requires.
How long we keep things
We destroy your sample within 30 days of your results unless you separately consent to storing it. We don’t offer that consent at checkout today, so we never store a sample beyond that.
If you ask us to destroy your data or your sample sooner, we complete that within 30 days, and confirm it to you in writing.
Federal and state law — including CLIA, and the rules in Illinois — require our laboratory to keep certain test records. We keep them for 7 years, even if you ask us to delete your data or destroy your sample.
Your rights by state
Your privacy rights over your own genetic and health data depend on where you live. Some of what applies:
- Illinois: under the Genetic Information Privacy Act, your genetic test results are confidential, and we release them only as the law allows.
- Several other states have their own direct-to-consumer genetic-privacy laws, which generally give you the right to express consent before testing, a separate consent before any transfer or use for research, and the destruction of your sample and data.
- Washington, Nevada and Connecticut treat this as "consumer health data" under their own laws, with added rights over its collection and sharing (see our Consumer Health Data notice).
- California treats your genetic data as "sensitive personal information" under the California Consumer Privacy Act.
- New York requires your written consent before certain genetic tests, and sets its own rules for destroying your sample.
Which of these apply to you, and how you exercise them, is [To be confirmed] by counsel. Deleting your data, and destroying your sample, is already confirmed: We delete your data, and destroy your sample, on request.
Children
Whether, and how, a minor may be tested through this service is [To be confirmed].
Changes to this policy
If we change this policy, we will post the new version on this page.
Contact
Questions about this policy go to info@genematrix.io, or call 847-302-9668.