Privacy Policy
Last updated: July 21, 2026
1. Introduction
Medical Testing Solutions, L.L.C. ("we," "us," or "our") respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at medicaltestingsolutions.com, use our customer portal, or interact with our services. By using our website or services, you agree to the practices described in this policy.
2. Information We Collect
Personal Information You Provide
We collect personal information that you voluntarily provide when you:
- Create a customer portal account (name, email, phone, company name, address)
- Submit a quote request or service inquiry
- Place an order or make a purchase
- Contact us via phone, email, or online forms
- Upload compliance documents (W9, tax exemption certificates)
This may include:
- Full name and job title
- Email address and phone number
- Mailing, shipping, and billing addresses
- Facility name, type, and location
- Payment information (processed securely through our payment processor — never stored on our servers)
- Messages, notes, or other content you provide in forms
Account Security Information
If you create a customer portal account, we collect and store information necessary to secure your account, including:
- Hashed password (we never store plaintext passwords)
- Two-factor authentication (2FA) method preference and encrypted TOTP secrets
- Login activity logs (timestamps, IP addresses) for security auditing
Automatically Collected Information
When you visit our website, we may automatically collect:
- IP address and approximate geographic location
- Browser type, version, and operating system
- Referring URLs and exit pages
- Pages viewed, time spent, and navigation patterns
- Device identifiers and screen resolution
- Session identifiers for cart functionality
3. How We Use Your Information
We use the information we collect to:
- Process and fulfill quote requests, orders, and repair service requests
- Provide, maintain, and improve our services and customer portal
- Communicate with you about inquiries, quotes, orders, and service appointments
- Send transactional notifications (order confirmations, shipping updates, quote responses)
- Send abandoned cart reminder emails if you begin a quote request but do not complete it — we may send up to two follow-up emails (at approximately 1 hour and 24 hours after cart abandonment) to the email address you provided
- Send marketing communications (with your consent, where required)
- Verify your identity and secure your account via two-factor authentication
- Detect, prevent, and respond to fraudulent or unauthorized activity
- Comply with legal obligations and regulatory requirements (including NFPA 99, ASSE, and medical device standards)
- Analyze website usage to improve user experience and optimize performance
4. Information Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information with:
- Service providers: Third-party vendors who assist in operating our business, including payment processors, email delivery services (Resend), shipping carriers (UPS), and cloud infrastructure providers. These providers are contractually obligated to protect your data and use it only for the services they provide to us.
- Advertising and analytics partners: We share information with Google (Google Ads, Google Analytics 4, Google Tag Manager, Google Merchant Center) and Microsoft (Microsoft Advertising / Bing Ads via the Microsoft UET tag, tag ID 97257101) to measure advertising effectiveness, attribute conversions, build remarketing audiences, and optimize campaign performance. For "enhanced conversions" and offline conversion match-back, we may transmit SHA-256 hashed versions of your email address, phone number, and/or name along with pseudonymous click identifiers (e.g.,
gclid,msclkid), conversion values, and page URLs. Hashing occurs before transmission; we do not share plaintext contact information with ad platforms. Data shared for this purpose is governed by each partner's data-processing terms (Google Ads Data Processing Terms and Microsoft Advertising Customer Match / EU Data Boundary terms) and is used solely for measurement, attribution, fraud prevention, and audience creation — never to publicly identify you. You may opt out of this ad-measurement sharing by declining non-essential cookies in our consent banner or by emailing sales@medicaltestingsolutions.com. - Accounting integrations: Order data may be synced with QuickBooks Online for invoicing and fulfillment purposes.
- Legal compliance: When required by law, regulation, subpoena, or legal process
- Business transfers: In connection with a merger, acquisition, or sale of assets
- Protection of rights: To protect our rights, property, or safety, or that of our users or the public
5. Data Sharing Restrictions
- Customer data is never shared with third parties for their own promotional or marketing purposes.
- Mobile opt-in and consent are never shared with anyone for any purpose. Any information sharing mentioned elsewhere in this policy explicitly excludes mobile opt-in data.
- Compliance documents (W9, tax exemption certificates) uploaded to the customer portal are accessible only to you and authorized administrators.
6. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes described in this policy:
- Customer accounts and profiles: Retained for the duration of your account. You may request deletion at any time.
- Order records: Retained for a minimum of 7 years for tax, regulatory, and warranty compliance purposes.
- Quote requests and service leads: Retained for 3 years after completion or closure, then anonymized or deleted.
- Abandoned cart data: Session-based cart data is automatically purged after 90 days.
- Security and activity logs: Retained for 1 year for fraud detection and security auditing.
- Analytics data: Aggregated analytics data is retained indefinitely; individual session data is retained per Google Analytics' standard retention settings.
7. Messaging Terms and Conditions
Contacts provide their phone number and check a box to opt in to messaging. By providing your phone number and agreeing to receive texts, you consent to receive text messages from Medical Testing Solutions, L.L.C, from (754) 315-1078 regarding informational and marketing communications. Consent is not a condition of purchase. Message frequency varies. Message & data rates may apply.
You can reply STOP to unsubscribe at any time or HELP for assistance. You can also contact us at (754) 315-1078 or sales@medicaltestingsolutions.com.
Mobile opt-in information is never shared with third parties.
Opt-In Confirmation
Upon opting in, you will receive the following confirmation message: "Thank you for opting in to receive messages from Medical Testing Solutions. Msg frequency varies. Msg & data rates may apply. Reply HELP for help. Reply STOP to opt-out."
SMS Terms of Service
By opting into SMS from a web form or other medium, you are agreeing to receive SMS messages from Medical Testing Solutions. This includes SMS messages for delivery notifications. Message frequency varies. Message and data rates may apply. See privacy policy at https://www.medicaltestingsolutions.com/privacy-policy/. Message HELP for help. Reply STOP to any message to opt out.
8. Data Security
We implement comprehensive technical and organizational security measures to protect your personal information:
- Encryption: All data is transmitted over TLS/SSL encrypted connections. Sensitive data at rest is encrypted using industry-standard algorithms.
- Authentication: Customer portal accounts are protected by mandatory two-factor authentication (2FA) via email or authenticator app (TOTP).
- Session security: An automatic 60-minute inactivity timeout protects unattended sessions.
- Access control: Row-level security policies ensure users can only access their own data. Administrative access requires separate role-based authorization.
- Payment security: Payment information is processed through our PCI-DSS Level 1 certified payment processor. Card numbers are never transmitted to or stored on our servers.
- Bot protection: Public forms are protected by Cloudflare Turnstile to prevent automated abuse.
- Activity monitoring: Login activity and security events are logged for audit and fraud detection purposes.
9. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, and understand user behavior.
Essential Cookies
These are required for core website functionality, including authentication sessions, cart persistence, and security tokens. They cannot be disabled.
Analytics Cookies (Google Analytics 4 & Google Tag Manager)
We use Google Analytics 4 and Google Tag Manager to understand how visitors use our website. These services collect:
- Visit frequency and page views
- Time spent on pages and navigation flow
- Referring websites
- General geographic location (based on IP address)
- Browser and device information
We do not merge personally identifiable information with GA4 reporting. You can opt out using the Google Analytics Opt-out Browser Add-on, or by declining non-essential cookies via our cookie consent banner.
Advertising & Conversion Measurement Cookies
With your consent, we set advertising and conversion-measurement tags to help us understand which ads and keywords drive quote requests, service leads, and purchases, and to build remarketing audiences of past visitors:
- Google Ads (gtag / conversion linker): Sets the
_gcl_*cookies to attribute conversions to Google Ads clicks and supports "enhanced conversions" using hashed email/phone. - Microsoft UET (Bing Ads), tag ID 97257101: Sets the
_uetsidand_uetvidcookies to measure Microsoft Advertising conversions, build remarketing lists, and support enhanced conversions using hashed email/phone. - Google Tag Manager: Container used to load the tags above and to fire virtual page-view events (e.g.,
/thank-you) on form submissions for conversion tracking.
These tags are used exclusively for measurement, attribution, and remarketing on the Google and Microsoft ad networks. We do not sell your data, and hashed contact identifiers cannot be reversed by us or the ad platforms to identify individual visitors publicly.
Managing Cookies & Consent
When you first visit our website, a cookie consent banner allows you to accept or decline non-essential cookies. If you decline, Google Analytics, Google Ads, and Microsoft UET tags are disabled (via Google Consent Mode v2 signals ad_storage=denied, analytics_storage=denied, ad_user_data=denied, and ad_personalization=denied, and the equivalent Microsoft UET consent signal). You can revisit your choice at any time via the "Cookie Preferences" link in the footer, or clear cookies through your browser settings.
10. Automated Emails and Communications
We send the following types of automated emails:
- Transactional emails: Order confirmations, shipping notifications, quote responses, and account security alerts (2FA codes, password resets). These cannot be opted out of.
- Abandoned cart reminders: If you begin a quote request and provide your email but don't complete the submission, we may send up to two reminder emails. You can opt out by replying "unsubscribe" or contacting us.
- Marketing emails: With your consent, we may send product updates or promotions. You can unsubscribe at any time via the link in each email.
11. Third-Party Links
Our website may contain links to third-party websites, including manufacturer product pages and compliance resources. We are not responsible for the privacy practices or content of these external sites. We encourage you to review their privacy policies before providing any personal information.
12. Children's Privacy
Our website and services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under the age of 13. We do not knowingly upload or share data related to individuals under the age of 13 with any third-party advertising or analytics platform. If we become aware that we have collected information from a child under 13, we will take steps to delete it promptly.
13. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information (subject to legal retention requirements)
- Portability: Request your data in a structured, commonly used format
- Opt out of marketing: Unsubscribe from marketing communications at any time
- Opt out of advertising: Opt out of interest-based advertising and ad personalization
- Restrict processing: Restrict or object to certain data processing activities
- Withdraw consent: Withdraw previously given consent at any time
To exercise any of these rights, contact us at sales@medicaltestingsolutions.com. We will respond within 30 days.
14. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with specific rights:
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we collect, use, and disclose.
- Right to Delete: You may request deletion of personal information we have collected, subject to certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: We do not sell your personal information for money. Under the CPRA's broader definition, our use of Google Ads and Microsoft UET remarketing/enhanced-conversion tags may qualify as "sharing" personal information for cross-context behavioral advertising. You may opt out of this sharing at any time by declining non-essential cookies in our consent banner, using the "Cookie Preferences" link in the footer, or emailing sales@medicaltestingsolutions.com with the subject "Do Not Share My Personal Information."
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
To submit a verifiable consumer request, email sales@medicaltestingsolutions.com with the subject "CCPA Request."
15. Users in the European Economic Area (EEA) and UK
If you are located in the European Economic Area or United Kingdom, the following additional provisions apply under the General Data Protection Regulation (GDPR):
- We obtain your consent before setting non-essential cookies or sharing your data with advertising partners, in accordance with Google's EU User Consent Policy.
- We process your data under the legal bases of consent, legitimate interest, and contractual necessity as applicable.
- You have the right to withdraw consent at any time by clearing your cookies or contacting us.
- You have the right to lodge a complaint with your local data protection authority.
- Data transfers outside the EEA are protected by Standard Contractual Clauses or equivalent safeguards.
16. Do Not Track Signals
Some browsers send "Do Not Track" (DNT) signals. Our website respects your cookie consent preferences set via our consent banner. If you decline analytics cookies, tracking is disabled regardless of DNT signals.
17. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date and, where required, notified via email. Your continued use of our website after changes constitutes acceptance of the revised policy.
19. HIPAA Compliance
Medical Testing Solutions, L.L.C. operates as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the HITECH Act. We create, receive, maintain, and transmit Protected Health Information (PHI) in connection with the medical gas testing, verification, and certification services we provide to Covered Entities such as hospitals, surgical centers, dental offices, and other healthcare facilities.
Business Associate Agreements
We enter into Business Associate Agreements (BAAs) with all Covered Entities and downstream subcontractors before accessing, creating, or handling any PHI. These agreements define the permitted uses and disclosures of PHI, our obligations to safeguard it, and breach notification procedures in accordance with 45 CFR Parts 160 and 164.
Protected Health Information (PHI) We May Handle
In the course of providing medical gas services, we may access or generate information that qualifies as PHI, including:
- Facility names, locations, and department identifiers associated with patient-care areas
- Verification and test reports referencing specific rooms, floors, or zones within healthcare facilities
- Maintenance records and inspection logs for medical gas systems serving patient areas
- Photographs or documentation of systems in patient-care environments
- Contact information for facility personnel involved in medical gas system management
HIPAA Security Safeguards
We implement administrative, physical, and technical safeguards as required by the HIPAA Security Rule (45 CFR § 164.308–312):
- Administrative Safeguards: Designated Security Officer, workforce training, risk assessments, incident response procedures, and business associate management
- Technical Safeguards: AES-256 encryption at rest and TLS 1.2+ encryption in transit, mandatory two-factor authentication (2FA), role-based access controls, automatic 60-minute session timeouts, and comprehensive audit logging of all data access
- Physical Safeguards: Restricted facility access, workstation security policies, and device management procedures
Minimum Necessary Standard
We apply the HIPAA Minimum Necessary standard to all uses and disclosures of PHI. Our systems enforce row-level security policies ensuring that users — including subcontractors — can only access the specific data necessary for their assigned tasks. We do not access, use, or disclose PHI beyond what is required to fulfill our contractual obligations.
Breach Notification
In the event of a breach of unsecured PHI, we will notify affected Covered Entities without unreasonable delay and no later than 60 days after discovery of the breach, in accordance with 45 CFR § 164.410. Our notification will include: the nature and extent of PHI involved, the identity of unauthorized persons who accessed the data, whether the PHI was actually acquired or viewed, and the corrective actions taken.
Subcontractor Compliance
All subcontractors who may access PHI through our platform or services are required to execute BAAs and comply with HIPAA requirements. We maintain a vetted network of ASSE-certified professionals who undergo HIPAA compliance verification as part of our onboarding process.
Your Rights Under HIPAA
If we maintain PHI about you as a patient or individual, you have the right to:
- Request access to and receive a copy of your PHI
- Request amendment of inaccurate PHI
- Receive an accounting of disclosures of your PHI
- Request restrictions on certain uses and disclosures
- File a complaint with us or with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights
To exercise any HIPAA-related rights or to request a copy of our Notice of Privacy Practices, contact our Privacy Officer at provost@medicaltestingsolutions.com.
20. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, our HIPAA practices, or our data handling, please contact us:
- Company: Medical Testing Solutions, L.L.C.
- Email: sales@medicaltestingsolutions.com
- Phone: (754) 315-1078
- Privacy/HIPAA Officer: provost@medicaltestingsolutions.com