Privacy Policy
Last Updated: January 17, 2023
Thanks for visiting iollo!
This Privacy Policy describes how iollo, Inc. (“iollo”,“we”, “us” and/or “our”) handles the personal informationthat we collect from and about you in connection with the following:
- our public website, currently located at https://www.iollo.com/(the “Site”);
- our at-home metabolomics testing kits (the “Tests”);
- our metabolomics services (“Metabolomic Testing”);
- and all associated content, features, functionalities, user interfaces, mobileapplications and software we may offer (collectively with the Site, Tests, andMetabolite Testing, our “Services”).
This Privacy Policy also describes certain legalrights you may have, subject to applicable law, and how you can exercise them.
For the purposes of this Privacy Policy, “Personal Information” means information about an identifiable person, as defined by applicable law. This includes information that, either alone or in combination with other information, can be used to identify, contact, or locate you, such as your name, address, email address, or phone number. It also includes the following health and biometric information:
- information related to your blood sample and/or blood test results from tests done by iollo laboratories or iollo research partners (“Metabolomic Information”);
- information you provide in response to iollo questionnaires or other website surveys or prompts, including assigned sex, body weight, height, diet, habits, product usage, ethnicity, and exercise (“Self-Reported Information”); and
- health and biometric information collected from integrations with wearables or health apps (such as your heart rate and steps per day collected from a smartwatch or diet information collected from a diet-tracking app) (“Imported Information”).
For the avoidance of doubt, Personal Information includes Metabolomic Information, Self-Reported Information, and Imported Information.
This Privacy Policy applies to information we collect and use for our own purposes, including information we collect from and about visitors to our website, customers when they register for and access their iollo account, and individuals in relation to our marketing activities. This Privacy Policy does not apply to the data we process under contract as a service provider to healthcare organizations. When we store, process, or transmit protected health information (as such term is defined by the Heath Insurance Portability and Accountability Act of 1996 or “HIPAA”) on behalf of a healthcare organization, we do so as its “business associate” (as also defined by HIPAA) and our use of that data is limited by our agreement with that healthcare organization.
By using any of iollo’s Services, you confirm that you have agreed to the iollo
Terms of Service and, to the extent permitted by law, and have read and understood this Privacy Policy.
1. Information We Collect
1.1 Information You Give Us Directly
We collect some information directly from you. For instance, we collect information that you voluntarily provide in the following ways:
- When you request information or purchase one of our plans. When you fill informs on our Site, including when you request additional information about our Services or sign up for a waitlist, we require that you provide us with certain information relevant to your request, such as your email address, first and last name, date of birth, assigned sex, where you live, how you heard about iollo, and what types of health metrics you are currently tracking. If you choose to purchase one of our plans, we require that you provide our third-party payment processor, Stripe, with your name, payment card information, and billing address.
- When you create your iollo account. If you enroll in one of our plans, you will need to create an account on our Site. Creating an account allows you to recover your data and log in on a different or shared device. The email address you provide us will serve as your username and you will be asked to set password to allow us to authenticate you at sign in. We may also ask for a referral or access code if someone bought an iollo plan for you as a gift or otherwise invited you to give iollo a try. We will populate your account with any information you provided during registration and will ask whether you would like to provide certain optional information such as a profile photo.
- When you send us a blood sample for analysis. When you send us a blood sample for analysis, we use advanced mass spectrometry technology to measure your metabolite levels. This analysis helps us make inferences about how you are aging, which of your metabolites are out of range, how your metabolic pathways are functioning, and the functional status of your various organs. From these inferences, we create personalized reports and recommendations for you.
- When you complete questionnaires. In order to create individualized diet and behavioral action plans for you, we need understand your exposome (diet, habits, product-usage, etc.). To collect this information, we will ask you to complete a questionnaire when you enroll and may ask you to complete similar surveys, prompts, and questionnaires from time to time thereafter. We collect any information you provide when completing these questionnaires, including information about your age, ethnicity, assigned sex, body weight, height, diet habits, medication and supplement intake, physical activity, sleep patterns, and family history. This Self-Reported Information may be captured by selecting an option from a series of choices presented to you or by providing free-form written notes which can include any information you choose.
- When you participate in research studies. We may contact you to ask if you would be willing to participate in a research study. If you decide to participate, you may be asked to provide demographic information, feedback, and any other information relevant to that survey or study.
- When you invite others to try iollo. We offer features that allow you to invite others to try iollo Services. If you use these features, we will store the invitee’s email address only so long as is necessary to send the invite. We also let the invitee know who invited them to use iollo and let them request that their information be deleted from our systems.
- When you purchase our Services as a gift for someone else. If you purchase our Services as a gift for someone else, any information you provide about the gift recipient will be used solely to deliver the gift. Your gift recipient must create their own account and provide their own blood sample. No Personal Information about the gift recipient will be shared with you unless they explicitly choose to do so.
- When you sign up to receive email communications from us, including newsletters or updates about products, services, and events we may offer. When you engage in one of these activities, we may collect your name, email address, and any additional information you choose to provide to us as part of that request. We may also track your participation in any of these activities to help us understand our users and improve our Services (such as tracking which emails you open to understand what type of content is most popular with our users).
- When you contact us. When you contact us by email; through our branded social media accounts or customer support site; through any integrated chat providers we may provide; or by telephone, SMS, or physical mail, we may collect your name, social media username (if applicable), email address, phone number, physical address, and the contents of your communication which can include any information you choose to provide.
1.2 Information We Collect Automatically When You Use Our Services
We also collect certain information automatically as you navigate our Services or interact with our communications, including the following:
- Information about the devices you use to access our Services (including your internet protocol (IP) address, browser type, and operating system);
- The address of the web page visited before and after using our Services;
- Details about your interactions with our Services (such as the date, time, length of stay, and specific pages accessed during your visits);
- Search terms used to reach our Services;
- Usage information(such as the number and frequency of visitors to our Site);
- Location information (such as general location information inferred from your IP address);and
We collect some of the information above using cookies or similar technologies. A “cookie” is a small text file that websites send to a visitor’s computer or other internet-connected device to uniquely identify the visitor’s browser or device or to store information or settings in the browser/device. We, and our third-party service providers, use cookies in order to do things such as recognize you when you return to our Site, save your preferences (including your preferences regarding cookie handling), understand usage patterns, and improve our mobile applications. We use both session cookies (which expire when you close your browser or app) and persistent cookies (which stay on your device until you delete them or until they expire).
If you do not want us to collect information through the use of cookies, you can disable cookies, limit the types of cookies you allow, or set your browser to alert you when cookies are being sent. Please refer to the guidance offered by your chosen web browser if you would like help managing your cookie preferences. Please note that if you reject or block cookies, the Services may not work as intended.
We also may partner with third parties who provide analytics services and serve advertisements on our behalf across the Internet and in mobile applications. These third-parties may use cookies and similar technologies to track your engagement with our Site as well as our online advertising and email marketing campaigns and permit us and them to analyze and track data, and do things like determine which advertising or marketing source brought someone to our Site and target advertisements to an audience based on prior browsing patterns on our Site.
We never share your Metabolomic Information, Self-Reported Information, or Imported Information with our third-party advertising and analytics partners.
1.3 Information We Collect from Other Sources
We may also obtain Personal Information from other sources. For instance, we may collect Personal Information about you from the following third-party sources:
- Payment processors: In general, when you purchase a plan or pay for other products or services through iollo, your payment card information is provided directly to our third-party payment processor and iollo does not collect or store that information. However, we may receive limited information about your payment card from our payment processors, such as the last four digits for your card, the country of issuance, and the expiration date.
- Third-Party Wearables and Health Apps. If you choose to, you can enable connections from your iollo account to a variety of third-party wearables and health apps (e.g., Whoop, Fitbit, Apple Watch, Oura). Enabling these integrations is entirely voluntary. Once enabled, the provider of the third-party wearable or health app may share a variety of information with us, such as heart rate, temperature data, sleep routines and phases, movement and activity levels, diet habits, product usage and any other information the third-party provider has chosen to make available to iollo to facilitate the integration. We use this Imported Information to provide our Services, including developing individualized action plans and recommendations for you. We encourage you to check the privacy settings and privacy policies of these third-party wearables and health apps to understand what information may be shared with us.
- Another person. We may collect Personal Information about you from another person if that person provides us with your email address or other information in order to invite you to try iollo or to gift you our Services.
- Social media platforms. We may offer social sharing features and other integrated tools such as widgets, which allow you to share content on our Site with third-party social media platforms such as Facebook, Twitter, or LinkedIn. If you choose to use these social sharing features, the provider of the third-party social media platform may make certain information available to us. This can include information necessary to facilitate the integration as well as any additional information the provider chooses to share with us or which you have permitted the provider to share through your privacy settings. We encourage you to check the privacy settings and privacy policies of these third-party social media platforms to understand what information might be shared with us.
2. How We Use Your Information
We use the information described above to do the following:
- Provide our Services (including creating your account and identifying you when you sign in; managing your access to and use of our Services; fulfilling your requests and registrations; and sending you technical notices, updates, security alerts, and support and administrative messages);
- Operate and improve our Services (including monitoring and analyzing usage, trends, and activities related to the Services and identifying, fixing, and troubleshooting bugs and service errors);
- Communicate with you (including responding to your requests, inquiries, comments, and suggestions);
- Personalize content (including developing individual action plans and personalized diet and behavior recommendations and tailoring content we send or display to you in order to provide you with information and resources we think will be relevant to you);
- Conduct internal data analysis (including identifying usage trends, determining the effectiveness of our promotional campaigns, and evaluating the user experience on our Site and Services);
- Conduct scientific research, to the extent you have given us your consent to do so (including de-identifying and/or aggregating information and using and disclosing it to our research partners in order to conduct or support research aimed at better understanding metabolic functioning and developing new knowledge, techniques, drugs, and devices);
- Further our networking, marketing, and social strategies (including posting testimonials; notifying you about programs, services, offers, promotions, and events; and promoting our programs and services);
- Protect against, identify, investigate, and respond to misuse of our Services (including preventing and detecting fraud, unauthorized access, and other unlawful behavior);
- Support our general business operations (including maintaining our business and legal recordkeeping); and
- Carry out any other purpose described to you at the time the information was collected.
3. How We Share Your Information
We may share information about you with third parties in the following circumstances:
- Companies under common control. We may share Personal Information between and among any current or future parents, subsidiaries, affiliates, and other companies under common control and ownership with iollo.
- Vendors and service providers. We may share Personal Information with contractors, service providers, and other third parties we use to support our business and provide the Services. These providers may complete transactions or perform services such as cloud storage on our behalf or for your benefit.
- Our research partners. With your consent, we may include your de-identified and/or aggregated Metabolomic and Self-Reported Information in disclosures to third parties for the purpose of research. iollo research is intended to advance science and knowledge and to create, commercialize, or undertake activities toward the practical applications of this learning to the improvement of longevity, health, and healthy lifespans. Research may be conducted by our own team, or by our research partners, which may include commercial or non-profit organizations that support or conduct medical research or conduct or support the development of drugs or devices to diagnose, predict, or treat health conditions. We contractually require our research partners to agree that they will not attempt to re-identify the data and will not transfer the de-identified data to another party unless that party also agrees in writing not to attempt to re-identify the de-identified data.
- Advertising and Analytics Partners. We may share your Personal Information with other third parties that provide online analytics and advertising services in order to better understand how individuals interact with our Services and other online services over time and across devices. However, we do not share Metabolomic Information, Self-Reported Information, or Imported Information with these partners.
- Public. We may offer features that allow you to connect with other iollo users and communicate in public or semi-public spaces. If you use these features or post information on our branded social media pages, that information may be displayed and viewable by other users.
- Business transfers. We may share Personal Information with another company in connection with or during negotiations of any merger, acquisition, financing, re-organization, bankruptcy, sale of all or a portion of our assets, or transition of services to another provider.
- Legal requirements. We may share Personal Information when we believe it is necessary to comply with a legal obligation, including lawful requests from public authorities to meet national security or law enforcement requirements. We may also share Personal Information when we believe it is necessary to protect our rights and property, to protect the safety of our users, and to defend against legal liability. If we are required to disclose your information in response to a subpoena or other government request, we will do our best to provide you with notice in advance, unless we are prohibited by law from doing so.
- Consent. We may share Personal Information with third parties with your consent and at your direction, including if we notify you that the information you provide will be shared in a particular manner and you provide that information.
We may also share aggregate or de-identified information, which cannot reasonably be used to identify you, for various purposes including compliance with various reporting obligations; for business or marketing purposes; or to assist third parties in understanding our users’ interests, habits, and usage patterns for certain programs, content, services, advertisements, promotions, and/or functionality available through the Services.
4. Your Rights and Choices
You have a variety of rights and choices related to our use of your Personal Information.
- Opting out of email marketing. You can opt out of receiving our promotional emails at any time by following the instructions included in those emails. Please be aware that it may take up to ten (10) days for us to process your request, and you may continue receiving promotional communications from us during that period. If you opt out of receiving such communications, please be aware that we may continue to send you non-promotional emails (such as updates to this Privacy Policy and other legally required notices of information).
- Restricting cookies/Do Not Track. iollo does not currently change its behavior in response to web browser “do not track” signals. However, you can configure most browsers to reject cookies or to notify you when you are sent a cookie, giving you a chance to decide whether or not to accept it. You can consult the help section of your browser to find out how to do this. Please note that if you choose to remove or reject cookies, this could affect the availability and functionality of our Services. In the event that a universally accepted standard emerges on how organizations should respond to “do not track” or similar opt-out signals, we will assess and provide an appropriate response to those signals.
- Access, update, or delete your information. If you would like to access, update, or delete Personal Information you have provided you may do so through your account settings or by emailing us at privacy@iollo.com. If you no longer wish to use iollo Services, you may close your account by sending a request to support@iollo.com. When close an account, we remove all Personal Information within your account. However, Personal Information that you have previously provided will not be removed from ongoing or completed internal R&D or business activities that use the information (as de-identified, statistical information). Similarly, if you close your account after you have separately agreed to participate in a research study, any Metabolomic Information that you have previously given consent to use in de-identified form will not be removed from ongoing or completed studies. In addition, we keep limited information related to your order history (e.g., name, contact, and transaction details) for accounting and compliance purposes. We may also keep cached archived copies of Personal Information for a limited period of time.
- Limiting information in your account. You can control the information we collect about you by limiting what information you provide through your account. Please note that if you choose not to provide certain information it may make it difficult or impossible for you to access some services.
5. Children’s Privacy
Our Services are intended for adults over 18 and we do not knowingly collect Personal Information from children. If you are a parent or legal guardian and think your child under 18 has given us Personal Information without your consent, please email us using the contact information below.
6. Links to Other Websites and Third-Party Content
We may provide links to third-party websites, services, and applications that are not operated or controlled by iollo. This Privacy Policy does not apply to the privacy practices of those third parties. The fact that we link to a website, service, or application is not an endorsement, authorization, or representation of our affiliation with that third party. We encourage you to review the privacy policies of any third-party service before providing any Personal Information to or through them.
7. Data Transfer
Our Services are intended for individuals residing in the United States. If you reside outside the United States, you may not use our Services at this time and should navigate away from this page.
Personal Information we collect may be stored and processed for the purposes set out in this Privacy Policy in the United States, where we are based; in Canada, where our sample storage facilities are located; or in any other country where we engage vendors or service providers. These countries may not have the same data protection laws as the country in which you originally provided the data. By using our Services or submitting your Personal Information to us, you agree to such transfers.
8. Data Retention
We only keep your Personal Information for so long as reasonably necessary for the purposes described in this Privacy Policy, as required by law, or as necessary to resolve disputes and enforce our rights and agreements. To dispose of Personal Information, we may anonymize it, delete it, or take other appropriate steps. Data may persist in copies made for backup and business continuity purposes for additional time.
9. Security
iollo usesgenerally accepted administrative, physical, and technical safeguards webelieve are appropriate to protect the confidentiality, integrity, andavailability of your Personal Information. Although we make reasonable effortsto protect Personal Information from loss, misuse, or alteration by thirdparties, you should be aware that there is always some risk involved intransmitting information over the internet and storing informationelectronically. iollo cannot and does not guarantee absolute security.
Please recognize that protecting your Personal Information is also your responsibility. We ask you to safeguard your password, secret questions and answers and other authentication information you use to access our Services. You should not disclose your authentication information to any third party. You should also immediately notify us of any unauthorized use of your password. We cannot secure Personal Information that you release on your own or that you request us to release. Neither can we protect your information once you have exported this data, or allow third parties access to your iollo accounts.
In addition, you may choose to disclose, through other means not associated with us, any part of your Personal Information, including your Metabolomic Information, Self-Reported Information, and Imported Information. You may share this information with friends or family members, groups of individuals, third-party service providers, doctors or other health care professionals, or other individuals. We recommend that you make such choices carefully.
If you do choose to share Metabolomic Information with your doctor or other health professional, that information may become part of your medical record. Other health professionals and health insurance companies may be able to access the Metabolomic Information in your health record. We will have no responsibility or liability for any consequences that may result because you have released or shared Personal Information with a third party. It is your responsibility to share your Personal Information, including Metabolomic Information only with people you know and trust.
10. Changes to Our Privacy Policy
We may change this Privacy Policy from time to time to reflect changes in our practices or in the law. If we make changes to this policy, we will post the updated Privacy Policy on our website and indicate when it was last revised. We encourage you to frequently check this page for any changes to stay informed about our practices. If we make material changes, we will notify you here, by email, or by means of a notice on the Services prior to the change becoming effective. Your continued use of the Services after the revised Privacy Policy has become effective indicates that you have read, understood, and agreed to the current version of this Privacy Policy, to the extent permitted by law.
11. Contacting Us
If you have any questions about our Privacy Policy or how we protect your Personal Information, please contact us at
privacy@iollo.com or you may write us at 2261 Market Street,#4822, San Francisco, CA 04114.