Skip to main content
qPCR Workbench
TermsPrivacy

MARINABIOLAB QPCR PLATFORM

Privacy Policy

Effective 7 October 2026

This policy explains how Marinabiolab LLC (“MarinaBioLab”, “we”, “us”), 3009 Quail Run Dr, Round Rock, TX 78681, handles information in the MarinaBioLab qPCR validation platform: the workbench at www.mblvalidation.com, the client portal at portal.mblvalidation.com, our internal owner console, and the services behind them (together, the “Service”). Questions go to accounting@marinabiolab.com.

1. Information we process

  • Account information. Your name, work email address, organization, role in that organization and workspace membership. The sign-in pages use a one-time code or link sent to your email. Supabase manages authentication credentials and sessions, including credentials for accounts that use password authentication.
  • Client organization and engagement information. Organization names and contacts, validation proposals and statements of work, Lab Build engagement details, checklists, scheduling information and project documents.
  • Laboratory data. Instrument run exports you or our scientists upload (for example plate layouts, sample and target names, Cq values and amplification data), the analyses calculated from them, review decisions, and the validation reports, tables and figures produced from them.
  • Electronic signatures. When you sign an agreement in the portal we record your consent to electronic records, the intent statement, your typed name and title, the date and time, your IP address and browser user agent, and a fingerprint (SHA-256) of the exact document signed. Scientific report approvals record the approver, role and time.
  • Payment status. Order, invoice and payment status for your engagement, such as amounts, currency, invoice and order numbers, and whether a payment has been received. Payment credentials are entered with the payment provider (Shopify or Intuit QuickBooks). The Service receives and retains provider order and payment records, including linked provider event payloads.
  • Audit and technical records. An append-only audit trail of actions taken in the Service, and limited technical data needed to run and secure it (request identifiers, timestamps, error reports).

2. How we use information

We use this information to provide the Service: to sign you in and keep workspaces separate, to analyze laboratory data and prepare validation reports, to run proposals, signatures, scheduling and payment tracking for your engagement, to communicate with you about it, to keep an audit trail, and to diagnose and secure the Service. We do not sell personal information, and we do not use it for advertising. The Service sets only the cookies needed to keep you signed in; it does not use analytics or advertising cookies, and error reporting is configured without session recording.

3. Service providers

We use the following providers to operate parts of the Service. The providers used for your engagement depend on which features and integrations are enabled:

  • Supabase: database, file storage and sign-in (including sign-in emails).
  • Railway: hosting for our application programming interface, background workers and the scientific co-pilot service.
  • Vercel: hosting for the workbench, client portal and owner console websites.
  • Sentry: error monitoring. Reports are filtered before they are sent and are configured not to include default personal data or session recordings.
  • Shopify: checkout and order status for validation engagement payments.
  • Intuit QuickBooks Online: invoice and payment status for Lab Build engagements (see section 4).
  • DocuSign: electronic signature, where an agreement is sent for signature through DocuSign rather than signed in the portal.
  • ClickUp: our internal project tracking. When an engagement is linked, details such as your organization name, project status, assigned scientist and order references are shared with our ClickUp workspace.
  • Microsoft 365 (Microsoft Graph): our business calendar and email for scheduling meetings and sending engagement notices when those features are enabled.
  • AI model providers (Anthropic, OpenAI and Google Gemini): power the scientific co-pilot that assists our laboratory staff. Under an approved evidence-sharing policy, requests can include laboratory evidence, measurement values and scientist-entered text. Some request types replace evidence with reference identifiers, but this masking does not apply to every request. A failed request may be retried with another configured provider from this list. Co-pilot output never approves a result or releases a report on its own.

We may also disclose information when required by law, or to protect the rights and safety of our clients, our staff or the Service.

4. QuickBooks integration

When enabled, the “MarinaBioLab qPCR Portal” integration connects to the QuickBooks Online company authorized by a MarinaBioLab owner. It uses the com.intuit.quickbooks.accounting permission in a read-only way: it reads company information and preferences, invoices and the payments applied to them, so that the portal can show whether a Lab Build invoice has been paid. It does not create, change, send or delete QuickBooks financial records. The connection is made by a MarinaBioLab owner and can be disconnected at any time from our owner console or from QuickBooks. Disconnecting disables further synchronization while keeping the payment history already recorded. QuickBooks access and refresh tokens are encrypted with AES-256-GCM before they are stored and are never shown in the Service or sent to your browser.

5. Security

Our public websites and APIs use HTTPS (TLS), and our websites require it through HTTP Strict Transport Security. Data in our database is separated by workspace with row-level security, so one client organization cannot read another’s records. Integration credentials are held only on our servers, and OAuth tokens are encrypted at rest. Access to the owner console is limited to MarinaBioLab owners. No system is perfectly secure; if we learn of a breach affecting your information we will notify you as the law requires.

6. Retention and deletion

We keep engagement records, laboratory data, reports, signatures and the audit trail for as long as needed to provide the Service, to support the validations we performed, and to meet our legal, accounting and quality obligations. Signature and audit records are append-only and are not altered after they are written. To ask for a copy of your information, a correction, or deletion of information we are not required to keep, email accounting@marinabiolab.com. We will confirm your request and respond within 30 days.

7. Children

The Service is for laboratory professionals and business clients. It is not directed to children under 16, and we do not knowingly collect their information.

8. Changes

We will post any change to this policy on this page with a new effective date, and tell active clients about material changes before they apply.

9. Contact

Marinabiolab LLC, 3009 Quail Run Dr, Round Rock, TX 78681 · accounting@marinabiolab.com · www.marinabiolab.com. See also our Terms of Service.

© 2026 Marinabiolab LLC · 3009 Quail Run Dr, Round Rock, TX 78681
Terms of ServicePrivacy Policyaccounting@marinabiolab.com