Privacy Policy
Introduction
1. Information We Collect
1.1 Information Provided Directly
- Assessment Quiz Responses. When individuals complete the AlloBiome pattern assessment quiz, responses are collected to determine the educational content most relevant to the individual’s selected pattern. Quiz responses include answers related to digestive symptoms, dietary habits, and lifestyle factors. No clinical diagnoses are made from these responses.
- Email Address. Collected during quiz completion, program purchase, or newsletter subscription to deliver educational content, program materials, and communications.
- Name. Collected when voluntarily provided during purchase or account setup.
- Payment Information. Processed securely through Stripe. AlloBiome does not store credit card numbers, CVVs, or full payment credentials on its own servers. Stripe handles all payment processing in compliance with PCI-DSS standards.
Support Communications. Any information provided through email correspondence or contact forms when reaching out for support.
1.2 Information Collected Automatically
1.3 Symptom Diary Entries
2. How We Use Information
AlloBiome uses collected information for the following purposes:
- Program Delivery. To deliver the appropriate educational program content based on quiz results, including weekly email sequences aligned with the three-phase program structure.
- Communication. To send educational content, program updates, The Daily Digest newsletter, and transactional emails such as purchase confirmations and onboarding sequences.
- Payment Processing. To process program purchases securely through Stripe.
- Platform Improvement. To analyze aggregated, anonymized usage data to improve program content, website functionality, and overall user experience.
- Customer Support. To respond to inquiries and provide assistance.
- Legal Compliance. To comply with applicable laws, regulations, and legal processes.
AlloBiome does not use personal information for clinical assessment, medical profiling, or diagnostic purposes. Quiz responses and symptom diary entries are used exclusively to align educational content delivery with the pattern the individual has identified through the assessment.
3. How We Share Information
AlloBiome does not sell, rent, or trade personal information to third parties. Information may be shared only in the following limited circumstances:
- Service Providers. AlloBiome uses trusted third-party service providers to operate its platform. These providers have access to personal information only as necessary to perform their functions and are contractually obligated to protect it. Current service providers include:
Stripe for payment processing (stripe.com/privacy)
Mailchimp for email delivery and program content distribution (mailchimp.com/legal/privacy)
Google for quiz and form hosting, analytics, and data processing (policies.google.com/privacy)
Hostinger/WordPress for website hosting (hostinger.com/privacy)
Meta (Facebook) for advertising measurement and audience targeting through the Meta Pixel, which collects data including pages visited, actions taken, and device information (facebook.com/privacy/policy)
- Legal Requirements. AlloBiome may disclose personal information if required to do so by law, regulation, court order, or other governmental request.
- Business Transfers. In the event of a merger, acquisition, or sale of assets, personal information may be transferred as part of the transaction. Individuals will be notified of any such change.
Aggregated Data. AlloBiome may share aggregated, de-identified data that cannot reasonably be used to identify any individual. This data may be used for research or educational purposes.
4. Cookies and Tracking Technologies
The AlloBiome website uses cookies and similar technologies to ensure functionality and improve user experience. These include:
- Essential Cookies. Required for basic website functionality such as page navigation and secure access.
- Analytics Cookies. Used to understand how visitors interact with the website, including pages visited and traffic sources. This data is collected in aggregate form.
- Marketing Cookies. Used to track the effectiveness of advertising campaigns and to deliver relevant content. AlloBiome uses the Meta Pixel to measure ad performance and build audiences for Meta (Facebook and Instagram) advertising. The Meta Pixel may collect browsing behavior, device identifiers, and interaction data. These cookies may also be placed by other third-party advertising partners. Individuals can manage Meta ad preferences at facebook.com/adpreferences.
Individuals can manage cookie preferences through browser settings. Disabling certain cookies may affect website functionality.
5. Data Retention
AlloBiome retains personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law. Specific retention guidelines include:
- Program and Account Data. Retained for the duration of the individual’s engagement with AlloBiome programs, plus an additional 24 months to support access to purchased content and customer service inquiries.
- Email Subscriber Data. Retained until the individual unsubscribes from communications. Upon unsubscription, data is removed from active mailing lists within 30 days.
- Payment Records. Transaction records are retained as required by applicable tax and financial regulations (typically 7 years).
- Analytics Data. Aggregated analytics data may be retained indefinitely as it cannot be used to identify individuals.
Symptom Diary Data. Retained only while the individual actively uses the tool. Individuals may request deletion at any time.
6. Data Security
AlloBiome takes reasonable administrative, technical, and physical measures to protect personal information from unauthorized access, disclosure, alteration, and destruction. Security measures include:
- Encryption of data in transit using SSL/TLS protocols
- PCI-DSS compliant payment processing through Stripe
- Access controls limiting internal access to personal information to authorized personnel only
- Regular review of security practices and third-party provider compliance
While AlloBiome strives to protect personal information, no method of transmission over the internet or electronic storage is 100% secure. AlloBiome cannot guarantee absolute security but is committed to implementing and maintaining industry-standard protections.
7. Individual Rights
Depending on applicable jurisdiction, individuals may have the following rights regarding their personal information:
- Right to Access. Request a copy of personal information held by AlloBiome.
- Right to Correction. Request correction of inaccurate or incomplete personal information.
- Right to Deletion. Request deletion of personal information, subject to legal and contractual retention requirements.
- Right to Opt Out. Unsubscribe from marketing communications at any time by clicking the unsubscribe link included in every email.
- Right to Data Portability. Request a portable copy of personal data in a commonly used format.
- Right to Restrict Processing. Request that AlloBiome limit how personal information is used.
To exercise any of these rights, individuals may contact AlloBiome at the email address provided in Section 12 of this policy. Requests will be processed within 30 days.
California residents may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected, the right to request deletion, and the right to opt out of the sale of personal information. AlloBiome does not sell personal information as defined under the CCPA. California residents may exercise their rights by contacting AlloBiome at the email address provided in Section 12 of this policy.
8. Children's Privacy
AlloBiome services are not directed at individuals under the age of 18. AlloBiome does not knowingly collect personal information from minors. If AlloBiome becomes aware that personal information has been collected from an individual under 18, that information will be promptly deleted. Parents or guardians who believe their child has submitted personal information to AlloBiome should contact us immediately.
9. Third-Party Links
10. International Users
AlloBiome is operated from the United States. Personal information collected through AlloBiome services may be transferred to and processed in the United States, where data protection laws may differ from those in the individual’s country of residence. By using AlloBiome services, individuals consent to the transfer and processing of their information in the United States.
For individuals in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data protection laws, AlloBiome will process personal information in accordance with applicable legal requirements, including the General Data Protection Regulation (GDPR) where applicable.
For individuals in these jurisdictions, AlloBiome processes personal information under the following legal bases as defined by the GDPR: (a) Contractual Necessity, for processing required to deliver purchased program content, including email delivery and payment processing; (b) Consent, for marketing communications, newsletter subscriptions, and the placement of non-essential cookies, which individuals may withdraw at any time by unsubscribing or adjusting cookie preferences; (c) Legitimate Interest, for website analytics, platform improvement, fraud prevention, and internal administrative purposes, where AlloBiome believes that these interests do not override individual privacy rights.
11. Changes to This Privacy Policy
12. Contact Information
For questions, concerns, or requests related to this Privacy Policy or personal data practices, individuals may contact AlloBiome at:
AlloBiome By NEIMS
New England Institute of Microbiome Science
Email: research@nebiome.com
Website: allobiome.com
Responses to privacy-related inquiries will be provided within 30 days.