Skip to content
uTuTransplant
  • For Recipients
  • For Donors
  • Navigator Services
  • Travel & Lodging
  • Learn
  • Join free
  • Log in
  • Navigator
Log in Start matching Join free Navigator
Legal

uTransplant Privacy Policy

Effective date: March 30, 2026
Last updated: August 19, 2026

This Privacy Policy explains how Bridge Clinical Care PLLC, which operates the uTransplant service and utransplant.com (“uTransplant,” “we,” “us,” or “our”), collects, uses, discloses, and retains personal information when you use utransplant.com, our private matching platform, accounts, messaging features, Navigator Services, educational resources, travel-assistance requests, partner inquiry forms, and related services (collectively, the “Platform”).

Because the Platform handles transplant-related information, please also read our separate Consumer Health Data Privacy Policy. For personal information that is Consumer Health Data, that health-specific policy controls over an inconsistent general disclosure in this Policy. This Policy alone is not consent or authorization to collect, use, or share Consumer Health Data where separate consent or authorization is required.

This Privacy Policy does not apply to a transplant center, lodging provider, airline, payment processor, care-portal provider, or other third party acting under its own privacy policy. It also is not a HIPAA Notice of Privacy Practices. Section 12 explains the HIPAA boundary.

1. Who controls your information

For the direct-to-consumer Platform, the controller or business responsible for the personal information described here is:

Bridge Clinical Care PLLC
Operator of uTransplant and utransplant.com
4513 Lincoln Ave, Suite 203C
Lisle, IL 60532
United States
privacy@utransplant.com

Unless a Navigator Agreement, care-portal notice, or HIPAA Notice of Privacy Practices presented at or before the relevant collection expressly names a different legal controller or covered provider, Bridge Clinical Care PLLC is the controller for the Navigator and Platform information described in this Policy. If another legal entity controls or provides a specific service, the service-specific document must identify that entity and its contact information, explain the respective roles and data flow, and govern that service to the extent of a direct conflict. An unnamed vendor, contractor, or support provider does not become a separate controller merely by supporting the service.

2. Our core privacy commitments

  • Recipient and donor profiles are private; they are not public pages, searchable directories, or indexed profiles.
  • We disclose profile information to a potential match only in the stages described in Section 6.
  • We do not sell personal information or consumer health data.
  • We do not share personal information for cross-context behavioral advertising and do not use transplant-related information for targeted advertising.
  • Under the current sponsorship model, we do not give sponsors patient, donor, or Navigator identities, contact details, profiles, messages, service records, or Consumer Health Data for the sponsor’s own marketing or other independent purpose.
  • We do not use information to decide transplant eligibility, medical suitability, waitlist priority, employment, insurance, housing, or credit.
  • We collect and retain only information reasonably related to the purposes described in this Policy and our Consumer Health Data Privacy Policy.

3. Personal information we collect

The information we collect depends on the services you use and what you choose to provide.

3.1 Identity, contact, and account information

This may include:

  • full name, email address, telephone number, state, and other contact information;
  • account role, username or account identifier, credentials, authentication records, and password-reset requests;
  • whether an account is for you or another adult;
  • caregiver, helper, or authorized-representative name and relationship; and
  • identity, authority, or age-verification information when reasonably needed for safety or legal compliance, including a government-identification image or signed authorization document only when we specifically request it through a time-limited secure verification process.

3.2 Profile and transplant-related information

This may include:

  • whether a profile concerns a recipient or potential living donor;
  • for a private matching profile, whether a kidney or liver is needed or offered, self-reported ABO blood type, and relationship to an intended recipient;
  • for Navigator Services, the transplant type, transplant center, evaluation or waitlist status, stage in the process, approximate timeline, willingness to travel, and other information you choose to provide;
  • state or general location;
  • personal story, donation intent, preferences, and other profile content;
  • potential-match results, opt-in decisions, connection status, blocks, reports, and identity-reveal choices; and
  • health, treatment, genetic, tissue-typing, disability, or other sensitive information you choose to provide in messages, intake, documents, or a Navigator engagement.

Much of this information is consumer health data. Our separate Consumer Health Data Privacy Policy describes it in more detail.

3.3 Messages, support, and service content

This may include:

  • on-platform messages and associated sender, recipient, delivery, and timing information;
  • emails, text-message preferences, support requests, safety reports, complaints, and survey responses;
  • Navigator intake information, session communications, notes, uploaded documents, written summaries, scheduling information, and e-signature records, to the extent we or our service providers receive them; and
  • consents, authorizations, Terms acceptance, disclosure choices, and communication preferences.

Do not use ordinary email or text messaging to send medical records, government identifiers, payment-card data, or other highly sensitive information. Use the secure channel we identify for that purpose.

3.4 Orders, subscriptions, and payment information

This may include:

  • selected plan or package, price, purchase and renewal dates, cancellation status, refunds, credits, and transaction identifiers;
  • billing name, address, payment method type, last four digits, and payment status when supplied by the processor; and
  • fraud, dispute, and chargeback information.

Stripe or another payment provider identified at checkout collects and processes complete payment-card details. Depending on the function and governing contract, a payment provider may process information for uTransplant and may process some information independently for fraud prevention, legal compliance, or other purposes described in its own privacy notice. uTransplant does not receive complete card numbers or security codes.

3.5 Travel, lodging, and partner inquiry information

Travel requests may include destination or transplant center, approximate dates, number of travelers, budget range, accessibility or lodging needs, and free-text notes. Partner inquiries may include organization name, contact person, business email, organization type, and proposed collaboration.

Free-text fields are not intended for unnecessary medical details. Provide only what is reasonably needed for the request.

3.6 Device, usage, and security information

When you use the Platform, we and our service providers may automatically collect:

  • IP address and approximate location derived from it;
  • browser, device, operating system, language, and screen information;
  • pages viewed, referring and exit pages, links selected, timestamps, session activity, and feature interactions;
  • authentication, error, diagnostic, performance, and security logs; and
  • cookie, session, and similar identifiers.

We do not use precise geofencing around healthcare facilities to identify or target people seeking or receiving healthcare services.

3.7 Information we do not intentionally collect

The private matching form does not require Social Security numbers, complete financial-account numbers, government identification numbers, biometric identifiers, or precise GPS location. Do not submit these unless we specifically request them through a secure process and explain why they are needed.

4. Sources of information

We may obtain personal information from:

  • you, including through forms, accounts, messages, payments, requests, and Navigator interactions;
  • a matching invitation you send or receive, so another adult can create their own matching account (kidney and liver matching accounts are not created by a helper login);
  • a caregiver, family member, helper, or authorized representative acting for you on Navigator or other non-matching requests;
  • another Platform user, such as a message, safety report, match choice, or information concerning a mutual connection;
  • our RNs and personnel, when they create service, scheduling, safety, or professional records;
  • a transplant center, clinician, care portal, or other organization, but only when you direct or authorize the exchange or another lawful basis applies;
  • payment, authentication, hosting, communications, e-signature, scheduling, care-portal, support, security, and other service providers;
  • travel, lodging, nonprofit, or partner organizations when needed to respond to a request you made; and
  • devices and Platform activity, through server logs, cookies, and similar technologies.

If another person provides information about you, you may contact us to access, correct, or delete it, subject to applicable exceptions.

5. How we use personal information

We may use personal information to:

  1. Provide the services you request. Create and maintain accounts; operate private kidney- and liver-matching profiles; compare the selected kidney-or-liver need or offer with self-reported ABO blood type for a preliminary private-matching screen; display potential matches; enable staged disclosures and messaging; provide Navigator Services; respond to travel and partner requests; and deliver educational content.
  2. Process orders and subscriptions. Check service availability, create checkout sessions, verify payment status, administer renewals, provide receipts, handle cancellations and refunds, and maintain transaction records.
  3. Communicate with you. Send account, match, message, scheduling, billing, support, safety, legal, and policy notices; respond to requests; and send reminders where permitted by law and your communication choices.
  4. Protect the Platform and its users. Authenticate users, prevent unauthorized access, detect fraud and organ-commerce activity, enforce staged disclosure, investigate safety reports, moderate misuse, and maintain audit and security logs.
  5. Comply with law and professional obligations. Maintain consent and contract records, respond to valid legal process, satisfy tax and accounting requirements, investigate incidents, make required notices, and meet applicable nursing or recordkeeping duties.
  6. Maintain and improve the Platform. Troubleshoot, measure performance, understand feature use, test changes, and improve accessibility, reliability, and user experience. We use deidentified or aggregated information for these purposes when reasonably feasible.
  7. Manage the business. Audit operations, obtain professional advice, pursue or defend legal claims, evaluate a financing or corporate transaction, and maintain business continuity.

We do not make solely automated decisions that determine medical suitability, donor eligibility, transplant priority, insurance, employment, housing, credit, or other legal or similarly significant effects.

If we want to use personal information for a materially different purpose, we will provide additional notice and obtain consent or authorization where required.

6. How private matching disclosures work

Profiles are accessible to authorized uTransplant personnel and contracted service providers as needed to operate and protect the service, but they are not public or searchable.

Private matching is limited to living-kidney and living-liver profiles. uTransplant does not offer private matching for bone marrow or blood stem cells, heart, lung, pancreas, deceased-donor organs, or other organs or tissues. Navigator Services may address other transplant types, but Navigator Services do not provide donor matching.

For kidney and liver private matching, the current disclosure stages are:

  1. Potential match: after any legally required Consumer Health Data sharing consent has been obtained, the selected organ—kidney or liver—and self-reported ABO blood type may be visible to another user identified as a potential match before either person mutually opts in to connect.
  2. Mutual opt-in: story and general location may become visible only after both people separately choose to connect.
  3. Identity reveal: real name, direct contact information, and other identifying details remain private unless and until the individual affirmatively chooses to reveal them.

This is only a preliminary informational screen. It is not HLA or tissue typing, crossmatching, medical-suitability review, donor or recipient approval, or a clinical decision. All medical evaluation and compatibility testing occur through the transplant program.

The interface will identify the information to be disclosed before an identity-reveal action. A transplant center may independently verify and use identities for clinical evaluation even when the donor and recipient choose not to know each other’s identities.

Once you reveal information to another user, that person may copy, save, or disclose it outside the Platform. We prohibit misuse, but we cannot guarantee another person’s conduct or retrieve information from their devices.

7. How we disclose personal information

We may disclose personal information as follows.

7.1 Service providers and contractors

We use vendors and contractors for hosting, databases, authentication, payment processing, communications, scheduling, care portals, e-signatures, customer support, security, legal compliance, and other operational services. A provider is treated as our processor or service provider only for processing it performs on our documented instructions under a binding contract that satisfies applicable law. Before permitting a provider to process Consumer Health Data on our behalf, we require the processing instructions, purpose limitations, confidentiality, security, rights-assistance, deletion, and other terms required by applicable law. For processing in which a provider determines its own purposes or means, the provider acts independently and its own privacy notice applies.

7.2 Matched users

We disclose information to a potential match only in the stages described in Section 6 and according to your choices. Users are prohibited from using match information for unrelated purposes.

7.3 RNs and professional-service personnel

Information needed for a Navigator engagement may be disclosed to the assigned licensed RN, authorized coverage personnel, and service providers supporting the engagement. A separate Navigator Agreement, care-portal notice, or HIPAA notice may provide additional terms.

7.4 Payment processors

We disclose the minimum purchase, account, contact, and transaction information reasonably necessary to Stripe or another payment provider to complete payments, manage recurring billing, prevent fraud, comply with law, and issue refunds. A payment provider may act as our processor or service provider for some functions and independently for other functions; its own privacy notice governs its independent processing. The payment provider, not uTransplant, receives the complete card number and security code.

7.5 Transplant centers and other organizations at your direction

We may disclose information to a transplant center, clinician, organ procurement organization, travel or lodging provider, nonprofit resource, or other organization when you request or authorize the disclosure or when it is necessary to complete a service you requested. We will not send Navigator-session details to a transplant center, employer, or insurer for their own purposes without your direction, consent, authorization, or another lawful basis.

7.6 Safety, legal, and compliance disclosures

We may disclose information when we reasonably believe disclosure is necessary to comply with law or valid legal process; protect rights, safety, or security; investigate fraud, organ commerce, threats, coercion, abuse, or a security incident; enforce agreements; or establish, exercise, or defend legal claims. Where legally permitted, we will consider the sensitivity of the information and disclose only what is reasonably necessary.

7.7 Corporate transactions

Personal information other than Consumer Health Data may be disclosed under appropriate confidentiality safeguards in connection with a financing, audit, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction. Consumer Health Data will be disclosed in transaction planning or diligence only where the disclosure qualifies for an applicable legal exception or the recipient is acting in a legally compliant processor or professional-adviser role; otherwise, we will first obtain any separate sharing consent or authorization required by law. A financing or proposed transaction does not by itself authorize Consumer Health Data disclosure. Where required, we will provide notice and obtain consent before a successor uses Consumer Health Data for a materially different purpose.

7.8 Deidentified or aggregated information

We may disclose information that has been reasonably deidentified or aggregated so that it cannot reasonably be linked to an individual. We publicly commit to maintain deidentified information in deidentified form and not attempt to reidentify it, except solely, under controlled conditions and where law permits, to test whether the deidentification method is effective.

8. What we do not sell or use for advertising

We do not sell personal information or consumer health data for money or other valuable consideration. We do not share personal information for cross-context behavioral advertising. Under the current sponsorship model, we do not allow sponsors to receive or use patient, donor, or Navigator identities, contact details, profiles, messages, service records, or Consumer Health Data for their own marketing or another independent purpose. We will not introduce a different sponsor-data model without separate legal review, updated notices, legally sufficient opt-in consent or authorization where required, and all other applicable safeguards before it begins.

We do not use transplant-related information to create targeted-advertising audiences.

9. Cookies, analytics, Global Privacy Control, and Do Not Track

The Platform uses cookies and similar technologies that are reasonably necessary for authentication, session continuity, security, fraud prevention, payment flow, load management, preferences, and basic operation. We do not currently use nonessential advertising or behavioral-analytics cookies. If we introduce a nonessential cookie or similar technology that requires consent, we will provide the required choice before it activates.

You can control cookies through browser settings, but blocking essential cookies may prevent login, checkout, messaging, or other functions. We do not currently use cookies to sell personal information or to process personal information for cross-context behavioral advertising.

Some browsers send legacy Do Not Track signals. Because no uniform industry standard governs those signals, the Platform does not respond to them. We do not currently sell personal information or process it for targeted advertising; accordingly, no such processing is active for a Global Privacy Control signal to disable. Before beginning any activity subject to a legally recognized universal opt-out signal, we will implement and test controls to honor supported signals, including Global Privacy Control, as required by law.

We do not knowingly permit third parties to collect personal information through the Platform over time and across unrelated websites for their own targeted-advertising purposes.

10. Communications choices

We may send account, security, billing, match, message, scheduling, service, and legal notices that are necessary to operate an active account or engagement.

We send marketing emails only as permitted by law. You may unsubscribe using the link in a marketing email or by contacting hello@utransplant.com. We will still send essential nonmarketing communications.

If we offer text messages or calls, we will request the consent required for the specific category and technology at the point of collection. Providing a telephone number does not by itself authorize marketing texts. Message and data rates may apply. You can reply STOP to opt out of texts and HELP for help, or contact us. We will honor legally recognized revocation methods within the time required by law.

We may send an abandoned-enrollment reminder only where law permits and, for regulated calls or text messages, only after obtaining the required consent. Marketing consent is not a condition of purchase.

11. Retention and deletion

We retain each category only for as long as reasonably necessary for the disclosed purpose, including:

  • while an account, paid matching period, connection, request, or Navigator engagement remains active;
  • for the time needed to complete staged disclosures, messaging, support, cancellation, refunds, or a user-requested referral;
  • for applicable nursing, professional, contract, tax, accounting, automatic-renewal, e-signature, fraud-prevention, security, and legal recordkeeping periods;
  • for applicable limitation periods and to establish, exercise, or defend claims; and
  • for backup roll-off, incident investigation, and continuity, subject to applicable deletion deadlines.

Retention differs by record type because profile content, messages, professional records, transaction evidence, consent logs, safety records, and backups serve different purposes and may be subject to different legal periods. We determine retention using those purposes, applicable legal and professional requirements, limitation periods, security needs, user choices, and backup cycles. When information is no longer needed under those criteria and applicable law, we delete, deidentify, or securely dispose of it.

Government-identification images submitted through our privacy-request verification channel are used only to authenticate identity or authority, protect the request process, prevent fraud, and comply with law. Unless a longer period is required by law or reasonably necessary for a documented fraud, security, dispute, or legal-hold purpose, we delete an identification image from active systems as soon as verification is complete and no later than 30 days after verification succeeds, fails, or is abandoned. For an exception, we document the reason, limit access and use to that reason, set a review and deletion date, and retain only the minimum necessary. We may retain a limited audit record of the verification method, result, and date for the ordinary compliance and limitations period without retaining the image, but only to the extent applicable law permits; if a valid deletion right applies and no exception supports retention, we delete or deidentify the limited record. This limited record does not include the document image, identification number, face template, physical-description fields, or a copy of an authority document.

Signed authorizations, powers of attorney, and other authority documents follow a separately justified schedule because they may be needed to establish who was permitted to act. We delete the complete authority document from active systems as soon as it is no longer needed and no later than 30 days after the request is closed, unless a longer period is required by law or reasonably necessary for a documented fraud, security, dispute, or legal-hold purpose. For an exception, we document the reason, limit access and use to that reason, set a review and deletion date, and retain only the minimum necessary. We may retain only the minimum audit record reasonably necessary to document the authority determination for the ordinary compliance and limitations period without retaining the complete document, but only to the extent applicable law permits; if a valid deletion right applies and no exception supports retention, we delete or deidentify the limited record. That limited record does not include the document image, identification number, face template, physical-description fields, or a copy of the authority document. Residual encrypted backup copies are isolated from ordinary use and expire through the applicable backup rotation and statutory deletion schedule.

Deletion may not be immediate where information remains in encrypted backups, a recipient’s copy of a message, a transaction or consent record, a safety record, or a professional record we must retain. We will restrict use of retained information to the reason for retention and will propagate deletion to processors and other recipients where applicable law requires it. Our Consumer Health Data Privacy Policy describes additional deletion rules, including backup deadlines that may apply to consumer health data.

12. HIPAA and professional-service records

Health-related information is not automatically protected by the Health Insurance Portability and Accountability Act (HIPAA) merely because it is sensitive or stored in a health-related website.

This Privacy Policy is not a HIPAA Notice of Privacy Practices. Whether HIPAA applies depends on facts such as whether a provider conducts HIPAA-covered electronic transactions or whether uTransplant handles protected health information for a HIPAA-covered entity as a business associate.

If uTransplant operates a Navigator service as a HIPAA-covered provider, uTransplant will issue the Notice of Privacy Practices required for that covered service. If uTransplant acts as a business associate for a HIPAA-covered entity, it will process protected health information under its agreement with that covered entity and the covered entity’s Notice of Privacy Practices; a business-associate agreement is not a consumer notice. An independent care-portal or healthcare provider may provide its own privacy notice. If a HIPAA-required document conflicts with this Policy, the HIPAA-required document controls for the protected health information within its scope.

Even where HIPAA does not apply, consumer health privacy, professional confidentiality, security, breach-notification, and other laws may apply. We handle transplant-related information under this Policy and our Consumer Health Data Privacy Policy and do not describe the Platform as “HIPAA certified.”

13. Security and incident response

We use reasonable administrative, technical, and physical safeguards proportionate to the sensitivity of the information and applicable law. No policy or safeguard can guarantee perfect security.

No system is perfectly secure. You are responsible for protecting credentials, using a unique password, securing your device and email account, and reporting suspected unauthorized access to trust@utransplant.com.

If a security incident affects personal information, we will investigate and provide notice to affected individuals, regulators, or others when and as required by applicable law, including the FTC Health Breach Notification Rule if it applies.

14. Your privacy rights

Depending on your residence, the information, and the law that applies to uTransplant, you may have the right to:

  • confirm whether we process your information and access it;
  • correct inaccurate information;
  • delete information;
  • obtain a portable copy of information you provided;
  • obtain information about third parties or affiliates that received certain data;
  • withdraw consent or request that certain processing stop;
  • opt out of sale, targeted advertising, or certain profiling;
  • limit certain uses or disclosures of sensitive information; and
  • appeal a denial of a privacy request.

We provide access, correction, deletion, and export controls through the account dashboard where available. You may also use our secure Privacy and Consumer Health Data Request Form or email privacy@utransplant.com with the subject “Privacy Request” to initiate a request. Do not send medical records or identity documents through ordinary email. Describe the right you want to exercise and the account or service involved.

We will verify a request using information reasonably related to the account and the sensitivity of the request. We will not ask for more information than reasonably necessary. If we cannot verify a request, we will explain the result where permitted. An authorized agent may submit a request, but we may require proof of authority and direct confirmation from the individual unless law provides otherwise.

We will respond within the time required by applicable law. If we deny a request, you may appeal by emailing privacy@utransplant.com with the subject “Privacy Appeal” and explaining why the decision should be reconsidered. We will not discriminate against you for exercising a privacy right, but deleting information needed to provide a requested service may require us to close or limit that service.

Rights are subject to legal exceptions. For example, we may retain information needed to complete a transaction, provide a requested service, maintain security, prevent fraud, preserve another person’s rights, comply with law or professional duties, or establish or defend legal claims.

California residents

California law requires commercial websites that collect personally identifiable information to disclose collection categories, third-party categories, change processes, effective date, and treatment of Do Not Track signals; those disclosures appear throughout this Policy. If the California Consumer Privacy Act applies to uTransplant, California residents may also exercise the applicable access, correction, deletion, portability, sale/share opt-out, and sensitive-information rights through the request method above. We do not sell or share personal information for cross-context behavioral advertising.

Other U.S. state rights

Residents of states with applicable comprehensive or consumer-health privacy laws may exercise the rights granted by those laws through the same request and appeal process. Our Consumer Health Data Privacy Policy provides the additional Washington, Nevada, Connecticut, and other consumer-health disclosures.

15. Information about other adults

If you seek to create a profile or request a service for another adult, you must have authority to provide the minimum invitation or authority-verification information and must give them access to this Privacy Policy and the Consumer Health Data Privacy Policy. We may first collect only the minimum information needed to send an invitation or verify your authority. We will not collect other health information about that adult, activate matching, or share their health information until we obtain the adult’s direct confirmation and required consent or verify your legal authority to act for them.

Do not submit an unwilling person’s information. A person whose information was submitted by someone else may contact privacy@utransplant.com to request access, correction, or deletion, subject to verification and legal exceptions.

16. Adults only

The Platform is for adults age 18 or older. We do not knowingly collect personal information through the Platform from anyone under 18 or create transplant-matching profiles for minors. Age confirmation must occur before health-data collection. If we learn that a minor’s information was submitted in violation of this Policy, we will take appropriate steps to delete or restrict it and may close the associated account. Contact privacy@utransplant.com if you believe a minor’s information has been submitted.

17. Changes to this Policy

We may update this Policy prospectively as our practices or the law change. The effective date at the top is the original effective date of this Policy; the Last updated date identifies this text. For a material change, we will provide notice by email, account message, or a prominent Platform notice before the change takes effect and will obtain consent or authorization where required. A revision does not become retroactive merely because the original effective date remains unchanged.

We will not materially expand the collection, sharing, or sale of consumer health data without the notice and consent or authorization required by applicable law. Historical versions will be retained for compliance purposes.

18. Contact us

Privacy questions and requests: privacy@utransplant.com
Privacy appeals: privacy@utransplant.com, subject “Privacy Appeal”
Security and safety reports: trust@utransplant.com

Bridge Clinical Care PLLC
Attn: uTransplant Privacy
4513 Lincoln Ave, Suite 203C
Lisle, IL 60532
United States

uTuTransplant

Independent RN Navigator services — connecting transplant patients, living donors, and the transplant centers that treat them.

4513 Lincoln Ave, Suite 203C
Lisle, IL 60532 Appointments are scheduled.

Platform

  • For Recipients
  • For Donors
  • Navigator Services
  • Travel & Lodging
  • Log in

Resources

  • Learn Hub
  • NLDAC Reimbursement Guide
  • Paired Exchange Explained
  • Choosing a Center

Company

  • Partner With Us
  • Trust & Safety
  • hello@utransplant.com

Legal

  • Privacy Policy
  • Consumer Health Data Privacy Policy
  • Privacy Request
  • Terms of Service
© uTransplant. Not a transplant center. Educational and coordination services only. uTransplant is operated by Bridge Clinical Care PLLC.