The short version
- We collect what you send us. Your name, your email, what you need, and whatever else you share while we work together.
- We do not sell it, rent it, or trade it. There is no advertising here, no analytics, and no tracking on this website.
- AI systems help run this studio, so your emails and project details pass through them. That gets its own plain section below, because most policies hide it.
- Your contracts, invoices and receipts sit behind a passcode and are kept out of search engines.
- Want a copy of what we hold, or want it gone? Email hello@morastudios.co and ask.
Who we are
Mora Studios is the brand name of Mora Ventures LLC, a limited liability company registered in Georgia. Michelle Mora owns and runs it. We design and build custom websites, brand systems, dashboards, and automation for small businesses and nonprofits, almost all of them in the United States.
This policy covers morastudios.co and the client portal at clients.morastudios.co, along with the email and project work that happens around them.
When we build a website for you, that website is yours, and this policy does not cover it. Your own site needs its own policy, and we will tell you so.
What we collect
When you send an inquiry
The form at clients.morastudios.co asks for four things, and that is the whole list:
- Your name
- Your email address
- Which of the listed needs you tick
- Anything you type in the box that says "in your own words"
The submission is handled by Netlify Forms. Netlify stores it and adds four things of its own to every submission: the IP address it came from, your browser's user agent, the page that referred you, and the time it arrived. We do not ask for those, and we do not use them for anything, but they are collected, so they belong in this list.
We are then emailed a copy. In practice that email is where an inquiry actually lives until somebody answers it.
When you email us
Everything in the message. Your address, your name as your mail client sends it, whatever you write, and any attachments. Our mail runs through Resend and Zoho. Replies you send to us are stored the same way.
When you book a call
Booking runs on Cal.com, which takes your name, your email, your time zone, and whatever you write in the notes field so we know what the call is about.
When you become a client
- Contact details for everyone we correspond with on your project, including people you copy in yourself. If your board or your finance address is on the thread, they are on our record.
- Project information. What you told us about your business, your answers to the discovery and onboarding questions, meeting notes, what we agreed, and the state of every deliverable.
- Documents. Your proposal, your agreement, your invoices, and your receipts.
- Payment records. The amount, the date it arrived, the method, and the invoice number it matched.
- A passcode for your portal, which we set and give to you.
When you sign a contract
Signing runs on DocuSeal. It records your name, your email, the business address you type in, and your signature. It also keeps a certificate of signature, which is the audit trail that makes the signature hold up: your IP address, your browser, your time zone, and a timestamp for each step from sent through opened to signed. That is how an electronic signature is evidenced, and it is attached to your executed copy, which comes back to your portal.
When you just visit morastudios.co
Nothing that identifies you, from us. There is no analytics on this site, no advertising pixel, no cookie, and nothing stored in your browser. We genuinely do not know who visited.
Three things on the page do reach other companies' servers, because your browser fetches them directly:
- Google Fonts. The typefaces load from Google, so Google receives your IP address, your browser details, and the page you are on. Google says the Fonts service sets no cookies and is not used for advertising or for building profiles.
- Live client sites. Several case studies show a real client website running inside a frame. Those frames load from the client's own site.
- One screenshot. A single case study image is generated by Microlink, so that image request goes to Microlink's servers.
Netlify hosts the site and keeps its own server logs, which include visitor IP addresses. We do not read them.
What we never collect
We hold no card numbers and no bank details. Payment happens on Zelle or PayPal, on their systems, not ours. What reaches us is that money arrived, how much, and which invoice it was for.
We do not collect social security numbers, government ID numbers, health information, or location data. We do not build profiles, run behavioural advertising, or buy lists.
And the flat one: we do not sell, rent, or trade your information to anyone, for any price. There is no exception to that sentence.
Where it goes
We are a small studio, so we do not run our own servers. These are the companies that hold parts of your information on our behalf. Each has its own privacy policy, and each one below is a service we actually use, not a list borrowed from somewhere.
Netlify
Hosts this site and the client portal, stores every inquiry form submission, and keeps the server logs.
Resend
Sends and receives our mail, which means it holds our correspondence with you.
Zoho
Michelle's own mailbox and the calendar that sends your meeting invitations.
Cal.com
Runs the discovery call booking page and holds what you enter there.
DocuSeal
Handles contract signing and keeps the signed document and its audit trail.
Zelle and PayPal
Take the actual payment. We see the record of it, never your card or account details.
Anthropic
Runs the Claude models our internal agents are built on. See the next section.
Firecrawl
Reads public web pages when we research a market or a competitor. We do not send client information to it.
Google Fonts
Serves the typefaces on this site directly to your browser.
Microlink
Generates one screenshot used in one case study card.
Beyond that, we share information only in two situations: when you ask us to, and when the law requires it. If we were ever ordered to hand something over, we would tell you unless we were legally barred from doing so.
If Mora Ventures LLC were ever sold or merged, client records would move with it, and we would tell affected clients before that happened.
AI, plainly
This studio is run with AI agents. That is not a marketing line, it is a description of how the work gets done, and it changes what happens to your information, so here it is in full.
Software agents read our inbox, file what arrives, keep the project record up to date, draft replies, draft proposals, and prepare invoices. They are built on Anthropic's Claude models.
So yes: your emails, your name, your project details, and the contents of your portal are processed by AI systems. If that is a problem for you, we would rather you knew before you hired us than after.
Here is what that does and does not mean.
- Nothing goes to you without Michelle approving it. Every message to a client, every invoice, every contract, needs a human approval before it can send. That is enforced in code that checks before the send happens, not in an instruction we hope the software follows.
- Some things an agent is never allowed to do at all. It cannot execute a contract, make a legal or tax determination, move money, or delete client data. No setting turns that on.
- Your information is not training data for us. We do not build models on your business, and we do not pool your data with another client's.
- AI output is checked before you see it. Anything drafted by an agent is read by a person first. When AI-assisted work forms part of what we deliver to you, our agreement says plainly that you review and approve it before you rely on it.
- You can ask. If you would rather your account were handled with less of this in the loop, say so and we will tell you honestly what it changes about our speed and our price.
On Anthropic's side: their commercial terms say they do not train models on customer content, and their standard retention for commercial use is 30 days. We are relying on their published terms the same as any other customer, and their policy is theirs to change. If it changes in a way that matters to you, we will update this page.
Your documents
Client confidentiality is not a courtesy here, it is in the agreement you sign, and it runs both directions. We keep your non-public information confidential, and you keep ours.
In practice that means:
- Your contracts, invoices, receipts and proposals are served only to a browser holding a valid session for your portal. A session for another client's portal does not open your documents.
- Those pages tell search engines not to index them, and the portal's robots file asks every crawler to stay out of the whole site.
- They are marked so that no cache, ours or anyone else's, is allowed to keep a copy.
Your work is your work. We reference clients publicly, in case studies and testimonials, only where we have agreed that with them.
How long we keep it
Honest answer: we do not have a formal retention schedule. Rather than print one we do not follow, here is what actually happens.
- Inquiries stay in Netlify's form records and in our mailbox. We do not currently delete them on a timer, and an unanswered one deliberately keeps resurfacing until somebody deals with it.
- Email is kept indefinitely, because a thread from eight months ago is often the only record of what was agreed.
- Client project records, contracts, invoices, receipts and payment records are kept indefinitely and on purpose. Some of that we are required to keep for tax, and some of it we keep because an agreement is still live or its terms outlast the project.
- Portal sessions expire in 12 hours and sign-in links in 7 days, automatically.
Some of it ages out on its own, whatever we do. Our email provider keeps message and log data for about 30 days on the plan we are on, and Anthropic's standard retention for commercial use is also 30 days. Netlify does not expire form submissions on a timer at all: deleting those is our job, and we say so here because it means an old inquiry sits there until someone removes it.
If a formal schedule ever exists, it will be written on this page and not somewhere you cannot see it. Meanwhile, if you want something deleted, the next section is how.
Getting a copy, or asking us to delete it
Email hello@morastudios.co and say what you want. You do not need to cite a law, prove you live in a particular state, or use any special wording. We aim to reply within five business days.
You can ask us to:
- Tell you what we hold about you
- Send you a copy of it
- Correct anything that is wrong
- Delete it
- Stop emailing you
We may need to confirm you are who you say you are before we hand over a client record, usually by replying on the email address already on the account.
Two honest limits. We cannot delete what has already left. An email you sent us also exists in your sent folder, and a payment record exists at your bank. And some records we have to keep: tax and financial records, and anything covering a live agreement or a legal claim. If we cannot delete something, we will tell you exactly what it is and why, rather than quietly keeping it.
Which privacy laws apply to us
Plenty of policies claim compliance with every regime on earth. That is not useful, and for a studio this size most of it is not true. Here is the real position as of the date at the top of this page.
What does apply
- The FTC Act. A published privacy policy has to be accurate, and failing to follow your own stated practices is treated as a deceptive act. That is the main reason this page describes what we do rather than what sounds good. FTC, privacy and security enforcement
- CAN-SPAM, for any commercial email we send. Accurate sender and subject lines, a real postal address in the message, and unsubscribe requests honoured. FTC, CAN-SPAM compliance guide
- Georgia's breach notification law, O.C.G.A. section 10-1-910 and following. It has no small business exemption. If personal information we hold were exposed, we are required to notify affected people without unreasonable delay, and we would.
What does not apply, and why we are saying so
- Georgia has no comprehensive consumer privacy law. A bill was introduced, but its privacy provisions were removed before the bill was signed in May 2026, so there is nothing in force here to comply with. Georgia SB 111, bill history
- The California CCPA and CPRA do not reach us. They apply to businesses above roughly $26.6 million in annual revenue, or handling 100,000 or more California consumers, or making half their money selling personal information. We are far below all three, and we sell nothing. California Privacy Protection Agency, threshold adjustments
- The other state privacy laws do not reach us either. Virginia, Colorado, Connecticut, Texas and the rest set their thresholds at similar volumes, typically 100,000 consumers. Texas works differently, exempting businesses that meet the federal small business definition, which we do.
- The GDPR does not apply. We have no European establishment, we do not offer our services to people in the EU, and we do not monitor anyone's behaviour there. EDPB guidelines on territorial scope
None of that changes how we treat a request. If you write to us asking for your data or asking us to delete it, we handle it the same way whether or not a statute makes us. The law is our floor, not our standard.
If we grow past any of these thresholds, or a Georgia law passes, this page changes.
Children
Mora Studios sells to businesses and nonprofits. Our site and our services are not directed at children, and we do not knowingly collect information from anyone under 13. If you believe a child has sent us something, email hello@morastudios.co and we will delete it.
Changes to this policy
When this changes, the date at the top of the page changes with it, and the current version always lives at this address.
If a change materially affects how we handle information for people who are already clients, we will email those clients rather than expect them to notice. We will not quietly reduce what we promise here and hope nobody rereads it.
Contact
Mora Ventures LLC
operating as Mora Studios
3276 Buford Dr Ste 104-160
Buford, GA 30519
United States
Anything on this page that is unclear, write and ask. If something here does not match what you have actually seen us do, we want to know that most of all.