Privacy Policy
This privacy policy explains what morneto.com collects, why, who else can see it, and how to ask for a copy or a deletion. In short: the contact form, our server logs, Google Analytics, and, if you pay online, your order and billing details, with card payments handled by Stripe.
What we collect
Last updated: October 2, 2026. This privacy policy covers the website morneto.com and the enquiries we receive through it. It is written in plain English on purpose, and it describes what actually happens on this site today rather than a generic template of everything an agency could do.
The short version. We collect what you type into our contact form, and our servers keep standard security logs. If you pay online, we keep your order and billing details, and Stripe, our payment processor, handles your card or bank details, which we never see or store. This website uses Google Analytics 4, which sets first-party cookies to count visits and see which pages get read. It runs no advertising pixels, remarketing tags or heat maps, and section 3 explains how to refuse the analytics cookies. We do not sell or share your personal information. You can ask us at any time what we hold about you, or ask us to delete it, by writing to support@morneto.com.
1. Who is responsible for your data
Morneto is a web design, SEO and Google Ads studio serving small and medium businesses in New York City and elsewhere in the United States. For the purposes of the EU and UK General Data Protection Regulation (GDPR), Morneto LLC is the controller of the personal data described in this privacy policy.
- Contact for all privacy matters: support@morneto.com
- Postal address: 1178 Broadway, 3rd Floor, Suite 663, New York, NY 10001.
- Data protection officer: we are not required to appoint one and we have not. Privacy requests are handled by the founder personally.
2. What we collect, why, and for how long
| What | Why we have it | Legal basis (GDPR) | How long we keep it |
|---|---|---|---|
| Name, email address, phone number (if you add one), company name, the service you selected and your message | To answer your enquiry, prepare an audit or a proposal, and follow it up | Steps taken at your request before a contract, Art. 6(1)(b); legitimate interest in replying to business enquiries, Art. 6(1)(f) | Up to 24 months after the last contact, then deleted; longer if you become a client |
| Email correspondence with us | To keep a record of what was asked and agreed | Contract, Art. 6(1)(b), and legitimate interest, Art. 6(1)(f) | Up to 24 months, or 7 years where it relates to an invoice |
| WhatsApp messages you send us: your WhatsApp number, profile name and the message | To answer your question and follow it up | Steps taken at your request before a contract, Art. 6(1)(b); legitimate interest in replying to business messages, Art. 6(1)(f) | Up to 24 months after the last contact, then deleted; longer if you become a client |
| Client and project records: contracts, invoices, access notes | To deliver the work and meet tax and accounting duties | Contract, Art. 6(1)(b), and legal obligation, Art. 6(1)(c) | 7 years for financial records; access credentials are deleted at the end of the engagement |
| Orders and payments, when you buy or subscribe on morneto.com: your name, company name, billing address, email address, the phone number and order notes if you add them, what you bought, the amount and currency, the type of payment method, the date and time, the IP address and browser the order came from, and the moment you accepted our terms and which version. If you choose to save a card, we keep only its brand, its last four digits, its expiry date and a reference from Stripe, never the full card number | To take the payment, send your receipt or invoice, run the plan you bought, handle refunds and disputes, and meet our tax and accounting duties | Contract, Art. 6(1)(b), and legal obligation, Art. 6(1)(c) | 7 years after the order, as a financial record; unpaid, failed or canceled orders are deleted after 30 days; a saved card is kept until you remove it or ask us to |
| Visitor analytics: pages viewed, referring source, device type and approximate location, collected by Google Analytics 4 through first-party cookies such as _ga (since 23 August 2026). Tags are loaded through Google Tag Manager. Google Signals is switched on, so where a visitor is signed in to a Google account that allows ads personalization, Google may add age, gender and interest categories in aggregate | To understand how visitors use the site and improve it | Consent where required, otherwise legitimate interest, Art. 6(1)(f) | Event-level data is retained by Google Analytics for 14 months; aggregated statistics persist in reports |
| Server and security logs: IP address, browser user agent, page requested, date and time, referring page | To keep the site online and secure and to investigate abuse or outages | Legitimate interest in the security and availability of the service, Art. 6(1)(f) | Rolling logs held by our host and by Cloudflare for a short period, typically up to 30 days, then overwritten |
| Aggregate search statistics: queries, impressions and clicks from Google Search Console and Bing Webmaster Tools | To understand which pages are found in search | Legitimate interest, Art. 6(1)(f) | Held by Google and Microsoft under their own retention rules; we do not export or store individual-level data |
We do not collect special categories of data such as health, biometric or political information, and we ask you not to send them through the form. We never receive or store your full card number or its security code: those go straight from your browser to Stripe. We do not knowingly collect anything from children; this site is aimed at business owners.
3. Cookies and tracking on this website
This website loads Google Analytics 4 through Google Tag Manager, and Google Analytics sets first-party cookies such as _ga and _ga_SL86V5YJ3E in your browser. They hold a randomly generated number, which lets Google count a returning visitor as one person instead of two. They carry no name, no email address and nothing you typed into the form. Until 23 August 2026 this site ran no analytics at all, and earlier versions of this page said so.
We run no advertising pixels, no remarketing tags, no Meta pixel, and no heat maps or session recording.
How to refuse it. You can block or delete these cookies in your browser settings, install the official Google Analytics opt-out add-on, or read the site in a private window. You can also email support@morneto.com and object to the processing, and we will exclude your visits.
Five other things can store data in your browser or reach it, and they are worth naming.
- Cloudflare security cookies. Cloudflare sits in front of this site as a content delivery network and firewall. If its bot protection challenges a visitor it may set strictly necessary cookies such as
__cf_bmorcf_clearance, which exist only to tell a person from an automated request. They carry no advertising identifier and expire within 30 minutes to a few hours. - The map on our New York area pages. Those pages show our Google Business Profile in an embedded Google map. It loads only when you scroll to it. When it does, your browser connects to Google directly, so Google receives your IP address and browser details and may set its own cookies, under the Google Privacy Policy. We receive nothing from the map.
- The chat button. Every page has a chat button in the bottom corner for WhatsApp and email. It runs on our own site and loads nothing from WhatsApp or Meta until you tap WhatsApp. To remember whether you opened it, it keeps a small note in your browser’s local storage (entries named
chatyWidget_0andactivechatyWidgets). The note holds no name or contact details, and it is not sent to us. Tapping WhatsApp opens WhatsApp with a message ready for you to send, and tapping email opens your own email app. - Caching. LiteSpeed Cache and Cloudflare store copies of our pages so they load quickly. Cached pages are anonymous, and caching does not identify you.
- Paying online. Our cart and checkout pages, and the Stripe pages our Pay online page links to, are the only places that set payment cookies. They are strictly necessary to hold your cart and take a payment safely, and none of them is used for advertising. WooCommerce, the shop software, sets
woocommerce_items_in_cartandwoocommerce_cart_hash, which last until you close your browser, andwp_woocommerce_session_followed by a random code, which remembers your cart for 2 days. Stripe.js, which draws the payment form, sets__stripe_mid(one year) and__stripe_sid(30 minutes) to check that a payment is not fraudulent, and it may run an invisible hCaptcha test for the same reason. On Stripe’s own payment and billing pages, Stripe sets its own cookies under the Stripe Cookie Policy.
When you use the contact form, WPForms includes a short-lived anti-spam token in the page itself. It prevents automated submissions, it is not a tracking cookie, and it is not linked to you.
4. Analytics
We use Google Analytics 4 to see how many people visit, which pages they read, and where they arrived from. We also see aggregate search data through Google Search Console and Bing Webmaster Tools: which search terms showed our pages and how often they were clicked, never who searched.
Google processes that usage data as our processor, including a truncated IP address and a randomly generated identifier, and Google’s own terms apply alongside this policy. You can read them in the Google Privacy Policy. When you send the contact form, the confirmation page also sends Google an event called generate_lead. It records that an enquiry was sent and which page it came from. It does not send Google your name, your email address, or the text of your message.
That same Google Privacy Policy also governs the other Google services we rely on: Google Tag Manager, Google Search Console, and any Google Ads account we manage inside a client’s own account.
5. Who we share information with
We do not sell, rent or trade personal information, and we do not share it for cross-context behavioral advertising. We do rely on a small number of service providers who process data on our instructions under a data processing agreement. When a project needs a specialist, we bring one in as a subcontractor; they see only what their part of the work needs, they work on our instructions, and they are required to keep it confidential.
| Provider | What they do for us | What they can see | Where |
|---|---|---|---|
| Hostinger | Website hosting, email and backups | Everything stored on the site, and every email you send us | EU and US data centers |
| Cloudflare | CDN, DNS, firewall and bot protection | Request metadata: IP address, user agent, URL, timestamp | Global edge network |
| WPForms | The contact form itself | Nothing on their servers: submissions are emailed to us, not stored in a third-party database | Runs on our own site |
| Analytics, Tag Manager, Search Console, the embedded map on our area pages, and Google Ads where we manage a client account | Website usage data tied to a random identifier; aggregate search data; for the map, your IP address and browser details; ad account data that belongs to the client | US and global | |
| Stripe | Card and bank payments, the checkout and billing portal for plans, and fraud checks | Your card or bank details, which go to Stripe and never to us; your name, email address and billing address; the amount and what it is for; and the device and browser signals its fraud checks collect | US and global |
| Trustpilot | Independent reviews | Only what you choose to write there, if you leave a review | EU |
Stripe and payment wallets. Stripe processes payments on our instructions, and it also uses payment and device data for its own fraud prevention and to meet its duties as a regulated payment company, under the Stripe Privacy Policy. If you pay with a wallet offered at checkout, such as Link, Apple Pay, Google Pay or Amazon Pay, that provider also handles your payment under its own privacy policy.
WhatsApp. If you message us on WhatsApp, the chat runs through WhatsApp, which is owned by Meta. WhatsApp handles your number and messages under its own WhatsApp Privacy Policy, not on our instructions, so it is not listed above as one of our service providers.
We may also disclose information where the law requires it, to protect our rights, or if the business is ever transferred to a new owner, in which case you would be told first.
6. International transfers
Morneto works from Europe and serves clients in the United States, so personal data may be processed in both places. Where data leaves the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses, by our providers’ participation in the EU-US Data Privacy Framework, or by your own request that we contact you. Ask us and we will tell you which safeguard applies to your data.
7. Your rights under the GDPR, for visitors in Europe
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the right to:
- Access a copy of the personal data we hold about you.
- Rectification of anything inaccurate or incomplete.
- Erasure of your data, where we have no overriding reason to keep it.
- Restriction of processing while a dispute is being resolved.
- Portability: your data in a machine-readable file.
- Objection to processing based on legitimate interests, including any direct marketing.
- Withdrawal of consent at any time, where consent is what we rely on.
- Complaint to your national supervisory authority if you think we have handled your data badly. We would rather you told us first, so we can fix it.
To use any of these rights, email support@morneto.com. We answer within 30 days, usually much sooner, and there is no charge. We may ask a question or two to confirm who you are before sending data out.
8. Your rights under the CCPA and CPRA, for California residents
If you are a California resident you have the right to know what personal information we collect and why, to receive a copy of it, to correct it and to have it deleted. You also have the right to opt out of the sale or sharing of personal information and to limit the use of sensitive personal information.
We do not sell or share personal information as the CCPA and CPRA define those terms, and we have not done so in the previous twelve months. We do not collect sensitive personal information, and we do not use personal information for cross-context behavioral advertising. That is why you will not find a “Do Not Sell or Share My Personal Information” switch on this site: there is nothing to switch off.
In the past twelve months the categories we have collected are identifiers, meaning name, email address, phone number (if you add one on the contact form or at checkout) and IP address, and commercial information, meaning the service you asked about. Once you pay online we also collect your billing address, your phone number if you give one, and a record of what you bought and paid, which fall into the same two categories. We never receive your full card number. They come directly from you or from your use of the website, and we use them for the business purposes set out in section 2. We will never treat you differently for exercising a privacy right. To make a request, email support@morneto.com with “Privacy request” in the subject line; an authorised agent may act for you with written proof.
9. Security, and the New York SHIELD Act
The New York Stop Hacks and Improve Electronic Data Security (SHIELD) Act requires reasonable administrative, technical and physical safeguards for the private information of New York residents. Ours are set out below.
- Administrative: one person is accountable for data security, the founder; access is limited to those who need it; suppliers are chosen partly on their security record and are bound by data processing terms; our practices are reviewed as part of routine site maintenance.
- Technical: HTTPS with modern TLS across the whole site; a Cloudflare firewall and bot protection in front of the origin server; two-factor authentication on hosting, domain, WordPress and Google accounts; least-privilege user roles; software and plugins kept up to date; daily backups stored separately from the live site; a written routine for restoring service after an incident.
- Physical: data sits in the secured data centers of our host and CDN, and work devices are encrypted and password-protected.
No system is perfect. If a breach affects your private information we will notify you and the relevant authorities without unreasonable delay, as the SHIELD Act and the GDPR require, and we will tell you plainly what happened and what to do about it.
10. Marketing
We do not run a newsletter and we do not add enquiries to a mailing list. If we ever start one, joining will be an active choice and every message will carry an unsubscribe link. We may follow up on an enquiry you sent us; ask us to stop and we stop.
11. When we work on your website or ad account
When you become a client we usually need access to systems that hold other people’s data, such as your website’s user list, your form entries or your Google Ads account. In that situation you remain the controller and we act as your processor: we use that access only for the agreed work, and we do not copy data out of your systems, except the backups and reports the agreed work needs. We store those securely and delete them at the end of the engagement, when we also remove our access. The details sit in the written agreement, with a data processing addendum where the GDPR applies.
12. Links to other websites
Our guides link to other websites, including Google’s documentation and other companies in our field. Those sites have their own privacy policies, and we are not responsible for them.
13. Changes to this privacy policy
If we change how we handle data we update this page and change the date at the top. Material changes, such as introducing analytics or advertising cookies, will be described before they take effect rather than afterwards.
14. How to reach us about privacy
Email support@morneto.com with “Privacy request” in the subject line, or use the contact form. We reply within one working day, and within 30 days for a formal access, correction or deletion request.
This privacy policy describes our own practices and is not legal advice. If you need a policy for your own business, have one written or reviewed by a qualified lawyer in your jurisdiction; we are happy to make sure it is linked correctly on your site.