Legal
Privacy Policy
Last updated: September 24, 2026
Who we are
yamilmorales.com (the “Site”) is operated by Yamil Morales, LLC, a limited liability company organized in Delaware, United States (“we”, “us”). We provide CRM and marketing automation consulting and implementation, free scheduled calls (the Strategy Call and the Quick Fix Diagnostic) and training programs such as AI Fluent.
For any question about this policy, the only contact channel is the contact form.
Information we collect
We collect personal information you give us directly and data generated automatically as you use the Site:
- Contact and lead forms: your name, email address, optional phone number, optional company, and your message. These are stored in our own database (Amazon RDS for PostgreSQL, us-east-1 region, United States).
- Call bookings: your contact details, your answers to the intake questions for each call type, your time zone, the email addresses of any additional guests you add, and the campaign attribution (UTM parameters) that brought you to the Site. Each appointment record includes tokenized links that let you reschedule or cancel.
- Payments: paid sessions are processed by Stripe (embedded checkout) or PayPal. We never see or store card numbers; we keep only a transaction reference and the amount paid.
- Email: booking confirmations, reminders and receipts are sent through Amazon SES; the newsletter is sent from HubSpot. We record delivery events (send, bounce, complaint, open, click) to manage email deliverability.
- Analytics: usage data collected with PostHog, described in the next section.
- Site visits: our own record of your visits, kept in our database under a random ID stored in the ym_vid cookie. For each visit it holds the pages you view and how long you stay on each, the links and buttons you click (never what you type into a form), the campaign (UTM) parameters and the site that referred you, your time zone and language, your browser, device and screen size, the country of your connection, a shortened IP (never the full address) and the matching PostHog session. When you submit a form, book a call or buy, the visits from that browser are linked to your contact, and the links to the Site in the emails our system sends you (confirmations, reminders, receipts and replies to your forms; not the newsletter) carry a code that does the same when you click one.
- Anti-abuse data: to rate-limit public forms and booking endpoints, we store a truncated SHA-256 hash of your IP address. The hash cannot be reversed to recover your IP and is purged within 24 hours.
Analytics and session recording
We use PostHog, hosted in the United States, to understand how the Site is used. PostHog automatically captures pageviews and interaction events, and it records sessions (a replay of how you navigate and interact with pages). Session recordings help us find usability problems and improve the Site.
Recordings mask what you type into form fields: they show that a field was filled in, not its contents. Details a page shows back to you afterwards, such as the email address on a booking confirmation, can still appear in a recording.
PostHog only creates an identified profile for people who identify themselves: by submitting a form, booking a call or buying, or by clicking a link in an email we sent them. At that moment we link that browser's earlier anonymous PostHog activity to the profile, under the person's email address. Visitors who never identify themselves are not tied to a personal profile.
Cookies and local storage
The Site uses the following cookies and browser storage:
- PostHog: an analytics cookie and localStorage entries used to collect the usage data described above.
- Visit history: the ym_vid cookie, a random ID the Site sets itself (a first-party cookie) to recognize your browser across visits; PostHog also attaches it to the usage data it collects. It lasts 13 months from your last visit. If you turn the visit history off, a ym_optout cookie remembers that choice for 13 months.
- Booking widget preferences: your 12/24-hour time format choice in localStorage, and UTM campaign parameters in sessionStorage.
- Admin authentication: session cookies (Amazon Cognito) used only on the private admin panel; they are never set for regular visitors.
- Stripe and PayPal: third-party cookies set during checkout to process your payment securely.
How we use your information
We use the information described above to:
- Respond to your inquiries and messages.
- Deliver our consulting, implementation, and training services.
- Schedule, confirm, remind, reschedule, and cancel appointments.
- Process payments and send receipts.
- Measure and improve the Site and its content.
- Send you our newsletter and market our own services, when you have asked us to. We never sell your data and never use it for third-party advertising.
Legal bases for processing
We process your information on the following bases:
- Consent: when you submit a contact or lead form, or subscribe to the newsletter. You can withdraw it at any time: every newsletter carries a one-click unsubscribe link, and you can also write to us.
- Performance of a contract: when you book a call or pay for a service, we process your data to deliver it.
- Legitimate interest: for analytics (including the record of Site visits), Site improvement, security, and abuse prevention.
Who we share your information with
We never sell your personal information. We share it only with the service providers needed to run the Site:
- Amazon Web Services (AWS): hosting, database (Amazon RDS for PostgreSQL), and transactional email (SES), acting as our processor.
- Cloudflare: runs the bot check (Turnstile) on the Site's forms (contact, Revenue Leak Map, newsletter and bookings), which reads signals such as your IP address and browser to tell people from bots. The links in our emails, and the image that records that an email was opened, also pass through Cloudflare (go.yamilmorales.com). Cloudflare acts as our processor, and also uses the bot-check signals to improve its own bot detection under its Turnstile privacy terms.
- Stripe and PayPal: payment processing. Both act as independent controllers of your payment data under their own privacy policies.
- PostHog: analytics and session recording, acting as our processor.
- Google: when you book a call, we create the event on our own Google Calendar and add your email as an attendee, so the invite reaches you. We do not access your calendar.
- Zoom: hosts the video call itself. We create the meeting through Zoom and share the join link with you; Zoom processes your participation in the call under its own privacy policy.
- HubSpot: our CRM, acting as our processor. Leads and newsletter subscribers are stored in our own database and synced to HubSpot, which is also where our newsletter is sent from. Contact-form messages are reviewed and pushed by hand rather than synced automatically.
International transfers
Our infrastructure runs in the United States, and your information is processed and stored there. If you visit from outside the United States (including Latin America or the European Economic Area), your information is transferred to the United States.
Data retention
We keep personal information only as long as it serves a purpose:
- Leads and appointment records: kept while we maintain a business relationship with you, or until you ask us to delete them.
- Email delivery events: kept to manage sender reputation and deliverability.
- Anti-abuse IP hashes: purged within 24 hours.
- Site visits: the visits of a browser that was never linked to a contact are deleted after 180 days, and so is a browser not seen for 180 days. Visits linked to your contact are kept with the contact, and deleted with it.
- Shortened IP: a visit stores only the network part of your IP address (/24 for IPv4, /48 for IPv6) and a keyed hash of the full address, which lets us match visits from the same address without storing the address. Both are removed from every visit after 180 days, linked to a contact or not.
- Email link codes: deleted after 180 days without use.
- Payment records: transaction references and amounts are kept as long as needed for accounting and tax obligations.
Your rights
You can request access to the personal information we hold about you, ask us to correct it, ask us to delete it, or object to analytics processing.
Deleting your information also deletes your visit history. The only visits kept are those of a browser another contact also used: they stay with that contact and are no longer linked to you.
To exercise any of these rights, send a request through the contact form. We will verify the request and respond.
California (CCPA) and other US state laws
We do not sell personal information, and we do not share it for cross-context behavioral advertising. California residents (and residents of states with similar laws) may exercise the access, correction, and deletion rights described above.
Because nothing is sold or shared, we do not treat a Global Privacy Control (GPC) signal as an opt-out from analytics. To turn off the record of your visits in a browser, open yamilmorales.com/?ym_optout=1 in it; yamilmorales.com/?ym_optout=0 turns it back on.
Visitors from the European Economic Area (GDPR)
Our services are aimed primarily at clients in the United States and Latin America. If you visit from the EEA or the United Kingdom, we extend you the rights provided by the GDPR: access, rectification, erasure, restriction, portability, and objection, on the legal bases described above.
Use the contact form to exercise them.
Children
The Site is not directed at anyone under 18, and we do not knowingly collect personal information from minors.
If you believe a minor has provided us personal information, let us know through the contact form and we will delete it.
Changes to this policy
We may update this policy as the Site evolves. When we do, we will update the date at the top of this page. This page always reflects the current version.