Skip to content

Privacy Policy

English translation. This is a translation provided for convenience. The binding version is the Spanish one at lorasystem.com/privacidad. In the event of any discrepancy between the two, the Spanish version prevails.

Last updated: July 18, 2026

This Privacy Policy explains what information Lora collects, how it is used, who it is shared with and what rights you have over it. It applies to Lora's website and to the services we provide to businesses in the United States, and to the data of those businesses' prospects and patients that we process on their behalf.

1. Information we collect

We collect two kinds of information:

  • From visitors to this site and from our clients: name, phone number, email and business name, when you book a call, fill out a form or sign up for a plan.
  • From our clients' prospects and patients (the people who message a business that uses Lora): name, phone number, social media identifiers (WhatsApp, Instagram, Facebook) and the content of their messages, in order to operate the booking bot and the CRM on behalf of that business. We process this data as a service provider to the client business, not as the owner of that data.

2. How we use your information

We use your information to contact you about our services, to book and confirm appointments, to operate our clients' communication bot and CRM, to produce performance reports, and to improve our services. We do not sell personal information to third parties.

3. Who we share your information with

We share information only with the providers needed to operate the service, under their own confidentiality and security terms: Lora System, the CRM and automation platform we operate under our own brand (GoHighLevel); Meta (Facebook, Instagram and WhatsApp), for the messaging channels and, on the Lora Max plan, the ad campaigns; and Vercel, where this website is hosted. We do not share your information with third parties for advertising purposes unrelated to Lora, and we do not sell it.

4. Cookies and similar technologies

We use cookies that are essential to the operation of the site, as well as analytics and advertising cookies (the Meta pixel, for example) to understand how you interact with the site and to measure how our campaigns perform. You can decline non-essential cookies from the cookie banner.

5. Information security

We implement technical and organizational security measures to protect your information, including encryption in transit (HTTPS/TLS), access controls and protection against common attacks. No system is completely foolproof; if we detect a security incident that affects you, we will notify you as required by applicable law.

6. Data retention

We keep your information for as long as there is an active service relationship, and for up to 24 months after it ends, unless the law requires us to keep it longer. After that period we delete it or anonymize it.

7. Your rights

You have the right to access, correct, delete or request a copy of your personal information. To exercise these rights, contact us through the evaluation call available on this site.

8. Notice for United States residents

Lora operates in the United States and our clients are U.S. businesses. If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you additional rights over your personal information: to know what information we collect, to request its deletion, to correct it, and to opt out of its sale or of its use for targeted advertising. We do not sell personal information for money. Other U.S. states, such as Virginia, Colorado, Connecticut and Utah, have their own privacy laws with similar rights. If you reside in any of these states and want to exercise your rights, contact us and we will handle your request under the law that applies to you.

9. Text messages (SMS/WhatsApp)

We only send automated text or WhatsApp messages to numbers that have given prior consent to be contacted — for example by filling out a form or starting a conversation with the business — in accordance with the Telephone Consumer Protection Act. You can opt out at any time by replying "STOP" or by asking us directly.

10. Email

Our emails identify the sender truthfully, include a valid physical postal address and an unsubscribe link, which we process within a maximum of 10 business days, in accordance with the CAN-SPAM Act.

11. Health data (PHI)

When a Lora client is a dental or aesthetic/med spa clinic, its patients' information may constitute protected health information (PHI) under HIPAA. We process this type of data only under a Business Associate Agreement signed separately with that clinic, and not before. This Privacy Policy does not replace or cover the obligations of that agreement.

12. Use of artificial intelligence

The system that responds to our clients' prospects and patients uses artificial intelligence. This is disclosed in the first automated message each person receives; the system never passes itself off as a human.

13. Minors

Our services are directed at businesses and their adult clients. We do not knowingly collect personal information from children under 13. If you believe a minor has given us information, contact us so we can delete it.

14. Changes to this policy

We may update this policy from time to time. Material changes will be reflected with a new last-updated date at the top of this page.

15. Contact

If you have questions about this Privacy Policy or want to exercise your rights, contact us through the evaluation call available on this site.