Privacy Policy
Last updated: May 2026
LLCora ("we", "us") respects your privacy. This policy explains what data we collect, why, and how we protect it. We comply with the EU GDPR, the California CCPA, and the Brazilian LGPD.
1. Who we are
LLCora is a US LLC formation service for non-residents operated by LLCora Inc., a US-registered entity. For privacy-related questions, contact us at hello@llcora.com.
2. What we collect
We only collect what we need to file your LLC and obtain your EIN.
a) You give us
- Full name, date of birth, nationality
- Email address and (optionally) phone number
- Postal address in your country of residence
- Passport or government-issued ID scan (for state KYC requirements)
- LLC name, business activity description, member structure
- Billing information (handled by Stripe / PayPal — we never see your full card number)
b) Collected automatically
- IP address, browser type, language, device (via Google Analytics 4 with IP anonymization)
- Pages visited, referrer, session duration
- Cookies — see our Cookies Policy
3. Why we collect it (legal bases)
| Purpose | Legal basis |
|---|---|
| Form your LLC with the state | Contract performance |
| Apply for your EIN with the IRS | Contract performance |
| Send transactional emails (order updates) | Contract performance |
| Compliance with US KYC/AML obligations | Legal obligation |
| Marketing emails (only with consent) | Consent |
| Analytics and product improvement | Legitimate interest |
4. Who we share data with
We share only the minimum needed to deliver our service:
- State Secretaries of State (Wyoming, New Mexico, Missouri, Delaware, etc.) — for filing your LLC
- Registered Agent partners — required by US law; they receive legal mail on your behalf
- The US Internal Revenue Service (IRS) — only the information required on Form SS-4 to obtain your EIN
- Stripe / PayPal — payment processors, PCI-DSS compliant
- Resend — transactional email provider (so you receive order confirmations)
- Vercel — our hosting provider
- Google (Analytics 4) — anonymized usage data
We do not sell your data. We do not share it with advertisers. We do not use it to train AI models.
5. International transfers
Data is processed in the United States (state filing, EIN) and in the European Union (some Vercel edge regions). Where data leaves your jurisdiction, we rely on Standard Contractual Clauses (EU) or equivalent safeguards.
6. Retention
- Formation documents: 7 years after order completion (US tax retention requirement)
- Marketing data: until you unsubscribe
- Analytics data: 14 months (Google Analytics default)
- Support emails: 3 years after last contact
7. Your rights
Under GDPR, CCPA and LGPD you have the right to:
- Access the data we hold about you
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Export your data in a portable format
- Object to processing
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
To exercise any of these, email hello@llcora.com. We respond within 30 days.
8. Security
We use TLS encryption in transit, encrypted databases at rest, role-based access controls, and regular security reviews. Despite our best efforts, no system is 100% secure — if a breach occurs, we will notify affected users within 72 hours as required by GDPR Art. 33.
9. Children
Our service is not intended for users under 18. We do not knowingly collect data from minors.
10. Changes
We may update this policy. The "last updated" date at the top reflects the most recent version. Material changes will be emailed to active customers.
11. Contact
Privacy questions, requests or complaints: hello@llcora.com · legal@llcora.com