Legal

Privacy Policy

Last updated 26 September 2026

We take the security of your business and your clients seriously. This policy explains what personal data we handle, why, and the choices and rights you have.

1. Who we are

Pygar AI Technologies ("we") runs HappyNoodle. For the personal data of our own account holders and directory visitors we are the data controller. Contact: admin@pygar.ai, Suite 33 Acorn Mill, Lees, Oldham, OL4 3DH, United Kingdom.

2. Two kinds of data

Account data: information about you as a user of HappyNoodle. We decide how this is used.

Customer Data: information our business users store about their own clients (contacts, proposals, invoices, messages). For this, the business is the controller and we process it only on their instructions. If you are a client of a HappyNoodle user, please contact that business first about your data.

3. What we collect

Account details: name, email, phone, business details, logo and sign-in records.

Directory and enquiry details: listing information businesses choose to publish, and the name, email, phone and message you send when you make an enquiry.

Reviews: star rating, comment and the display name you choose when leaving a review.

Usage and security data: device, browser, IP address and activity logs used to keep accounts secure.

Connected services: limited data from services you connect, such as Xero or Google Calendar, only to provide the feature you asked for.

4. Why we use it (lawful bases)

To provide the Service under our contract with you.

To keep the Service secure and prevent fraud and abuse (legitimate interests).

To send service messages such as sign-in and billing notices (contract).

To send product news only where you have agreed (consent), which you can withdraw at any time.

To meet legal and tax obligations (legal obligation).

5. Directory enquiries

When you send an enquiry, your name, email, phone and message are shared with the business you contact and added to their contact list so they can reply. That business then becomes responsible for your data. We keep a record that the enquiry was made to prevent spam.

6. Who we share data with

Hosting, database and email-delivery providers who process data on our behalf under contract; services you choose to connect (for example Xero, Google); professional advisers; and authorities where the law requires. We never sell personal data, and we do not use Customer Data or data from connected services to train AI models.

7. AI features

Optional AI features (such as brief refinement, writing assistance and account briefings) send only the relevant text to our contracted AI provider to generate a response. We instruct providers not to use Customer Data to train their general models. You should review AI output before relying on or sharing it.

8. International transfers

Where data is processed outside the UK, we use UK-approved safeguards such as the International Data Transfer Agreement or adequacy regulations.

9. How long we keep it

Account data for as long as your account is open and up to 6 years afterwards for tax and legal records. Customer Data is deleted within 30 days of account closure unless the business exports it first. Security logs are kept for up to 12 months.

10. Security

Every business's data is separated at database level so users only see businesses they belong to. Third-party keys are encrypted and never sent to the browser. Access is logged and reviewed.

11. Your rights

Under UK GDPR you can ask to access, correct, delete, restrict or move your data, and object to certain uses. Email us and we will respond within one month. You can also complain to the Information Commissioner's Office (ico.org.uk).

12. Cookies and similar storage

We use a small number of cookies and similar browser storage (local storage and session storage). We do not use advertising, cross-site tracking or profiling cookies, and we do not sell browsing data. Our Terms of Service rely on this section as our Cookie Policy.

Essential (always on, no consent needed under PECR because the Service cannot work without them):

• Sign-in session (browser storage, key starting "sb-"): keeps you securely signed in and refreshes your session. Lasts until you sign out.

• Active business (local storage "bos.active-location"): remembers which business you were working in. Cleared when you sign out.

• Proposal access pass (session storage "hn-proposal-grant"): remembers that you verified your emailed code for a proposal. Deleted when you close the tab and expires within 12 hours.

• Security check (Cloudflare Turnstile, challenges.cloudflare.com): confirms you are human on sign-in, sign-up and directory enquiries to stop spam and account abuse. Cloudflare may set short-lived security cookies.

• Secure payments (our payment provider): when you open checkout, the payment provider sets cookies needed for fraud prevention and to complete payment safely.

Optional (functional, set only when you use the feature and never used for tracking):

• Website chat conversation (local storage "webchat:…"): lets a visitor continue a chat on a business's website. You can clear it with "Start a new one".

• Sidebar layout (cookie "sidebar_state"): remembers whether the menu is open. Up to 7 days.

• Admin preferences (local storage "hn-cost-rates"): saves site administrators' cost-estimate settings on their own device.

Guided tour progress and account preferences are stored in your account, not in cookies.

Managing cookies: you can block or delete cookies and storage in your browser settings. Blocking essential items will stop sign-in, security checks or payments working. Clearing optional items simply resets those preferences. If we ever introduce analytics or marketing cookies, we will ask for your consent first and update this policy.

13. Changes

We will post any changes here and tell you in the app if they are significant.