Legal

Privacy policy

What personal data Noddable holds about you, why we hold it, how long for, and what you can make us do about it.

Version 2026-09-16 · In effect from 16 September 2026 · Last updated 16 September 2026
Published by [REGISTERED COMPANY NAME] Limited, company number [COMPANY NUMBER], registered in England and Wales. Questions: legal@noddable.com

Draft — not yet reviewed by a solicitor. This document was prepared as a starting point and has not been checked by a qualified legal adviser. It should not be relied on, held out as binding, or published to customers in this state. Details shown in square brackets are placeholders that must be completed.

This policy is written under the UK GDPR and the Data Protection Act 2018, and applies the EU GDPR where it applies to you. The controller is [REGISTERED COMPANY NAME] Limited, [REGISTERED OFFICE LINE 1], [TOWN], [POSTCODE], United Kingdom, company number [COMPANY NUMBER], registered with the Information Commissioner's Office under [ICO REGISTRATION NUMBER]. Contact us about anything in it at privacy@noddable.com.

We are not required to appoint a Data Protection Officer and have not appointed one. Privacy questions are handled by a named person, reachable at the address above.

1. Two different roles

This policy covers two relationships, and it matters which one you are in.

  1. You, our customer. We decide how and why your account data is handled, so we are the controller and this policy governs it.
  2. Your clients, and anyone in your photographs. We hold that data because you put it there. You decide what it is for; we only act on your instructions. You are the controller and we are your processor. What we may and may not do with it is set out in the data processing agreement, not here — and the people concerned should look to your privacy notice, not ours.

2. What we collect

DataWhere it comes from
Account — your email address, your name if you give it, and the role you hold on an accountYou, when you sign up
How you found us — if the link you signed up from carried campaign tags (for example which of our posts, or which creator's code), those tags. Never the page you came from or anything about your deviceThe link you followed, when you sign up
Sign-in — a one-time code, stored only as a hash, and a session record holding a hash of your session token and its expiryGenerated when you sign in
Your sites and galleries — names, settings, and the content you uploadYou, as you use the service
Billing — your name, billing address, VAT number, the invoices we issue, and the last four digits and expiry of your cardYou, through Stripe. Your full card number goes to Stripe and never to us
Support — the emails you send us and our repliesYou, when you contact us
Fault records — the path that failed, the error message, and the account it happened onGenerated automatically when something breaks
Abuse limits — a short-lived counter against a hashed identifier, so one caller cannot flood the sign-in endpointGenerated at the edge

3. Why, and on what legal basis

PurposeLawful basis
Giving you the service you have signed up for, including publishing your sites and delivering your galleriesPerformance of a contract
Signing you in and keeping your sessionPerformance of a contract
Taking payment, issuing invoices, chasing unpaid onesPerformance of a contract; legal obligation for the tax record
Emailing you about your account — renewal reminders, changes to these documents, security noticesPerformance of a contract; legal obligation for some of them
Keeping the service secure, rate-limiting abuse, investigating misuseLegitimate interests — running a service that is not trivially abusable
Recording faults so we can fix themLegitimate interests — a service that works
Knowing which of our posts and partners bring people to us, and crediting a creator who referred youLegitimate interests — spending our effort where it works, and paying referrals fairly
Keeping accounting recordsLegal obligation — Companies Act 2006 and HMRC requirements
Sending you product news you have asked forConsent, withdrawable in one click in every message

Where we rely on legitimate interests we have considered whether our interest is overridden by your rights, and we will share that assessment with you if you ask.

4. What we deliberately do not collect

This section is the reason several of the others are short.

  • No advertising or analytics networks, on this website or on any website we publish for a customer. No pixels, no tag manager, no third-party fonts.
  • No visitor identifiers on published sites. The optional visitor statistics feature counts page views, and records the referring website's hostname and the country. It stores no address, no cookie, no device fingerprint and no generated identifier, and cannot be used to follow one person. That is why a site using it does not need a cookie banner for it.
  • No profiling and no automated decisions that produce legal or similarly significant effects about you.
  • No sale of data. We do not sell or share personal data, in the ordinary sense or in the specific senses those words carry in US state privacy laws.
  • No training of AI models on your content — yours, or your clients'.

Cookies are covered separately and in full in the cookie policy. There are three, all strictly necessary, and none of them belongs to anybody else.

5. How long we keep it

These are enforced by a scheduled job, not by intention — the numbers below are the ones the system actually applies.

RecordKept for
Account and its content, while you are a customerUntil you close the account
Account and its content, after you leaveDeleted after 90 days; out of backups within a further 35
Sign-in codesValid 10 minutes; deleted within a day
Session records30 days maximum, deleted at expiry
Fault records30 days
Gallery activity — link opened, files downloaded365 days
Visitor statistics rollups (no personal data)400 days
Invoices and accounting records6 years from the end of the financial year, as the law requires
Support correspondence2 years from the last message

6. Who else sees it

Only the providers we need to run the service, each under a written contract that allows them to use the data only for us. They are listed, by name and by purpose, on the sub-processors page — currently our infrastructure provider and our payment provider, and no one else.

We will also disclose data where we are legally required to, or to establish or defend a legal claim. If we are asked for your data by an authority, we will tell you unless we are prohibited from doing so.

If our business is sold, your data may transfer with it. You would be told before that happened and the new owner would be bound by this policy until it gave you notice of any change.

7. Where it is held

Your account data and your content are held on infrastructure in the United Kingdom and the European Economic Area by default.

Some of our providers are established outside the UK and EEA, or may access data from outside it for support purposes. Where that happens we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on an adequacy decision where one covers the country concerned, together with the technical measures described below. We will give you a copy of the relevant safeguard on request.

8. How it is protected

  • Everything is served over TLS. Data is encrypted at rest by the storage platform.
  • Sessions are stored as a SHA-256 of the token, so a copy of our database could not be replayed as a live session. Sign-in codes are stored the same way and are never recoverable.
  • There are no passwords to leak, because there are none. Sign-in is a one-time code, rate limited both per address and per caller.
  • Every query for site and client data is scoped to a tenant derived from the session or the hostname, never from anything the browser sends.
  • Uploads are checked by their actual file signature rather than by what the browser claims they are.
  • Access to production data is limited to those who need it, and is used for support and operations only.

More detail is on our security page. If we suffer a personal data breach that is likely to risk your rights, we will report it to the ICO within 72 hours and tell you without undue delay where the risk to you is high.

9. Your rights

You can ask us to:

  • Give you a copy of the personal data we hold about you;
  • Correct it if it is wrong or incomplete;
  • Delete it, where we have no overriding reason to keep it;
  • Restrict what we do with it while a dispute about it is resolved;
  • Give it to you or to someone else in a portable form, where we hold it on the basis of your consent or of our contract;
  • Stop processing based on legitimate interests, by objecting — and stop direct marketing, which we will always do, no questions asked;
  • Withdraw consent at any time, where consent is what we relied on.

Write to privacy@noddable.com. We will respond within one month, and tell you if we need longer because the request is complex. There is no charge unless a request is manifestly unfounded or excessive. We may need to confirm who you are first — usually by using the email address already on the account.

If your request is about data you uploaded about someone else, we will pass it to you rather than act on it, because in that case you are the controller and the decision is yours.

10. How to complain

Please tell us first — most things are a misunderstanding and we would rather fix it. If you are not satisfied you can complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, at ico.org.uk/make-a-complaint or on 0303 123 1113. If you are in the EEA you may complain to your own national supervisory authority instead.

11. Children

The service is not for children. We do not knowingly collect personal data from anyone under 18 as a customer. Photographs of children uploaded by a customer are that customer's responsibility, and their lawful basis and any necessary consent are a matter for them as controller.

12. Changes

We will update this policy when what we do changes. If a change is material we will email you before it takes effect. Every version is dated; the current one is shown at the top of this page.

← All legal documents