Privacy notice
Development demo ยท Updated 25 September 2026
Yardspur is currently a development demo for invited testing with fictional customer and job details. It is not yet open for general business use. This notice describes the current demo, not planned features.
Who runs Yardspur
Yardspur is operated by Yousif Saeid, trading as Yardspur. For privacy questions or requests, email yousifsaeid757@gmail.com. Yousif is responsible for personal information used to administer and test this demo.
Information used in the demo
We process test account names, email addresses, business names, password hashes and session records; company logos; quote details and PDF documents; approval and delivery records; and connected account identifiers and access credentials. For linked WhatsApp instructions, we process the sender number, message text, message identifiers and timestamps, extracted quote details and processing status. Information comes from testers and the Google, Meta and OpenAI services they use through Yardspur.
Do not submit real customer records, payment-card details, sensitive personal information or voice notes. Voice transcription and calendar integration are not currently provided.
Why information is processed
We use this information to operate test workspaces, link authorised accounts, receive instructions, prepare and review quote drafts, generate PDFs, send explicitly approved test documents and investigate problems. For demo administration and security, we rely on our legitimate interests in developing and protecting the service, balanced against the interests of testers. We use information supplied in enquiries to respond to those enquiries. Providing account and connection details is necessary to use the corresponding features; otherwise those features remain unavailable.
AI-assisted drafts
When incoming drafting is enabled, text instructions from the linked owner number are sent to OpenAI's API for structured quote extraction. AI can make mistakes. A person must check the draft and approve it before customer delivery. Receiving a message does not itself approve or send a document. We do not use this feature to make decisions about people with legal or similarly significant effects.
We request that OpenAI not store Responses application state. This does not remove all provider retention: OpenAI describes default abuse-monitoring retention of up to 30 days, with exceptions. See OpenAI's API data controls.
Connected services and recipients
Google handles account connection and Gmail delivery. The current Gmail integration uses basic account identity and permission to send email; it does not request permission to read your inbox. Meta handles WhatsApp messages and webhook delivery. OpenAI processes the text instructions used for drafts. Cloudflare carries the temporary webhook connection. Approved documents are shared with the recipients selected by the tester. These providers also process information under their own terms and privacy notices. We do not sell personal information or use the demo for advertising.
Storage, security and retention
The demo workspace database and generated document records are stored on the development computer. Connected account tokens are encrypted in that database, passwords are hashed, and WhatsApp webhook signatures are checked. Access is restricted to the development environment. Messages, quotes and approval history currently remain in the local database until manually removed; automated retention and self-service deletion are not implemented.
Contact us to request removal of demo information or disconnection of an account. We will assess and respond to the request, including any applicable legal obligation to retain particular records. Disconnecting an integration does not automatically erase previously created quotes or copies already delivered to email or WhatsApp recipients. Provider-held copies are subject to those providers' retention arrangements.
International processing
The providers used by the demo may process information outside the United Kingdom. Do not assume UK-only storage. Before inviting real business/customer data into a production service, we will confirm the applicable provider agreements and transfer safeguards and update this notice.
Cookies and local storage
The local application uses a session cookie to keep you signed in. This static privacy page does not include advertising, analytics scripts or tracking cookies. A hosting provider may process technical request information to serve and secure the page.
Your choices and rights
You can pause incoming drafting, disconnect integrations, or contact us about access, correction, deletion, restriction, portability or objection to processing. These rights depend on the circumstances. We may need to verify your identity to protect your information. You may complain to the UK Information Commissioner's Office.
Changes
We will update this notice as the demo changes, including before moving to hosted production or onboarding real business customer data.