Privacy Policy
Effective Sep 1, 2026
Overview
We are Stub Holdings Limited (company number: 14323727), trading as stub (“we”, “us”, “our”). stub is a cloud-based financial management, invoicing, accounting, bookkeeping, and online payments platform built for small businesses, entrepreneurs and freelancers.
This privacy policy (“Policy”) explains what personal information we collect, why we collect it, how we use and share it, and what rights you have. It applies to everyone who uses our platform, website, and services (“Services”). Please read it carefully.
This Policy applies from the Effective Date above and replaces all previous versions.
Quick reference
If you are short on time, here is a summary. For full details, please read the relevant section.
- What data we collect: Account details, contact information, financial records, payment data, device and usage data, and AI interaction data. See Section 2.
- Why we collect: To provide and improve the Services, process payments, comply with the law, and, with your permission, send you marketing. See Section 3.
- Who we share it with: Service providers, AI technology partners, payment processors, and, where required, regulators. We never sell your data. See Section 4.
- International transfers: Your data may be processed in the US, UK, or EEA. We put safeguards in place. See Section 5.
- How long we keep it: For as long as needed to provide the Services and comply with the law. See Section 6.
- Your rights: Access, correction, deletion, objection, portability, and more. See Section 7.
- AI features: We use AI for transaction categorisation, reconciliation, anomaly detection, and more. We do not use your data to train general AI models. See Section 3.5.
- Cookies: We use strictly necessary cookies and, with your consent, analytics and advertising cookies. See Section 8.
- Contact us: privacy@stub.africa or our Information Officer / Data Protection Contact (details in Section 10).
1. Scope of this Policy
1.1 What this Policy covers
This Policy covers personal information that we control, being personal information about our users, website visitors, and business contacts where we decide how and why it is processed.
1.2 What this Policy does not cover
When you use stub to manage your own customers, suppliers, employees, or contractors, for example by creating invoices, uploading payroll records, or maintaining a supplier list, the personal information of those third parties is processed by us as your service provider (or “operator”/“processor” under applicable data protection laws). In that case:
- You are the responsible party / controller for that information.
- We process it only on your instructions and in accordance with this Policy (and the relevant data processing agreement, if applicable).
- Third parties whose data you upload should direct privacy rights requests to you, not to us.
This Policy also does not apply to third-party websites, apps, or services that you may link to from stub. Those services operate under their own privacy policies.
1.3 Who this Policy applies to
This Policy applies to you if you:
- create or use a stub account;
- visit our website at https://stub.africa/ (“Website”);
- use our mobile or desktop applications;
- use our APIs or developer tools;
- contact us for support; or
- otherwise interact with us in connection with the Services.
1.4 Applicable laws
We operate under, and this Policy is designed to comply with:
- the Protection of Personal Information Act 4 of 2013 (South Africa) (“POPIA”);
- the UK General Data Protection Regulation and the Data Protection Act 2018 (United Kingdom) (“UK GDPR”); and
- other applicable data protection and privacy laws, regulations, and regulatory guidance (together, “Applicable Data Protection Laws”).
Where we refer to “personal information” or “personal data”, we mean any information from which a living individual can be identified, directly or indirectly. Both terms are used to reflect the terminology of POPIA and UK GDPR respectively, and for the purposes of this Policy they mean the same thing.
2. Personal information we collect
The personal information we collect depends on how you interact with us.
2.1 Information you give us directly
When you register, use the Services, or contact us, we collect:
Account and identity information
- Full name, username, and password
- Email address and telephone number
- Business name, job title, and business address
- VAT registration number, tax reference number, or other business identifiers
Financial and payment information
- Subscription and billing details (processed by PCI-DSS compliant payment processors - we do not store full card numbers)
- Bank account details you connect for bank feeds or payment reconciliation
- Financial records you create or upload, including invoices, quotes, credit notes, purchase orders, expense records, and journal entries
- Information about your customers, suppliers, and other business contacts that appears in your financial records
Content you upload or create
When you use the Services, you may upload or generate content including:
- Prompts, instructions, documents, and other material you submit to our AI features (“Inputs”);
- Content generated by our AI in response to your Inputs (“Outputs”);
- Supporting documents such as receipts, contracts, bank statements, and payroll files;
- Profile images or business logos.
You own your content. Our collection and use of it is governed by this Policy and our terms of service, available at https://stub.africa/resources/terms-of-service (“Terms of Service”).
Communications and support data
- Messages, emails, or chat conversations you send us
- Call recordings (where you are notified and do not object: see Section 3.4)
- Survey responses, feedback, and competition entries
2.2 Information we collect automatically
When you use our Website or Services, we automatically collect:
- Device and connection data: IP address (and approximate location derived from it), device type and model, operating system, browser type and version, mobile carrier, and time zone.
- Usage data: pages viewed, features used, links clicked, search queries, session duration, login timestamps, and interaction with in-product features.
- Log and diagnostic data: error logs, crash reports, performance metrics, and API request metadata (including model version, token counts, and latency for AI features).
- Cookies and similar technologies: see Section 8.
2.3 Information from third parties
We may receive personal information from:
- Third-party account providers: if you sign up or log in via Google, Apple, or another provider, we receive your name, email address, and profile identifier from them.
- Connected services: if you integrate your bank account, payment gateway, e-commerce platform, or other third-party service with stub, we receive transaction and account data as authorised by you.
- Payment processors: confirmation of payment status and basic billing details.
- Public sources: company registration details, publicly available business information, where relevant.
2.4 Special categories of personal information
We do not generally seek to collect special categories of personal information (such as health data, racial or ethnic origin, biometric data, or trade union membership). If any such information is included in documents you upload or content you submit, we will treat it with heightened care under our security measures and Applicable Data Protection Laws. Please do not submit sensitive personal information unless it is necessary for your use of the Services.
Children. The Services are not directed at children under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at privacy@stub.africa and we will delete it promptly.
3. How we use personal information
We use personal information only for the purposes set out in this Policy. The table in Section 11 sets out our lawful bases for each processing purpose. Our main uses are described below.
3.1 Providing and operating the Services
We use your personal information to:
- create and manage your account;
- process and reconcile your financial transactions;
- generate invoices, quotes, reports, and other documents;
- process subscription payments and billing;
- provide customer support and technical assistance;
- send you transactional communications (such as payment confirmations, invoices, and technical notices); and
- connect third-party integrations you have authorised.
3.2 Payment processing
We facilitate payments through integrated third-party payment service providers (such as card schemes, instant EFT providers, and digital wallets including Apple Pay and Google Pay). When you make or receive a payment through stub:
- your payment details are passed securely to the relevant payment service provider;
- payment service providers process your data under their own privacy policies and applicable financial services regulations; and
- we receive and store transaction confirmation data, reference numbers, and payment status information needed to maintain your accounting records.
We do not store full payment card numbers. All card data is handled exclusively by PCI-DSS compliant payment processors.
3.3 Analytics, security, and service improvement
We use aggregated, de-identified, and pseudonymised data to:
- understand how users interact with the Services and improve product features;
- detect and prevent fraud, abuse, and security incidents;
- monitor the stability and performance of our systems; and
- conduct internal research and business analysis.
We do not use your personal information in raw, identifiable form for these purposes. Any data used to improve our AI features is aggregated and de-identified as described in Section 3.5.
3.4 Marketing and communications
We may send you marketing communications about stub products, features, and events where:
- You are an existing customer and the communication relates to similar products or services (existing customer exception under POPIA section 69 and UK Privacy and Electronic Communications Regulations); or
- You have given us your consent to receive marketing.
Every marketing message will include a clear, free-of-charge opt-out mechanism. You may also opt out at any time by emailing privacy@stub.africa or updating your account preferences. We will process your opt-out within 5 business days.
We may monitor and record telephone calls for training, quality assurance, dispute resolution, and compliance purposes. You will be notified at the start of any recorded call.
3.5 AI features and automated processing
stub uses artificial intelligence and machine learning (“AI”) to power features including transaction categorisation, reconciliation, anomaly detection, natural-language search and summarisation, and document generation. This section explains how we handle personal information in connection with AI.
AI sub-processors
To deliver AI features, we transmit relevant content (which may include personal information and financial data) to specialist AI providers acting as our sub-processors, including:
- Anthropic PBC
- OpenAI OpCo LLC
- Google LLC
Each sub-processor is bound by a written agreement that requires security measures consistent with those we apply ourselves.
AI training
We do not use your content in identifiable form to train our own or any third-party general-purpose AI model. We may use aggregated and irreversibly de-identified data from which all direct and indirect identifiers have been removed to improve, monitor, and benchmark our AI features. De-identified data is no longer personal information and falls outside Applicable Data Protection Laws.
Automated actions
Some AI features can take actions on your behalf within the Services, for example, drafting invoices, categorising transactions, or sending communications. Before any automated action is taken, you set the scope of authority you grant the AI. We log the inputs, decisions, and outputs of each automated action to provide you with an audit trail.
AI output limitations
AI Outputs are probabilistic and may contain errors, omissions, or inaccuracies (sometimes called “hallucinations”). AI Outputs do not constitute accounting, tax, legal, or financial advice. You must review all AI Outputs before relying on them and remain responsible for the accuracy of your records and decisions.
Automated decision-making
We do not subject you to decisions based solely on automated processing (including profiling) that produce legal or similarly significant effects, unless: (i) it is necessary for our contract with you; (ii) it is authorised by law with suitable safeguards; or (iii) you have given explicit consent. Where any such automated decision is made, you have the right to request human review, express your view, and contest the decision by contacting our Information Officer.
3.6 Legal and regulatory compliance
We use and retain personal information as required to:
- comply with tax, accounting, anti-money-laundering, and other applicable laws;
- respond to lawful requests from regulators, law enforcement, and courts;
- establish, exercise, or defend legal claims; and
- detect and prevent fraud, financial crime, and unauthorised access.
4. How we share personal information
We share personal information only as necessary for the purposes described in this Policy. We do not sell your personal information. We share it in the following circumstances:
4.1 Service providers and sub-processors
We share personal information with trusted third-party service providers who help us operate the Services, including:
- cloud hosting and infrastructure providers;
- payment processors and financial institutions (see Section 3.2);
- AI technology providers (see Section 3.5);
- customer support and helpdesk platforms;
- email delivery and communications providers;
- analytics and monitoring services;
- identity verification providers (where applicable); and
- marketing and advertising technology providers (where applicable).
All service providers are bound by written agreements that restrict their use of personal information to the services they provide to us.
4.2 Third-party integrations you authorise
If you connect a third-party application or service to stub (such as a bank feed, payment gateway, or e-commerce platform), you authorise us to share relevant data with that third party as required to provide the integration. The third party's own privacy policy governs their use of your data. We recommend you review it before enabling an integration.
AI assistants and connectors.
The Services can also be connected to third-party artificial-intelligence assistants and applications (for example, an AI assistant or "connector" offered by a third party such as Anthropic). Where you authorise such a connection, you are directing us to make your content and account information available to that AI assistant on your behalf, so that it can read, summarise, and act on that information in response to your instructions. We share your information only with an AI assistant you have authorised, and only for as long as that authorisation remains in effect. You can review or revoke a connection at any time, after which we will stop sharing your information with that assistant. Information you access through a connected AI assistant is also processed by that third party under its own terms and privacy policy, over which we have no control - we recommend you review them before connecting.
4.3 Your organisation or administrator
If you use stub through an account created for you by your employer or another organisation, we may share information about your use of the Services with that organisation to the extent necessary to manage the account and provide the Services.
4.4 Legal requirements and protection of rights
We may disclose personal information where we believe in good faith that disclosure is reasonably necessary to:
- comply with applicable law, regulation, or a lawful order from a court or regulator;
- prevent or investigate fraud, financial crime, or a serious security incident;
- protect the rights, property, or safety of stub, our users, or the public; or
- establish, exercise, or defend legal claims.
Where possible, we will notify you before disclosing your personal information in response to a legal request, unless we are prohibited from doing so.
4.5 With your consent
We may share personal information with third parties where you have given us your express consent to do so.
5. International transfers of personal information
stub is operated by a company registered in the United Kingdom. In providing the Services, your personal information may be transferred to, stored in, and processed in countries other than your country of residence, including by our sub-processors and infrastructure providers operating in the United States, the European Economic Area, and the United Kingdom.
5.1 Transfers from South Africa (POPIA)
Where we transfer personal information outside South Africa, we comply with section 72 of POPIA by ensuring that:
- the recipient is subject to a law, binding corporate rules, or a binding agreement that provides an adequate level of protection substantially similar to POPIA; or
- you have consented to the transfer after being informed that the destination country may not provide equivalent protection.
5.2 Transfers from the United Kingdom (UK GDPR)
Where we transfer personal information outside the United Kingdom, we rely, depending on the destination, on:
- UK adequacy regulations made by the Secretary of State;
- the UK Addendum to the EU Standard Contractual Clauses; or
- the UK International Data Transfer Agreement (IDTA),
in each case supplemented by appropriate additional safeguards such as encryption and access controls.
A copy of the specific transfer safeguards in place for a particular transfer is available on request from our Information Officer.
6. How long we keep personal information
We retain personal information for as long as is necessary to fulfil the purposes described in this Policy or as required by law. The table below summarises our main retention periods. Please note that these may change if legal requirements change.
| Category | Retention period | Legal basis | Notes |
|---|---|---|---|
| Account & registration data | Duration of account + 6 years | Contract; Legal obligation | Tax and accounting record-keeping |
| Financial records (invoices, transactions, ledger entries) | 5 years (SA) / 6 years (UK) from end of financial year | Legal obligation | SA Tax Administration Act s 29; UK HMRC rules |
| Payment data | As required by PCI-DSS and applicable law | Legal obligation; Contract | Handled by PCI-DSS compliant processors |
| AI interaction data (identifiable form) | 12 months from collection | Legitimate interests | Then deleted or irreversibly de-identified |
| Support and communications data | 3 years from last interaction | Legitimate interests; Legal claims | Dispute resolution, quality assurance |
| Device and usage data (logs) | Up to 24 months | Legitimate interests | Security monitoring, analytics |
| Marketing preference data | Until opt-out + 3 years | Consent; Legitimate interests | Evidence of consent / preference |
When we no longer need personal information, we securely delete or irreversibly de-identify it. You may request an export of your account content within 30 days of closing your account - see our Terms of Service for details.
7. Your rights
Depending on where you are located and the laws that apply to you, you may have the following rights in relation to your personal information. To exercise any of these rights, contact our Information Officer at privacy@stub.africa.
- Right of access: Request confirmation of whether we hold personal information about you and, if so, a copy of that information (POPIA Form 2 access request; UK GDPR Article 15).
- Right to correction: Ask us to correct personal information that is inaccurate, incomplete, or out of date.
- Right to deletion / erasure: Request deletion of your personal information where it is no longer necessary for the purpose for which it was collected, where you have withdrawn consent, or where applicable law requires it. Note that we may need to retain certain data to comply with legal obligations.
- Right to object: Object to processing based on our legitimate interests, including direct marketing. Objections to direct marketing will always be honoured. Other objections will be assessed case by case.
- Right to restrict processing: Ask us to pause processing of your personal information in certain circumstances (for example, while we verify the accuracy of the data).
- Right to data portability: Receive your personal information in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible (UK GDPR Article 20).
- Right to withdraw consent: Where processing is based on your consent, withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
- Right not to be subject to automated decision-making: Not to be subject to a decision based solely on automated processing (including profiling) that produces legal or similarly significant effects. See Section 3.5.
- Right to complain: See Section 10.
We will respond to rights requests within the time required by applicable law - generally 30 days (POPIA Form 2 requests) or one calendar month (UK GDPR requests). We may extend the response period by up to two further months for complex requests, and will notify you if we do so. We may need to verify your identity before acting on a request.
8. Cookies and similar technologies
We use cookies and similar tracking technologies (such as web beacons, pixels, and session-replay scripts) on our Website and in our Services. Cookies are small files stored on your device that help us recognise you and remember your preferences.
We use:
- Strictly necessary cookies: These are required for the Services to function and do not require your consent.
- Functional cookies: These remember your preferences and personalise your experience (for example, language and region settings).
- Analytics cookies: These help us understand how the Services are used so we can improve them.
- Advertising cookies: These help us and our partners deliver relevant advertising.
We will request your prior opt-in consent (via our cookie banner) for all cookies other than strictly necessary cookies. You may change your preferences at any time at https://stub.africa. You can also control cookies through your browser settings. Disabling certain cookies may affect the functionality of the Services.
9. Security
We take the security of your personal information seriously. We implement appropriate technical and organisational measures to protect it against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Our security measures include:
- encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256);
- role-based access controls with least-privilege provisioning;
- multi-factor authentication for administrative and privileged access;
- regular third-party penetration testing and vulnerability scanning;
- secure software development practices and code review;
- environment segregation (development, staging, production);
- comprehensive logging, monitoring, and anomaly detection;
- documented incident response and disaster recovery procedures; and
- for AI features: prompt and output isolation, data processing agreements with AI sub-processors, and configuration of AI providers to disable training on our data.
We restrict access to personal information to personnel who need it to perform their duties and who are bound by confidentiality obligations.
If we become aware of a security incident affecting your personal information, we will notify you and the relevant regulator(s) without undue delay and, where required, within the requisite deadlines.
No method of transmission over the internet or method of electronic storage is 100% secure. If you believe your account has been compromised, please contact us at privacy@stub.africa immediately.
10. How to contact us
If you have any questions, concerns, or requests relating to this Policy or our handling of your personal information, please contact:
Information Officer and Data Protection Contact:
Attention: Alex Oloo
Email: privacy@stub.africa
Post: Stub Holdings Limited, 6 Riverdale Drive, Earlsfield, SW18 4UR, London, United Kingdom
Our Information Officer is responsible for compliance with POPIA, handling access requests under POPIA and the Promotion of Access to Information Act (PAIA), and liaising with the Information Regulator. The same officer serves as our Data Protection Contact for UK GDPR purposes.
You may also lodge a complaint at any time with: Information Regulator of South Africa: inforeg@inforegulator.org.za; or UK Information Commissioner's Office: ico.org.uk.
11. Legal bases for processing
The table below sets out the lawful bases we rely on for each main processing purpose under UK GDPR Article 6 and POPIA section 11.
| Processing purpose | Categories of data | Lawful basis | Notes |
|---|---|---|---|
| Providing and operating the Services | Identity & contact; Account; Financial content | Contract | Core service delivery |
| Processing payments | Payment data; Identity & contact | Contract; Legal obligation | Required for billing |
| Operating AI features | Inputs; Outputs; AI interaction data | Contract; Legitimate interests | Core product functionality |
| Security, fraud prevention, abuse detection | All categories | Legitimate interests; Legal obligation | Protecting platform and users |
| Analytics and service improvement | Usage data; Aggregated/de-identified data | Legitimate interests | No raw personal data used for model training |
| Direct marketing (existing customers) | Identity & contact; Usage data | Legitimate interests | Opt-out available in every message |
| Direct marketing (new contacts) | Identity & contact | Consent | Opt-in required |
| Legal and regulatory compliance | As required by law | Legal obligation | Includes AML, tax, court orders |
| Establishing or defending legal claims | Relevant data | Legitimate interests; Legal obligation | |
| Non-essential cookies and tracking | Device data; Usage data | Consent | Via cookie banner |
Where we rely on legitimate interests, we have carried out a balancing test and are satisfied that our interests do not override your privacy rights. You may request a copy of our legitimate interests assessment from our Information Officer.
12. Updates to this Policy
We may update this Policy from time to time. If we make a material change, we will notify you by email or by posting a notice in the Services before the change takes effect. We will update the “Last updated” date at the top of this document. Where required by law, we will request your consent before applying changes to existing processing activities.
Previous versions of this Policy are available on request from our Information Officer.