stashi

Privacy policy

Last updated: 19 September 2026

Introduction

Stashi ("we", "us", "our") operates the Stashi mobile and web application (the "Service"), which helps self-employed tradespeople and small businesses in the United Kingdom capture, store, organise and share their business receipts.

This Privacy Policy explains what personal information we collect, why we collect it, how we use it, and the rights you have over your data. It applies to anyone who creates a Stashi account or uses the Service.

By creating an account or using the Service, you agree to the collection and use of your information as described in this policy.

Information we collect

Account information: your name, email address, and authentication details you provide when you register or sign in.

Business information: the business name and type you enter during onboarding, used to organise your receipts and label any share links you create.

Receipt information: images of receipts you upload or photograph, together with the merchant, date, amounts, VAT, category and folder details you confirm. Receipt images are stored in private storage tied to your account.

Usage information: records of how many receipts you have scanned, which plan you are on, and technical data such as device type and app activity needed to run and improve the Service.

Payment information: when you buy a paid plan, payment is processed by our payment provider, Stripe. We do not store your full card number on our servers.

How we use your information

To provide the Service: creating your account, storing and organising your receipts, generating accountant-ready exports, and creating the share links you request.

To extract receipt data: when you scan a receipt, we send the image to an AI model to read the merchant, date and amounts, then return those details for you to confirm before anything is saved.

To manage your subscription: processing payments, tracking your plan and scan allowance, and sending you renewal and account-related notices.

To keep the Service secure and working: detecting and preventing abuse, fixing bugs, and improving performance and features.

To contact you: about your account, important changes, legal obligations, and — only where you have agreed — product updates.

Legal basis for processing (UK GDPR)

We process your personal data under the following lawful bases:

Performance of a contract: to provide the Service you signed up for, including storing your receipts and processing your subscription.

Legitimate interests: to keep the Service secure, prevent fraud, and improve how it works, where this does not override your rights.

Legal obligation: where we are required to keep records, for example for tax or accounting compliance.

Consent: for optional communications and any processing that requires it. You can withdraw consent at any time without affecting processing already carried out.

Receipt data and special categories

Receipts may occasionally reveal personal details, but Stashi is not designed to process special category data under Article 9 of the UK GDPR.

Please do not upload documents that contain sensitive information unrelated to your business expenses. We only process the receipt content needed to extract and store expense data as described in this policy.

How we store and protect your data

Your receipt images and extracted data are stored securely and are tied to your account. Only you can access your own receipts and folders, unless you create a share link that explicitly exposes selected receipts to others.

Access to your data is restricted to authorised personnel and systems, and we apply technical and organisational measures such as encryption in transit, access controls and regular security review.

No system is perfectly secure. While we work to protect your data, we cannot guarantee absolute security.

Sharing and disclosure

We do not sell your personal data or receipt content.

We share information only in these limited circumstances: with service providers who help us run the Service (such as our hosting, AI extraction and payment providers) under appropriate confidentiality and data-protection terms; when required by law, court order or legitimate regulatory request; and in connection with a sale, merger or transfer of our business, subject to confidentiality.

Our providers process data only on our instructions and for the purposes of delivering the Service to you.

Share links

You may create share links to let your accountant or others view selected receipts. A share link only ever exposes the receipts you explicitly select, and never your full library.

Share links can be revoked or set to expire. Anyone with the link can view the shared receipts until you disable or delete the link, so keep links to people you trust.

AI-powered receipt extraction

When you scan a receipt, we use an AI model to read the image and suggest the merchant, date, currency, amounts and category. These are suggestions only.

You confirm or correct the extracted details before they are saved. We are not responsible for the accuracy of any receipt data you do not review, and you should always check important figures yourself.

Data retention

We keep your receipts and account data for as long as your account is active, so you can access your records and exports.

If you delete your account, we permanently delete your receipts, folders, share links and associated data, except where we are legally required to keep some records for longer.

If you cancel a paid subscription but keep your account, your receipts remain stored and accessible to you.

Your rights

Under the UK GDPR you have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive a copy of it in a portable format, and withdraw consent where processing relies on it.

You can exercise most of these rights directly in the app — for example by exporting your data or deleting your account from the Account screen.

To make any other request, contact us using the details below. We will respond within one month, and you have the right to complain to the Information Commissioner's Office (ICO) if you are unhappy with how we handle your data.

International transfers

Your data may be processed by our providers outside the United Kingdom. Where this happens, we use appropriate safeguards such as standard contractual clauses to make sure your data is protected to UK standards.

Children's privacy

The Service is intended for businesses and self-employed individuals. It is not directed to anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.

Cookies

The Service uses essential technical storage needed to function and to keep you signed in. We do not use advertising cookies or sell data to advertisers.

Changes to this policy

We may update this Privacy Policy as the Service evolves. We will notify you of significant changes through the app or by email, and the "last updated" date will reflect when the change took effect.

Contact us

If you have any questions about this Privacy Policy or your personal data, contact us at support@stashi.app.