SlipStack handles your business's financial paperwork, so we hold ourselves to a simple standard: your documents live in your accounts, we collect only what the service needs, and South Africa's Protection of Personal Information Act (POPIA) is the floor — not the ceiling.
POPIA compliance
SlipStack processes personal information in line with the Protection of Personal Information Act, 2013 (POPIA):
Lawful, minimal processing — we collect only what's needed to read your receipts, file them, and run your account: your business details, WhatsApp number, email address, and the receipts you choose to send us.
Purpose limitation — your data is used to deliver the service you signed up for. We never sell it, rent it, or use it for third-party advertising.
Consent for marketing — optional tips and product emails are sent only with your consent, and every one carries a one-click unsubscribe that takes effect immediately.
Cross-border safeguards — where data is processed outside South Africa (our servers are in the European Union), it's done under section 72 of POPIA with providers bound by equivalent data-protection standards.
SlipStack is deliberately built so that we are the pipeline, not the vault:
Receipt images and PDFs are filed to your own Google Drive — organised, named, and always yours to open, move, or download.
Your cost dashboard is a Google Sheet in your own Google account, not a report locked inside our app.
Accounting entries post into your own Xero organisation, with the receipt attached for audit.
If you ever leave, everything already lives with you. No lock-in, no export ransom.
Google access is granted by you via Google's own consent screen and can be revoked at any time from your Google account settings.
Security practices
Encryption in transit — all traffic to SlipStack is served over HTTPS/TLS; the same goes for our connections to Google, Xero, WhatsApp, and payment providers.
Verified webhooks — inbound messages and payment notifications are cryptographically signature-checked before we act on them, with replay protection.
Expiring, signed links — account-setup links are cryptographically signed and expire automatically; they can't be forged or reused indefinitely.
Least-privilege access — production credentials are locked down on the server, kept out of the codebase, and access to production is restricted.
Daily off-site backups — the database is backed up off-server every day, so your records survive a hardware failure.
Monitored in production — errors are tracked in real time so problems are found and fixed fast.
Payments
Subscriptions are processed by Paystack, a PCI-DSS-compliant payment provider. Your card details never touch SlipStack's servers — we only receive confirmation that a payment succeeded.
What happens when AI reads your slip
When you send a receipt, the image is passed to our AI extraction partners for one job only: reading the vendor, date, total, and VAT off the slip. The extracted details are then filed to your Drive, Sheet, and accounting system.
Receipt data is never sold and never used for advertising. Anything we retain is kept solely to run your account and meet the record-keeping obligations below.
Retention & deletion
Account and receipt records are kept while your account is active, and for 5 years afterwards to satisfy South African tax and audit record-keeping requirements — then deleted.
Receipts already filed to your own Drive, Sheet, and accounting system are yours and are untouched by anything we delete on our side.