Acceptable Use Policy

Effective Sep 1, 2026

Overview

This Acceptable Use Policy ("AUP") sets out the rules that apply to your use of the stub Platform and Services operated by Stub Holdings Limited (company number 14323727) ("stub", "we", "us").

This AUP forms part of, and is incorporated into, our Terms of Service. Words defined in the Terms of Service have the same meaning here. Where this AUP and the Terms of Service overlap, both apply; where they genuinely conflict, the Terms of Service prevail.

Breaching this AUP is a breach of the Terms of Service, and the consequences set out in What happens if you breach this policy apply.

stub is bookkeeping and financial management software. It holds the books, invoices, bank feeds, payment pages, documents and AI agents that a business runs on. The rules below reflect that: most of them exist because misuse of stub does not just affect stub, it affects your customers, your suppliers, your bank, your payment provider and your regulator.

Who this policy applies to

This AUP applies to everyone who uses the Services, and you are responsible for each of them complying with it:

  • you, as the account holder and as the business whose books are kept in stub;
  • anyone you invite into a business in stub — employees, bookkeepers, accountants, contractors and any other member or guest, whatever their role or permission level;
  • anything you connect to your stub account — apps you install, integrations you authorise, and any software using an API key or OAuth credential issued for your account; and
  • AI Features you authorise to act on your behalf, within the scope of authority you have granted them.

An act or omission by any of the above is treated as your act or omission for the purposes of this AUP.

The general rules

You must not use the Services:

  1. for any unlawful purpose, or in breach of any law, regulation, licence condition or professional obligation that applies to you, in any jurisdiction in which you operate;
  2. to record, present or transmit information you know to be false or misleading — including falsified books, back-dated records, fictitious invoices, or financial statements you know do not reflect reality;
  3. to infringe anyone's intellectual property rights, or to submit content you do not have the right to submit;
  4. to harass, abuse, threaten, defame, impersonate or discriminate against any person;
  5. to distribute malware, or to upload or transmit any code intended to damage, disrupt, or gain unauthorised access to any system;
  6. to interfere with, probe, or circumvent the security, authentication, authorisation, entitlement, quota or rate-limiting features of the Services;
  7. to place unreasonable or disproportionate load on the Services, or to degrade the experience of other customers;
  8. to scrape, spider, crawl, harvest or bulk-extract data from the Services other than through interfaces we provide for that purpose and within their documented limits;
  9. to resell, sublicense, or make the Services available to third parties as your own product, except where we have agreed that in writing; or
  10. to build, train, benchmark or evaluate a competing product, model or dataset.

Rules for specific parts of the Service

Your account and the people in it

  • Keep your credentials secret. Do not share a login, and do not use anyone else's. Where a person needs access, invite them as a member of the business rather than handing over a password.
  • Grant each member the least access they need, and remove members promptly when they leave or their role changes. You are responsible for what your members do.
  • Do not accept or send an invitation to join a business you are not genuinely entitled to access.
  • Only create a business in stub for an entity you own, control, or are authorised in writing to act for. Accountants and bookkeepers acting for clients must have that client's authority.
  • Tell us at security@stub.africa as soon as you suspect any unauthorised access to your account, a business, an API key, or a connected app.

Your books and financial records

  • Use stub to keep a genuine record of your business's activity. Do not use it to create or maintain records intended to deceive a bank, an investor, an insurer, a tax authority, an auditor, or a counterparty.
  • Do not use invoicing, quoting, ordering, stock, expense or journal features to produce documents for transactions that did not occur, or to disguise the nature, source or ownership of funds.
  • You are responsible for the accuracy, completeness and lawfulness of everything you file, submit or publish on the basis of data held in stub, including tax and statutory returns. Reports, insights and sales-tax calculations generated by the Services are aids, not a substitute for your own review or for professional advice.

Bank feeds and connected financial accounts

The Services connect to third-party banking, payment, payroll, and commerce providers on your instruction.

  • You may only connect an account that belongs to the business in stub, or that you are expressly authorised by the account holder to connect. Connecting someone else's account without their authority is a serious breach of this AUP and may be a criminal offence.
  • You must comply with the terms of the provider whose account you connect. If that provider suspends or revokes access, or if their terms prohibit the connection, you must stop using the integration.
  • Do not use a connection to retrieve, retain or share transaction data for any purpose other than operating the business it belongs to.
  • Do not use automated statement retrieval, imports or reconciliation to poll a provider more aggressively than the provider permits, or to work around a limit the provider has set.
  • Revoke connections you no longer need, and disconnect an account as soon as the business stops being entitled to it.

The Services let you collect payment from third parties, including through hosted payment pages, payment links, and payment buttons on invoices and receipts.

  • You may only collect payment for goods or services that you genuinely supply, in the name of the business that supplies them.
  • Do not use a payment page or link to impersonate another business, to collect on behalf of an undisclosed third party, or to act as a payment facilitator, aggregator, or money transmitter for others.
  • Do not use the Services to test, validate or enumerate payment card numbers or bank details, to process payments you know to be fraudulent, or to process refunds, credits or reversals for a purpose other than a genuine commercial one.
  • Do not use the Services in connection with money laundering, terrorist financing, sanctions evasion, or any transaction involving a person or jurisdiction subject to UK, EU, UN, US or other applicable sanctions.
  • Your payment provider's own acceptable use and prohibited business rules apply in addition to this AUP. Where they are stricter, they govern.

Invoices, quotes, contracts, delivery notes, receipts, statements and similar documents can be sent to third parties and viewed through a shareable link without the recipient logging in.

  • Anyone with the link can view the document. Treat a link as sensitive, share it only with the intended recipient, and do not put anything in a document you are not willing for a link-holder to see.
  • Do not use documents or shared links to phish, to solicit payment to an account that is not yours, to impersonate another business, or to distribute content unrelated to the transaction the document records.
  • Do not put personal data, payment card details, tax identifiers, bank credentials or other sensitive information into free-text, notes, description or reference fields that are not specifically intended to capture it.
  • Where you attach or embed third-party content — logos, images, terms, or contract text — you must have the right to use it.

Messages, reminders and notifications we send for you

The Services send email and messages on your behalf, including invoice delivery, payment reminders, statements, and automated follow-ups.

  • You must have a lawful basis to contact every recipient, and you must comply with the direct-marketing and electronic-communications law that applies to them (including PECR and the UK GDPR, POPIA, and equivalent laws elsewhere).
  • Send transactional messages only to the counterparties they concern. The Services are not a bulk-email, newsletter, or marketing-campaign tool, and must not be used as one.
  • Do not use the Services as a mail relay, or to send unsolicited, deceptive or repetitive messages. Honour opt-outs and stop-contact requests.
  • Do not configure reminders, schedules, recurring documents or automations to send at a volume or frequency that would be harassing to the recipient or abusive of the sending infrastructure.
  • We may cap, throttle, queue, or stop sending on your behalf where we reasonably believe your sending is harming recipients, other customers, or the deliverability of the Services.

Files, uploads and imports

  • Do not upload malware, or files crafted to exploit a parser, viewer, extraction or optical-character-recognition pipeline.
  • Do not upload content that is illegal, obscene, or that you do not have the right to store and process — including third-party personal data you have no lawful basis to share with us.
  • Use file storage for records related to your business and its books. The Services are not general-purpose file hosting, backup, or content distribution, and must not be used to store or serve unrelated material.
  • Do not upload or import data at a volume or rate designed to exhaust storage, processing or extraction capacity.

AI Features and automated agents

The AI-specific terms in the "AI Features" section of the Terms of Service apply in full and are not repeated here. In addition, when using AI Features you must not:

  • submit inputs designed to bypass safety, accuracy, entitlement or content-filtering controls, including prompt injection and jailbreaking;
  • attempt to extract system prompts, model weights, retrieval indices, embeddings, or training data, or to reconstruct another customer's data through the AI Features;
  • use inputs, outputs or any other content obtained through the Services to train, fine-tune, evaluate or benchmark any AI model or system;
  • present an output as human-authored work, or as the advice of a qualified accountant, auditor, tax adviser or lawyer, unless such a person has in fact reviewed and approved it;
  • authorise an AI Feature to take any action you would not be lawfully entitled to take yourself, or grant it a scope of authority wider than the task requires; or
  • rely on an automated action for a material accounting, tax, payment or regulatory outcome without human review.

You choose the scope of authority you grant, you can revoke it at any time, and actions taken within that scope bind you. We may require human confirmation for categories of automated action, and may suspend the ability of AI Features to act on your behalf where we reasonably believe they are being misused, are malfunctioning, or are producing outputs that pose a risk.

The API, API keys and connected apps

  • API keys and OAuth credentials issued for your account are secrets. Do not embed them in client-side code, public repositories, mobile applications, or anywhere a third party can read them. Rotate them if they are exposed and tell us at security@stub.africa.
  • Request only the scopes your integration needs, and use the data you receive only for the purpose the business authorised.
  • Respect published rate limits, pagination and quotas. Do not run parallel clients, rotate keys, or use multiple accounts to exceed a limit that applies to you.
  • Do not use the API to mirror, replicate or re-host stub data as a competing service, or to build a product that substitutes for the Services.
  • If you publish an app that other stub customers install, you are responsible for its security, its handling of their data, and its compliance with this AUP. We may suspend or remove an app that breaches it.
  • Undocumented endpoints, internal interfaces, administrative tooling and pre-release features are not part of the Services. Do not call them, and do not rely on them.

Security testing and vulnerability reporting

  • Do not conduct penetration testing, vulnerability scanning, fuzzing, load testing, stress testing or denial-of-service testing against the Services without our prior written permission.
  • Do not attempt to access data belonging to another customer, escalate privileges, or bypass tenancy, entitlement or feature-flag boundaries.
  • If you discover a vulnerability, report it to security@stub.africa promptly, give us reasonable time to remediate, do not access or retain more data than is needed to demonstrate the issue, and do not disclose it publicly before we have fixed it.
  • We will not pursue a good-faith researcher who follows the paragraph above.

Other people's personal data

When you put personal data into stub — your customers, suppliers, employees or their staff — you are the controller of that data and we process it for you in terms of the privacy policy (and/or data processing agreement, if entered into and applicable).

  • You must have a lawful basis for putting that data into stub and for the purposes you use it for, and you must give the individuals concerned whatever notice the law requires.
  • Do not upload special-category data (health, biometric, political, religious, trade-union, sexual-life or similar), children's data, or criminal-offence data except where the Services are specifically intended to hold it and you have a lawful basis to do so.
  • Do not use the Services to build marketing lists, profile individuals, or enrich, sell or share personal data outside the operation of your business.
  • Respond to data-subject requests that reach you as controller. Where one reaches us instead, we will refer it to you.

Businesses and activities we do not support

You must not use the Services to keep the books of, take payment for, or otherwise operate a business engaged in:

  • anything illegal in any jurisdiction where the business operates or its customers are located;
  • regulated financial services, deposit-taking, lending, insurance, money transmission, or investment activity carried on without the licence or authorisation it requires;
  • dealing in cryptoassets on behalf of third parties, or unregistered cryptoasset exchange or custody activity;
  • pyramid schemes, Ponzi schemes, chain letters, matrix schemes, get-rich-quick schemes, or multi-level marketing whose returns depend on recruitment;
  • weapons, ammunition, explosives, or controlled military or dual-use goods sold without the required licence;
  • controlled drugs, novel psychoactive substances, or unlicensed pharmaceuticals;
  • counterfeit, stolen, or infringing goods, or the circumvention of technical protection measures;
  • human trafficking, forced labour, prostitution where unlawful, or any sexual content involving minors or non-consenting adults;
  • gambling, betting, lotteries or gaming of chance operated without the required licence in each jurisdiction served;
  • the sale of personal data, credentials, hacking services, malware, or tools whose principal purpose is unauthorised access;
  • activity involving a person, entity, vessel or jurisdiction subject to applicable sanctions; or
  • any activity your bank, payment provider, or other integrated provider prohibits under its own terms.

If you are unsure whether an activity is supported, ask us at legal@stub.africa before you rely on the Services for it.

Reporting a problem

WhatWhere
A security vulnerability, or suspected unauthorised access or AI activitysecurity@stub.africa
Misuse of the Services by another user, including a fraudulent invoice, payment page or linklegal@stub.africa
A privacy concern or a data-subject requestprivacy@stub.africa
Anything elsehi@stub.africa

Tell us what you saw, where you saw it, and when. Include the document, link, business or account reference where you have one.

What happens if you breach this policy

Where we reasonably believe this AUP has been breached, or is likely to be breached, we may take any action we consider appropriate, including:

  • investigating the activity, and asking you for information about it;
  • limiting, suspending or withdrawing a specific capability — for example sending on your behalf, API access, an integration, a shared link, a payment page, or the ability of AI Features to take automated actions — while we investigate;
  • removing or disabling access to content;
  • suspending or terminating your access to the Platform and the Services, immediately and without refund where the breach is serious;
  • bringing legal proceedings against you, and recovering the costs of doing so; and
  • disclosing information to law enforcement, regulators, or an affected provider, where we are required or entitled to do so.

We will act proportionately, and will normally tell you what we have done and why, unless telling you would prejudice an investigation or we are prohibited from doing so. Nothing in this section limits any other right or remedy available to us, including under the Terms of Service.

Changes to this policy

We may update this AUP as the Services change and as new forms of misuse appear. The current version is always available at this page. Where a change materially increases your obligations, we will give you notice in accordance with the "Notices" section of the Terms of Service. Your continued use of the Services after a change takes effect is acceptance of it.

Contact

Stub Holdings Limited (company number 14323727)

General: hi@stub.africa · Legal notices: legal@stub.africa · Privacy: privacy@stub.africa · Security: security@stub.africa

This AUP is governed by the laws of England and Wales, and the dispute resolution provisions of the Terms of Service apply to it.