Privacy Policy for Stackive
Last updated: 4 March 2026

Stackive (“we”, “us”, or “our”) respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use the Stackive mobile application, website, and related services (collectively, the “Services”).

This policy is drafted to align with the Protection of Personal Information Act, 4 of 2013 (POPIA) of South Africa and, where applicable, the EU General Data Protection Regulation (GDPR).

1. Who We Are

Responsible Party: Stackive
Contact details:
Website: https://stackive.co.za
Email: kinohogan@gmail.com

Stackive determines the purpose and means of processing your personal information and is therefore the “Responsible Party” under POPIA.

2. Information We Collect

We are committed to data minimisation and intentionally limit the personal information we collect.

2.1 Account and Login Information
Account authentication and login information is handled and securely stored by Google Firebase Authentication. Stackive does not directly store passwords or raw authentication credentials on its own servers.

2.2 Profile Information
We collect your name, email address, and preferred currency when you create an account. Profile photos, where used, are stored locally on your device only. Stackive does not upload, store, or process user profile photos on its servers.

2.3 Financial Data You Provide
Stackive allows you to manually enter financial information including transaction amounts, descriptions, categories, savings goals, and account balances. This data is self-reported and entered voluntarily. Stackive does not connect to any bank accounts or financial institutions.

2.4 App Data Stored via Cloud Firestore
We use Google Cloud Firestore, a cloud-hosted database provided by Google Firebase, to store basic app data necessary for the operation of Stackive. This may include:

  • User preferences and app settings
  • Self-reported financial goals, budgeting inputs, and non-bank transactional data you choose to enter
  • Product reminders (premium feature)
  • Savings goals and progress

Data stored in Firestore is associated with your account and is subject to Google Firebase’s security infrastructure and data handling practices. Firestore data is stored on Google’s servers, which may be located outside of South Africa. Where this occurs, we ensure appropriate safeguards are in place in accordance with POPIA and GDPR requirements.

2.5 Consent Records
We record when you accept our Privacy Policy, Terms of Use, and age confirmation, including timestamps. These records are maintained for compliance purposes.

2.6 Usage and App Data
App usage data and interactions (in aggregated or pseudonymised form), device information such as device type and operating system, and IP address and approximate location (used for security and analytics purposes).

2.7 Security and Audit Data
We maintain local audit logs of security-relevant events such as login attempts, data exports, and account changes. These logs are stored on your device and are included in data exports upon request.

2.8 Information You Choose to Provide
Communications you send to us (support requests or feedback).

We do not intentionally collect sensitive personal information or special personal information as defined under POPIA.

3. How We Use Your Information

We process personal information lawfully and minimally for the following purposes: to provide, operate, and improve Stackive; to personalise insights, budgeting tools, and recommendations; to communicate with you about your account or updates; to respond to support requests; to comply with legal and regulatory obligations; and to prevent fraud, misuse, or security incidents.

4. Legal Grounds for Processing

We process your personal information based on one or more of the following lawful grounds: your consent (recorded at account creation with timestamps), performance of a contract with you, compliance with legal obligations, and our legitimate interests, provided these do not override your rights.

5. Sharing of Personal Information

We do not sell your personal information.

We share limited information only where necessary: Google Firebase (including Firestore and Authentication) for secure authentication, cloud data storage, and app infrastructure; Apple’s StoreKit for subscription and payment processing; service providers who assist in operating the Services (e.g. hosting or analytics), using aggregated or anonymised data where possible; and regulatory or law enforcement authorities where legally required.

We do not share private financial credentials, passwords, or locally stored profile photos.

All third parties are required to maintain appropriate confidentiality and security safeguards.

6. International Data Transfers

If personal information is transferred outside South Africa — including via Google Cloud Firestore, whose servers may be located internationally — we ensure that the recipient is subject to laws or agreements providing an adequate level of protection, or that appropriate safeguards are in place, consistent with POPIA and GDPR requirements.

7. Data Security

We implement reasonable technical and organisational measures to protect personal information, including:

  • Encryption at rest: All locally stored data is encrypted using AES-256-GCM via Apple’s CryptoKit framework. Encryption keys are stored in the device Keychain, protected by the device passcode.
  • Encryption in transit: All data transmitted between the App and our servers uses Transport Layer Security (TLS 1.2 or higher).
  • Biometric authentication: Optional Face ID or Touch ID protection for app access.
  • Session management: Automatic session timeout after a configurable period of inactivity (default: 30 minutes).
  • Secure deletion: Account deletion uses secure data overwriting to prevent recovery of deleted information.
  • Jailbreak detection: The App detects modified devices and warns users of potential security risks.

Authentication and cloud data storage services are managed through Google Firebase, which applies industry-standard security practices. Sensitive credentials are not stored by Stackive. Profile photos remain on the user’s device and are not transmitted to our systems.

While we take security seriously, no system is completely secure, and absolute security cannot be guaranteed.

8. Data Retention

We retain personal information only for as long as necessary to fulfil the purposes outlined in this policy. Specifically:

  • Active accounts: Data is retained for the duration of your account’s active use.
  • Inactive accounts: If your account is inactive for a continuous period of two (2) years, we may delete or anonymise your data. You will be notified before any such deletion occurs.
  • Account deletion: Upon account deletion, all associated data — including Firestore records, local data, consent records, and audit logs — is permanently and irreversibly removed.
  • Legal obligations: Data may be retained longer where required or permitted by law.

9. Your Rights

Subject to applicable law (including GDPR Articles 15-22 and POPIA Section 23-25), you have the right to:

  • Access your personal information
  • Rectification — request correction of inaccurate data (available in-app via Settings)
  • Erasure — request deletion of your account and all associated data (available in-app via Settings > Delete Account)
  • Data portability — export all your data in a machine-readable format (JSON) from within the App
  • Object to processing — object to certain types of data processing
  • Withdraw consent — withdraw your consent for data processing at any time. Withdrawal of consent may result in the deletion of your account
  • Restrict processing — request that we limit the processing of your data in certain circumstances

To exercise these rights, you may use the relevant features within the App or contact us using the details in Section 1.

10. Cookies and Analytics

We may use cookies or similar technologies to improve functionality and analyse usage. You may manage cookie preferences through your device or browser settings.

11. Children’s Privacy

Stackive is not intended for individuals under the age of 16, in accordance with GDPR Article 8. We do not knowingly collect personal information from children under 16. Age confirmation is required during account creation. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted within the app or on our website, and the updated version will be effective from the stated date. We will notify you of material changes through the App or via email.

13. Complaints

If you believe we have not complied with applicable data protection laws, you may lodge a complaint with the Information Regulator of South Africa:

Information Regulator (South Africa) — Website: https://inforegulator.org.za

For users in the European Economic Area, you may also lodge a complaint with your local supervisory authority under GDPR Article 77.

14. Contact Us

If you have questions or concerns about this Privacy Policy, our data practices, or wish to exercise your data rights, please contact us via the details available on https://stackive.co.za or email kinohogan@gmail.com