Legal Privacy policy
What we hold, and why.
PaymentDue holds your business's records so it can show you who owes you money. This says exactly what that means, who else ever sees any of it, and how to get it back or have it deleted.
Last updated 18 September 2026
Who is responsible
This policy is issued under the Protection of Personal Information Act (POPIA) by:
- Responsible party
- PaymentDue, a South African sole proprietorship
- Information officer
- The proprietor, reachable at the address below
- privacy@paymentdue.co.za
The two hats we wear
This matters more than it sounds, because it decides who you ask for what.
- For your own account — your name, your email address, your billing — we are the responsible party. Ask us directly.
- For your customers' records, which came out of your accounting system, you are the responsible party and we are your operator. We hold them on your instruction and do nothing with them that you have not asked for. If one of your customers asks what you hold about them, the answer is yours to give — and everything we hold is visible to you in the app.
What we collect
When you open an account
- Your email address, and your name if you give one.
- Your password, stored only as a hash. We cannot read it, which is why a forgotten password is reset rather than looked up.
- The name of your business, and the companies you set up.
From the accounting system you connect
When you connect Xero, QuickBooks Online or Zoho Books, PaymentDue reads and stores:
- Your customers — name, email address, phone number and VAT number, as your accounting system holds them.
- Your invoices — number, dates, amounts, what is still owed and the status.
- The connection itself — the access and refresh tokens that let PaymentDue keep reading, encrypted at rest.
PaymentDue only reads. It does not create, change or delete anything in your accounting system.
When reminders go out
We keep a record of every reminder: who it was addressed to, when it was attempted, the exact words that went, and whether it arrived or failed. That record is what lets you answer “did we ever chase this?”, so it is kept rather than discarded.
When you use the service
- An audit log of security-relevant actions — signing in, changing a password, connecting or disconnecting an accounting system, an administrator locking an account. Each entry records when, who, what, and the internet address the request came from.
- Sessions, so you stay signed in and can sign out everywhere.
- Billing records — what you were invoiced, for how many companies, and whether it was paid.
When you write to us
The contact form on this site stores what you type — name, email address, and the company, phone number and message if you give them — together with the internet address it was sent from, which is what stops the form being used to flood us. Only an administrator reads it.
When you visit this website
Nothing until you say yes. No analytics script loads and no analytics cookie is set until you accept on the banner. Accepting loads Google Analytics, which sets a cookie identifying your browser across visits so we can see which pages are read. Declining is remembered just as firmly, and you can change your mind from Cookie settings in the footer at any time.
The app at app.paymentdue.co.za stores your session and a few preferences in your browser. Those are not tracking and there is no way to turn them off short of not signing in.
Why we hold it, and on what basis
- To provide the service you asked for — your account, your records, your reminders. This is the contract between us.
- To bill you, and to keep the invoices tax law requires us to keep.
- To keep the service secure — the audit log and the addresses in it exist to answer “who did that, and from where?”. This is our legitimate interest, and yours.
- To understand which pages of this site are useful, with your consent, and only with it.
We do not sell personal information, and we do not use it for advertising. We do not use one business's records to do anything for another.
Who else sees it
Only the suppliers it takes to run the service, each doing one job:
- Microsoft Azure — runs the application and the database.
- Google Firebase — serves this website and the app to your browser.
- Google Analytics — website statistics, only if you accepted.
- Our email provider — delivers reminders, password resets and confirmations.
- The accounting system you connected — which is where your records came from, and which you have your own relationship with.
We will also hand over information where the law requires it. Some of these suppliers process data outside South Africa, which POPIA allows where the receiving country or the supplier's contract provides comparable protection.
How it is protected
- Everything travels over an encrypted connection.
- Passwords are stored as hashes and never in a form anybody can read.
- The tokens that reach your accounting system are encrypted where they are stored.
- Each business's records are separated at the database, so a request made for one company cannot return another's.
- Sign-in is locked after repeated wrong passwords.
No system is perfectly safe, and we will not pretend otherwise. If a breach puts your information at risk, we will tell you and the Information Regulator, as POPIA requires.
How long it is kept
- Your records, for as long as your account is open. Disconnecting an accounting system erases the records that came from it.
- When you close your account, what we hold for the companies nobody else is left in is deleted — customers, invoices, reminders and the connection. Nothing in your accounting system is touched.
- If nothing has to outlive it, the account goes too, and your email address is free to open a new one with. That is what happens to anybody we have never invoiced.
- Where something does have to outlive it — a company carrying on with other people in it, or invoices we are required to keep — we keep the row those records point at, deactivated and stripped of everything personal. Your email address is released even then.
- Invoices we have sent you, and the audit log, outlive the account. Tax law requires the first, and an invoice has to carry the name it was issued to. The second is a security record that would be worth nothing if the person it describes could erase it.
Your rights
Under POPIA you may:
- ask what we hold about you, and get a copy;
- have it corrected if it is wrong;
- have it deleted, except where we are required to keep it;
- object to a particular use;
- complain to the Information Regulator.
Most of this you can do yourself in the app, immediately. For the rest, write to privacy@paymentdue.co.za and we will answer within a reasonable time and at no charge.
The Information Regulator of South Africa can be reached at enquiries@inforegulator.org.za, or at inforegulator.org.za. You are entitled to complain to them whether or not you have raised it with us first, though we would like the chance.
Children
PaymentDue is a tool for businesses and is not meant for anybody under 18. We do not knowingly collect information about children.
Changes
When this policy changes in substance we will say so in the app or by email, and the date at the top of this page will change. We will not quietly broaden what we do with your information.
See also the terms and conditions, or write to us on the contact page.