numstack

Numstack Privacy Policy

Effective date: 27 September 2026

1. Controller and contact

NSS Software Ltd., United Kingdom is the controller of personal data processed through Numstack's app, website and support services.

Address: 128 City Road, London, EC1V 2NX, United Kingdom. Privacy: privacy@nsssoftware.co.uk. Deletion requests: support@nsssoftware.co.uk.

Numstack is restricted to users aged 18 and over. Contact us if a child has provided personal data.

2. Personal data

We obtain data from you, your use of Numstack, and payment and mobile top-up providers:

Account and number details are required for the corresponding services. Reminders, push notifications and analytics are optional. Stripe processes payment credentials; we do not store full card numbers or security codes. See Stripe's Privacy Policy.

3. Purposes and legal bases

Purpose Legal basis
Accounts, payments, top-ups, requested reminders, support, closure and service messages Contract performance
Security, abuse prevention, error investigation and disputes Legitimate interests in service security, reliability and protection of legal rights
Required records and lawful requests Legal obligation
Optional usage analytics Consent

Scheduled top-ups follow your instructions and depend on available funds and provider results.

We use PostHog only with consent. Declining does not restrict service. Analytics excludes names, emails, phone numbers, Numstack account IDs, exact payment amounts and payment credentials. We do not record session replays. Random identifiers distinguish installations or browsers. Website analytics uses first-party cookies and browser storage only after you allow it.

For the app, withdraw consent in Account → Settings → Usage analytics. For the website, open Analytics settings in the footer and choose Reject. App and website choices are separate and apply to that installation or browser. Website choices are stored for 6 months, including a timestamp and notice version. Rejecting analytics does not restrict access. Withdrawal stops new collection and clears local analytics identifiers and unsent data; it does not automatically delete events already received by PostHog or affect the lawfulness of prior processing.

4. Recipients and international transfers

Relevant data is shared with:

Processors are subject to applicable data-protection agreements and law.

Our servers and database are in Germany; PostHog uses EU Cloud. Other processing may occur in the United States and other countries, including the recipient operator's country. Resend stores service email data in the United States.

Transfers subject to UK or EU transfer restrictions rely on recognised adequacy decisions or appropriate safeguards, including EU Standard Contractual Clauses and the UK Addendum where applicable. Contact us for details and copies of safeguards.

5. Retention

Data Period
Account and number data Until no longer needed for the account and its closure, subject to lawful retention below
Analytics Up to 12 months from the event, or earlier where erasure is legally required following consent withdrawal or a request
Temporary address for deletion confirmation Up to 7 days after deletion; removed earlier on acceptance by the email provider or permanent sending failure
Required accounting and tax records 6 years from the relevant financial year-end
Ordinary technical and security logs Up to 90 days from creation
Support correspondence Up to 24 months after request closure
Numstack backups Up to 30 days from creation

Necessary records may be kept longer for legal obligations, ongoing disputes, investigations or claims. Deleted backup data is excluded from ordinary use until expiry; deletion is reapplied after restoration.

Resend separately retains message and delivery records: its standard period is 30 days, with 7-day backups. Independent controllers apply their own lawful retention periods.

We protect data through access controls and encryption.

6. Account deletion

Request deletion in Account → Settings, without an additional email. Access ends, schedules stop and notifications are disabled. Final deletion may await pending transactions or balance review.

We erase profile and sign-in data and direct number identifiers, and attempt to send confirmation. Email delivery does not determine whether deletion is complete.

Necessary transaction records may remain and are not necessarily anonymous. Analytics, backups and provider records follow their applicable retention and deletion rules, subject to your statutory rights.

7. Your rights

Subject to applicable law, you may request access, correction, erasure, restriction and data portability, and withdraw consent at any time.

Right to object: you may object to processing based on legitimate interests on grounds relating to your situation.

Use the contacts above or another valid verbal or written channel. We may require proportionate identity verification and information to locate records. Analytics is not linked to your email or account. We explain any lawful refusal or limitation and available remedies.

You may complain to the UK Information Commissioner's Office or another competent local authority.

8. Changes

We may update this policy at any time and publish the revised effective date. We provide notice and obtain consent where required by applicable law.