Steinfin works with sensitive accounts receivable and customer information. Our approach is simple: use only the information the service needs, keep access controlled, and leave you in control of the connection.
Steinfin works mainly with business accounts receivable information and business contact details. That does not make privacy less important: business contacts are still personal data, and we handle client data as a processor under a data processing agreement, in line with GDPR.
We work with systems such as Xero, QuickBooks and Sage. The connection is set up from your own account, using the access you grant, and it stays under your control.
Steinfin is a managed service. Our team needs invoice and customer information to follow up, handle replies and review exceptions. We would rather say that plainly than pretend no one ever sees your data.
Steinfin's role is accounts receivable operations. We use payment information, such as payment status and remittance details, to keep accounts up to date. The money itself never passes through us.
Our website and its forms are served over HTTPS, and supported accounting platforms connect through their own encrypted connections.
Automation and AI can help organise accounts, spot what needs attention and prepare routine work. People review what goes to your customers, and commercial decisions stay with you. Ask us which tools would process your information.
We use providers for hosting, email delivery and accounting or workflow software. They may only use data to provide their service to us. Contact us for the current list.
We contact your customers only about their own invoices, using the contacts in your records and the rules you agree with us. We do not share one customer's details with another, or disclose more than the follow-up needs.
Details are in our privacy policy.
We notify affected clients and, where required, the relevant authorities. Think you have found a security issue on our website? Email [email protected].
Read our privacy policy, website terms and service terms. For how the service runs day to day, see how Steinfin works.
If your team has a questionnaire or specific requirements, send it over. We will answer directly.
Only what the receivables work needs: invoice details, outstanding balances, payment status, customer business contacts, promises, queries and the history of follow-up on each account. We do not need access to unrelated business information.
No. We never ask you to share your accounting system password. You authorise the connection from your own account, and you can disconnect it at any time.
Our access is scoped to what is needed to review invoices, follow up for payment and report back to you. We have no reason to look at unrelated areas such as payroll or HR, and we do not.
Only the people working on your account. Because Steinfin is a managed service, those people do see invoice and customer information, since that is how the follow-up gets done. Your information is not shared outside that team.
No. Steinfin does not hold client funds. Your customers keep paying directly into your own bank account or payment system, exactly as they do now.
No. We do not ask for your online banking login, and we never ask your customers for their card or bank details.
Our website and its forms are served over encrypted HTTPS connections, and supported accounting platforms connect through their own encrypted connections. For specific questions about how stored data is protected, contact us and we will answer directly.
Automation and AI can help us organise accounts, spot what needs attention and prepare routine work. People review what goes to your customers, and commercial decisions always stay with you. If you want to know which tools would process your information, ask us before you start.
Ask us about the specific tools involved in your service and we will tell you how each one handles data. We are happy to confirm this in writing as part of onboarding.
Yes. The accounting connection belongs to your account, so you can review or remove it at any time without needing our help.
The accounting connection is disconnected, and your information is kept only as long as our agreement and the law require, then deleted or anonymised. You can also make deletion requests under GDPR.
We use service providers for things like hosting, email delivery and accounting or workflow software, and they may only use data to provide their service to us. Contact us for the current list.
Not at present. Our approach centres on controlled access, minimal data, client-controlled connections and responsible handling. If your procurement process needs specific assurances, contact us and we will answer your questions directly.
We work to identify and contain it, investigate what happened, fix the cause, and notify affected clients and, where required, the relevant authorities.