Operated by FundiAI (Pty) Ltd
Registration No: 2025/739927/07
Website: www.fundibill.online | Email: info@fundibill.online | Tel: 063 736 9445
Version 1.0 | Effective: 1 June 2026 | Last reviewed: 1 June 2026
1. Introduction
FundiBill is a subscription-based invoicing application for South African small businesses, operated by FundiAI (Pty) Ltd (“FundiAI”, “we”, “us”). This Privacy Policy explains how we collect, use, store, and protect personal information in connection with the FundiBill application and website (www.fundibill.online), in accordance with the Protection of Personal Information Act, 4 of 2013 (“POPIA”).
By creating a FundiBill account, subscribing, or using the application in any way, you confirm that you have read and understood this Privacy Policy.
2. Who Is Responsible for Your Information?
FundiAI (Pty) Ltd is the Responsible Party under POPIA for the personal information of FundiBill subscribers — meaning the information you provide when you register, subscribe, and use the application.
Information Officer: Dewald van Rensburg
Email: info@fundibill.online | Tel: 063 736 9445
3. An Important POPIA Distinction — Your Data vs Your Clients’ Data
FundiBill is a tool you use to manage your own business. This means two separate categories of personal information exist within the application, and they are treated differently under POPIA:
YOUR ACCOUNT DATA (FundiAI is Responsible Party)
This is information about you as a FundiBill subscriber — your name, email address, business details, and payment records. FundiAI determines how and why this information is processed. This Privacy Policy governs how we handle it.
YOUR CLIENT DATA (You are the Responsible Party)
This is information you enter into FundiBill about your own customers — their names, email addresses, physical addresses, and invoicing records. You determine how and why this information is processed. FundiAI acts only as the Operator storing and processing it on your behalf to deliver the service. You are responsible for ensuring your own POPIA compliance in relation to your clients’ personal information.
4. What Information We Collect About You (as a Subscriber)
4.1 Account and Registration Information
- Full name and business name.
- Email address and phone number.
- Business registration number (if provided).
- Password (stored in encrypted form — we never see your plain-text password).
4.2 Subscription and Billing Information
- Subscription plan selected (Monthly or Annual) and subscription status.
- Payment reference information for EFT reconciliation.
- PayFast transaction records (card or instant EFT). We do not store card numbers — PayFast handles payment card data under their own security standards.
- Invoice history for your FundiBill subscription.
4.3 Usage and Technical Information
- Log data: IP address, browser type, device type, operating system, and pages accessed within the application.
- Usage patterns: features used, session duration, and frequency of use — used to improve the application.
- Error and crash reports: technical data generated when the application encounters a problem.
4.4 Support Communications
- Emails, queries, and support requests you send to info@fundibill.online.
- Records of issues raised and resolutions provided.
5. Your Client Data — What We Store on Your Behalf
When you use FundiBill, you enter information about your own business clients in order to create and send invoices. This typically includes:
- Client names, business names, and contact details (email addresses, phone numbers, physical addresses).
- Invoice details (line items, amounts, due dates, payment status).
- Any notes or references you add to invoices or client records.
FundiAI stores and processes this data solely to provide the FundiBill service to you. We do not use your clients’ information for our own marketing, analytics, or any purpose beyond operating the application. As the Responsible Party for this data, you must:
- Have a lawful basis for collecting and storing your clients’ personal information.
- Ensure your clients are aware their information is being used to generate invoices.
- Handle requests from your clients to access, correct, or delete their information.
- Comply with POPIA in your own invoicing and business practices.
6. Why We Collect and Use Your Information
- To create and maintain your FundiBill account.
- To deliver the FundiBill subscription service and process your payments.
- To send you subscription-related communications (receipts, renewal reminders, service updates).
- To provide support when you contact us.
- To improve the FundiBill application using aggregated, anonymised usage data.
- To detect and prevent fraud, abuse, or security incidents.
- To comply with our legal obligations under POPIA, PAIA, tax legislation, and other applicable South African law.
We will not use your information for unrelated purposes without your consent. We do not sell your personal information to any third party.
7. Google API Services and Gmail Data Usage
FundiBill offers an optional feature that lets you send invoices and related emails to your clients directly from your own Gmail address, using Google’s Gmail API. This section explains exactly what this feature accesses, why, and how that data is handled. This feature is optional — FundiBill works fully without it, using our own email sending infrastructure instead.
7.1 What We Access
If you choose to connect your Gmail account, FundiBill requests only the “gmail.send” scope from Google. This scope allows FundiBill to send an email from your Gmail address on your instruction. It does not grant FundiBill any ability to:
- Read, view, search, or scan your Gmail inbox, sent mail, drafts, or any existing messages.
- Access your Gmail contacts or address book.
- Delete, modify, or organise any of your existing Gmail content or labels.
- Access any Gmail data beyond the single outgoing email you choose to send through FundiBill at the time you send it.
7.2 Why We Request This Access
We request this access so that invoices and related emails you send through FundiBill can appear in your clients’ inboxes as coming directly from your own Gmail address, rather than from a generic FundiBill sending address. This improves deliverability and trust, since clients recognise and can reply directly to your own email address.
7.3 How This Data Is Stored and Protected
- When you connect your Gmail account, Google issues an authentication token to FundiBill. This token is encrypted at rest and stored securely — we never see or store your Gmail password.
- The token is used only to authorise the specific send action you initiate within FundiBill (e.g., clicking “Send Invoice”). It is not used for any other purpose.
- We do not store the body content of emails sent through this feature beyond what is necessary to complete delivery and to maintain your own invoice record within FundiBill (e.g., a copy of the invoice itself, which you have created and own).
- We do not store, log, or retain copies of your Gmail inbox or any messages other than the one you actively chose to send.
7.4 Human Access to This Data
No FundiAI employee or contractor accesses data obtained through the Gmail API except where strictly necessary for security purposes, to comply with applicable law, or with your explicit consent (for example, to help you troubleshoot a sending issue you have reported to us).
7.5 No Use for Advertising
Data obtained through the Gmail API is never used for advertising purposes, and is never sold, rented, or shared with third parties for their own marketing or advertising purposes.
7.6 Revoking Access
You can disconnect FundiBill’s access to your Gmail account at any time, either:
- Within FundiBill, via your account integration settings; or
- Directly through your Google Account at myaccount.google.com/permissions, under “Third-party apps with account access”.
Once disconnected, FundiBill’s stored authentication token for your account is deleted, and FundiBill can no longer send email on your behalf until you reconnect.
7.7 Google API Services User Data Policy Compliance
FundiBill’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. Who We Share Your Information With
FundiAI does not sell personal information. We share information only where necessary to operate FundiBill:
- Hosting and infrastructure providers: The servers and cloud infrastructure that run FundiBill. These providers store your account data and client data on our behalf under written data processing agreements.
- Email delivery providers: Services used to send you subscription emails, receipts, renewal reminders, and any invoices you send to your clients through FundiBill.
- PayFast: For processing subscription payments. PayFast operates under its own privacy policy and PCI-DSS security standards. FundiAI receives only payment confirmation and reference data — not your card details.
- Analytics tools: Anonymised or aggregated usage data may be processed by analytics tools to help us understand how FundiBill is used and where to improve it.
- Professional advisers: Accountants, lawyers, and auditors where necessary, bound by professional confidentiality obligations.
- Regulatory authorities and law enforcement: Where required by South African law or a competent court order.
9. Cross-Border Data Transfers
Some of the third-party providers we use to operate FundiBill — including cloud hosting, email delivery, and analytics services — may process data outside South Africa. Where cross-border transfers occur, we take steps to ensure appropriate protections are in place, such as contractual agreements requiring the recipient to maintain an adequate level of data protection consistent with POPIA. We only transfer personal information internationally where a lawful basis exists.
10. How Long We Keep Your Information
9.1 While You Are a Subscriber
We retain your account information and client data for as long as your subscription is active. You can access, update, or export your data at any time during this period.
9.2 After Cancellation or Non-Renewal
After your subscription ends, your account and all associated data — including your client data, invoice history, and account details — are retained for 30 days. During this window you can log in and export your records.
After 30 days, your account and data are permanently deleted from our active systems. Residual copies may remain in encrypted backups for a short additional period before being overwritten in the normal course of our backup rotation.
9.3 Financial and Legal Records
Subscription payment records and billing history are retained for as long as required by the Income Tax Act and applicable tax regulations — typically 5 years — even after your account is deleted.
9.4 Support Records
Support communications are retained for up to 2 years after your subscription ends, for quality assurance and dispute resolution purposes.
11. How We Protect Your Information
We implement reasonable technical and organisational security measures to protect your information and your clients’ data from unauthorised access, loss, alteration, or disclosure. These measures include:
- HTTPS encryption on all connections to www.fundibill.online.
- Encrypted storage of passwords — we never store or see your plain-text password.
- Access controls limiting which systems and personnel can access subscriber data.
- Multi-factor authentication (MFA) on our administrative systems where available.
- Regular backups of application data.
- Vendor due diligence — we work with reputable hosting and infrastructure providers.
No system is perfectly secure. If you suspect your FundiBill account has been compromised, contact us immediately at info@fundibill.online. In the event of a data breach affecting personal information, we will notify the Information Regulator and affected subscribers as required by POPIA section 22.
12. Your Rights Under POPIA
As a data subject, you have the following rights in respect of your account data:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your personal information (subject to legal retention obligations and our 30-day post-cancellation retention window).
- Objection: Object to the processing of your personal information in certain circumstances.
- Data portability: Request an export of your FundiBill data (invoices, client records) at any time during your active subscription.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact our Information Officer at info@fundibill.online. We will respond within a reasonable time and in accordance with POPIA requirements.
If you are not satisfied with our response, you may lodge a complaint with the Information Regulator:
Information Regulator (South Africa)
Website: www.inforegulator.org.za
Tel: 010 023 5200 | Toll-free: 0800 017 236
Email: enquiries@inforegulator.org.za
13. Cookies and Tracking
FundiBill and www.fundibill.online use cookies and similar technologies to:
- Keep you logged in to your account (session cookies — essential for the application to function).
- Remember your preferences within the application.
- Analyse usage patterns to improve the application (analytics cookies).
Essential session cookies are required for FundiBill to work and cannot be disabled without losing access to your account. Analytics cookies can be managed through your browser settings or the cookie preference options on our website.
14. Children’s Privacy
FundiBill is a business application intended for use by adults operating legitimate South African businesses. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created a FundiBill account, please contact us at info@fundibill.online and we will delete the account promptly.
15. Third-Party Links and Services
The FundiBill application and website may contain links to third-party websites or services (for example, payment providers or help resources). FundiAI is not responsible for the privacy practices or content of those third-party sites. Please review their privacy policies before providing them with any personal information.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the application, our business practices, or applicable law. When we make material changes, we will notify active subscribers by email at least 14 days before the changes take effect, and publish the updated Policy at www.fundibill.online/privacy with the new effective date.
Continued use of FundiBill after the effective date of an updated Policy constitutes your acceptance of the changes.
17. Contact Us
For questions, requests, or concerns about this Privacy Policy or your personal information:
FundiBill — operated by FundiAI (Pty) Ltd
Email: info@fundibill.online
Phone: 063 736 9445
Hours: Monday to Friday, 09:00–17:00 (SAST)
Website: www.fundibill.online
Information Officer: Dewald van Rensburg | d@fundiai.co.za