Policies and company information
The small print.
Privacy notice
Version 1 · in effect from 5 October 2026
Who we are
Stoneledger Limited (“Stoneledger”, “we”) is the controller of the personal data described here. Our registered office is 71-75 Shelton Street, Covent Garden, London WC2H 9JQ and our company number is 17481774. For anything about your data, write to privacy@stoneledgeruk.co.uk. Our registration with the Information Commissioner's Office was applied for on 5 October 2026; its number will be added here once it is issued.
We have not appointed a Data Protection Officer. We are not required to: we are not a public authority, and our core activity is not large-scale monitoring or large-scale processing of special category data.
What we collect, why, and on what basis
| What | Why | Lawful basis | Kept |
|---|---|---|---|
| The Register interest and Book a demo forms: name, email, business name, phone if you give it, industry, business type, whether CIS applies, a time that suits you for a demo, and anything you add. Also how you found us: the page you sent the form from, any campaign or referral code in its address, and the name of the website that linked you to it. Each form reaches us as an email in our business mailbox; it is not stored anywhere else | To tell you when Stoneledger opens or to arrange your demo, to understand who is interested, and to learn which of our marketing works | Consent (Article 6(1)(a)). You can withdraw it at any time and we will delete the record | Until you withdraw, or 24 months after the last contact |
| The Embed in your website form, for accountancy practices: practice name, website address, your name, email, phone if you give it, and anything you add, with how you found us. It reaches us as an email in our business mailbox and is not stored anywhere else. If your practice goes on to pay, Stripe takes the payment on its own page | To set the checkers up on your practice's website and to take payment for them | Consent (Article 6(1)(a)) for the request; once it goes ahead, our contract with your practice and our legitimate interest in providing and billing the service (Article 6(1)(b) and (f)) | Until you withdraw, or 24 months after the last contact if it does not go ahead; payment records for six years, as tax law requires |
| Businesses we contact about Stoneledger: the business's name, trade, address, telephone number and website; for a company, its Companies House details and the names of its directors and owners; and a note of what was said when we speak | To tell local businesses and accountancy practices about Stoneledger where it may suit them, and to remember what was said so we do not repeat ourselves | Our legitimate interest in telling businesses about a service they may need (Article 6(1)(f)). We have weighed it against your interests in a written assessment, and you can object at any time | While we are in touch, and for 24 months after the last contact. If you ask us not to contact you, we keep only the business name, the number or address, the date and that you asked, for as long as we contact anyone, so that we never contact you again |
| Account data: name, email, hashed password, two-factor secret, sign-in times, IP address of each sign-in | To give you an account, keep it secure, and show you where it has been used | Performance of our contract with you (Article 6(1)(b)); security is also our legitimate interest (Article 6(1)(f)) | While the account exists, then 12 months |
| Your books: everything you record in Stoneledger, including personal data about your own customers, suppliers, employees and subcontractors | To provide the service you are paying for | Performance of our contract with you. For the personal data of your contacts, you are the controller and we are your processor - see Data processing terms | While the account exists, then 90 days, unless you ask sooner |
| Fraud prevention headers: your device type, screen size, time zone, browser, local and public IP address, and the window in which you acted | HMRC requires these with every Making Tax Digital (MTD) submission. We do not choose to collect them and we never use them for anything else | Legal obligation (Article 6(1)(c)) and performance of our contract | With the submission record, 7 years, to match HMRC's own record-keeping period |
| Submission records: what was sent to HMRC, when, and what HMRC answered | So a return can be opened a year later and read back to the records behind it, and so we can help if HMRC queries it | Legal obligation and legitimate interest in being able to evidence what was filed | 7 years |
| Billing: name, billing address, the last four digits and expiry of your card, and what you paid | To take payment and meet our own tax obligations | Contract, and legal obligation for the accounting records | 7 years (Companies Act and HMRC requirements) |
| Support messages | To answer you | Contract, or our legitimate interest in answering an enquiry | 24 months |
We never hold your full card number. Payments will be taken by Stripe, who receive the card details directly; we see only the last four digits and the expiry.
We do not sell your data, and we do not use it to train anything. Your books are not used to build models, generate benchmarks, or produce any product other than your own accounts.
If we have contacted you about Stoneledger
We may call, write to or call in at a business we think Stoneledger could help. Where your details came from: public sources only - the Companies House register, OpenStreetMap, the Food Standards Agency's food hygiene rating register, printed trade directories such as Checkatrade's, and your own website or listings. Before we call, we check the number against the Telephone Preference Service and the Corporate Telephone Preference Service, and we do not call a number registered on either unless you have agreed to hear from us. We do not email or text a sole trader or a partnership about Stoneledger unless you ask us to.
To stop us: say so when we call, or email hello@stoneledgeruk.co.uk. You do not need to give a reason. We stop at once, and keep only the short note described above so that we never contact you again. You have the other rights below too, and you can complain to the ICO.
Who else sees it
- DigitalOcean - our server and database, in London. Data stays in the UK.
- Cloudflare - our domain names, and emergency protection if the site is attacked.
- Resend - sends our emails (invitations, password resets, receipts), and passes what you send through the forms on this website to our own mailbox.
- Google - our business mailbox (Google Workspace). Emails you send us are held on Google's servers, which may be outside the UK.
- Stripe - will take payment, once accounts open.
- HMRC - only what you tell us to submit, when you tell us to submit it.
- Our professional advisers, and anyone we are legally required to tell.
If we ever sell the business, your data would go with it, and you would be told first.
Outside the UK
Your books and your account are stored in the UK. Some of the suppliers above are outside it: where personal data reaches them, it is protected by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or by the UK Extension to the EU–US Data Privacy Framework where the supplier is certified under it.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to what we do with it, and to have it sent to another provider. Where we rely on consent you can withdraw it at any time. Write to privacy@stoneledgeruk.co.uk; we will answer within one month.
You can export everything in your books to a spreadsheet yourself, at any time, without asking us.
Complaining about how we handle your data
Since 19 June 2026 the Data (Use and Access) Act 2025 requires every organisation to have a route for data protection complaints and to say what it is. Ours:
- Email privacy@stoneledgeruk.co.uk, or write to us at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ. You do not have to use any particular form of words or say which law you are relying on - just tell us what is wrong.
- We will acknowledge within 30 days, which is the outside limit the Act sets, and in practice within 2 working days.
- We will look into it and give you a substantive answer, and tell you the outcome.
- We keep a record of every data protection complaint and what was done about it.
You can also complain to the Information Commissioner's Office - ico.org.uk, 0303 123 1113 - at any time. You do not have to come to us first, although the ICO will usually ask whether you have.
Two things we want to be clear about
- There is no automated decision-making. Nothing about you is decided by a machine without a person.
- Giving us your data is a condition of the service. We cannot run your accounts without your accounting records, and HMRC will not accept a submission without the fraud prevention headers. If you do not want either, we cannot provide the service.
Website terms of use
Version 1 · in effect from 5 October 2026
This site is run by Stoneledger Limited, company number 17481774, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ. Contact: hello@stoneledgeruk.co.uk. Using the site means accepting these terms.
What this site is
General information about Stoneledger. It is not accounting, tax or legal advice, and it is not a substitute for an accountant. Figures shown in screenshots come from sample data, not from real businesses. We may change the site, or any part of it, at any time.
What belongs to whom
The Stoneledger name, the logo, the design, the words and the images on this site belong to us or to our licensors. You may read the site, print pages and share links. You may not copy the content into another product, republish it, or use the Stoneledger name or logo without our written permission.
What you must not do
Do not try to break into the site, introduce anything malicious, scrape it automatically at a rate that burdens it, or use it to do anything unlawful. Genuine security research is welcome - see Security and vulnerability reporting.
Links
Where we link to another site, we do not control it and are not responsible for it.
Our liability
We do not limit our liability for death or personal injury caused by negligence, for fraud, or for anything else the law does not allow us to limit. Beyond that, and to the extent the law allows, we are not liable for loss arising from use of this site or reliance on anything in it.
Law
These terms are governed by the law of England and Wales, and the courts of England and Wales have jurisdiction. If you live in Scotland or Northern Ireland you may also bring proceedings in your own courts.
Terms of service
Version 1 · applies when Stoneledger opens accounts
An agreement between you and Stoneledger Limited, company number 17481774. By opening an account you accept it.
1. What Stoneledger is, and what it is not
Stoneledger is bookkeeping and tax software. It records what you tell it, works out figures from those records, and - where you ask it to, and where HMRC has recognised us - submits them.
It is not an accountant and it does not give advice. The figures it produces are only as good as what you put in. You remain responsible for your own tax returns, for the accuracy of your records, and for meeting your own deadlines. If your affairs are complicated, get an accountant.
Stoneledger does not file anything with HMRC yet. It has completed its testing in HMRC’s sandbox, and we are preparing our applications to HMRC. Until HMRC grants live access, the product will say so on every screen that mentions submitting, and no claim to the contrary is part of this agreement.
2. Your account
You need an account, a password and an authenticator app. Keep them to yourself: anything done through your account is treated as done by you. Tell us at once if you think someone else has got in.
One account is one person. A business can invite others and give each of them a role; the person who owns the books decides who sees them.
You must be 18 or over, and using Stoneledger for a business.
3. What you pay
| Plan | Price | Billed |
|---|---|---|
| Stoneledger, monthly | £8 a month (no VAT to add) | Monthly, in advance |
| Stoneledger, annual | £50 a year (no VAT to add) | Yearly, in advance |
| Stoneledger Bridge | £10 a year, £4 a quarter or £3 a month, per business (no VAT to add) | Once, for the period bought |
Prices include VAT where VAT applies. A Bridge pass covers one business. If you file for more than one business you need a pass for each; an agent filing for clients needs a pass per client.
Renewal. Monthly and annual plans renew automatically until you cancel. Before an annual plan renews, we will email you at least 30 days ahead with the date, the price and how to cancel. A monthly plan renews on the same date each month, without a separate reminder.
Changing prices. We may change prices with at least 30 days' notice by email. If you do not accept the new price you can cancel before it takes effect and we will refund the unused part of anything you have already paid.
Failed payments. If a payment fails we will try again and tell you. If it keeps failing we may restrict access to the service. We will not delete your books because you have not paid, and you will always be able to export them.
4. Cancelling, and your rights if you are a consumer
You can cancel at any time from inside the product. A monthly plan runs to the end of the month you have paid for. An annual plan runs to the end of the year you have paid for.
If you are buying as a consumer rather than for a business, the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013 give you 14 days to change your mind from the day you sign up. If you ask us to start the service straight away and then cancel within the 14 days, we may keep a proportionate amount for what you have used. If, at your request, the service has been fully provided within the 14 days - a Bridge pass you have used to file, for example - the right to cancel ends once it has been provided, and we will ask you to confirm you understand that before we start. Most Stoneledger customers are buying for a business and these rights do not apply to them.
5. Your data
Your books are yours. You can export everything to a spreadsheet at any time, without asking us and without paying. We keep earlier versions so you can go back to one.
When you close your account we keep your books for 90 days in case you change your mind, then delete them. Ask us sooner and we will delete them sooner. Some records - what was submitted to HMRC, and our own accounting records - we must keep for longer; see the privacy notice.
Where your books contain other people's personal data, the Data processing terms below form part of this agreement.
6. What we promise, and what we do not
We will provide the service with reasonable skill and care. We aim to keep it available but we do not promise it will never be down: we may take it offline for maintenance, and we will give notice where we can. There is no service level guarantee and no compensation for downtime.
Support is by email, in English, on working days. We aim to answer within one working day and do not guarantee it.
We may change the product. We will not remove something you depend on without telling you.
7. Liability
Nothing here limits our liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot be limited by law.
Subject to that, and because this is a business agreement: we are not liable for lost profits, lost business, lost goodwill, or for any penalty, interest or surcharge imposed on you by HMRC, and our total liability to you in any 12 months is limited to what you paid us in those 12 months.
Read that last part carefully. On a £50-a-year plan it means our liability is capped at £50. That is normal for software at this price, and it is the reason the product shows you the working behind every figure rather than asking you to trust it. If you need more cover than that, you need an accountant who carries professional indemnity insurance, and we would say so to your face.
8. Ending it
You can leave at any time. We may suspend or end your account if you break these terms, do not pay, or use the service unlawfully - with notice, and with a chance to put it right, unless the breach is serious. Either way you get your data.
9. Changes, and the law
We may change these terms. For anything that materially affects you we will give at least 30 days' notice by email, and you may cancel before it takes effect.
This agreement is governed by the law of England and Wales. The courts of England and Wales have jurisdiction; if you live in Scotland or Northern Ireland you may also bring proceedings there.
Data processing terms
Version 1 · forms part of the terms of service, from when accounts open
Your books hold personal data about other people - your customers, your suppliers, your employees, your subcontractors, your tenants. For that data you are the controller and we are your processor, and UK GDPR Article 28 requires this to be written down.
| Subject matter | Providing the Stoneledger service to you. |
| Duration | While your account is open, plus the retention periods in the terms of service. |
| Nature and purpose | Storing, organising, calculating from and - on your instruction - transmitting your business records to HMRC. |
| Types of data | Names, contact details, addresses, payment details, amounts invoiced and paid. Where you run payroll or CIS: National Insurance numbers, UTRs, dates of birth, pay and deductions. Where you let property: tenants' names and contact details. |
| Data subjects | Your customers, suppliers, employees, subcontractors, tenants and anyone else you record. |
| Special category data | None is required by the service. Do not put any in free-text notes. |
What we undertake
- We process only on your documented instructions - which means using the product, and this agreement - unless the law requires otherwise, in which case we will tell you first unless the law forbids it.
- Everyone with access is under a duty of confidence.
- We take the security measures Article 32 requires, set out in Security below: encryption in transit and at rest, access separated business by business in the database itself, two-factor sign-in for everyone, and audited access.
- Sub-processors. You authorise the ones listed below. We will give you at least 30 days' notice before adding or replacing one, and you may object; if you do and we cannot resolve it, you may cancel without penalty and we will refund the unused part. Each is bound by terms no weaker than these.
- We will help you answer people's rights requests, and you can do most of it yourself: every record in your books can be found, corrected, exported or deleted from inside the product.
- We will tell you about a personal data breach without undue delay, and in any event within 24 hours of becoming aware of it, with what we know and what we are doing. That is tighter than the law requires of us, on purpose: your own 72-hour clock to the ICO starts when we tell you.
- We will help with your data protection impact assessments and any consultation with the ICO, so far as what we do is relevant.
- At the end we will delete your data within 90 days, or return it sooner if you ask. You can export it yourself at any time.
- Audits and inspections. We will make available all the information you need to show we meet these obligations: our documentation, and answers to your security questionnaire, which we expect will normally be enough. Where they are not enough, or after a personal data breach, we will allow for and contribute to an audit, including an inspection, by you or an auditor you appoint who is bound by confidentiality - no more than once in any twelve months unless a breach has happened, on 30 days' notice, at your cost.
Our sub-processors
| Who | What they do | Where |
|---|---|---|
| DigitalOcean | Servers and database | London, UK |
| Cloudflare | Domain names; emergency protection if the service is attacked | UK/EU, with global fallback |
| Resend | Sends our emails | EU |
| Stripe | Will take payment, once accounts open | UK and USA |
HMRC is not a sub-processor. When you submit, HMRC receives the data as a controller in its own right.
Accessibility statement
Version 1 · last reviewed 5 October 2026
We want Stoneledger to be usable by everyone, including people using a screen reader, a keyboard only, or a large text size.
The standard
We aim for WCAG 2.2 level AA. We are a private company, so the Public Sector Bodies Accessibility Regulations 2018 do not apply to us; the Equality Act 2010 duty to make reasonable adjustments does, and we take the same standard as the target anyway.
Where we are
This statement is honest rather than flattering: we have not yet had an independent accessibility audit, so we cannot claim conformance. What we have done:
- Every screen works from the keyboard alone, and the focus outline is always visible.
- Headings, landmarks and form labels are marked up properly, and every control has a name.
- Colour is never the only way something is said: money in and money out carry a sign as well as a colour, and overdue items say “overdue”.
- Text contrast is checked against AA in all five colour themes.
- Anything that moves respects
prefers-reduced-motion. - The page works at 200% zoom and down to a 320px-wide screen.
Known problems, which we intend to fix:
- Some tables of figures are wide and scroll sideways on a small screen.
- The charts convey their shape visually; the same figures are always available as a table beside them, but the charts themselves are not described.
- No independent audit has been done yet. We check contrast, keyboard use in the forms and every screen width before each change goes live, and will publish an independent audit's findings here once one has been done.
If something is in your way
Write to support@stoneledgeruk.co.uk. We will reply within 5 working days, tell you what we can do and by when, and find you another way to get the same thing done in the meantime.
Complaints
Version 1 · in effect from 5 October 2026
If we have got something wrong we would rather hear it than not.
How
Email support@stoneledgeruk.co.uk, or write to us at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ. Tell us what happened, when, and what you would like us to do about it.
What happens
- We acknowledge it within 2 working days.
- We look into it and give you a full answer within 10 working days. If it is going to take longer we will tell you why and when to expect an answer.
- If you are not satisfied, say so and it will be looked at again by the company's director, who will reply within a further 10 working days. That is our final answer.
Complaints about personal data are handled separately
The Data (Use and Access) Act 2025 gives data protection complaints their own statutory route, with its own acknowledgement deadline. It is set out in the privacy notice, and in short: email privacy@stoneledgeruk.co.uk, we acknowledge within 30 days at the outside and in practice within 2 working days, we answer substantively, and we keep a record. You can go to the ICO at any time without coming to us first.
If you are still unhappy
- About your personal data: the Information Commissioner's Office, ico.org.uk, 0303 123 1113.
- About a purchase, if you bought as a consumer: we do not use an alternative dispute resolution (ADR) scheme. With our final answer we will tell you what else is open to you, which for most consumers is the small claims court.
- About your tax: we are not regulated by HMRC as an agent and we do not give tax advice, so there is no professional body to complain to about us. If your complaint is about advice, it belongs with whoever gave it.
Security and vulnerability reporting
Version 1 · in effect from 5 October 2026
How your data is protected
- Everything travels over HTTPS, and is encrypted at rest.
- Sign-in is invite-only with a password and an authenticator code, every time.
- Each business's data is separated in the database itself, not only in the application, so a fault in the application cannot show one customer another's books.
- Passwords are hashed, never stored. We cannot read yours.
- Access to production is logged, and every change to your books is versioned so it can be undone.
- Daily backups, held in the UK, with a restore from them tested automatically every week.
Reporting a vulnerability
Email security@stoneledgeruk.co.uk. The same address is in
/.well-known/security.txt.
We will acknowledge within 2 working days and keep you posted until it is resolved. We will credit you if you want to be credited. We do not pay bounties.
What we ask
- Give us reasonable time to fix it before telling anyone else. 90 days is the usual expectation.
- Use only your own account and your own test data. Do not access, change or delete anyone else's.
- No denial of service, no spam, no social engineering of our people or our suppliers, no physical attacks.
- Stay within the law.
In scope
stoneledgeruk.co.uk and its subdomains, and the Stoneledger product. Our suppliers'
infrastructure - DigitalOcean, Cloudflare, Resend, Stripe - is not ours to authorise testing on;
report those to them.
Our undertaking
If you follow the above and report in good faith, we will not take legal action against you and we will not report you. If a third party brings action against you for research that followed this policy, we will say publicly that it was authorised.
Company information
The company details are from Companies House
A company must show on its website its registered name, registered number, where it is registered, and its registered office address (Company, Limited Liability Partnership and Business (Names and Trading Disclosures) Regulations 2015). The Electronic Commerce (EC Directive) Regulations 2002 also require a geographic address, an email address, the VAT number if VAT registered, and any professional body or regulator.
- Trading name
- Stoneledger
- Registered name
- Stoneledger Limited
- Registered in
- England and Wales
- Company number
- 17481774
- Registered office
- 71-75 Shelton Street, Covent Garden, London WC2H 9JQ
- hello@stoneledgeruk.co.uk
- VAT number
- Not registered for VAT
- ICO registration
- Applied for on 5 October 2026; the number will be added here once it is issued
Stoneledger is independent software. It is not affiliated with, or endorsed by, HM Revenue & Customs. It has completed testing in HMRC’s sandbox and is preparing its applications to HMRC; it is not yet on HMRC’s list of recognised software for Making Tax Digital (MTD).