Privacy Policy
Last updated: May 27, 2026
1. Who we are
muups ("muups", "we", "us", or "our") is an accounts-receivable automation service operated by STM Group LLC, a limited liability company organized in New Mexico, USA. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to the muups web application and related services (the "Service").
muups is a business-to-business product intended for use by companies and their authorized personnel. It is not directed to consumers or to children.
2. Information we collect
We collect the following categories of information:
- Account information. Your name, email address, and company details provided when you create an account.
- Invoice and customer data you upload. When you upload or sync invoices, we process the data they contain, which may include your customers’ names, email addresses, invoice amounts, reference numbers, and due dates.
- Financial account data via Plaid. If you connect a bank account, we access read-only transaction information through Plaid (see Section 4).
- Usage and technical data. Limited technical information necessary to operate and secure the Service, such as log data and authentication events.
3. How we use your information
We use the information we collect to:
- provide the Service — including generating and sending payment reminder sequences, detecting incoming payments, and reconciling them against your outstanding invoices;
- authenticate you and secure your account;
- communicate with you about the Service;
- maintain, improve, and troubleshoot the Service; and
- comply with legal obligations.
We do not sell your personal information or your customers’ personal information, and we do not use it for advertising.
4. Bank connections through Plaid
We use Plaid Inc. ("Plaid") to connect to your financial institution. When you choose to connect a bank account, you authorize Plaid to access information from that account on your behalf. We request read-only transaction data for the sole purpose of detecting and reconciling payments against your invoices. We never initiate transfers or move funds, and we never receive or store your online banking login credentials — those are handled directly by Plaid.
Plaid’s collection and use of your information is governed by Plaid’s own privacy policy, available at plaid.com/legal. You can disconnect a linked account at any time from your settings, which revokes our continued access to that account’s data.
5. How we share information
We share information only with service providers ("subprocessors") that help us operate the Service, and only as needed for them to perform their function. These currently include:
- Plaid — secure bank account connectivity;
- Supabase — database and authentication hosting (data hosted in the European Union, Frankfurt region);
- Vercel — application hosting;
- Resend — transactional and reminder email delivery;
- Anthropic — AI processing used to draft reminder email content.
We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a business transfer (such as a merger or acquisition), subject to this Policy.
6. How we protect your information
We apply industry-standard safeguards, including encryption of data in transit (TLS 1.2 or better) and at rest (AES-256), role-based access controls, and multi-factor authentication on the critical systems that store or process financial data. While no method of transmission or storage is completely secure, we work to protect your information using appropriate technical and organizational measures.
7. Data retention
We retain your information for as long as your account is active or as needed to provide the Service. When you close your account, or upon a valid deletion request, we delete or anonymize your personal information within a reasonable period, except where we are required to retain it to comply with legal obligations, resolve disputes, or enforce our agreements.
8. Your rights
Depending on your location, you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. Because data is hosted in the European Union, we apply these rights consistent with the EU General Data Protection Regulation (GDPR) where applicable.
To exercise any of these rights, contact us at privacy@muups.com. You may also disconnect any linked bank account at any time from your settings.
9. International data transfers
We host data in the European Union (Frankfurt). If you access the Service from outside the EU, your information may be transferred to and processed in the EU and other countries where our service providers operate. We take steps to ensure such transfers are subject to appropriate safeguards.
10. Cookies
We use only the cookies and similar technologies that are necessary to operate the Service, such as keeping you signed in. We do not use advertising or cross-site tracking cookies.
11. Changes to this Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
12. Contact us
If you have questions about this Privacy Policy or our data practices, contact us at:
STM Group LLC (muups)
4405 Jager Dr NE
Rio Rancho, NM 87144, USA
privacy@muups.com