Compliance at Tuppence.
Who we are, who provides the regulated parts of Tuppence, and how we keep card data and your business safe — in plain English.
Placeholder details. The regulatory information on this page is a template pending confirmation and legal review. Items in [square brackets] will be replaced with confirmed details before live launch and must not be relied on.
Who we are
Tuppence (tuppence.ai) is a payments platform for developers and AI agents, built on Stripe Connect. It is a trading name of [Company legal name] Ltd, a company registered in [England and Wales].
| Legal name | [Company legal name] Ltd |
|---|---|
| Company number | [company number] |
| Registered office | [registered office address] |
| VAT number | [VAT number] |
| ICO registration | [ICO registration number] |
Regulatory status
Tuppence does not process card payments or issue cards itself. Those regulated services are provided by Stripe and its partners:
| Card payment processing | Stripe Payments UK Ltd [confirm entity, regulatory status and FRN 000000] |
|---|---|
| Terms for businesses | Stripe Connected Account Agreement, including the Stripe Services Agreement, accepted during onboarding |
| Tuppence card issuing | Stripe Issuing, with cards issued by [issuing partner] [regulatory status, FRN 000000] |
| Tuppence’s own status | [To be confirmed — for example, agent or distributor status, or not regulated] |
You can check the details of any regulated firm on the Financial Conduct Authority’s Financial Services Register.
Our agent tools — the API, MCP server, tool packs, agent identities and mandates — are software. They carry out actions within the keys, mandates and approvals a business sets. They do not provide financial or investment advice.
PCI DSS
Tuppence is designed so that card data never touches our systems. Payers enter card numbers and security codes only into Stripe’s own fields on hosted checkout and pay pages. We store only a token, the card brand and the last four digits. The same is true for Tuppence cards: Stripe holds the full card details.
- This design is intended to keep Tuppence within SAQ A scope under the Payment Card Industry Data Security Standard.
- Our SAQ A attestation of compliance is [to be signed before live launch].
- AI agents connected to Tuppence must never collect card numbers. Our Acceptable Use Policy makes this a rule.
Your balance and payouts
Money from your card payments is held in your Stripe connected account, not in a Tuppence bank account, until it is paid out to your bank. [Confirm how Stripe holds and protects connected account balances, and whether any safeguarding or FSCS statement applies.]
As risk controls, funds from your first week of payments settle on T+7, and we or Stripe may hold payouts or keep a rolling reserve where the risk calls for it. See our Terms of Service.
Financial crime and KYC
We work to keep Tuppence from being used for financial crime. Our approach combines Stripe’s checks with our own:
- Know your business. Before a business can take live payments, we collect details of the business and the people who own and control it through our own forms. Identity documents and a selfie are captured through Stripe Identity and passed to Stripe. We do not store them.
- Sanctions and verification. Stripe screens and verifies businesses as part of its KYC, and we carry out our own checks. [Describe Tuppence’s own checks, screening provider and risk assessment.]
- Monitoring. We watch for unusual activity, such as card testing, spikes in refunds or disputes, and cashback farming, and can hold payouts, freeze cards or close accounts.
- Staged access. Live payments are opening to waitlisted businesses in stages, so we can review each business as it goes live.
- Accountability. [Name or role of the person responsible for financial crime controls, and whether a Money Laundering Reporting Officer is required — to be confirmed.]
We or Stripe may ask you for information or documents from time to time. This helps keep the payment system safe.
Certifications
| PCI DSS | SAQ A — [attestation to be signed before live launch] |
|---|---|
| SOC 2 | [SOC 2 — status] |
| ISO/IEC 27001 | [ISO 27001 — status] |
| Cyber Essentials | [Cyber Essentials — status] |
Stripe and Google Cloud hold their own certifications, which they publish. These cover their services, not Tuppence.
Data protection
We process personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We host Tuppence on Google Cloud in the europe-west2 region (London). [Company legal name] Ltd is registered with the Information Commissioner’s Office under registration number [ICO registration number].
Our Privacy Notice explains what we collect, why, how long we keep it and your rights, including how to contact our Data Protection Officer at [DPO email address]. You can also read how we protect your data on our security page.
Complaints
If something has gone wrong, we want to hear about it and put it right. Our complaints procedure explains how to raise a complaint and how long we will take to respond.
Depending on what your complaint is about, eligible complainants may be able to refer it to the Financial Ombudsman Service, a free and independent service for settling disputes. [Confirm which complaints are eligible.]
Modern slavery statement
[Modern slavery statement to be confirmed, if required.] We are opposed to modern slavery and human trafficking in all its forms, and expect the same of our suppliers and partners.
Last updated [date]. For regulatory questions, please contact us.