HubSpot · HubSpot Sub-Processors · View original document ↗

Payment Processor Sub-Processor (Stripe)

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time HubSpot changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity HubSpot recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for HubSpot Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

This provision identifies Stripe, Inc. as a feature-specific Sub-Processor engaged to support Commerce Hub products and services, with data centers listed in the United States across all regional data center columns.

This analysis describes what HubSpot's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision discloses that payment-related Customer Data processed through HubSpot Commerce Hub is handled by Stripe, Inc. as a Sub-Processor. Customers using Commerce Hub for payment processing should be aware that payment and transaction data may be accessible to Stripe across US-based infrastructure, with no EU or other regional data center listed for this Sub-Processor.

Consumer impact (what this means for users)

Under this provision, Customer Data associated with Commerce Hub payment transactions is processed by Stripe, Inc. using US-based infrastructure. Customers in the EU or other non-US jurisdictions using Commerce Hub should evaluate the transfer mechanisms applicable to payment data transferred to Stripe's US infrastructure.

Cross-platform context

See how other platforms handle Payment Processor Sub-Processor (Stripe) and similar clauses.

Compare across platforms →

Monitoring

HubSpot has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Stripe, Inc. Payment Processor Support Commerce Hub products and services United States United States United States United States

Excerpt from HubSpot's Sub-Processors

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: Payment data processing engages GDPR Article 28 for EU customers, as well as PCI DSS requirements applicable to payment card data. Stripe operates its own compliance certifications (including PCI DSS), but the sub-processor relationship means HubSpot retains controller-level obligations for Customer Data shared with Stripe. EU customers transferring payment-related personal data to Stripe's US infrastructure require Standard Contractual Clauses or equivalent transfer mechanisms. The Irish Data Protection Commission and relevant financial regulators have jurisdiction depending on the nature of payment data processed. (2) GOVERNANCE EXPOSURE: Medium. The absence of EU or regional data center options for Stripe means all Commerce Hub payment data flows to US-based Stripe infrastructure regardless of customer location. This requires documented transfer mechanisms for EU and other non-US customers and may trigger additional obligations under sector-specific regulations for customers in financial services. (3) JURISDICTION FLAGS: EU and EEA customers using Commerce Hub face cross-border transfer obligations for payment data sent to Stripe's US infrastructure. UK customers are subject to equivalent UK GDPR transfer requirements. Customers in jurisdictions with local data residency requirements for financial data should assess whether US-only Stripe processing is compliant. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should confirm that HubSpot's DPA and Stripe's data processing addendum together provide adequate contractual coverage for payment data. Teams should verify PCI DSS scope and whether HubSpot's use of Stripe affects the customer's own PCI DSS compliance obligations. (5) COMPLIANCE CONSIDERATIONS: Customers using Commerce Hub should update their records of processing activities to reflect Stripe as a Sub-Processor for payment data and confirm that applicable transfer mechanisms (Standard Contractual Clauses or equivalent) are in place for non-US customers.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has jurisdiction over payment data practices and sub-processor disclosures affecting US consumers and businesses.
    File a complaint →

Provision details

Document information
Document
HubSpot Sub-Processors
Entity
HubSpot
Document last updated
July 6, 2026
Tracking information
First tracked
July 6, 2026
Last verified
July 9, 2026
Record ID
CA-P-015671
Document ID
CA-D-00932
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
be1ee395d61eaf157e884c8abd16fb6f7764b8b8dffdb3704efbafbd67a0364d
Analysis generated
July 6, 2026 23:16 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: HubSpot
Document: HubSpot Sub-Processors
Record ID: CA-P-015671
Captured: 2026-07-06 23:16:08 UTC
SHA-256: be1ee395d61eaf15…
URL: https://conductatlas.com/platform/hubspot/hubspot-sub-processors/provision/CA-P-015671/payment-processor-sub-processor-stripe/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does HubSpot's Payment Processor Sub-Processor (Stripe) clause do?

This provision discloses that payment-related Customer Data processed through HubSpot Commerce Hub is handled by Stripe, Inc. as a Sub-Processor. Customers using Commerce Hub for payment processing should be aware that payment and transaction data may be accessible to Stripe across US-based infrastructure, with no EU or other regional data center listed for this Sub-Processor.

How does this clause affect you?

Under this provision, Customer Data associated with Commerce Hub payment transactions is processed by Stripe, Inc. using US-based infrastructure. Customers in the EU or other non-US jurisdictions using Commerce Hub should evaluate the transfer mechanisms applicable to payment data transferred to Stripe's US infrastructure.

Is ConductAtlas affiliated with HubSpot?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by HubSpot.