Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The statement designates Stripe as an independent data controller for payment and contact data collected during transactions on Palantir websites, and directs users to Stripe's own privacy policy for information on how that data is processed.
This analysis describes what Palantir's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Palantir does not control the processing of payment data once it is submitted via Stripe's payment interface on Palantir platforms. Individuals seeking to exercise data rights over payment data or understand how it is used must engage directly with Stripe under Stripe's own terms and privacy policy.
Interpretive note: The regulatory treatment of the Stripe independent controller designation may depend on the technical structure of the integration and applicable jurisdiction, as GDPR controller status is determined by factual circumstances rather than contractual designation alone.
The updated Privacy Statement now authorizes Palantir to disclose personal data to promotional code partners who may then contact you if you sign up for a Palantir service using their code. This establishes a new third-party contact pathway not previously disclosed in the policy. The terms do not specify how frequently partners may contact you, what data is included in the disclosure, or whether you can opt out of partner contact after signing up.
View change record →Under this provision, payment and contact data submitted during a transaction on Palantir's website is processed by Stripe as an independent data controller, not by Palantir. Data rights requests related to payment data collected through Stripe must be directed to Stripe under Stripe's privacy policy.
Cross-platform context
See how other platforms handle Stripe as Independent Data Controller for Payment Data and similar clauses.
Compare across platforms →Monitoring
Palantir has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"When you make a payment on our website, our payment processor, Stripe, collects your Payment Data and Contact data directly from you. Palantir does not provide Payment Data to Stripe. As a result, Stripe is an independent controller of information provided in the course of using Stripe's payment processing service on Palantir platforms. To understand how Stripe will process your information please see Stripe's privacy policy and Stripe's terms.Excerpt from Palantir's Privacy Statement
1. REGULATORY LANDSCAPE: The designation of Stripe as an independent controller rather than a processor implicates GDPR and UK GDPR requirements for controller-to-controller data sharing arrangements, as well as CCPA's treatment of third-party data sharing. Under GDPR, the distinction between joint controller and independent controller arrangements has compliance implications for transparency obligations and liability allocation. 2. GOVERNANCE EXPOSURE: Low to Medium. The independent controller designation for Stripe is a standard disclosure in the payments context, but organizations transacting with Palantir should confirm that the controller designation is consistent with how the technical integration operates, as the GDPR distinction between controller, joint controller, and processor relationships depends on factual circumstances rather than contractual labels alone. 3. JURISDICTION FLAGS: EEA and UK jurisdictions apply the most detailed requirements regarding controller designation and transparency. The practical enforceability of the independent controller designation under GDPR may depend on the technical and contractual structure of the Palantir-Stripe integration. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should note that Palantir asserts no responsibility for Stripe's processing of payment data, directing users to Stripe's own policies. This limits Palantir's contractual liability with respect to payment data incidents. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should review whether the controller designation is consistent with applicable regulatory guidance and whether adequate notice of Stripe's independent controller status is provided to users prior to payment submission.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that Palantir does not control the processing of payment data once it is submitted via Stripe's payment interface on Palantir platforms. Individuals seeking to exercise data rights over payment data or understand how it is used must engage directly with Stripe under Stripe's own terms and privacy policy.
Under this provision, payment and contact data submitted during a transaction on Palantir's website is processed by Stripe as an independent data controller, not by Palantir. Data rights requests related to payment data collected through Stripe must be directed to Stripe under Stripe's privacy policy.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Palantir.