Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement prohibits users from transferring or moving Stripe software, technology, or services, including encryption software, to or from any country in a manner not permitted by applicable law.
This analysis describes what Stripe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a user-facing export control compliance obligation, specifically calling out encryption software, which is subject to Export Administration Regulations in the United States and equivalent controls in other jurisdictions.
Under this clause, users must ensure that any transfer or movement of Stripe software, technology, or services across national borders complies with applicable export control law. The specific mention of encryption software reflects the heightened regulatory attention that encryption technology receives under U.S. export administration rules.
Cross-platform context
See how other platforms handle Export Control and Technology Transfer Restriction and similar clauses.
Compare across platforms →Monitoring
Stripe has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"You must not, and must not allow others to: Transfer or move software, technology, or services (including our software or encryption software) to or from any country in a way that law does not permit.Excerpt from Stripe's Acceptable Use Policy
1. REGULATORY LANDSCAPE: This provision directly engages the U.S. Export Administration Regulations administered by the Bureau of Industry and Security, the International Traffic in Arms Regulations where applicable, and equivalent export control frameworks in the EU (EU Dual-Use Regulation), UK (Export Control Order), and other jurisdictions. The specific reference to 'encryption software' reflects EAR Category 5, Part 2 controls on cryptographic items. Violations of export control law can result in civil and criminal penalties under the Export Control Reform Act. 2. GOVERNANCE EXPOSURE: High for organizations with international operations. Export control violations can result in significant civil penalties, criminal prosecution, and denial of export privileges. The provision places compliance responsibility on the user, which may create exposure for organizations that deploy or distribute Stripe software or services internationally without conducting an export classification review. 3. JURISDICTION FLAGS: Organizations operating in or transferring technology to or from countries subject to U.S. comprehensive sanctions (including Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine) face the highest exposure. EU and UK export control regimes may impose additional restrictions on dual-use technology transfers. The encryption software carve-out warrants specific attention for organizations operating in markets where cryptographic technology is subject to import or export controls. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement and vendor teams should verify that any deployment of Stripe software or services in international locations has been assessed against applicable export classification requirements. Agreements with international partners that involve Stripe software or services should include representations regarding export control compliance. 5. COMPLIANCE CONSIDERATIONS: Legal and compliance teams should conduct an export classification review for any Stripe software or technology components used in cross-border deployments, with particular attention to encryption functionality. Organizations operating in multiple jurisdictions should assess compliance with both U.S. EAR and applicable foreign export control regimes.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes a user-facing export control compliance obligation, specifically calling out encryption software, which is subject to Export Administration Regulations in the United States and equivalent controls in other jurisdictions.
Under this clause, users must ensure that any transfer or movement of Stripe software, technology, or services across national borders complies with applicable export control law. The specific mention of encryption software reflects the heightened regulatory attention that encryption technology receives under U.S. export administration rules.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Stripe.