8 Total
2 High severity
6 Medium severity
0 Low severity
Summary

Stripe's Privacy Policy establishes the procedures and legal bases for collection, use, and processing of personal data from payment end-users, merchant account holders, and website visitors. The policy specifies that Stripe collects name, contact details, payment card information, bank account details, transaction history, device identifiers, IP addresses, browsing behavior on Stripe-hosted pages, and derived financial profile information. For California residents and EU/UK users, the policy establishes mechanisms for exercising data access, correction, and deletion rights through Stripe's Privacy Center.

Technical / Legal Breakdown

This document is Stripe's global Privacy Policy (last updated April 28, 2026), governing the collection, use, and sharing of Personal Data across Stripe's Business Services, End User Services, websites, and applications, with Stripe acting as either a data controller or data processor depending on the activity. The policy states that Stripe collects identifiers, financial information, transaction data, device and network data, location information, behavioral and usage data, and inferred characteristics, and authorizes sharing with Business Users, Financial Partners, service providers, advertising and analytics partners, and government or law enforcement authorities. The policy distinguishes between multiple data subject roles (End Customers, End Users, Representatives, and Visitors) and asserts that data collected about End Customers is primarily processed as a service provider on behalf of Business Users, which may limit direct consumer rights against Stripe in those contexts. The policy references GDPR, CCPA and the California Privacy Rights Act, the EU-US Data Privacy Framework, the UK-Switzerland frameworks, and applicable financial services regulations; it designates Stripe, Inc. (US) and Stripe Payments Europe Limited (EU/EEA/UK) as the primary responsible entities depending on jurisdiction. Material compliance considerations include the breadth of inferred data and behavioral profiling disclosed, cross-border data transfer mechanisms, the scope of Financial Partners and sub-processors with whom data is shared, and the policy's assertion that Stripe may share data with law enforcement without notice to users in some circumstances.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial

7 important changes detected

7 versions captured · Last updated: May 2026

What changed Stripe updated its privacy policy on May 19, 2026 to replace all references to its payment service 'Link' with 'Onelink.' This is a product rebranding change that affects how the policy describes End User Services, account creation, transaction data collection, and bank account integration. No changes were made to what data Stripe collects, how it processes personal data, or users' rights and obligations.
Why this matters Stripe updated its privacy policy to reflect the rebranding of its Link product to Onelink. This is purely a naming change. All references to Link—including how account creation, payment transactions, and bank account integration work—now refer to Onelink instead. The policy's substantive provisions governing what data Stripe collects, how it uses personal data, and what rights users have remain unchanged.
View full change record →
What changed Stripe updated its Privacy Policy on April 29, 2026 with four minor editorial changes. The policy's last-updated date was changed from February 23, 2026 to April 28, 2026. Stripe's legal entity name was simplified from 'Stripe Inc., now known as Stripe, LLC' to 'Stripe, LLC' in the Data Privacy Framework compliance statement. The reference to learning more about the Data Privacy Framework was expanded from a generic 'Learn More' link to explicit text stating 'You can learn and read Stripe's Data Privacy Framework Policy here'. These are formatting and organizational updates with no material changes to substantive privacy rights or data-handling practices.
Why this matters Stripe's Privacy Policy was updated with editorial revisions that do not substantively alter consumer privacy rights or data practices. The policy continues to state Stripe's compliance with the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. Data Privacy Framework. The clarified link to Stripe's Data Privacy Framework Policy provides more direct access to supplementary framework information, but this is a disclosure improvement rather than a change to how Stripe collects, uses, or shares personal data.
View full change record →

April 25, 2026 low

Stripe updated its privacy policy on April 25, 2026 with minor editorial changes. Three contact email addresses for exercising privacy rights had trailing spaces added after the email addresses. The …

View change record →
April 23, 2026 low

Stripe updated its privacy policy on April 23, 2026, but the substantive changes detected are minimal. The update date listed in the document was revised from February 23, 2026 to …

View change record →
April 18, 2026 low

Stripe updated its Privacy Policy on April 18, 2026 with 39 new sentences and 73 modified sentences. The changes include refined definitions of Stripe entities, expanded descriptions of Financial Partners …

View change record →
March 16, 2026 low

Stripe updated its Privacy Policy on March 16, 2026 with multiple minor edits to defined terms and descriptions. The document's last-updated date was changed from February 23, 2026 to January …

View change record →
March 15, 2026 low

Stripe updated its Privacy Policy on March 15, 2026 with 39 new sentences and 73 modified sentences. The changes clarify definitions of key terms used in the policy, expand the …

View change record →

Recent Provision Changes Apr 25, 2026

8 provisions unchanged.

View full change record →
High — 2 provisions
Medium — 6 provisions

Monitoring

Stripe has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Collection from Third-Party Data Sources and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FCRA
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
GLBA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗

Related Analysis

Consumer Rights · April 21, 2026
Stripe's Reserve and Hold Authority: What the Terms Authorize

Stripe's terms authorize fund reserves, payout withholding, and account termination. Here is what the agreement states and what business ow…

Archival ProvenanceSource & Archival Record
Last Captured May 19, 2026 00:11 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000106
Version ID CA-V-002714
SHA-256 75784d548ae312ef3404c433596e9ade4f9edc9f3d5ae3ade71e1a6f105c97c7
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans