Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that Stripe may collect biometric data as part of its identity verification services, where applicable under local law.
This analysis describes what Stripe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that biometric data collection is within scope of Stripe's data practices for identity verification purposes, which engages state biometric privacy statutes and GDPR special category data provisions requiring explicit consent.
Interpretive note: The specific biometric data collection and consent mechanisms are referenced in the policy but the relevant sections were truncated in the provided document text; full assessment requires review of the complete policy.
Under this provision, individuals using Stripe's identity verification services may have biometric data collected and processed, subject to applicable law and the consent mechanisms Stripe employs in those contexts.
How other platforms handle this
The right to notice. You have the right to be notified which categories of Personal Data are being collected and the purposes for which the Personal Data is being used.
In certain circumstances, the right to data portability, which means that you can request that we provide certain Personal Data we hold about you in a machine-readable format
If you want to see what information we have collected about you, you can request a copy of your data in the Data & Privacy section of your User Settings. You should receive your data packet within 30 days.
Monitoring
Stripe has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"This Privacy Policy describes the Personal Data that we collect, how we use and share it, and how you can reach us with privacy-related inquiries.Excerpt from Stripe's Privacy Policy
1. REGULATORY LANDSCAPE: Biometric data collection engages Illinois BIPA, Texas and Washington state biometric privacy laws, GDPR Article 9 special category data provisions (requiring explicit consent or another specified legal basis), and CCPA sensitive personal information provisions. Enforcement authorities include state attorneys general and EU data protection authorities. BIPA in particular carries statutory damages provisions that have produced significant class action litigation. 2. GOVERNANCE EXPOSURE: High. Biometric data is subject to heightened statutory protections in multiple U.S. states and under GDPR. Collection without compliant consent mechanisms, inadequate retention and destruction schedules, or unauthorized disclosure can expose both Stripe and its merchant clients to regulatory enforcement and private litigation. Illinois BIPA does not require a showing of actual harm for statutory damages. 3. JURISDICTION FLAGS: Illinois residents have direct BIPA claims; Texas and Washington residents have state-specific biometric privacy protections. EU and EEA residents are protected under GDPR Article 9 explicit consent requirements for biometric data. Any Stripe merchant that uses Stripe's identity verification service with customers in these jurisdictions should assess whether its own privacy disclosures and consent mechanisms are compliant. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations using Stripe's identity verification features should confirm whether Stripe's data processing agreement addresses biometric data specifically, including retention limits, subprocessor restrictions, and deletion obligations. These terms may require negotiation or addendum for organizations with heightened exposure in BIPA jurisdictions. 5. COMPLIANCE CONSIDERATIONS: Organizations deploying Stripe identity verification should conduct a data protection impact assessment where required under GDPR Article 35, given the special category status of biometric data. Consent flows presented to end users should specifically identify biometric data collection and its purpose. Retention and deletion schedules for biometric data should be confirmed with Stripe and documented in internal data inventories.
Regulatory citations, enforcement risk, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes that biometric data collection is within scope of Stripe's data practices for identity verification purposes, which engages state biometric privacy statutes and GDPR special category data provisions requiring explicit consent.
Under this provision, individuals using Stripe's identity verification services may have biometric data collected and processed, subject to applicable law and the consent mechanisms Stripe employs in those contexts.
ConductAtlas has identified this type of provision across 295 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Stripe.