The policy applies not only to individuals with Stripe accounts but also to end customers of businesses that use Stripe to process transactions, who may have no direct relationship with Stripe.
This analysis describes what Stripe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Stripe processes personal data of individuals who interact with merchant websites powered by Stripe technology, even absent a direct account relationship, which creates distinct data subject rights obligations and controller-processor role considerations under GDPR and CCPA.
Interpretive note: The full scope of Stripe's data processing for non-account-holder end customers is described across multiple sections of the policy and the Privacy Center, which was truncated in the provided document text.
Under this provision, individuals who complete purchases on third-party websites using Stripe's payment infrastructure have their transaction and identity data processed by Stripe under the terms of this policy, regardless of whether they have created a Stripe account.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
To stop us collecting your location information, you can update your device settings, stop using the Service, or uninstall our mobile apps.
"We provide financial infrastructure for the internet. Individuals and businesses of all sizes use our technology and services to facilitate purchases, accept payments, send payouts, and manage their online businesses. This Privacy Policy describes the Personal Data that we collect, how we use and share it, and how you can reach us with privacy-related inquiries.Excerpt from Stripe's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that Stripe processes personal data of individuals who interact with merchant websites powered by Stripe technology, even absent a direct account relationship, which creates distinct data subject rights obligations and controller-processor role considerations under GDPR and CCPA.
Under this provision, individuals who complete purchases on third-party websites using Stripe's payment infrastructure have their transaction and identity data processed by Stripe under the terms of this policy, regardless of whether they have created a Stripe account.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Stripe.