Provision record
Stripe · Stripe Privacy Policy · View original document ↗

Dual Controller and Processor Role

High severity Medium confidence Explicit document language Common · 290 of 352 platforms
Stay ahead of the changes
Track Stripe and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

Depending on what you are doing with Stripe, Stripe may be responsible for your data as the primary decision-maker (controller) or as a company processing data on behalf of the business you bought from (processor). This distinction affects whether you can ask Stripe directly to access or delete your data.

This analysis describes what Stripe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

When Stripe acts as a processor on behalf of a Business User, your privacy rights requests may need to go to the merchant, not Stripe. This can make exercising rights more complex for consumers who interact with Stripe only through third-party checkouts.

Interpretive note: The practical allocation of controller versus processor responsibilities for specific data flows depends on the contractual arrangements between Stripe and individual Business Users, which are not fully disclosed in this policy.

Clause Stability Stable

0
Changes
5
Months Monitored
May 10, 2026
First Seen
May 20, 2026
Last Seen
This clause type exists across 5149 other provisions on other platforms.

Change history

modified May 19, 2026

Severity increased from medium to high; quotation marks changed from single to double quotes with no substantive content change.

View full change record →

Consumer impact (what this means for users)

Consumers who have paid through a Stripe-powered merchant checkout may find that their access, deletion, or correction requests must be directed to the merchant rather than to Stripe, because Stripe processes that data as a service provider on the merchant's behalf rather than as a data controller in its own right.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Visit Stripe's Privacy Center to identify whether Stripe is the controller for your data. If so, submit a deletion or access request through the form provided. If Stripe is acting as a processor for a merchant, contact that merchant directly.

How other platforms handle this

ZipRecruiter Medium

Where ZipRecruiter processes your Personal Data in the capacity of a service provider (data processor), and you seek access, or want to correct, amend, or delete your Personal Data...we will provide you with the data controller's contact information, so you can contact them directly.

Tinder Medium

If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.

Skillshare Medium

When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
Depending on the activity, Stripe assumes the role of a "data controller" and/or "data processor" (or "service provider"). For more details about our privacy practices, including our role, the specific Stripe entity responsible under this Policy, and our legal bases for processing your Personal Data, please visit our Privacy Center.

Excerpt from Stripe's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: The controller/processor distinction directly engages GDPR Articles 4, 24, and 28, which impose different obligations and liability frameworks on controllers versus processors.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FCRA
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
GLBA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
UK GDPR
United Kingdom
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Stripe Privacy Policy
Entity
Stripe
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
May 12, 2026
Record ID
CA-P-008376
Document ID
CA-D-00106
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
e890465edaed11bb33b45ff82fa28c2229bfdaefaee990533dbc293b657216d6
Analysis generated
May 10, 2026 05:54 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Stripe
Document: Stripe Privacy Policy
Record ID: CA-P-008376
Captured: 2026-05-10 05:54:16 UTC
SHA-256: e890465edaed11bb…
URL: https://conductatlas.com/platform/stripe/stripe-privacy-policy/provision/CA-P-008376/dual-controller-and-processor-role/
Accessed: Sept. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Stripe's Dual Controller and Processor Role clause do?

When Stripe acts as a processor on behalf of a Business User, your privacy rights requests may need to go to the merchant, not Stripe. This can make exercising rights more complex for consumers who interact with Stripe only through third-party checkouts.

How does this clause affect you?

Consumers who have paid through a Stripe-powered merchant checkout may find that their access, deletion, or correction requests must be directed to the merchant rather than to Stripe, because Stripe processes that data as a service provider on the merchant's behalf rather than as a data controller in its own right.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.

Is ConductAtlas affiliated with Stripe?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Stripe.