Stripe · Stripe Privacy Policy

Fraud Prevention and Legitimate Interests Basis

High severity
Share 𝕏 Share in Share

What it is

Stripe uses your personal data — including transaction history and device information — in automated fraud detection systems, relying on its 'legitimate interests' as the legal basis rather than your consent.

Consumer impact (what this means for users)

Your financial and behavioral data may be processed by automated machine learning systems for fraud risk scoring without your consent, and this processing may affect your ability to complete transactions or use financial services if you are flagged.

How other platforms handle this

T-Mobile Medium

Yes, for many of our products and services. We may get information about your credit history from credit-reporting agencies and from other third parties, which may affect your credit rating, in connection with your application for a Product or Service, and to review or collect on your account. We ma...

Square Medium

When you interact with our online services, or open emails we send you, we obtain certain information using automated technologies, such as cookies, web server logs, web beacons and other technologies. A "cookie" is a text file that websites send to a visitor's computer or other internet-connected d...

Apple Medium

Location information. Precise location only with your permission — for example, for features like Find My or Maps. Some location-related functionality uses Wi-Fi, Bluetooth, and cell tower locations, as well as GPS. Location can also be inferred from other data such as an IP address.

See all platforms with this clause type →
Need full compliance memos? See Professional →

Why it matters (compliance & risk perspective)

Relying on 'legitimate interests' for automated fraud processing means Stripe does not need your consent and you have a limited right to object, but this basis is subject to a balancing test under GDPR that Stripe must be able to demonstrate it has conducted.

View original clause language
We use Personal Data to detect, prevent, and mitigate fraud, abuse, and other harmful or illegal activities affecting Stripe, our users, or others. We may use automated tools and machine learning to process Personal Data for fraud detection and security purposes. This processing is based on our legitimate interests and those of third parties in maintaining secure and reliable Services.

Institutional analysis (Compliance & legal intelligence)

REGULATORY FRAMEWORK: Use of automated processing for fraud detection implicates GDPR Art. 6(1)(f) (legitimate interests), Art. 22 (automated decision-making with legal or similarly significant effects), and Recital 71 (profiling). CCPA §1798.185 and CPRA §1798.100 provide consumers with opt-out rights for certain profiling. EU AI Act (Regulation 2024/1689) may classify high-risk AI systems used in payment fraud detection in a regulated category. FTC Act Section 5 applies to deceptive or unfair automated decision systems.

🔒

Compliance intelligence locked

Regulatory citations, enforcement risk, and due diligence action items.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations. Professional: full compliance memo.

Applicable agencies

  • CFPB
    Automated fraud scoring that affects payment processing or financial access may implicate CFPB regulations on fair lending, adverse action notices, and consumer financial protection.
    File a complaint →
  • FTC
    Automated profiling and decision-making using personal data without consent may constitute an unfair practice under FTC Act Section 5.
    File a complaint →

Applicable regulations

EU AI Act
European Union
BIPA
Illinois, USA
CCPA/CPRA
California, USA
COPPA
United States Federal
CAN-SPAM
United States Federal
DMA
European Union
FCRA
United States Federal
GDPR
European Union
GLBA
United States Federal
HIPAA
United States Federal
TCPA
United States Federal
UK GDPR
United Kingdom

Provision details

Document information
Document
Stripe Privacy Policy
Entity
Stripe
Document last updated
March 24, 2026
Tracking information
First tracked
March 15, 2026
Last verified
April 9, 2026
Record ID
CA-P-002342
Document ID
CA-D-00106
Evidence Provenance
Source URL
Wayback Machine
SHA-256
87ac9fcdb4b3be9c7831662daf59f5425643d84690f687c3e918ab83a226dd37
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: Stripe | Document: Stripe Privacy Policy | Record: CA-P-002342
Captured: 2026-03-15 11:47:00 UTC | SHA-256: 87ac9fcdb4b3be9c…
URL: https://conductatlas.com/platform/stripe/stripe-privacy-policy/fraud-prevention-and-legitimate-interests-basis/
Accessed: April 28, 2026
Classification
Severity
High
Categories

Other provisions in this document

Related Analysis