The policy authorizes Stripe to use transaction, identity, and device data across its network of merchants and financial partners for fraud detection and financial risk assessment purposes.
This analysis describes what Stripe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision permits Stripe to share personal and financial data across its broader merchant ecosystem for fraud prevention purposes, which implicates data minimization and purpose limitation requirements under GDPR and equivalent frameworks, and may affect individuals' transaction outcomes across multiple unrelated merchants.
Interpretive note: The specific categories of data shared within the fraud prevention network and the precise scope of cross-merchant data use are described in sections of the policy that were truncated in the provided document text.
Under this provision, transaction and identity data associated with a user's activity at one Stripe-powered merchant may be used to assess fraud risk at other Stripe-powered merchants, as part of Stripe's stated fraud prevention network.
How other platforms handle this
We will also provide an individual opt-out choice, or opt-in for sensitive data, before we share your data with third parties other than our agents, or before we use it for a purpose other than which it was originally collected.
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
"We provide financial infrastructure for the internet. Individuals and businesses of all sizes use our technology and services to facilitate purchases, accept payments, send payouts, and manage their online businesses.Excerpt from Stripe's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision permits Stripe to share personal and financial data across its broader merchant ecosystem for fraud prevention purposes, which implicates data minimization and purpose limitation requirements under GDPR and equivalent frameworks, and may affect individuals' transaction outcomes across multiple unrelated merchants.
Under this provision, transaction and identity data associated with a user's activity at one Stripe-powered merchant may be used to assess fraud risk at other Stripe-powered merchants, as part of Stripe's stated fraud prevention network.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Stripe.