Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that Stripe collects government-issued identification information, including identification numbers and document images, as part of identity verification processes for account holders and transaction participants.
This analysis describes what Stripe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Collection of government-issued identification data engages heightened sensitivity requirements under multiple privacy frameworks and triggers specific obligations regarding secure storage, limited retention, and restricted sharing under applicable identity verification and financial services regulations.
Interpretive note: The specific categories of government identification collected and the retention and deletion schedules are disclosed in sections of the policy that were truncated in the provided document text.
Under this provision, individuals required to complete identity verification through Stripe's services will have government-issued identification data collected and processed, subject to the retention and security obligations described in the policy and applicable law.
How other platforms handle this
The right to notice. You have the right to be notified which categories of Personal Data are being collected and the purposes for which the Personal Data is being used.
In certain circumstances, the right to data portability, which means that you can request that we provide certain Personal Data we hold about you in a machine-readable format
If you want to see what information we have collected about you, you can request a copy of your data in the Data & Privacy section of your User Settings. You should receive your data packet within 30 days.
Monitoring
Stripe has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"This Privacy Policy describes the Personal Data that we collect, how we use and share it, and how you can reach us with privacy-related inquiries.Excerpt from Stripe's Privacy Policy
1. REGULATORY LANDSCAPE: Collection of government-issued identification numbers engages CCPA sensitive personal information provisions (which include government identification numbers), GDPR special category adjacent provisions regarding data that carries particular risks, and U.S. financial services know-your-customer requirements under the Bank Secrecy Act and FinCEN regulations. State identity theft protection laws in multiple U.S. jurisdictions impose additional restrictions on handling of government identification numbers. 2. GOVERNANCE EXPOSURE: High. Government identification data is among the highest-sensitivity categories in most privacy frameworks. Unauthorized access, improper retention, or unlawful disclosure creates significant regulatory exposure and potential harm to data subjects. The combination of identity document images with financial account data creates a high-value data set from a security perspective. 3. JURISDICTION FLAGS: California residents have specific rights regarding sensitive personal information including government identification numbers under CPRA, including a right to limit use. EU and EEA residents may have rights under GDPR depending on how identification data is categorized in the specific processing context. U.S. states with identity theft protection laws impose security requirements for entities holding government identification numbers. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations using Stripe's identity verification services should review the sub-processors list at stripe.com/service-providers/legal to identify any third parties who may access government identification data as part of verification workflows. Subprocessor agreements should be assessed for appropriate data handling and security obligations. 5. COMPLIANCE CONSIDERATIONS: Organizations deploying Stripe identity verification should confirm that data retention schedules for government identification documents comply with applicable law and Stripe's stated practices. End-user consent flows should specifically identify government identification collection and its purpose. Internal data inventories should document government identification data flows through Stripe infrastructure.
Regulatory citations, enforcement risk, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Collection of government-issued identification data engages heightened sensitivity requirements under multiple privacy frameworks and triggers specific obligations regarding secure storage, limited retention, and restricted sharing under applicable identity verification and financial services regulations.
Under this provision, individuals required to complete identity verification through Stripe's services will have government-issued identification data collected and processed, subject to the retention and security obligations described in the policy and applicable law.
ConductAtlas has identified this type of provision across 295 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Stripe.