Stripe · Stripe Terms of Service

Data Processing and Privacy

High severity
Share 𝕏 Share in Share 🔒 PDF
Watch Stripe Get alerts when this provision or policy changes.
Watch — $9.99/mo

What it is

Stripe collects and shares your business data and your customers' payment data with its partners, banking providers, and card networks. You're responsible for making sure your customers agreed to have their data processed by Stripe.

Why it matters (compliance & risk perspective)

Merchants are responsible for obtaining downstream customer consent for Stripe's data processing, meaning any GDPR or CCPA compliance failures in the merchant's consent mechanisms could expose both the merchant and Stripe to regulatory liability.

Consumer impact (what this means for users)

Merchants bear the contractual obligation to ensure their customers have consented to Stripe's data collection and sharing practices, which means GDPR or CCPA violations in the merchant's checkout flow could result in regulatory liability flowing back to the merchant under the SSA's indemnification clause. End consumers' payment data — including card numbers, bank account details, and transaction history — is shared with a broad network of Stripe affiliates and financial partners.

How other platforms handle this

Dropbox Medium

Dropbox uses certain trusted third parties (for example, providers of customer support and IT services) for the business purposes of helping us provide, improve, protect, and promote our Services. These third parties will access your information to perform tasks on our behalf, and we'll remain respo...

Amazon Medium

When you use Amazon Services, third-party service providers and sellers may receive information about your interactions to the extent necessary for them to fulfill their services. Third-party sellers who sell on Amazon's platform receive customer information necessary to fulfill orders, including na...

Calm Medium

If your Calm subscription has been provided to you by someone else, like your employer or a family member who invited you to use one of their dependent subscriptions, we may inform them that you have signed up for the subscription they offered you;

See all platforms with this clause type →

This clause could change without notice.

Get alerted when Stripe updates this policy — with plain-language summaries and severity ratings.

Watch Stripe Need compliance memos? Professional →
View original clause language
By entering into this Agreement, you authorize Stripe to collect, use, retain, and share information about you and your transactions in accordance with Stripe's Privacy Policy (available at stripe.com/privacy) and any applicable Data Processing Agreement. Stripe may share your data with its affiliates, financial partners, card networks, and as required by applicable law or regulation. You represent and warrant that you have obtained all necessary consents from your customers to permit Stripe to process their payment data as described in the Privacy Policy.

Institutional analysis (Compliance & legal intelligence)

REGULATORY FRAMEWORK: This provision engages GDPR (Regulation 2016/679) Articles 6, 13, 14, 28, and 46 — specifically the controller/processor relationship between the merchant (controller) and Stripe (processor), and the requirement for a Data Processing Agreement (Art. 28). CCPA (Cal. Civ. Code §§ 1798.100-1798.199) applies to California merchants and their customers. PCI-DSS v4.0 applies to all parties handling cardholder data. FinCEN's Customer Due Diligence Rule (31 C.F.R. § 1010.230) and Bank Secrecy Act (31 U.S.C. § 5318) require Stripe to collect and retain transaction and identity data. ECPA (18 U.S.C. § 2510 et seq.) may apply to certain data interception practices.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations. Professional: full compliance memo.

Applicable agencies

  • FTC
    The FTC enforces against unfair or deceptive data practices under Section 5 of the FTC Act and has authority over commercial data sharing by payment processors.
    File a complaint →
  • State AG
    State attorneys general enforce CCPA and state privacy laws applicable to merchants and their payment processors, including data sharing without adequate consumer notice.
    File a complaint →

Applicable regulations

BIPA
Illinois, USA
CCPA/CPRA
California, USA
COPPA
United States Federal
CAN-SPAM
United States Federal
DMA
European Union
FCRA
United States Federal
GDPR
European Union
GLBA
United States Federal
HIPAA
United States Federal
UK GDPR
United Kingdom

Provision details

Document information
Document
Stripe Terms of Service
Entity
Stripe
Document last updated
April 29, 2026
Tracking information
First tracked
March 15, 2026
Last verified
April 9, 2026
Record ID
CA-P-002351
Document ID
CA-D-00107
Evidence Provenance
Source URL
Wayback Machine
SHA-256
f8031ea85047f87e96bd4f8806a7d96cf4b6716e28a2c1a50dc99260b9a49889
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: Stripe | Document: Stripe Terms of Service | Record: CA-P-002351
Captured: 2026-03-15 11:34:26 UTC | SHA-256: f8031ea85047f87e…
URL: https://conductatlas.com/platform/stripe/stripe-terms-of-service/data-processing-and-privacy/
Accessed: May 4, 2026
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Don't miss changes to this clause.

Stripe has updated this policy before. Get alerted on the next change.

Watch Stripe

Frequently Asked Questions

What does Stripe's Data Processing and Privacy clause do?

Merchants are responsible for obtaining downstream customer consent for Stripe's data processing, meaning any GDPR or CCPA compliance failures in the merchant's consent mechanisms could expose both the merchant and Stripe to regulatory liability.

How does this clause affect you?

Merchants bear the contractual obligation to ensure their customers have consented to Stripe's data collection and sharing practices, which means GDPR or CCPA violations in the merchant's checkout flow could result in regulatory liability flowing back to the merchant under the SSA's indemnification clause. End consumers' payment data — including card numbers, bank account details, and transaction history — is …

Is ConductAtlas affiliated with Stripe?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Stripe.