Monitored company
Stripe
clause.watch tracks 1 legal document published by Stripe, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy & terms
Privacy Policy Overview
Document date: Last updated April 28, 2026.
This document is primarily a privacy policy, not a complete terms-of-service agreement. It explains data practices but does not set out detailed contractual rules, warranties, liability caps, governing law, or dispute procedures for using Stripe’s services.
1. Data Collection & Usage
The data collected depends on whether you are an End User, End Customer, Business Representative, or Visitor.
Types of data collected
- Identity and contact data: name, email, phone number, address, date of birth, government ID, tax ID, ownership information, and login credentials.
- Payment and transaction data: card or bank details, payment method images, purchase amount and date, merchant and location, payment status, refunds, chargebacks, subscriptions, fulfillment, tax information, and transaction history.
- Financial information: bank-account details, balances, account transactions, login credentials supplied through Financial Connections, credit reports, income, and—where relevant—Social Security numbers.
- Verification and biometric data: identity documents, selfies, and potentially biometric matching information. Some biometric processing requires consent.
- Technical and online activity: IP address, device and browser information, cookies, pages visited, links clicked, language, time spent, referral pages, and mouse-activity indicators.
- Communications: support tickets, emails, surveys, phone calls, chats, event participation, forum posts, and recordings or transcripts of calls.
- Location and premises data: approximate location and CCTV or audiovisual data at Stripe offices or events.
Main purposes
Stripe uses data to:
- Process payments, payouts, refunds, subscriptions, accounting, tax, and disputes.
- Provide, personalize, improve, and develop its services.
- Verify identity, conduct credit checks, and comply with KYC/AML, sanctions, tax, and other legal requirements.
- Detect fraud, unauthorized transactions, security threats, misuse, and financial losses.
- Communicate service notices, authentication codes, support information, surveys, and marketing.
- Advertise Stripe services and measure advertising effectiveness.
A significant risk is that Stripe may receive checkout information even when you abandon a transaction.
2. User Rights
Depending on location and legal limitations, users may request:
- Confirmation and access to their data.
- Information about categories of data and recipients.
- Correction or updating of inaccurate data.
- Deletion in legally permitted circumstances.
- Restriction of processing.
- Data portability.
- Withdrawal of consent.
- Objection to processing based on legitimate interests.
- Opt-out from marketing communications.
- Appeal of decisions concerning privacy requests.
Requests can generally be made through Stripe’s Privacy Center or its Data Protection Officer at dpo@stripe.com. If Stripe acts only as a processor for a merchant, users generally must exercise rights through that merchant. Merchants may have their own privacy practices and may independently use the data for marketing.
US users may also have rights to opt out of targeted advertising and certain legally defined “sales” or “sharing.” Stripe honors Global Privacy Control signals. Financial privacy rules may limit some rights for users obtaining consumer financial products.
3. Third-Party Sharing
Data may be shared with:
- The merchant or Business User involved in the transaction.
- Banks, card networks, payment processors, acquirers, and other Financial Partners.
- Identity-verification, fraud-prevention, credit-reporting, cloud, analytics, customer-support, and audit providers.
- Stripe affiliates.
- Advertising partners, analytics companies, and social networks.
- Government, law-enforcement, courts, regulators, and tax authorities.
- Purchasers or successor entities in a merger, sale, restructuring, or similar transaction.
- Other partners when you consent or request a related service, such as BNPL or crypto services.
Stripe states it does not sell personal data for payment, but its disclosures to advertising partners may legally constitute “sale” or “sharing” under some US laws.
4. AI/ML Training
Yes. Stripe expressly says it may use Personal Data to train AI models that power its services and fraud-protection systems. It also analyzes transaction data, call recordings, and chat transcripts for service improvement, quality assurance, training, and operational purposes. The policy does not clearly explain whether all such data is anonymized, how long training data is retained, or whether users can opt out generally.
5. Key User Obligations and Risks
Account holders must:
- Protect passwords and API keys.
- Use strong, unique credentials.
- Promptly report suspected security compromises.
- Provide accurate identity, business, financial, and tax information.
- Comply with applicable laws and Stripe’s service agreements.
Users should understand that fraud systems, credit checks, sanctions screening, and automated risk assessments may affect transaction approval, account access, or financial-service eligibility.
6. Liability & Disputes
This policy:
- Disclaims any guarantee that data transmission or storage is completely secure.
- Does not provide a complete liability limitation, warranty disclaimer, indemnity, arbitration clause, governing-law provision, or dispute-resolution process.
- Directs unresolved privacy concerns in certain international-transfer contexts to third-party dispute mechanisms and relevant regulators.
The separate Stripe Services Agreement, Consumer Terms, merchant terms, and applicable financial-product agreements may contain the operative liability and dispute terms.
7. Changes
Stripe may revise the policy for new services, legal requirements, or changed practices. Changes become effective when posted or when legally required notice is provided. Notice may appear on Stripe’s website, Dashboard, email, or physical address associated with an account. Users should monitor the “Last updated” date and account communications.
Change history
2026-09-06 · Privacy & terms
2026-09-01 · Privacy & terms
2026-09-01 · Privacy & terms
2026-08-24 · Privacy & terms
2026-08-22 · Privacy & terms
2026-08-21 · Privacy & terms
2026-08-21 · Privacy & terms
2026-08-20 · Privacy & terms
2026-08-19 · Privacy & terms
2026-08-19 · Privacy & terms
2026-08-18 · Privacy & terms
2026-04-28 · Privacy & terms
The publisher records this document as revised on this date (“Last updated: April 28, 2026”).
Between 2019-08-07 and 2020-01-19 · Privacy & terms
Between 2013-07-06 and 2019-02-20 · Privacy & terms