Last updated: January 16, 2026
This Privacy Policy includes important information about your personal data and we encourage you to read it carefully.
This Privacy Policy includes important information about your personal data and we encourage you to read it carefully.
We've recently added a new data controller, Stripe Technology Company Limited, to our Privacy Center. For an overview of current Stripe data controllers please visit our Privacy Center.
We provide financial infrastructure for the internet. Individuals and businesses of all sizes use our technology and services to facilitate purchases, accept payments, send payouts, and manage their online businesses.
This Privacy Policy (“Policy”) describes the Personal Data that we collect, how we use and share it, and how you can reach us with privacy-related inquiries. The Policy also outlines your rights and choices as a data subject, including the right to object to certain uses of your Personal Data.
Depending on the activity, Stripe assumes the role of a “data controller” and/or “data processor” (or “service provider”). For more details about our privacy practices, including our role, the specific Stripe entity responsible under this Policy, and our legal bases for processing your Personal Data, please visit our Privacy Center.
In this Policy, "Stripe", "we", "our," or "us" refers to the Stripe entity responsible for the collection, use, processing, and handling of Personal Data as described in this document. Depending on your jurisdiction, the specific Stripe entity responsible for your Personal Data might vary. Learn More.
"Personal Data" refers to any information associated with an identified or identifiable individual, which can include data that you provide to us, and that we collect about you during your interaction with our Services (such as device information, IP address, etc.).
"Services" refers to the products, services, devices, and applications that we provide under the Stripe Services Agreement or the Stripe Credit Card Terms of Service (collectively, "Business Services"), or the Stripe Consumer Terms of Service ("End User Services"); websites ("Sites") like Stripe.com and Link.com; and other Stripe applications and online services. We provide Business Services to entities ("Business Users"). We provide End User Services directly to individuals for their personal use.
"Financial Partners" are financial institutions, banks, and other partners such as payment method acquirers, payment intermediaries, payment aggregators, payout providers, payment method providers, payment processors, and card networks that we partner with, directly or indirectly, to provide the Services.
Depending on the context, "you" might be an End Customer, End User, Representative, or Visitor:
In this Policy, "Transaction Data" refers to data collected or used by Stripe in relation to transactions you request. Some Transaction Data is Personal Data and may include: your name, email address, contact number, billing and shipping address, payment method information (like credit or debit card number, bank or payment method account details, or payment card image chosen by you), merchant and location details, amount and date of purchase, information about payment status, and in some instances, information about what was purchased, order fulfillment status, subscription status, applicable tax amounts, refund or chargeback information, and support interactions.
1. Personal Data that we collect and how we use and share it
2. More ways we collect, use and share Personal Data
3. Legal bases for processing data
6. International data transfers
For purposes of the General Data Protection Regulation (GDPR) and other applicable data protection laws, we rely on a number of legal bases to process your Personal Data. Learn More. For some jurisdictions, there may be additional legal bases, which are outlined in the Jurisdiction-Specific Provisions section below.
a. Contractual and Pre-Contractual Business Relationships. We process Personal Data to enter into business relationships with prospective Business Users and End Users and fulfill our respective contractual obligations with them. These processing activities include:
b. Legal Compliance. We process Personal Data to verify the identities of individuals and entities to comply with obligations related to fraud monitoring, prevention, and detection, laws associated with identifying and reporting illicit and illegal activities, such as those under the Anti-Money Laundering ("AML") and Know-Your-Customer ("KYC") regulations, and financial reporting obligations. For example, we may be required to record and verify a Business User's identity to comply with regulations designed to prevent money laundering, fraud, and financial crimes. These legal obligations may require us to report our compliance to third parties and subject ourselves to third party verification audits.
c. Legitimate Interests. Where permitted under applicable law, we rely on our legitimate business interests to process your Personal Data. The following list provides an example of the business purposes for which we have a legitimate interest in processing your data:
d. Consent. We may rely on consent or explicit consent to collect and process Personal Data regarding our interactions with you and the provision of our Services such as Link, Financial Connections, Atlas, and Identity. When we process your Personal Data based on your consent, you have the right to withdraw your consent at any time, and such a withdrawal will not impact the legality of processing performed based on the consent prior to its withdrawal.
e. Substantial Public Interest. We may process special categories of Personal Data, as defined by the GDPR, when such processing is necessary for reasons of substantial public interest and consistent with applicable law, such as when we conduct politically-exposed person checks. We may also process Personal Data related to criminal convictions and offenses when such processing is authorized by applicable law, such as when we conduct sanctions screening to comply with AML and KYC obligations.
f. Other valid legal bases. We may process Personal Data further to other valid legal bases as recognized under applicable law in specific jurisdictions. See the Jurisdiction-specific provisions section below for more information.
Depending on your location and subject to applicable law, you may have choices regarding our collection, use, and disclosure of your Personal Data:
If you wish to stop receiving marketing-related communications from us, you can opt-out by clicking the unsubscribe link included in such communications or as described here. We'll try to process your request(s) as quickly as reasonably practicable. However, it's important to note that even if you opt out of receiving marketing-related communications from us, we retain the right to communicate with you about the Services you receive (like support and important legal notices) and our Business Users might still send you messages or instruct us to send you messages on their behalf.
Depending on your location and subject to applicable law, you may have the following rights regarding the Personal Data we process about you as a data controller:
You may have additional rights, depending on applicable law, over your Personal Data. See the Jurisdiction-specific provisions section below.
To exercise your data protection rights related to Personal Data we process as a data controller, visit our Privacy Center or contact us as outlined below. For Personal Data we process as a data processor, please reach out to the relevant data controller (Business User) to exercise your rights. If you contact us regarding your Personal Data we process as a data processor, we will refer you to the relevant data controller to the extent we are able to identify them.
We make reasonable efforts to provide a level of security appropriate to the risk associated with the processing of your Personal Data. We maintain organizational, technical, and administrative measures designed to protect the Personal Data covered by this Policy from unauthorized access, destruction, loss, alteration, or misuse. Learn More. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure.
We encourage you to assist us in protecting your Personal Data. If you hold a Stripe account, you can do so by using a strong password, safeguarding your password or API key against unauthorized use, and avoiding using identical login credentials you use for other services or accounts for your Stripe account. If you suspect that your interaction with us is no longer secure (for instance, you believe that your Stripe account's security has been compromised), please contact us immediately.
We retain your Personal Data for as long as we continue to provide the Services to you or our Business Users, or for a period in which we reasonably foresee continuing to provide the Services. Even after we stop providing Services directly to you or to a Business User that you're doing business with, and even after you close your Stripe account or complete a transaction with a Business User, we may continue to retain your Personal Data to:
In cases where we keep your Personal Data, we do so in accordance with any limitation periods and record retention obligations imposed by applicable law. Learn More.
As a global business, it's sometimes necessary for us to transfer your Personal Data to countries other than your own, including the United States and India. These countries might have data protection regulations that are different from those in your country. When transferring data across borders, we take measures to comply with applicable data protection laws related to such transfer. In certain situations, we may be required to disclose Personal Data in response to lawful requests from officials, such as law enforcement or security authorities. Learn More.
If you are located in the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland, please refer to our Privacy Center for additional details. When a data transfer mechanism is mandated by applicable law, we employ one or more of the following:
Stripe complies with the EU-U.S. Data Privacy Framework ("EU-U.S. DPF"), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework as set forth by the U.S. Department of Commerce and as applicable. Learn More.
Stripe's privacy practices, as described in this Privacy Policy, comply with the Cross Border Privacy Rules System ("CBPR") and Privacy Rules for Processor ("PRP") systems. These systems provide a framework for organizations to ensure protection of personal data transferred among participating economies. Where CBPR and/or PRP are recognized as a valid transfer mechanism under applicable law, Stripe will transfer Personal Data in accordance with the CBPR and PRP certifications Stripe has obtained. More information about the framework can be found here and here. If you have unresolved privacy or data use concerns that we have not addressed satisfactorily, please contact our U.S. based third-party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request. To view the status of our certifications, please click here (CBPR) and here (PRP).
We may change this Policy from time to time to reflect new services or changes in our privacy practices or relevant laws. The "Last updated" legend at the top of this Policy indicates when this Policy was last materially revised. Any changes are effective the latter of when we post the revised Policy on the Services or otherwise provide notice of the update as required by law.
We may provide you with disclosures and alerts regarding the Policy or Personal Data collected by posting them on our website and, if you are an End User or Representative, by contacting you through your Stripe Dashboard, email address and/or the physical address listed in your Stripe account.
Where required, we have put in place appropriate safeguards for the cross-border transfer of Personal Data from Brazil, including the Brazilian Standard Contractual Clauses.
If you have any questions or complaints about this Policy, please contact us. If you are an End Customer (i.e., an individual doing business or transacting with a Business User), please refer to the privacy policy or notice of the Business User for information regarding the Business User's privacy practices, choices and controls, or contact the Business User directly.
The following Consumer Privacy Notice applies to you if you are an individual who resides in the United States and obtains financial services from Stripe primarily for your own personal, family, or household purposes.
Last updated: January 16, 2026
| FACTS | WHAT DOES STRIPE DO WITH YOUR PERSONAL INFORMATION? |
|---|---|
| Why? | Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect your personal information. Please read this notice carefully to understand what we do. |
| What? | The types of personal information we collect and share depend on the product or service you have with us. This information can include: • Social Security Number • Contact details • Account balances and transaction history • Payment, transaction, and purchase information and history • Credit reports and other information necessary to facilitate credit card issuing When you are no longer our customer, we continue to share your information as described in this notice. |
| How? | All financial companies need to share customers' personal information to run their everyday business. In the section below, we list the reasons financial companies can share their customers' personal information; the reasons Stripe chooses to share; and whether you can limit this sharing. |
| Reasons we can share your personal information | Does Stripe Share? | Can you limit this sharing |
|---|---|---|
| For our everyday business purposes - such as to process your transactions, detect fraud and prevent loss for you, us, as well as our Business Users and Financial Partners, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus | Yes | No |
| For our marketing purposes - to offer our products and Services to you | Yes | No |
| For joint marketing with other financial companies | Yes | No |
| For our affiliates' everyday business purposes - information about your transactions and experiences | Yes | No |
| For our affiliates' everyday business purposes - information about your creditworthiness | No | We don't share |
| For our affiliates to market to you | No | We don't share |
| For nonaffiliates to market to you (for data not collected through Financial Connections). | Yes | Yes |
| For nonaffiliates to market to you (for data collected through Financial Connections) | No | We don't share |
| To limit our sharing | Login to your Link account at app.link.com/settings and toggle off data sharing from the Messaging menu. Please note: If you are a new customer, we can begin sharing your information 30 days from the date we sent this notice. When you are no longer our customer, we continue to share your information as described in this notice. However, you can contact us at any time to limit our sharing. |
|---|
| Questions? | Contact us at privacy@stripe.com or visit us at https://support.link.com |
|---|
| Who we are | |
|---|---|
| Who is providing this notice? | Stripe, Stripe Payments Company, and their affiliates that provide consumers services in the U.S. |
| What we do | |
|---|---|
| How does Stripe protect my personal information? | To protect your personal information from unauthorized access, destruction, loss, alteration, or misuse we use security measures to comply with federal law. These measures include computer safeguards and secured files and buildings. We impose access controls along with ongoing monitoring to prevent data misuse, and we require our service providers to take similar steps to protect your information. |
| How does Stripe collect my personal information? | We collect your personal information, for example, when you • open a Link account; • ask Stripe to process a payment for goods or services; • provide bank account information to Stripe using Financial Connections We also collect your personal information from others, such as affiliates or other companies. |
| Why can't I limit all sharing? | Federal law gives you the right to limit only • sharing for affiliates' everyday business purposes — information about your creditworthiness • affiliates from using your information to market to you • sharing for nonaffiliates to market to you. State laws and individual companies may give you additional rights to limit sharing. See the Other Important Information section below for more information on your rights under state law. |
| What happens when I limit sharing for an account I hold jointly with someone else? | Your choices will apply to everyone on your account. |
| Definitions | |
|---|---|
| Affiliates | Companies related by common ownership or control. They can be financial and nonfinancial companies. • Our affiliates include companies operating under the Stripe name, such as Stripe Technology Europe, Ltd. and Stripe Payments UK, Ltd. |
| Nonaffiliates | Companies not related by common ownership or control. They can be financial and nonfinancial companies. • Nonaffiliates with which we share personal information include service providers that perform services or functions on our behalf, Business Users with which you choose to transact, partners with which we share data to provide you with services, and advertising partners, analytics providers, and social networks, who assist us in advertising our Services to you. |
| Joint Marketing | A formal agreement between non-affiliated financial companies that together market financial products or services to you. • Our joint marketing partners include financial companies we partner with to provide you with financial services. |
| Other important information |
|---|
Vermont: If your account with us is associated with a Vermont billing address, we will not disclose information about your creditworthiness to our affiliates and will not disclose your personal information, financial information, credit report, or health information to nonaffiliated third parties to market to you, other than as permitted by Vermont law, unless you authorize us to make those disclosures. For joint marketing, we will only disclose your name, contact information, and information about your transactions. Additional information concerning our privacy policies can be found in our Privacy Policy and Privacy Center. California: If your account with us is associated with a California billing address, we will not disclose Personal Data we collect about you except to the extent permitted under California law. For instance, we may disclose your Personal Data as necessary to process transactions or provide products and services you request, at your instruction, as required for institution risk control, and to safeguard against fraud, identity theft, and unauthorized transactions. |
For additional information about our privacy practices, please visit the Stripe Privacy Center and Link Privacy Center.