Link’s updated Privacy Policy will be effective as of November 20, 2026.
This Privacy Policy includes important information about your personal data and we encourage you to read it carefully.
This Privacy Policy includes important information about your personal data and we encourage you to read it carefully.
Link is a digital wallet provided by Stripe that facilitates a variety of payment-related features and services, including saving your information for an accelerated checkout experience. With a Link account, you can use your saved information when shopping with businesses that have enabled Link Services. As part of its suite of consumer services, Link also supports Financial Connections, a separate Stripe feature that allows consumers to securely connect financial accounts and share verified bank data with businesses. This Privacy Policy (“Policy”) explains how Stripe collects, uses, shares, and protects your Personal Data in connection with Link (including when you use services such as Financial Connections through Link), and describes the choices and rights you may have. For information on how Stripe processes Personal Data across its other services, including Payments, Radar, Billing, and Identity, please refer to the Stripe Privacy Policy.
For more details about our privacy practices, including our legal bases for processing your Personal Data, please visit our Privacy Center.
In this Policy, “Link”, “Stripe”, “we”, “our,” or “us” refers to the Stripe entity responsible for the processing of your Personal Data as described in this Policy. We use the term “processing” to mean collecting, using, handling, and any other activity with respect to your Personal Data. The Stripe entity responsible for the processing of your Personal Data depends on your location, and the product or service you use with us:
Where applicable terms or notices identify another entity as responsible for the processing of your Personal Data, that entity will be responsible. We may also use Stripe Affiliates in the same location or other locations, as well as Service Providers and Sub-processors to help provide our Services to you.
Depending on the way in which you interact with Link Services or the Sites, “you” might be an End User or a Visitor:
This section explains the Personal Data we may collect about End Users and Visitors. Our collection and use of Personal Data differs based on whether you are an End User or Visitor, as well as the specific Service that you are using. For example, you are an End User if you used Link to create an account and store information for transactions with a Business User, and you may also be a Visitor if you’ve visited link.com.
We provide End User Services when we provide the Services, such as Link, directly to you for your personal use. Additional details regarding our collection, use, and sharing of End User Personal Data, including the legal bases we rely on for processing such data, can be found in our Privacy Center. The Personal Data we collect about End Users includes:
We may collect the Personal Data described above directly from you, or through your use of the End User Services. We may also receive Personal Data from Business Users, Financial Partners, service providers, and publicly available sources.
When you visit the Sites or otherwise interact with us about Link or Financial Connections without using a Link account, we collect information you provide directly and information collected through cookies and similar technologies (in accordance with our Cookie Policy). Please see additional U.S. privacy disclosures here. The Personal Data we collect about Visitors includes:
This section explains how we use the Personal Data of End Users. More details about how we use End Users’ Personal Data, along with the legal bases we rely on for processing such Personal Data, can be found in our Privacy Center.
Services. We use your Personal Data to provide the End User Services to you, which includes support, contextualization (such as language preferences, local currency checkout, and setting choices), and communication about our End User Services (such as communicating Policy updates and information about our Services). For example, Stripe may use cookies and similar technologies or the data that you provide to our Business Users (such as when you input your email address on a Business User’s website) to recognize you and help you use Link when visiting a Business User’s website. Learn more about how we use cookies and similar technologies in Stripe’s Cookie Policy. To help enable Link across Business User websites, we may use device and browser information associated with your Link account or technical information we obtain from third parties to recognize you, including when you visit a Business User’s website for the first time.
Fraud detection, loss prevention, and security. We use Personal Data to help detect fraud and prevent financial losses for you, us, our Business Users, and our Financial Partners, including detecting unauthorized purchases. We also use Personal Data to help secure our services and transactions against unauthorized access, use, alteration, or misappropriation of Personal Data, information, and funds. As part of Link’s fraud prevention, detection, security monitoring, and compliance efforts, we may collect information through Link and Financial Connections and from you, Business Users, Financial Partners, publicly available sources, and third parties. This information may include IP addresses and other identifiers that help us identify and respond to potential security threats. Learn more. Additionally, we may use technology to evaluate the potential risk of fraud associated with individuals arising from attempted transactions by an End User with our Business Users or Financial Partners. For example, if you use a connected bank account to make payments through a Business User, Stripe may combine your Financial Connections data, including account balances and transaction history, with other information, such as signals derived from Stripe's payments network, to assess the risk of those individual payment transactions, including the likelihood of payment failure or fraud.
Analyzing, improving, and developing our services. We collect and process Personal Data throughout our various services to improve our services, develop new services, and support our efforts to make our services more efficient, relevant, and useful to you. Learn more. We also may use Personal Data to generate aggregate and statistical information to understand and explain how our services are used. Examples of how we use Personal Data to analyze, improve, and develop our products and services include:
Agent features. When you connect an Agent, we collect and process information the Agent shares with us, as well as information needed to operate the integration and fulfill your requests, including authentication information, your requests and interactions, and transaction-related information. We may use this information to help complete purchases you instruct your Agent to make on your behalf; provide the services; prevent fraud; comply with legal and financial-partner requirements; and handle refunds, disputes, and other transaction-related requests.
Advertising. Where permitted by applicable law, including any consent requirements, we may use your Personal Data, including Transaction Data, to assess your eligibility for and offer you other End User Services, or to promote existing End User Services, including through co-marketing with partners such as Stripe Business Users. Learn more. Subject to applicable law, including any consent requirements, we may use and share End User Personal Data with third-party partners to allow us to advertise our End User Services to you, including through interest-based advertising, and to track the efficacy of such ads. We do not sell your Personal Data to third parties in exchange for monetary payment, but we may provide your data to third-party partners, such as advertising partners, analytics providers, and social networks, who assist us in advertising our services to you. Learn more. You may manage your preferences here.
Insights for Business Users. Where permitted by applicable law, including any consent requirements, we may use your Personal Data, including Transaction Data, to derive insights and to personalize offers and communications to you for Stripe and for Business Users. You may opt-out by managing applicable data-sharing and advertising preferences under Data Sharing in Settings. Learn more.
Communications. We use the contact information we have about you to deliver our Services, which may involve sending codes via text message (such as SMS and RCS) or other messaging channels for your authentication. Learn more. If you are an End User or Visitor, we may communicate with you using the contact information we have about you to provide information about our services and our Affiliates’ services, invite you to participate in our events, surveys, or user research, or otherwise communicate with you for marketing purposes, in compliance with applicable law, including any consent or opt-out requirements. For example, if you provide your contact information to us when signing up for Link or when signing up for updates, we may use this data to follow up with you regarding an event, to provide information requested about our services, and to include you in our Link marketing campaigns. Where permitted under applicable law, we may record and transcribe our calls with you to provide our services, comply with our legal obligations, and perform research and quality assurance, and for training purposes. Learn more.
Social media and promotions. If you opt to submit Personal Data to engage in an offer, program, or promotion, we use the Personal Data you provide to manage the offer, program, or promotion. We also use the Personal Data you provide, along with the Personal Data you make available on social media platforms, for marketing purposes, unless we are not permitted to do so.
Automated and AI-powered communications. We may leverage automated dialing systems and AI technologies, such as AI-powered voice agents and AI transcription, chat, and email tools, to initiate and conduct communications with you for operational, support, sales, marketing, and lead qualification purposes. These technologies are used to enhance the efficiency of our outreach and to provide immediate engagement tailored to your needs. We may use Personal Data, including call recordings and transcripts of interactions facilitated by automated systems for staff training, quality assurance, and other operational purposes, as well as to train, test, and improve the artificial intelligence and machine learning models. To opt out of call recording, please do so when prompted at the beginning of the call.
Automated decision making: We may use automated tools that process your Personal Data in certain circumstances. In these circumstances, decisions may be made automatically and without human review. We may use automated decision making in situations such as:
If we use automated decision making to make a decision that produces legal or similarly significant effects concerning you, we will provide the notices and choices required by applicable law. These may include the right to request information about the automated processing, opt out of certain processing, request human review or intervention, express your point of view, or contest or appeal a decision. You can exercise any applicable rights by contacting us at one of the methods in the "Contact Us" section.
Compliance with legal obligations. We use Personal Data to meet our contractual and legal obligations related to anti-money laundering, Know-Your-Customer ("KYC") laws, anti-terrorism activities, safeguarding vulnerable customers, export control, and prohibition of doing business with restricted persons or in certain business fields, among other legal obligations. For example, we may monitor transaction patterns and other online signals and use those insights to identify fraud, money laundering, and other harmful activity that could affect Link and its Affiliates, our Financial Partners, End Users, Business Users and others. Learn more. Safety, security, and compliance for our Services are key priorities for us, and collecting and using Personal Data is crucial to this effort.
Minors. Our Services are not directed to children under the age of 13, and we request that they do not provide Personal Data to seek Services directly from Link. In certain jurisdictions, we may impose higher age limits as required by applicable law.
This section explains how we use the Personal Data of Visitors. More details about how we use Visitors’ Personal Data, along with the legal bases we rely on for processing such Personal Data, can be found in our Privacy Center. Please see additional U.S. privacy disclosures here.
This section explains how we may disclose the Personal Data of End Users and Visitors. Please see additional U.S. privacy disclosures here.
For purposes of the General Data Protection Regulation (“GDPR”) and other applicable data protection laws, we rely on a number of legal bases to process your Personal Data. Learn more. For some jurisdictions, there may be additional legal bases, which are outlined in the Jurisdiction-Specific Provisions section below.
Depending on your location and subject to applicable law, you may have choices regarding our collection, use, and disclosure of your Personal Data:
If you wish to stop receiving marketing-related communications from us, you can opt-out by clicking the unsubscribe link included in such communications, or by updating your preferences in your Link account settings. We'll try to process your request(s) as quickly as reasonably practicable. However, it's important to note that even if you opt out of receiving marketing-related communications from us, we retain the right to communicate with you about the Services you receive (like support and important legal notices), and our Business Users might still send you messages or instruct us to send you messages on their behalf.
Depending on your location and subject to applicable law, you may have the following rights regarding the Personal Data that we process about you as a data controller:
You may have additional rights, depending on applicable law, over your Personal Data. Please see the Jurisdiction-specific provisions section below.
To exercise your data protection rights related to the Personal Data we process as a data controller, visit our Privacy Portal or contact us as outlined below. For Personal Data we process as a data processor, please reach out to the relevant data controller (Business User) to exercise your rights. If you contact us regarding your Personal Data we process as a data processor, we will refer you to the relevant data controller to the extent that we are able to identify them.
We make reasonable efforts to provide a level of security that is appropriate to the risk associated with the processing of your Personal Data. We maintain organizational, technical, and administrative measures designed to protect the Personal Data covered by this Policy from unauthorized access, destruction, loss, alteration, or misuse. Learn more. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure.
We encourage you to assist us in protecting your Personal Data. If you hold a Link account, you can help us protect your Personal Data by using a strong password, safeguarding your password against unauthorized use, and avoiding reusing login credentials from other accounts for your Link account. If you suspect that your interaction with us is no longer secure (for instance, if you believe that your Link account's security has been compromised), please contact us immediately.
We retain your Personal Data for as long as we continue to provide the Services to you, or for a period in which we reasonably foresee continuing to provide the Services. Link account information is generally retained while your account remains active. We may retain Transaction Data and limited account information after account closure where necessary to comply with legal, tax, accounting, and financial-recordkeeping obligations, resolve disputes, or prevent fraud. Even after we stop providing Services directly to you or to a Business User that you're doing business with, and even after you close your Link account or complete a transaction with a Business User, we may continue to retain your Personal Data to:
In cases where we retain your Personal Data, we do so in accordance with any limitation periods and record retention obligations imposed by applicable law. Learn more.
As a global business, we may sometimes need to transfer your Personal Data to countries other than your own, including the United States and India. These countries may have data protection regulations that are different from those in your country. When transferring data across borders, we take measures to comply with applicable data protection laws related to such transfer. In certain situations, we may be required to disclose Personal Data in response to lawful requests from officials, such as law enforcement or security authorities. Learn more.
If you are located in the European Economic Area (“EEA”), the United Kingdom (”UK”), or Switzerland, please refer to our Privacy Center for additional details. When a data transfer mechanism is mandated by applicable law, we employ one or more of the following:
Stripe complies with the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework as set forth by the U.S. Department of Commerce and as applicable. Learn more.
Link’s privacy practices, as described in this Privacy Policy, comply with the Cross Border Privacy Rules System (“CBPR”) and Privacy Rules for Processor (“PRP”) systems. These systems provide a framework for organizations to ensure protection of personal data transferred among participating economies. Where CBPR and/or PRP are recognized as a valid transfer mechanism under applicable law, Link will transfer Personal Data in accordance with the CBPR and PRP certifications Stripe has obtained. More information about these frameworks may be found here and here. If you have unresolved privacy or data use concerns that we have not addressed satisfactorily, please contact our U.S. based third-party dispute resolution provider (free of charge) here. To view the status of our CBPR and PRP certifications, please see here and here, respectively.
For U.S. consumers who obtain Link or Financial Connections financial services primarily for personal, family, or household purposes, our collection, use, and sharing of Personal Data are governed by the Gramm-Leach-Bliley Act and described in the U.S. Consumer Privacy Notice below. Other U.S. privacy rights may apply only to Personal Data and processing that are not subject to the Gramm-Leach-Bliley Act.
| FACTS | WHAT DOES LINK DO WITH YOUR PERSONAL INFORMATION? |
|---|---|
| Why? | Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect your personal information. Please read this notice carefully to understand what we do. |
| What? | The types of personal information we collect and share depend on the product or service you have with us. This information can include:
When you are no longer our customer, we continue to share your information as described in this notice. |
| How? | All financial companies need to share customers' personal information to run their everyday business. In the section below, we list the reasons financial companies can share their customers' personal information; the reasons Link chooses to share; and whether you can limit this sharing. |
| Reasons we can share your personal information | Does Link share? | Can you limit this sharing? |
|---|---|---|
| For our everyday business purposes – such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus | Yes | No |
| For our marketing purposes - to offer our products and Services to you | Yes | No |
| For joint marketing with other financial companies | Yes | No |
| For our affiliates' everyday business purposes - information about your transactions and experiences | Yes | No |
| For our affiliates' everyday business purposes - information about your creditworthiness | Yes | Yes |
| For our affiliates to market to you | No | We don’t share |
| For nonaffiliates to market to you | Yes | Yes |
| To limit our sharing | Log in to your Link account at app.link.com/settings and toggle off data sharing from the Messaging menu. Please note: If you are a new customer, we can begin sharing your information 30 days from the date we sent this notice. When you are no longer our customer, we continue to share your information as described in this notice. However, you can contact us at any time to limit our sharing. |
|---|
| Questions? | Contact us at privacy@stripe.com or visit us at https://support.link.com |
|---|
| Who we are | |
|---|---|
| Who is providing this notice? | Stripe, Stripe Payments Company, and their affiliates that provide consumer services in the U.S., including Stripe, LLC and Sold through Link, LLC |
| What we do | |
|---|---|
| How does Link protect my personal information? | To protect your personal information from unauthorized access and use, we use security measures that comply with federal law. These measures include computer safeguards and secured files and buildings. We impose access controls along with ongoing monitoring to help prevent data misuse, and we require our service providers to take similar steps to help protect your information. |
| How does Link collect my personal information? | We collect your personal information, for example, when you
We also collect your personal information from others, such as credit bureaus, affiliates, or other companies. |
| Why can’t I limit all sharing? | Federal law gives you the right to limit only
State laws and individual companies may give you additional rights to limit sharing. See below for more on your rights under state law. |
| What happens when I limit sharing for an account I hold jointly with someone else? | Your choices will apply to everyone on your account. |
| Definitions | |
|---|---|
| Affiliates | Companies related by common ownership or control. They can be financial and nonfinancial companies.
|
| Nonaffiliates | Companies not related by common ownership or control. They can be financial and nonfinancial companies.
|
| Joint Marketing | A formal agreement between non-affiliated financial companies that together market financial products or services to you.
|
| Other important information |
|---|
Vermont: If your account with us is associated with a Vermont billing address, we will not disclose information about your creditworthiness to our affiliates and will not disclose your personal information, financial information, or credit report to nonaffiliated third parties to market to you, other than as permitted by Vermont law, unless you authorize us to make those disclosures. For joint marketing, we will only disclose your name, contact information, and information about your transactions. Additional information concerning our privacy policies can be found in our Privacy Policy and Privacy Center. California: If your account with us is associated with a California billing address, we will not disclose Personal Data we collect about you except to the extent permitted under California law. For instance, we may disclose your Personal Data as necessary to process transactions or provide products and services you request, at your instruction, as required for institution risk control, and to safeguard against fraud, identity theft, and unauthorized transactions. |
For additional information about our privacy practices, please visit the Stripe Privacy Center.
ออสเตรเลีย "ข้อมูลส่วนบุคคล" หมายรวมถึง "ข้อมูลส่วนตัว" ตามคำจำกัดความภายใต้กฎหมายคุ้มครองความเป็นส่วนตัวที่บังคับใช้ในออสเตรเลีย รวมถึง Privacy Act 1988 (Cth) ที่มีการแก้ไขเป็นครั้งคราว
บราซิล คุณสามารถใช้สิทธิ์ของคุณโดยติดต่อ DPO Adi Gilad ของเราที่ dpo@stripe.com ผู้อยู่อาศัยในบราซิลซึ่ง Lei Geral de Proteção de Dados Pessoais ("LGPD") มีผลบังคับใช้ มีสิทธิ์ตามที่ระบุไว้ในมาตรา 18 ของ LGPD หาก LGPD มีผลบังคับใช้กับการประมวลผลข้อมูลส่วนบุคคลของคุณ คุณอาจมีสิทธิ์ดำเนินการดังนี้
หากจำเป็น เราได้จัดให้มีมาตรการป้องกันที่เหมาะสมสำหรับการโอนข้อมูลส่วนบุคคลข้ามพรมแดนจากบราซิลไว้แล้ว เช่น ข้อสัญญามาตรฐานของบราซิล
แคนาดา ตามที่ใช้ในนโยบายนี้ คำว่า "กฎหมายที่ใช้บังคับ" หมายรวมถึง Federal Personal Information Protection and Electronic Documents Act ("PIPEDA"), Personal Information Protection Act, SBC 2003 c 63 ในบริติชโคลัมเบีย, Personal Information Protection Act, SA 2003 c P-6.5 ในอัลเบอร์ตา และ Act Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39-1 ("Quebec Private Sector Act") ในควิเบก ดูข้อมูลเพิ่มเติม "ข้อมูลส่วนบุคคล" หมายรวมถึง "ข้อมูลส่วนตัว" ตามคำจำกัดความภายใต้กฎหมายดังกล่าว
เขตเศรษฐกิจยุโรป (EEA) และสหราชอาณาจักร คุณสามารถใช้สิทธิ์ของคุณได้โดยติดต่อ DPO ของเราที่ dpo@stripe.com หากคุณเป็นผู้อยู่อาศัยใน EEA หรือหน่วยงานของ Stripe ที่เป็นผู้รับผิดชอบข้อมูลส่วนบุคคลของคุณอยู่ภายใต้ GDPR ในลักษณะอื่นใด และคุณเชื่อว่าการประมวลผลข้อมูลของคุณขัดต่อข้อกำหนดของ GDPR คุณสามารถส่งข้อสงสัยหรือยื่นข้อร้องเรียนต่อ Irish Data Protection Commission (คณะกรรมการคุ้มครองข้อมูลแห่งไอร์แลนด์) ได้ หากคุณเป็นผู้อยู่อาศัยในสหราชอาณาจักร ให้ส่งข้อสงสัยหรือข้อกังวลของคุณไปที่ UK Information Commissioner’s Office (สำนักงานคณะกรรมาธิการข้อมูลข่าวสารของสหราชอาณาจักร) คุณยังมีสิทธิ์เพิ่มเติมภายใต้กรอบแนวคิดด้านความเป็นส่วนตัวของข้อมูลระหว่างสหภาพยุโรปและสหรัฐอเมริกา (EU-U.S. DPF) และส่วนขยายของ EU-U.S. DPF สำหรับสหราชอาณาจักร ดูข้อมูลเพิ่มเติม
ฝรั่งเศส คุณมีสิทธิ์กำหนดคำสั่งทั่วไปหรือคำสั่งเฉพาะเจาะจงเกี่ยวกับการจัดเก็บ การลบ และการเปิดเผยข้อมูลส่วนบุคคลของคุณภายหลังการเสียชีวิตของคุณ นอกจากนี้ คุณยังสามารถลงทะเบียนคำสั่งดังกล่าวไว้กับ "บุคคลที่สามที่เชื่อถือได้ทางดิจิทัลซึ่งได้รับการรับรอง" และเป็นที่ยอมรับของ CNIL ได้อีกด้วย คำสั่งเหล่านี้อาจระบุชื่อบุคคลที่จะรับผิดชอบในการดำเนินการตามคำสั่งดังกล่าว หรือหากไม่มีการระบุไว้ ทายาทของคุณจะเป็นผู้รับผิดชอบในการดำเนินการแทน คุณสามารถส่งคำสั่งของคุณมายังเราได้โดยติดต่อที่ privacy@stripe.com
เขตบริหารพิเศษฮ่องกง (Hong Kong SAR) ในนโยบายฉบับนี้ คำว่า "กฎหมายที่ใช้บังคับ" รวมถึงกฎหมายว่าด้วยข้อมูลส่วนบุคคล (ความเป็นส่วนตัว) (Personal Data (Privacy) Ordinance หรือ PDPO) (Cap. 486) ของฮ่องกง การให้ข้อมูลส่วนบุคคลของคุณถือเป็นความสมัครใจ เว้นแต่จะระบุไว้เป็นอย่างอื่น อย่างไรก็ตาม ในกรณีที่จำเป็นต้องมีการเก็บรวบรวมข้อมูลส่วนบุคคลเพื่อให้เราปฏิบัติตามภาระผูกพันทางกฎหมายหรือเพื่อดำเนินการตามสัญญาที่มีกับคุณ (เช่น การประมวลผลธุรกรรมการชำระเงิน หรือการดำเนินการยืนยันตัวตนตามที่กฎหมายกำหนด) การให้ข้อมูลของคุณถือเป็นข้อบังคับ และหากคุณไม่ให้ข้อมูลดังกล่าว เราจะไม่สามารถให้บริการแก่คุณได้ หากคุณเป็นผู้อยู่อาศัยในฮ่องกงและประสงค์จะใช้สิทธิ์ในการเข้าถึงหรือแก้ไขข้อมูลของคุณ หรือหากคุณไม่พอใจกับการจัดการข้อร้องเรียนใดๆ ของเราภายใต้นโยบายฉบับนี้ คุณสามารถติดต่อเจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล (DPO) ของเรา หรือเลือกติดต่อสำนักงานคณะกรรมาธิการความเป็นส่วนตัวของข้อมูลส่วนบุคคลแห่งฮ่องกง (Office of the Privacy Commissioner for Personal Data หรือ PCPD) ได้
อินเดีย ในนโยบายนี้ "กฎหมายที่ใช้บังคับ" หมายรวมถึงพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคลดิจิทัล ("DPDPA") เมื่อ DPDPA มีผลบังคับใช้ และกฎที่ออกภายใต้กฎหมายดังกล่าว นอกจากนี้ คำว่า "ผู้ควบคุมข้อมูล" จะหมายรวมถึง "ผู้ดูแลข้อมูล" และคำว่า "เจ้าของข้อมูล" จะหมายรวมถึง "ผู้รับผิดชอบข้อมูล" ซึ่งทั้งสองคำนิยามไว้ใน DPDPA
อินโดนีเซีย ในนโยบายนี้ "กฎหมายที่ใช้บังคับ" หมายรวมถึงกฎหมายฉบับที่ 11 ปี 2008 ซึ่งแก้ไขเพิ่มเติมโดยกฎหมายฉบับที่ 19 ปี 2016 ว่าด้วยข้อมูลและธุรกรรมทางอิเล็กทรอนิกส์ ข้อบังคับของรัฐบาลฉบับที่ 71 ปี 2019 ว่าด้วยการนำระบบอิเล็กทรอนิกส์และธุรกรรมไปใช้ และระเบียบรัฐมนตรีว่าการกระทรวงคมนาคมและสารสนเทศ ฉบับที่ 20 ปี 2016 ว่าด้วยการคุ้มครองข้อมูลส่วนบุคคลในระบบอิเล็กทรอนิกส์ และตั้งแต่เดือนกันยายน 2024 เป็นต้นไป กฎหมายฉบับที่ 27 ปี 2022 ว่าด้วยการคุ้มครองข้อมูลส่วนบุคคล ("กฎหมาย PDP") หากคุณมีคำถามหรือข้อร้องเรียนใดๆ เกี่ยวกับนโยบายนี้ โปรดติดต่อ DPO ของเราที่ dpo@stripe.com
ญี่ปุ่น ในนโยบายนี้ "กฎหมายที่ใช้บังคับ" หมายรวมถึง Act on the Protection of Personal Information ("APPI" หรือพระราชบัญญัติว่าด้วยการคุ้มครองข้อมูลส่วนบุคคล) เมื่อเราถ่ายโอนข้อมูลส่วนตัวของเจ้าของข้อมูลในญี่ปุ่นไปยังเขตอำนาจศาลที่ไม่ได้รับการยอมรับว่า "เพียงพอ" โดยคณะกรรมการคุ้มครองข้อมูลส่วนตัว เราจะทำข้อตกลงเป็นลายลักษณ์อักษรกับบุคคลภายนอกที่อยู่นอกประเทศญี่ปุ่น ข้อตกลงที่เป็นลายลักษณ์อักษรเหล่านี้ให้สิทธิ์และภาระผูกพันเทียบเท่ากับที่ระบุไว้ภายใต้ Japanese Act on the Protection of Personal Information (พระราชบัญญัติคุ้มครองข้อมูลส่วนตัวของญี่ปุ่น) สำหรับข้อมูลเพิ่มเติมว่าเรามั่นใจได้อย่างไรว่าบุคคลภายนอกกำลังปกป้องข้อมูลของคุณและตำแหน่งที่ข้อมูลของคุณอยู่ โปรดดูข้อมูลด้านบนหรือติดต่อเราตามที่อธิบายไว้ด้านล่าง สำหรับคำอธิบายของระบบและกรอบการทำงานต่างประเทศที่อาจส่งผลต่อการดำเนินการตามมาตรการที่เทียบเท่าโดยบุคคลภายนอก โปรดดูที่นี่ ในบางกรณี และตามที่ได้รับอนุญาตภายใต้ APPI เราอาจใช้ "ผลประโยชน์สาธารณะ" เป็นพื้นฐานทางกฎหมาย เช่น การตรวจจับการฉ้อโกงและการป้องกันการสูญเสีย
มาเลเซีย ในนโยบายนี้ "กฎหมายที่ใช้บังคับ" หมายรวมถึง Malaysian Personal Data Protection Act 2010 (พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคลของมาเลเซียปี 2010) ซึ่งอาจมีการแก้ไขเพิ่มเติมเป็นครั้งคราว หากคุณมีคำถามหรือข้อร้องเรียนใดๆ เกี่ยวกับนโยบายนี้ โปรดติดต่อ DPO ของเราที่ dpo@stripe.com
นิวซีแลนด์ ในนโยบายนี้ "กฎหมายที่ใช้บังคับ" หมายรวมถึง New Zealand Privacy Act 2020 (พระราชบัญญัติคุ้มครองความเป็นส่วนตัวของนิวซีแลนด์ฉบับปี 2020) ตามที่มีการแก้ไขเป็นครั้งคราว การประมวลผลข้อมูลชีวมิติของเราผ่านบริการ Stripe Identity เป็นไปตามหลักเกณฑ์ Biometric Privacy Processing Code เมื่อคุณใช้บริการนี้เราจะเก็บรวบรวมและใช้ภาพถ่ายเอกสารประจำตัวของคุณและภาพถ่ายเซลฟีเพื่อยืนยันตัวตนของคุณและป้องกันการทุจริต ข้อมูลชีวมิตินี้จะถูกเก็บรักษาไว้เป็นระยะเวลาหนึ่งปี หากคุณมีข้อกังวล คุณมีสิทธิ์ติดต่อเราหรือ New Zealand Privacy Commissioner (คณะกรรมาธิการความเป็นส่วนตัวของนิวซีแลนด์) สำหรับรายละเอียดเพิ่มเติมเกี่ยวกับข้อมูลที่เราเก็บรวบรวมวัตถุประสงค์เฉพาะในการเก็บรวบรวมและทางเลือกอื่นในการยืนยันตัวตน โปรดดูนโยบายความเป็นส่วนตัวฉบับเต็มของเรา ศูนย์ความเป็นส่วนตัว และเอกสาร Stripe Identity
สาธารณรัฐประชาชนจีน หากคุณมีถิ่นพำนักอยู่ในสาธารณรัฐประชาชนจีน (ไม่รวมเขตบริหารพิเศษฮ่องกง เขตบริหารพิเศษมาเก๊า และไต้หวัน สำหรับวัตถุประสงค์ของนโยบายฉบับนี้เท่านั้น) ("จีนแผ่นดินใหญ่") ให้ใช้ข้อกำหนดเพิ่มเติมดังต่อไปนี้
สิงคโปร์ ในนโยบายนี้ "กฎหมายที่มีผลบังคับใช้" หมายรวมถึง Personal Data Protection Act 2012 ("PDPA" หรือกฎหมายคุ้มครองข้อมูลส่วนบุคคลปี 2012) (ฉบับที่ 26 ปี 2012) ซึ่งแก้ไขเพิ่มเติมเป็นครั้งคราว ในบางกรณี และตามที่ได้รับอนุญาตภายใต้ PDPA เราอาจใช้ "ความยินยอมโดยปริยาย" เป็นฐานทางกฎหมาย ตัวอย่างเช่น เราทำเช่นนั้นเมื่อคุณให้ข้อมูลส่วนบุคคลของคุณแก่เราโดยสมัครใจ หากคุณมีข้อสงสัยหรือข้อร้องเรียนใดๆ เกี่ยวกับนโยบายนี้ โปรดติดต่อ DPO ของเราที่ dpo@stripe.com
เกาหลีใต้ ในนโยบายฉบับนี้ คำว่า "กฎหมายที่ใช้บังคับ" รวมถึงพระราชบัญญัติคุ้มครองข้อมูลส่วนตัว ("PIPA") และพระราชบัญญัติการใช้และการคุ้มครองข้อมูลสินเชื่อ ("CIA") ข้อมูลส่วนบุคคลอาจถูกโอนไปยังบริษัทในเครือทั่วโลกและผู้ให้บริการของ Link ซึ่งตั้งอยู่ในสหรัฐอเมริกาและประเทศอื่นๆ เพื่อวัตถุประสงค์ในการมอบหมายงาน การจัดเก็บข้อมูล การดำเนินงาน และการสนับสนุนลูกค้า ทั้งนี้ ให้เป็นไปตามกฎหมายที่ใช้บังคับ ดูข้อมูลเพิ่มเติม
สวิตเซอร์แลนด์ ในนโยบายนี้ "กฎหมายที่ใช้บังคับ" หมายรวมถึง Swiss Federal Act on Data Protection ("FADP" หรือกฎหมายรัฐบาลกลางสวิสว่าด้วยการคุ้มครองข้อมูล) ตามที่มีการแก้ไขเพิ่มเติม หากต้องการใช้สิทธิ์ของคุณภายใต้ FADP โปรดติดต่อ DPO ของเราที่ dpo@stripe.com คุณอาจมีสิทธิ์เพิ่มเติมภายใต้กรอบการทำงานความเป็นส่วนตัวของข้อมูลระหว่างสวิตเซอร์แลนด์-สหรัฐอเมริกา ดูข้อมูลเพิ่มเติม
ไทย ในนโยบายนี้ "กฎหมายที่ใช้บังคับ" หมายรวมถึงพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (Personal Data Protection Act 2019 หรือ "PDPA") หากเราอาศัยฐานกฎหมายบางประการ (เช่น "ภาระผูกพันกฎหมาย" หรือ "ความจำเป็นตามสัญญา") และคุณไม่ได้ให้ข้อมูลส่วนบุคคลของคุณแก่เรา เราอาจไม่สามารถให้บริการแก่คุณได้อย่างถูกต้องตามกฎหมาย หากคุณมีคำถามหรือข้อร้องเรียนใดๆ เกี่ยวกับนโยบายนี้ โปรดติดต่อ DPO ของเราที่dpo@stripe.com เราใช้มาตรการป้องกันที่เหมาะสมตามความจำเป็นสำหรับการโอนข้อมูลส่วนบุคคลข้ามพรมแดนจากประเทศไทย ซึ่งรวมถึงข้อสัญญามาตรฐานของสหภาพยุโรป ซึ่งมีการปรับให้เหมาะกับการโอนข้อมูลของประเทศไทยตามประกาศของคณะกรรมการคุ้มครองข้อมูลส่วนบุคคลว่าด้วยหลักเกณฑ์การให้ความคุ้มครองข้อมูลส่วนบุคคลที่ส่งหรือโอนไปยังต่างประเทศ ตามมาตรา 29 ของพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 พ.ศ. 2566 (2023)
สหรัฐอาหรับเอมิเรตส์ ในนโยบายฉบับนี้ คำว่า "กฎหมายที่ใช้บังคับ" รวมถึงกฎหมาย Federal Decree-Law No. 45 of 2021 ว่าด้วยการคุ้มครองข้อมูลส่วนบุคคล ("PDPL") สำหรับการประมวลผลข้อมูลภายในพื้นที่หลัก (mainland) ของสหรัฐอาหรับเอมิเรตส์ หรือกฎหมายคุ้มครองข้อมูลของเขตเศรษฐกิจเสรีทางการเงินที่เกี่ยวข้อง (เช่น DIFC Data Protection Law ฉบับที่ 5 ปี 2020 หรือ ADGM Data Protection Regulations 2021) เมื่อเรามีการโอนข้อมูลส่วนบุคคลออกนอกสหรัฐอาหรับเอมิเรตส์ เราจะดำเนินการให้มีมาตรการคุ้มครองที่เหมาะสมตามที่ระบุไว้ในมาตรา 22 และมาตรา 23 ของ PDPL (หรือกฎหมายของเขตเศรษฐกิจเสรีที่เกี่ยวข้อง) เช่น การโอนข้อมูลไปยังเขตอำนาจศาลที่ได้รับการยอมรับว่ามีมาตรฐานการคุ้มครองข้อมูลที่เพียงพอ หรือการจัดทำข้อสัญญามาตรฐานที่ได้รับอนุมัติ หากท่านต้องการใช้สิทธิตามกฎหมายของสหรัฐอาหรับเอมิเรตส์ โปรดปฏิบัติตามขั้นตอนที่ระบุไว้ในนโยบายความเป็นส่วนตัวฉบับนี้ หรือติดต่อเจ้าหน้าที่คุ้มครองข้อมูล (Data Protection Officer) ของเราที่ dpo@stripe.com ทั้งนี้ หากท่านไม่พอใจต่อการตอบกลับหรือการจัดการข้อร้องเรียนด้านความเป็นส่วนตัวของเรา ท่านสามารถติดต่อ UAE Data Office หรือคณะกรรมาธิการคุ้มครองข้อมูล (Data Protection Commissioner) ของเขตเศรษฐกิจเสรีทางการเงินที่เกี่ยวข้องได้เช่นกัน
สหรัฐอเมริกา หากคุณเป็นผู้บริโภคที่อาศัยอยู่ในสหรัฐอเมริกา ("สหรัฐ") เราจะประมวลผลข้อมูลส่วนตัวของคุณตามกฎหมายความเป็นส่วนตัวของรัฐบาลกลางและรัฐของสหรัฐอเมริกา หากต้องการรายละเอียดเพิ่มเติม โปรดดูข้อมูลด้านล่างและดูการเปิดเผยข้อมูลความเป็นส่วนตัวเพิ่มเติมของสหรัฐอเมริกาที่นี่ Link ใช้คุกกี้ (รวมถึงคุกกี้โฆษณา) ตามที่อธิบายไว้ในนโยบายคุกกี้ของเรา คุณสามารถจัดการการตั้งค่าคุกกี้ของคุณได้ที่นี่
We may change this Policy from time to time to reflect new services or changes in our privacy practices or relevant laws. The “Last updated” legend at the top of this Policy indicates when this Policy was last materially revised. Any changes are effective the latter of when we post the revised Policy on the Services or otherwise provide notice of the update as required by law.
We may provide you with disclosures and alerts regarding the Policy or Personal Data collected by posting them on our website and, if you are an End User or Representative, by contacting you through your Link account, email address and/or the physical address listed in your Link account.
If you have any questions or complaints about this Policy, please contact us.