Paradraw
Stripe/Stripe Privacy Center is drafted as if it could incorporate Consumer Terms of Service
Stripe Privacy Center · p401
notice

Stripe Privacy Center

25,644 words, 668 clausesno date on the pageread 08/10/2026source

·Welcome to the Stripe Privacy Center

·Stripe respects the privacy of everyone that engages with our platform, and we are committed to being transparent about our privacy processes and policies. We are a platform that enables millions of businesses, and in order to provide our services to our Business Users and End Users, we collect and process personal data.

·The Stripe Privacy Center contains the answers to frequently asked questions about how we collect and use personal data, the rights that individuals have in relation to personal data held by Stripe, and how Stripe complies with international data protection laws.

·All materials have been prepared for general information purposes only. The information presented is not legal advice, is not to be acted on as such, may not be current and is subject to change without notice.

·Below is a list of terms that will help "you" navigate the Privacy Center: "YOU" | MEANING | STRIPE EXAMPLES

Business UserStripe provides services to entities ("Business Users") who directly and indirectly provide us with "End Customer" Personal Data in connection with those Business Users' own business and activities.Stripe user or merchant Platform User Connect Accounts
End CustomerWhen you do business with, or otherwise transact with, a Business User (typically a merchant using Stripe Checkout, e.g. when you buy a pair of shoes from a merchant that uses Stripe for payment processing) but are not directly doing business with Stripe, we refer to you as an "End Customer."Individual using Identity Cardholder using Checkout
End UserWhen you directly use an End User Service (such as when you sign up for Link, or make a payment to Stripe Climate in your personal capacity), for your personal use, we refer to you as an "End User."User of Link Personal contributor to Stripe Climate
RepresentativeWhen you are acting on behalf of an existing or potential Business User (e.g. you are a founder of a company, or administering an account for a merchant who is a Business User), we refer to you as a "Representative."Beneficial owner Shareholder, officer, director Account representative
VisitorWhen you visit a Site without being logged into a Stripe account or otherwise communicate with Stripe, we refer to you as a "Visitor." (e.g. you send Stripe a message asking for more information because you are considering being a user of our products).Stripe Sessions attendee Stripe Site visitor

·Contents

·Stripe's Role in Managing Data- Is Stripe acting as a data controller or a data processor?- Which Stripe entities are involved?

·How We Use Data- What are Stripe's data controller activities?- How does Stripe use Personal Data to improve its products and Services?- How does Stripe use Personal Data to prevent fraud?- How does Stripe use personal data to train artificial intelligence models?- How does Stripe use and share data to authenticate my transactions?- Does Stripe collect precise location data?- How does Stripe use Representative contact information to provide its Services?- As a Stripe Business User and as a data controller, what does GDPR mean for me?- As a Business User, what notice do I provide to my End Customers about Stripe?

·Third Parties- Who are Stripe's sub-processors and how are they vetted?- In addition to its sub-processors, what other third parties does Stripe share information with?- Are there any jurisdictional nuances to Stripe's use of service providers in verifying the identity of Stripe's Business Users?- Data Obtained from Third Parties- From where does Stripe collect information used for fraud prevention and security purposes?

·Marketing- How does Stripe use Personal Data for co-marketing End User Services?- Does Stripe Record Calls?- How does Stripe collect information for phone verification?

  • ·Categories of Personal Information Collected and Disclosed Under the CCPA
  • ·What sensitive personal information under the California Consumer Privacy Act (CCPA) does Stripe collect and for what purposes does Stripe use that data?
  • ·Does Stripe "sell" or "share" my personal information under the CCPA? How long will Stripe keep my data? California Privacy Rights Metrics
  • ·What legal basis does Stripe rely on to process Personal Data as a data controller? End Users End Customers Representatives Visitors
  • ·What is a Data Processing Agreement (DPA) and how can I get one with Stripe?

·General- How do you implement Privacy by Design at Stripe?- As a Business User, what notice do I provide to my End Customers about Stripe?

·Stripe Product Information- Stripe Identity- Stripe's Card Image Verification- Stripe Connect At a Glance- Stripe Connect - I am a user with a Custom connected account. Does Stripe also collect information about my Custom connected account from a third party?- Stripe Connect - What responsibilities do Connect platforms with custom accounts have to allow their users to update or correct information associated with their accounts?- Stripe Connect - I am a user with a Custom connected account. Will data collected from a third party be visible to my customers?- Promotional Emails Feature- Stripe Delegated Authentication- Onelink- Onelink - What is "Sold through Onelink"?- What information is shared with BNPL or crypto wallet services?- Stripe Capital Direct and Capital for Platforms- Financial Connections- Are there instances when Stripe receives non-Stripe transaction history?- Refunds to End Customer Bank Account- Stripe Frontier

  • ·Does Stripe have a Data Protection Officer (DPO)? Quebec Act

·General- How is Stripe dealing with its international data transfers?- Why is Stripe storing authentication and authorization data globally?

·International Data Transfer Certifications- Is Stripe certified under the EU-U.S Data Privacy Framework?- How does Stripe's certification under the EU-U.S. DPF impact my organization?- What is CBPR and PRP and is Stripe certified?

·Standard Contractual Clauses and UK Addendum- How do the SCCs and UK Addendum impact my organization?- How to get a copy of the SCCs or UK Addendum?

·How To Exercise Your Rights and Choices- How do I exercise my data protection rights?- Does Stripe honor the Global Privacy Control (GPC) opt-out preference signal?- Can I turn off tracking and advanced fraud signals?- How do I delete my account?- How do I delete my Custom Connect account?- How do I delete my Express Connect account?Additional Information- When does Stripe continue to process data after it has received a deletion request or objection to the processing?- What data may be shared or made available to enable me to see Stripe ads on other sites?- How long will Stripe keep my data?- What is the Privacy Policy for Stripe Media Services?

·Your Rights and Choices (India)- Does Stripe localize storage of data in India?- Where can I lodge my complaint on data handling in India?- Notification IT Rules 2021

·General Information- How does Stripe use cookies?- What is Stripe.js?- Does Stripe use CAPTCHA to protect its website from fraud and abuse?- What data may be shared or made available to enable me to see Stripe ads on other sites?

·Cookies and Fraud Detection- What are advanced fraud signals?- Why are advanced fraud signals not ad tracking?- What obligations should merchants keep in mind relating to cookie technology on their sites?

·Cookies and Onelink- How does Stripe remember payment method details for Onelink?- What obligations should Onelink users keep in mind relating to cookie technology on their sites? Contact our Privacy Team

  • ·Where can I learn more about Stripe's security practices?

·How We Collect, Disclose, and Use Personal Data

·Is Stripe acting as a data controller or a data processor?

·The answer is both.

·The "data controller" is the entity which determines the purposes and means of the data processing taking place. The "data processor" is an entity acting on behalf and under the instructions of a controller in processing Personal Data.

·Stripe is a data controller when it determines the purposes and means of the processing taking place. Please see this Privacy Center article for more information on Stripe's controller activities.

·Stripe is a data processor where it is providing the Stripe Services to Business Users and facilitating payment transactions on behalf of and at the direction of a Business User. Our Business Users direct us to take payment from cardholders / End Customers and we act on their instructions.

·Stripe is also considered a processor when servicing the Stripe platform (e.g. when Stripe responds to a request for customer support from a Business User).

·As a platform provider, we need to ensure consistency across our platform, and that includes consistency with respect to the commitments that we give about how we operate our platform. We contract with all of our Business Users (including some of the world's largest companies) on this basis.

·Which Stripe entities are involved?

·For most of our services, the primary data controller is either Stripe, LLC the US parent company operating under US law or Stripe Technology Company, Limited ("STC"), an Irish company operating under Irish law.

·The Stripe entities responsible for your data will depend on your location, the product or service you use with us and the specific context of the data processing which determines whether Stripe is acting as a data controller and/or data processor.

·If you are located outside of the Americas [e.g., European Economic Area ("EEA"), Switzerland, the United Kingdom, the Middle East and Africa, or Asia Pacific ("APAC")], the following entities may act as data controllers, either individually or jointly depending on the product or service you use:

  • ·Stripe Technology Company, Limited ("STC"): An Irish company that is Stripe's main establishment in Europe under GDPR. STC has primary responsibility for processing your Personal Data outside of the Americas.
  • ·Stripe Payment Europe, Limited ("SPEL"): An Irish company with principal responsibility for contracting with Stripe Users in certain jurisdictions outside of the Americas (see table below).
  • ·Stripe local regulated entities: These are specific Stripe entities that are licensed, authorised or registered by a local regulatory authority in a particular jurisdiction. When payment processing services offered by Stripe require an authorised provider or electronic money institution or where otherwise specified, the Stripe local regulated entity will provide those services. In such instances STC, SPEL and the relevant Stripe local regulated entity are joint data controllers of your Personal Data.

·If you are located in the Americas, your Data Processing Agreement ("DPA") will be with Stripe, LLC and if you are located outside of the Americas, your DPA will be with SPEL.

·Please see our table below for more information on which Stripe entity is your data controller in these jurisdictions:

User location | Purposes of processing | Stripe Entity/Your data controller | Stripe Entity Location
AustraliaProvision of services and regulated activities in accordance with https://stripe.com/au/legal/ssaStripe Payments Australia Pty Ltd A.C.N. 160 180 343Australia STCIreland
Your contracting entity under our DPASPELIreland All other activitiesSTCIreland
BrazilProvision of services and regulated activities in accordance with https://stripe.com/br/ssaStripe Brasil Soluções de Pagamento - Instituição de Pagamento LtdaBrazil Stripe, LLCUSA
All other activities | Stripe, LLC | USA
CanadaProvision of services and regulated activities in accordance with https://stripe.com/en-ca/ssaStripe Payments Canada, LtdCanada Stripe, LLCUSA
All other activities | Stripe, LLC | USA
EEA | Provision of certain authorised payment services and other regulated activities in the EEA. Please see https://stripe.com/ie/ssa | Stripe Technology Europe, Limited | Ireland
Your contracting entity under our SSA & DPASPELIreland All other activitiesSTCIreland
IndiaProvision of services and regulated activities in accordance with https://stripe.com/in/legal/ssaStripe India Private LimitedIndia STCIreland
Your contracting entity under our DPASPELIreland All other activitiesSTCIreland
IndonesiaProvision of services and regulated activities in accordance with https://stripe.com/id/ssaPT Stripe Payments IndonesiaIndonesia STCIreland
Your contracting entity under our DPA.SPELIreland All other activitiesSTCIreland
Japan | Provision of services in accordance with https://stripe.com/en-jp/legal | Stripe Japan, Inc.STC | JapanIreland
Your contracting entity under our DPA.SPELIreland All other activitiesSTCIreland
MalaysiaProvision of services and regulated activities in accordance with https://stripe.com/en-my/legal/ssaStripe Payments Malaysia Sdn. Bhd.Malaysia STCIreland
Your contracting entity under our DPASPELIreland All other activitiesSTCIreland
MexicoProvision of services in accordance with https://stripe.com/mx/legal/ssaStripe Payments Mexico, S. de R.L. de C.V.Mexico Stripe, LLCUSA
All other activities | Stripe, LLC | USA
United Kingdom | Provision of authorised payment services and other regulated activities in the UK. Please see https://stripe.com/gb/ssa | Stripe Payments UK, Ltd. | United Kingdom
Your contracting entity under our SSA & DPASPELIreland All other activitiesSTCIreland
United States | All activities | Stripe, LLC | USA
Provision of lending facilitation services to bank partners in connection with Stripe Capital loans in the United States | Stripe Brokering, Inc. | USA
Provision of certain Stripe Services which involve money transmission or other regulated services under U.S. Law. | Stripe Payments Company | USA
New Zealand | Provision of services and regulated activities in accordance with https://stripe.com/nz/ssa | Stripe New Zealand LimitedSTC | New Zealand Ireland
Your contracting entity under our DPASPELIreland All other activitiesSTCIreland
SingaporeProvision of services and regulated activities in accordance with https://stripe.com/en-sg/legalStripe Payments Singapore Pte. Ltd.Singapore STCIreland
Your contracting entity under our DPASPELIreland All other activitiesSTCIreland
Switzerland | Provision of authorised payment services and other regulated activities in Switzerland. Please see https://stripe.com/gb/ssa | Stripe Payments UK, Ltd. | United Kingdom
Your contracting entity under our SSA & DPASPELIreland All other activitiesSTCIreland
ThailandProvision of services and regulated activities in accordance with https://stripe.com/th/legal/ssaStripe Payments (Thailand) Ltd.Thailand STCIreland
Your contracting entity under our DPASPELIreland All other activitiesSTCIreland
Any other jurisdiction in the Americas | All other activities and your contracting entity under our DPA and SSA. | Stripe, LLC | USA
Any other jurisdictions in EMEA | Your contracting entity under our DPA and SSA | SPEL | Ireland
Provision of Stablecoin Financial Account UX Services in accordance with https://stripe.com/legal/sfa-termsStripe, LLCUSA All other activitiesSTCIreland
Any other jurisdictions in APAC, except for Hong Kong (SAR) | Provision of Stablecoin Financial Account UX Services in accordance with https://stripe.com/legal/sfa-terms | Stripe, LLC | USA All other activities | STC | Ireland

·Depending on your location, the location of your Customers, and the nature of the services Stripe is providing, (other than the entities set out above) we may use Stripe Affiliates in the same location or other locations, as well as Service Providers and Sub-processors to help provide the Services to you. These entities act as data processors on behalf of Stripe, LLC or STC depending on the jurisdiction. You will find the most up to date list of Stripe affiliates, Service Providers and Sub-processors here.

·What are Stripe's data controller activities?

  • ·Determine and utilize third parties (banks and payment method providers);
  • ·Monitor, prevent and detect fraudulent transactions and other fraudulent activity on the Stripe platform;
  • ·Monitor, prevent and mitigate financial loss, security risks, and other harm;
  • ·Implement, maintain and perform internal processes that enable Stripe to provide its products and Services, including relationship management, billing and invoicing;
  • ·Comply with Law, including applicable anti-money laundering screening and know-your-customer obligations, and Financial Partner and Governmental Authority requirements and requests; and
  • ·Analyze and develop Stripe's products and Services.

·How does Stripe use Personal Data to improve its products and Services?

·Stripe collects data, including Personal Data, while providing Services to its users. Stripe uses some of the data it collects to improve its products and Services, including by training the models it employs for fraud and loss prevention and to analyze the performance of Stripe's products as permitted by applicable law and agreements.

·Personal Data is required to train Stripe's fraud and loss prevention models, including those employed by Stripe Radar and Stripe Identity. These products rely in part on their ability to recognize certain characteristics that help determine whether a transaction is fraudulent or unlikely to complete. For example, they compare Personal Data presented in a specific transaction to Personal Data collected in the past to identify when a fraudster is attempting to perpetrate fraud, including to impersonate a Stripe User or their End Customers.

·In addition to using Personal Data to train its fraud and loss prevention models, Stripe also uses Transaction Data to assess the functioning of its current products and proposed product improvements. For instance, Stripe uses data collected by its java script library stripe.js to assess the performance of the checkout surfaces it provides to Business Users, and payment authorization data to evaluate ways to improve authorization rates for Business Users. Stripe uses Personal Data, such as IP address, to identify which pages and features a user interacted with during a checkout session, so that it can assess the effect different features have on the outcome of a checkout session.

·Stripe uses pseudonymized or aggregated Transaction Data for these purposes in certain circumstances. When Stripe communicates the results of its product performance analytics to Business Users or for advertising purposes, it does so only in aggregated or de-identified form that does not permit third-parties outside of Stripe to associate that data with any particular End Customers.

·You should consult your legal counsel regarding how best to disclose Stripe's data usage to your customers. But, here is a paragraph you could add to your privacy policy if it doesn't already include such a disclosure:

  • ·We use Stripe for payments, analytics, and other business services. Stripe may collect personal data including via cookies and similar technologies. The personal data Stripe collects may include transactional data and identifying information about devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud detection, loss prevention, authentication, and analytics related to the performance of its services. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.

·How does Stripe use personal data to train artificial intelligence models?

·We train artificial intelligence models that we deploy for a number of purposes, including to prevent fraud and other harm to Stripe, Users, and others, increase authorization rates and revenue realization for Business Users, provide and improve User experience on other Services, and identify when Business Users may benefit from services they are not currently using. Preventing Fraud

·We train artificial intelligence models to prevent fraud in a number of ways, using different kinds of data appropriate to the kinds of fraud we are trying to prevent. These fraud prevention models include:

  • ·Our transaction fraud models which power Stripe Radar and are trained to recognize transaction fraud, including card testing and card cashing. We train such models using data related to activity that individuals and businesses have conducted on our Services. We also use information from third party and publicly available sources including those related to data compromises and fraud attacks. The training data may include payments transaction data, such as names, addresses, location based on IP addresses, and payment method information, advanced fraud detection data, Financial Connections data, and signals from third party providers regarding whether consumer transaction details and device information may have been compromised, fabricated, or associated with fraud. Using such details enables our models to recognize patterns in the information we receive at the time of a transaction that may indicate fraud attacks.
  • ·Our authorization fraud models which we use to provide advanced fraud tools to Stripe Issuing users. We train these models using data related to activity conducted using cards issued through the Stripe Issuing program. This training data may include transaction data, accountholder data, authorized user data, and merchant information, such as names, email addresses, card details, addresses, and histories of authorizations, declines, and disputes. Based on these features, our models evaluate the circumstances surrounding a transaction presented for authorization on a Stripe Issuing card to score the risk that a given transaction is attempted without authorization. Issuing users can leverage these scores to determine whether to block or allow transactions attempted on cards issued for them.
  • ·Business User risk models that identify when prospective Business Users may pose a heightened risk of fraud and other losses to Stripe, Users, and other participants in the financial ecosystem. We train these models using risk signals related to Business User and Representative details, such as names, email addresses, dates of birth, physical addresses, bank account information, and device details, business information, such as industry information and website content, patterns of activity on our Services, including payments, disputes, and past fraud actions, advanced fraud signals collected when a Business User or Representative accesses our sites, and signals indicating that Business User or Representative details may be compromised, fabricated, or associated with fraud. We collect this data from our Services and publicly available and third-party sources. Training on such data allows our models to recognize usage patterns by Business Users that can be indicative of potential fraud and other behavior that may cause losses.

·Increasing Authorization and Revenue Realization

·We train artificial intelligence models to increase authorization rates and revenue realization for Business Users who use our payments products. Models we train for these purposes include:

  • ·Models that power Stripe Billing's Smart Retries feature. This feature uses artificial intelligence to identify the best time to re-attempt a failed subscription payment. We train the Smart Retries models on data from past transactions on Stripe to identify the times at which transactions associated with a customer's card details, name, email address, IP address, billing address, and shipping address have been successful. This model may be trained on features indicating the time and outcome of past transactions, card features, such as address, bin, and card type, user device features, such as IP address and user agent, and transaction features, such as the amount, subscription type and history, and product description. We also use location based on IP address as calculated by third-party service providers. Based on this information, Smart Retries recommends to users when may be the best time to make another attempt at processing a failed subscription payment.
  • ·Models that power Stripe Payments's Adaptive Acceptance feature. We use these models to determine whether to reattempt charges that a card network or issuing bank rejected on the first attempt and to automatically select the optimal protocol optimization and authentication pathway for the transaction. We train the models using data from past transactions on Stripe, including features related to the history of authorizations and declines we have observed for the card, customer, or merchant involved in the transaction, transaction features such as the merchant, amount of the charge, and the reason it was declined, and card features such as the bin, issuer, and expiry date. Based on these features, the models calculate the probability that a charge will be successful if submitted at different times and according to different protocols. We use this probability of authorization to determine how to submit the charge to maximize profit for Stripe and its Users. Providing Other Services

·We train artificial intelligence models to power other Services such as:

  • ·Stripe Identity, which uses artificial intelligence models to match verification subjects with their photo ID documents. These models compare biometric features in the selfies with those in the documents and spot features common to fraudulent verification attempts, such as images where the subject's face is obscured by a mask or the document has been modified or does not match a known format. We train Identity's models using images from verification subjects who have consented to our using their data to improve Stripe Identity.
  • ·Instant Bank Payments, which uses artificial intelligence models to evaluate the risk that someone is attempting to misuse the service by conducting a transaction using a bank account they are not authorized to use or an account with insufficient funds. End Users who sign up for Instant Bank Payments agree to provide us with details from their bank accounts, such as ownership information, transaction history, and balance details, to determine whether to authorize their transactions and train our models to recognize when banks are likely to reject future transactions attempted through the Instant Bank Payments Service. Identifying Services for Users

·We also train models to recognize Business Users that are good candidates to use additional Stripe services, such as Stripe Capital in the US. We may train these models using information related to a Business User's activity on the Stripe platform and, when the user provides them to us, bank account and other financial information. The models are trained using such information so that they can recognize similarities between the current Business User and other Business Users who have benefitted from our products in the past. To the extent that Business Users are individuals, such data may constitute Personal Data.

·As a Stripe Business User and as a data controller, what does GDPR mean for me?

·As a Stripe Business User and a data controller, the GDPR places responsibility on you in relation to the Personal Data that you process through Stripe services (i.e., your End Customers' data). If you have customers anywhere in the EU / UK, you are required to comply with the GDPR (and/or the UK's version of GDPR), no matter where your business is located. Fundamentally, you must ensure that you have a lawful basis for processing Personal Data and that you are transparent with your customers about how their data is used.

·Data controllers will need to have certain contractual terms in place with third parties who act as data processors on their behalf. To assist Business Users with their compliance with the GDPR, Business Users enter into a Data Processing Agreement ("DPA") with Stripe. Understanding both your obligations and Stripe's role under the DPA is essential for operating within the GDPR framework. We encourage you to read our DPA to learn more.

·Who are Stripe's sub-processors and how are they vetted?

·Please see our service providers page where we have a list of our sub-processors, affiliates, and most common service providers. Stripe identifies, evaluates, and engages sub-processors through our vendor management program. We enter into a contract with each sub-processor prior to sharing data with the sub-processor, and each contract contains terms that provide for monitoring and audit. In addition, all vendors are vetted and approved through Stripe's security review process before we begin using their services.

·From where does Stripe collect information used for fraud prevention and security purposes?

·To prevent fraud and strengthen our security, we may collect information from Business Users, End Customers, End Users, financial parties, and in some cases third parties. For example, we collect and analyze information that helps us identify bad actors and bots, including both transactional data (such as amount, customer shipping address, date, and so on) and advanced fraud detection signals (device and activity signals). Learn more.

·Stripe also receives information from third parties to prevent and respond to security incidents, and for protecting against other fraudulent activity. For example, we may receive information from third parties about IP addresses that malicious actors have compromised. Stripe may use Representatives' Personal Data provided at onboarding to query third party databases regarding fraud and risk signals associated with that data. The third party providers operating these databases may use Stripe's experience with the Personal Data queried to inform their fraud and risk signals.

·How does Stripe use and share data to authenticate my transactions?

·To help prevent fraudulent transactions when you use your debit or credit card to pay a Business User, we may share data related to you and your transaction with your card issuer, bank, and payment method provider so that they can verify your identity and authenticate your payment method. The data we share to enable this process may include Personal Data such as your name, email address and phone number, and payment-specific data like your billing and shipping address.

·Issuers and payment method providers may use the information we share to verify you through a process called 3D Secure Authentication or 3DS. 3DS is an authentication standard designed by the major card networks which aims to reduce fraud and provide added security by providing an additional layer of authentication to online card payments. 3DS is often known by its branded names like Visa Secure, Mastercard Identity Check, or American Express SafeKey. It works by comparing the information you provide at the time of the transaction with the information that your issuer and payment method provider already have on file, to help reduce the risk that someone else may use your card for an unauthorized transaction.

·Additionally, we may share contextual data, such as your device ID and previous transaction history. The process may take place as part of the checkout flow, which may involve you being redirected to another page where your bank asks you for a code or password to approve the purchase.

·3DS is frequently used in Europe in support of Strong Customer Authentication requirements under the Payment Services Directive (PSD2) and to comply with similar regulations in other countries including the UK, India and Australia. When we act as a service provider to your bank under our Stripe Issuing program we and our service providers may use Personal Data such as your card number, contact information, payment-specific data, like your billing and shipping address, and contextual data such as your device ID and transaction history to facilitate 3DS authentication.

·How does Stripe use Personal Data to prevent fraud?

·The Stripe products that use Personal Data to enable Stripe's Business Users to detect and prevent fraud include Stripe Radar, Stripe Identity, and Stripe Merchant Risk Tooling. Stripe also employs internal risk models and other product features, such as 3D Secure incorporated into Stripe's Issuing product, to prevent its products and Services from being used for fraudulent activity.

·Stripe Radar processes Personal Data as described here using its artificial intelligence model to produce scores indicating the likelihood that a payment method is being offered by someone other than an authorized user. These scores are designed to identify fraudulent transactions, they do not rate the character or creditworthiness of the individuals involved in a particular transaction. Based on the service selected by the Business User, Stripe may provide the Radar scores to its Business Users to help them to combat fraud and provide a mechanism for them to set rules to better manage transactions based on Radar scores and other indicators of fraud.

·Stripe Identity uses Personal Data, as described here, to combat fraud by enabling Business Users to verify whether the person they are transacting with is who they say they are. Identity compares biometric identifiers in a selfie against government issued ID. Identity can also validate Personal Data, such as name, date of birth, and government ID number, that an End Customer types into a web form against government and third-party databases to determine if the identity presented matches the government issued ID number.

·Stripe's internal risk models seek to combat fraud by recognizing when a fraudster is attempting to use Stripe's Services for fraudulent purposes. For instance, Stripe uses Radar scores internally to determine whether a payment method offered to Stripe products such as Link, Frontier, Crypto Onramp, and Bill Pay should be accepted or rejected as likely fraudulent. Stripe's internal risk models also use aggregated cardholder features to recognize when a large number of transactions are likely being conducted by the same individual for purposes of testing or cashing out stolen payment methods. Where Stripe recognizes such activity, it will block transactions to prevent harm to itself, its users, and others.

·Stripe Merchant Risk Tooling leverages Stripe's internal risk models to help Stripe Connect Platforms identify indicators of potential fraud associated with their Connected Accounts. Merchant Risk Tooling produces reasoned scores that identify to Platform's internal fraud teams when there are indicators consistent with a Connected Account attempting to use the Platform's services (and Stripe) for fraudulent purposes. These scores are designed to supplement the Platforms' due diligence related to their Connected Accounts and their business activities. They do not score the character or creditworthiness of the individuals involved in the Connected Accounts' operations. The data factored into Merchant Risk Tooling includes payments Transaction Data, business Representative details (such as IP address, physical address, and e-mail address) business website content, and other information regarding the businesses Business Users operate on Stripe.

·Along with attempting to combat fraud at the merchant and Stripe-wide levels as described above, Stripe also incorporates features in its individual products that use Personal Data to prevent fraud. One such feature is 3D Secure authentication, incorporated in Stripe Issuing. This feature is required by law in certain jurisdictions and requires cardholders to authenticate using one or more factors before they can complete an online transaction. Stripe and its service providers use and store Personal Data including cardholder PANs, contact information, and transaction history to authenticate cardholders using one time passcodes and knowledge of past transactions. These measures help combat fraud by increasing the likelihood that the person offering a card for payment is an authorized user.

·I heard that Stripe is collecting additional information about my account from a third party and/or my other Stripe account. Why is Stripe collecting this information?

·Stripe may collect additional information about your account to allow Stripe and its Financial Partners to detect fraud and/or fulfill financial compliance requirements. These requirements come from our Financial Partners or regulatory obligations and are intended to prevent abuse of the financial system. Examples of missing data fields include your address, phone number, social security number, date of birth, employer identification number, or website URL. Stripe may be able to fill in some of this information by leveraging data we have collected from one of your other Stripe accounts or by obtaining data from a third party. We will show Business Users the information that we are associating with their account on your dashboard, and Business Users may update or correct that information via your dashboard. Please see Stripe's Privacy Policy for additional information.

·Does Stripe collect precise location data?

·Devices such as mobile phones or computers may collect precise location data using GPS technology. Stripe does not collect GPS data from devices and browsers.

·Depending on the Services you use and the Business Users' implementation of our Business Services, we will collect information (including IP addresses) through cookies and similar technology. We will collect your IP address when you visit our Sites. Please see our Cookie Policy to learn more. Stripe may use location information, including approximate latitude and longitude, derived from End Customers IP addresses to detect potentially fraudulent transactions.

·We also receive approximate location information (such as country, city or state) from third party providers such as MaxMind to help us determine the approximate location of Visitors to our website for marketing purposes (for example, inviting you to local Stripe events).

·In addition to its sub-processors, what other third parties does Stripe share information with?

·When we work with service providers in our capacity as a data processor for our Business Users' and End Users' Personal Data, the GDPR calls these third-party service providers a sub-processor. Sub-processors are service providers who have or potentially will have access to or process Personal Data on behalf of Stripe where Stripe acts as a data processor for the Business User. These third parties are disclosed on our Stripe Sub-Processor and Service Providers List.

·In addition to Stripe's Sub-processors, we may also share Business Users' onboarding data and payment instrument information with third party business partners when this is necessary to provide our Services to our Business Users. We do so, for example, for the purposes of offering payment processing Services to our Business Users or facilitating payment settlements.

·Third parties to whom we may disclose Personal Data for this purpose are banks, payment method (service) providers, digital wallets and payment processors, including, but not limited to, the following entities:

  • ·American Express Payment Services Limited and American Express Payments Europe S.L.
  • ·Banking Circle S.A. Barclays Bank PLC Citibank Europe plc
  • ·Credit Mutuel Arkea and Arkea Banking Services
  • ·Currence iDEAL B.V. Klarna AB
  • ·Mastercard Europe S.A. Polski Standard Płatności Swisscard AECS GmbH Visa Europe Limited
  • ·TrueLayer Ltd.

·Learn more about payment methods. The data shared with payment method providers will depend on the payment method(s) enabled on the Business User's account.

·In addition, Stripe shares Personal Data as we believe necessary to, among other things, protect Stripe's Services, rights, privacy, safety and property of Stripe, our users or others. For example, to protect our Services, Stripe may receive or disclose information about IP addresses that malicious actors have compromised.

·Please note that if you provide us with your payment method information (e.g., a card number and expiration date) to store on file or otherwise in connection with a transaction, Stripe may update your card information if your information has changed or been updated to ensure your transactions go through smoothly, including by working with your card issuer or payment card network. If you would prefer to not have your updated payment method details shared with us, please reach out to your card issuing bank.

·Transfer

·Stripe will pass on Personal Data to affiliates and service providers or sub-processors, if deemed strictly necessary to carry out contractual obligations or for the data to be processed. Depending on the enabled payment method(s), data may be transferred to the jurisdiction(s) of the respective payment method(s). Before we engage any third party, we perform due diligence, including a vendor security assessment. All of our service providers are subject to contract terms designed to ensure that these service providers process Personal Data only for the purposes of providing services to Stripe and in accordance with our commitments to Users and applicable data protection laws. Moreover, Stripe maintains and enforces a security program that addresses the management of security and the security controls employed by Stripe, which includes third party risk management. In addition, Stripe employees, agents, and contractors acknowledge their data security and privacy responsibilities under Stripe's policies.

·Financial Connections

·If you are an End Customer who has been asked to link your financial account using Stripe, please visit the support webpage here to learn more about our privacy practices. Or you can jump to the specific topics linked here:

  • ·Linking my financial account and consent
  • ·Data collected, stored, and shared from my linked account
  • ·How Stripe accesses data from my linked account
  • ·Relationship between Stripe and its service providers Data security
  • ·Who can access data from my linked account and for what purposes Who will obtain my login credentials
  • ·Requesting disconnection or data deletion
  • ·Correcting my financial account information

·What Business User and Representative data does Stripe share with a payment method to facilitate Business Users' enabling the payment method?

·Stripe makes it possible for its Business Users to enable payment methods including card networks such as Visa and MasterCard, mobile and online payment methods such as WeChat Pay and Alipay, and buy now pay later providers such as Klarna and Afterpay. Certain payment methods are enabled by default when you onboard with Stripe. After onboarding, for eligible users, Stripe may enable additional payment methods after notifying you. Your Stripe dashboard allows you to enable or disable payment methods at any time.

·Stripe may share information regarding a Business User and the Business User's Representative with a payment method provider when a payment method is enabled and when Stripe processes transactions involving the payment method. The payment method provider may require Business Users' and their Representatives' Personal Data for a number of purposes, including complying with know your customer (KYC), anti-money laundering, and other legal and compliance requirements, preventing fraud, facilitating transactions, providing Services to Business Users, and servicing the payment method's platform. For these purposes, Stripe may provide payment method providers with Business User data, including but not limited to business name, business type, merchant category codes, merchant ID, transaction history, bank account information, and other transaction specific information such as product type and tax amount that Stripe ascertains from that data. Stripe may also provide payment methods with Business Users' Representatives' Personal Data, including name, address, contact information, date of birth, tax identification number, and other government issued ID information. The information Stripe shares with payment method providers is data that Stripe has collected from the merchant or ascertained from data provided by the merchant.

·How does Stripe use Representative contact information to provide its Services?

·As part of providing our Services we may process Representative contact information for purposes including authentication, providing updates regarding the Services, providing support, and to address issues related to Business Users' Stripe accounts, such as unpaid balances.

·What data about End-Customers and their transactions is used by Radar and what data does Stripe share with its Radar Business Users?

·When processing payments, it's valuable to Stripe, Business Users and End Customers to enable legitimate transactions while also trying to prevent fraudulent transactions, making online purchases safer for everyone involved. Radar helps detect potentially fraudulent transactions for Stripe's Business Users (i.e., merchants) through machine learning and other techniques. To do this, Radar leverages data collected across our Services.

·Radar's artificial intelligence model produces transaction "scores" indicating the model's assessment of the likelihood that a transaction is fraudulent. Business Users can leverage this score and use it to implement automated rules to determine whether to allow, block, or flag transactions for additional review. Business Users can use Radar as one of multiple inputs in making decisions with respect to the potential for fraud in a transaction.

·Radar uses data collected about the End Customer from various sources, including payments Transaction Data, advanced fraud detection data, Bank Connections data, IP address, and physical address information. Radar uses this data to assess whether the payment method offered by the End Customer is likely unauthorized.

·Stripe may share with the Business User and allow them to export (where allowed by Law) certain information relevant to fraud detection, including:

  • ·a transaction score that assesses the likelihood of the transaction becoming a fraudulent charge-back, risk insights for that transaction,
  • ·related payments made by the End-Customer to the Business User,
  • ·other Transaction Data related to that End-Customer's transaction with that Business User (e.g., cardholder name, card information, and the payment amount and date),
  • ·device and browser information for the device used to make the transaction with that Business User, and
  • ·aggregated benchmarks.

·As a Business User, what notice do I provide to my End Customers about Stripe?

·Under the terms of our agreements, Business Users are required to provide all necessary notices and obtain all necessary rights and consents from their End Customers to enable Stripe to lawfully collect, use, retain and disclose the Personal Data as part of the Stripe Services. Business Users, as data controllers and/or the End Customer facing entity, are responsible for the contents of their privacy notice and cookie banner. As an example, here is a paragraph that you can consider adding to your privacy notice or cookie (if you don't already have such a disclosure):

·We use Stripe for payments, analytics, and other business services. Stripe may collect personal data including via cookies and similar technologies. The personal data Stripe collects may include transactional data and identifying information about devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud and prevention and detection, authentication, analytics related to the performance of its services, and to enhance and customize the user experience. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.

·Please be aware that the disclosure above is for illustrative purposes only and is not legal advice. Please talk to your legal advisor to understand how to comply with your obligations under applicable law.

·To comply with our transparency obligations, we explain how our cookies are used in our Cookie Policy and our Cookies Settings Dashboard sets out our list of cookies. We remind our Business Users to review the cookies placed on their website and to update their cookie banners accordingly.

·Are there any jurisdictional nuances to Stripe's use of service providers in verifying the identity of Stripe's Business Users?

·Germany

·Stripe, through its service providers, may use information from infoscore Consumer Data GmbH to verify the identity of Stripe Business Users in Germany. Information about infoscore Consumer Data GmbH is available here.

·Data Obtained from Third Parties

·If you have been notified by Stripe that we obtained your data from a third party, the following applies:

  • ·Your Personal Data will be processed as set out inin accordance with Stripe's Privacy Policy, which in accordance with Art. 14 GDPR describes:
  • ·the identity and the contact details of Stripe;
  • ·the contact details of Stripe's Data Protection Officer;
  • ·the purposes of the processing for which the Personal Data are intended as well as the legal basis for the processing, which includes prospecting and direct marketing, as permitted under applicable law;
  • ·the recipients or categories of recipients of the Personal Data. In addition to the recipients mentioned in the Stripe Privacy Policy, Personal Data may be shared with Salesloft, Inc. as a processor of Stripe;
  • ·that Stripe intends to transfer Personal Data to a recipient in a third country and a reference to the appropriate or suitable safeguards and the means to obtain a copy of them or where they have been made available (see here and here for more information);
  • ·the period for which the Personal Data will be stored and/or the criteria used to determine that period;
  • ·the existence of the right to request from Stripe access to and rectification or erasure of Personal Data or restriction of processing concerning the data subject and to object to processing as well as the right to data portability or any other applicable rights under data protection laws (see also here);
  • ·the right to lodge a complaint with a supervisory authority.
  • ·Categories of Personal Data Obtained: We process granular categories of Personal Data, including full name, business email address, direct phone number, professional social media profiles, business physical address, company metadata (such as company name, registration number, size, and domain), professional role and title, industry sector, and professional history.
  • ·Data Sources: We collect Personal Data from third-party providers, including Cognism Limited, ZoomInfo Technologies Inc., API Hub, Inc. (Clearbit), Crunchbase Inc., PitchBook Data, Inc., infoAnalytica, Inc., People Data Labs, Inc., Apollo.ai GmbH, and Dealroom.co, as well as publicly available corporate registers and online sources. These third parties operate as independent data controllers. If you wish to be removed from their databases, please contact them directly.
  • ·Legal Basis for Processing: All processing of data obtained from third parties is based on Stripe's legitimate interests pursuant to Art. 6(1)(f) GDPR. These legitimate interests include:
  • ·market research and analysis; prospecting and selling; and
  • ·marketing and advertising.
  • ·Where you are a potential Business User or a representative of a potential Business User, Stripe may also obtain information about you and your organization from enrichment providers and publicly available sources. This may include firmographic information such as company size, industry, growth indicators, and information about the organization's existing payment-service or billing providers.
  • ·Stripe uses this information to understand an organization's potential business needs, maintain accurate business records, tailor outreach, and market Stripe services where permitted by applicable law.
  • ·Your Rights as a Data Subject: You may have explicit rights under applicable laws regarding your Personal Data, including the right to request access, rectification, restriction of processing, data portability, erasure (right to be forgotten), and the right to object at any time to processing based on legitimate interests (including direct marketing). To exercise any of these rights, please submit a request through our Privacy Portal or contact our Data Protection Officer directly.

·Does Stripe Record Calls?

·In some situations, we may record and/or transcribe voice or video calls we have with you. At the start of the call, we disclose the fact that a call is being recorded and, unless we are legally required to record the call, will ask for your consent to record the call and/or offer you the option to decline the call being recorded. We may use third-party systems to record and/or transcribe calls, including Zoom and Salesloft. In some cases, transcripts are generated by AI tools.

·The call recordings will be processed for the purposes stated at the start of the call, typically for quality and training purposes, and in accordance with Stripe's Privacy Policy. We enable you to exercise your rights as a data subject under applicable law with respect to these recordings as set out in Stripe's Privacy Policy. In the event that you request a copy of the recording, Stripe may provide you with a redacted copy of the recording, or a (redacted) transcript of the recording, where appropriate, and as permitted under applicable law.

·We normally retain call recordings for up to 3 years. We may retain transcripts for a further limited period for training, quality and operational purposes.

·User support related phone calls are normally retained for 5 years as Stripe is under a legal obligation to keep this data for 5 years. Collection related call recordings are also kept for 5 years.

·After this, call recordings will be deleted, unless we have a valid legal ground to keep the call recordings for a longer period of time.

·How does Stripe collect information for phone verification?

·When you use Stripe Services, we may need to verify your identity to comply with legal requirements or ensure that we are dealing with you and not a fraudster attempting to impersonate you. We may also verify your identity as a service to the Business Users with which you choose to transact. One of the data points we may consider for these purposes is whether your phone number is associated with the other information you have provided while seeking services from us or our Business Users. We may rely on third-party services providers to assist us in performing such verification checks. In particular, your wireless carrier may disclose information about your account and your wireless device, if available, to Stripe or our service providers for the duration of your business relationship, to help us identify you or your wireless device, to prevent fraud, and as otherwise described in our Privacy Policy.

·How does Stripe use Personal Data for co-marketing End User Services?

·If you have a Link account, Stripe may review your Link Transaction Data to determine which businesses you transact with and which additional services you may benefit from. We may also, where permitted by law, use your Personal Data (such as your email address, device information, and transaction history) to send you marketing information about our Services or co-marketing communications about how you can use our Services with Business Users you transact or interact with. We do not share your Transaction Data or other Personal Data with these Business Users to facilitate these marketing activities.

·U.S. Privacy Disclosures

·Categories of Personal Information Collected and Disclosed Under the CCPA

·Below are the categories of data we collect and how that information is used in the last 12 months. We also disclosed this data for a business purpose within the preceding 12 months.

CATEGORIES OF PERSONAL INFORMATION COLLECTEDPURPOSES:DISCLOSED FOR A BUSINESS PURPOSE WITHIN THE PRECEDING 12 MONTHS TO:
Identifiers (e.g., a device identifier)Identity verification, fraud prevention and security, to provide and advertise our Services, and to comply with law.We may disclose the data, pursuant to applicable law, to: service enablers (including service providers, Financial Partners servicing the financial product), third parties like ad partners that help us advertise our products and Services, the merchant that you do business with (a.k.a. our Business User), an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies.
Characteristics of protected classifications under California or federal law (e.g., gender and age noted in ID documents that you submit so that Stripe can verify your identity on behalf of your merchant - a.k.a. our Business User)Identity verification, fraud prevention and security, to provide our Services, and to comply with law.We may disclose the data, pursuant to applicable law, to: service enablers (including service providers and Financial Partners servicing the financial product), the merchant that you do business with (a.k.a. our Business User), an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies.
Commercial information (e.g., the merchant that you choose to do business with - a.k.a. our Business User may receive your Transaction Data)Fraud prevention and security, to provide our Services, to comply with law, enforce our terms of services, and for other purposes consistent with your consent and applicable law.We may disclose the data, pursuant to applicable law, to: service enablers (including service providers and Financial Partners servicing the financial product), the merchant that you do business with (a.k.a. our Business User), an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies.
Biometric information (e.g., biometric identifiers from photo IDs used to confirm your identity)Identity verification, fraud prevention and security, and for other purposes consistent with your consent and applicable law, such as to improve our verification systems. Learn more.We may disclose the data, pursuant to applicable law, to: a service provider - i.e., Amazon Web Services ("AWS"), an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies.
Online activity information (e.g., information about devices and browsers across certain Business User sites that use Stripe and IP addresses associated with those devices and browsers, and usage data)Fraud detection and security, to comply with law, and to provide and advertise our Services.We may disclose the data, pursuant to applicable law, to: service enablers (including service providers, Financial Partners servicing the financial product), third parties like ad partners that help us advertise our products and Services, the merchant that you do business with (a.k.a. our Business User), an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies.
Location Data (Learn more)Fraud detection and security, in furtherance of compliance with legal obligations, and to provide and advertise our Services.We may disclose the data, pursuant to applicable law, to: service enablers (including service providers, Financial Partners servicing the financial product), third parties like ad partners that help us advertise our products and Services, the merchant that you do business with (a.k.a. our Business User), an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies.
Audiovisual (e.g., visual, audio, or similar information, like photos you submit so that Stripe can verify your identity on behalf of your merchant - a.k.a. our Business User)Identity verification, fraud prevention and security, to provide our Services, and to comply with legal obligations.We may disclose the data, pursuant to applicable law, to: service providers, the merchant that you do business with (a.k.a. our Business User), an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies.
Professional or Employment-Related InformationRecruiting and employment, and to comply with legal obligations.We may disclose the data, pursuant to applicable law, to: service providers, an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies.
Categories of personal information described in Cal. Civ. Code 1798.80(e)(such as name, address, telephone number, credit card or debit card number)See above. Identity verification, fraud prevention and security, to provide and advertise our Services, and to comply with legal obligations.We may disclose the data, pursuant to applicable law, to: service enablers (including service providers and Financial Partners servicing the financial product), the merchant that you do business with (a.k.a. our Business User), an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies.

·What sensitive personal information under the California Consumer Privacy Act (CCPA) does Stripe collect and for what purposes does Stripe use that data?

·Stripe only processes sensitive personal information for the purposes specified in section 7027(m) of the California Consumer Privacy Act Regulations, or without the purpose of inferring characteristics about a consumer.

Sensitive Personal Information CategoriesPurposes include:
Identification documents, including driver's license, passport, and social security (including any underlying sensitive information in the identity card, such as racial or ethnic origin)Identity verification, fraud prevention and security, to provide our Services, and to comply with legal obligations.
Biometric informationIdentity verification, fraud prevention and security, and for other purposes consistent with your consent and applicable law, such as to improve our verification systems. Learn more.
Location Data Learn more.Fraud detection and security, to comply with law, and to provide our Services. Learn more.
Account log-in, financial account in combination with any required security access code, password, or credentials allowing access to an accountTo provide our Services (e.g., Financial Connections), comply with law, enforce our terms of services, and for other purposes consistent with your consent and applicable law.

·Does Stripe "sell" or "share" my personal information under the CCPA?

·We do not transfer your Personal Data to third parties in exchange for payment. However, as noted above, we may provide your Personal Data to third party partners, such as advertising partners, analytics providers, and social networks, who assist us in advertising our products and Services to you. Because these third parties may use the data Stripe provides for their own purposes (such as to improve their ad delivery), Stripe's provision of data to these parties may be considered a data "sale" or "sharing" as those terms are defined under the CCPA and other applicable US privacy laws. To our knowledge, Stripe does not sell personal information of minors under 16 years of age.

·Within the past 12 months, the following categories of Personal Information described in section 1798.80(e) of the California Civil Code have been "sold" or "shared" (as defined under the CCPA) to third parties (including advertising partners) who assist us in advertising our Services: Identifiers (e.g., a device identifier)

  • ·Online activity information (e.g., information about devices and browsers across certain Business User sites that use Stripe and IP addresses associated with those devices and browsers, and usage data) Geolocation Data (e.g., IP addresses)

·You can opt out of targeted advertising and any related data "sales" or "sharing" here.

·How long will Stripe keep my data?

·Stripe keeps Personal Data as necessary to achieve the purposes listed here. To determine the appropriate retention periods for different categories of Personal Data, we consider various criteria such as the jurisdiction you are located in, the nature of our relationship with you, the types of products or Services being offered or provided to you, the nature and sensitivity of your Personal Data, retention requirements under applicable laws and regulations, and other legitimate interests we may pursue through retaining your Personal Data, including detecting and preventing fraud and financial crimes, enforcing and defending our legal rights, complying with valid legal process requests from courts or competent authorities, improving the quality of our Services, and promoting our products and Services as appropriate and as permitted by applicable law and agreements.

·For most jurisdictions, Stripe will generally keep Personal Data we obtain from our Business Users for a period of five or more years from the end of the business relationship with you, or the date of the last transaction, whichever is later.

·The table below outlines different categories of personal data collected, along with the retention period or the criteria used to determine that period.

CATEGORIES OF PERSONAL DATA COLLECTEDRETENTION PERIOD OR THE CRITERIA USED TO DETERMINE THAT PERIOD
Non-sensitive Identifiers (e.g., name, postal address, email address, account name) Categories of personal information described in Cal. Civ. Code § 1798.80(e) (such as name, address, telephone number, credit card or debit card number) Characteristics of protected classifications under California or federal law (e.g., gender and age noted in ID documents that you submit so that Stripe can verify your identity on behalf of your merchant - a.k.a. our Business User) Commercial information (e.g., Transaction Data that the merchant you choose to do business with - a.k.a. our Business User - may receive) Online activity information (e.g., certain information about devices and browsers across certain Business User sites that use Stripe, and usage data) Audiovisual (e.g., visual, audio, or similar information, like photos you submit so that Stripe can verify your identity on behalf of your merchant - a.k.a. our Business User)For the duration necessary for Stripe to: (1) comply with law; (2) provide the Stripe Services, and; (3) pursue our legitimate interests, including detecting and preventing fraud and financial crimes, enforcing and defending our legal rights, complying with valid legal process requests from courts or competent authorities, improving the quality of our Services, and promoting our products and Services as appropriate and as permitted by applicable law and agreements.
Biometric information (e.g., biometric identifiers from photo IDs and selfies used to confirm your identity)No longer than 1 year, or upon revocation of your consent, whichever is earlier.
Geolocation Data (e.g., IP addresses)For the duration necessary for Stripe to: (1) comply with law; (2) provide the Stripe Services, and; (3) pursue our legitimate interests, including detecting and preventing fraud and financial crimes, enforcing and defending our legal rights, and complying with valid legal process requests from courts or competent authorities.
Professional or Employment-Related Information Education information that is not publicly available as defined in the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g)For the duration necessary for Stripe to: (1) comply with law; (2) make certain employment and performance-related decisions; (3) address future hiring needs; (4) ensure health and safety in the workplace; (5) conduct certain administrative tasks, including to administer benefits; and (6) pursue our legitimate interests, including enforcing and defending our legal rights and complying with valid legal process requests from courts or competent authorities.
Sensitive personal information, as defined by California law (Learn More)For information regarding your government IDs (including the sensitive data therein) and your location data, Stripe will retain that data for the duration necessary to: (1) comply with law; (2) provide the Stripe Services, and; (3) pursue our legitimate interests, including detecting and preventing fraud and financial crimes, enforcing and defending our legal rights, complying with valid legal process requests from courts or competent authorities. For biometric data, see above.Where we rely on consent to collect your other sensitive personal information (e.g, financial account login credentials), Stripe will no longer retain this data upon your revocation of consent.

·California Privacy Rights Metrics

·The following includes aggregate metrics of data subject rights requests received in the 2023 calendar year. This data reflects requests received from individuals in California and may also include requests from individuals who do not reside in California.

  • ·Number of "request to know" received and complied with in whole or in part: 7
  • ·Number of "requests to delete" received and complied with in whole or in part: 7719
  • ·Number of "request to correct" received: 0
  • ·Average number of days taken to respond to a request to know or delete: 1

·Due to the nature of Stripe's products and Services, when we receive a general "request to delete," our process is to direct the requestor to a page to action their request depending upon the relationship they have with Stripe. We also offer data subjects the opportunity to contact us, should they have any questions or concerns.

·Stripe may retain Personal Data where permitted by law, including to comply with our legal obligations. For example, as a provider of payment services, Stripe is required to comply with many regulations, including anti-terrorism and anti-money laundering laws. These laws require Stripe to retain certain information associated with Stripe users for a prescribed period of time after account closure. Learn more about our retention obligations in our Privacy Policy.

·We rely upon a number of legal grounds to enable our use of your Personal Data. In short, we use Personal Data to facilitate the business relationships we have with our Business Users and End Users, to comply with our financial regulatory and other legal obligations, and to pursue our legitimate business interests. We also use Personal Data to complete transactions and to provide payment-related Services to our Business Users.

·The table below provides a detailed overview of why and how we use your Personal Data.

·For the purposes of the EU and UK GDPR and the Thai Personal Data Protection Act 2019 ("PDPA"), we rely upon a number of legal bases to enable our processing of your Personal Data.

·End Users

·When you directly use an End User Service (such as when you sign up for Link, or make a payment to Stripe Climate in your personal capacity), for your personal use, we refer to you as an "End User."

PROCESSING PURPOSECATEGORIES OF PERSONAL DATALEGAL BASES
Provide our Services. To provide Services to you, including delivery, support, personalization and messages related to the service.Your name, contact information, payment information including Bank Account Information and Bank Payments, and/or payment card number, CVC code and expiration date.Our contractual necessity to perform our contractual relationship with you, under applicable data protection laws.
For the provision of our Services including Link, Atlas and Identity. When we process data based on your consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing based on such consent before the consent is withdrawn.If you choose to use Link you agree to let Stripe store your payment method and related information so that you can more readily make purchases with Business Users who use Stripe to provide payment processing Services (e.g. Stripe Checkout).Based on consent in processing this personal information.
Card Products and Financial Products including Issuing and Treasury Direct Services.We use your Personal Data to offer you card products and financial products and Services under the Stripe brand and/or under the brand of a Business User.Your name, email address, phone number, postal address, transaction information, password, PIN or similar credentials, card PANs, age, DOB, credit card number, drivers license number, tax ID, cookie data, tags and beacons, IP address.Our legitimate interests in promoting our products and in determining eligibility for and offer new Stripe products and Services.
Provide cryptocurrency-related Services, including enabling End Users with Link accounts to purchase cryptocurrency from licensed third-party cryptocurrency exchange providers using a variety of payment methods and save certain personal information to facilitate subsequent cryptocurrency-related transactions.Your name, email address, date of birth, billing address, IP address, information related to your cryptocurrency wallet (including wallet identifier, access times, and IP address used to create and access the wallet), and information related to your cryptocurrency purchases, including your transaction history.Based on consent in processing this personal information.
Offer our Services and Alert you of Changes to our Services.For example, through Stripe Capital we work with Financial Partners to offer financing to certain users who can satisfy particular criteria and will process your data to help determine if you qualify for financing or not. Certain information will be processed by Stripe prior to the offer of financing in order to determine eligibility.The name and other identifying details and contact information of a Business User's Representatives, physical address of Business User, and the Business User's Stripe ID and information related to the Business User's performance on Stripe or off of Stripe if the Business User chooses to provide such information.Our legitimate interests in promoting our products and in determining eligibility for and offer new Stripe products and Services.
Fraud Detection Services. We use your Personal Data collected across our Services (e.g. Stripe Radar) to detect and prevent fraud against us, our Business Users and Financial Partners, including to detect unauthorized log-ins using your online activity.Transaction information. This includes: name, email address, billing and/or shipping address, payment method information (such as credit or debit card number, bank account information or payment card image), merchant and location, purchase amount, date of purchase, and in some cases, some information about what you have purchased, phone number and tax-related ID.This includes web browsing information, usage data, referring URLs, location, cookies data, device data and identifiers.IP address and physical address.Our legitimate interests in monitoring and detecting fraud to ensure we detect activity that can have a harmful effect on our End Users.
Marketing and Advertising. We may use your Personal Data to assess your eligibility for and offer you other Services. We use End User Personal Data for interest-based advertising and marketing purposes. We do not share End Customer Personal Data to third parties for their marketing purposes unless you give us or the third party permission to do so.Contact information including: name, email address, work phone number, and job title.Connection data such as IP address, and web behavior (page visited, length on page, etc.)Based on consent in processing this personal information.Our legitimate interest in undertaking marketing activities to offer you products or Services that may be of interest to you.
Compliance and Harm Prevention. We process and share Personal Data as we believe necessary: (i) to comply with applicable law, (ii) for compliance with rules imposed by payment method in connection with use of that payment method (e.g. network rules for Visa); (iii) to enforce our contractual rights; (iv) to secure or protect the Services, rights, privacy, safety and property of Stripe, you or others, including against other malicious or fraudulent activity and security incidents; and (v) to respond to valid legal process requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include authorities outside your country of residence.Any Personal Data we process, including information necessary for identity verification such as government-issued IDs or selfie images.Where these processing activities or disclosures are necessary to comply with our legal obligations, for the protection of a person's vital interests, for reasons of public interest, for reasons of substantial public interest, or for the purposes of Stripe's or a third party's legitimate interest in keeping Stripe secure, preventing a breach of the law, harm or crime, enforcing or defending legal rights, claims, or obligations, facilitating the collection of taxes and prevention of tax fraud or preventing loss or damage.

·End Customers

·When you do business with, or otherwise transact with, a Business User (typically a merchant using Stripe Checkout, e.g. when you buy a pair of shoes from a merchant that uses Stripe for payment processing) but are not directly doing business with Stripe, we refer to you as an "End Customer."

PROCESSING PURPOSECATEGORIES OF PERSONAL DATALEGAL BASES
Provide our Services to Business Users, including to process online payment transactions or in-person checkout, to calculate applicable sales tax, to invoice and bill, and to calculate their revenue.If you are an End Customer, when you make payments to, send shopping cart reminders, get refunds from, begin a purchase or otherwise transact with a Business User through Stripe's Services or a Stripe-provided device, Stripe will receive your transaction information. Depending on how the Business User has integrated our Business Services, we may receive this information directly from you, the Business User or another service provider to you or the Business User.Transaction Information (including from Checkout, Payment Processing and Treasury/Issuing Use). Your name, email, billing and/or shipping address, payment method information (such as credit or debit card number, bank account information or payment card image), merchant and location, purchase amount, date of purchase, and in some cases, some information about what you have purchased, phone number and tax-related ID. The payment method information that we collect will depend upon the payment method that you choose to use from the list of available payment methods offered by the Business User as part of the "checkout" process for your purchase. We may also receive your transaction history with the Business User.Transaction-Related Information / Purchase Interests. Information typed into a checkout field that is not ultimately submitted to the Business User.Our legitimate interests in providing the Stripe products and Services. Stripe processes this Personal Data given its legitimate interest in improving the Services and where it is necessary for the adequate performance of the contract with the Business Users.
Provide our Services to Business Users, to order payment methods on a per-customer basis on behalf of the Business User, to implement fraud thresholds chosen by the Business User, and to verify your payment method.Verification Information. Your age (when purchasing age restricted goods) or information about you being the person who is authorized to use a payment method.The information collected will be the information that you choose to share for these purposes, which may include your government ID, your photo, your live image, and Personal Data apparent from the physical payment method (e.g. credit card image).Our legal obligations in respect of our financial and regulatory obligations.
Reduce fraud and enhance security. We will use Personal Data about your identity, including information that you provide, to perform verification Services for Stripe or for the Business Users that you are doing business with and to reduce fraud and enhance security.In some cases you may provide a "selfie" along with an image of your identity document, and we will use technology to compare and calculate whether they match and can be "verified." We will use information from our service providers and our Services to help verify your identity and fraud prevention.Based on consent in processing this personal information.Our legitimate interests in detecting, monitoring and preventing fraud and unauthorized payment transactions.
Radar and Card Verification Services. We use Personal Data of End Customers to detect and prevent fraud for Business Users, including to detect fraudulent payment cards using payment card images and unauthorized log-ins using online activity. In providing such Services, we may provide Business Users that have requested such Services with limited Personal Data about End Customers so that the Business Users can assess the fraud risk associated with an attempted transaction by its End Customer. We may also use payment card images to improve our Business Services.Transaction information. This includes: name, email address, billing and/or shipping address, payment method information (such as credit or debit card number, bank account information or payment card image), merchant and location, purchase amount, date of purchase, and in some cases, some information about what you have purchased, phone number and tax-related ID.This includes web browsing information, usage data, referring URLs, location, cookies data, device data and identifiers.IP address and physical address.Our legitimate interests in detecting, monitoring and preventing fraud and unauthorized payment transactions.
Compliance and Harm Prevention. We share Personal Data as we believe necessary: (i) to comply with applicable law, (ii) to comply with rules imposed by payment method in connection with use of that payment method; (iii) to enforce our contractual rights; (iv) to secure or protect the Services, rights, privacy, safety and property of Stripe, you or others, including against other malicious or fraudulent activity and security incidents; and (v) to respond to valid legal process requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include authorities outside your country of residence.Any Personal Data we process.Our legal obligations where disclosures are necessary to comply with our legal obligations.Our legitimate interest in keeping Stripe secure, preventing a breach of the law, harm or crime, enforcing or defending legal rights, claims, or obligations, facilitating the collection of taxes and prevention of fraud or preventing loss or damage.

·Representatives

·When you are acting on behalf of an existing or potential Business User (e.g. you are a founder of a company, or administering an account for a merchant who is a Business User), we refer to you as a "Representative."

PROCESSING PURPOSECATEGORIES OF PERSONAL DATALEGAL BASES
Reduce fraud and enhance security. We will use Personal Data about your identity, including information that you provide, to perform verification Services for Stripe.Onboarding and verification information that you choose to share for these purposes, which may include your government ID, photo, live image, and Personal Data apparent from the physical payment method (e.g. credit card image).Our legal obligations in respect of our financial and regulatory obligations. We process Personal Data to verify the identity of the Representatives of our Business Users in order to comply with fraud monitoring, prevention and detection obligations, laws associated with the identification and reporting of illegal and illicit activity, such as AML (Anti-Money Laundering) and KYC (Know-Your-Customer) obligations, and financial reporting obligations.
Advertising. We may use and share Representative Personal Data with others so that we may advertise and market our products and Services to you, including through interest-based advertising subject to any consent requirements under applicable law.Contact information including: name, email address, work phone number, and job title.Connection data such as IP address, and web behavior (page visited, length on page, etc.)Based on consent in processing this personal information.
Communications.We may send you email marketing communications about Stripe products and Services, invite you to participate in our events or surveys, or otherwise communicate with you for marketing purposes, provided that we do so in accordance with applicable law, including any consent or opt-out requirements.Contact information such as your name, email address, phone number.Based on consent in processing this personal information.Our legitimate interests in responding to inquiries, sending Service notices, ensuring compliance with applicable laws, preventing fraud, improving our Services and providing customer support.
Tax and Atlas (Incorporation) Services. We may use your Personal Data to file taxes on behalf of your associated Business User. If your Business User uses Atlas, we may use your Personal Data to submit forms to the IRS on your behalf and to file documents with other governmental authorities.Your contact details, such as name, postal address, telephone number, and email address; and financial and personal information about you, such as your ownership interest in the Business User, your date of birth and government identifiers associated with you and your organization (such as your social security number, tax number, or Employer Identification Number). You may also choose to provide bank account information.Our compliance with legal obligations in respect of our financial and regulatory obligations. We process Personal Data to verify the identity of the Representatives of our Business Users in order to comply with fraud monitoring, prevention and detection obligations, laws associated with the identification and reporting of illegal and illicit activity, such as AML (Anti-Money Laundering) and KYC (Know-Your-Customer) obligations, and financial reporting obligations.Our contractual necessity to perform our contractual relationship with you, under applicable data protection laws.

·Visitors

·When you visit a Site without being logged into a Stripe account or otherwise communicate with Stripe, we refer to you as a "Visitor." (e.g. you send Stripe a message asking for more information because you are considering being a user of our products).

PROCESSING PURPOSECATEGORIES OF PERSONAL DATALEGAL BASES
Communications. We use any contact information that you provide to us to respond to any inquiries or requests for information you made; and if you have asked about us or our Services, to send you marketing emails by either asking for your consent or providing you an opt out in any messages we send.Contact information such as your name, email address, phone number.Information you have provided to us, such as the products you are interested in.Based on consent in processing this personal information.Our legitimate interests in responding to inquiries, sending Service notices and providing customer support.
Advertising. When you visit our Sites, we (and our service providers) may use Personal Data collected from you and your device to target advertisements for Stripe Services to you on our Sites and other sites you visit ("interest-based advertising").Information collected from cookies such as your device, browser ID, and pages on our website which you have visited.Based on consent in processing this personal information.Our legitimate interest in undertaking marketing activities to offer you products or Services that may be of interest to you.
Fraud Detection. We use your Personal Data collected across our Services to detect and prevent fraud against Stripe, our Business Users and Financial Partners.Advanced Fraud Signals information collected via cookies. This includes web browsing information, usage data, referring URLs, location, cookies data, device data and identifiers.Our legitimate interests in detecting, monitoring and preventing fraud and unauthorized payment transactions.

·Data Processing Agreement

·What is a Data Processing Agreement (DPA) and how can I get one with Stripe?

·A Data Processing Agreement ("DPA") is a contract between a data controller and a data processor that describes the roles and responsibilities of the parties when personal data is processed. If you are a Business User, please visit our FAQs page here to learn more about our DPA. Please contact us or your account manager if you have any questions.

·Information about Stripe Products

·How do you implement Privacy by Design at Stripe?

·Privacy by design aims at building privacy and data protection up front and into the design specifications and architecture of information and communication systems and technologies to facilitate compliance with privacy and data protection principles. We rely on our internal privacy team and a review process for any new product launch. We are dedicated to proactively embedding privacy throughout the product development lifecycle, from engineering to product management. This helps ensure that people can trust the Stripe products that they enjoy every day.

·Stripe Identity

·End Customers

·If you have been asked to verify your identity or have verified your identity using Stripe Identity, please visit the support web pages here and here to learn more about our privacy practices for Stripe Identity. Alternatively, you can jump to the specific topics linked here:

  • ·Stripe's role in controlling and processing identity data in the US Understanding Stripe Identity Biometric verification Consent to use my identity information Security of my identity data What data is collected Identity data retention How I delete my identity data
·Business User That Requested Verification

·If you are a Business User that is using or intends to use Stripe Identity, please visit the support web page here for additional guidance on what you can tell your users and here and here for additional guidance on privacy considerations for your business.

·Stripe's Card Image Verification

·If you have been asked by your merchant (i.e., a Stripe Business User) to scan your credit card before completing your requested transaction, please visit the support webpage here to learn more about Stripe's Card Image Verification.

·Stripe Connect At a Glance

·Description

·Stripe Connect is a payment software your third party platform provider (Platform) may use to enable you to receive Stripe Services (including payment processing) and/or receive payouts.

·Data Controller/ Data Processor

·Stripe acts as both a data controller and data processor for the Platform. The Stripe entity that acts as data controller/ data processor for data processed in Europe is Stripe Payments Europe Limited ("SPEL").

·Personal Data

·The Personal Data transmitted to Stripe usually involves first name, last name, address, identification number, e-mail address, IP address, telephone number, and other data necessary for payment processing.

·Purpose

·The transmission of the data is aimed at payment processing, ledger management, and fraud prevention. The Business User / Platform will transfer Personal Data to Stripe. The Personal Data exchanged between Stripe and the Business User / Platform may be transmitted to verification agencies, and Business User data may be shared with Platforms. This transmission is intended for the Platform to manage its ledger and for Stripe to conduct identity and risk checks.

·Transfer

·Stripe will pass on Personal Data to affiliates and service providers or sub-processors, if deemed necessary to carry out contractual obligations or for the data to be processed.

·Privacy Policy

·For full details please see the applicable Privacy Policy of Stripe.

·I am a user with a Custom connected account. Does Stripe also collect information about my Custom connected account from a third party?

·If you are a user with a Custom connected account, Stripe may collect additional information about your account to enable fraud detection and fulfill financial compliance requirements. These requirements for additional information come from our regulators or Financial Partners and are intended to prevent abuse of the financial system. Examples of missing data fields include your address, phone number, social security number, date of birth, employer identification number, or website URL. Stripe may leverage data we already have from one of your Stripe accounts or Stripe may fill in some of this information by receiving data from a third party. You may view the information that we are associating with your account and update or correct that information by contacting the platform or business that created your Stripe payment account. Please see Stripe's Privacy Policy for additional information.

·What responsibilities do Connect platforms with custom accounts have to allow their users to update or correct information associated with their accounts?

·You, the Platform, are responsible for all interactions with your Custom accounts and for collecting all of the information needed to verify the Custom account-holders. Since Custom account holders cannot log into Stripe, it is up to you to build the user dashboard and communication channels. You are responsible for actioning any request by a user to update or correct their Stripe Custom account information.

·I am a user with a Custom connected account. Will data collected from a third party be visible to my customers?

·Card networks and issuers use statement descriptors to identify payments on a cardholder's bank statement. Statement descriptors usually include information about the payment, such as the name and phone number of the seller. However, the exact information displayed is ultimately up to a cardholder's bank. If Stripe updates your account's business address, phone number, or email address, these fields may be displayed on the statement descriptor within the cardholder's bank statement. However, the exact information displayed is ultimately up to the card network or the cardholder's bank. If any information is incorrect, please reach out to the platform through which you receive charges to ensure you have provided them with the most accurate information about you and your business.

·Promotional Emails Feature

·For End Customers and prospective End Customers of our Business Users
·What is the Promotional Emails feature?

·Promotional Emails is a feature that gives Business Users who use "Stripe Checkout" Services a tool to enable sending email promotional content to their customers and prospective customers. When you visit a Business User's checkout page (that is powered by Stripe Checkout Services), the Promotional Email feature will enable Stripe to collect information about your preferences to receive promotional emails from that merchant.

·Promotional email preferences are collected whether or not you complete the purchase or are just a prospective End Customer. "Prospective End Customer" means you visited a Business User's site and expressed an intent to make a purchase by starting a purchase on the Business User's checkout page, but did not complete that purchase during that session. To be a "prospective End Customer" for the promotional email feature, you also need to have started to input your contact information into the checkout form, and then not delete that information prior to the end of the session.

·If you, prospective End Customer, indicate permission to receive news and personalized offers by virtue of the opt-in/opt-out checkbox on your Business User's checkout form, the following Personal Data is provided to your Business User so that your Business User can contact you to remind you of the items you left in the checkout or to provide you news and personalized offers:

  • ·Email (if provided by you).
  • ·Items in your cart with that merchant (if any).

·"Personalized offers" means promotional or marketing materials tailored to you, such as coupons or advertisements based on the items in your cart or (in some cases) your prior purchases from that Business User. Even if you opt-out of personalized offers by a Business User, if you do business with that Business User, they may still need to contact you in order to enable a purchase (e.g., for delivery or billing purposes) or in connection with customer support. Please see your Business User's privacy policy for more information.

·What is Stripe's role (Data Processor/Controller) in the processing of my Personal Data?

·For the Promotional Emails feature, Stripe acts as a data processor or service provider, meaning that Stripe is acting at the direction of the Business User that has implemented this Stripe provided feature. The Stripe entity that acts as a data processor for Personal Data is:

  • ·Stripe, LLC in the United States.
  • ·Stripe Payments Europe Limited outside of the United States, including Europe
·What Personal Data Is Stripe Collecting?

·Stripe's Privacy Policy describes in more detail the Personal Data that Stripe collects in connection with payment transactions.

·What Personal Data is Shared by Stripe with the Business Users I use?

·Whenever you complete a transaction on a Business User's website that uses Stripe services, as a service provider to that Business User, Stripe will share your contact information with that Business User. Business Users use the information that Stripe provides in accordance with its own privacy policy, including in connection with your purchase.

·With the Promotional Emails feature:
  • ·If you complete a purchase with a Business User, in addition to the transaction-related information identified in our Privacy Policy (e.g., your contact and billing information and the details of your transaction), Stripe will also share with your Business User your personalized offers and news preferences as determined by the opt-in/opt-out checkbox from your checkout form.
  • ·If you are a prospective End Customer (you start a purchase with your Business User on their checkout form but do not complete that purchase), the Personal Data that we share with your Business User depends on the following:
  • ·If you have not inputted any Personal Data into your Business User's checkout form, then we will not share any Personal Data with that Business User.
  • ·If you have inputted Personal Data into your Business User's checkout form:
  • ·If the checkbox for receiving news and personalized offers is not enabled when you leave your Business User's checkout session, we will not share any of that Personal Data.
  • ·If the checkbox for receiving news and personalized offers is enabled when you leave your Business User's checkout session, we will share the following information with that Business User:
  • ·Email (if provided by you).
  • ·Items in your cart with that merchant (if any).

·End Customers and prospective End customers should always review the privacy policy or notice of the Business Users they visit and do business with for information about the Business User's data collection practices and purposes outside of this Stripe feature.

·Does Stripe share my Personal Data with other Business Users?

·No. Stripe does not share Personal Data collected in connection with purchases (or attempted purchases) from one Business User's checkout with another Business User. Please see our Privacy Policy to learn more about our practices.

·How do I stop promotional emails from a merchant?

·Any offers or promotional emails that you receive as a result of a Business User's use of the Promotional Emails feature are sent by Business Users (or others identified in the message), and not by Stripe. I If you do not find value in receiving these emails, please contact the Business User you are receiving the messages from. Stripe requires that Business Users that choose to implement the Promotional Email feature also provide the option to unsubscribe or opt-out of receiving further promotional messages. It would be a breach of Stripe's terms of service for a Business User to not promptly comply with opt-out requests.

·How Does the Data Collection and Transfer Work?

·The Promotional Email feature does not use cookies or track you across Business Users. Information collected from the Business User's checkout page is transferred only to the Business User via API calls or webhooks. Webhooks are a way for Stripe to send the information to the Business User automatically upon their request. Your information provided at checkout is encrypted in transit using HTTPS and TLS. See Security at Stripe for more information.

·How do I stop the sale of my Personal Data in connection with this feature?

·Stripe does not sell your Personal Data. See our Privacy Policy for more information. The Promotional Emails feature is not the sale of Personal Data. Rather, Stripe acts as a processor (or service provider) to Business Users for the Promotional Email feature. Please contact your Business User to learn about their Personal Data practices and how you can exercise rights to stop the sale or processing of Personal Data provided under applicable law and/or their privacy policy.

·Stripe requires that Business Users that choose to implement the Promotional Email feature also provide the option to unsubscribe or opt-out of receiving further promotional messages. It would be a breach of Stripe's terms of service for a Business User to not promptly comply with opt-out requests.

·For Business Users

·How to Use this Service as a Business User

·If you are a business that is using or intends to use Stripe's Promotional Emails feature, please visit the support webpage for tips and guidance on information to share with your End Customers and prospective End Customers regarding privacy considerations in connection with the Promotional Emails feature for your business.

·Stripe Delegated Authentication

·Cardholders

·You may be given the option to enable on-device biometric verification and provide your consent for Stripe to store your payment method details for future transactions that use the same card. Please visit our support site to learn more about our privacy practices for Stripe Delegated Authentication. Alternatively, you can jump to a specific topic here:

  • ·Why does the cardholder see Stripe when asked to authenticate a payment?
  • ·What is Stripe Delegated Authentication?
  • ·How is Personal Data used in Stripe Delegated Authentication?
  • ·How can cardholders provide and withdraw their consent for the storage of their payment method details?

·We offer you the opportunity to store your payment methods with us so that you can conveniently use it across certain merchants who are our Business Users - we call this "Link" (formerly known as "Remember Me"). When you choose to use Link, you agree to let us store your payment method so that you can more readily make purchases through Link with Business Users of our payment processing Business Services (e.g., name, card number, cvc, and expiration date). We will also collect other Transaction Data, including billing address, shipping address, email and phone number. Your payment method data is secured using PCI-DSS standards.

·Should you not have used Link and receive an SMS in error due to an inaccurate number being inserted at the authentication flow stage you can opt out here and your Personal Data will be deleted.

·When you see "Sold through Link," Stripe acts as the merchant of record on behalf of the Business User.

·Business Users can offer and sell their digital products using Stripe Managed Payments under the "Sold through Link" brand. If you place an order for a digital product where you see "Sold through Link" - or if your card or bank statement shows "Link.com*[Business User name]" (or similar) - your purchase is being handled by Stripe through its Stripe Managed Payments product on behalf of the Business User.

·Stripe also provides additional support and order management services through Link to help you manage your orders that were Sold through Link. They include:

  • ·A dashboard where you can see your order history, track, and manage your purchases
  • ·Tools to update payment methods or manage subscriptions
  • ·Support for renewals, refunds, or customer service

·For subscriptions that are Sold through Link, you must have a Link account to ensure we can verify your identity, manage ongoing payments, and provide continuous support. We provide these features in addition to the core Link experience described in the Link Privacy Policy and subject to these terms.

·What Information is Shared with the Business User?

·When you complete a "Sold through Link" order, Stripe shares your order information with the Business User so they can fulfill your order and manage their relationship with you. This may include your contact information, payment information, tax identification number, billing and shipping address, and order details.

·The Business User may retain this information and use it according to their own privacy policy. For more details on how the Business User may handle your data, please refer to the Business User's privacy policy.

·Deleting Your Information

·You can request that your information be deleted from Link in connection with your "Sold through Link" orders by requesting the deletion of your Link account. To request deletion, please follow the instructions on this page.

·Deleting your Link account will also result in:

  • ·any active subscriptions Sold through Link being canceled; and
  • ·all information provided for a Sold through Link order will be deleted.

·Please note that the Business User may have stored the information provided during checkout (such as your contact and billing details) independently of Link in accordance with their own privacy policy. We recommend reaching out to them directly if you would like them to delete your information as well.

·What information is shared with BNPL or crypto wallet services?

·When using Link you can choose to pay for purchases using Buy Now, Pay Later (BNPL) services or crypto wallets.

·BNPL

·With respect to BNPL, in order to facilitate the transaction we send and receive data from the BNPL provider you choose (i.e., Klarna). During the checkout process, we will notify you of what data will be shared and whom it will be shared with. The Personal Data we share may include your name, address, email, IP address, phone number, date of birth, social security number (we will only collect and share this data if required by your choice of financing), and any other relevant Transaction Data. Stripe will also receive and retain similar information from your choice of BNPL provider for any discrepancies.

·Who's terms or privacy policy applies?

·When you select a BNPL provider, you will also be provided with their terms of use and privacy policy. Any data you provide to Link is governed by our Terms of Service and Privacy Policy. Any data we share at your direction, with a BNPL provider of your choice, will be subject to their terms of use and privacy policy.

·What BNPL providers are available?

·While merchants can enable Affirm or Klarna as a payment method, Link users can connect their Link and Klarna accounts. As we add more BNPL providers, we will continue to update this page with any relevant information.

·Crypto Wallets

·When you use Link to pay with a supported crypto wallet service, such as Phantom, we will similarly need to share certain Personal Data with the crypto wallet provider. This may include your name, address, date of birth, government-issued ID, and other KYC-related information. At Phantom's direction, this KYC data may be forwarded to their approved third-party partners. Phantom will only forward your data to these partners after obtaining your explicit consent, ensuring you are informed and agree to this onward sharing.

·Who's terms or privacy policy applies?

·As with BNPL services, any data we share at your direction with a crypto wallet provider is subject to that provider's terms of use and privacy policy. Data you provide to Link is governed by our Terms of Service and Privacy Policy, while any data shared onward at Phantom's direction will be subject to their terms and privacy policy.

·What crypto wallet providers are available?

·Currently, Link supports the Phantom crypto wallet. As we add more supported crypto wallet providers, we will update this page with the relevant information.

·Stripe Capital Direct and Capital for Platforms

·Stripe Capital provides Business Users with access to fast, flexible funding so businesses can manage cash flows and invest in growth. Through Stripe Capital for Platforms, Platforms can also enable financing offers to be extended to their users, including their Connected Account. Depending on your business's corporate structure and jurisdiction, you may be eligible for different types of financing.

·In partnership with Stripe Capital, financing is provided by one of our financial partners depending on where your business is located:

  • ·US: Celtic Bank or YouLend Ltd.
  • ·UK: YouLend Ltd.
  • ·France: YouLend SAS and its affiliates.
  • ·Germany: YouLend GmbH and its affiliates.
  • ·Australia: Fundbox Australia Pty Ltd. and its affiliates. Canada: Fundbox, Inc and its affiliates
·What information does Stripe process for Stripe Capital and Capital for Platforms?

·We use existing data linked to your Stripe account to evaluate your business's eligibility to receive an offer for Stripe Capital. In Capital for Platforms, we follow the same approach, except that we will review existing data linked to a Connected Account's Stripe Account to assess their eligibility.

·The following information may be considered prior to the offer of financing in order to determine eligibility, including: Payment processing volume Refund/disputes rate Duration of relationship with Stripe Bank account balances Transaction history

·If your business is based in the US, you may also be asked to link additional data sources, such as business bank accounts or business credit information, in order to receive financing through Stripe Capital. Additionally, the following information may also be processed prior to the offer of financing for your US business: Business credit history

  • ·Information about you and your Representatives, which may include name, address, credit history, banking relationships, last four digits of a Social Security Number, and financial history
  • ·If you're a Connected Account, off-Stripe transaction history that we receive from your Platform, in accordance with your agreement with them.

·In the US, Platforms may elect to extend offers for financing to their customers, regardless of whether they process payments through Stripe. In accordance with the Platform's terms with its customers, the Platform may share off-Stripe transaction history and other business information with Stripe in order to assess the business' eligibility for financing. If applicable, the Platform may also share contact information to enable Stripe to notify the business about their financing offer. Any information shared by the Platform will be protected in accordance with Stripe's Privacy Policy. If the business decides to apply for financing, it will be invited to create a Stripe account and its information will be shared with our financial partners as described below. Learn more.

·Where Stripe is satisfied that a business meets particular criteria established by Stripe and our financial partners (as applicable), we, or the Platform, will send the business an email and/or a dashboard notification notifying them of their business's eligibility for potential financing from a financial partner and invite them to apply.

·When a business initiates the application process, Stripe pre-populates the application form with information from the business's Stripe account and requires the business to confirm that it is correct. When you submit an application, your information will be shared with our financial partner in your region.

·This information may include: Company name Business display name Annual revenue Company number Company phone number and address Business URL (or Product Description) MCC (or Industry) Business address Business phone number Business email

  • ·If applicable, the names and email addresses for any individuals who own 25% or more of the business
  • ·The names of each company director, executive or senior manager who has significant management responsibility for the business

·A Representative who has authority to sign a loan agreement on behalf of the company (such as a director, board member, an owner of 25% or more of the company, or otherwise someone with significant management control) may be asked to provide the following personal information as part of the application process and that information will be shared with our financial partner in your region: Name

  • ·If Owner, Percentage Ownership Threshold
  • ·Home address, and provision of a document, such as a household bill, which verifies their home address
  • ·Government ID number, and provision of an ID document which verifies the number provided Tax identification number DOB Email Phone Number

·We will process your Personal Data in accordance with our legitimate business interests. Analysis of your Personal Data helps us to manage our business in accordance with our legitimate interests. It allows us to:

  • ·Verify the identity of our Business Users in order to comply with fraud monitoring, prevention and detection obligations, applicable laws associated with the identification and reporting of illegal and illicit activity, such as AML (Anti-Money Laundering) and KYC (Know-Your-Customer) obligations, and financial reporting obligations.
  • ·Assess the level of financial risk to us, financial partners and to Business Users involved in offering Business Users financing.
  • ·Enhance our machine learning models to allow us to better tailor financing to, and decrease the risk to, you and other Business Users.
  • ·Assess your eligibility for, and offer you, Stripe Capital and Capital for Platforms Services.

·We will also process your data where it is necessary for a financing agreement that you have entered into or because you have submitted an application to receive funding and to determine eligibility to enter into a financing agreement with us or with our financial partners.

·We, or the Platform, may send you email marketing communications about Stripe Capital offers, provided we, or the Platform, do so in accordance with applicable law, including any consent requirements.

·Who does Stripe share information with?

·Stripe may share your and your Representative's Personal Data with its financial partners in order to determine your eligibility for financing you have requested, or to enable you to apply for financing or as necessary complete and/or service transactions with financial partners who in some cases may purchase the right to receive repayment on your financing. Stripe may also share and obtain information about you, your business and your Representatives from Stripe's service providers and other third parties, including credit reporting agencies, banking partners and information bureaus. If you're a Connected Account, we may also share and receive information about you with your Platform, in accordance with your agreement with them.

·What is Stripe's role?

·The Stripe entity responsible for your Personal Data will depend on the location of your business. Please see our Privacy Center article here for more information on the data controller that is responsible for Personal Data collected and processed in relation to Stripe Capital. Canada

·This section contains information about Stripe Capital and Stripe Capital for Platforms for Business Users located in Canada (including Quebec).

·When you apply for financing through Stripe Capital or Stripe Capital for Platforms, Stripe transfers your Personal Data to our financial partner, Fundbox Inc, which processes and stores data in the United States. This transfer is necessary to enable Fundbox Inc to process your application, and to provide financing to your business.

·In addition to the information listed above, Stripe processes and shares your Business Number with Fundbox Inc as part of your application.

·How do I opt-out of receiving Capital offers?

·Business Users have the option to unsubscribe or opt-out of receiving Capital offers via the link included in Stripe Capital emails. Business Users may also opt-out of dashboard notifications via the settings page of the Stripe Dashboard. If you're a Connected Account using Capital for Platforms, please contact your platform owner to unsubscribe or opt-out of receiving Capital offers. If you have any questions, please contact us.

·Are there instances when Stripe receives non-Stripe transaction history?

·Yes. For example, Stripe enables the Business User to import non-Stripe data through the Stripe Dashboard to consolidate their revenue data in one place. Learn more. Separately, Stripe may also obtain your account transactions from your financial account with your consent. Learn more.

·Refunds to End Customer Bank Account

·End Customers

·If you have been asked to provide your bank account and other information to process a refund on behalf of your merchant (i.e., our Business User), please visit the webpage here to learn more about our privacy practices for End Customer bank account refunds.

·Business User that uses Stripe to Process Refunds

·If you are a Business User that is using or intends to use Stripe to process refunds, please visit the webpage here for additional guidance on privacy considerations for your business.

·Stripe Frontier

·What is Stripe Frontier?

·Frontier is an advance market commitment (AMC) that aims to accelerate the development of carbon removal technologies by guaranteeing future demand for them. It facilitates purchases from high-potential carbon removal companies on behalf of buyers. Learn more at https://frontierclimate.com/.

·What information does Stripe Frontier collect?

·We will collect any information you choose to provide to us, for example, through support tickets, emails or social media. When you respond to Stripe emails or surveys, we collect your email address, name and any other information you choose to include in the body of your email or responses. If you contact us by phone, we will collect the phone number you use to call Stripe, as well as other information you may provide during the call. We will also collect your engagement data such as your registration for, attendance of, or viewing of Stripe events and other interaction with Stripe personnel. See our privacy policy for more information.

·Is my data relating to Stripe Frontier transferred?

·We are a global business. Personal Data may be stored and processed in any country where we do business. We may transfer your Personal Data to countries other than your own country, including to the United States. These countries may have data protection rules that are different from your country. When transferring data across borders, we take measures to comply with applicable data protection laws related to such transfer. In certain situations, we may be required to disclose Personal Data in response to lawful requests from Officials (such as law enforcement or security authorities). See our privacy policy for more information.

·What are my rights and choices with respect to the information collected for Stripe Frontier?

·You may have choices regarding our collection, use and disclosure of your Personal Data. If you no longer want to receive marketing-related emails from us, you may opt-out via the unsubscribe link included in such emails or as described here. We will try to comply with your request(s) as soon as reasonably practicable. Depending on your location and subject to applicable law, you may have the following rights described here with regard to the Personal Data we control about you.

·How do I exercise my rights as to Stripe Frontier?

·EEA and UK . To exercise your rights, you may contact our DPO. If you are a resident of the EEA or we have identified Stripe Payments Europe Limited as your data controller, and believe we process your information within the scope of the General Data Protection Regulation (GDPR), you may direct your questions or complaints to the Irish Data Protection Commission. If you are a resident of the UK, you may direct your questions or concerns to the UK Information Commissioner's Office.

·California . If you are a consumer located in California, please review the California Consumer Privacy Act ("CCPA") section of our Privacy Policy.

·See our privacy policy for additional jurisdiction-specific provisions.

·Any questions about Stripe Frontier and the processing of your data?

·If you have any questions or complaints, please contact us.

·Data Protection Officer

·Does Stripe have a Data Protection Officer (DPO)?

·Yes, Stripe has appointed a Data Protection Officer ("DPO"), who can and they can be reached via email.

·Quebec Act Respecting the Protection of Personal Information

·Who is Stripe's person in charge of personal information under the Quebec Act Respecting the Protection of Personal Information in the Private Sector, and how do I contact them?

·Stripe's Chief Privacy Officer is the person in charge of personal information. You may contact them via email.

·We are committed to protecting personal information and have established policies and procedures that govern our treatment of personal information. These policies and procedures include, among other things, the following:

  • ·policies and procedures to protect personal information in our custody and control from unauthorized access, use or disclosure.
  • ·processes to respond to data subject requests and complaints in a timely and effective manner.
  • ·a framework for the retention and destruction of personal information to ensure compliance with legal obligations, and to securely destroy personal information once no longer required.
  • ·a privacy framework that defines the roles and responsibilities for our employees with respect to the treatment of personal information.
  • ·providing our employees with regular privacy training and awareness.

·International Data Transfers

·The detail below is provided for informational purposes. It is not intended to provide legal advice. Stripe urges Business Users to consult with legal counsel to familiarize themselves with the requirements that govern their specific situations.

·How is Stripe dealing with its international data transfers?

·As a global business, Personal Data may be transferred to, and processed, in any country where we do business, where our service providers do business or if you use an international payment method or financial partner service, the countries in which that payment method or financial partner operates.

·We may transfer your Personal Data to countries other than your own country, including to the United States. Stripe relies on a number of data transfer mechanisms to legalize the transfer of Personal Data around the globe.

·Stripe continues to have appropriate safeguards and compliance measures to ensure an adequate level of protection of Personal Data transferred outside the UK, EEA and Switzerland. Stripe's measures may include:

  • ·Transferring Personal Data from the originating to a country or recipient that has been deemed to have an adequate level of data protection by relevant privacy authorities, including the European Commission.
  • ·The EU-U.S. Data Privacy Framework ("EU-U.S. DPF"), which allows personal data to flow freely between the EEA and certified organizations in the U.S. The European Commission has adopted an adequacy decision confirming that personal data can be transferred from the European Economic Area ("EEA") to certified U.S. organizations. The UK Government similarly confirmed that organizations can rely on the UK Extension to the EU-U.S. DPF ("UK Extension") to transfer data from the UK to certified U.S. organizations. The Swiss Federal Council has confirmed that organizations can rely on the Swiss-US Data Privacy Framework ("Swiss-U.S. DPF") to transfer data from Switzerland to certified US companies and it has adopted an adequacy decision for the U.S. in this respect. Stripe's parent entity, Stripe, LLC is certified under the EU-U.S DPF, Swiss-U.S. DPF and the UK Extension. Stripe relies on the Data Privacy Framework to transfer personal data from respectively the EEA, the UK and Switzerland to the US. To learn more about the DPF program, please visit https://www.dataprivacyframework.gov/, and to view our certification on the DPF list, please see here.
  • ·The Standard Contractual Clauses ("SCCs") approved by the European Commission. SCCs are a transfer mechanism (in the form of a legal contract) used by Stripe to provide a legal mechanism to transfer EU personal data outside of the EEA/UK. These are required under EU data protection law (known as the GDPR) and are incorporated into our agreements.
  • ·The UK International Data Transfer Addendum ("UK Addendum") issued by the UK's Information Commissioner's Office to provide a legal mechanism to transfer personal data from the UK. This mechanism is required under UK data protection law (known as UK GDPR) and is incorporated into our agreements.
  • ·The amended EU SCCs as approved by the Thai privacy regulator for transfers of personal data outside of Thailand under the Thai Personal Data Protection Act B.E. 2562.
  • ·Other alternative data transfer mechanisms approved by relevant privacy authorities to enable the transfer of Personal Data to a third country.

·Stripe respects the privacy of everyone that engages with our products and Services, and we are committed to being transparent about our privacy processes and policies. To learn more about our commitment to privacy and data security, please see our Privacy Policy, the rest of the Stripe Privacy Center, and the Stripe Security Center.

·We also want to highlight some of our supplementary measures to protect our Business Users' data from unauthorized access.

·Stripe employs security controls and maintains and enforces a security program that addresses the management of security. We also perform risk assessments and implement and maintain controls for risk identification, analysis, monitoring, reporting, and corrective action. Stripe maintains and enforces an asset management program that appropriately classifies and controls hardware and software assets throughout their life cycle. In addition, Stripe employees, agents, and contractors acknowledge their data security and privacy responsibilities under Stripe's policies.

·Stripe applies technical and organizational measures that include the following:

  • ·Virtual access control to prevent data processing systems from being used by unauthorized persons.
  • ·Data access control to ensure that persons entitled to use a data processing system gain access only to such Personal Data in accordance with their access rights, and that Personal Data cannot be read, copied, modified or deleted without authorization.
  • ·Disclosure control to ensure that Personal Data cannot be read, copied, modified or deleted without authorization during electronic transmission, transport or storage on storage media (manual or electronic), and that it can be verified to which companies or other legal entities Personal Data are disclosed.
  • ·Entry control to audit whether data have been entered, changed or removed (deleted), and by whom, from data processing systems.
  • ·Stripe relies on third party service providers to host its production infrastructure. Those third parties apply physical access control to prevent unauthorized persons from gaining access to the data processing systems available at premises and facilities (including databases, application servers, and related hardware), where Personal Data are processed.
  • ·Availability control to ensure that Personal Data are protected against accidental destruction or loss (physical/logical).
  • ·Separation control to ensure that Personal Data collected for different purposes can be processed separately.

·By default, Stripe encrypts data at rest and data in transit. We further protect your data with tools like audit logs, access management policies and certifications as described on our Payments page in the section "Security and compliance at the core". Security controls implemented at Stripe include TLS 1.2 configuration of endpoints for data in transit, TLS and/or SSL encryption for HTTPS and regular testing of infrastructure components. Two-step authentication is available for an extra layer of security at Dashboard login.

·We get requests for access to data from law enforcement, and we review each request with the goal of responding with the minimum amount of required information in response to legitimate, legally mandated requests.

·If you have any questions, please contact us.

·Is Stripe certified under the EU-U.S Data Privacy Framework?

·Stripe has certified its participation in the EU-U.S. Data Privacy Framework ("EU-U.S. DPF"), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework. Stripe relies on the DPF to enable international transfers. In case the DPF is invalidated or Stripe is otherwise prevented from relying on the DPF, we incorporate multiple transfer mechanisms to ensure that data transfers can continue. If more than one data transfer mechanism applies, the DPF takes precedence. You can learn more about our certification and read the Stripe Data Privacy Framework Policy at https://stripe.com/legal/data-privacy-framework.

·How does Stripe's certification under the EU-U.S. DPF impact my organization?

·The EU-U.S. DPF is a legal framework that allows organizations to transfer EEA Personal Data to certified organizations in the U.S. Stripe's Data Transfers Addendum sets out the data transfer mechanisms that Stripe may rely on to carry out international transfers of personal data, including the EU-U.S. DPF. You can learn more about our certification and read the Stripe Data Privacy Framework Policy at https://stripe.com/legal/data-privacy-framework. If you are a Business User and would like to transfer data to us under the DPF, please contact us or your account manager if you have any questions.

·How do the SCCs and UK Addendum impact my organization?

·SCCs are legal contracts entered into between parties that are transferring EEA Personal Data outside of the EEA. Stripe may rely on the SCCs for transfers of EEA data in our Services. We have updated our Data Transfer Addendum and agreements to incorporate the SCCs (where applicable).

·How to get a copy of the SCCs or UK Addendum?

·You can review our Data Transfers Addendum which includes the latest data transfer mechanisms, including the SCCs, the UK addendum and the Swiss addendum here.

·What is CBPR and PRP and is Stripe certified?

·Cross-Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP) schemes are frameworks designed to facilitate data privacy harmonization across international boundaries, historically within the Asia-Pacific Economic Cooperation (APEC) region but now as a global scheme. CBPR is aimed at organizations handling personal data as a data controller, ensuring compliance with robust privacy standards and enabling secure cross-border data flow. It requires certified organizations to develop compliant privacy policies and practices and undergo independent certification. PRP, on the other hand, is tailored for data processors, establishing standards for how processors manage and secure data on behalf of data controllers. It provides a mechanism for demonstrating compliance with global privacy requirements, promoting trust and accountability.

·Stripe's privacy practices comply with CBPR and PRP systems as evidenced by the CBPR and PRP certifications Stripe has obtained. To view the status of our certifications, please click here (CBPR) and here (PRP).

·Where CBPR and/or PRP are recognized as a valid transfer mechanism under applicable law, Stripe will transfer Personal Data in accordance with the CBPR and PRP certifications Stripe has obtained.

·Why is Stripe storing authentication and authorization data globally?

·We have integrated a robust, multi-region infrastructure dedicated to optimizing authentication, authorization, and identity management. This infrastructure spans multiple geographic regions, specifically including our data centers located in the United States and India. By adopting this global approach, we have significantly enhanced the speed and reliability of our Services, allowing users to benefit from faster and more consistent access to their data, regardless of their location. This advancement results in a superior and seamless service experience with reduced latency, which is essential for maintaining high standards of user satisfaction.

·Our focus on global data storage centers around particular categories of Personal Data, strictly limited to aspects of user authentication and security. The specific types of data stored globally include Representative identifying information such as name, location, email address, phone number, date of birth, IP address, and device ID. These elements are integral to various facets of our operations, including login credentials and settings for multi-factor authentication, as well as device information and security challenges relevant to account security. Additionally, session management data, user roles and permissions, team invitations and management, and Single Sign-On (SSO) configurations fall under this umbrella of globally stored data.

·Importantly, this global storage strategy does not extend to any transactional information or other data related to End Customers.

·Your Rights and Choices

·How do I exercise my data protection rights?

·Depending on your location and subject to applicable law, you may have the following rights: Right to confirmation of processing Right to access Right of rectification/correction Right to data portability Right to restrict processing Right to object to processing

  • ·Right to withdraw consent (where it is relied upon) Right to erasure/deletion
  • ·Right to opt-out of processing for targeted advertising
  • ·Right to opt-out from profiling for certain decisions with legal or similarly significant effect
  • ·Right to opt-out of receiving electronic communications from us
  • ·Right to non-discrimination for exercising your rights
  • ·Right to opt-out from a sale of personal information
  • ·Right to opt-out of "sharing" under California privacy law (learn more)
  • ·Right to confirm the third parties or categories of third parties to which personal data has been disclosed
  • ·Right to limit the use or sharing of sensitive personal information (learn more)
  • ·Right to appeal Stripe's response to your data subject request Right to complain under UK GDPR

·Please read this section to find out more about specific rights. To submit a request to exercise any of the rights described above, please reach out to us by email, or via our form or by physical addresses listed in Contact Us.

·You have the right to complain to your local data protection authority if you are unhappy with our privacy practices.

·Which privacy rights are available in my state?

·Laws in the various U.S. states may provide different privacy rights. For more information on which rights may be available under the laws in your state, consult the following table:

Right to confirmation of processingCalifornia, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia
Right to accessCalifornia, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia
Right to correctionCalifornia, Colorado, Connecticut, Delaware, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Virginia
Right to data portabilityCalifornia, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia
Right to deletionCalifornia, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia
Right to opt-out of processing for targeted advertisingColorado, Connecticut, Delaware, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia
Right to opt-out from a sale of personal dataCalifornia, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia
Right to opt-out from profiling for certain decisions with legal or similarly significant effectsColorado, Connecticut, Delaware, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Virginia
Right to non-discrimination for exercising your rightsCalifornia, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia
Right to appeal the refusal of a request to exercise your rightsColorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Virginia
Right to confirm the third parties or categories of third parties to which personal data has been disclosedDelaware, Maryland, Minnesota, Oregon
Right to limit the use and disclosure of sensitive personal dataCalifornia
Right to opt-out from sharing for cross-context behavioral advertisingCalifornia
·How do I access my data?

·Depending on your location and subject to applicable law, you may have the right to request confirmation of whether Stripe processes Personal Data relating to you, and if so, to request a copy of that Personal Data.

·If you are a Business User, End User, or otherwise have a direct relationship with Stripe (e.g. if you are a merchant, Link user, or if you have verified your identity through Stripe Identity solely for Stripe's own business purposes), you can use our self‐service tool that allows direct users to access their personal data directly: https://privacy.stripe.com/access.

·If you are a Business User or Representative, you may also login in to the Stripe Dashboard to view personal information shared with Stripe.

·If you are the End Customer of a Business User that uses Stripe Services, the Business User would be the correct party to respond to a data subject access request related to your transactional information.

·If you do not wish to use the self-service tool, you may also submit your access request by email, or through our form. Please note that we may need to verify your identity and your relationship with us before we can proceed with your request.

·How do I unsubscribe from marketing emails?

·If you are a Business User or Visitor, you may unsubscribe from Stripe marketing emails here. If you have any questions about how to opt-out of Stripe marketing communications, please contact us here.

·If you are a Link user, you may opt-out from marketing-related emails by using the unsubscribe link in any marketing email you receive, or by managing your subscription preferences in the Link website. To manage your preferences log into your Link account, then navigate to your account settings. Turn "Marketing emails - Receive updates and deals from Link and its partners" on or off. Your email address will be opted out of email marketing communications as soon as possible.

·How do I exercise my right to complain under UK data protection laws?

·Individuals in the UK have a right to complain to a data controller if they consider that the data controller has infringed data protection laws.

·If you are a Business User, End User, or otherwise have a direct relationship with Stripe (e.g. if you are a merchant, Link user, or if you have verified your identity through Stripe Identity solely for Stripe's own business purposes), you can exercise your right to complain to Stripe by contacting us by email, or through our form.

·Please note that if you are the End Customer of a Business User that uses Stripe Services and your complaint relates to processing where Stripe acts as a data processor, the Business User would be the correct party to respond to a complaint under UK GDPR and Data Protection Act 2018.

·When does Stripe continue to process data after it has received a deletion request or objection to the processing?

·In certain circumstances, Stripe may be required by law to retain and process your Personal Data even after a deletion request or objection to the processing. For instance, Stripe is required to retain certain Personal Data it receives from its Business Users to satisfy legal obligations under Know Your Customer (KYC) and Anti-Money Laundering (AML) laws.

·Stripe may also rely on compelling legitimate grounds to continue processing your Personal Data. Stripe may act on such grounds, for instance, when it takes steps to prevent fraud and financial crimes. When Personal Data is necessary to enable or maintain the integrity of Stripe's fraud detection and financial models, Stripe may not be able to honor requests to delete or stop processing that data. If Stripe honored such requests, fraudsters might take advantage of its willingness to do so to seek deletion of data related to their past fraudulent activities. Without such data, Stripe would be less able to recognize similar activities in the future.

·What data may be shared or made available to enable me to see Stripe ads on other sites?

·To enable Visitors of Stripe.com to see Stripe ads on other sites, we use advertising APIs and server-side pixels. The data that Stripe shares or makes available to enable this advertising include identifiers, internet or other similar network activity, IP addresses, and device characteristics. Any potentially personally identifying details are hashed through cryptographic SHA-256 hashing. Click the below links to learn more about the data that may be shared or made available to enable this feature. You can disable the toggle in the "advertising" section of our cookie settings page at any time.

Third party serviceData that we may share or make availableService descriptionLearn more
MetaSign-up information and interactions with Stripe and our products, website activity, IP address, device and browser characteristics, timestamps of visits, cryptographically hashed (SHA-256) email, first name, last name.The Meta Conversions API is a Meta business tool that creates a direct connection between yourmarketing data and the Meta technologies that optimize ad performance. This helps you touse your own marketing data to optimize ad targeting, decrease cost per action and see amore complete picture of campaign outcomes while respecting people's privacy.https://www.facebook.com/business/tools/facebook-conversions-api https://developers.facebook.com/docs/marketing-api/conversions-api/
LinkedinSign-up information and interactions with Stripe and our products, website activity, IP address, device and browser characteristics, timestamps of visits, cryptographically hashed (SHA-256) email, first name,) last name.With the Linkedin Conversions API, you can connect both your online and offline data to LinkedIn so you can see how your campaigns influenced actions taken on your website, sales completed over the phone, or leads collected in-person at an event.https://www.linkedin.com/help/lms/answer/a1655394
RedditSign-up information and interactions with Stripe and our products, website activity, IP address, device and browser characteristics, timestamps of visits, cryptographically hashed (SHA-256) email, first name, last name.The Reddit Conversions API is a server-to-server solution that shares your conversion data directly to Reddit's platform without needing website code. By building a sustainable server-side connection, this integration is more resilient to signal loss and will help deliver stronger campaign performance via improved measurement, targeting, and optimization.https://business.reddithelp.com/helpcenter/s/article/Conversions-API
XSign-up information and interactions with Stripe and our products, website activity, IP address, device and browser characteristics, timestamps of visits, cryptographically hashed (SHA-256) email, first name, last name.The X Conversions API is a server-to-server solution that shares your conversion data directly to X's platform. By building a sustainable server-side connection, this integration is more resilient to signal loss and will help deliver stronger campaign performance via improved measurement, targeting, and optimization.https://developer.twitter.com/en/docs/twitter-ads-api/measurement/web-conversions/conversion-api
LineSign-up information and interactions with Stripe and our products, website activity, IP address, device and browser characteristics, timestamps of visits, cryptographically hashed (SHA-256) email, first name, last name.Line Conversions API is a server-to-server solution that shares your conversion data directly to Line's platform. By building a sustainable server-side connection, this integration is more resilient to signal loss and will help deliver stronger campaign performance via improved measurement, targeting, and optimization.https://conversion-api-docs.linebiz.com/en/
GoogleSign-up information and interactions with Stripe and our products, website activity, IP address, device and browser characteristics, timestamps of visits, cryptographically hashed (SHA-256) email.The Google Tag is a tracking tag for Google's advertising products (Search, Display, YouTube, GA4) enabling advertisers to serve a more personalised ad experience across Google's advertising products. Combined with Google's API solutions, advertisers can share conversion data to enhance on-site activity with offline customer interactions to improve measurement, targeting, and optimization.https://developers.google.com/tag-platform/tag-manager/server-side/overview https://support.google.com/google-ads/answer/11347292?sjid=13132835489466327554-NC
DemandbaseIP address, timestamps of visit, referrer, page URL, cookie ID, Sign-up information, device and browser characteristicsThe Demandbase tag reads the IP address and cookie of each visitor and passes that information to our identification API, which determines which company the visitor works for. In this way, we're able to measure visitors' interest in your company.https://support.demandbase.com/hc/en-us/articles/115005051743-Understanding-the-Demandbase-Tag

·Does Stripe honor the Global Privacy Control (GPC) opt-out preference signal?

·Yes. Global Privacy Control (GPC) is a signal that is sent by a web browser on your behalf that communicates your choice to opt-out of sharing for targeted advertisements. If you have enabled GPC on your browser, you will automatically be opted out of any "sharing" when you interact with our site. You can learn more about how to use opt-out preference signals by visiting the Global Privacy Control website.

·Can I turn off tracking and advanced fraud signals?

·Your web browser may allow you to manage your cookie preferences, including deleting or disabling Stripe cookies. If you choose to disable cookies, keep in mind that some features of our Site or Services may not operate as intended. Disabling cookies will not disable the collection of advanced fraud signals, which we use to prevent fraud on Stripe. The collection of this data is controlled by the Business User that integrated with Stripe. If a Business User seeks to disable this data collection, they can find instructions to do so through Stripe's documentation. You can take a look at the help section of your web browser or follow the links below to understand your options for disabling cookies. Google Chrome Microsoft Internet Explorer Microsoft Edge Safari Firefox Opera

·You can learn more about how businesses can disable collection of advanced fraud signals in our documentation for disabling advanced fraud detection.

·How do I delete my account?

·You can close your Stripe account from the Settings page on the Dashboard. You can read more about that on our support page: Close a Stripe account.

·Please be aware that we will delete some, but not all, of the information that we hold, for the reasons explained below.

·As a provider of payment services, Stripe is required to comply with many regulations, including anti-terrorism and anti-money laundering laws. These regulations and laws may require Stripe to retain transactional records associated with Business Users for a prescribed period of time after the close of the business relationship. You can read more about our underwriting obligations in our Privacy Policy.

·How do I delete my Custom Connect account?

·If you have a Custom Connect account, your account is managed by a Platform / Business User. They are the party responsible for managing payments for you and responding to your query; therefore we recommend reaching out to them for assistance.

·How do I delete my Express Connect account?

·If you have an Express Connect account, your account is managed by a Platform / Business User. They are the party responsible for managing payments for you and responding to your query; therefore we recommend reaching out to them for assistance.

·What is the Privacy Policy for Stripe Media Services?

·The Privacy Policy for Stripe Media Services (Media Privacy Policy) describes how Stripe collects and processes Personal Data in order to provide the Stripe Media Services, including Stripe Press, Increment, and Works in Progress. We encourage you to read our Media Privacy Policy to learn more.

·Does Stripe localize storage of data in India?

·Personal Data may be processed either locally in India or in any other country where we have operations or where we engage service providers, to the extent permitted under applicable laws of India. Where required payment system data will be stored only on servers in India in accordance with the RBI data localization requirements.

·Where can I lodge my complaint on data handling in India?

·If you have any questions or complaints regarding the treatment of your Personal Data in India, you may contact our Nodal Officer and Grievance Officer: Name - Yogender Singh

·Email Address - complaints-in@stripe.com

·Address - Prestige Tech Pacific Park, 10th Floor, Building 2, Kadubeesanahalli Village, Varthur Hobli, Bangalore East Taluk, Bangalore-560103 Karnataka, India

·For more information about complaint handling, please visit here.

·Separately, for law enforcement requests, please contact LERequests@stripe.com.

·For privacy related questions or concerns, you may also contact Stripe's Data Protection Officer ("DPO") via dpo@stripe.com. If we are unable to address your complaint or grievance, you have the right to escalate the matter to the Data Protection Board of India.

·Notification IT Rules 2021

·We are required to inform you that in case of non-compliance with rules and regulations, our Privacy Policy or user agreement, we have the right to terminate your access or usage rights immediately or remove non-compliant information or both, as the case may be.

·Cookies & Other Technology

·How does Stripe use cookies?

·We use cookies and similar technologies to (1) ensure that our Services function properly, (2) prevent and detect fraud and violations of our terms of service, (3) understand how Visitors use and engage with our Site, (4) advertise our products and Services, where allowed and, (5) analyze and improve our Services and your Site experience including improved relevancy and navigation, customizing your user experience (such as language preference and region-specific content), and curating content about Stripe and our Services that's tailored to you. Depending on your relationship with Stripe and the domain you are visiting, different cookies apply. For instance some cookies are set on a public Stripe or Link domain, some on the Stripe Dashboard or a Link settings page, and some on the payment page available to End Users who make payments using Stripe Services, including Link.

·Cookies play an important role in helping Stripe provide personal, effective and safe Services. Please be mindful that we change the cookies periodically as we improve or add to our Services. For more information, please see our Cookie Policy.

·What is Stripe.js?

·Stripe.js is a JavaScript library that businesses use to integrate Stripe and accept online payments (corresponding iOS and Android SDKs enable the same use cases). Stripe uses Stripe.js to facilitate fraud prevention technologies and the use of its Link payment Services on the websites of Business Users.

·For fraud detection, Stripe.js uses cookies, including `__stripe_mid`, `__stripe_sid`, and `m`, to collect signals differentiating legitimate behavior from fraudulent behavior. For example, fraudsters and bots often spend less time on Business Users' pages than legitimate End Customers. We are able to detect this behavior and use it in evaluating the risk that a transaction is fraudulent.

·When you visit a site that uses Stripe, you might see this fraud prevention activity in a privacy report or tracker list on your web browser. Stripe doesn't-and won't-share or sell the fraud data it collects using Stripe.js to advertisers. Stripe works to keep this fraud detection data secure and ensure it does not leave Stripe infrastructure. It is exchanged between the following Stripe-controlled hosts:js.stripe.com, m.stripe.network, and m.stripe.com, and access to this data is tightly restricted to a small number of Stripe employees whose security permissions are regularly reviewed. You can read more about how Stripe uses data for fraud prevention in our Privacy Policy.

·Stripe also uses the Stripe.js library to implement cookies and similar technology such as `pay_sid`, `link.auth_session_client_secret`, and `elements_session` to enable Link to remember users' information for faster checkout across Stripe merchant sites and to collect analytics related to Link's implementation on checkout pages.

·You should regularly review the Stripe cookies that are placed on your website and other data collected by Stripe.js. You should consult your counsel regarding how best to disclose this data collection to your customers, including by updating your cookie banner. But, here is a paragraph you could add to your privacy disclosures if they do not already include such information:

·We use Stripe for payments, analytics, and other business services. Stripe may collect personal data including via cookies and similar technologies. The personal data Stripe collects may include transactional data and identifying information about devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud and loss prevention and detection, authentication, analytics related to the performance of its services, and to enhance and customize the user experience. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.

·What are advanced fraud signals?

·Stripe's advanced fraud detection looks at signals about device characteristics and user activity indicators that help distinguish between legitimate and fraudulent transactions. These signals are highly indicative of fraud and power Stripe's fraud prevention systems, such as Radar. The signals are securely transmitted to Stripe's backend by periodically making requests to the m.stripe.com endpoint.

·You can learn more in our documentation for advanced fraud detection.

·Why are advanced fraud signals not ad tracking?

·Stripe only uses these advanced fraud detection signals to enable secure payments and prevent fraud. We don't use this data to build individual profiles or share or sell it to third-party advertisers.

·You can read more about how we use this data in our Privacy Policy.

·What obligations should merchants keep in mind relating to cookie technology on their sites?

·This article aims to provide information about the use of cookies and similar technologies ("cookies") on the websites where you as a merchant may use Stripe Services and how the cookies support the functions and features of Stripe's Services for merchants. For example, your use of certain Stripe Services may load stripe.js. Stripe.js is a javascript library provided by Stripe, and in one of its functions it uses cookies for various purposes including fraud prevention, authentication, and analytics (for the avoidance of doubt, the elements_session analytics cookie is only set in some US states). Please refer to https://stripe.com/cookie-settings for more information. The specific cookies used by stripe.js depend on your configuration with the related Stripe products.

·For example, one of the key features of stripe.js is the fraud prevention system provided by Stripe's Radar product. Radar uses cookies to help businesses reduce chargebacks and losses from fraudulent transactions.

·Please note that the use of cookies may have legal implications depending on the geographical location of your business and customers. As a result, you may need to take appropriate action to ensure compliance with local regulatory requirements related to cookies.

·You should regularly review the Stripe cookies that are placed on your website to ensure that your own privacy disclosures tell your end users about this type of data collection, and also update your cookie disclosure and/or consent banner accordingly after reviewing the cookies placed on your website.

·Here is a paragraph you could add to your privacy disclosures if it does not already include such a disclosure:

·We use Stripe for payments, analytics, and other business services. Stripe may collect personal data including via cookies and similar technologies. The personal data Stripe collects may include transactional data and identifying information about devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud detection, loss prevention, authentication, and analytics related to the performance of its services. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.

·Below is an overview of the specific cookies associated with each product and their respective functions for Embeddable Checkout, Elements, Radar, and Link.

Cookie NameCategoryDescriptionCookie in use when using:
mFraud PreventionSet for fraud prevention purposes and helps us assess the risk associated with an attempted transaction. Learn more about advanced fraud detection.Radar
__stripe_midFraud PreventionSet for fraud prevention purposes and helps us assess the risk associated with an attempted transaction. Learn more about advanced fraud detection.Radar
__stripe_sidFraud PreventionSet for fraud prevention purposes and helps us assess the risk associated with an attempted transaction. Learn more about advanced fraud detection.Radar
pay_sidAuthenticationProvide a logged-in experience when a consumer uses link.com to make purchases on a merchant site.Link, Embeddable Checkout, Checkout & Elements
__Host-LinkSessionAuthenticationStores consumer credentials to provide a one-click payment experience at checkout.Link & Elements
link.auth_session_client_secretAuthenticationProvide a logged-in experience when a consumer uses Stripe-hosted payment UIs to make purchases and Crypto Onramp to purchase crypto.Link
elements_sessionAnalyticsThe `elements_session` US-only cookie allows us to measure the result of changes we make to the Stripe Elements product and ensure that the performance of the product continues to improve over time.Embeddable Checkout, Elements & Link

·How does Stripe remember payment method details for Link?

·Link (formerly known as "Remember Me") lets End Users save and reuse their payment information for faster checkout at thousands of online businesses that use Stripe. When an End User makes a purchase via a Business User (i.e., merchant) that enables Link, the End User can ask Stripe to remember their payment method details, such as credit and debit card details. If an individual chooses to be remembered, Stripe will remember the End User's email address, phone number, shipping address, and payment method details for future Link transactions.

·The payment method details for future transactions may be remembered across multiple Stripe Business Users. Generally, once the cookie is set, the End User may make "1-click" purchases using Link when you check out, which means that Stripe will automatically populate the End User's saved information into their checkout on their behalf, and use the information to complete the transaction faster.

·If the End User enters their phone number or email address during a future Link transaction, Stripe will authenticate the End User by sending the End User a One Time Passcode (OTP), e.g. via an SMS message or email. If the End User correctly enters the OTP, Stripe or the Business User will set a cookie in the End User's browser, indicating that the End User has been authenticated. If the End User does not enter the OTP, or elects to "log out" of their Link session then the cookie won't remember the End User.

·A cookie is only stored in a specific browser on a specific device. If an End User wishes to make 1-click purchases in a different browser or on a different device, they must go through the OTP authentication process for the new browser or device combination.

·After 90 days, it will be necessary for the End User to re-complete the OTP process. The End User may also proactively remove the cookie by clearing cookies in their browser or by selecting the "log out" option when this option is presented in checkout.

·If an End User no longer wishes for Stripe to remember their payment method details when they check out in the future, the End User may use the self-service deletion tool. Alternatively, the End User may also contact Stripe support to make this request.

·The description above describes how an End User may control how their information is stored and used to check out. However, this does not affect the other contexts in which Stripe may store and use End User information. In particular, Stripe may store and use such information as described elsewhere on this Privacy Center - including for purposes such as for advanced fraud detection.

·Based on your integration choice (e.g., for Link in Elements), you may have legal responsibilities associated with cookies and similar technology that Stripe uses for fraud detection and/or authentication purposes.

·You should always check with your legal counsel to understand how you should comply with applicable legal obligations with setting cookies and similar technology. This section has information to keep in mind.

·Stripe cookies or similar technology are set on your domain (e.g. on your checkout flow) from the Stripe.js library. The current Stripe cookies from the Stripe.js library include fraud prevention cookies like `__stripe_mid`, `__stripe_sid`, and `m`, and also end-user authentication cookies like`pay_sid` and `__Host-LinkSession`.

·You should regularly review the Stripe cookies that are placed on your website to ensure that your own privacy disclosures tell your End Users about this type of data collection, and also update your cookie banner accordingly after reviewing the cookies placed on your website. Here is a paragraph you could add to your privacy disclosures if it does not already include such a disclosure:

·We use Stripe for payments, analytics, and other business services. Stripe may collect personal data including via cookies and similar technologies. The personal data Stripe collects may include transactional data and identifying information about devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud detection, loss prevention, authentication, and analytics related to the performance of its services. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.

·Does Stripe use CAPTCHA to protect its website from fraud and abuse?

·Yes, some of the Stripe Sites may implement Google reCAPTCHA Enterprise to help prevent fraud and abuse. Information collected by Google is used to provide and improve reCAPTCHA Enterprise and for general security purposes. Use of reCAPTCHA Enterprise is subject to Google's Privacy Policy and Terms of Use.

·We may also use hCAPTCHA Enterprise to help protect Stripe's Sites and Services from fraud and abuse, including by bots impersonating human beings. When you access Stripe's Sites and Services protected by hCAPTCHA, we may share data, including browser features and certain hashed identifiers with our hCAPTCHA provider Intuition Machines, Inc. To the extent that this data is Personal Data, Intuition Machines processes it on Stripe's behalf as a Data Processor.

·Contact Us

·Contact our Privacy team

·If you have any outstanding privacy questions after reviewing the privacy policy, please don't hesitate to reach out to us by email, or through our form.

·If you'd like to send us physical mail, please send to: Stripe, LLC 354 Oyster Point Boulevard

·South San Francisco, California, 94080, USA Attention: Stripe Legal Stripe Technology Company Limited

·One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland Attention: Stripe Legal

·Where can I learn more about Stripe's security practices?

·Visit our security page to learn more about Stripe's security practices. You should contact us immediately if you become aware of any unauthorized use or any other breach of security regarding the Stripe services.

Consumer Terms of Service · p1
Part of the agreement

Consumer Terms of Service

18,696 words, 393 clausesupdated September 30, 2026read 08/10/2026source

·Welcome! Last updated: September 30, 2026

11. Introduction and Scope

·These Consumer Terms of Service ("Terms of Service" or "Terms") are a legal agreement between us ( "us", "our", "we", or "Stripe") and you (referred to as "you" or "your"), the individual who uses one or more of the products and services we offer for your personal use under these Terms (each service offered to you, a "Consumer Service"). The following Terms are a legally binding agreement between you and us, and it describes the terms and conditions applicable to your use of our Consumer Services. By using our Consumer Services, you agree to be bound by these Terms, and any new features or tools that are added will also be subject to these Terms. The Stripe entity with which you are entering into these Terms depends on your location and the specific Consumer Service used and can be found here.

·These general Terms apply to all of our Consumer Services that reference these Terms. Businesses that use the Consumer Services described in these Terms are subject to these Terms even if used for business purposes and the business using the Consumer Service is referred to as "you" or "your." Businesses that use Stripe products and services offered under the Stripe Services Agreement are referred to as "Business Users."

22. Additional Terms That Apply to You

·The following additional policies and terms also apply when you access or use the Consumer Services, all of which are incorporated by reference into these Terms:

  • ·Arbitration Agreement. IF YOU ARE LOCATED IN THE UNITED STATES, YOU AGREE TO OUR ARBITRATION AGREEMENT, WHICH REQUIRES YOU TO RESOLVE DISPUTES BETWEEN YOU AND STRIPE ON AN INDIVIDUAL BASIS THROUGH ARBITRATION, PROHIBITS YOU FROM MAINTAINING OR PARTICIPATING IN A CLASS ACTION LAWSUIT, WAIVES YOUR RIGHT TO A JURY TRIAL, AND LIMITS THE TIME IN WHICH A CLAIM MAY BE BROUGHT.
  • ·Privacy Policy. You acknowledge the Privacy Policy. Stripe and the Business User are independent controllers of personal data collected in conjunction with the Consumer Services and will independently and separately determine the purposes and means of its processing of personal data. We may transfer your personal data to countries other than your own country, including the United States. Please read the Privacy Policy carefully to understand how your information is collected, used, and shared in connection with these Consumer Services. Learn more by reviewing Link's Privacy Center.
  • ·Product-Specific Terms. A Consumer Service may have specific terms that apply when you use that particular Consumer Service. These product-specific Terms are listed in the left-hand menu.
  • ·Acceptable Use Policy. Your use of a Consumer Service is subject to Stripe's Acceptable Use Policy.

·We may revise these Terms from time to time. We will use reasonable efforts to notify you of material changes to these Terms in advance of their effectiveness, including by posting notice on the applicable Consumer Services or providing notice via an email address associated with you. The revised Terms will be effective on the date stated in the revised Terms. By using a Consumer Service after any revisions become effective, you agree to those changes. If you do not agree with any changes to these Terms, you must stop using the Consumer Services.

33. Eligibility

·You may only enter into these Terms if you are over the age of majority and able to enter into a legally binding contract in the country in which you reside.

·You must not use the Consumer Services if you have previously been terminated or suspended from using any of our services, including any Consumer Service. You may not enter into the Terms or use any Consumer Service if you are the target of government sanctions, such as those applied by the U.S. Department of the Treasury Office of Foreign Assets Control, or any other national government.

·You must be eligible for the particular Consumer Services to the extent they are available in your country. If we present an incorrect country for you or you move countries, then you must correct the country in your account or contact support before using the Consumer Services again.

44. Stripe's Role

·Stripe offers and provides you with the Consumer Services described in these Terms. You, and not Stripe, are responsible for the purchases you make using the Consumer Services. The Business User, and not Stripe, is responsible for the goods or services that you may purchase from them using the Consumer Services, including but not limited to quality of goods, returns, accuracy, refunds (except as stated in the Sold Through Link Terms), fraud, advertising, protection of intellectual property rights, liability relating to the Business User's products or services, or non-compliance with applicable law. If you purchased digital goods or digital services from a Business user that is stated as "Sold through Link" (each purchase, an "Order"), then Stripe may have additional responsibilities to you as described in the "Sold Through Link Terms".

·Your access to and use of the Consumer Services does not change your relationship with the Business User, third party services or platforms or with your bank or credit or debit card company.

·Except as provided otherwise in these Terms, Stripe will not intervene in any dispute between you and a Business User for any transactions using the Consumer Services. If you find yourself in a dispute with a Business User or a third party, we encourage you to contact the other party and try to resolve the dispute. If you choose to contact Stripe's support team regarding a Business User, you acknowledge that we may, but are not required to, forward information about your issue, such as your email address and a summary of your issue to the Business User with a request that they contact you directly to resolve your concern. Except as provided otherwise in these Terms, Stripe will not make judgments regarding factual disputes or legal issues or claims between you and the Business User, and Stripe has no obligation to resolve any disputes.

55. Identification and Prevention of Fraud

·You agree that:

  • ·Information you provide about yourself and your use of the Consumer Services must be complete and accurate as of the time provided, and you must keep this information up-to-date;
  • ·To the extent law allows, we and our service providers may verify your identity, except as otherwise provided in product-specific terms.
  • ·You must notify us immediately if you become aware of any unauthorized use or access to your account. You are responsible for any actions taken through the use of your credentials, except for actions taken after you have told us that your account or credentials have been compromised.

66. Communications via Text, Push Notification, Email, and Phone

·To the extent allowable under law, by providing us with a phone number, you consent to receiving text (SMS) messages, push notifications, and phone calls from us. Such communications may include, but are not limited to, requests for authentication, receipts, reminders, notifications regarding updates to your account or account support, requests for product feedback, and marketing or promotional communications. You acknowledge that you are not required to consent to receive promotional texts or calls as a condition of using any Consumer Service. Call and text message communications may be generated by automatic telephone dialing systems. Standard message and data rates your cell phone carrier applies may apply to the text messages we send you.

·You may opt-out of receiving promotional email communications we send to you by following the unsubscribe options on such emails or by managing your communications preferences in the app. You may opt-out of text messages from Stripe by replying STOP or by following instructions that you receive in the text message. You may opt-out of phone calls by notifying the caller or by contacting support. You acknowledge that opting out of receiving communications may impact your use of Consumer Services.

77. Our Intellectual Property Rights

·We reserve all rights not expressly granted to you in these Terms. The Consumer Services are protected by trademark, copyright, patent and other laws of the United States and other countries. We own all rights, title, interest in and to the Consumer Services and all copies of the Consumer Services, and all Intellectual Property Rights in them. Your use of the Consumer Services is subject to these Terms, and these Terms do not grant you any rights to our Intellectual Property Rights or the Intellectual Property Rights of our licensors, licensees, or partners.

·For the purposes of these Terms, "Intellectual Property Rights" means all patent rights, copyright rights, mask work rights, moral rights, rights of publicity, trademark, trade dress and service mark rights, goodwill, trade secret rights, and other intellectual property rights that may exist now or come into existence in the future, and all of their applications, registrations, renewals and extensions, under the laws of any state, country, territory or other jurisdiction.

88. Feedback

·You may choose to submit feedback, ideas and suggestions about the Consumer Services, but it is never required. You may provide us with feedback on the Consumer Services by contacting support. You agree that we may use, integrate, and share all feedback, ideas, and suggestions you submit for any purpose and without compensation or obligation to you. You assign to us all rights, title and interest to any feedback, ideas and suggestions, including the right to use, modify and integrate them in any manner.

99. Termination

·Termination by Us: We may terminate these Terms (or any part), and we may limit, suspend, change, or remove your access to any or all Consumer Services, including any feature or aspect of the Consumer Services, at any time for any reason. If commercially reasonable, we will take reasonable steps to notify you before taking any action that restricts your access to the Consumer Services. If in our sole judgment you fail, or we suspect that you have failed, to comply with any term or provision of these Terms, we may terminate these Terms at any time without notice to you and accordingly we may terminate your access to the Consumer Services.

·Termination by You: Subject to any product-specific Terms below, you may terminate any Consumer Service at any time and for any reason by terminating the Consumer Service or closing or deleting your account as described below in the Link Account Terms. Termination will be effective on the date that your account is closed.

·Effect of Termination. Upon termination, you will not have any further use of or access to the Consumer Services. Subject to applicable law, you will also not have any use of or access to any information you submitted through the Consumer Services, and all rights granted under these Terms will end. Termination does not relieve you of your obligations to pay amounts owed to Stripe, Business Users, or any other obligation contracted prior to termination. Termination does not revoke any third-party payment authorizations. The following provisions will survive even after these Terms terminate: Arbitration Agreement, Our Intellectual Property, Feedback, Disclaimer of Warranties, Limitation of Liability, Governing Law, Assignment and Third Party Beneficiaries, and Miscellaneous Terms.

1010. Disclaimer of Warranties

·You release Stripe from any claims, demands, and damages arising out of disputes relating to your use of the Consumer Services or your placement of an Order, including those disputes with other Business Users or parties.

·We, our affiliates, and our respective agents, and contractors (together, the "Disclaiming Entities") make no warranties with respect to the products, services or information provided by Business Users to you. You agree, with respect to any claim regarding the products, service or information provided by Business Users to you, that the Disclaiming Entities are not responsible or liable for, and you release the Disclaiming Entities from all claims, demands and damages, including but not limited to: (a) product liability claims related to Business User products; (b) claims that the offer or sale of Business User products or services fails to conform to any applicable legal or regulatory requirement; (c) claims about Business Users' products, services, or practices arising under consumer protection or similar legislation; (d) claims based on any inaccurate, incomplete or out of date information offered by a Business User; (e) claims of infringement of intellectual property rights by the Business User; or (f) claims about any third party platform where you may interact with or purchase from. Your recourse for claims related to the products or services that you purchase from a Business User is against the Business User and not the Disclaiming Entities.

·Subject to statutory consumer guarantees, which will apply irrespective of this disclaimer, the Consumer Services are provided "as-is" and without any representation or warranty, whether express or implied. The Disclaiming Entities and Business Users make no representation or warranty of any kind whatsoever (other than those implied by statute) with respect to the Consumer Services or the content, materials, information and functions we make accessible, and specifically disclaim all implied warranties of merchantability, fitness for a particular purpose, title and non-infringement. We do not promise that the Consumer Services will be uninterrupted, error-free, free from cyber attacks, or secure.

·The Disclaiming Entities do not control or make any warranties regarding the products or services others or Business Users provide in connection with your Orders or the Consumer Services. In other words, we do not have control over the businesses from which you're purchasing when using the Consumer Services, and we do not promise or imply that the products or services you buy using the Consumer Services will work as promised or be safe to use.

·Some laws limit or prohibit disclaiming the warranties referred to in the previous paragraphs, or impose obligations on us that we can't eliminate with these Terms. In those case, this section (Disclaimer of Warranties) does not restrict, exclude or modify any consumer rights under any applicable law.

1111. Limitation of Liability

·The Disclaiming Entities and Business Users will not be liable to you for any failure to perform our obligation under these Terms due to a Force Majeure Event. A "Force Majeure Event" is any event beyond the control of the Disclaiming Entities that significantly impacts Stripe's ability to perform its obligations under these Terms, including a strike or other labor dispute; labor shortage, stoppage or slowdown; supply chain disruption; embargo or blockade; telecommunication breakdown; cyber blackout; power outage or shortage; inadequate transportation service; inability or delay in obtaining adequate supplies; weather; earthquake; fire; flood; act of God; riot; civil disorder; civil or government calamity; epidemic; pandemic; state or national health crisis; war; invasion; hostility (whether war is declared or not); terrorism threat or act; Law; or act of a Governmental Authority.

·Subject to applicable consumer laws in your country, which will apply irrespective of this limitation of liability, the Disclaiming Entities will not be liable to you for any failure to perform our obligations under these Terms where performance of that obligation would have put us in violation of applicable law.

·The Disclaiming Entities will not be liable to you in any circumstances for:

·(a) Loss of business, loss of goodwill, loss of opportunity, or loss of profit; or

·(b) Any loss that we could not have reasonably anticipated.

·Subject to the specific product Terms below and applicable consumer laws in your country, in no event will a Disclaiming Entity's liability arising out of or in connection with these Terms exceed the greater of $200 USD or, if applicable, the amount you paid for the Order on which your claim is based.

·You and we agree that the other has relied on the disclaimer of warranties and limitation of liability stated above in entering into these Terms, the limitation and disclaimer are essential to the agreement between you and us under these Terms, and they will apply to the fullest extent allowed by law.

·Some laws restrict our ability to disclaim or limit our liability. In those cases, this section does not restrict, exclude or modify any consumer rights under any applicable law.

1212. Governing Law

·If you reside in the United States, California law will govern any claim or dispute between you and us that arises out of these Terms, regardless of conflict of law principles.

·If you reside outside of the United States, your governing law is specified here.

1313. Assignment and Third-Party Beneficiaries

·You must not assign your rights or obligations under these Terms to anyone without our prior written consent. We may delegate performing our obligations, and we may assign our rights and novate our obligations under these Terms to Stripe affiliates, at any time for any reason by providing notice to you.

1414. Miscellaneous Terms

·These Terms, together with the Arbitration Agreement (if applicable), E-Sign Agreement, the Acceptable Use Policy, and the product-specific Terms below are the only agreement between you and us regarding the Consumer Services. In the event of an irreconcilable conflict or inconsistency between a provision in these Terms and any product-specific Terms below, the provision in the product-specific Terms will govern. These Terms do not create any partnership, joint venture, or other agency relationship between you and us. If we do not immediately exercise a right we have under these Terms, we do not waive that right. We retain our ability and right to enforce any part of these Terms at a later time. If any part of these Terms is found unenforceable, that part will be ignored, and all of the remaining terms will remain in effect.

1515. Terms Applicable to Artificial Intelligence Commerce Platform Purchases

·When you use Link to purchase goods or services from a Business User selling on an Artificial Intelligence (AI) commerce platform, you authorize your credit card, debit card, or other payment method on file with Link or the AI commerce platform to be charged for the purchase of those goods or services from the Business User.

·You agree that Stripe, the AI commerce platform, or the Business User will obtain an authorization to cover the cost of the goods or services you have purchased from the Business User and that you will be charged for the goods or services purchased by you and any applicable taxes and/or fees.

·The Business User, not Stripe or the AI commerce platform, is the seller of the goods or services to you. You agree that your purchase is being made from the Business User, that the Business User is the merchant of record, and that title to any goods passes to you when the goods are purchased from the applicable Business User. If you have an issue with your purchase or related delivery, you must contact the Business User from which your goods or services were purchased to resolve the issue. You agree that any returns or refunds for goods or services purchased using Link services are subject to the Business User's refund and return policies, which vary by Business User.

1616. Contact

·If you have a question about the Consumer Services or how these Terms apply to you, please contact support.

11. Description of Link Accounts

·Link is a digital account that facilitates a variety of payment-related features, including saving your information for an accelerated checkout experience. Business Users that have enabled Link services (a "Link Merchant") may ask you if you would like to save your information, or use your information saved to your Link Account (defined below), for future payments across Link Merchants. When you authorize us to save your information, you are signing up for an account with Link (a "Link Account"). You may also create a Link Account by visiting Link.com and signing up directly for a Link Account.

·How we use your Link Account Information

·When you sign up directly for a Link Account, we will collect and store certain personal data from you, such as:

  • ·Your name, email address, and mobile phone number ("Account Information"); and
  • ·If you elect to provide it, your credit card, debit card, bank account information, and billing address ("Payment Information").

·When you create a Link Account as part of Link accelerated checkout service we will collect and store certain personal data from you, such as:

  • ·Your Account Information;
  • ·Your Payment Information;
  • ·Your shipping address ("Shipping Information"); and
  • ·Information related to your purchase from a Link Merchant, such as the order date, amount, and product details (such as name, price, photos) ("Order Information").

·Together, your Account Information, Payment Information, Shipping Information and Order Information, as applicable, are your "Saved Information." We will use all personal data we collect about you in accordance with the Link Privacy Policy, including to develop and analyze our services and to share with our Link Merchants and our Business Users. The data we share with Link Merchants and Business Users may include: (i) the fact that you have a Link Account, (ii) whether you completed a purchase using Link accelerated checkout services, and (iii) the payment method type used for a purchase you made using Link. We may also share your Account Information with our financial partners in order to assist you in obtaining services from our financial partners.

·When you login to your Link Account, we or the Link Merchant will use cookies or similar technologies to associate your web browser, app, or device (or data regarding your web browser, app, or device) to your Link Account and to recognize you when you visit that Link Merchant or another Link Merchant on the same web browser, app, or device. You will be able to log in to your Link Account to access your Saved Information by inputting your email address and using a passkey or a verification code sent to you via SMS text message or by email. You can then make purchases using your Account Information, Payment Information, and Shipping Information across Link Merchants when you are logged in with us on the same browser, app or device. When you are logged in to your Link Account, we will provide the Link Merchant with your Account Information, Payment Information, and/or your Shipping Information to facilitate a faster checkout. If you are not logged in to your Link Account, for example, because your session has expired, you've cleared your cookies, or you're using a device that is different from the one you used to last access Link, you may log in again via the same method outlined above.

22. Your Rights and Obligations

  • ·You may only save Payment Information with us that you are authorized to use.
  • ·When you are logged into your Link Account and you input or use a new payment method (such as a different debit or credit card, or a different bank account), you authorize Stripe to save that new payment method information to your Link Account as part of your Payment Information. The last payment method you used to make a successful transaction may become your default payment method the next time you are completing a transaction on a Link Merchant's site. You may also change your default payment method by logging into your Link Account on app.link.com.
  • ·Message and data rates may apply for any SMS messages that we send to you, or you send to us. If you have any questions about your text plan or data plan, contact your wireless or mobile provider.
  • ·We reserve the right to modify or terminate Link or any of the features or tools provided therein for any reason (acting in our reasonable discretion), and at any time. We will try to notify you first unless it is unreasonable to do so.
  • ·We reserve the right to refuse service to anyone for any reason at any time.

33. Updating or terminating your Link Account

  • ·These Link Account Terms are effective unless and until they are terminated by either you or us. You may terminate these Link Account Terms at any time by deleting your Link Account.
  • ·If you want to delete your Saved Information, your Link Account, or stop storing information using Link, please let us know by visiting this page and submitting your email address.
  • ·You can manage your Saved Information on your Link Account, the next time you checkout on a Link Merchant site, or by visiting https://support.link.com for more instructions. Should you update your Payment Information, you authorize Stripe to validate and store your Payment Information, including your credit card, on file.
  • ·If your access to your Link Account is terminated by you or us, we will delete your Saved Information in accordance with our Privacy Policy.

44. Adding or Removing a Payment Method

  • ·You can add or remove certain payment methods to your Link Account such as a credit card, debit card, a buy-now-pay-later (BNPL) account, or a bank account. Before linking a payment method, you should review and understand the consumer protection rights and remedies available for different payment sources in your jurisdiction, such as under the Electronic Fund Transfer Act (EFTA) and Fair Credit Billing Act (FCBA) in the United States.
  • ·If you add a BNPL account to your Link Account, your BNPL account will remain logged-in via your Link Account. This means that you will not need to separately log in to your BNPL account to access it via Link. It also means that access to your Link account will also provide access to your BNPL account.
  • ·Please keep your Payment Information current (e.g., credit card number and expiration date). If this information changes, you authorize us to, as permitted by and in accordance with the law, update it using information and third-party sources available to us without any action on your part. If you do not want us to update your card information, you may remove your Payment Information from your Link Account.
  • ·Removing a payment method from your Link Account does not cancel or change any amounts you still owe to a Link Merchant or to a BNPL provider. Specifically, if you remove a payment method from your Saved Information, this will not terminate or cancel any outstanding payment plans you may have entered into with a BNPL provider or any subscriptions you may have purchased with a Link Merchant using your Saved Information. You must cancel your subscriptions with the Link Merchant directly, and you must manage your BNPL payment plans with the BNPL provider directly.
  • ·Where applicable, we may ask you to connect your bank account to your Link Account to make it easier to pay with your bank account subsequently through your Link Account. Any bank account you choose to save to your Link Account is referred to as a "Saved Bank Account." Through your Link Account and under the Financial Connections Terms, you may also choose to provide your Saved Bank Account details directly to a Business User regardless of whether Stripe is involved in a subsequent transaction. We will collect data from your Saved Bank Account (and other accounts under the same account credentials) pursuant to the Financial Connections Terms and the Link Privacy Policy. We may use your Saved Bank Account data to, among other things, verify that your Saved Bank Account is valid, check your balance to confirm there are sufficient funds for your purchase, streamline your requested payments and assess your eligibility for and offer you Consumer Services that we or our affiliate provides. You authorize us to credit amounts or otherwise send payments to the bank account you would like to save to your Link Account and your existing Saved Bank Account(s), including to determine whether your bank account is valid and active, as well as for promotions and refunds.
  • ·Each time you use your Link Account to pay a Link Merchant using your Saved Bank Account, you are authorizing the Link Merchant to debit your Saved Bank Account for up to the total amount you authorize the merchant to charge ("Total Authorized Amount") pursuant to the Link Bank Payments Authorization. You authorize us to retry a debit on your Saved Bank Account if your bank rejects the original debit. If the Link Merchant chooses, they may debit your Saved Bank Account, pursuant to your Link Bank Payments Authorization, for amounts less than the Total Authorized Amount, which in the aggregate will not exceed the Total Authorized Amount. Where your Saved Bank Account is a U.S. bank account, you agree that your grant of the authorization in this paragraph complies with the National Automated Clearinghouse Association (NACHA) operating rules and has the same legal effect as if you had signed a paper mandate containing the same terms.
  • ·If you do not see an option to pay using a bank account through your Link Account, it may be because the Link Merchant has not allowed those payments or the Link Merchant or bank is not eligible for bank payments via our Consumer Services. If your bank account transaction fails without an actual attempt to debit your Saved Bank Account, it may be because we determined the transaction is at high risk of being returned unsuccessfully (e.g. if your historical account balance is below the transaction amount). This can help prevent you from incurring insufficient funds fees from your bank. We recommend that you use a different bank account or payment method or reach out to us if you have questions. Your use of your bank account as a payment method is also subject to the terms, benefits, and protections associated with your personal bank account. If you use your bank account as a payment method and do not have sufficient funds to make a purchase, you could incur overdraft fees, insufficient funds fees or other fees with your bank.
  • ·If at any time you would like to revoke your Link Bank Payments Authorization or you no longer want your Saved Bank Account to be a payment method saved to your Link Account, you must delete your Saved Bank Account as a payment method from your Link Account. If a payment with your Saved Bank Account was not initiated from your Link Account but involved Link or Stripe connecting your financial account with that Business User, please see the Financial Connections Terms or this page for information on how to disconnect your Saved Bank Account.

55. Backup payment method

  • ·If your default or selected payment method is unavailable, or the transaction is unsuccessful using that payment method (for example, because your Saved Bank Account has insufficient funds), the Link Merchant may initiate a transaction on any other payment method saved to your Link Account (a "Backup Payment Method"). Generally, transactions on Backup Payment Methods will be attempted in the following order, if applicable: (1) Saved Bank Account, (2) debit card, and (3) credit card. In some cases, a Backup Payment Method of the same type will be used (for example, if your default payment method is a card, the Backup Payment Method may also be a card).
  • ·We will identify that a Backup Payment Method applies before you complete the purchase (e.g., whether during a one-time checkout or for any subscription payments, during the initial subscription purchase).
  • ·If you do not wish to have a Backup Payment Method used, you may either (i) not consent to the use of the Backup Payment Method or (ii) manage your payment methods on your Link Account.

66. Beta Program

·If you would like access to the newest Link products and services, you can opt in to participate in the Link beta program via the settings in your Link Account. When you join the Link beta program, you are authorizing us to process your Saved Information to determine if you are eligible for our newest products and services. We may also send you communications to market the availability of a new product or service.

77. Security

  • ·We take the protection of your Saved Information seriously and have implemented technical and organizational measures designed to safeguard it from accidental loss and from unauthorized access, use, alteration, or disclosure. These measures include industry-standard practices and technology to help maintain the security, confidentiality, and integrity of your data.
  • ·While we strive to provide robust security, no system is completely foolproof. We cannot guarantee that unauthorized third parties will never be able to defeat our security measures or misuse your Saved Information. We encourage you to remain vigilant and take responsibility for securing your personal data, knowing that you provide it at your own risk.
  • ·Learn more about our security here. If you have reason to believe that the security of your Link Account has been compromised, please contact us immediately at support.link.com/contact.

88. Dormant Accounts

  • ·If your Link Account remains inactive for a continuous period of two years, we may consider the account dormant and may close your Link Account at our discretion (a "Dormant Account").
  • ·A Link Account is considered a Dormant Account if you have not done any of the following Link Account activities during a continuous two year period:
  • ·Making a payment or purchase using Link at a Link Merchant;
  • ·Adding, updating or removing any of your Saved Information;
  • ·Initiating account settings changes or updating security preferences;
  • ·Engaging with customer support related to your Link Account, including inquiries or disputes; or
  • ·Logging in to your Link Account and browsing or reviewing transaction history.
  • ·Prior to closing the Dormant Account, Stripe will notify you using the email address associated with your Link Account. Starting from the date of our notice to you, we will provide you with a period of 30 days to reactivate your Link Account by logging in and performing any Link Account activity listed above.
  • ·If Stripe does not receive a response or the account remains inactive after the 30-day notice period, your Link Account will be closed.

99. Protection from Unauthorized Transactions (only for U.S. consumers)

  • ·You may view your Link Account statement that shows your Link Account transactions and certain Order information by logging into your Link Account ("Link Transaction History").
  • ·To protect yourself from unauthorized activity in your Link Account, you should regularly log into your Link Account and review your Link Transaction History. You should review transaction details to ensure that each transaction was authorized and accurately completed.
  • ·Stripe will protect you from unauthorized transactions initiated with your Link Account. When this protection applies, Link will cover you for the full amount of the unauthorized activity as long as you cooperate with us and follow the procedures described below.
  • ·What is an Unauthorized Transaction? An "Unauthorized Transaction" occurs when your Link Account is used to make a purchase with a debit card issued by a U.S.-based bank or a U.S. bank account that you did not authorize and that did not benefit you. For example, if someone steals or fraudulently obtains access to your Link Account and makes a purchase using your Link Account with a saved U.S. debit card or a U.S. Saved Bank Account, an Unauthorized Transaction has occurred.
  • ·What is not considered an Unauthorized Transaction? The following are NOT considered Unauthorized Transactions:
  • ·If you grant authority to someone to use your Link Account (by giving them your login information) and they exceed the authority you gave them. You are responsible for transactions made in this situation unless you have previously notified Stripe that you no longer authorize transactions by that individual.
  • ·Other unauthorized purchases using the Saved Bank Account, including via Stripe's payment processing services, but that are not initiated with your Link Account. For those types of unauthorized purchases, contact your financial institution to report the unauthorized activity.
  • ·Reporting an Unauthorized Transaction.
  • ·If you believe your Link Account has been compromised, please contact Link consumer support immediately at support.link.com/contact or call 1-888-820-7551.
  • ·Tell us IMMEDIATELY if you believe that an electronic fund transfer has been made without your permission using your login information or by other means. If you tell us within the 60 days after we provide you with your Link Transaction History showing transfers you did not make, you may be eligible for a refund of the full amount paid for Unauthorized Transactions.

1010. Error Resolution (only for U.S. consumers)

  • ·What is an Error? An "Error" means the following:
  • ·An "Unauthorized Transaction", as it is defined above.
  • ·When a transaction is incorrectly recorded in your Link Account.
  • ·You send a payment and the incorrect amount is debited from your Link Account.
  • ·An incorrect amount is credited to your Link Account.
  • ·A transaction is missing from or not properly identified in your Link Transaction History.
  • ·We make a computational or mathematical error related to your Link Account.
  • ·You request Link Transaction History that Stripe is required to provide to you.
  • ·You request information concerning pre-authorized (recurring) transfers from your Link Account that Stripe is required to provide to you.
  • ·You request additional information or clarification concerning a transfer from your Link Account, including a request you make to determine whether an error has occurred.
  • ·You inquire about the status of a pending transfer from your Link Account.
  • ·What is not considered an Error? The following are NOT considered Errors:
  • ·If you give someone access to your Link Account (by giving them your login information) and they use your Link Account without your knowledge or permission. You are responsible for transactions made in this situation.
  • ·Requests for duplicate documentation or other information for tax or other recordkeeping purposes.
  • ·In case of Errors or questions about your electronic transfers
  • ·Telephone us at 1-888-820-7551, contact us at support.link.com/contact, or write us at Link │ Built by Stripe Stripe, LLC 354 Oyster Point Blvd. South San Francisco, CA 94080
  • ·Notify us as soon as you can, if you think your statement or receipt is wrong or if you need more information about a transfer listed on the statement or receipt. We must hear from you no later than 60 days after the problem or error appeared on your Link Transaction History.
  • 1Tell us your name and account number.
  • 2Describe the error or the transfer you are unsure about, and explain as clearly as you can why you believe it is an error or why you need more information.
  • 3Tell us the dollar amount of the suspected error.
  • ·If you tell us orally, we may require that you send us your complaint or question in writing within 10 business days.
  • ·We will determine whether an error occurred within 10 business days after we hear from you and will correct any error promptly.
  • ·We will tell you the results after completing our investigation. If we decide that there was no error, we will send you a written explanation. You may ask for copies of the documents that we used in our investigation.

11. Registration, Access, and Use

·You must sign up for a Link Account or have an existing Link Account to use Link Balance. You will need to complete certain verification procedures before you are permitted to use Link Balance. Your Link Account will be the sole means of accessing your Link Balance.

·By using Link Balance, you agree that you will use Link Balance only for yourself, and not on behalf of any third party. You are fully responsible for all activity that occurs on your Link Account, including Link Balance activity. You are solely responsible for maintaining the security of your device and your Link Account credentials. Link is not liable for any loss or liability resulting from unauthorized access to your Link Balance that occurs as a result of your failure to keep your credentials or device secure, or due to a compromise of your device, email, or phone number.

22. Custodial Services and Ownership

·As part of your Link Balance, Link will provide qualifying users a custodial wallet to hold your Supported Digital Assets. Bridge (a Stripe company) is the custodian of your Supported Digital Assets. By providing instructions relating to your Supported Digital Assets through your Link Account (e.g., the instruction of a withdrawal), you are providing instructions directly to Bridge. By using Link Balance, you agree to be bound by the Bridge User Terms found here. You are ultimately legally responsible for all transactions and risk of loss. As long as you continue to hold Supported Digital Assets in your Link Balance, Bridge will retain control over electronic private keys associated with blockchain addresses operated by Bridge, including the blockchain addresses used to hold the Supported Digital Assets credited to your Link Balance.

·Bridge will not receive title to any Supported Digital Assets; you will retain title to Supported Digital Assets in compliance with applicable law. As owner of the Supported Digital Assets in your Link Balance, you will bear all risk of loss (including due to fluctuations in asset value or fraudulent or unauthorized transactions) of such Supported Digital Assets.

33. Balance Information

·You will be able to view and manage your Link Balance on the Link app. Information you will be able to view include: (i) the amount (and currency) of each Supported Digital Asset transaction; (ii) a reference and description of the Supported Digital Asset transaction; (iii) if applicable, any fees charged; (iv) if applicable, the rate of exchange, and the amount (in the new currency) after exchange; and (v) the date of each Supported Digital Asset Transaction.

44. Withdrawals from Link Balance

·You may withdraw your Supported Digital Assets by instructing Bridge (via your Link Account) to debit the applicable Supported Digital Asset from your Link Balance and convert the Supported Digital Assets to fiat currency for deposit into your personal bank account. Withdrawal requests may be subject to outages, downtime, time to conduct blockchain operations to fulfill your request, and other applicable policies. You are responsible for risk of loss arising from incorrect instructions provided to Link and Bridge. Once you have initiated a withdrawal, you cannot cancel or reverse it.

·We make no guarantees regarding the amount of time it may take to complete a transfer or withdrawal of Supported Digital Assets. You acknowledge that the blockchain networks underlying the Supported Digital Assets are decentralized and outside of our control. Network congestion, high transaction volumes, or issues with the underlying protocol may cause transactions to be delayed, suspended, or fail. Link and Bridge are not responsible for any losses or damages caused by such delays or failures.

55. Fees

·By using Link Balance, you agree that Link may charge fees, including service fees, pass-through fees from sub-processors, gas fees, foreign exchange fees, and any other fees associated with the storage and withdrawal of the applicable Supported Digital Asset in your Link Balance (collectively, "Fees"). You grant Link a standing authorization to automatically deduct all applicable Fees directly from your Link Balance or from the proceeds of a specific transaction at the time the liability is incurred, without further notice to you. Fees may be debited from your Link Balance for a specific transaction and will be reflected in your Link Balance information.

66. Supported Digital Assets

·Link Balance currently supports USD Coin ("USDC") and may support other digital assets in the future ("Supported Digital Asset"). USDC is issued by Circle and pegged to USD at a 1:1 ratio.

77. No Deposit Insurance

·You acknowledge that your Link Balance is not a bank account or a deposit account. Supported Digital Assets held in your Link Balance are not legal tender, are not backed by any government, and are not insured by the Federal Deposit Insurance Corporation (FDIC) or any other governmental agency.

88. Operation of Digital Asset Protocols

·Link does not own or control the underlying software protocols which govern the operation of the Supported Digital Assets. Link assumes no responsibility for the operation of the underlying protocols and does not guarantee the functionality or security of network operations. In particular, the underlying protocols may be subject to sudden changes in operating rules (including "forks"). Any such operating changes may materially affect the availability, value, functionality, and/or the name of the Supported Digital Assets in your Link Balance. In the event of any such operational change, Link reserves the right to take such steps as may be necessary to protect the security and safety of Supported Digital Assets held in your Link Balance, including, without limitation, temporarily suspending operations for the involved Supported Digital Assets. Link will use commercially reasonable efforts to provide you with reasonable prior notice of its response to any material operating change.

99. Payment Service Partners

·Link may use a third-party payment processor to process withdrawal requests from your Link Balance to your local bank account. Link may add or change third party payment processors for the purposes of providing the Link Balance services at any time.

1010. Dormant Account Unclaimed Property

·For the avoidance of doubt, Dormant Account terms of your Link Account apply to your Link Balance. Following Dormant Account notification, applicable law may require Bridge to deliver unclaimed Supported Digital Assets held in your Link Balance to the applicable governmental authority as unclaimed property.

1111. Suspension, Termination, and Cancellation

·Link may suspend, restrict, or terminate your access to Link Balance, and may instruct Bridge to suspend any transfer of any Supported Digital Assets, with immediate effect for any reason at our sole discretion and is under no obligation to disclose the details of its decision to you.

·In the event your access to Link Balance has been terminated, you will be permitted to transfer Supported Digital Assets associated with your Link Balance for thirty (30) days after notice of termination unless such transfer is otherwise prohibited under applicable law. If your Supported Digital Assets are not transferred following termination of your Link Balance, your Supported Digital Assets may be subject to applicable escheatment laws. Link is not responsible for any liability or loss you may incur resulting from suspension or termination of Link Balance under these terms.

1212. Verification Procedures

·Link is required to identify users registering for and using Link Balance. This ensures Link remains in compliance with applicable KYC/AML laws, which is necessary to continue offering Supported Digital Asset and Link Balance services to our customers. Link collects and verifies information about you in order to: (i) protect Link and the community from fraudulent users; and (ii) to keep appropriate records of Link's customers. Link may require you to provide or verify additional information, engage in enhanced due diligence, or to wait some amount of time after completion of a transaction, before permitting you to use any Link Balance service and/or before permitting you to engage in transactions.

11. Registration, Access, and Use

·You must sign up for a Link Account or have an existing Link Account to use Link Balance Self-Custody Wallet ("Link Balance NCW"). You will need to complete certain verification procedures before you are permitted to use Link Balance NCW. While your Link Balance NCW remains connected to your Link Account, your Link Account will be the sole means of accessing your Link Balance NCW. Link Balance NCW may provide you and ability to purchase Supported Digital Assets as well as spend those Supported Digital Assets using a virtual card. By purchasing Supported Digital Assets via Link or creating a virtual card, you also agree to the Fiat-to-Crypto Onramp Terms and Link Virtual Card Terms.

·By using Link Balance NCW, you agree that you will use it only for yourself and not on behalf of any third party. You are fully responsible for all activity that occurs on your Link Account, including Link Balance NCW activity. You are solely responsible for maintaining the security of your device and your Link Account credentials. Link is not liable for any loss or liability resulting from unauthorized access to your Link Balance NCW that occurs as a result of your failure to keep your credentials or device secure, or due to a compromise of your device, email, or phone number.

22. Self-Custody and Ownership

·Link Balance NCW is a neutral technology service that enables you to access your on-chain Supported Digital Assets. You retain ownership of your Supported Digital Assets and control over the cryptographic credentials used to authorize transactions from your on-chain wallet. Link does not hold or control those Supported Digital Assets as a custodian. You may grant Link permission to initiate or sign transactions using Link Balance NCW as described in Section 6. Any such authority is limited to the scope of the permissions you approve, including any applicable transaction limits, conditions, and duration. Link may exercise those permissions while you are not actively using Link.

·Granting a permission does not transfer ownership of your Supported Digital Assets to Link. You may revoke permissions through the applicable process described when you enable the feature. Revocation is subject to the timing and effects described in Section 6.

·Link Balance NCW uses wallet infrastructure provided by Privy. By using a Link Balance NCW, you also agree to the Privy User Terms. Link and Privy provide technology that enables you to create and access your on-chain wallet and authorize transactions. You are ultimately legally responsible for all transactions and bear the risk of loss, including loss due to fluctuations in asset value or fraudulent or unauthorized transactions. Supported Digital Assets are recorded on the applicable blockchain rather than held by the Link Balance NCW service or in your Link Account. A balance displayed in your Link Account represents information about your on-chain Supported Digital Assets and is not a deposit with, or a promise of repayment by, Stripe or Privy.

33. Export and Independent Access

·You may export the private key or other credentials needed to control your on-chain wallet and its Supported Digital Assets by following the process described here.

·Exporting the private key or other credentials creates additional security risks. Anyone who obtains those private keys or credentials may be able to control your on-chain wallet and its Supported Digital Assets. If you lose or disclose an exported private key or other wallet credential, Link may be unable to restore access to your wallet. Transactions made using compromised credentials may be irreversible, and Link may be unable to recover the transferred Supported Digital Assets.If you access your wallet through another application using exported credentials, that application's terms apply, and Link features may not be available.

44. Balance Information and Blockchain Transactions

·You will be able to view and manage your on-chain Supported Digital Assets via Link Balance NCW on the Link app. Information you will be able to view include: (i) the amount (and currency) of each Supported Digital Asset transaction; (ii) a reference and description of the Supported Digital Asset transaction; (iii) if applicable, any fees charged; (iv) if applicable, the rate of exchange, and the amount (in the new currency) after exchange; and (v) the date of each Supported Digital Asset Transaction.

·Blockchain transactions are processed by the applicable software protocol. Once submitted, a transaction may not be capable of cancellation or modification. Once confirmed, a blockchain transaction ordinarily cannot be reversed. Any available refund must be made as a separate transaction by the recipient or applicable service provider.

·We do not guarantee that a transaction will be accepted, confirmed or completed within a particular time. Network congestion, outages, protocol changes and other circumstances may cause transactions to be delayed or fail.

55. Wallet Security and Recovery

·You are responsible for securing your devices, accounts, authentication credentials and any private keys or recovery information that you export or receive. Do not disclose private keys or secret recovery information to anyone, including anyone claiming to provide customer support.

·If your authentication or recovery methods are lost, unavailable, or compromised, you may lose access to Link Balance NCW, your on-chain wallet, or your Supported Digital Assets, or another person may be able to authorize transactions from your on-chain wallet. Loss of access may result in the permanent loss of your Supported Digital Assets. Resetting your Link Account credentials does not necessarily restore access to your on-chain wallet or Supported Digital Assets.

66. Transaction Authorization

·You are responsible for reviewing the details of each transaction or permission request before approving it, including the Supported Digital Asset, amount, blockchain network, destination address and applicable fees. An incorrect address or network may result in permanent loss.

·Certain features allow you to authorize Link or another service to initiate or sign transactions within permissions you approve, including when you are not actively using Link Balance NCW. We will describe the scope of those permissions and how to revoke them before you enable the feature. Revocation prevents future use of the revoked permission once effective, but does not undo transactions already submitted or separately revoke permissions granted.

77. Transaction Settings, Delegated Authority and Policies

·Link Balance NCW may allow you to configure transaction-related settings, parameters, rules, conditions, schedules, triggers, or other logic through your Link Account. Link will submit on-chain transactions from your on-chain wallet through Link Balance NCW solely in accordance with your configured settings and policies. You may modify or disable these settings through Link or other supported means.

·You are responsible for reviewing, configuring, updating, and maintaining the transaction settings and permissions you select, including any transaction limits, approved recipients, schedules, triggers, and approval requirements. Before enabling or changing a setting or permission, you should ensure that it reflects your intended instructions.

88. Withdrawals from Link Balance NCW

·Link Balance NCW may allow you to withdraw your Supported Digital Assets by converting them to fiat currency for deposit into your personal bank account. Withdrawal requests are subject to applicable policies and may be delayed, suspended, or prevented by events beyond our reasonable control, including blockchain congestion or outages, internet or telecommunications failures, cyberattacks, governmental actions, changes to an underlying protocol, and failures of third-party service providers. Once you initiate a withdrawal, you cannot cancel or reverse it.

·We make no guarantees regarding the amount of time it may take to complete a transfer or withdrawal of Supported Digital Assets. You acknowledge that the blockchain networks underlying the Supported Digital Assets are decentralized and outside of our control. Network congestion, high transaction volumes, or issues with the underlying protocol may cause transactions to be delayed, suspended, or fail. Link is not responsible for any losses or damages caused by such delays or failures.

99. Fees

·By using Link Balance NCW, you agree that Link may charge fees, including service fees, pass-through fees from sub-processors, gas fees, foreign exchange fees, and any other fees associated with the storage and withdrawal of the applicable Supported Digital Asset in your Link Balance NCW (collectively, "Fees"). You grant Link a standing authorization to automatically deduct all applicable Fees directly from your on-chain Supported Digital Assets or from the proceeds of a specific transaction at the time the liability is incurred, without further notice to you. Fees may be debited from your on-chain Supported Digital Assets for a specific transaction and will be reflected in your Link Balance NCW information.

1010. Supported Digital Assets

·Link Balance NCW currently supports access to USD Coin ("USDC") and may support other digital assets in the future. USDC and any other digital assets supported by Link Balance NCW are referred to collectively as "Supported Digital Assets" and individually as a "Supported Digital Asset." Supported Digital Assets do not include fiat currency.

·USDC is issued by Circle and is designed to maintain a value of one U.S. dollar per USDC, but its market price may be higher or lower. The amount you receive when converting, selling, or withdrawing USDC may differ because of market conditions, liquidity, fees, and the applicable exchange rate. Link does not guarantee that any Supported Digital Asset will maintain a particular value, remain liquid or available, or be convertible or redeemable at any particular price.

1111. No Deposit Insurance

·You acknowledge that your Link Balance NCW service is not a bank account or a deposit account. Supported Digital Assets accessed with your Link Balance NCW are not legal tender, are not backed by any government, and are not insured by the Federal Deposit Insurance Corporation (FDIC) or any other governmental agency.

1212. Taxes

·Transactions involving Supported Digital Assets may have tax consequences. You are responsible for determining and satisfying any tax obligations that apply to your use of Link Balance NCW, including any applicable reporting and payment obligations. Tax laws relating to digital assets may change. This section does not limit any reporting, withholding, or other obligations imposed on Link or a service provider by applicable law.

1313. Operation of Digital Asset Protocols

·Link does not own or control the underlying software protocols which govern the operation of the Supported Digital Assets. Link assumes no responsibility for the operation of the underlying protocols and does not guarantee the functionality or security of network operations. In particular, the underlying protocols may be subject to sudden changes in operating rules (including "forks"). Any such changes may materially affect the availability, value, functionality, or name of the Supported Digital Assets accessed through Link Balance NCW.

1414. Payment Service Partners

·Link may use a third-party payment processor to process withdrawals of fiat currency to your local bank account following the conversion of your Supported Digital Assets through Link Balance NCW. Link may add or change third-party payment processors used to provide Link Balance NCW services at any time.

1515. Suspension, Termination, and Closure

·Link may suspend, restrict, or terminate your access to Link Balance NCW through Link in accordance with these terms, including for security reasons, suspected misuse, or compliance with applicable law.

·Restriction or termination of access through Link does not transfer ownership of your Supported Digital Assets to Link or expand Link's authority over them. It may, however, affect your ability to use Link's interface, authentication, or other features. Before closing your Link Account, you should transfer your Supported Digital Assets or complete the export process and confirm that you can access your wallet independently. Closing your Link Account does not itself transfer your Supported Digital Assets, erase blockchain records or revoke permissions previously granted.

1616. Verification Procedures

·Link is required to identify users registering for and using certain functionality of Link Balance NCW. This ensures Link remains in compliance with applicable KYC/AML laws, which is necessary to continue offering Supported Digital Asset and Link Balance NCW services to our customers. Link may require you to provide or verify additional information, engage in enhanced due diligence, or to wait some amount of time after completion of a transaction, before permitting you to use any Link Balance NCW service and/or before permitting you to engage in transactions.

11. Scope and Applicability

·These Link Consumer Prepaid Debit Card Terms of Service ("Virtual Card Terms") govern your use of the Link consumer prepaid debit card ("Link Virtual Card," "Link Prepaid Debit Card," or "Card") related services Stripe offers for your personal use as further described in Section 3 below (the "Consumer Prepaid Cardholder Services").

·Stripe works with one or more banks (each, an "Issuing Bank") to provide the Consumer Prepaid Cardholder Services. In connection with your use of the Consumer Prepaid Cardholder Services, the Issuing Bank directly issues your Card. You may access the Consumer Prepaid Cardholder Services through your Link Account. These Virtual Card Terms govern your relationship with Stripe only.

·Your Card is a consumer prepaid debit card. It is not a credit card or a gift card, and it does not provide any overdraft, line of credit, or other credit feature. Your ability to use the Card is limited to the available balance in your Link Balance (for the purposes of this section, Link Balance refers to both Link Balance (Custodial) and Link Balance NCW). The terms for participating in Link Balance are governed by the Link Balance Terms found here. Your Card is governed by the Issuing Bank Terms (defined below), which contain important information about your rights and obligations, including applicable fees, transaction limits, error resolution procedures, and liability protections for unauthorized transactions.

·To receive a Card, you must first agree to the Issuing Bank's cardholder terms found here ("Issuing Bank Terms"). Your continued use of that Card is subject to (a) those Issuing Bank Terms, (b) these Virtual Card Terms, (c) the Link Balance Terms, and (d) any other Link Consumer Services used in connection or combination with the Consumer Prepaid Cardholder Services. In the event of a conflict between these Virtual Card Terms and the Issuing Bank Terms regarding your Card, your rights under applicable federal or state law, or your rights to error resolution or protections for unauthorized transactions, the Issuing Bank Terms will control.

·If your agreement with the Issuing Bank terminates or if your Link Balance is closed, Stripe may restrict or terminate your access to the Consumer Prepaid Cardholder Services.

22. Eligibility

·To use the Consumer Prepaid Cardholder Services, you must:

  • ·Sign up for a Link Account or have an existing Link Account;
  • ·Sign up for Link Balance or be an existing user of Link Balance; and
  • ·Not use the Consumer Prepaid Cardholder Services for any purpose other than personal use.

·You may not use the Consumer Prepaid Cardholder Services if Stripe has previously suspended or terminated your Link Account, your access to any Link Consumer Service, or any agreement between you and Stripe.

·In connection with your request for a Card and use of the Consumer Prepaid Cardholder Services, Stripe, on behalf of the Issuing Bank, may collect your name, address, date of birth, Social Security number or tax identification number, and other information necessary to verify your identity as required by applicable law, including applicable requirements under the USA PATRIOT Act. You agree to provide accurate and complete information and to promptly update such information as necessary.

33. Stripe's Role and Relationship to Your Card Account

·Stripe provides the Consumer Prepaid Cardholder Services as the program manager. In that capacity, Stripe provides services on behalf of the Issuing Bank, including processing transactions, facilitating customer support, and providing technology and related services that enable you to access and use your Card.

·Stripe is not the issuer of your Card. Your Card is issued by the Issuing Bank. Stripe is not a bank and does not hold your funds. In performing services on behalf of the Issuing Bank, Stripe may, among other things:

  • ·Process and facilitate Card transactions, including authorization of transactions against the available balance in your Link Balance, clearing, and settlement;
  • ·Facilitate the error resolution and unauthorized transaction investigation processes described in the Issuing Bank Terms, including receiving your notices of error, conducting investigations, and applying provisional credits as required by applicable law;
  • ·Provide or facilitate customer support for the Consumer Prepaid Cardholder Services;
  • ·Collect identity verification information on behalf of the Issuing Bank;
  • ·Deliver required disclosures, notices, and other communications on behalf of the Issuing Bank;
  • ·Facilitate the delivery of periodic statements as required by the Issuing Bank Terms and applicable law;
  • ·Enable digital wallet functionality in connection with your Card, as described in the Issuing Bank Terms; and
  • ·Perform other services as described in these Consumer Prepaid Card Terms, the Issuing Bank Terms, or as otherwise required by applicable law.

·When Stripe performs services described in the Issuing Bank Terms, including error resolution and unauthorized transaction protections under the Electronic Fund Transfer Act and Regulation E, Stripe does so on behalf of and as an authorized agent of the Issuing Bank. Your rights under the Issuing Bank Terms and applicable law, including your rights to error resolution and protections for unauthorized transactions, are not limited, waived, or modified by these Virtual Card Terms.

44. Card Information and Transaction limits

·You will be able to view and manage information related to your Card on the Link app. Information that you will be able to view may include viewing or changing your PIN, viewing Card details, locking your Card, replacing your Card, and canceling your Card. Additional information can be found here.

·Your Card supports a maximum transaction limit which can be found here.

55. Suspension and Termination

·Termination by Us. Stripe may terminate these Virtual Card Terms, and Stripe may limit, suspend, change, or remove your access to the Consumer Prepaid Cardholder Services, including any feature or aspect of the Consumer Prepaid Cardholder Services, at any time for any reason. Stripe will take reasonable steps to notify you before taking any action that restricts your access to the Consumer Prepaid Cardholder Services. If in our sole judgment you fail, or Stripe suspects that you have failed, to comply with any term or provision of these Virtual Card Terms, Stripe may terminate these Virtual Card Terms at any time without prior notice to you and accordingly Stripe may terminate your access to the Consumer Prepaid Cardholder Services.

·Termination by You. You may terminate these Virtual Card Terms at any time and for any reason by terminating your access to the Consumer Prepaid Cardholder Services. Termination will be effective on the date that your access to the Consumer Prepaid Cardholder Services is terminated.

·Effect of Termination. Upon termination of these Virtual Card Terms, your right to access or use the Consumer Prepaid Cardholder Services immediately ceases, and all licenses and rights granted to you under these Virtual Card Terms automatically terminate. The disposition of any remaining available balance in your Link Balance following termination is governed by the Issuing Bank Terms and the Link Balance Terms, as applicable.

·Termination does not revoke any third-party payment authorizations or your obligation to satisfy any pending transactions. You acknowledge that, subject to applicable law, Stripe has no obligation to provide you with access to any data or information submitted through the Consumer Prepaid Cardholder Services after termination, except to the extent required by the Issuing Bank Terms or applicable law, including your right to obtain your transaction history as described in the Issuing Bank Terms.

·The following provisions will survive even after these Consumer Prepaid Card Terms terminate: Stripe's Role and Disclaimer of Warranties.

66. Disclaimer of Warranties

·You release Stripe from any claims, demands, and damages arising out of disputes relating to your use of the Consumer Prepaid Cardholder Services, including those disputes with other parties.

·We, our affiliates, and our respective agents and contractors make no warranties with respect to the products, services, or information provided by the Issuing Bank to you. You agree, with respect to any claim regarding the products, services, or information provided by the Issuing Bank to you, that Stripe is not responsible or liable for, and you release Stripe from all claims, demands, and damages, including but not limited to: (a) claims based on any inaccurate, incomplete, or out-of-date information offered by the Issuing Bank; or (b) claims about any third-party platform where you may interact with or purchase from.

·Notwithstanding the foregoing, nothing in this section limits, waives, or modifies: (a) any rights you have under the Issuing Bank Terms; (b) any rights or protections afforded to you under the Electronic Fund Transfer Act, Regulation E, or any other applicable federal or state consumer protection law; or (c) any obligation Stripe has to you when acting on behalf of the Issuing Bank, including with respect to error resolution, unauthorized transaction protections, and the delivery of required disclosures and periodic statements.

·Applicable law may limit or prohibit disclaiming the warranties referred to in the previous paragraphs, or impose obligations on Stripe that it cannot eliminate with these Virtual Card Terms. In those cases, this section does not restrict, exclude or modify any consumer rights.

·Scope and Applicability

·These terms ("Link Agentic Terms") apply if you authorize an Agent to access your Link Account. Link's agentic features allow you to enable your agent to make purchases on your behalf, to access your financial account data through financial insights, and provide authorization of Agent transactions to third-party merchants and services. By authorizing an Agent to connect to your Link Account, you agree to be bound by these Link Agentic Terms and any new features or tools that are added will also be subject to these Link Agentic Terms.

·Definition of Agent

·For the purposes of these Link Agentic Terms, "Agent" means any software, computer or other automated technology, including any such technology that operates through, in conjunction with, or by invoking other automated systems, platforms, APIs, or agents, whether or not you have direct control over or visibility into each intermediate system in the chain, that is capable of, designed for, or employed for the purpose of independently or semi-independently acting as your delegate, proxy, intermediary, or agent in any transactional or authorization activity or in accessing your financial account data, whether in a single transaction or across multiple ongoing transactions. Your Agent constitutes an "electronic agent" or equivalent concept as defined or recognized under the laws of your jurisdiction, including the Uniform Electronic Transactions Act (UETA) and similar statutes, and that transactions initiated or completed by your Agent are legally binding upon you.

·To allow Agents to initiate transactions on your behalf, you will need to authorize an Agent to connect to your Link Account. When you connect an Agent to your Link Account, you are authorizing Link to share your personal data with the Agent or artificial intelligence commerce platform it operates on to use the Agent's services and authorization activity on your behalf, which may include:

·(a) Account Information, such as your name, email address, and mobile phone number;

·(b) payment information, such as the name of your credit or debit cards and the last four digits of the card numbers, bank account names and last four digits of the account number, and billing address; (c) Shipping Information; and

·(d) information related to your order, such as information related to your purchase, order date, amount, and product details.

·You may also connect an agent to your Link Account to access your financial account data. The way your financial account data is accessed depends on how you connect your Agent. If you use a self-hosted Agent - meaning software or technology that you operate on your own device or through infrastructure you control - Stripe issues a credential to your device that authorizes access to your financial account data. Your Agent accesses your financial account data through your device using that credential, and Stripe's responsibility for that data ends when the credential is delivered to your device. If you connect a third-party Agent - meaning software or technology operated by a third party on your behalf - Stripe will share your financial account data directly with that Agent. When Stripe shares your financial account data with third-party Agents, they must be registered as Financial Connections data recipients and have accepted applicable terms with Stripe. We reserve the right to deny or revoke access to any third-party Agent that is not registered or does not comply with applicable terms.

·You acknowledge that:

  • ·you are authorizing an Agent to connect to your Link Account to (i) receive and transmit information necessary to complete a transaction; (ii) initiate, complete, and manage transactions with merchants on your behalf; (iii) access financial account data on your behalf; and/or (iv) authorize and verify Agent transactions to third party merchants and services;
  • ·the Agent may use personal data within your Link Account to complete transactions, including providing your personal data to the merchant in connection with the transaction;
  • ·once your personal data is shared with the Agent, the Agent's use of your data will be governed by the instructions, parameters, and settings you set for your Agent, and the Agent's privacy policy, if applicable. We are not responsible for the Agent's handling, use, storage, or disclosure of your personal data after it has been shared;
  • ·you are encouraged to review the Agent's privacy policy and security practices, as applicable, before authorizing the Agent to access your Link Account. You may withdraw your consent to the future sharing of personal data with an Agent at any time by disconnecting the Agent from your Link Account;
  • ·we will use all personal data we collect about you in accordance with the Link Privacy Policy. You acknowledge that the "prompts" or instructions you provide to the Agent, as well as your Agent's API calls and related metadata, Agent management information, and product information may be processed by Link to improve Link services, including but not limited to the interoperability between Link and the Agent;
  • ·you will use any credentials shared with you only for personal purposes, and will not use those credentials to build, operate, or distribute a commercial product or services that accesses financial account data other than your own; and
  • ·when you use an Agent, you are choosing to interact with generative artificial intelligence rather than a human representative to facilitate financial tasks.

·Approval of the Transaction Amount

·You are solely responsible for reviewing and approving the Spend Request for each transaction initiated by or through the Agent before it is completed, to the extent required. "Spend Request" means the dollar (or other currency) amount the Agent surfaces for your approval in response to your purchasing instruction. You may be required to approve Spend Requests using secure methods, such as biometric passkeys. You are responsible for all transactions completed through your Agent using your Link Account credentials.

·Agents may occasionally misinterpret instructions or provide inaccurate information about products or pricing, engage in a transaction that you did not intend, or populate inaccurate information within your Link Transaction History. You should review your Agent activity, Link Transaction History, and other financial statements regularly. If an Agent has engaged in a transaction that you did not intend, you may consider disconnecting the Agent from your Link Account at any time.

·You may disconnect an Agent from your Link Account at any time by:

·(a) Managing your connected applications or authorized Agents through your Link Account settings at app.link.com; or

·(b) Revoking the Agent's access through the Agent's own platform, to the extent such functionality is available.

·Upon disconnection, Link will no longer pass your personal data to the Agent, and the Agent will not have the ability to access your financial account data or initiate transactions on your behalf through your Link Account. Disconnection will not affect transactions that have already been approved or completed prior to disconnection. Disconnecting your account or deleting your personal data may not cancel or stop payments (or recurring payments) that you have already approved. A disconnected Agent will still have access to your previously-shared personal data and any financial account data that you have already given the Agent access to. Disconnecting an Agent from your Link Account does not disconnect your financial accounts from your Link Account. To manage access to your financial accounts, see the Financial Connections terms. You should reach out to the Agent or Agent platform for any requests to delete your personal data.

·You are Responsible for Your Agent

·Agent connectivity is provided on an "AS IS" basis. You are responsible for ensuring that you trust any Agent you authorize to access your Link Account. By connecting your Agent, you acknowledge that we do not control the logic and/or outcomes of your Agent, and you agree that your use of an Agent is subject to that Agent's terms of service, privacy policy, and security practices, if applicable. We assume no responsibility for and make no representations as to the terms of use and privacy and security practices employed by any Agent. As between you and Stripe, you are responsible for all Agent-initiated transactions as if you had taken the action yourself. Your connection of an Agent to your Link Account constitutes your authorization for the Agent to engage in transactions on your behalf, whether those transactions were intended by you or not; those transactions were caused by bugs, hallucinations and/or misinterpretations; or those transactions differ from your provided instructions; except in the case the transaction is the result of our technical failure or error. For the avoidance of doubt, transactions carried out by an Agent that you have authorized to connect to your Link Account will not be considered Unauthorized Transactions for the purposes of Section 9 of the Link Account Terms (Protection from Unauthorized Transactions (only for U.S. consumers)).

·We facilitate the connection between the Agent and your Link Account but do not control and are not responsible for the Agent's actions or recommendations, including but not limited to the accuracy or security of information the Agent presents to you and/or the Agent's use of your data. You are solely responsible for defining, monitoring, and if necessary, terminating your Agent's connectivity.

·You acknowledge that the Agent may send you communications independently and, if applicable, such communications are governed by the Agent's own terms and policies, if any.

·Our Role

·When you use an Agent to initiate a transaction on your behalf, we may charge or debit your selected payment method for the purchase with an Agent, which will be reflected in your card, bank, or payment method statement as "LNKAGNT*[merchant name]" or similar. When we charge or debit your selected payment method, we are providing a separate service to you that enables your Agent to procure and purchase goods or services from a merchant on your behalf. In some cases, this includes the creation of a separate payment method, and you will not receive your underlying card offers, benefits, or rewards. In such cases, we will use this separate payment method to initiate your purchase, and you will reimburse us for the purchase of goods and services we make on your behalf. Your payment to us satisfies your payment obligations to the merchant for your purchase of the goods or services.

·We do not have or receive possession or title to the goods or services. The merchant sells the goods or services to you. The merchant remains responsible for the goods and services you purchase using an Agent connected to your Link Account, and the merchant is responsible for fulfilling your order, providing you with an itemized receipt, liability relating to the merchant's products or services, compliance with applicable law, and any indirect taxes charged to you. You are responsible for reviewing and complying with the terms and conditions that apply to the merchant's products you purchase using an Agent connected to your Link Account.

·Refunds, Returns, Chargebacks

·To initiate a refund for a transaction made with an Agent on your behalf, you should start by contacting the merchant directly. To the extent necessary, we will provide as much information as possible to you and the merchant to facilitate resolution of your concern. You may also reach out to Link Support to initiate a refund request. Refunds for orders will be determined on a case-by-case basis and may be refused by us if there is evidence of fraud, refund abuse, or other misconduct as stated in our Link agent wallet Refund Policy. You should review the Link agent wallet Refund Policy and the refund policy of the merchant from whom you purchased your goods or services. We reserve the right to redirect you to the merchant, in which case the merchant's refund policy applies. Unless required by law, we do not provide refunds for unused subscriptions or if you changed your mind about an order.

·We will assess your refund requests based on the information you provide to us. We may at times request additional information from you regarding the purchase. If you do not provide the additional information within the time as reasonably requested, your refund may be denied. You may have additional rights as a consumer against the merchant if the goods or services purchased are significantly not as described, faulty, or not fit for purpose.

·To initiate a return, you must contact the merchant directly. Returns will be subject to the merchant's return policy, which varies by merchant.

·For product and delivery issues relating to your order, or any issues related to use of the product you purchased in your order, please contact the merchant directly. We do not provide product-related customer support services (e.g., how to use the product).

·If you do not recognize a charge from us on your payment method statement you can reach out to us here.

·Security

·You must not share your Link Account credentials (including your passkeys or one-time codes) directly with an Agent or its developer. Connections must be made only through the official Link authorization interface. We, our Affiliates, and respective agents may, at our discretion, decline, cancel, or refuse to initiate any transaction where we reasonably believe you did not approve the Spend Request, is fraudulent or unauthorized, illegal, or exposes us to unacceptable risk.

·To the extent you download or enable any functionality to connect your Agent to your Link Account, the functionality is provided "AS IS" and "AS AVAILABLE." To the maximum extent permitted by law, we do not make any, and expressly disclaim all, express and implied warranties and statutory guarantees with respect to downloaded or enabled functionality, and are not liable for any losses, damages, or costs you or others may suffer arising out of its use. This applies any time you connect a third party agent, platform, or app to your Link Account.

·Informational Purposes Only; Not Financial Advice

·When you authorize your Agent to access your financial account data to help you understand your spending and financial activity, any outputs or analyses your Agent generates based on your financial account data are informational only and do not constitute financial advice, investment advice, tax advice, or any other form of professional financial guidance. We do not review, verify, endorse, or take responsibility for your Agent's outputs or recommendations. You should consult a qualified financial professional before making financial decisions based on information provided by your Agent.

·We do not warrant the accuracy, completeness, or timeliness of any Agent outputs based on your financial account data.

·Financial Connections Terms

·We provide a Consumer Service that allows you to connect your financial accounts to easily share your financial account data with Stripe and our affiliates (and to the extent identified, our Business User with which you are interacting), so that you can receive better product experiences. These Financial Connections Terms, along with the Consumer Terms of Service, apply when you use this Consumer Service.

·When you interact with a Business User that has enabled this Consumer Service, we will ask you to connect one or more of your financial accounts. If you agree to connect your financial accounts with us, Stripe will collect data from those financial accounts (associated with the login information you provide) for account selection and as reasonably necessary to provide this Consumer Service. We will only provide the Business User with the data categories (and related insights) requested by the Business User for the specific accounts you choose to share with the Business User.

·Your financial account data is either provided directly by your financial institution, or collected by us or our third party partners by collecting, storing and using your login information (such as your username and password). We refer to these financial institutions and partners as "Data Sources." Finicity Corporation is one of our Data Sources, and their terms are available here and incorporated into these Financial Connections Terms by this reference. At your request, we may also make your financial account data available to you directly through Stripe products, tools, or channels you authorize.

·When you agree to connect your financial account using this Consumer Service, you consent to the collection, use, and retention of your financial account data (including personal data) for that financial account. Once connected to your financial account(s), we and our Data Sources will regularly collect, use, and store the following types of data from your financial accounts:

  • ·Account owner information, including contact information (such as your name and address);
  • ·Account balances, including current and pending balances;
  • ·Account details, including your account type and bank, and account numbers and related identifiers (e.g., routing numbers);
  • ·Account transactions, including balance, transaction date, payee, location, transaction, description, and amount.

·Among other things, we may use your data to:

  • ·Verify your financial account;
  • ·Facilitate the processing of your requested payments;
  • ·Mitigate fraud, financial loss, or other harm to you, our Business Users, and us;
  • ·Assess your eligibility for and offer you our other products or services;
  • ·Analyze, develop, and update this Consumer Service and our other products and services;
  • ·Provide you customer support;
  • ·Comply with law, and enforce our terms; and
  • ·For other purposes consistent with your consent and applicable law.

·For example, we may use your financial account data to decrease the likelihood that you are charged with insufficient funds fees or experience an ACH return and to assess your eligibility for and offer you Consumer Services that we or our affiliates provide. Please review the Financial Connections FAQs to learn more. We will use your personal data in accordance with our Privacy Policy.

·We will only provide the Business User the categories of financial account data (including related insights) that the Business User requests and with your permission. Please remember, however, that our Privacy Policy covers our privacy practices, and not our Business Users' privacy practices. Business Users may use your financial account data, for example, to verify that your account is valid and to check your account balance.

·In some cases, we and our Data Sources collect and store your financial institution login information, depending on the type of connection that we have with your financial institution. You authorize, and represent that you have the lawful right to authorize, us and our Data Sources to log into and access the data in your connected financial account(s) for the purposes described above. In order to provide you a better experience, you also authorize Stripe or our Data Sources to save, to remember, to trust or to take a similar action for account logins solely by Stripe or our Data Sources. We or our Data Sources may also be notified that account login is pending your action (such as your entry of a multifactor authentication code). We may prompt you to complete that action directly in your financial institution's application. This Consumer Service is not endorsed or sponsored by any financial institution whose account(s) are accessible through this Consumer Service, and we are not an agent of those financial institutions.

·We will only provide the Business User with the data categories (and related insights) requested by the Business User for the specific accounts you select to share with the Business User. Otherwise, we disclose your financial account data and login information only to our trusted service providers and to the Data Sources only as necessary to provide this Consumer Service. We have implemented security controls that are designed to safeguard your data. To learn more, please visit https://stripe.com/docs/security/stripe.

·If you want to disconnect your financial account from access by the Business User, you may do so through our disconnection form. Once your financial account has been disconnected, the Business User cannot access any subsequently refreshed financial account data from Stripe. Disconnecting your account or deleting your personal data from Stripe may not cancel or stop payments (including recurring payments) that you have already authorized. If you would like to request our Business User to cease debiting your account or to delete any copies of your data they obtained through this Consumer Service, please contact the Business User directly.

·Stripe typically does not collect additional information from your disconnected financial account. In some cases, however, our Data Sources (or your financial institution) do not enable us to cease collecting your financial account data until all accounts associated with the applicable login information have been disconnected. You can also use our disconnection form to request that we disconnect all accounts and to delete the financial account data we obtained (and associated login information, if we have collected them).

·You may choose for us to save your financial account for future use across our eligible Business Users, including when you check out on their websites and applications. When you authorize us to save your financial account to Link, you are signing up for Link and creating a Link Account, and we will collect and store certain personal data from you, such as your name, email address, and mobile phone number. Please see the Link Account Terms for more information about Link Accounts.

·Identity Terms

·If you agree to save your identity information to your Link Account or verify your identity using your Link Account, you may choose to use your Link Account to share your identity verification data in the future with Stripe or other eligible businesses (i.e., our Business Users). This identity verification data may include the personal data you provided (such as a photo of your driver's license or passport) and our verification results (including insights).

·We generate verification results by comparing the information you provide with information about you that we collect from our Business Users, partners, identity verification service providers, and publicly available sources. If you agree for us to verify your identity using your identity document and your photo, your verification results are based on the biometric identifiers we generate and store from your images. Learn More. Stripe will use this information as a controller to verify your identity.

·Stripe or Business Users may ask you to verify your identity for a number of reasons, including for compliance purposes, to confirm that you do not already have an account or that you are authorized to use a payment method. To the extent Stripe asks to verify your identity for its own purposes we may do so, including to comply with our own legal obligations, and for loss and fraud prevention and security purposes.

·An advantage of saving your identity information to, or verifying your identity with, your Link Account is that you may not need to go through the trouble of re-submitting your identity information for other Business Users in the future. Rather, you may be able to verify your identity more quickly and easily by providing consent to share the verification data you saved to your Link Account with specific Business Users. Before you agree to verify your identity with data saved to your Link Account, we will inform you whether your verification data will be used by Stripe or shared with that Business User. If you agree to share your verification data with a Business User, please note that Business User is an independent controller of your verification data, and the Business User's use of your data is subject to the Business User's privacy policy.

·If you want to delete your identity information from your Link Account, there are instructions for how to do so here. If you choose to delete your identity information from your Link Account, please note Stripe or the Business User may still have your verification data. If you would like to request the Business User to delete any copies of your personal data they obtained through this End User Service, please contact the Business User directly.

·When you purchase digital goods or digital services from a Business User that is stated as "Sold through Link" (each purchase, an "Order"), then these Sold through Link Terms and the Purchase Terms (below) apply to you. When you use Link to manage and receive support for your Orders, then the Buyer Services Terms below apply to you. The Consumer Terms of Service apply to these Sold through Link Terms and you should review those terms as well. Additional terms may apply to you based on your location as described in the Country or Region Specific Provisions. If you do not agree to these Sold through Link Terms or any of the additional terms stated to apply to you, please do not complete your Order.

·When you place an Order or use the Buyer Services (as described in the Buyer Services Terms below), these Sold through Link Terms control if there is a conflict with any Consumer Terms of Service or Link Account Terms. How we Use your Information

·You authorize us ("we", "us", "our", or "Stripe") and our affiliates to use your personal data that you provide to us in accordance with our Privacy Policy. In addition you also authorize us and our affiliates to use your personal data in connection with providing the Buyer Services to you, in connection with providing the Stripe Managed Payments Services to Business Users, and in connection with facilitating your Order from Business Users. We and our affiliates may access, use, store and disclose information you provide in connection with your Order, to: (i) comply with law, (ii) enforce these Sold through Link Terms, (iii) detect, prevent and address fraud, (iv) charge and collect indirect tax where required to do so, (v) respond to your support requests and address technical or security issues, and (vi) to protect our and our affiliates' rights, property and safety and those of Business Users and the general public. You authorize us and our affiliates to share all Order-related information, including your contact information (e.g., name, email address, phone number, etc.), billing and shipping address, payment information, tax identification number, and order details (e.g., order date, price, etc.) (collectively, "Order Data"), with the Business User and the Business User will have access to your Order Data. The Business User may make available your Order Data to you (e.g., in their own customer dashboard) and that Order Data will be used and stored in accordance with the Business User's privacy policy. Country or Regional Specific Provisions

·If the terms in this section that apply to you conflict with other terms in these Sold through Link Terms or the Consumer Terms, then the terms in this section control.

Country or Region where you are locatedAdditional or modified provisions that apply to you
Australia, New ZealandTo the extent that you purchase digital goods or digital services from a Business User that is stated as "Sold through Link," or use Buyer Services provided by Stripe, as a consumer within the meaning of the Australian Consumer Law as set out in the Competition and Consumer Act 2010 (Cth) or the New Zealand Consumer Guarantees Act 1993, you have certain rights and remedies (including consumer guarantee rights) that cannot be excluded, restricted or modified by agreement. Nothing in these Sold through Link Terms operates to exclude, restrict or modify the application of any implied condition, warranty or guarantee, or the exercise of any right or remedy, or the imposition of any liability under law where to do so would: (a) contravene that law; or (b) cause any section of these Sold through Link Terms to be void. The Disclaimer and Limitation of Liability Sections of these Sold through Link Terms do not apply to the extent any loss, claims, demands, and damages arise out of Stripe's breach of this Agreement, negligence, fraud or willful misconduct.
CanadaModifying "Purchase Terms" below: Sold Through Link, LLC, ("Link SMP") is a registered Payments Services Provider and provides Stripe Managed Payments services to Stripe Payments Canada Limited, which in turn facilitates your Order from the Business User.
European UnionIf you are a financial entity subject to the EU Digital Operational Resilience Act (DORA), and your Order is for an "ICT service" within the meaning of DORA, you are responsible for ensuring that the Business User's terms of service contain the contractual provisions required under DORA, if relevant. If you are a consumer under EU law, you have a right to cancel your Order during the cooling off period. The cooling off period is for 14 days from the date you receive access to or delivery of the product you purchased in your Order. To exercise this right, contact Customer Support and follow the instructions for requesting a refund and include "cooling off period" as the basis for your refund request.
IndonesiaDisclaimer of WarrantiesSubject to statutory consumer guarantees, which will apply irrespective of this disclaimer, the Consumer Services are provided "as-is" and without any representation or warranty, whether express or implied. We, our affiliates, and our respective agents, and contractors (together, the "Disclaiming Entities") and Business Users make no representation or warranty of any kind whatsoever (other than those implied by statute) with respect to the Consumer Services or the content, materials, information and functions we make accessible, and specifically disclaim all implied warranties of merchantability, fitness for a particular purpose, title and non-infringement. We do not promise that the Buyer Services will be uninterrupted, error-free, free from cyber attacks, or secure. Nothing in these Sold through Link Terms is intended to exclude or restrict any rights or remedies available to you under applicable laws, including but not limited to Law No. 8 of 1999 on Consumer Protection. In particular, mandatory statutory guarantees that apply to the products sold through Link by the Business User under an Order to consumers and the Buyer Services offered by us to consumers shall continue to apply. Nothing in these Sold through Link Terms is intended to exclude or restrict any rights or remedies available to you under applicable laws, including but not limited to Law No. 8 of 1999 on Consumer Protection. In particular, mandatory statutory guarantees that apply to the products sold through Link by the Business User under an Order to consumers and the Buyer Services offered by us to consumers shall continue to apply.Limitation of LiabilitiesThe Disclaiming Entities will not be liable to you in any circumstances for: (a) Loss of business, loss of goodwill, loss of opportunity, or loss of profit; or (b) Any loss that we could not have reasonably anticipated, except where such liability arises as a direct result of the Disclaiming Entities' gross negligence, fraud, or willful misconduct.
MalaysiaDisclaimer of WarrantiesSubject to statutory consumer guarantees, which will apply irrespective of this disclaimer, the Consumer Services are provided "as-is" and without any representation or warranty, whether express or implied. We, our affiliates, and our respective agents, and contractors (together, the "Disclaiming Entities") and Business Users make no representation or warranty of any kind whatsoever (other than those implied by statute) with respect to the Buyer Services or the content, materials, information and functions we make accessible, and specifically disclaim all implied warranties of merchantability, fitness for a particular purpose, title and non-infringement. We do not promise that the Consumer Services will be uninterrupted, error-free, free from cyber attacks, or secure. Nothing in these Sold through Link Terms is intended to exclude or restrict any rights or remedies available to you under applicable laws, including but not limited to the Consumer Protection Act 1999. In particular, mandatory statutory guarantees that apply to the products sold through Link by the Business User under an Order to consumers and the Buyer Services offered by us to consumers shall continue to apply. Nothing in these Sold through Link Terms is intended to exclude or restrict any rights or remedies available to you under applicable laws, including but not limited to the Consumer Protection Act 1999. In particular, mandatory statutory guarantees that apply to the products sold through Link by the Business User under an Order to consumers and the Buyer Services offered by us to consumers shall continue to apply. Limitation of LiabilitiesThe Disclaiming Entities will not be liable to you in any circumstances for: (a) Loss of business, loss of goodwill, loss of opportunity, or loss of profit; or (b) Any loss that we could not have reasonably anticipated, except where such liability arises as a direct result of the Disclaiming Entities' gross negligence, breach of contract, fraud, or willful misconduct.
United KingdomIf you are a consumer under UK law, you have a right to cancel your Order during the cooling off period. The cooling off period is for 14 days from the date you receive access to or delivery of the product you purchased in your Order. To exercise this right, contact Customer Support and follow the instructions for requesting a refund and include "cooling off period" as the basis for your refund request.
United StatesArbitration agreement. IF YOU ARE LOCATED IN THE UNITED STATES, YOU AGREE TO OUR ARBITRATION AGREEMENT, WHICH REQUIRES YOU TO RESOLVE DISPUTES BETWEEN YOU AND STRIPE ON AN INDIVIDUAL BASIS THROUGH ARBITRATION, PROHIBITS YOU FROM MAINTAINING OR PARTICIPATING IN A CLASS ACTION LAWSUIT, WAIVES YOUR RIGHT TO A JURY TRIAL, AND LIMITS THE TIME IN WHICH A CLAIM MAY BE BROUGHT. You also agree to the Link E-Sign Disclosure.

·Purchase Terms

·These Purchase Terms are part of the Sold Through Link Terms and apply when you are placing an Order. Stripe and its affiliates facilitating your ability to place an Order is a Consumer Service under the Consumer Terms of Service.

·Stripe's affiliate, Sold Through Link, LLC, ("Link SMP"), is a third party beneficiary of the Sold Through Link Terms.

·Stripe's Role.

·Link SMP provides Stripe Managed Payments services to the Business User. For tax purposes, Link SMP's sole supply to you is the product of the Business User. What this means is that when you place an Order, and your payment is successful, Link SMP enables you to get access to the product.

·The Business User remains responsible for the products that you purchase through Link SMP, including delivery (unless fulfilled by Link SMP), quality of goods, returns, accuracy, fraud, advertising, protection of intellectual property rights, liability relating to the Business User's products or services, and compliance with applicable law. You are responsible for reviewing and complying with the terms and conditions that apply to the products you purchase through an Order.

·Placing and Paying for Orders.

·When placing an Order, Link SMP will charge or debit your selected payment method for the Order, which will be reflected in your card, bank or payment method statement as a payment for your Order from "Link.com * [Business User name]" or similar. You may only pay with the payment methods accepted in the checkout, which may vary based on your location. Certain Orders may require the preauthorization of your payment method with the actual charge following the preauthorization, for example, Orders for subscriptions with an initial free trial period or preorders. If your payment method does not support preauthorizations, then your payment method will be charged when the Order is placed. The payment method you use to purchase your Order will be used for ongoing subscription payments.

·Link SMP or its affiliates may request and collect any of the following information to calculate appropriate indirect taxes (sales taxes, VAT, GST, etc.) for Orders: your billing information, shipping information, and tax identification number. Link SMP or its affiliates may use Order Data for fraud, security and product improvement reasons. Payment for your Order will be processed by affiliates of Link SMP using the payment method you select at checkout. Your payment to Link SMP or its affiliates satisfies your payment obligations to the Business User for your Order. Where your Order is subject to indirect taxes, you are responsible for payment of such indirect taxes, which are collected by Link SMP or its affiliates as part of the payment for your Order where Link SMP or its affiliates are required to do so.

·You, and not Link SMP or its affiliates, are responsible for any fees or surcharges applied by your bank or payment method used related to the transactions processed for Orders (such as foreign transaction fees or cross border fees). Buyer Services, such as Link customer support services, cannot assist you with disputes related to these fees or surcharges.

·Declined or Cancelled Orders.

·Link SMP and its affiliates may decline or cancel any Order if it or they reasonably believe there is suspected fraud, security risk or violation of Stripe terms or policies. Link SMP and its affiliates also reserve the right to decline or cancel abnormal Orders, Orders based on actual or suspected errors, or any Orders which Link SMP or its affiliates suspects are made in bad faith. For Orders cancelled on the basis of actual or suspected error, Link SMP will refund the amount you actually paid. If your Order exceeds a quantity limitation for the product being purchased, Link SMP and its affiliates may decline or cancel your Order.

·Customer Support For issues relating to your Order please reach out to us at https://support.link.com/topics/sold-through-link. We reserve the right to redirect you to the Business User. For any issues related to use of the product you purchased in your Order please contact the Business User directly. We do not provide product-related customer support services (e.g., how to use the product).

·Returns and Refunds You may reach out to Customer Support to initiate a refund request. Refunds for Orders will be determined on a case by case basis and may be refused by Link SMP if there is evidence of fraud, refund abuse, or other misbehavior as stated in our refund policy. You should review the Link SMP Refund Policy and the refund policy of the Business User from whom you placed your Order. In the event the refund policy of the Business User you placed an Order with is more restrictive than our refund policy, our refund policy will control. Unless required by Law, we do not provide refunds for unused subscription periods or if you changed your mind about an Order.

·We will assess your refund requests based on the information you provide to us. We may at times request additional information from you in relation to the Order. If you do not provide the additional information within the time as reasonably requested, your refund may be denied.

·You may have additional rights as a Consumer against the Business User if products purchased through your Order are significantly not as described, faulty or not fit for purpose. Subscription Migration

·Link SMP reserves the right to transfer or assign your subscriptions that you purchased through an Order to an affiliate, and such affiliate will assume the responsibilities and obligations of Link SMP under these Purchase Terms.

·If requested by the Business User from whom you purchased one or more subscriptions through an Order, Link SMP may transfer or assign such subscriptions to that Business User upon providing you notice ("Transfer Notice"). The Transfer Notice will state the date of the transfer or assignment of the applicable subscriptions, and any other relevant information. You authorize and consent to the transfer of your subscription as described in the Transfer Notice. Unless otherwise stated in the Transfer Notice, all of our and Link SMP obligations under these Sold through Link Terms will terminate immediately on the date of the Transfer Notice.

·If a Business User transfers or assigns your subscription to us and Link SMP ("Subscription Transfer"), then, from that Subscription Transfer date, you acknowledge and agree that: (a) your subscription with the Business User is now deemed a completed Order, (b) you authorize Link SMP to charge or debit your selected payment method for the Order, and (c) you agree to be bound by these Sold through Link Terms. Currency Selection

·Link SMP may present you with the choice of making payment for an Order in either Link SMP's default currency ("Default Currency"), or your local currency as predicted by Link SMP ("Local Currency") (the "Adaptive Pricing Services"). Payment in your Local Currency is optional, and you can choose to pay for your Order in the Default Currency. The exchange rate applied to convert Default Currency for a particular Order into Local Currency is received from Link SMP's third-party providers, and includes a markup to guarantee your exchange rate during checkout ("Applicable Exchange Rate").

·For Orders that you have elected to pay in Local Currency, involving: A. one-time purchases, the Applicable Exchange Rate is determined at the time the payment total is displayed in Local Currency on the final checkout page. B. subscriptions, the Applicable Exchange Rate is determined on every payment date of your subscription billing cycle by using the Local Currency equivalent of the Default Currency price for that payment date. As a result, you may be charged different amounts in Local Currency on each subscription payment because the Applicable Exchange Rate can vary. To change your chosen payment currency for a subscription, you must cancel your existing subscription and resubscribe.

·Link SMP does not impose any other fees, taxes or charges, however, your card issuer may charge you additional fees. If you decide to refund an Order that you paid for in Local Currency, the same Applicable Exchange Rate will apply to the refund.

·The Adaptive Pricing Services do not exchange one currency for another, and can only be used to make payment for an Order. Link SMP can change the terms and conditions for the Adaptive Pricing Services at any time. The terms in effect at the time of your payment will apply to that transaction.

·Buyer Services Terms

·We provide services to you that enable you to manage and receive support in a single global portal for your Orders as part of your Link Account (the "Buyer Services"). Except as stated otherwise in these Buyer Services Terms, we provide you with post-Order services that include access to your transaction history, receipts, Order-related customer support, customer support in disputes between you and a Business User for any Order, and a process for requesting refunds.

·These Buyer Services Terms are part of the Sold through Link Terms, and, along with the Consumer Terms of Service and Link Account Terms, apply when you use the Buyer Services through a Link Account. The Link Account Terms apply to the Buyer Services and you should review those terms as well.

·Your Use of Buyer Services.

·You may access the Buyer Services for your Orders by signing up for Link and creating a Link Account. If you have an existing Link Account, the Buyer Services will automatically be added to your existing Link Account. If you do not have an existing Link Account, you can create a Link Account and have the option (but not the requirement) to save your payment information for an accelerated checkout experience across Link Merchants. If you elect not to save your payment information then we will not use cookies to recognize your device for an accelerated checkout experience at Link Merchant's website. The Buyer Services only apply to Orders from Business Users selling through Link SMP.

·Your access to and use of the Buyer Services does not change your relationship with the Business User, third party services or platforms, or with your bank or credit or debit card company. Connecting Orders to your Link Account

·Orders can only be connected to your Link Account if the email address on the Order and the email address used for your Link Account are exactly the same. Buyer Services are only available for Orders successfully connected to your Link Account. Managing your Link Account

·Your Link Account is considered active if you have an ongoing subscription Order for a product that is managed through the Buyer Services. You must provide to us valid and current information about yourself when requested by us or our affiliates within the time specified in the request.

·Disputes, Returns, Refunds and Customer Support for Orders

·For any disputes, returns, and refund issues related to your Order, refer to the Customer Support and Returns and Refunds sections of the Purchase Terms above. Subscription Management

·To change, manage, or cancel a subscription that you purchased through an Order, please do so via your Link Account at Link.com. You should review the Business User's subscription policy. If you submit a request to delete your Link Account, any ongoing subscriptions that you purchased through an Order will be cancelled upon deletion of your Link Account. You are responsible for any cancellation fees or other penalties imposed by the Business User for cancellation of the subscription.