19,182 words, 708 clausesupdated September 28, 2026read 08/10/2026source
| The Stripe Services Agreement governs the use of Stripe by our business users. It is divided into General Terms, which apply to every user, and product-specific Service Terms, which only apply based on the specific services you use.Read more about the Stripe Services Agreement and its structure in our Overview & FAQs.For informational purposes only, we have translated the Stripe Services Agreement into selected languages. |
|---|
| Read more about the changes made September 28, 2026. |
·The Stripe Services Agreement (the "Agreement") is an agreement between you or the entity you represent ("User") and the applicable Stripe entity specified in Section 12 (Definitions) ("Stripe") and governs User's access to and use of the Services and Stripe Technology. The Agreement consists of the General Terms, which contain the terms that apply to all Services and Stripe Technology, all Service Terms, which apply to User's use of specific Services and Stripe Technology, and any other terms incorporated into the Agreement. Capitalized terms are defined in Section 12 (Definitions), Service Terms, and inline. The Regional Terms in Section 13 (Regional Terms) apply based on User's Stripe Account Country.
·This Agreement is effective when User first accesses or uses the Services or Stripe Technology (the "Effective Date") and continues until User or Stripe terminates it under Section 10.1 (Suspension and Termination) or other provision allowing for termination (the "Term").
·If you are accepting the Agreement on behalf of User, you represent that you have full authority to legally bind User to this Agreement. If User is a sole proprietor, both User and Representative agree to be bound by the terms of the Agreement.
·Disputes between User and Stripe are subject to a class action waiver and will be resolved by individual binding arbitration, except as stated otherwise in this Agreement. Please read the arbitration provision in Section 11.4 (Dispute Resolution; Agreement to Arbitrate) as it affects User's rights under this Agreement.
·Last modified: September 28, 2026
1.11.1 Services.
·Stripe (and its Affiliates, as applicable) will make the Services available to User, and if applicable, give User access to a Stripe Dashboard. Stripe may enable certain Services or features on User's behalf which User may disable by contacting Stripe, or, where available, opting out within the Stripe Dashboard or API. User must use the Services solely for User's Business Purposes and in compliance with the Documentation.
1.21.2 Restrictions.
·(a) General Restrictions. User must not, and must not enable or allow any third party to:
·(i) use the Services for personal, family, or household purposes;
·(ii) circumvent any technical limitations of the Services or enable functionality that is disabled or prohibited, or access or attempt to access non-public Stripe systems or data;
·(iii) use the Services to engage in any activity that is fraudulent, deceptive, exploitative, or harmful;
·(iv) perform or attempt to perform any action that interferes with the operation of the Services or affects other Stripe users' use of Stripe services;
·(v) rent, lease, or otherwise transfer User's rights granted under Section 1.1 (Services) to a third party;
·(vi) copy, reproduce, republish, upload, post, transmit, resell, or distribute in any way, any part of the Services, Documentation, or the Stripe Website except as Law permits;
·(vii) attempt to create a Stripe Account on behalf of or for the benefit of a user whose use of the Stripe services was suspended or terminated by Stripe, unless Stripe approves otherwise;
·(viii) act as service bureau or pass-through agent for the Services with no added value to Customers; or
·(ix) use the Services to conduct a Prohibited or Restricted Business, transact with any Prohibited or Restricted Business, or enable any individual or entity (including User) to operate or benefit from any Prohibited or Restricted Business, unless Stripe has pre-approved the respective Prohibited or Restricted Business in writing.
·(b) Age Restrictions. Only people 13 years of age or older may open a Stripe Account and use the Services and Stripe Technology. If User or User's Representative is not 18 years of age or older (or the age of majority where User resides):
·(i) User must add a Representative who is an adult (which may be a parent or legal guardian) to User's Stripe Account;
·(ii) both User and Representative agree to be bound by the terms of the Agreement; and
·(iii) Representative agrees to be responsible and liable for User's actions in its Stripe Account and User's compliance with this Agreement.
1.31.3 Support.
·Stripe will provide User with standard technical support for issues relating to User's Stripe Account and use of the Services through support channels and Documentation that Stripe makes available on the Stripe Website. Stripe also offers optional paid support plans that may include priority support and response times that exceed the standard technical support. Stripe is not obligated to provide support to Customers.
1.41.4 Preview Services.
·Stripe may make a Preview Service available to User. Stripe will indicate to User, via the Stripe Dashboard, Stripe Website, or otherwise, whether a Service, or part of it, is a Preview Service. Stripe may specify additional requirements or use restrictions that apply to User ́s use of Preview Services in Preview Service Terms or Documentation. Unless Stripe otherwise agrees in writing, User's use of Preview Services is confidential, and User will provide timely Feedback on the Preview Services if requested by Stripe. Stripe may add or remove features of the Preview Services, or suspend or terminate User's access to Preview Services at any time. By their nature, Preview Services may be feature-incomplete, unstable, or contain bugs, and use of the Preview Services is at User's own risk and discretion. User should not use Preview Services in a production environment unless User understands and accepts the limitations of the Preview Service. Stripe may communicate Fees for a Preview Service in writing outside of the Stripe Pricing Page. Notwithstanding anything else in this Agreement, to the maximum extent permitted by Law, Stripe provides no warranty, indemnity, or support for Preview Services. Stripe's aggregate liability for Preview Services is limited to the lesser of the total Fees paid by User to Stripe (excluding all pass-through fees levied by Financial Providers) during the 12 month period before the first event giving rise to liability and USD $1,000.
1.51.5 Modifications; Updates.
·(a) Modifications. Stripe may modify or discontinue any aspect of the Services or Stripe Technology, including imposing conditions on use of the Services or Stripe Technology or ceasing to offer a Service or Stripe Technology in a specific country or region. Stripe will provide User reasonable notice if the modification or discontinuation would materially reduce the functionality of a Service or Stripe Technology that User is then using, except where Stripe determines such notice would (i) create or increase a security risk for Stripe, its users, or its Financial Providers; or (ii) cause Stripe (or its Affiliates, as applicable) to violate Law or breach an obligation to a Governmental Authority or Financial Provider.
·(b) Updates. Stripe is not obligated to provide any Updates, but may do so at its discretion. If Stripe makes an Update available, User must implement it by the deadline stated in Stripe's notice. If no deadline is stated, then User must implement the Update within 30 days of the notice date.
1.61.6 Third-Party Services.
·Stripe may reference, allow User to access, or promote Third-Party Services. User's use of any Third-Party Service is subject to that Third-Party Service's terms of use and privacy policies, and is at User's sole risk. Stripe does not approve, endorse, or recommend any Third-Party Services to User and disclaims all responsibility and liability for use of any Third-Party Service.
1.71.7 AI Agent.
·If User uses an AI Agent to access the Stripe Services, User is solely responsible for each action initiated by or through the AI Agent. User acknowledges that: (a) an AI Agent constitutes an "electronic agent" or equivalent concept as defined or recognized under the Uniform Electronic Transactions Act (UETA) and similar Laws; and (b) actions initiated or completed by an AI Agent are legally binding on User.
2.12.1 License.
·Subject to this Agreement, Stripe (or its Affiliates, as applicable) grants User a limited, worldwide, royalty-free, non-exclusive, non-transferable (except as allowed under Section 11.10 (Assignment)), non-sublicensable, revocable license during the Term to use the Stripe Technology solely (i) as necessary to use the Services, (ii) for User's Business Purposes; and (iii) in compliance with Law, this Agreement and the Documentation. The Stripe Technology is licensed, not sold, to User by Stripe (or its Affiliates, as applicable). The terms of this Agreement will govern all updates, upgrades, new versions, and replacements unless an update is accompanied by a separate license, in which case the terms of that license will govern.
2.22.2 Exclusions.
·The license granted in this Section does not allow User to, and User agrees not to, use or run the Stripe Technology in any way other than in accordance with this Agreement and the Documentation. User may distribute elements of the Stripe Technology identified by Stripe as "distributable", if any, as long as User does so solely in binary or object code form and subject to the terms of an end user license agreement at least as protective of Stripe and its licensors as the terms of this Section. User must not use Stripe Technology in a manner that creates an obligation to (i) disclose, distribute or make Stripe Technology available in source code form; (ii) license Stripe Technology for the purpose of making modifications or derivative works; or (iii) redistribute Stripe Technology at no charge. User must not remove, obscure, modify or otherwise tamper with notices (including trademark, copyright and other proprietary notices) or legends contained in any Stripe Technology.
2.32.3 Third-Party Software.
·User acknowledges that open source software included in the Stripe Technology may grant User additional rights. If there is a conflict between an open source license and this Agreement regarding open source code, the applicable open source license terms supersede the conflicting terms of this Agreement. Portions of the Stripe Technology may utilize third-party software and other copyrighted material.
2.42.4 Modifications and Reverse Engineering.
·Except to the extent that the following restriction is not permitted under Law, User must not (and User must not enable or allow any third party to) decompile, reverse engineer, disassemble, attempt to derive the source code of, decrypt, tamper, translate, modify, or create derivative works of all or any part of the Stripe Technology or any services provided by Stripe. User agrees not to remove, obscure, or alter any proprietary notices (including trademark and copyright notices) that may be affixed to or contained within the Stripe Technology.
2.52.5 Transfer.
·User must not rent, lease, lend, sell, share, redistribute, or sublicense the Stripe Technology, or enable others to do so, in each case unless expressly permitted under this Agreement or otherwise authorized by Stripe in writing.
·Stripe is entitled to rely on any instruction or action taken within User's Stripe Account. User must ensure that its Stripe Account is not used or modified by anyone other than User and its authorized representatives, and will use commercially reasonable efforts to prevent the unauthorized access, disclosure, or use of its Stripe Account Credentials. If User believes that its Stripe Account Credentials have been wrongly accessed, disclosed, or used, User must promptly notify Stripe and cooperate fully, including by providing any information Stripe reasonably requests. Any action or inaction by Stripe will not diminish User's responsibility for the security of its Stripe Account Credentials or for any unauthorized access, disclosure, or use of them. User is solely responsible for any losses, damages or costs that User or others may suffer arising out of or relating to hacking, tampering, or unauthorized access of the Services, User's Stripe Account, or Protected Data, or User's failure to use or implement anti-fraud or data security measures, except to the extent that those losses, damages, or costs are caused by Stripe's gross negligence, fraud, or willful misconduct.
4.14.1 Data Processing Agreement.
·Each party will comply with the DPA, including the Data Transfers Addendum, which is incorporated into this Agreement by this reference. The DPA sets out the parties' respective obligations and responsibilities regarding Personal Data processing in connection with the Services.
4.24.2 Stripe Data.
·User will use Stripe Data only as expressly permitted by this Agreement or other written agreements between Stripe and User (or their Affiliates).
4.34.3 Data Incident Notification.
·If User experiences a Data Incident that is reasonably likely to impact Stripe or its Affiliates, User must notify Stripe without undue delay, which will be no later than 48 hours, after becoming aware of the Data Incident. In this notice, User shall provide Stripe with the following information: (a) the type of Personal Data that was the subject of the Data Incident; (b) the categories and potential number of individuals or records affected (including their countries); and (c) the status of User's investigation and current or planned remediation.
4.44.4 Retention of Data.
·Stripe is not obligated to retain data that it receives from or through User after the Term, except as (a) required by Law; (b) reasonably required for Stripe to perform any post-termination obligations; (c) this Agreement otherwise states; or (d) the parties otherwise agree in writing.
4.54.5 Third Party Data User Provides.
·If User enables Services or functionality that provide Stripe access to data, including Personal Data and Content, from User's third party service providers ("Third Party Data"), then User authorizes Stripe to access and use the Third Party Data, and User must obtain all necessary rights and consents from the applicable individuals and third parties sufficient to enable Stripe to lawfully collect, use, retain, and disclose the Third Party Data. Stripe will use Third Party Data as this Agreement describes and to (a) secure, provide, and update the Stripe services, (b) comply with Law and Financial Provider requirements, and (c) prevent and mitigate fraud, financial loss, and other harm. User must not provide Protected Health Information to Stripe as part of Third Party Data. User is liable for any disclosure of Protected Health Information to Stripe when User provides access to the Third Party Data.
4.64.6 Controls.
·Each party will maintain commercially reasonable administrative, technical, and physical safeguards designed to protect data in its possession or under its control from unauthorized access, accidental loss, and unauthorized modification. Stripe will comply with its obligations in the Data Security Exhibit.
4.74.7 Stripe Output Data.
·User's use of Stripe Output Data is limited to User's own internal business purposes and for its intended purpose as may be described in the applicable Service Terms or Documentation. User must not use Stripe Output Data: (a) as the sole input into User's decision making process (e.g., automated decision making, profiling) about engaging, ceasing to engage, or refraining from engaging in a business relationship with any Customer; (b) as a factor in determining a person's eligibility for credit, insurance, housing or employment; or in any way that could cause Stripe to be a "consumer reporting agency" (as defined in FCRA) or cause the Stripe Output Data to constitute a "consumer report" (as defined in FCRA) or any comparable concept under Law; (c) to discriminate based on race, gender, or other protected characteristics, or take any "adverse action" (as defined in FCRA); (d) in a manner that constitutes a prohibited AI practice under the EU AI Act or in a manner that would cause Stripe to be characterized as a provider or co-deployer of a high-risk AI system; or (e) to develop, test, validate, train, enhance or deploy any machine learning models or algorithms that are a substitute for, or substantially similar to, the Services. User must not sell (including, as defined in the CCPA), rent, transfer, make available, or communicate orally or through other means Stripe Output Data. User must delete Stripe Output Data promptly upon Stripe's reasonable written request.
5.15.1 Ownership; Intellectual Property Rights.
·(a) IP Rights. As between the parties, Stripe, its Affiliates, and its third party licensors own all IP Rights in the Services, the Stripe Technology, Stripe Data, the Stripe Marks, the Documentation, and the Stripe Website. All rights not expressly granted in this Agreement are reserved.
·(b) Reservation of Rights. Nothing in this Agreement assigns or transfers ownership of any IP Rights to the other party, or contemplates a joint development of intellectual property.
·(c) Rights and Permissions. User will ensure that User's use of the Services and Stripe Technology will not violate or infringe upon any third-party rights, including IP Rights. If User provides Content to Stripe, User agrees that it has obtained, as applicable, all necessary rights and permissions to share the Content and enable Stripe's use of the Content. User grants to Stripe, on behalf of itself and its Affiliates, a perpetual, worldwide, non-exclusive, irrevocable, royalty-free license to use the Content to develop, improve, and provide Services and Stripe Technology and for Stripe's internal business purposes.
5.25.2 Feedback.
·During the Term, User may provide Feedback to Stripe and its Affiliates, which Stripe may use without restriction or obligation. Feedback is voluntary and User grants to Stripe, on behalf of itself and its Affiliates, a perpetual, worldwide, non-exclusive, irrevocable, royalty-free license to use that Feedback for any purpose.
5.35.3 Marks Usage.
·(a) License Grant. Subject to this Agreement, each party (or its applicable Affiliates) grants to the other party a worldwide, non-exclusive, non-transferable (except as allowed under Section 11.10 (Assignment)), non-sublicensable (except to its Affiliates and Financial Providers (as applicable)), royalty-free license during the Term to use the granting party's Marks solely to provide the Services to User and to identify Stripe as User's service provider. All goodwill generated from the use of the grantor party's Marks will inure to the sole benefit of the Mark owner.
·(b) Stripe's Permitted Uses of User's Marks. Stripe and its Affiliates may refer to User as a user of Services in their financial disclosure documents. Stripe and its Affiliates may use User's Marks:
·(i) on Stripe webpages and apps that identify Stripe's customers or users;
·(ii) in Stripe sales and marketing materials and communications; and
·(iii) in connection with any promotional activities to which the parties agree in writing.
·When using User's Marks, Stripe must comply with the usage terms or guidelines that User provides to Stripe in writing (if any).
·(c) User's Permitted Uses of Stripe Marks. When using Stripe's Marks, User must comply with the terms located at https://stripe.com/legal/marks/ and all additional usage terms and guidelines that Stripe provides to User in writing (if any).
6.16.1 Use; Protection.
·Stripe and User (each, a "Recipient") will use reasonable care, and no less than the same degree of care that the recipient uses to protect its own confidential information of a similar nature, to prevent the unauthorized disclosure of the other party's (the "Discloser") Confidential Information.
6.26.2 Permitted Disclosures.
·A Recipient may disclose Confidential Information only to its and its Affiliates' directors, employees, contractors, agents, professional advisors, and third-party auditors who have a legitimate need to know it and are subject to confidentiality obligations at least as protective as this Agreement. Additionally, Stripe may disclose User's Confidential Information to Financial Providers, their respective Affiliates, and Stripe's third-party service providers as reasonably necessary to perform the Services. 6.3 Required Disclosures
·A Recipient may disclose Confidential Information if required by Law, subpoena, or court order, or if directed by a Governmental Authority. Subject to Stripe's obligations under the DPA, Recipient will use reasonable efforts to provide Discloser with advance notice of the required disclosure (if permitted by Law). Any assistance provided by Recipient to help Discloser contest the disclosure will be at Discloser's sole expense.
6.46.4 Exclusions.
·These confidentiality obligations do not apply to information that: (a) is or becomes publicly available through no fault of the Recipient; (b) was known or possessed without restriction prior to receipt from the Discloser; (c) was received from a third party without breach of confidentiality obligations; or (d) was independently developed without using the Discloser's Confidential Information.
7.17.1 Stripe Fees.
·(a) Fees. The Fees are as listed on the Stripe Pricing Page, unless User and Stripe otherwise agree in writing, including via click-through agreement. Unless User and Stripe otherwise agree in writing or if Law requires, payment obligations are non-cancelable and Fees paid are non-refundable.
·(b) Subscriptions. Subscription Services are governed by the terms of the applicable Subscription Plan. If User exceeds the entitlement scope in the Subscription Plan, then except as stated otherwise in the Subscription Plan or agreed in writing between the parties, Stripe will charge User for the increased scope of use according to the Fees stated on the Stripe Pricing Page.
·(c) Updates to Fees and Subscription Plans. Subject to the requirements of Law, Stripe may revise the Fees and Subscription Plans at any time. Stripe will provide User with at least 30 days' notice of any increase in a Fee or any new Fees for any Service that User is using, or any materially adverse change in a Subscription Plan.
·(d) Fee Waivers. Stripe may offer a Service without charge, or waive a Fee for that Service, and may start charging a Fee for that Service upon at least 30 days notice (or longer period if Law requires) to User. Taxes may still be collected on waived Fees.
·(e) Trials and Promotions. Stripe may make certain Services available to User on a trial or promotional basis free of charge, or at a discount, until (i) the expiration or termination of the trial or promotion, at which point the Fees stated on the Stripe Pricing Page will apply, or (ii) the start of any Subscription Plan that User has purchased, at which point that Subscription Plan will automatically commence. Trials and promotions may be subject to additional Taxes, terms and conditions, as communicated to User by Stripe.
·(f) Fee Credits. If User receives a Fee Credit, then the Stripe Fee Credit Terms apply to the Fee Credit.
7.27.2 Collection of Fees and Other Amounts.
·(a) User must pay, or ensure that Stripe is able to collect, Fees, Taxes, and other amounts User owes to Stripe under this Agreement, or under any other agreement with a Stripe Entity, when due.
·(b) Stripe may collect all amounts owed by User by deducting them from User's Stripe Account balance, charging User's primary Payment Method (e.g., a credit card), or invoicing User for those amounts.
·(c) If a Stripe Entity is unable to collect any amounts due by a User Entity to a Stripe Entity, or if a User Entity's Stripe Account balance is negative or does not contain funds sufficient to pay the amounts due by the User Entity to a Stripe Entity, then Stripe or its Affiliate may, to the extent Law permits, deduct, recoup or setoff these amounts from any of the following: (i) if established and applicable, a Reserve of any User Entity; (ii) funds payable by a Stripe Entity to a User Entity; (iii) the Stripe Account balance of a User Entity; (iv) each User Bank Account (if any); and (v) a backup User-selected Payment Method.
·(d) If the currency of the amount being deducted is different from the currency of the amount User owes, Stripe may deduct an amount equal to the amount owed (using Stripe's conversion rate), together with the fees Stripe incurs in making the conversion.
·(e) If Stripe believes it transferred funds to User in error, Stripe may deduct, recoup or setoff those funds in accordance with this Agreement.
7.37.3 Taxes.
·(a) Exclusion of Taxes. The Fees exclude all Taxes, except as the Stripe Pricing Page or other documents expressly state to the contrary.
·(b) User's Tax Responsibilities. User has sole responsibility and liability for:
·(i) determining which, if any, Taxes or fees apply to the sale of its products and services, acceptance of donations, or payments it receives in connection with its use of the Services; and
·(ii) assessing, collecting, reporting, and remitting Taxes for its business to the appropriate tax and revenue authorities.
·(c) Payment of Taxes.
·(i) If Stripe is required by Law to collect or withhold any Taxes, Stripe may deduct those Taxes from the amount otherwise owed to User or charge those Taxes, as the case may be, and pay those Taxes to the appropriate taxing authority. If User is exempt from paying, or is otherwise eligible to pay a reduced rate on, those Taxes, User may provide to Stripe a copy of the original certificate that satisfies applicable legal requirements attesting to its tax-exempt status or reduced rate eligibility, in which case Stripe will not deduct the Taxes that certificate covers.
·(ii) User must provide accurate information regarding its tax affairs as Stripe reasonably requests, and must promptly notify Stripe if any information that Stripe prepopulates is inaccurate or incomplete. Stripe may send documents to User and Governmental Authorities for transactions processed using the Services; specifically, Stripe may be required under Law to file periodic informational returns with Governmental Authorities related to User's use of the Services. User agrees that Stripe may send tax-related information electronically to User.
7.47.4 User Bank Account.
·If Stripe requires User to link a User Bank Account with Stripe in connection with User's use of the Services, then:
·(a) User must: (i) designate at least one User Bank Account in connection with the Services, (ii) be the named account holder of each User Bank Account, (iii) maintain each User Bank Account in a country approved by Stripe for Bank Account maintenance, and (iv) maintain authorization to initiate settlements to and debits from each User Bank Account, consistent with Section 7.5 (Debit Authorization).
·(b) User must not grant or assign to any third party any lien on or interest in funds that may be owed to User related to this Agreement until the funds are deposited into a User Bank Account.
7.57.5 Debit Authorization.
·Without limiting Section 7.2 of these General Terms, User authorizes Stripe to debit and credit each User Bank Account without separate notice, and according to the applicable User Bank Account Debit Authorization, to collect amounts User or another User Entity owes under this Agreement. If Stripe is unable to collect those amounts by debiting a User Bank Account, then User immediately grants to Stripe a new, original authorization to debit each User Bank Account without notice and according to the applicable User Bank Account Debit Authorization. Stripe may rely on this authorization to make one or more attempts to collect all or a subset of the amounts owed. User's authorization under this Section will remain in full force and effect until (i) all User Entity Stripe Accounts are closed; or (ii) all fees and other amounts User owes under this Agreement are paid, whichever occurs later. If applicable debit scheme authorization rules grant User the right to revoke User's debit authorization, then to the extent Law permits, User waives that right.
8.18.1 Nature of Claims and Failure of Essential Purpose.
·The exclusions and limitations in this Section 8 (Limitation of Liability) apply regardless of the legal theory or form of action and will survive and apply even if any limited remedy in this Agreement fails of its essential purpose.
8.28.2 Disclaimers.
·Stripe provides the Services and Stripe Technology "as is", and to the maximum extent permitted by Law, Stripe does not make any, and disclaims all, warranties (other than those stated as a "warranty" in this Agreement) and statutory guarantees, the implied warranties of fitness for a particular purpose, merchantability and non-infringement, and the implied warranties arising from any course of dealing, course of performance or usage in trade. Stripe does not warrant that User's use of the Services and Stripe Technology will be uninterrupted or error-free or that User's use of the Services and Stripe Technology comply with Law. Stripe is not liable for delays, failures or problems inherent in use of the internet and electronic communications or other systems outside Stripe's control.
8.38.3 Limitation on Indirect Liability.
·Except for Excluded Claims, to the maximum extent permitted by Law, neither party will have any liability in relation to this Agreement for any indirect, consequential, special, reliance, incidental, or punitive damages, lost revenue, profits, savings or goodwill, business interruption, personal injury, property damage, or loss of data, whether in contract, negligence, strict liability, tort, or other legal or equitable theory, even if these losses, damages, or costs are foreseeable, and whether or not any party has been advised of their possibility.
8.48.4 Liability Cap.
·Except for Excluded Claims, a party's total aggregate liability for damages and Losses arising out of or relating to the Agreement is limited to the total Fees paid by User (excluding all pass-through fees levied by Financial Providers) during the 12 month period before the first event giving rise to liability. User's payment obligations, including Fees, Assessed Fines and Taxes are not limited by this Section 8.4.
9.19.1 Indemnities.
·(a) General Indemnities. Subject to Section 9.2 (Limitations on Indemnity), User will indemnify Stripe, its Affiliates, and their directors, employees, and agents for all Losses arising from User's use of the Services or Stripe Technology, gross negligence, willful misconduct, fraud, or material breach of the Agreement.
·(b) IP Indemnities.
·(i) Indemnity. Subject to Section 9.2 (Limitations on Indemnity), each party will indemnify the other party, its Affiliates, and their directors, employees, and agents for all Losses, to the extent they arise from an IP Claim, except that this indemnification obligation does not apply if the indemnified party uses the Materials in combination with other materials not provided by the indemnifying party (if the Materials the indemnifying party provided would not infringe absent the combination).
·(ii) Remedial Actions. If an IP Claim arises, the indemnifying party may, at its sole discretion and expense (i) modify the Materials it provided to be non-infringing, replace them with non-infringing alternatives, or obtain a license for the indemnified party to continue using the Materials; or (ii) upon 30 days' notice, terminate the indemnified party's use of the infringing Materials.
·(iii) Exclusive Remedies. This Section 9.1(b) states the indemnifying party's entire liability to the indemnified parties, and the indemnified parties' sole and exclusive rights and remedies, with respect to an IP Claim.
9.29.2 Limitations on Indemnity.
·An indemnifying party's obligations under Section 9.1 do not apply to the extent that the Claim or Losses arise out of an indemnified party's negligence, fraud, willful misconduct, or breach of this Agreement.
9.39.3 Defense of Claims.
·If the indemnified party seeks to enforce an indemnity under this Agreement, it must promptly notify the indemnifying party of the applicable Claim and allow the indemnifying party to take exclusive control of its defense and settlement. The indemnified party must cooperate with and provide reasonable assistance to the indemnifying party in conducting such defense and settlement, at the indemnifying party's expense, and will not take any actions that prejudice the defense. The indemnifying party will control the defense (including choice of counsel) and settlement at its expense, but will not enter into any settlement that imposes any obligation on the indemnified party (other than payment of money, which the indemnifying party must pay) without the indemnified party's prior written consent. An indemnified party's delay or failure in notifying the indemnifying party of a Claim will not relieve the indemnifying party of its indemnity obligations, except to the extent the indemnifying party has been prejudiced by such delay or failure.
10.110.1 Suspension and Termination.
·(a) Termination by User.
·(i) Termination for Convenience. User may terminate this Agreement at any time by closing its Stripe Account via the Stripe Dashboard.
·(ii) Termination for Cause. User may terminate this Agreement immediately upon notice to Stripe if Stripe materially breaches this Agreement and, if capable of cure, does not cure the breach within 10 days after receiving notice specifying the breach.
·(b) Suspension and Termination by Stripe.
·(i) Suspension. Stripe may immediately suspend User's access to the Stripe Technology and use of any or all of the Services if:
·(1) Stripe reasonably believes that by providing the Services to User, Stripe or User has violated, or is reasonably likely to violate, any Law or Governmental Authority requirement or directive or, if applicable, Financial Provider Terms or Financial Provider directive;
·(2) User experiences an Insolvency Event;
·(3) User breaches this Agreement or any other agreement between the parties;
·(4) Stripe reasonably believes User's acts or omissions degrade, or may degrade, the security, privacy, stability or reliability of the Stripe services, Stripe Technology or any third party's system (e.g., User's involvement in a distributed denial of service attack);
·(5) Stripe reasonably believes User is engaged in a business or activity that may be unlawful, enables or facilitates (or may enable or facilitate) illegal or prohibited transactions, may be harmful to a third party, or otherwise presents an unacceptable risk to Stripe;
·(6) Stripe reasonably believes User's activity increases, or may increase, the rate of fraud that Stripe observes;
·(7) User does not promptly respond to Stripe's request for, or fails to provide, User Information; or
·(8) User does not promptly update its implementation of the Services or Stripe Technology to the latest production version Stripe recommends or requires.
·(ii) Termination.
·(1) Termination for Convenience. Unless otherwise agreed in writing, Stripe may terminate this Agreement or close User's Stripe Account at any time. Stripe will notify User in accordance with Law.
·(2) Termination for Cause. Stripe may immediately terminate this Agreement or revoke access to any part of the Services or Stripe Technology if (A) User materially breaches this Agreement and, if capable of cure, does not cure the breach within 10 days after receiving notice specifying the breach; (B) User experiences an Insolvency Event and Law allows for termination; (C) any event listed in Section 10.1(b)(i) of these General Terms occurs; or (D) Law requires, or a Governmental Authority or Financial Provider directs Stripe to do so. Stripe will notify User in accordance with Law.
10.210.2 Effect of Termination.
·Upon termination of this Agreement, User's rights to use the Services and the Stripe Technology immediately cease. User must immediately cease accessing the Services and delete all license keys, access keys and copies of Stripe Technology. In no event will termination relieve User of its obligation to pay any amounts payable to Stripe for the period prior to the effective date of termination. Unless stated to the contrary, termination of this Agreement will not affect any other agreement between the parties or their Affiliates.
10.310.3 Survival.
·The following will survive termination of this Agreement:
·(a) User's obligation to pay Fees;
·(b) Sections 3 (Stripe Account Security), 5.1 (Ownership; Intellectual Property Rights), 5.2 (Feedback), 7 (Fees; Taxes; User Bank Account), to the extent applicable to Services provided or to Transactions submitted during the Term, 8 (Limitation of Liability), 9 (Indemnification), 10.2 (Effect of Termination),11.2 (Notices and Communications), 11.3 (Governing Law), 11.4 (Dispute Resolution; Agreement to Arbitrate), 11.7 (Entire Agreement), 11.8 (Modification), 11.9 (Order of Precedence), 11.10 (Assignment), 11.11 (Severability), 11.12 (Waivers), 11.13 (Force Majeure), 11.14 (No Agency), 11.15 (Cumulative Rights; Injunctions), 11.17 (Interpretation), 12 (Definitions), to the extent used in a surviving clause, 13 (Regional Terms);
·(c) Section 4 (Privacy and Data Use), for so long as Stripe or User holds Stripe Data or Personal Data, as applicable;
·(d) the DPA, for so long as Stripe holds Personal Data or Protected Data, except for provisions regarding a Data Incident where User is the data custodian, which will survive for as long as User holds Stripe Data or Personal Data; and
·(e) trade secrets, indefinitely, and all other confidentiality obligations, for 3 years after the date of termination.
11.111.1 Compliance with Law.
·Each party must comply with all Laws applicable to its business in its performance of obligations or exercise of rights under this Agreement. User is solely responsible for evaluating and configuring the Services to comply with User's legal obligations.
11.211.2 Notices and Communications.
·Notices to Stripe. Except as may be required by Applicable Law or unless this Agreement states otherwise, for notices to Stripe, contact Stripe. A notice User sends to Stripe is deemed to be received when Stripe receives it.
·Communications to User. User consents to electronic communications as described in the E-SIGN Disclosure, which is incorporated into this Agreement by this reference. Stripe also may send User Communications by physical mail or delivery service to the postal address listed in the applicable Stripe Account. A Communication Stripe sends to User is deemed received by User on the earliest of (i) when posted to the Stripe Website or Stripe Dashboard; (ii) when sent by text message or email; and (iii) three business days after being sent by physical mail or when delivered, if sent by delivery service.
11.311.3 Governing Law.
·This Agreement and any disputes between User and Stripe will be governed by, and construed in accordance with, the Governing Law as specified in the Regional Terms, without giving effect to its conflict of law principles.
11.411.4 Dispute Resolution; Agreement to Arbitrate.
·(a) Binding Arbitration.
·(i) Claims Subject to Arbitration. Except as stated otherwise in Section 11.4(a)(ii) or the Regional Terms, all disputes, claims, and controversies, whether based on past, present, or future events, including those arising out of or relating to statutory or common law and the breach, termination, enforcement, interpretation, or validity of any provision of this Agreement, will be determined by binding arbitration by a single arbitrator.
·(ii) Claims Not Subject to Arbitration. All disputes, claims, and controversies principally related to a party's IP Rights will be resolved by litigation. The parties submit to the non-exclusive jurisdiction of the courts specified in the Regional Terms for these disputes, claims, and controversies.
·(iii) Non-waiver of Arbitration. Making claims with law enforcement or governmental enforcement agencies, exercising any self-help remedies (such as setoff rights), or seeking injunctive relief or provisional remedies in aid of arbitration from a court of appropriate jurisdiction, does not constitute a waiver of any right to compel arbitration.
·(iv) Procedural Matters. Arbitration will be conducted in English. The Regional Terms specify the seat of the arbitration and the applicable arbitration rules and procedure.
·(v) Provision of an Award. Subject to the limitations of liability in this Agreement, the arbitrator may award monetary damages and any other remedies allowed by the Governing Law. The arbitrator will not have the authority to modify any term or provision of this Agreement. The arbitrator will deliver a reasoned, written decision with respect to the dispute to each party.
·(vi) Final and Binding. Any award will be final and binding on the parties and will be deemed to have been made at the seat of arbitration, and each party will act promptly in accordance with the award.
·(vii) Enforcement. Any award (including interim or final remedies) may be confirmed in or enforced by any court having jurisdiction over either party or its assets, including the courts identified in the jurisdiction and venue provision in the Regional Terms.
·(b) Notice of Disputes. Before commencing arbitration, the party asserting a claim must send a written notice of dispute to the other party. All dispute notices to Stripe must be sent to notices@stripe.com. All dispute notices to User must be sent to the email address listed on the applicable Stripe Account. All notices must (i) provide User's name, email address, mailing address, and Stripe account ID (if any); (ii) describe the nature and factual and legal basis of the dispute; and (iii) detail the specific relief sought. If User appoints an attorney to submit its notice, User must provide written authorization allowing Stripe to discuss User's dispute and account details with User's attorney. Stripe may require User (or User's attorney) to verify User's identity and confirm User's authorization to disclose account information. User will cooperate with any reasonable verification request. After notice of arbitration is provided, the parties will meet for the purpose of resolving the dispute and, if the dispute is not resolved within 30 days of the notice, then a party may commence arbitration in accordance with the applicable rules.
·(c) Confidentiality of Arbitration. The parties will keep confidential the existence of the arbitration, the details of the arbitration proceeding, the hearing, and the arbitrator's decision except: (i) as necessary to prepare for and conduct the arbitration hearing; (ii) in connection with a court application for a preliminary remedy, confirmation, vacatur, or modification of an arbitrator's award; (iii) the Stripe Parties may disclose the arbitrator's decision in confidential settlement negotiations related to other disputes; (iv) as necessary to professional advisers that are subject to a strict duty of confidentiality; and (v) as Law otherwise requires. The parties, witnesses, and arbitrator will treat as confidential and will not disclose to any third person (other than witnesses or experts) any submissions, documentary, or other evidence produced in any arbitration, except as Law requires or if the evidence was obtained from the public domain or was otherwise obtained independently from the arbitration.
·(d) Conflict of Rules. In the case of a conflict between the provisions of this Section 11.4 and the applicable arbitration rules specified in the Regional Terms, the provisions of this Section 11.4 will prevail.
11.511.5 Legal Fees and Costs.
·In any dispute, litigation, arbitration, or other legal proceeding arising out of or relating to this Agreement, the arbitrator or court will award to the prevailing party, if any, its reasonable attorneys' fees and costs incurred in connection with such proceeding. Notwithstanding the foregoing, if User is liable for any amounts owed under this Agreement, User is also liable for all costs incurred by the other party (including but not limited to Stripe, if applicable) during collection of those amounts. Such collection costs include reasonable attorneys' fees and expenses, costs of any arbitration or court proceeding, collection agency fees, applicable interest, and any other related costs.
11.611.6 Trade Control.
·User must not use or otherwise export, re-export, or transfer the Stripe Technology except as authorized by United States law and the laws of the jurisdiction(s) in which the Stripe Technology was distributed and obtained, including by providing access to Stripe Technology (a) to any individual or entity ordinarily resident in a High-Risk Jurisdiction; or (b) to any High-Risk Person. By using the Stripe Technology, User represents and warrants that User is not (i) located in or organized under the laws of any High-Risk Jurisdiction; (ii) a High-Risk Person; or (iii) owned 50% or more, or controlled, by individuals and entities (x) located in or, as applicable, organized under the laws of any High-Risk Jurisdiction; or (y) any of whom or which is a High-Risk Person. User must not use the Services or Stripe Technology for any purposes prohibited by Law, including the development, design, manufacture or production of missiles, nuclear, chemical, or biological weapons.
11.711.7 Entire Agreement.
·The Agreement, together with any separate written agreement relating to Fees, constitutes the entire agreement and understanding of the parties with respect to the Services, and supersedes all prior and contemporaneous agreements and understandings.
11.811.8 Modification.
·Stripe may modify this Agreement (or any portion of it) at any time by posting a revised version of the modified portion(s) on the Stripe Legal Page or by notifying User. The modified Agreement is effective upon posting or as stated in the notice, if Stripe notifies User. By continuing to use Services after the effective date of any modification to this Agreement, User agrees to be bound by the modified Agreement. User is responsible for checking the Stripe Legal Page regularly for modifications to this Agreement. Except as this Agreement otherwise allows, this Agreement may not be modified except in writing signed by the parties.
11.911.9 Order of Precedence.
·If any term in these General Terms conflicts with a term in any Service Terms or terms incorporated by reference into this Agreement, then unless terms of lower precedence expressly state to the contrary, the order of precedence is: (a) the Service Terms; (b) these General Terms; and (c) all terms incorporated by reference into this Agreement.
11.1011.10 Assignment.
·User may not assign or transfer any of its rights or obligations under this Agreement without Stripe's prior consent (which consent will not be unreasonably withheld or delayed). However, User may assign this Agreement in its entirety to its successor resulting from a merger, acquisition, or sale of all or substantially all of User's assets or voting securities, provided that (i) User provides Stripe with prompt written notice of the proposed assignment, (ii)the assignee agrees in writing to assume all of User's obligations under this Agreement, and (iii) the assignee complies with Stripe's procedural and documentation requirements to give effect to the assignment. To request Stripe's consent to assign this Agreement, please contact Stripe. Any attempt by User to transfer or assign this Agreement, except as expressly authorized above, will be void. Stripe and its Affiliates may assign and transfer its rights and obligations under this Agreement (in whole or in part) without User's consent. This Agreement will be binding on, inure to the benefit of, and be enforceable by the parties and their permitted assigns.
11.1111.11 Severability.
·If any court or Governmental Authority determines a provision of this Agreement is unenforceable, the parties intend that this Agreement be enforced as if the unenforceable provision were not present and that any partially valid and enforceable provision be enforced to the extent that it is enforceable.
11.1211.12 Waivers.
·A waiver must be in writing signed by the waiving party to be effective. A party's failure to enforce any provision of this Agreement will not constitute a waiver of that party's rights to subsequently enforce the provision.
11.1311.13 Force Majeure.
·Neither party will be liable for any failure or delay in performance to the extent caused by a Force Majeure Event. Nothing in this Section 11.13 will excuse User's payment obligations to Stripe.
11.1411.14 No Agency.
·Each party to this Agreement, and each Financial Provider (if applicable), is an independent contractor. Nothing in this Agreement serves to establish a partnership, joint venture, general agency, trust, or fiduciary relationship between Stripe and User, or with any Financial Provider. If this Agreement expressly establishes an agency relationship between User as principal and a Stripe Entity as agent, the agency conferred, including User's rights as principal and a Stripe Entity's obligations as agent, is limited strictly to the stated appointment and purpose and implies no duty to User, or a Stripe Entity, and will in no event establish an agency relationship for tax purposes. User further acknowledges that Stripe will not be subject to any fiduciary duties or obligations to User or to any other person, or any other duties or obligations except as expressly stated in this Agreement.
11.1511.15 Cumulative Rights; Injunctions.
·The rights and remedies of the parties under this Agreement are cumulative. Each party may exercise any of its rights or remedies under this Agreement, along with all other rights and remedies available to it at Law or in equity. Any material breach by a party of Sections 2, 4, 5, and 6 could cause the non-breaching party irreparable harm for which the non-breaching party has no adequate remedies at Law. Accordingly, the non-breaching party is entitled to seek specific performance or injunctive relief for the breach.
11.1611.16 Subcontractors and Affiliates.
·Stripe may use subcontractors or its Affiliates in the performance of its obligations under this Agreement. Stripe remains responsible for its overall performance under this Agreement and for having appropriate written agreements in place with its subcontractors and Affiliates to enable Stripe to meet its obligations under this Agreement.
11.1711.17 Interpretation.
·(a) No provision of this Agreement will be construed against a party on the basis of that party being the drafter.
·(b) References to "includes" or "including" not followed by "only" or a similar word mean "includes, without limitation" and "including, without limitation," respectively.
·(c) All references in this Agreement to any terms, documents, Law, or Financial Provider Terms are to those items as they may be amended, supplemented, or replaced from time to time. All references to APIs and URLs are references to those APIs and URLs as they may be updated or replaced.
·(d) The section headings of this Agreement are only for convenience and have no interpretive value.
·(e) Unless expressly stated otherwise, any consent or approval that may be given by a party (i) is only effective if given in writing and in advance; and (ii) may be given or withheld in the party's sole and absolute discretion.
·(f) References to "business days" means weekdays on which banks are generally open for business in the country in which Stripe is located. Unless specified as business days, all references in this Agreement to days, months, or years mean calendar days, calendar months, or calendar years.
·(g) Unless expressly stated to the contrary, when a party makes a decision or determination under this Agreement, that party has the right to use its sole discretion in making that decision or determination.
·(h) The United Nations Convention on Contracts for the International Sale of Goods will not apply to this Agreement.
·"Stripe" means the entity specified below for User's Stripe Account Country. Service Terms may address further additional or deviating Stripe entities for the respective Services.
| Country / Region | Stripe Contracting Entity |
|---|---|
| United States | Stripe, LLCStripe Payments Company* Canada | Stripe Payments Canada, Ltd.** | |
| Mexico | Stripe Payments Mexico, S. de R.L. de C.V.** |
| Brazil | Stripe Brasil Soluções de Pagamento - Instituição de Pagamento Ltda** |
| Other countries in the Americas, to the extent Stripe offers Services in these countries | Stripe, LLC |
·*This Stripe entity is an additional party to the Agreement if stated in the applicable Stripe Financial Services Terms, or in other applicable Service Terms.
·**Stripe, LLC is an additional party to this Agreement solely for the purposes of processing Personal Data under Section 4 (Privacy and Data Use) of this Agreement.
| Country / Region | Stripe Contracting Entity |
|---|---|
| Countries in the European Economic Area:Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden | Stripe Payments Europe, LimitedStripe Technology Europe, Limited* |
| Gibraltar, Switzerland, United Kingdom | Stripe Payments Europe, LimitedStripe Payments UK Ltd* |
| United Arab Emirates | Stripe Payments Europe, Limited |
| Other countries in Europe, Middle East and Africa, to the extent Stripe offers Services in these countries | Stripe Payments Europe, Limited |
·*This Stripe entity is an additional party to the Agreement if stated in the applicable Stripe Financial Services Terms, or in other applicable Service Terms.
| Country / Region | Stripe Contracting Entity |
|---|---|
| Australia | Stripe Payments Australia Pty Ltd.*** |
| Hong Kong | Stripe Payments Europe, Limited India | Stripe India Private Ltd.*** | |
| Indonesia | PT Stripe Payments Indonesia*** Japan | Stripe Japan, Inc.*** | |
| Malaysia | Stripe Payments Malaysia Sdn. Bhd.*** |
| New Zealand | Stripe New Zealand Limited*** |
| Singapore | Stripe Payments Singapore Pte. Ltd.*** |
| Thailand | Stripe Payments (Thailand) Ltd*** |
| Other countries in Asia Pacific, to the extent Stripe offers Services in these countries | Stripe Technology Company Limited*** |
·***Stripe Payments Europe, Limited is an additional party to this Agreement solely for the purposes of processing Personal Data under Section 4 (Privacy and Data Use) of this Agreement.
·"Affiliate" means an entity that directly or indirectly Controls, is Controlled by, or is under common Control with another entity.
·"AI Agent" means any software, computer or other automated technology, including any such technology that operates through, in conjunction with, or by invoking other automated systems, platforms, APIs or agents, whether or not User has direct control over or visibility into each intermediate system in the chain, that is capable of, designed for, or employed for the purpose of independently or semi-independently acting as User's delegate, proxy, intermediary, or agent in any transactional activity, whether in a single transaction or across multiple ongoing transactions.
·"API" means application programming interface.
·"Assessed Fines" means assessments, penalties, fines, and fees imposed by Governmental Authorities or Financial Providers arising out of or relating to the use of the Services.
·"Business Purpose" means the operational activities, functions, or objectives of User, including, but not limited to, activities relevant to carrying out its organizational, commercial, non-profit, or governmental mission.
·"CCPA" means California Consumer Privacy Act of 2018, Cal. Civ. Code Sections 1798.100-1798.199, and its implementing regulations.
·"Change of Control" means (a) an event in which any third party or group acting together, directly or indirectly, acquires or becomes the beneficial owner of, more than 50% of a party's voting securities or interests; (b) a party's merger with one or more third parties; (c) a party's sale, lease, transfer, or other disposal of all or substantially all of its assets; or (d) the entry into any transaction or arrangement that would have the same or similar effect as a transaction referred to in (a)-(c) of this definition; but, does not include an initial public offering or listing.
·"Claim" means any claim, demand, government investigation, or legal proceeding that a third party makes or brings against any indemnified party.
·"Communication" has the meaning given to it in the E-SIGN Disclosure.
·"Confidential Information" means all information disclosed by a party ("Disclosing Party") to the other party ("Receiving Party"), whether orally or in writing, that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure.
·"Content" means all text, images, and other data (excluding Personal Data) or information that Stripe does not provide to User and that User uploads, publishes, uses, or provides to Stripe in connection with the Services.
·"Control" means direct or indirect ownership of more than 50% of the voting power or equity in an entity.
·"Customer" means User's customer or donor.
·"Data Incident" means an unauthorized or unlawful processing, use, access, loss, disclosure, destruction, or alteration of Personal Data in a party's or its Affiliate's, or a party's or its Affiliate's subcontractor's, agent's, or representative's, possession or control.
·"Documentation" means the sample code, instructions, requirements, and other documentation (a) available on the Stripe Website, the first page of which is located at https://docs.stripe.com; and (b) included in the Stripe SDKs.
·"DPA" means the data processing agreement located at www.stripe.com/legal/dpa.
·"E-SIGN Disclosure" means the E-SIGN Disclosure terms found on the Stripe Website.
·"EU AI Act" means Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024, laying down harmonized rules on artificial intelligence, as amended or supplemented from time to time.
·"Excluded Claims" means: (a) a party's gross negligence, fraud, or willful misconduct; (b) User's breach of Section 1.2 (Restrictions); (c) a party's breach of Section 6 (Confidentiality), except that a breach arising from a Data Incident is not an Excluded Claim under this clause (c); or (d) amounts payable under Section 9.1 (Indemnities).
·"FCRA" means the Fair Credit Reporting Act, 15 U.S.C. § 1681, et seq., as amended.
·"Feedback" means ideas, suggestions, comments, observations, and other input regarding the Services and the Stripe Technology.
·"Fees" means the fees and charges applicable to the Services.
·"Financial Provider" means an entity that provides financial services and with which a Stripe Entity interacts to provide the Services.
·"Force Majeure Event" means an event beyond the reasonable control of the affected party, including a strike or other labor dispute or labor shortage, stoppage, or slowdown; supply chain disruption; embargo or blockade; cyberattack or other harmful third-party interference with information systems, including through the use of artificial intelligence; telecommunication breakdown; power outage or shortage; inadequate transportation service; inability or delay in obtaining adequate supplies; weather; earthquake; fire; flood; natural disaster; act of God; riot; civil disorder; civil or government calamity; epidemic; pandemic; state, national, or international health crisis; war; invasion; hostility (whether war is declared or not); terrorism threat or act; Law; or act of a Governmental Authority.
·"General Terms" means the preamble and Sections 1 through 13 of this Stripe Services Agreement.
·"Governmental Authority" means a regulator or other governmental agency or entity with jurisdiction over the Services, Stripe, or User, as applicable.
·"High-Risk Jurisdiction" means any jurisdiction or administrative region that Stripe has deemed to be of particularly high risk, as identified in Stripe's Prohibited and Restricted Businesses List.
·"High-Risk Person" means any individual or entity that Stripe has deemed to be of particularly high risk, as identified in Stripe's Prohibited and Restricted Businesses List.
·"Insolvency Event" means, with respect to a party, the occurrence or reasonable likelihood of any of the following (or any analogous procedure or step):
·(a) a party is unable to pay its debts or is deemed unable to pay its debts or is deemed unable to pay its debts as they fall due under applicable Law;
·(b) a party is the subject of an involuntary petition or proceeding for winding up, bankruptcy, liquidation, administration, or equivalent proceedings, which is not dismissed or stayed within 30 days;
·(c) a party passes a resolution or takes formal corporate action for its winding up, dissolution, liquidation, or administration (except for the purposes of a solvent amalgamation, reconstruction, or reorganization);
·(d) a party stops, or threatens to stop, carrying on all or substantially of its business;
·(e) a liquidator, receiver, administrator, or similar officer is appointed over the whole or a material part of a party's assets;
·(f) a party is the subject of a petition, application, or order for its administration, or a notice of intention to appoint an administrator is given, or any equivalent step is taken by any person under applicable Law with a view to the administration of a party;
·(g) the party enters into, or commences formal negotiations for, a composition, assignment, or restructuring arrangement with its creditors generally (or any class of them), due to actual or anticipated financial distress, or a moratorium is declared in respect of any of its indebtedness;
·(h) the appointment of, or any formal step taken to appoint, a liquidator, receiver, administrative receiver, administrator, or similar officer over a party or a material part of its assets (provided that any involuntary step or proceeding is not dismissed or stayed within 30 days);
·(i) any security is enforced, or any legal process (including execution, attachment, lien, or levy) is levied, against a material part of a party's assets and is not discharged or stayed within 30 days; or
·(j) any material subsidiary of a party is subject to any of the events listed in this definition.
·"IP Claim" means:
·(a) where Stripe is the indemnifying party, a Claim by a third party that the indemnified party's use of the Stripe Technology, Services, Stripe Marks, or any other Material that Stripe provided infringes the IP Rights of the third party; and
·(b) where User is the indemnifying party, a Claim by a third party that the indemnified party's use of the User Marks or any other Material that User provided infringes the IP Rights of the third party.
·"IP Rights" means all copyrights, patents, trademarks, service marks, trade secrets, moral rights, and other intellectual property rights recognized anywhere in the world.
·"Law" means all applicable laws, rules, regulations, and other binding requirements of any Governmental Authority.
·"Losses" means all amounts finally awarded or settled to the third party making a Claim, and all penalties, fines, and reasonable third-party costs (including reasonable legal fees) paid by the indemnified parties, to the extent arising from the Claim.
·"Mark" means a trademark, service mark, design mark, logo or stylized script.
·"Materials" means any software, hardware, documents, data, Marks, inventions, or other materials provided by a party.
·"Payment Method" means a payment method that Stripe accepts as part of the Stripe Payments Services (e.g., a Visa credit card, Klarna).
·"Payment Method Provider" means the provider of a Payment Method (e.g., Visa Inc., Klarna Bank AB).
·"Payment Method Rules" means the publicly available guidelines, bylaws, rules, and regulations a Payment Method Provider imposes that describe how a Payment Method may be accepted and used.
·"Personal Data" means any information relating to an identifiable natural person that is Processed (as defined in the Data Processing Agreement) in connection with the Services, and includes "personal data" as defined in the GDPR and "personal information" as defined in the CCPA.
·"Preview" means the product release phase "proof of concept", "alpha", "beta", "pilot", "invite only", "private preview", "private developer preview", "public preview", "developer preview", or similar designation.
·"Preview Service" means any Preview feature or portion of the Services or Stripe Technology.
·"Privacy Policy" means any or all of a publicly posted privacy policy, privacy notice, data policy, cookies policy, cookies notice, or other similar public policy or public notice that addresses a party's Personal Data practices and commitments.
·"Prohibited and Restricted Business List" means the list of Prohibited and Restricted Businesses accessible from the Stripe Legal Page.
·"Prohibited or Restricted Business" means any category of business or business practice for which a Service cannot be used or its use is limited (as applicable), as identified in Stripe's Prohibited and Restricted Businesses List.
·"Protected Data" means all User Information and Personal Data.
·"Protected Health Information" has the meaning given to the term "protected health information" in 45 CFR §160.103 (the US Code of Federal Regulations).
·"Regional Terms" means regional terms specified in this Agreement for User's Stripe Account Country. To the extent of a conflict, the Regional Terms prevail.
·"Representative" means an individual submitting User's application for a Stripe Account.
·"Reserve" means collateral funds which Stripe holds and controls to satisfy any liabilities or potential liabilities User incurs under this Agreement, including any funds described as "Reserve" amounts in the Reserve Notice, the Stripe Dashboard or in any other communications to User.
·"Service" means a service Stripe (or its Affiliate, as applicable) makes available to User, including any service described in the Service Terms. Service excludes all Third-Party Services.
·"Service Terms" means terms incorporated into this Agreement that apply to particular Services.
·"Stripe" has the meaning given to it above in this Section 12.
·"Stripe Account" means a Stripe account through which User accesses the Services.
·"Stripe Account Country" means the country or region User selected when opening User's Stripe Account and is the country or region where User's business address, as reflected in User's account details, is located, or, in the case of an individual, the country or region where User is doing business.
·"Stripe Account Credentials" means User's Stripe Account credentials, which includes the Stripe API keys.
·"Stripe API" means all instances of the Stripe application programming interfaces, including all endpoints that enable Stripe users to use Stripe services.
·"Stripe Consumer Terms of Service" means the Stripe Consumer Terms of Service accessible from the Stripe Legal Page.
·"Stripe Dashboard" means the interactive user interface through which a Stripe user may view information about and manage a Stripe Account.
·"Stripe Data" means data that User obtains via the Services, including (a) information relating to the Stripe API interactions via the Stripe Technology; (b) information Stripe uses for security or fraud prevention; and (c) all aggregated information Stripe generates from the Services.
·"Stripe Entity" means Stripe or any of its Affiliates.
·"Stripe Financial Services Terms" means the Stripe Financial Services Terms accessible from the Stripe Legal Page.
·"Stripe Legal Page" means www.stripe.com/legal.
·"Stripe Output Data" means any data User receives through the Stripe Services which has been produced or returned by or through the Services, including the Orchestrated Output Data and Stripe Radar Data.
·"Stripe Parties" means Stripe and its Affiliates, and the directors, employees, and agents of each Stripe Entity.
·"Stripe Pricing Page" means www.stripe.com/[countrycode]/pricing, where "[countrycode]" means the two-letter abbreviation for the country where a Stripe Account is located, and any other pages on the Stripe Website that are accessible from that page.
·"Stripe Technology" means all software (including software in the Stripe SDKs), application programming interfaces (including the Stripe API), user interfaces (including the Stripe Dashboard), and other technology that Stripe and its Affiliates use to provide and make the Services available.
·"Stripe Website" means www.stripe.com.
·"Subscription Plan" means a Subscription Service's entitlement scope, term length, and pricing plan, as stated on the Stripe Pricing Page, online sign-up page, Documentation, or as otherwise agreed between User and Stripe, including via the Stripe Dashboard.
·"Subscription Service" means a Service or combination of Services, as applicable, that User pays for on a recurring basis.
·"Taxes" means any applicable taxes and duties imposed by any Governmental Authority, including sales and use tax, excise tax, gross receipts tax, value-added tax (VAT), goods and services tax (GST) (or equivalent transaction taxes), and withholding tax.
·"Third Party Data" means data, including Personal Data and Content, from User's third party service providers.
·"Third-Party Service" means a service, product, or promotion provided by a third party that utilizes, integrates with, or is ancillary to the Services.
·"Transaction" means a Payment Method transaction request initiated via the Stripe Technology through which Stripe is directed to capture funds for or from a payer's associated account with respect to a payment from a Customer to User, and includes the authorization, settlement, and if applicable, Disputes, Refunds, and Reversals with respect to that Payment Method transaction request.
·"Update" means a modification, feature enhancement, or update to the Services or Stripe Technology that requires User to take some action, which may include changing User's implementation of the Services or Stripe Technology.
·"User Bank Account" means a bank or other financial institution account User designates to Stripe.
·"User Bank Account Debit Authorization" means a debit authorization on the terms specified at www.stripe.com/legal/bank-debit-authorizations.
·"User Compliance Information" means information about User that Stripe reasonably requires to comply with Law, and Governmental Authority and Financial Provider requirements, and may include information (including Personal Data) about User's representatives, beneficial owners, principals, and other individuals associated with User's Stripe Account.
·"User Entity" means an individual or entity that is part of the User Group (including you).
·"User Financial Information" means (a) information about User that Stripe reasonably requires to assess User's business and financial condition and outstanding credit exposure, including financial statements (and, where applicable, unaudited management accounts including a profit and loss account, balance sheet and cash-flow statement) and supporting documentation (including bank statements); (b) information and supporting documentation to enable Stripe to calculate User's risk of loss; and (c) all other information Stripe reasonably requests to assess User's risk and ability to perform its obligations under this Agreement.
·"User Group" means (a) User; (b) any entity or individual that Stripe reasonably determines is associated with User; and (c) each of User's and their Affiliates that has entered into an agreement with a Stripe Entity under which a Stripe Entity provides services.
·"User Information" means User Compliance Information and User Financial Information.
·The following Regional Terms apply for the countries or regions below. If there is a conflict between the General Terms and the Regional Terms, the Regional Terms prevail.
·If Stripe provides Services in countries not listed in this Section 13, then (i) for countries in the Americas, the Regional Terms for the United States apply, and (ii) for countries in the rest of the world, the Regional Terms for Ireland apply.
·The following Regional Terms apply for Users in the United States.
13.113.1 Governing Law.
·The laws of the state of California are the Governing Law.
13.213.2 Dispute Resolution.
13.2.113.2.1 Binding Arbitration.
·(a) Arbitration will be held in San Francisco, California.
·(b) The American Arbitration Association ("AAA") will administer the arbitration under the AAA's Commercial Arbitration Rules ("AAA Rules").
·(c) The arbitrator will apply the substantive law of the State of California and of the United States, excluding their conflict or choice of law rules.
·(d) Payment of applicable fees, including filing, administration, and arbitrator fees, will be governed by the AAA Commercial Arbitration Fee schedule.
·(e) The parties acknowledge that this Agreement evidences a transaction involving interstate commerce. Notwithstanding the provisions in Section 13.1 referencing applicable substantive law, the Federal Arbitration Act (9 U.S.C. Sections 1-16) will govern any arbitration conducted in accordance with this Agreement.
13.2.213.2.2 Jurisdiction and Venue.
·For any claims that relate to IP Rights, each party consents to exclusive personal jurisdiction in the United States District Court for the Northern District of California, and for all other claims that may not be subject to arbitration or to confirm an arbitrator's award, each party consents to exclusive personal jurisdiction in the federal courts for the Northern District of California and the state courts located in San Mateo County, California.
13.2.313.2.3 No Jury Trial.
·If for any reason a claim or dispute proceeds in court rather than through arbitration, to the extent Law permits, each party knowingly and irrevocably waives any right to trial by jury in any action, proceeding or counterclaim arising out of or relating to this Agreement or any of the transactions contemplated between the parties.
13.2.413.2.4 Class Waiver.
·To the extent Law permits, any dispute arising out of or relating to this Agreement, whether in arbitration or in court, will be conducted only on an individual basis and not in a class, consolidated or representative action. Notwithstanding any other provision of this Agreement or the AAA Rules, disputes regarding the interpretation, applicability, or enforceability of this class waiver may be resolved only by a court and not by an arbitrator. If this waiver of class or consolidated actions is deemed invalid or unenforceable, neither party is entitled to arbitration.
·The following Regional Terms apply for Users in the European Economic Area.
13.113.1 Governing Law.
·The laws of Ireland are the Governing Law.
13.213.2 Dispute Resolution.
13.2.113.2.1. Binding Arbitration.
·(a) Arbitration will be held in Dublin, Ireland.
·(b) The International Chamber of Commerce ("ICC") International Court of Arbitration will administer the arbitration under its ICC Rules ("ICC Rules").
·(c) The arbitrator will apply the laws of Ireland.
·(d) The arbitrator may be the same nationality as any of the parties, and must be a member of the Law Society of Ireland or the Bar of Ireland, unless the parties agree otherwise.
13.2.213.2.2 Claims not subject to Arbitration-Jurisdiction and Venue.
·For claims that may not be subject to arbitration, which includes claims that relate to IP Rights, each party consents to exclusive jurisdiction in the courts of Ireland.
13.2.313.2.3 No Class Action Waiver.
·The class action waiver in the preamble does not apply.
13.2.413.2.4 Insolvency Proceedings.
·Nothing in this Agreement will preclude Stripe from making any application or issuing any legal or insolvency proceeding in an appropriate court under insolvency laws in the User's jurisdiction.
·The following Regional Terms apply for Users in the United Kingdom, Switzerland and Gibraltar.
13.113.1 Governing Law.
·The laws of England and Wales are the Governing Law.
13.213.2 Dispute Resolution.
13.2.113.2.1. Binding Arbitration.
·(a) Arbitration will be held in London, England.
·(b) The International Chamber of Commerce ("ICC") International Court of Arbitration will administer the arbitration under its ICC Rules ("ICC Rules").
·(c) The arbitrator will apply the laws of England and Wales.
13.2.213.2.2 Claims not subject to Arbitration-Jurisdiction and Venue.
·For claims that may not be subject to arbitration, which includes claims that relate to IP Rights, each party consents to exclusive jurisdiction in the courts of England.
13.2.313.2.3 No Class Action Waiver.
·The class action waiver in the preamble does not apply.
13.2.413.2.4 Insolvency Proceedings.
·Nothing in this Agreement will preclude Stripe from making any application or issuing any legal or insolvency proceeding in an appropriate court under insolvency law in the User's jurisdiction.
13.313.3 Assignment.
·Stripe may novate or transfer this Agreement, or any rights and obligations under it, to any Stripe Affiliate without the User's prior written consent. Stripe may not novate or transfer this Agreement, or its rights and obligations under it, to any other party without the User's prior written consent, which must not be unreasonably withheld or delayed.
·The following Regional Terms apply for Users in Australia. 13.1 Governing Law
·The laws of the state of New South Wales are the Governing Law.
13.213.2 Dispute Resolution. 13.2.1 Binding Arbitration
·(a) Arbitration will be held in Sydney, New South Wales, Australia.
·(b) The Resolution Institute ("RI") will administer the arbitration under its RI Arbitration Rules ("RI Rules").
·(c) The arbitrator will apply the substantive law of the State of New South Wales and of Australia, excluding their conflict or choice of law rules. The parties acknowledge that this Agreement evidences a transaction involving interstate commerce. Notwithstanding the foregoing, the Commercial Arbitration Act 2010 (NSW) will govern any arbitration conducted in accordance with this Agreement.
·(d) The party initiating the arbitration is responsible for paying the applicable filing fee. Each party will advance one-half of the fees and expenses of the arbitrator, the costs of the attendance of a stenographer at the arbitration hearing, and the costs of the arbitration facility.
13.2.213.2.2 Claims not subject to Arbitration-Jurisdiction and Venue.
·For claims that may not be subject to arbitration, which includes claims that relate to IP Rights, each party consents to exclusive jurisdiction in courts of New South Wales, Australia.
13.2.313.2.3 No Class Action Waiver.
·The class action waiver in the preamble does not apply.
13.313.3 Australian Consumer Law.
13.3.113.3.1 Non-excludable Conditions.
·The disclaimers and limitations of liability in this Agreement will apply notwithstanding the failure of the essential purpose of any limited remedy. To the extent that User acquires goods or services from Stripe as a consumer within the meaning of the Australian Consumer Law as set out in the Competition and Consumer Act 2010 (Cth), User has certain rights and remedies (including consumer guarantee rights) that cannot be excluded, restricted or modified by agreement. Nothing in this Agreement operates to exclude, restrict or modify the application of any implied condition, warranty or guarantee, or the exercise of any right or remedy, or the imposition of any liability under Law where to do so would: (a) contravene that law; or (b) cause any term of this agreement to be void (referred to as a "Non-excludable Condition").
13.3.213.3.2 Limitations on Liability for Breach of Non-excludable Conditions.
·The limitations on liability do not apply to Non-excludable Conditions. To the extent that the Australian Consumer Law permits, a party's liability for breach of a Non-excludable Condition is limited, at the party's option, to (i) in the case of services, supplying the services again or payment of the cost of having the services supplied again; and (ii) in the case of goods, replacing the goods, supplying equivalent goods or repairing the goods, or payment of the cost of replacing the goods, supplying equivalent goods or having the goods repaired.
13.413.4 Limitation of Disclaimers.
·The disclaimers in this Agreement (including in Section 8.2 (Disclaimers)) do not apply to the extent any losses, damages or costs arise out of Stripe's negligence, fraud or willful misconduct.
13.513.5 Gross Negligence.
·"Gross Negligence" means a serious disregard for, or an indifference to, an obvious risk.
13.613.6 Notice for Stripe's Termination for Convenience.
10.1Section 10.1(b)(ii)(1) (Termination for Convenience) is replaced with the following.
·Unless otherwise agreed in writing, Stripe may terminate this Agreement or close User's Stripe Account at any time upon 30 days' notice to User. Stripe will notify User in accordance with Law.
13.713.7 Modification.
11.8Section 11.8 (Modification) is replaced as follows:
·Subject to the requirements of Law, Stripe may reasonably modify this Agreement (or any portion of it) at any time by posting a revised version of the modified portion(s) on the Stripe Legal Page or by notifying User. For any material modifications to the Agreement, or modifications reasonably considered to be detrimental to User, Stripe will provide User with reasonable written notice of at least 30 days (or longer period if Law requires). The modified Agreement is effective upon posting or as stated in the notice, if Stripe notifies User as specified above. For the avoidance of doubt, User may terminate the Agreement at any time under Section 10.1(a)(i) (Termination for Convenience). By continuing to use Services after the effective date of any modification to this Agreement, User agrees to be bound by the modified Agreement. Except as this Agreement otherwise allows, this Agreement may not be modified except in writing signed by the parties.
13.813.8 Interpretation.
·The interpretation rule that no provision of this Agreement will be construed against any party on the basis of that party being the drafter only applies to the extent permitted by Law.
13.913.9 Notice of Assignment.
·If Stripe assigns and transfers its rights and obligations under this Agreement as described in Section 11.10 (Assignment), Stripe will provide prior written notice to User.
13.1013.10 Processing of Personal Data by Stripe Payments Europe, Limited.
·Stripe Payments Europe, Limited is an additional party to this Agreement solely for the purposes of processing Personal Data under Section 4 (Privacy and Data Use).
·The following Regional Terms apply for Users in Brazil.
13.113.1 Governing Law.
·The laws and regulations of the Federative Republic of Brazil are the Governing Law.
13.213.2 Dispute Resolution.
·This provision supersedes Section 11.4. Each party irrevocably submits to the exclusive personal jurisdiction of, and agrees that any dispute, claim, or controversy will be brought before, the Judicial District of São Paulo, State of São Paulo, disregarding any other competent court or authority to settle the dispute, and each party waives all objections to that jurisdiction and venue.
13.313.3 Eligible Age.
·User may not use the Services if User or User's representative is under 18 years of age.
13.413.4 Labor and Environmental Laws.
·User warrants that as applicable to User's business and activities, User (i) complies with the labor and environmental Law in force in Brazil; (ii) does not use child or slave labor in User's business; (iii) complies with standards relating to occupational health and safety; (iv) does not directly or indirectly via an Affiliate contract with any third party that does not comply with labor and environmental Laws; (v) will, upon request, present to Stripe all licenses, permits, and other documents User is required to hold under labor and environmental Law; and (vi) will keep Stripe informed about questions, requests, or decisions from applicable Governmental Authorities regarding environmental and labor issues.
13.513.5 No Debit Authorization.
·For the avoidance of doubt, Stripe's right to debit the User Bank Account, the User Bank Account Debit Authorization and related references to such right do not apply.
13.613.6 Collection of Fees and other Amounts.
·Stripe will only deduct, recoup or setoff Fees and other amounts User owes to Stripe under agreements between User and Stripe, and will not include Fees and other amounts owed under other agreements between Stripe and User Affiliates or between User and Stripe Affiliates.
13.713.7 Indemnification for Fault.
·The negligence standard for User's indemnification obligation for Losses in Section 9 (Indemnification) is replaced with fault ("culpa"). For purposes of indemnification obligations, any reference to "negligence" shall be replaced with "fault".
13.813.8 Limitation of Liability.
·Subsections 8.3 and 8.4 of Section 8 (Limitation of Liability) are replaced by the following:
8.38.3 Excluded Damages. Except for Excluded Claims, to the maximum extent permitted by Law, neither party will be liable to the other party or to the other party's Affiliates in connection with this Agreement or the Services, whether during or after the Term, for any lost profits, personal injury, property damage, loss of data, business interruption, or any damages that do not arise directly and immediately from any act or omission of such party (such as indirect, incidental, consequential, exemplary, moral, loss of a chance, or punitive damages), even if such losses, damages, or costs were foreseeable or even if User or Stripe have been advised of their possibility.
8.48.4 Limitation of Liability. Except for Excluded Claims, to the maximum extent permitted by Law, neither party will be liable to the other party or to the other party's Affiliates in connection with this Agreement or the Services, whether during or after the Term, for any losses, damages, or costs that, in the aggregate, exceed the greater of: (i) the amount of fees actually paid by User to Stripe (excluding fees passed on to Financial Providers) in the 12 months period before the event giving rise to the liability; and (ii) R$2,500.00. User's payment obligations, including Fees, Assessed Fines and Taxes are not limited by this Section 8.4.
13.913.9 Processing of Personal Data by Stripe, LLC
·Stripe, LLC is an additional party to this Agreement solely for the purposes of processing Personal Data under Section 4 (Privacy and Data Use).
·The following Regional Terms apply for Users in Canada.
13.113.1 Governing Law.
·The laws of the Province of Ontario are the Governing Law.
13.213.2 Dispute Resolution.
13.2.113.2.1 Binding Arbitration.
·(a) Arbitration will be held in Toronto, Ontario, Canada.
·(b) The International Centre for Dispute Resolution ("ICDR") will administer the arbitration under its Canadian Arbitration Rules.
·(c) The arbitrator will apply the substantive law of the Province of Ontario and the federal laws of Canada applicable in that province, excluding their conflict or choice of law rules.
13.2.213.2.2 Jurisdiction and Venue.
·For all claims not subject to arbitration or to confirm an arbitrator's award, each party consents to exclusive jurisdiction in the courts located in Toronto, Ontario, Canada.
13.2.313.2.3 No Jury Trial.
·If for any reason a claim or dispute proceeds in court rather than through arbitration, to the extent Law permits, each party knowingly and irrevocably waives any right to trial by jury in any action, proceeding or counterclaim arising out of or relating to this Agreement or any of the transactions contemplated between the parties.
13.2.413.2.4 Class Waiver.
·To the extent Law permits, any dispute arising out of or relating to this Agreement, whether in arbitration or in court, will be conducted only on an individual basis and not in a class, consolidated or representative action. Notwithstanding any other provision of this Agreement or the Canadian Arbitration Rules, disputes regarding the interpretation, applicability, or enforceability of this class waiver may be resolved only by a court and not by an arbitrator. If this waiver of class or consolidated actions is deemed invalid or unenforceable, neither party is entitled to arbitration.
13.313.3 Language.
·The parties agree that this Agreement and all related documents will be written in English. Les parties conviennent que le présent Contrat et tous les documents associés seront rédigés en anglais.
13.413.4 Personal Data processed outside of Canada.
·User must disclose to User's Customers in User's Privacy Policy that Personal Data may be transferred, processed, and stored outside of Canada and, as a result, may be subject to disclosure as Law requires. Stripe will not sell or lease Personal Data that Stripe receives from User to any third party.
13.513.5 Processing of Personal Data by Stripe, LLC
·Stripe, LLC is an additional party to this Agreement solely for the purposes of processing Personal Data under Section 4 (Privacy and Data Use).
·The following Regional Terms apply for Users in Hong Kong.
13.113.1 Governing Law.
·The laws of Singapore are the Governing Law.
13.213.2 Dispute Resolution.
13.2.113.2.1 Binding Arbitration.
·(a) Arbitration will be held in Singapore.
·(b) The Singapore International Arbitration Centre ("SIAC") will administer the arbitration under the SIAC Rules ("SIAC Rules").
·(c) The arbitrator will apply the laws of Singapore.
13.2.213.2.2 Claims not subject to Arbitration-Jurisdiction and Venue.
·For claims that may not be subject to arbitration, which includes claims that relate to IP Rights, each party consents to exclusive jurisdiction in the courts of Hong Kong.
13.2.313.2.3 No Class Action Waiver.
·The class action waiver in the preamble does not apply.
13.313.3 Third Party Rights.
·Unless expressly stated otherwise in this Agreement, a person who is not a party to this Agreement has no right under the Contracts (Rights of Third Parties) Act 2001 of Singapore to enforce or enjoy any benefit under this Agreement. Nothing in this Section affects any rights of any permitted assignee or transferee of this Agreement or any right or remedy of a third party which exists or is available apart from such applicable laws and regulations. Nothing affects Stripe's right to amend, modify, supplement, rescind, replace or vary this Agreement at any time in its discretion and no prior consent from or notice to any such person who is not a party to this Agreement shall be required for Stripe to exercise such rights or to exercise any of Stripe's rights under this Agreement.
·The following Regional Terms apply for Users in India.
13.113.1 Governing Law.
·The laws of Bangalore, India are the Governing Law.
13.213.2 Dispute Resolution.
13.2.113.2.1 Binding Arbitration.
·(a) Arbitration will be held in Bangalore, India.
·(b) The Singapore International Arbitration Centre ("SIAC") will administer the non-appearance-based arbitration under the SIAC Arbitration Rules ("SIAC Rules").
·(c) The arbitrator will apply the provisions of the (Indian) Arbitration and Conciliation Act, 1996 (as amended).
13.2.213.2.2 Claims not subject to Arbitration-Jurisdiction and Venue.
·For claims that may not be subject to arbitration, which includes claims that relate to IP Rights, each party consents to exclusive jurisdiction in the courts in Bangalore, India.
13.2.313.2.3 Service of Process.
·Each party hereby agrees to service of process through personal service at their corporate headquarters, registered address, or primary address (for individuals or sole proprietors). Nothing in this Agreement will affect the right of any party to serve process in any other manner permitted by Law.
13.2.413.2.4 No Jury Trial.
·If for any reason a claim or dispute proceeds in court rather than through arbitration, to the extent Law permits, each party knowingly and irrevocably waives any right to trial by jury in any action, proceeding or counterclaim arising out of or relating to this Agreement or any of the transactions contemplated between the parties.
13.2.513.2.5 Class Waiver.
·To the extent Law permits, any dispute arising out of or relating to this Agreement, whether in arbitration or in court, will be conducted only on an individual basis and not in a class, consolidated or representative action. Notwithstanding any other provision of this Agreement or the SIAC Rules, disputes regarding the interpretation, applicability, or enforceability of this class waiver may be resolved only by a court and not by an arbitrator. If this waiver of class or consolidated actions is deemed invalid or unenforceable, neither party is entitled to arbitration.
13.313.3 Electronic Record.
·This document is an electronic record in terms of Information Technology Act, 2000 (as amended) and the rules and regulations thereunder (collectively, the "IT Act"), and is governed by the IT Act, and all other applicable Laws pertaining to electronic records. By clicking the acceptance button, registering for a Stripe Account, accessing, using or installing the Stripe API, Dashboard, or any part of the Services, User specifically agrees to be bound by the terms and conditions of this Agreement. User's registration for a Stripe Account or access, use or installation of the Stripe API, Dashboard, or any part of the Services, constitutes User's electronic signature, and User consents to electronic provision of all disclosures and notices from Stripe, including those required by Law. User also agrees that User's electronic consent will have the same legal effect as a physical signature.
13.413.4 Additional Tax Provisions.
·Stripe will send User a tax invoice but User is solely responsible for (a) providing Stripe the information necessary to populate the tax invoice in a timely manner; and (b) the accuracy of the information User provides (including the tax registration ID). Without limiting the previous paragraph, User is responsible for paying to the tax authorities the Tax Deducted at Source ("TDS") due on the Fees. In order to do so, User must determine the appropriate rate, file the appropriate forms, and make the appropriate TDS payments. After filing and paying the appropriate TDS amount, User will receive a tax certificate from the tax authorities, which shows the exact TDS amount paid under Stripe's Permanent Account Number (AAXCS5874N). If User submits the certificate to Stripe at priority-support-in@stripe.com within 30 days of the certificate's issue date, Stripe will reimburse User for the TDS that User has paid (as shown on the certificate).
·Stripe may, in its sole discretion, pay User an advance monthly TDS reimbursement if User provides Stripe a valid Tax Deductor Account Number (TAN). User will file the appropriate forms, make the appropriate TDS payments to the tax authorities, and promptly send Stripe the tax certificate User receives for that payment. If, due to User's acts or omissions, Stripe cannot claim or does not receive a full credit for any TDS that Stripe previously reimbursed to User, Stripe may deduct a corresponding amount from User's Stripe Account. Stripe is not liable for any Taxes, interest or penalty incurred or caused by User's acts or omissions (including User's delay or non-payment of TDS to the tax authorities).
13.513.5 Security Incident Reporting.
·If any security breach, leak, loss, or compromise of Data occurs on User's systems, website, or application, and it affects User's compliance with this Agreement or User's obligations under applicable Law, User must report the incident in accordance with applicable Law, including User's reporting obligations to the Indian Computer Emergency Response Team (CERT-In).
13.613.6 Processing of Personal Data by Stripe Payments Europe, Limited.
·Stripe Payments Europe, Limited is an additional party to this Agreement solely for the purposes of processing Personal Data under Section 4 (Privacy and Data Use).
·The following Regional Terms apply for Users in Indonesia.
13.113.1 Governing Law.
·The laws of the Republic of Indonesia are the Governing Law.
13.213.2 Dispute Resolution.
13.2.113.2.1 Binding Arbitration.
·(a) Arbitration will be held in Singapore.
·(b) The Singapore International Arbitration Centre ("SIAC") will administer the arbitration under the SIAC Rules ("SIAC Rules").
·(c) The arbitrator will apply the laws of Singapore.
13.2.213.2.2 Claims not subject to Arbitration-Jurisdiction and Venue.
·For claims that may not be subject to arbitration, which includes claims that relate to IP Rights, each party consents to exclusive jurisdiction in the courts of Indonesia.
13.2.313.2.3 Service of Process.
·Each party hereby agrees to service of process through personal service at their corporate headquarters, registered address, or primary address (for individuals or sole proprietors). Nothing in this Agreement will affect the right of any party to serve process in any other manner permitted by Law.
13.2.413.2.4 No Jury Trial.
·If for any reason a claim or dispute proceeds in court rather than through arbitration, to the extent Law permits, each party knowingly and irrevocably waives any right to trial by jury in any action, proceeding or counterclaim arising out of or relating to this Agreement or any of the transactions contemplated between the parties.
13.2.513.2.5 Class Waiver.
·To the extent Law permits, any dispute arising out of or relating to this Agreement, whether in arbitration or in court, will be conducted only on an individual basis and not in a class, consolidated or representative action. Notwithstanding any other provision of this Agreement or the SIAC Rules, disputes regarding the interpretation, applicability, or enforceability of this class waiver may be resolved only by a court and not by an arbitrator. If this waiver of class or consolidated actions is deemed invalid or unenforceable, neither party is entitled to arbitration.
13.313.3 Provision of Services from Systems located outside of Indonesia.
·Stripe will provide some or all of the Service from systems located within the United States or other countries outside of Indonesia. It is User's obligation to disclose to User's Customers that Data may be transferred, processed and stored outside of Indonesia and, as set forth in Stripe's Privacy Policy, may be subject to disclosure as required by applicable Laws, and to obtain from User's Customers all necessary consents under applicable Laws in relation to the foregoing.
13.413.4 Termination.
·User agrees to waive the provisions of Article 1266 paragraphs (2) and (3) of the Indonesian Civil Code and therefore this Agreement may be terminated (either partly or wholly, either temporary or permanently) without the need for a court decision.
13.513.5 Language.
·This Agreement is made in the Bahasa Indonesia language and the English language. In the event of any inconsistency of different interpretation between the Bahasa Indonesia version and the English version, the English version prevails and the Bahasa Indonesia version shall be deemed to be automatically amended (with effect from the date when the English version is brought into force) to make the relevant part of the Bahasa version consistent with the English version. User represents to have read and to fully understand the contents and consequences of this Agreement, and to have made and entered into this Agreement freely and without duress.
13.613.6 Processing of Personal Data by Stripe Payments Europe, Limited.
·Stripe Payments Europe, Limited, is an additional party to this Agreement solely for the purposes of processing Personal Data under Section 4 (Privacy and Data Use).
·The following Regional Terms apply for Users in Malaysia.
13.113.1 Governing Law.
·The laws of Malaysia are the Governing Law.
13.213.2 Dispute Resolution.
13.2.113.2.1 Binding Arbitration.
·(a) Arbitration will be held in Kuala Lumpur, Malaysia.
·(b) The Asian International Arbitration Centre (Malaysia) ("AIAC") will administer the arbitration under the AIAC Arbitration Rules ("AIAC Rules").
·(c) The arbitrator will apply the laws of Malaysia.
13.2.213.2.2 Claims not subject to Arbitration-Jurisdiction and Venue.
·For claims that may not be subject to arbitration, which includes claims that relate to IP Rights, each party consents to exclusive jurisdiction in the courts of Malaysia.
13.2.313.2.3 Service of Process.
·Each party hereby agrees to service of process through personal service at their corporate headquarters, registered address, or primary address (for individuals or sole proprietors). Nothing in this Agreement will affect the right of any party to serve process in any other manner permitted by Law.
13.2.413.2.4 No Jury Trial.
·If for any reason a claim or dispute proceeds in court rather than through arbitration, to the extent Law permits, each party knowingly and irrevocably waives any right to trial by jury in any action, proceeding or counterclaim arising out of or relating to this Agreement or any of the transactions contemplated between the parties.
13.2.513.2.5 Class Waiver.
·To the extent Law permits, any dispute arising out of or relating to this Agreement, whether in arbitration or in court, will be conducted only on an individual basis and not in a class, consolidated or representative action. Notwithstanding any other provision of this Agreement or the AIAC (Malaysia) Rules, disputes regarding the interpretation, applicability, or enforceability of this class waiver may be resolved only by a court and not by an arbitrator. If this waiver of class or consolidated actions is deemed invalid or unenforceable, neither party is entitled to arbitration.
13.313.3 Provision of Services from Systems located outside of Malaysia.
·Stripe will provide some or all of the Service from systems located within the United States or other countries outside of Malaysia. It is User's obligation to disclose to User's Customers that Data may be transferred, processed and stored outside of Malaysia and, as set forth in Stripe's Privacy Policy, may be subject to disclosure as required by applicable Laws, and to obtain from User's Customers all necessary consents under applicable Laws in relation to the foregoing.
13.413.4 Effectiveness of Modifications of the Terms.
·Modifications of the terms of this Agreement will come into effect 10 days after Stripe posts the modified version on the Stripe Legal Page (or, if a longer period is required by applicable Law or specified in a notice by Stripe, that longer period).
13.513.5 Language.
·The parties acknowledge that they have required this Agreement and all related documents to be drawn up in the English language.
13.613.6 Processing of Personal Data by Stripe Payments Europe, Limited.
·Stripe Payments Europe, Limited is an additional party to this Agreement solely for the purposes of processing Personal Data under Section 4 (Privacy and Data Use).
·The following Regional Terms apply for Users in Mexico.
13.113.1 Governing Law.
·The laws of Mexico are the Governing Law.
13.213.2 Dispute Resolution.
13.2.113.2.1 Binding Arbitration.
·(a) Arbitration will be held in Mexico City, Mexico.
·(b) The International Chamber of Commerce ("ICC") will administer the arbitration in accordance with its Rules.
·(c) The arbitrator will apply the substantive law of Mexico.
13.2.213.2.2 Jurisdiction and Venue.
·For all claims not subject to arbitration or to confirm an arbitrator's award, each party consents to exclusive jurisdiction in the courts located in Mexico City, Mexico.
13.2.313.2.3 No Jury Trial.
·If for any reason a claim or dispute proceeds in court rather than through arbitration, to the extent Law permits, each party knowingly and irrevocably waives any right to trial by jury in any action, proceeding or counterclaim arising out of or relating to this Agreement or any of the transactions contemplated between the parties.
13.2.413.2.4 Class Waiver.
·To the extent Law permits, any dispute arising out of or relating to this Agreement, whether in arbitration or in court, will be conducted only on an individual basis and not in a class, consolidated or representative action. Notwithstanding any other provision of this Agreement or the ICC Rules, disputes regarding the interpretation, applicability, or enforceability of this class waiver may be resolved only by a court and not by an arbitrator. If this waiver of class or consolidated actions is deemed invalid or unenforceable, neither party is entitled to arbitration.
13.313.3 Provision of Services outside of Mexico.
·User is responsible for (a) disclosing to User's Customers that Stripe will provide some or all of the Services using infrastructure located within the United States or other countries outside of Mexico, and that Personal Data may be transferred, processed and stored outside of Mexico; and (b) obtaining from User's Customers all necessary consents under Law related to the transfer, processing or storage of Personal Data outside of Mexico.
13.413.4 Judicial Notices and Electronic Consent.
·User consents to receiving judicial notices at the business address that appears in User's Stripe Account, which is designated as User's legal domicile. User must keep that address updated. User also agrees that User's electronic consent will have the same legal effect as a physical signature, in accordance with article 1803 of the Mexican Federal Civil Code (Código Civil Federal), article 89 and related articles of the Mexican Code of Commerce (Código de Comercio).
13.513.5 Processing of Personal Data by Stripe, LLC
·Stripe, LLC is an additional party to this Agreement solely for the purposes of processing Personal Data under Section 4 (Privacy and Data Use).
·The following Regional Terms apply for Users in New Zealand.
13.113.1 Governing Law.
·The laws of New Zealand are the Governing Law.
13.213.2 Dispute Resolution. 13.2.1 Binding Arbitration
·(a) Arbitration will be held in Auckland, New Zealand.
·(b) The International Centre for Dispute Resolution ("ICDR") will administer the arbitration under the International Arbitration Rules (including its expedited procedures where applicable) and the Arbitration Act 1996.
·(c) The arbitrator will apply the substantive law of New Zealand, excluding any conflict or choice of law rules.
·(d) The party initiating the arbitration is responsible for paying the applicable filing fee. Each party will advance one-half of the fees and expenses of the arbitrator, the costs of the attendance of a stenographer at the arbitration hearing, and the costs of the arbitration facility.
13.2.213.2.2 Claims not subject to Arbitration-Jurisdiction and Venue.
·For claims that may not be subject to arbitration, which includes claims that relate to IP Rights, each party consents to exclusive jurisdiction in courts of New Zealand.
13.2.313.2.3 No Class Action Waiver.
·The class action waiver in the preamble does not apply.
13.313.3 Consumer Guarantees Act / Fair Trading Act.
·Services and Stripe Technology are supplied and acquired in trade, and accordingly the parties agree to opt out of the provisions of the New Zealand Consumer Guarantees Act 1993 and sections 9, 12A, 13 and 14(1) of the New Zealand Fair Trading Act 1986 in respect of the Services and Stripe Technology. User may only use the Services for business purposes.
13.413.4 Limitation of Indemnity Obligations.
·A party's obligations to indemnify the other party do not apply to the extent the Claim or Losses arise out of the other party's breach of this Agreement, negligence, fraud or willful misconduct.
13.513.5 Limitation of Disclaimers.
·The disclaimers in this Agreement (including in Section 8.2 (Disclaimers)) do not apply to the extent any losses, damages or costs arise out of Stripe's negligence, fraud or willful misconduct.
13.613.6 Gross Negligence.
·"Gross Negligence" means a serious disregard for, or an indifference to, an obvious risk.
13.713.7 Notice for Stripe's Termination for Convenience.
10.1Section 10.1(b)(ii)(1) (Termination for Convenience) is replaced with the following.
·Unless otherwise agreed in writing, Stripe may terminate this Agreement or close User's Stripe Account at any time upon 30 days' notice to User. Stripe will notify User in accordance with Law.
13.813.8 Modification.
11.8Section 11.8 (Modification) is replaced as follows:
·Subject to the requirements of Law, Stripe may reasonably modify this Agreement (or any portion of it) at any time by posting a revised version of the modified portion(s) on the Stripe Legal Page or by notifying User. For any material modifications to the Agreement, or modifications reasonably considered to be detrimental to User, Stripe will provide User with reasonable written notice of at least 30 days (or longer period if Law requires). The modified Agreement is effective upon posting or as stated in the notice, if Stripe notifies User as specified above. For the avoidance of doubt, User may terminate the Agreement at any time under Section 10.1(a)(i) (Termination for Convenience). By continuing to use Services after the effective date of any modification to this Agreement, User agrees to be bound by the modified Agreement. Except as this Agreement otherwise allows, this Agreement may not be modified except in writing signed by the parties.
13.913.9 Interpretation.
·The interpretation rule that no provision of this Agreement will be construed against any party on the basis of that party being the drafter only applies to the extent permitted by Law.
13.1013.10 Notice of Assignment.
·If Stripe assigns and transfers its rights and obligations under this Agreement as described in Section 11.10 (Assignment), Stripe will provide prior written notice to User.
13.1113.11 Processing of Personal Data by Stripe Payments Europe, Limited.
·Stripe Payments Europe, Limited is an additional party to this Agreement solely for the purposes of processing Personal Data under Section 4 (Privacy and Data Use).
·The following Regional Terms apply for Users in Japan.
13.113.1 Governing Law.
·The laws of Japan are the Governing Law.
13.213.2 Dispute Resolution.
13.2.113.2.1 Binding Arbitration.
·(a) Arbitration will be held in Tokyo, Japan.
·(b) The Japan Commercial Arbitration Association ("JCAA") will administer the arbitration under the JCAA Commercial Arbitration Rules ("JCAA Rules").
·(c) The arbitrator will apply the laws of Japan.
·(d) The party initiating the arbitration is responsible for paying the applicable filing fee. Each party will advance one-half of the fees and expenses of the arbitrator, the costs of the attendance of a stenographer at the arbitration hearing, and the costs of the arbitration facility.
13.2.213.2.2 Claims not subject to Arbitration-Jurisdiction and Venue.
·For claims that may not be subject to arbitration, which includes claims that relate to IP Rights, each party consents to exclusive jurisdiction in the Tokyo District Court or Tokyo Summary Court, whichever has jurisdiction over the matter under the Governing Law.
13.2.313.2.3 No Class Action Waiver.
·The class action waiver in the preamble does not apply.
13.313.3 Anti-Social Forces Representation and Warranty.
·User and Stripe each represent on behalf of itself, that neither User or Stripe (a) is an Anti-Social Force, nor are any of User's or Stripe's officers or employees an Anti-Social Force, (b) falls or will fall under any Anti-Social Forces Relationship, or (iii) will carry out or use a third party to carry out any Anti-Social Conduct.
·"Anti-Social Conduct" means (a) making violent demands; (b) making unreasonable demands exceeding legal entitlement; (c) using threatening behavior or violence in relation to a transaction; (d) spreading false rumors, using fraudulent means, or using force to harm the other party's reputation or business; or (e) other acts similar to any of the above.
·"Anti-Social Force" means (a) an organized crime group (boryokudan); (b) a member of an organized crime group in the past five years; (c) an associate of an organized crime group; (d) a corporate racketeer (sokaiya); (e) a social or political movement racketeer that engages in violent or illegal activities seeking improper profits by pretending to engage in social or political movements (shakai undotu hyobo goro); (f) a violent organization employing specialized knowledge (tokushu chinou boryoku shudan tou); or (g) another person or entity similar to any of the above.
·"Anti-Social Forces Relationship" means any person or entity (a) having a relationship in which Anti-Social Forces control management or are substantially involved in management; (b) having a relationship in which that person or entity improperly benefits from Anti-Social Forces; (c) having a relationship in which funds or favors are provided to Anti-Social Forces; or (d) substantially involved in management having a socially reprehensible relationship with Anti-Social Forces.
13.413.4 Processing of Personal Data by Stripe Payments Europe, Limited.
·Stripe Payments Europe, Limited is an additional party to this Agreement solely for the purposes of processing Personal Data under Section 4 (Privacy and Data Use).
·The following Regional Terms apply for Users in Singapore.
13.113.1 Governing Law.
·The laws of Singapore are the Governing Law.
13.213.2 Dispute Resolution.
13.2.113.2.1 Binding Arbitration.
·(a) Arbitration will be held in Singapore.
·(b) The Singapore International Arbitration Centre ("SIAC") will administer the arbitration under the SIAC Rules ("SIAC Rules").
·(c) The arbitrator will apply the laws of Singapore.
13.2.213.2.2 Claims not subject to Arbitration-Jurisdiction and Venue.
·For claims that may not be subject to arbitration, which includes claims that relate to IP Rights, each party consents to exclusive jurisdiction in the courts of Singapore.
13.2.313.2.3 No Class Action Waiver.
·The class action waiver in the preamble does not apply.
13.313.3 Third Party Rights.
·Unless expressly stated otherwise in this Agreement, a person who is not a party to this Agreement has no right under the Contracts (Rights of Third Parties) Act 2001 of Singapore to enforce or enjoy any benefit under this Agreement. Nothing in this Section affects any rights of any permitted assignee or transferee of this Agreement or any right or remedy of a third party which exists or is available apart from such applicable laws and regulations. Nothing affects Stripe's right to amend, modify, supplement, rescind, replace or vary this Agreement at any time in its discretion and no prior consent from or notice to any such person who is not a party to this Agreement shall be required for Stripe to exercise such rights or to exercise any of Stripe's rights under this Agreement.
13.413.4 Processing of Personal Data by Stripe Payments Europe, Limited.
·Stripe Payments Europe, Limited, is an additional party to this Agreement solely for the purposes of processing Personal Data under Section 4 (Privacy and Data Use).
·The following Regional Terms apply for Users in Thailand.
13.113.1 Governing Law.
·The laws of Thailand are the Governing Law.
13.213.2 Dispute Resolution.
13.2.113.2.1 Binding Arbitration.
·Arbitration will be held in Thailand.
·The Thailand Arbitration Center ("THAC") will administer the arbitration under the THAC Arbitration Rules ("THAC Rules").
·The arbitrator will apply the laws of Thailand.
13.2.213.2.2 Claims not subject to Arbitration-Jurisdiction and Venue.
·For claims that may not be subject to arbitration, which includes claims that relate to IP Rights, each party consents to exclusive jurisdiction in the courts of Thailand.
13.2.313.2.3 Service of Process.
·Each party hereby agrees to service of process through personal service at their corporate headquarters, registered address, or primary address (for individuals or sole proprietors). Nothing in this Agreement will affect the right of any party to serve process in any other manner permitted by Law.
13.2.413.2.4 No Jury Trial.
·If for any reason a claim or dispute proceeds in court rather than through arbitration, to the extent Law permits, each party knowingly and irrevocably waives any right to trial by jury in any action, proceeding or counterclaim arising out of or relating to this Agreement or any of the transactions contemplated between the parties.
13.2.513.2.5 Class Waiver.
·To the extent Law permits, any dispute arising out of or relating to this Agreement, whether in arbitration or in court, will be conducted only on an individual basis and not in a class, consolidated or representative action. Notwithstanding any other provision of this Agreement or the THAC Rules, disputes regarding the interpretation, applicability, or enforceability of this class waiver may be resolved only by a court and not by an arbitrator. If this waiver of class or consolidated actions is deemed invalid or unenforceable, neither party is entitled to arbitration.
13.313.3 Effectiveness of Modifications of the Terms.
·Modifications of the terms of this Agreement will come into effect 30 days after Stripe posts the modified version on the Stripe Legal Page (or, if a longer period is required by applicable Law or specified in a notice by Stripe, that longer period).
13.413.4 Provision of Services from Systems located outside of Thailand.
·Stripe will provide some or all of the Service from systems located within the United States or other countries outside of Thailand. It is User's obligation to disclose to User's Customers that Data may be transferred, processed and stored outside of Thailand and, as set forth in Stripe's Privacy Policy, may be subject to disclosure as required by applicable Laws, and to obtain from User's Customers all necessary consents under applicable Laws in relation to the foregoing.
13.513.5 Language.
·The parties acknowledge that they have required this Agreement and all related documents to be drawn up in the English language.
13.613.6 Additional Tax Provisions.
·User must settle Fees and other amounts due to Stripe for a given month on the first of the following month, or, if we notify User of another date, on that date. Unless Stripe notifies User of another method of settlement, the settlement will be made by deducting or setting off amounts that User owes from User's Stripe Account balance, debiting a User Bank Account, or as this Agreement otherwise permits. Stripe may, in its sole discretion, pay User an advance monthly withholding tax reimbursement. User will file the appropriate forms, make the appropriate withholding tax payments to the tax authorities, and promptly send Stripe the tax certificate for that payment. If, due to User's acts or omissions, Stripe cannot claim or does not receive a full credit for any withholding tax that Stripe previously reimbursed to User, Stripe may deduct a corresponding amount from User's Stripe Account. Stripe is not liable for any taxes, interest or penalty incurred or caused by User's acts or omissions (including User's delay or non-payment of withholding tax to the tax authorities).
13.713.7 Processing of Personal Data by Stripe Payments Europe, Limited.
·Stripe Payments Europe, Limited is an additional party to this Agreement solely for the purposes of processing Personal Data under Section 4 (Privacy and Data Use).
·The following Regional Terms apply for Users in the United Arab Emirates.
13.113.1 Governing Law.
·The laws of Ireland are the Governing Law.
13.213.2 Dispute Resolution.
13.2.113.2.1. Binding Arbitration.
·(a) Arbitration will be held in Dublin, Ireland.
·(b) The International Chamber of Commerce ("ICC") International Court of Arbitration will administer the arbitration under its ICC Rules ("ICC Rules").
·(c) The arbitrator will apply the laws of Ireland.
·(d) The arbitrator may be the same nationality as any of the parties, and must be a member of the Law Society of Ireland or the Bar of Ireland, unless the parties agree otherwise.
13.2.213.2.2 Claims not subject to Arbitration-Jurisdiction and Venue.
·For claims that may not be subject to arbitration, which includes claims that relate to IP Rights, each party consents to exclusive jurisdiction in the courts of Ireland.
13.2.313.2.3 Service of Process.
·Each party agrees to service of process through personal service at their corporate headquarters, registered address, or primary address (for individuals or sole proprietors). Nothing in this Agreement will affect the right of any party to serve process in any other manner permitted by Law.
13.2.413.2.4 No Jury Trial.
·If for any reason a claim or dispute proceeds in court rather than through arbitration, to the extent Law permits, each party knowingly and irrevocably waives any right to trial by jury in any action, proceeding or counterclaim arising out of or relating to this Agreement or any of the transactions contemplated between the parties.
13.2.513.2.5 Class Waiver.
·To the extent Law permits, any dispute arising out of or relating to this Agreement, whether in arbitration or in court, will be conducted only on an individual basis and not in a class, consolidated or representative action. Notwithstanding any other provision of this Agreement or the ICC Rules, disputes regarding the interpretation, applicability, or enforceability of this class waiver may be resolved only by a court and not by an arbitrator. If this waiver of class or consolidated actions is deemed invalid or unenforceable, neither party is entitled to arbitration.
13.313.3 Processing, Disclosure and Transfer of Data Outside the United Arab Emirates.
·User acknowledges and agrees that Stripe may provide some or all of the Services from systems located in the United States or other countries outside the United Arab Emirates as listed in the Stripe Sub-processors List (as defined in the DPA). In connection with the Services, Stripe and its Affiliates may collect, access, use, process, store, disclose and transfer outside the United Arab Emirates: (a) Protected Data; (b) Content; (c) Third Party Data; and (d) other data and information relating to User, User's business, User's representatives, employees, contractors and other personnel, Customers, and transactions processed through the Services.
·Stripe may disclose or transfer this data and information to its Affiliates, Financial Providers, payment method providers, Card Networks, service providers, professional advisers and Governmental Authorities, including the Central Bank of the United Arab Emirates, as necessary to:
·(a) provide, operate, secure, support and improve the Services;
·(b) process transactions and perform related reconciliation, settlement, reporting and support activities;
·(c) comply with Law, regulatory requirements, Card Network Rules, and requests from Governmental Authorities;
·(d) prevent, detect, investigate and manage fraud, money laundering, terrorist financing, security incidents and other unlawful or prohibited activity;
·(e) perform identity, verification, credit, risk and compliance checks;
·(f) provide products or services requested or enabled by User;
·(g) obtain professional advice or services from persons subject to appropriate confidentiality obligations;
·(h) facilitate an actual or proposed financing, investment, reorganisation, sale, merger, assignment or other transfer of all or part of Stripe's business or assets, subject to appropriate confidentiality obligations; and
·(i) otherwise to provide the Services as set out in the Agreement.
·User must provide Customers and other relevant individuals (including Connected Accounts) with all notices required by Law and obtain all rights, permissions and consents necessary to enable Stripe and the recipients described in this section to Process, disclose and transfer their data as described above.
·To the extent any data described in this section is Personal Data, the DPA, including the Data Transfers Addendum, governs its processing.
25,644 words, 668 clausesno date on the pageread 08/10/2026source
·Stripe respects the privacy of everyone that engages with our platform, and we are committed to being transparent about our privacy processes and policies. We are a platform that enables millions of businesses, and in order to provide our services to our Business Users and End Users, we collect and process personal data.
·The Stripe Privacy Center contains the answers to frequently asked questions about how we collect and use personal data, the rights that individuals have in relation to personal data held by Stripe, and how Stripe complies with international data protection laws.
·All materials have been prepared for general information purposes only. The information presented is not legal advice, is not to be acted on as such, may not be current and is subject to change without notice.
·Below is a list of terms that will help "you" navigate the Privacy Center: "YOU" | MEANING | STRIPE EXAMPLES
| Business User | Stripe provides services to entities ("Business Users") who directly and indirectly provide us with "End Customer" Personal Data in connection with those Business Users' own business and activities. | Stripe user or merchant Platform User Connect Accounts |
|---|---|---|
| End Customer | When you do business with, or otherwise transact with, a Business User (typically a merchant using Stripe Checkout, e.g. when you buy a pair of shoes from a merchant that uses Stripe for payment processing) but are not directly doing business with Stripe, we refer to you as an "End Customer." | Individual using Identity Cardholder using Checkout |
| End User | When you directly use an End User Service (such as when you sign up for Link, or make a payment to Stripe Climate in your personal capacity), for your personal use, we refer to you as an "End User." | User of Link Personal contributor to Stripe Climate |
| Representative | When you are acting on behalf of an existing or potential Business User (e.g. you are a founder of a company, or administering an account for a merchant who is a Business User), we refer to you as a "Representative." | Beneficial owner Shareholder, officer, director Account representative |
| Visitor | When you visit a Site without being logged into a Stripe account or otherwise communicate with Stripe, we refer to you as a "Visitor." (e.g. you send Stripe a message asking for more information because you are considering being a user of our products). | Stripe Sessions attendee Stripe Site visitor |
·Stripe's Role in Managing Data- Is Stripe acting as a data controller or a data processor?- Which Stripe entities are involved?
·How We Use Data- What are Stripe's data controller activities?- How does Stripe use Personal Data to improve its products and Services?- How does Stripe use Personal Data to prevent fraud?- How does Stripe use personal data to train artificial intelligence models?- How does Stripe use and share data to authenticate my transactions?- Does Stripe collect precise location data?- How does Stripe use Representative contact information to provide its Services?- As a Stripe Business User and as a data controller, what does GDPR mean for me?- As a Business User, what notice do I provide to my End Customers about Stripe?
·Third Parties- Who are Stripe's sub-processors and how are they vetted?- In addition to its sub-processors, what other third parties does Stripe share information with?- Are there any jurisdictional nuances to Stripe's use of service providers in verifying the identity of Stripe's Business Users?- Data Obtained from Third Parties- From where does Stripe collect information used for fraud prevention and security purposes?
·Marketing- How does Stripe use Personal Data for co-marketing End User Services?- Does Stripe Record Calls?- How does Stripe collect information for phone verification?
·General- How do you implement Privacy by Design at Stripe?- As a Business User, what notice do I provide to my End Customers about Stripe?
·Stripe Product Information- Stripe Identity- Stripe's Card Image Verification- Stripe Connect At a Glance- Stripe Connect - I am a user with a Custom connected account. Does Stripe also collect information about my Custom connected account from a third party?- Stripe Connect - What responsibilities do Connect platforms with custom accounts have to allow their users to update or correct information associated with their accounts?- Stripe Connect - I am a user with a Custom connected account. Will data collected from a third party be visible to my customers?- Promotional Emails Feature- Stripe Delegated Authentication- Onelink- Onelink - What is "Sold through Onelink"?- What information is shared with BNPL or crypto wallet services?- Stripe Capital Direct and Capital for Platforms- Financial Connections- Are there instances when Stripe receives non-Stripe transaction history?- Refunds to End Customer Bank Account- Stripe Frontier
·General- How is Stripe dealing with its international data transfers?- Why is Stripe storing authentication and authorization data globally?
·International Data Transfer Certifications- Is Stripe certified under the EU-U.S Data Privacy Framework?- How does Stripe's certification under the EU-U.S. DPF impact my organization?- What is CBPR and PRP and is Stripe certified?
·Standard Contractual Clauses and UK Addendum- How do the SCCs and UK Addendum impact my organization?- How to get a copy of the SCCs or UK Addendum?
·How To Exercise Your Rights and Choices- How do I exercise my data protection rights?- Does Stripe honor the Global Privacy Control (GPC) opt-out preference signal?- Can I turn off tracking and advanced fraud signals?- How do I delete my account?- How do I delete my Custom Connect account?- How do I delete my Express Connect account?Additional Information- When does Stripe continue to process data after it has received a deletion request or objection to the processing?- What data may be shared or made available to enable me to see Stripe ads on other sites?- How long will Stripe keep my data?- What is the Privacy Policy for Stripe Media Services?
·Your Rights and Choices (India)- Does Stripe localize storage of data in India?- Where can I lodge my complaint on data handling in India?- Notification IT Rules 2021
·General Information- How does Stripe use cookies?- What is Stripe.js?- Does Stripe use CAPTCHA to protect its website from fraud and abuse?- What data may be shared or made available to enable me to see Stripe ads on other sites?
·Cookies and Fraud Detection- What are advanced fraud signals?- Why are advanced fraud signals not ad tracking?- What obligations should merchants keep in mind relating to cookie technology on their sites?
·Cookies and Onelink- How does Stripe remember payment method details for Onelink?- What obligations should Onelink users keep in mind relating to cookie technology on their sites? Contact our Privacy Team
·The answer is both.
·The "data controller" is the entity which determines the purposes and means of the data processing taking place. The "data processor" is an entity acting on behalf and under the instructions of a controller in processing Personal Data.
·Stripe is a data controller when it determines the purposes and means of the processing taking place. Please see this Privacy Center article for more information on Stripe's controller activities.
·Stripe is a data processor where it is providing the Stripe Services to Business Users and facilitating payment transactions on behalf of and at the direction of a Business User. Our Business Users direct us to take payment from cardholders / End Customers and we act on their instructions.
·Stripe is also considered a processor when servicing the Stripe platform (e.g. when Stripe responds to a request for customer support from a Business User).
·As a platform provider, we need to ensure consistency across our platform, and that includes consistency with respect to the commitments that we give about how we operate our platform. We contract with all of our Business Users (including some of the world's largest companies) on this basis.
·For most of our services, the primary data controller is either Stripe, LLC the US parent company operating under US law or Stripe Technology Company, Limited ("STC"), an Irish company operating under Irish law.
·The Stripe entities responsible for your data will depend on your location, the product or service you use with us and the specific context of the data processing which determines whether Stripe is acting as a data controller and/or data processor.
·If you are located outside of the Americas [e.g., European Economic Area ("EEA"), Switzerland, the United Kingdom, the Middle East and Africa, or Asia Pacific ("APAC")], the following entities may act as data controllers, either individually or jointly depending on the product or service you use:
·If you are located in the Americas, your Data Processing Agreement ("DPA") will be with Stripe, LLC and if you are located outside of the Americas, your DPA will be with SPEL.
·Please see our table below for more information on which Stripe entity is your data controller in these jurisdictions:
| User location | Purposes of processing | Stripe Entity/Your data controller | Stripe Entity Location | ||||
| Australia | Provision of services and regulated activities in accordance with https://stripe.com/au/legal/ssa | Stripe Payments Australia Pty Ltd A.C.N. 160 180 343 | Australia STC | Ireland |
| Your contracting entity under our DPA | SPEL | Ireland All other activities | STC | Ireland |
| Brazil | Provision of services and regulated activities in accordance with https://stripe.com/br/ssa | Stripe Brasil Soluções de Pagamento - Instituição de Pagamento Ltda | Brazil Stripe, LLC | USA |
| All other activities | Stripe, LLC | USA | ||||
| Canada | Provision of services and regulated activities in accordance with https://stripe.com/en-ca/ssa | Stripe Payments Canada, Ltd | Canada Stripe, LLC | USA |
| All other activities | Stripe, LLC | USA | ||||
| EEA | Provision of certain authorised payment services and other regulated activities in the EEA. Please see https://stripe.com/ie/ssa | Stripe Technology Europe, Limited | Ireland | ||||
| Your contracting entity under our SSA & DPA | SPEL | Ireland All other activities | STC | Ireland |
| India | Provision of services and regulated activities in accordance with https://stripe.com/in/legal/ssa | Stripe India Private Limited | India STC | Ireland |
| Your contracting entity under our DPA | SPEL | Ireland All other activities | STC | Ireland |
| Indonesia | Provision of services and regulated activities in accordance with https://stripe.com/id/ssa | PT Stripe Payments Indonesia | Indonesia STC | Ireland |
| Your contracting entity under our DPA. | SPEL | Ireland All other activities | STC | Ireland |
| Japan | Provision of services in accordance with https://stripe.com/en-jp/legal | Stripe Japan, Inc.STC | JapanIreland | ||||
| Your contracting entity under our DPA. | SPEL | Ireland All other activities | STC | Ireland |
| Malaysia | Provision of services and regulated activities in accordance with https://stripe.com/en-my/legal/ssa | Stripe Payments Malaysia Sdn. Bhd. | Malaysia STC | Ireland |
| Your contracting entity under our DPA | SPEL | Ireland All other activities | STC | Ireland |
| Mexico | Provision of services in accordance with https://stripe.com/mx/legal/ssa | Stripe Payments Mexico, S. de R.L. de C.V. | Mexico Stripe, LLC | USA |
| All other activities | Stripe, LLC | USA | ||||
| United Kingdom | Provision of authorised payment services and other regulated activities in the UK. Please see https://stripe.com/gb/ssa | Stripe Payments UK, Ltd. | United Kingdom | ||||
| Your contracting entity under our SSA & DPA | SPEL | Ireland All other activities | STC | Ireland |
| United States | All activities | Stripe, LLC | USA | ||||
| Provision of lending facilitation services to bank partners in connection with Stripe Capital loans in the United States | Stripe Brokering, Inc. | USA | ||||
| Provision of certain Stripe Services which involve money transmission or other regulated services under U.S. Law. | Stripe Payments Company | USA | ||||
| New Zealand | Provision of services and regulated activities in accordance with https://stripe.com/nz/ssa | Stripe New Zealand LimitedSTC | New Zealand Ireland | ||||
| Your contracting entity under our DPA | SPEL | Ireland All other activities | STC | Ireland |
| Singapore | Provision of services and regulated activities in accordance with https://stripe.com/en-sg/legal | Stripe Payments Singapore Pte. Ltd. | Singapore STC | Ireland |
| Your contracting entity under our DPA | SPEL | Ireland All other activities | STC | Ireland |
| Switzerland | Provision of authorised payment services and other regulated activities in Switzerland. Please see https://stripe.com/gb/ssa | Stripe Payments UK, Ltd. | United Kingdom | ||||
| Your contracting entity under our SSA & DPA | SPEL | Ireland All other activities | STC | Ireland |
| Thailand | Provision of services and regulated activities in accordance with https://stripe.com/th/legal/ssa | Stripe Payments (Thailand) Ltd. | Thailand STC | Ireland |
| Your contracting entity under our DPA | SPEL | Ireland All other activities | STC | Ireland |
| Any other jurisdiction in the Americas | All other activities and your contracting entity under our DPA and SSA. | Stripe, LLC | USA | ||||
| Any other jurisdictions in EMEA | Your contracting entity under our DPA and SSA | SPEL | Ireland | ||||
| Provision of Stablecoin Financial Account UX Services in accordance with https://stripe.com/legal/sfa-terms | Stripe, LLC | USA All other activities | STC | Ireland |
| Any other jurisdictions in APAC, except for Hong Kong (SAR) | Provision of Stablecoin Financial Account UX Services in accordance with https://stripe.com/legal/sfa-terms | Stripe, LLC | USA All other activities | STC | Ireland | ||||
·Depending on your location, the location of your Customers, and the nature of the services Stripe is providing, (other than the entities set out above) we may use Stripe Affiliates in the same location or other locations, as well as Service Providers and Sub-processors to help provide the Services to you. These entities act as data processors on behalf of Stripe, LLC or STC depending on the jurisdiction. You will find the most up to date list of Stripe affiliates, Service Providers and Sub-processors here.
·Stripe collects data, including Personal Data, while providing Services to its users. Stripe uses some of the data it collects to improve its products and Services, including by training the models it employs for fraud and loss prevention and to analyze the performance of Stripe's products as permitted by applicable law and agreements.
·Personal Data is required to train Stripe's fraud and loss prevention models, including those employed by Stripe Radar and Stripe Identity. These products rely in part on their ability to recognize certain characteristics that help determine whether a transaction is fraudulent or unlikely to complete. For example, they compare Personal Data presented in a specific transaction to Personal Data collected in the past to identify when a fraudster is attempting to perpetrate fraud, including to impersonate a Stripe User or their End Customers.
·In addition to using Personal Data to train its fraud and loss prevention models, Stripe also uses Transaction Data to assess the functioning of its current products and proposed product improvements. For instance, Stripe uses data collected by its java script library stripe.js to assess the performance of the checkout surfaces it provides to Business Users, and payment authorization data to evaluate ways to improve authorization rates for Business Users. Stripe uses Personal Data, such as IP address, to identify which pages and features a user interacted with during a checkout session, so that it can assess the effect different features have on the outcome of a checkout session.
·Stripe uses pseudonymized or aggregated Transaction Data for these purposes in certain circumstances. When Stripe communicates the results of its product performance analytics to Business Users or for advertising purposes, it does so only in aggregated or de-identified form that does not permit third-parties outside of Stripe to associate that data with any particular End Customers.
·You should consult your legal counsel regarding how best to disclose Stripe's data usage to your customers. But, here is a paragraph you could add to your privacy policy if it doesn't already include such a disclosure:
·We train artificial intelligence models that we deploy for a number of purposes, including to prevent fraud and other harm to Stripe, Users, and others, increase authorization rates and revenue realization for Business Users, provide and improve User experience on other Services, and identify when Business Users may benefit from services they are not currently using. Preventing Fraud
·We train artificial intelligence models to prevent fraud in a number of ways, using different kinds of data appropriate to the kinds of fraud we are trying to prevent. These fraud prevention models include:
·Increasing Authorization and Revenue Realization
·We train artificial intelligence models to increase authorization rates and revenue realization for Business Users who use our payments products. Models we train for these purposes include:
·We train artificial intelligence models to power other Services such as:
·We also train models to recognize Business Users that are good candidates to use additional Stripe services, such as Stripe Capital in the US. We may train these models using information related to a Business User's activity on the Stripe platform and, when the user provides them to us, bank account and other financial information. The models are trained using such information so that they can recognize similarities between the current Business User and other Business Users who have benefitted from our products in the past. To the extent that Business Users are individuals, such data may constitute Personal Data.
·As a Stripe Business User and a data controller, the GDPR places responsibility on you in relation to the Personal Data that you process through Stripe services (i.e., your End Customers' data). If you have customers anywhere in the EU / UK, you are required to comply with the GDPR (and/or the UK's version of GDPR), no matter where your business is located. Fundamentally, you must ensure that you have a lawful basis for processing Personal Data and that you are transparent with your customers about how their data is used.
·Data controllers will need to have certain contractual terms in place with third parties who act as data processors on their behalf. To assist Business Users with their compliance with the GDPR, Business Users enter into a Data Processing Agreement ("DPA") with Stripe. Understanding both your obligations and Stripe's role under the DPA is essential for operating within the GDPR framework. We encourage you to read our DPA to learn more.
·Please see our service providers page where we have a list of our sub-processors, affiliates, and most common service providers. Stripe identifies, evaluates, and engages sub-processors through our vendor management program. We enter into a contract with each sub-processor prior to sharing data with the sub-processor, and each contract contains terms that provide for monitoring and audit. In addition, all vendors are vetted and approved through Stripe's security review process before we begin using their services.
·To prevent fraud and strengthen our security, we may collect information from Business Users, End Customers, End Users, financial parties, and in some cases third parties. For example, we collect and analyze information that helps us identify bad actors and bots, including both transactional data (such as amount, customer shipping address, date, and so on) and advanced fraud detection signals (device and activity signals). Learn more.
·Stripe also receives information from third parties to prevent and respond to security incidents, and for protecting against other fraudulent activity. For example, we may receive information from third parties about IP addresses that malicious actors have compromised. Stripe may use Representatives' Personal Data provided at onboarding to query third party databases regarding fraud and risk signals associated with that data. The third party providers operating these databases may use Stripe's experience with the Personal Data queried to inform their fraud and risk signals.
·To help prevent fraudulent transactions when you use your debit or credit card to pay a Business User, we may share data related to you and your transaction with your card issuer, bank, and payment method provider so that they can verify your identity and authenticate your payment method. The data we share to enable this process may include Personal Data such as your name, email address and phone number, and payment-specific data like your billing and shipping address.
·Issuers and payment method providers may use the information we share to verify you through a process called 3D Secure Authentication or 3DS. 3DS is an authentication standard designed by the major card networks which aims to reduce fraud and provide added security by providing an additional layer of authentication to online card payments. 3DS is often known by its branded names like Visa Secure, Mastercard Identity Check, or American Express SafeKey. It works by comparing the information you provide at the time of the transaction with the information that your issuer and payment method provider already have on file, to help reduce the risk that someone else may use your card for an unauthorized transaction.
·Additionally, we may share contextual data, such as your device ID and previous transaction history. The process may take place as part of the checkout flow, which may involve you being redirected to another page where your bank asks you for a code or password to approve the purchase.
·3DS is frequently used in Europe in support of Strong Customer Authentication requirements under the Payment Services Directive (PSD2) and to comply with similar regulations in other countries including the UK, India and Australia. When we act as a service provider to your bank under our Stripe Issuing program we and our service providers may use Personal Data such as your card number, contact information, payment-specific data, like your billing and shipping address, and contextual data such as your device ID and transaction history to facilitate 3DS authentication.
·The Stripe products that use Personal Data to enable Stripe's Business Users to detect and prevent fraud include Stripe Radar, Stripe Identity, and Stripe Merchant Risk Tooling. Stripe also employs internal risk models and other product features, such as 3D Secure incorporated into Stripe's Issuing product, to prevent its products and Services from being used for fraudulent activity.
·Stripe Radar processes Personal Data as described here using its artificial intelligence model to produce scores indicating the likelihood that a payment method is being offered by someone other than an authorized user. These scores are designed to identify fraudulent transactions, they do not rate the character or creditworthiness of the individuals involved in a particular transaction. Based on the service selected by the Business User, Stripe may provide the Radar scores to its Business Users to help them to combat fraud and provide a mechanism for them to set rules to better manage transactions based on Radar scores and other indicators of fraud.
·Stripe Identity uses Personal Data, as described here, to combat fraud by enabling Business Users to verify whether the person they are transacting with is who they say they are. Identity compares biometric identifiers in a selfie against government issued ID. Identity can also validate Personal Data, such as name, date of birth, and government ID number, that an End Customer types into a web form against government and third-party databases to determine if the identity presented matches the government issued ID number.
·Stripe's internal risk models seek to combat fraud by recognizing when a fraudster is attempting to use Stripe's Services for fraudulent purposes. For instance, Stripe uses Radar scores internally to determine whether a payment method offered to Stripe products such as Link, Frontier, Crypto Onramp, and Bill Pay should be accepted or rejected as likely fraudulent. Stripe's internal risk models also use aggregated cardholder features to recognize when a large number of transactions are likely being conducted by the same individual for purposes of testing or cashing out stolen payment methods. Where Stripe recognizes such activity, it will block transactions to prevent harm to itself, its users, and others.
·Stripe Merchant Risk Tooling leverages Stripe's internal risk models to help Stripe Connect Platforms identify indicators of potential fraud associated with their Connected Accounts. Merchant Risk Tooling produces reasoned scores that identify to Platform's internal fraud teams when there are indicators consistent with a Connected Account attempting to use the Platform's services (and Stripe) for fraudulent purposes. These scores are designed to supplement the Platforms' due diligence related to their Connected Accounts and their business activities. They do not score the character or creditworthiness of the individuals involved in the Connected Accounts' operations. The data factored into Merchant Risk Tooling includes payments Transaction Data, business Representative details (such as IP address, physical address, and e-mail address) business website content, and other information regarding the businesses Business Users operate on Stripe.
·Along with attempting to combat fraud at the merchant and Stripe-wide levels as described above, Stripe also incorporates features in its individual products that use Personal Data to prevent fraud. One such feature is 3D Secure authentication, incorporated in Stripe Issuing. This feature is required by law in certain jurisdictions and requires cardholders to authenticate using one or more factors before they can complete an online transaction. Stripe and its service providers use and store Personal Data including cardholder PANs, contact information, and transaction history to authenticate cardholders using one time passcodes and knowledge of past transactions. These measures help combat fraud by increasing the likelihood that the person offering a card for payment is an authorized user.
·Stripe may collect additional information about your account to allow Stripe and its Financial Partners to detect fraud and/or fulfill financial compliance requirements. These requirements come from our Financial Partners or regulatory obligations and are intended to prevent abuse of the financial system. Examples of missing data fields include your address, phone number, social security number, date of birth, employer identification number, or website URL. Stripe may be able to fill in some of this information by leveraging data we have collected from one of your other Stripe accounts or by obtaining data from a third party. We will show Business Users the information that we are associating with their account on your dashboard, and Business Users may update or correct that information via your dashboard. Please see Stripe's Privacy Policy for additional information.
·Devices such as mobile phones or computers may collect precise location data using GPS technology. Stripe does not collect GPS data from devices and browsers.
·Depending on the Services you use and the Business Users' implementation of our Business Services, we will collect information (including IP addresses) through cookies and similar technology. We will collect your IP address when you visit our Sites. Please see our Cookie Policy to learn more. Stripe may use location information, including approximate latitude and longitude, derived from End Customers IP addresses to detect potentially fraudulent transactions.
·We also receive approximate location information (such as country, city or state) from third party providers such as MaxMind to help us determine the approximate location of Visitors to our website for marketing purposes (for example, inviting you to local Stripe events).
·When we work with service providers in our capacity as a data processor for our Business Users' and End Users' Personal Data, the GDPR calls these third-party service providers a sub-processor. Sub-processors are service providers who have or potentially will have access to or process Personal Data on behalf of Stripe where Stripe acts as a data processor for the Business User. These third parties are disclosed on our Stripe Sub-Processor and Service Providers List.
·In addition to Stripe's Sub-processors, we may also share Business Users' onboarding data and payment instrument information with third party business partners when this is necessary to provide our Services to our Business Users. We do so, for example, for the purposes of offering payment processing Services to our Business Users or facilitating payment settlements.
·Third parties to whom we may disclose Personal Data for this purpose are banks, payment method (service) providers, digital wallets and payment processors, including, but not limited to, the following entities:
·Learn more about payment methods. The data shared with payment method providers will depend on the payment method(s) enabled on the Business User's account.
·In addition, Stripe shares Personal Data as we believe necessary to, among other things, protect Stripe's Services, rights, privacy, safety and property of Stripe, our users or others. For example, to protect our Services, Stripe may receive or disclose information about IP addresses that malicious actors have compromised.
·Please note that if you provide us with your payment method information (e.g., a card number and expiration date) to store on file or otherwise in connection with a transaction, Stripe may update your card information if your information has changed or been updated to ensure your transactions go through smoothly, including by working with your card issuer or payment card network. If you would prefer to not have your updated payment method details shared with us, please reach out to your card issuing bank.
·Stripe will pass on Personal Data to affiliates and service providers or sub-processors, if deemed strictly necessary to carry out contractual obligations or for the data to be processed. Depending on the enabled payment method(s), data may be transferred to the jurisdiction(s) of the respective payment method(s). Before we engage any third party, we perform due diligence, including a vendor security assessment. All of our service providers are subject to contract terms designed to ensure that these service providers process Personal Data only for the purposes of providing services to Stripe and in accordance with our commitments to Users and applicable data protection laws. Moreover, Stripe maintains and enforces a security program that addresses the management of security and the security controls employed by Stripe, which includes third party risk management. In addition, Stripe employees, agents, and contractors acknowledge their data security and privacy responsibilities under Stripe's policies.
·If you are an End Customer who has been asked to link your financial account using Stripe, please visit the support webpage here to learn more about our privacy practices. Or you can jump to the specific topics linked here:
·Stripe makes it possible for its Business Users to enable payment methods including card networks such as Visa and MasterCard, mobile and online payment methods such as WeChat Pay and Alipay, and buy now pay later providers such as Klarna and Afterpay. Certain payment methods are enabled by default when you onboard with Stripe. After onboarding, for eligible users, Stripe may enable additional payment methods after notifying you. Your Stripe dashboard allows you to enable or disable payment methods at any time.
·Stripe may share information regarding a Business User and the Business User's Representative with a payment method provider when a payment method is enabled and when Stripe processes transactions involving the payment method. The payment method provider may require Business Users' and their Representatives' Personal Data for a number of purposes, including complying with know your customer (KYC), anti-money laundering, and other legal and compliance requirements, preventing fraud, facilitating transactions, providing Services to Business Users, and servicing the payment method's platform. For these purposes, Stripe may provide payment method providers with Business User data, including but not limited to business name, business type, merchant category codes, merchant ID, transaction history, bank account information, and other transaction specific information such as product type and tax amount that Stripe ascertains from that data. Stripe may also provide payment methods with Business Users' Representatives' Personal Data, including name, address, contact information, date of birth, tax identification number, and other government issued ID information. The information Stripe shares with payment method providers is data that Stripe has collected from the merchant or ascertained from data provided by the merchant.
·As part of providing our Services we may process Representative contact information for purposes including authentication, providing updates regarding the Services, providing support, and to address issues related to Business Users' Stripe accounts, such as unpaid balances.
·When processing payments, it's valuable to Stripe, Business Users and End Customers to enable legitimate transactions while also trying to prevent fraudulent transactions, making online purchases safer for everyone involved. Radar helps detect potentially fraudulent transactions for Stripe's Business Users (i.e., merchants) through machine learning and other techniques. To do this, Radar leverages data collected across our Services.
·Radar's artificial intelligence model produces transaction "scores" indicating the model's assessment of the likelihood that a transaction is fraudulent. Business Users can leverage this score and use it to implement automated rules to determine whether to allow, block, or flag transactions for additional review. Business Users can use Radar as one of multiple inputs in making decisions with respect to the potential for fraud in a transaction.
·Radar uses data collected about the End Customer from various sources, including payments Transaction Data, advanced fraud detection data, Bank Connections data, IP address, and physical address information. Radar uses this data to assess whether the payment method offered by the End Customer is likely unauthorized.
·Stripe may share with the Business User and allow them to export (where allowed by Law) certain information relevant to fraud detection, including:
·Under the terms of our agreements, Business Users are required to provide all necessary notices and obtain all necessary rights and consents from their End Customers to enable Stripe to lawfully collect, use, retain and disclose the Personal Data as part of the Stripe Services. Business Users, as data controllers and/or the End Customer facing entity, are responsible for the contents of their privacy notice and cookie banner. As an example, here is a paragraph that you can consider adding to your privacy notice or cookie (if you don't already have such a disclosure):
·We use Stripe for payments, analytics, and other business services. Stripe may collect personal data including via cookies and similar technologies. The personal data Stripe collects may include transactional data and identifying information about devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud and prevention and detection, authentication, analytics related to the performance of its services, and to enhance and customize the user experience. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.
·Please be aware that the disclosure above is for illustrative purposes only and is not legal advice. Please talk to your legal advisor to understand how to comply with your obligations under applicable law.
·To comply with our transparency obligations, we explain how our cookies are used in our Cookie Policy and our Cookies Settings Dashboard sets out our list of cookies. We remind our Business Users to review the cookies placed on their website and to update their cookie banners accordingly.
·Stripe, through its service providers, may use information from infoscore Consumer Data GmbH to verify the identity of Stripe Business Users in Germany. Information about infoscore Consumer Data GmbH is available here.
·If you have been notified by Stripe that we obtained your data from a third party, the following applies:
·In some situations, we may record and/or transcribe voice or video calls we have with you. At the start of the call, we disclose the fact that a call is being recorded and, unless we are legally required to record the call, will ask for your consent to record the call and/or offer you the option to decline the call being recorded. We may use third-party systems to record and/or transcribe calls, including Zoom and Salesloft. In some cases, transcripts are generated by AI tools.
·The call recordings will be processed for the purposes stated at the start of the call, typically for quality and training purposes, and in accordance with Stripe's Privacy Policy. We enable you to exercise your rights as a data subject under applicable law with respect to these recordings as set out in Stripe's Privacy Policy. In the event that you request a copy of the recording, Stripe may provide you with a redacted copy of the recording, or a (redacted) transcript of the recording, where appropriate, and as permitted under applicable law.
·We normally retain call recordings for up to 3 years. We may retain transcripts for a further limited period for training, quality and operational purposes.
·User support related phone calls are normally retained for 5 years as Stripe is under a legal obligation to keep this data for 5 years. Collection related call recordings are also kept for 5 years.
·After this, call recordings will be deleted, unless we have a valid legal ground to keep the call recordings for a longer period of time.
·When you use Stripe Services, we may need to verify your identity to comply with legal requirements or ensure that we are dealing with you and not a fraudster attempting to impersonate you. We may also verify your identity as a service to the Business Users with which you choose to transact. One of the data points we may consider for these purposes is whether your phone number is associated with the other information you have provided while seeking services from us or our Business Users. We may rely on third-party services providers to assist us in performing such verification checks. In particular, your wireless carrier may disclose information about your account and your wireless device, if available, to Stripe or our service providers for the duration of your business relationship, to help us identify you or your wireless device, to prevent fraud, and as otherwise described in our Privacy Policy.
·If you have a Link account, Stripe may review your Link Transaction Data to determine which businesses you transact with and which additional services you may benefit from. We may also, where permitted by law, use your Personal Data (such as your email address, device information, and transaction history) to send you marketing information about our Services or co-marketing communications about how you can use our Services with Business Users you transact or interact with. We do not share your Transaction Data or other Personal Data with these Business Users to facilitate these marketing activities.
·Below are the categories of data we collect and how that information is used in the last 12 months. We also disclosed this data for a business purpose within the preceding 12 months.
| CATEGORIES OF PERSONAL INFORMATION COLLECTED | PURPOSES: | DISCLOSED FOR A BUSINESS PURPOSE WITHIN THE PRECEDING 12 MONTHS TO: |
|---|---|---|
| Identifiers (e.g., a device identifier) | Identity verification, fraud prevention and security, to provide and advertise our Services, and to comply with law. | We may disclose the data, pursuant to applicable law, to: service enablers (including service providers, Financial Partners servicing the financial product), third parties like ad partners that help us advertise our products and Services, the merchant that you do business with (a.k.a. our Business User), an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies. |
| Characteristics of protected classifications under California or federal law (e.g., gender and age noted in ID documents that you submit so that Stripe can verify your identity on behalf of your merchant - a.k.a. our Business User) | Identity verification, fraud prevention and security, to provide our Services, and to comply with law. | We may disclose the data, pursuant to applicable law, to: service enablers (including service providers and Financial Partners servicing the financial product), the merchant that you do business with (a.k.a. our Business User), an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies. |
| Commercial information (e.g., the merchant that you choose to do business with - a.k.a. our Business User may receive your Transaction Data) | Fraud prevention and security, to provide our Services, to comply with law, enforce our terms of services, and for other purposes consistent with your consent and applicable law. | We may disclose the data, pursuant to applicable law, to: service enablers (including service providers and Financial Partners servicing the financial product), the merchant that you do business with (a.k.a. our Business User), an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies. |
| Biometric information (e.g., biometric identifiers from photo IDs used to confirm your identity) | Identity verification, fraud prevention and security, and for other purposes consistent with your consent and applicable law, such as to improve our verification systems. Learn more. | We may disclose the data, pursuant to applicable law, to: a service provider - i.e., Amazon Web Services ("AWS"), an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies. |
| Online activity information (e.g., information about devices and browsers across certain Business User sites that use Stripe and IP addresses associated with those devices and browsers, and usage data) | Fraud detection and security, to comply with law, and to provide and advertise our Services. | We may disclose the data, pursuant to applicable law, to: service enablers (including service providers, Financial Partners servicing the financial product), third parties like ad partners that help us advertise our products and Services, the merchant that you do business with (a.k.a. our Business User), an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies. |
| Location Data (Learn more) | Fraud detection and security, in furtherance of compliance with legal obligations, and to provide and advertise our Services. | We may disclose the data, pursuant to applicable law, to: service enablers (including service providers, Financial Partners servicing the financial product), third parties like ad partners that help us advertise our products and Services, the merchant that you do business with (a.k.a. our Business User), an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies. |
| Audiovisual (e.g., visual, audio, or similar information, like photos you submit so that Stripe can verify your identity on behalf of your merchant - a.k.a. our Business User) | Identity verification, fraud prevention and security, to provide our Services, and to comply with legal obligations. | We may disclose the data, pursuant to applicable law, to: service providers, the merchant that you do business with (a.k.a. our Business User), an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies. |
| Professional or Employment-Related Information | Recruiting and employment, and to comply with legal obligations. | We may disclose the data, pursuant to applicable law, to: service providers, an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies. |
| Categories of personal information described in Cal. Civ. Code 1798.80(e)(such as name, address, telephone number, credit card or debit card number) | See above. Identity verification, fraud prevention and security, to provide and advertise our Services, and to comply with legal obligations. | We may disclose the data, pursuant to applicable law, to: service enablers (including service providers and Financial Partners servicing the financial product), the merchant that you do business with (a.k.a. our Business User), an entity engaged in a business transfer/merger, law enforcement, courts, governments and regulatory agencies. |
·Stripe only processes sensitive personal information for the purposes specified in section 7027(m) of the California Consumer Privacy Act Regulations, or without the purpose of inferring characteristics about a consumer.
| Sensitive Personal Information Categories | Purposes include: |
|---|---|
| Identification documents, including driver's license, passport, and social security (including any underlying sensitive information in the identity card, such as racial or ethnic origin) | Identity verification, fraud prevention and security, to provide our Services, and to comply with legal obligations. |
| Biometric information | Identity verification, fraud prevention and security, and for other purposes consistent with your consent and applicable law, such as to improve our verification systems. Learn more. |
| Location Data Learn more. | Fraud detection and security, to comply with law, and to provide our Services. Learn more. |
| Account log-in, financial account in combination with any required security access code, password, or credentials allowing access to an account | To provide our Services (e.g., Financial Connections), comply with law, enforce our terms of services, and for other purposes consistent with your consent and applicable law. |
·We do not transfer your Personal Data to third parties in exchange for payment. However, as noted above, we may provide your Personal Data to third party partners, such as advertising partners, analytics providers, and social networks, who assist us in advertising our products and Services to you. Because these third parties may use the data Stripe provides for their own purposes (such as to improve their ad delivery), Stripe's provision of data to these parties may be considered a data "sale" or "sharing" as those terms are defined under the CCPA and other applicable US privacy laws. To our knowledge, Stripe does not sell personal information of minors under 16 years of age.
·Within the past 12 months, the following categories of Personal Information described in section 1798.80(e) of the California Civil Code have been "sold" or "shared" (as defined under the CCPA) to third parties (including advertising partners) who assist us in advertising our Services: Identifiers (e.g., a device identifier)
·You can opt out of targeted advertising and any related data "sales" or "sharing" here.
·Stripe keeps Personal Data as necessary to achieve the purposes listed here. To determine the appropriate retention periods for different categories of Personal Data, we consider various criteria such as the jurisdiction you are located in, the nature of our relationship with you, the types of products or Services being offered or provided to you, the nature and sensitivity of your Personal Data, retention requirements under applicable laws and regulations, and other legitimate interests we may pursue through retaining your Personal Data, including detecting and preventing fraud and financial crimes, enforcing and defending our legal rights, complying with valid legal process requests from courts or competent authorities, improving the quality of our Services, and promoting our products and Services as appropriate and as permitted by applicable law and agreements.
·For most jurisdictions, Stripe will generally keep Personal Data we obtain from our Business Users for a period of five or more years from the end of the business relationship with you, or the date of the last transaction, whichever is later.
·The table below outlines different categories of personal data collected, along with the retention period or the criteria used to determine that period.
| CATEGORIES OF PERSONAL DATA COLLECTED | RETENTION PERIOD OR THE CRITERIA USED TO DETERMINE THAT PERIOD |
|---|---|
| Non-sensitive Identifiers (e.g., name, postal address, email address, account name) Categories of personal information described in Cal. Civ. Code § 1798.80(e) (such as name, address, telephone number, credit card or debit card number) Characteristics of protected classifications under California or federal law (e.g., gender and age noted in ID documents that you submit so that Stripe can verify your identity on behalf of your merchant - a.k.a. our Business User) Commercial information (e.g., Transaction Data that the merchant you choose to do business with - a.k.a. our Business User - may receive) Online activity information (e.g., certain information about devices and browsers across certain Business User sites that use Stripe, and usage data) Audiovisual (e.g., visual, audio, or similar information, like photos you submit so that Stripe can verify your identity on behalf of your merchant - a.k.a. our Business User) | For the duration necessary for Stripe to: (1) comply with law; (2) provide the Stripe Services, and; (3) pursue our legitimate interests, including detecting and preventing fraud and financial crimes, enforcing and defending our legal rights, complying with valid legal process requests from courts or competent authorities, improving the quality of our Services, and promoting our products and Services as appropriate and as permitted by applicable law and agreements. |
| Biometric information (e.g., biometric identifiers from photo IDs and selfies used to confirm your identity) | No longer than 1 year, or upon revocation of your consent, whichever is earlier. |
| Geolocation Data (e.g., IP addresses) | For the duration necessary for Stripe to: (1) comply with law; (2) provide the Stripe Services, and; (3) pursue our legitimate interests, including detecting and preventing fraud and financial crimes, enforcing and defending our legal rights, and complying with valid legal process requests from courts or competent authorities. |
| Professional or Employment-Related Information Education information that is not publicly available as defined in the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g) | For the duration necessary for Stripe to: (1) comply with law; (2) make certain employment and performance-related decisions; (3) address future hiring needs; (4) ensure health and safety in the workplace; (5) conduct certain administrative tasks, including to administer benefits; and (6) pursue our legitimate interests, including enforcing and defending our legal rights and complying with valid legal process requests from courts or competent authorities. |
| Sensitive personal information, as defined by California law (Learn More) | For information regarding your government IDs (including the sensitive data therein) and your location data, Stripe will retain that data for the duration necessary to: (1) comply with law; (2) provide the Stripe Services, and; (3) pursue our legitimate interests, including detecting and preventing fraud and financial crimes, enforcing and defending our legal rights, complying with valid legal process requests from courts or competent authorities. For biometric data, see above.Where we rely on consent to collect your other sensitive personal information (e.g, financial account login credentials), Stripe will no longer retain this data upon your revocation of consent. |
·The following includes aggregate metrics of data subject rights requests received in the 2023 calendar year. This data reflects requests received from individuals in California and may also include requests from individuals who do not reside in California.
·Due to the nature of Stripe's products and Services, when we receive a general "request to delete," our process is to direct the requestor to a page to action their request depending upon the relationship they have with Stripe. We also offer data subjects the opportunity to contact us, should they have any questions or concerns.
·Stripe may retain Personal Data where permitted by law, including to comply with our legal obligations. For example, as a provider of payment services, Stripe is required to comply with many regulations, including anti-terrorism and anti-money laundering laws. These laws require Stripe to retain certain information associated with Stripe users for a prescribed period of time after account closure. Learn more about our retention obligations in our Privacy Policy.
·We rely upon a number of legal grounds to enable our use of your Personal Data. In short, we use Personal Data to facilitate the business relationships we have with our Business Users and End Users, to comply with our financial regulatory and other legal obligations, and to pursue our legitimate business interests. We also use Personal Data to complete transactions and to provide payment-related Services to our Business Users.
·The table below provides a detailed overview of why and how we use your Personal Data.
·For the purposes of the EU and UK GDPR and the Thai Personal Data Protection Act 2019 ("PDPA"), we rely upon a number of legal bases to enable our processing of your Personal Data.
·When you directly use an End User Service (such as when you sign up for Link, or make a payment to Stripe Climate in your personal capacity), for your personal use, we refer to you as an "End User."
| PROCESSING PURPOSE | CATEGORIES OF PERSONAL DATA | LEGAL BASES |
|---|---|---|
| Provide our Services. To provide Services to you, including delivery, support, personalization and messages related to the service. | Your name, contact information, payment information including Bank Account Information and Bank Payments, and/or payment card number, CVC code and expiration date. | Our contractual necessity to perform our contractual relationship with you, under applicable data protection laws. |
| For the provision of our Services including Link, Atlas and Identity. When we process data based on your consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing based on such consent before the consent is withdrawn. | If you choose to use Link you agree to let Stripe store your payment method and related information so that you can more readily make purchases with Business Users who use Stripe to provide payment processing Services (e.g. Stripe Checkout). | Based on consent in processing this personal information. |
| Card Products and Financial Products including Issuing and Treasury Direct Services.We use your Personal Data to offer you card products and financial products and Services under the Stripe brand and/or under the brand of a Business User. | Your name, email address, phone number, postal address, transaction information, password, PIN or similar credentials, card PANs, age, DOB, credit card number, drivers license number, tax ID, cookie data, tags and beacons, IP address. | Our legitimate interests in promoting our products and in determining eligibility for and offer new Stripe products and Services. |
| Provide cryptocurrency-related Services, including enabling End Users with Link accounts to purchase cryptocurrency from licensed third-party cryptocurrency exchange providers using a variety of payment methods and save certain personal information to facilitate subsequent cryptocurrency-related transactions. | Your name, email address, date of birth, billing address, IP address, information related to your cryptocurrency wallet (including wallet identifier, access times, and IP address used to create and access the wallet), and information related to your cryptocurrency purchases, including your transaction history. | Based on consent in processing this personal information. |
| Offer our Services and Alert you of Changes to our Services.For example, through Stripe Capital we work with Financial Partners to offer financing to certain users who can satisfy particular criteria and will process your data to help determine if you qualify for financing or not. Certain information will be processed by Stripe prior to the offer of financing in order to determine eligibility. | The name and other identifying details and contact information of a Business User's Representatives, physical address of Business User, and the Business User's Stripe ID and information related to the Business User's performance on Stripe or off of Stripe if the Business User chooses to provide such information. | Our legitimate interests in promoting our products and in determining eligibility for and offer new Stripe products and Services. |
| Fraud Detection Services. We use your Personal Data collected across our Services (e.g. Stripe Radar) to detect and prevent fraud against us, our Business Users and Financial Partners, including to detect unauthorized log-ins using your online activity. | Transaction information. This includes: name, email address, billing and/or shipping address, payment method information (such as credit or debit card number, bank account information or payment card image), merchant and location, purchase amount, date of purchase, and in some cases, some information about what you have purchased, phone number and tax-related ID.This includes web browsing information, usage data, referring URLs, location, cookies data, device data and identifiers.IP address and physical address. | Our legitimate interests in monitoring and detecting fraud to ensure we detect activity that can have a harmful effect on our End Users. |
| Marketing and Advertising. We may use your Personal Data to assess your eligibility for and offer you other Services. We use End User Personal Data for interest-based advertising and marketing purposes. We do not share End Customer Personal Data to third parties for their marketing purposes unless you give us or the third party permission to do so. | Contact information including: name, email address, work phone number, and job title.Connection data such as IP address, and web behavior (page visited, length on page, etc.) | Based on consent in processing this personal information.Our legitimate interest in undertaking marketing activities to offer you products or Services that may be of interest to you. |
| Compliance and Harm Prevention. We process and share Personal Data as we believe necessary: (i) to comply with applicable law, (ii) for compliance with rules imposed by payment method in connection with use of that payment method (e.g. network rules for Visa); (iii) to enforce our contractual rights; (iv) to secure or protect the Services, rights, privacy, safety and property of Stripe, you or others, including against other malicious or fraudulent activity and security incidents; and (v) to respond to valid legal process requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include authorities outside your country of residence. | Any Personal Data we process, including information necessary for identity verification such as government-issued IDs or selfie images. | Where these processing activities or disclosures are necessary to comply with our legal obligations, for the protection of a person's vital interests, for reasons of public interest, for reasons of substantial public interest, or for the purposes of Stripe's or a third party's legitimate interest in keeping Stripe secure, preventing a breach of the law, harm or crime, enforcing or defending legal rights, claims, or obligations, facilitating the collection of taxes and prevention of tax fraud or preventing loss or damage. |
·When you do business with, or otherwise transact with, a Business User (typically a merchant using Stripe Checkout, e.g. when you buy a pair of shoes from a merchant that uses Stripe for payment processing) but are not directly doing business with Stripe, we refer to you as an "End Customer."
| PROCESSING PURPOSE | CATEGORIES OF PERSONAL DATA | LEGAL BASES |
|---|---|---|
| Provide our Services to Business Users, including to process online payment transactions or in-person checkout, to calculate applicable sales tax, to invoice and bill, and to calculate their revenue.If you are an End Customer, when you make payments to, send shopping cart reminders, get refunds from, begin a purchase or otherwise transact with a Business User through Stripe's Services or a Stripe-provided device, Stripe will receive your transaction information. Depending on how the Business User has integrated our Business Services, we may receive this information directly from you, the Business User or another service provider to you or the Business User. | Transaction Information (including from Checkout, Payment Processing and Treasury/Issuing Use). Your name, email, billing and/or shipping address, payment method information (such as credit or debit card number, bank account information or payment card image), merchant and location, purchase amount, date of purchase, and in some cases, some information about what you have purchased, phone number and tax-related ID. The payment method information that we collect will depend upon the payment method that you choose to use from the list of available payment methods offered by the Business User as part of the "checkout" process for your purchase. We may also receive your transaction history with the Business User.Transaction-Related Information / Purchase Interests. Information typed into a checkout field that is not ultimately submitted to the Business User. | Our legitimate interests in providing the Stripe products and Services. Stripe processes this Personal Data given its legitimate interest in improving the Services and where it is necessary for the adequate performance of the contract with the Business Users. |
| Provide our Services to Business Users, to order payment methods on a per-customer basis on behalf of the Business User, to implement fraud thresholds chosen by the Business User, and to verify your payment method. | Verification Information. Your age (when purchasing age restricted goods) or information about you being the person who is authorized to use a payment method.The information collected will be the information that you choose to share for these purposes, which may include your government ID, your photo, your live image, and Personal Data apparent from the physical payment method (e.g. credit card image). | Our legal obligations in respect of our financial and regulatory obligations. |
| Reduce fraud and enhance security. We will use Personal Data about your identity, including information that you provide, to perform verification Services for Stripe or for the Business Users that you are doing business with and to reduce fraud and enhance security. | In some cases you may provide a "selfie" along with an image of your identity document, and we will use technology to compare and calculate whether they match and can be "verified." We will use information from our service providers and our Services to help verify your identity and fraud prevention. | Based on consent in processing this personal information.Our legitimate interests in detecting, monitoring and preventing fraud and unauthorized payment transactions. |
| Radar and Card Verification Services. We use Personal Data of End Customers to detect and prevent fraud for Business Users, including to detect fraudulent payment cards using payment card images and unauthorized log-ins using online activity. In providing such Services, we may provide Business Users that have requested such Services with limited Personal Data about End Customers so that the Business Users can assess the fraud risk associated with an attempted transaction by its End Customer. We may also use payment card images to improve our Business Services. | Transaction information. This includes: name, email address, billing and/or shipping address, payment method information (such as credit or debit card number, bank account information or payment card image), merchant and location, purchase amount, date of purchase, and in some cases, some information about what you have purchased, phone number and tax-related ID.This includes web browsing information, usage data, referring URLs, location, cookies data, device data and identifiers.IP address and physical address. | Our legitimate interests in detecting, monitoring and preventing fraud and unauthorized payment transactions. |
| Compliance and Harm Prevention. We share Personal Data as we believe necessary: (i) to comply with applicable law, (ii) to comply with rules imposed by payment method in connection with use of that payment method; (iii) to enforce our contractual rights; (iv) to secure or protect the Services, rights, privacy, safety and property of Stripe, you or others, including against other malicious or fraudulent activity and security incidents; and (v) to respond to valid legal process requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include authorities outside your country of residence. | Any Personal Data we process. | Our legal obligations where disclosures are necessary to comply with our legal obligations.Our legitimate interest in keeping Stripe secure, preventing a breach of the law, harm or crime, enforcing or defending legal rights, claims, or obligations, facilitating the collection of taxes and prevention of fraud or preventing loss or damage. |
·When you are acting on behalf of an existing or potential Business User (e.g. you are a founder of a company, or administering an account for a merchant who is a Business User), we refer to you as a "Representative."
| PROCESSING PURPOSE | CATEGORIES OF PERSONAL DATA | LEGAL BASES |
|---|---|---|
| Reduce fraud and enhance security. We will use Personal Data about your identity, including information that you provide, to perform verification Services for Stripe. | Onboarding and verification information that you choose to share for these purposes, which may include your government ID, photo, live image, and Personal Data apparent from the physical payment method (e.g. credit card image). | Our legal obligations in respect of our financial and regulatory obligations. We process Personal Data to verify the identity of the Representatives of our Business Users in order to comply with fraud monitoring, prevention and detection obligations, laws associated with the identification and reporting of illegal and illicit activity, such as AML (Anti-Money Laundering) and KYC (Know-Your-Customer) obligations, and financial reporting obligations. |
| Advertising. We may use and share Representative Personal Data with others so that we may advertise and market our products and Services to you, including through interest-based advertising subject to any consent requirements under applicable law. | Contact information including: name, email address, work phone number, and job title.Connection data such as IP address, and web behavior (page visited, length on page, etc.) | Based on consent in processing this personal information. |
| Communications.We may send you email marketing communications about Stripe products and Services, invite you to participate in our events or surveys, or otherwise communicate with you for marketing purposes, provided that we do so in accordance with applicable law, including any consent or opt-out requirements. | Contact information such as your name, email address, phone number. | Based on consent in processing this personal information.Our legitimate interests in responding to inquiries, sending Service notices, ensuring compliance with applicable laws, preventing fraud, improving our Services and providing customer support. |
| Tax and Atlas (Incorporation) Services. We may use your Personal Data to file taxes on behalf of your associated Business User. If your Business User uses Atlas, we may use your Personal Data to submit forms to the IRS on your behalf and to file documents with other governmental authorities. | Your contact details, such as name, postal address, telephone number, and email address; and financial and personal information about you, such as your ownership interest in the Business User, your date of birth and government identifiers associated with you and your organization (such as your social security number, tax number, or Employer Identification Number). You may also choose to provide bank account information. | Our compliance with legal obligations in respect of our financial and regulatory obligations. We process Personal Data to verify the identity of the Representatives of our Business Users in order to comply with fraud monitoring, prevention and detection obligations, laws associated with the identification and reporting of illegal and illicit activity, such as AML (Anti-Money Laundering) and KYC (Know-Your-Customer) obligations, and financial reporting obligations.Our contractual necessity to perform our contractual relationship with you, under applicable data protection laws. |
·When you visit a Site without being logged into a Stripe account or otherwise communicate with Stripe, we refer to you as a "Visitor." (e.g. you send Stripe a message asking for more information because you are considering being a user of our products).
| PROCESSING PURPOSE | CATEGORIES OF PERSONAL DATA | LEGAL BASES |
|---|---|---|
| Communications. We use any contact information that you provide to us to respond to any inquiries or requests for information you made; and if you have asked about us or our Services, to send you marketing emails by either asking for your consent or providing you an opt out in any messages we send. | Contact information such as your name, email address, phone number.Information you have provided to us, such as the products you are interested in. | Based on consent in processing this personal information.Our legitimate interests in responding to inquiries, sending Service notices and providing customer support. |
| Advertising. When you visit our Sites, we (and our service providers) may use Personal Data collected from you and your device to target advertisements for Stripe Services to you on our Sites and other sites you visit ("interest-based advertising"). | Information collected from cookies such as your device, browser ID, and pages on our website which you have visited. | Based on consent in processing this personal information.Our legitimate interest in undertaking marketing activities to offer you products or Services that may be of interest to you. |
| Fraud Detection. We use your Personal Data collected across our Services to detect and prevent fraud against Stripe, our Business Users and Financial Partners. | Advanced Fraud Signals information collected via cookies. This includes web browsing information, usage data, referring URLs, location, cookies data, device data and identifiers. | Our legitimate interests in detecting, monitoring and preventing fraud and unauthorized payment transactions. |
·A Data Processing Agreement ("DPA") is a contract between a data controller and a data processor that describes the roles and responsibilities of the parties when personal data is processed. If you are a Business User, please visit our FAQs page here to learn more about our DPA. Please contact us or your account manager if you have any questions.
·Privacy by design aims at building privacy and data protection up front and into the design specifications and architecture of information and communication systems and technologies to facilitate compliance with privacy and data protection principles. We rely on our internal privacy team and a review process for any new product launch. We are dedicated to proactively embedding privacy throughout the product development lifecycle, from engineering to product management. This helps ensure that people can trust the Stripe products that they enjoy every day.
·If you have been asked to verify your identity or have verified your identity using Stripe Identity, please visit the support web pages here and here to learn more about our privacy practices for Stripe Identity. Alternatively, you can jump to the specific topics linked here:
·If you are a Business User that is using or intends to use Stripe Identity, please visit the support web page here for additional guidance on what you can tell your users and here and here for additional guidance on privacy considerations for your business.
·If you have been asked by your merchant (i.e., a Stripe Business User) to scan your credit card before completing your requested transaction, please visit the support webpage here to learn more about Stripe's Card Image Verification.
·Stripe Connect is a payment software your third party platform provider (Platform) may use to enable you to receive Stripe Services (including payment processing) and/or receive payouts.
·Stripe acts as both a data controller and data processor for the Platform. The Stripe entity that acts as data controller/ data processor for data processed in Europe is Stripe Payments Europe Limited ("SPEL").
·The Personal Data transmitted to Stripe usually involves first name, last name, address, identification number, e-mail address, IP address, telephone number, and other data necessary for payment processing.
·The transmission of the data is aimed at payment processing, ledger management, and fraud prevention. The Business User / Platform will transfer Personal Data to Stripe. The Personal Data exchanged between Stripe and the Business User / Platform may be transmitted to verification agencies, and Business User data may be shared with Platforms. This transmission is intended for the Platform to manage its ledger and for Stripe to conduct identity and risk checks.
·Stripe will pass on Personal Data to affiliates and service providers or sub-processors, if deemed necessary to carry out contractual obligations or for the data to be processed.
·For full details please see the applicable Privacy Policy of Stripe.
·If you are a user with a Custom connected account, Stripe may collect additional information about your account to enable fraud detection and fulfill financial compliance requirements. These requirements for additional information come from our regulators or Financial Partners and are intended to prevent abuse of the financial system. Examples of missing data fields include your address, phone number, social security number, date of birth, employer identification number, or website URL. Stripe may leverage data we already have from one of your Stripe accounts or Stripe may fill in some of this information by receiving data from a third party. You may view the information that we are associating with your account and update or correct that information by contacting the platform or business that created your Stripe payment account. Please see Stripe's Privacy Policy for additional information.
·You, the Platform, are responsible for all interactions with your Custom accounts and for collecting all of the information needed to verify the Custom account-holders. Since Custom account holders cannot log into Stripe, it is up to you to build the user dashboard and communication channels. You are responsible for actioning any request by a user to update or correct their Stripe Custom account information.
·Card networks and issuers use statement descriptors to identify payments on a cardholder's bank statement. Statement descriptors usually include information about the payment, such as the name and phone number of the seller. However, the exact information displayed is ultimately up to a cardholder's bank. If Stripe updates your account's business address, phone number, or email address, these fields may be displayed on the statement descriptor within the cardholder's bank statement. However, the exact information displayed is ultimately up to the card network or the cardholder's bank. If any information is incorrect, please reach out to the platform through which you receive charges to ensure you have provided them with the most accurate information about you and your business.
·Promotional Emails is a feature that gives Business Users who use "Stripe Checkout" Services a tool to enable sending email promotional content to their customers and prospective customers. When you visit a Business User's checkout page (that is powered by Stripe Checkout Services), the Promotional Email feature will enable Stripe to collect information about your preferences to receive promotional emails from that merchant.
·Promotional email preferences are collected whether or not you complete the purchase or are just a prospective End Customer. "Prospective End Customer" means you visited a Business User's site and expressed an intent to make a purchase by starting a purchase on the Business User's checkout page, but did not complete that purchase during that session. To be a "prospective End Customer" for the promotional email feature, you also need to have started to input your contact information into the checkout form, and then not delete that information prior to the end of the session.
·If you, prospective End Customer, indicate permission to receive news and personalized offers by virtue of the opt-in/opt-out checkbox on your Business User's checkout form, the following Personal Data is provided to your Business User so that your Business User can contact you to remind you of the items you left in the checkout or to provide you news and personalized offers:
·"Personalized offers" means promotional or marketing materials tailored to you, such as coupons or advertisements based on the items in your cart or (in some cases) your prior purchases from that Business User. Even if you opt-out of personalized offers by a Business User, if you do business with that Business User, they may still need to contact you in order to enable a purchase (e.g., for delivery or billing purposes) or in connection with customer support. Please see your Business User's privacy policy for more information.
·For the Promotional Emails feature, Stripe acts as a data processor or service provider, meaning that Stripe is acting at the direction of the Business User that has implemented this Stripe provided feature. The Stripe entity that acts as a data processor for Personal Data is:
·Stripe's Privacy Policy describes in more detail the Personal Data that Stripe collects in connection with payment transactions.
·Whenever you complete a transaction on a Business User's website that uses Stripe services, as a service provider to that Business User, Stripe will share your contact information with that Business User. Business Users use the information that Stripe provides in accordance with its own privacy policy, including in connection with your purchase.
·End Customers and prospective End customers should always review the privacy policy or notice of the Business Users they visit and do business with for information about the Business User's data collection practices and purposes outside of this Stripe feature.
·No. Stripe does not share Personal Data collected in connection with purchases (or attempted purchases) from one Business User's checkout with another Business User. Please see our Privacy Policy to learn more about our practices.
·Any offers or promotional emails that you receive as a result of a Business User's use of the Promotional Emails feature are sent by Business Users (or others identified in the message), and not by Stripe. I If you do not find value in receiving these emails, please contact the Business User you are receiving the messages from. Stripe requires that Business Users that choose to implement the Promotional Email feature also provide the option to unsubscribe or opt-out of receiving further promotional messages. It would be a breach of Stripe's terms of service for a Business User to not promptly comply with opt-out requests.
·The Promotional Email feature does not use cookies or track you across Business Users. Information collected from the Business User's checkout page is transferred only to the Business User via API calls or webhooks. Webhooks are a way for Stripe to send the information to the Business User automatically upon their request. Your information provided at checkout is encrypted in transit using HTTPS and TLS. See Security at Stripe for more information.
·Stripe does not sell your Personal Data. See our Privacy Policy for more information. The Promotional Emails feature is not the sale of Personal Data. Rather, Stripe acts as a processor (or service provider) to Business Users for the Promotional Email feature. Please contact your Business User to learn about their Personal Data practices and how you can exercise rights to stop the sale or processing of Personal Data provided under applicable law and/or their privacy policy.
·Stripe requires that Business Users that choose to implement the Promotional Email feature also provide the option to unsubscribe or opt-out of receiving further promotional messages. It would be a breach of Stripe's terms of service for a Business User to not promptly comply with opt-out requests.
·If you are a business that is using or intends to use Stripe's Promotional Emails feature, please visit the support webpage for tips and guidance on information to share with your End Customers and prospective End Customers regarding privacy considerations in connection with the Promotional Emails feature for your business.
·You may be given the option to enable on-device biometric verification and provide your consent for Stripe to store your payment method details for future transactions that use the same card. Please visit our support site to learn more about our privacy practices for Stripe Delegated Authentication. Alternatively, you can jump to a specific topic here:
·We offer you the opportunity to store your payment methods with us so that you can conveniently use it across certain merchants who are our Business Users - we call this "Link" (formerly known as "Remember Me"). When you choose to use Link, you agree to let us store your payment method so that you can more readily make purchases through Link with Business Users of our payment processing Business Services (e.g., name, card number, cvc, and expiration date). We will also collect other Transaction Data, including billing address, shipping address, email and phone number. Your payment method data is secured using PCI-DSS standards.
·Should you not have used Link and receive an SMS in error due to an inaccurate number being inserted at the authentication flow stage you can opt out here and your Personal Data will be deleted.
·When you see "Sold through Link," Stripe acts as the merchant of record on behalf of the Business User.
·Business Users can offer and sell their digital products using Stripe Managed Payments under the "Sold through Link" brand. If you place an order for a digital product where you see "Sold through Link" - or if your card or bank statement shows "Link.com*[Business User name]" (or similar) - your purchase is being handled by Stripe through its Stripe Managed Payments product on behalf of the Business User.
·Stripe also provides additional support and order management services through Link to help you manage your orders that were Sold through Link. They include:
·For subscriptions that are Sold through Link, you must have a Link account to ensure we can verify your identity, manage ongoing payments, and provide continuous support. We provide these features in addition to the core Link experience described in the Link Privacy Policy and subject to these terms.
·When you complete a "Sold through Link" order, Stripe shares your order information with the Business User so they can fulfill your order and manage their relationship with you. This may include your contact information, payment information, tax identification number, billing and shipping address, and order details.
·The Business User may retain this information and use it according to their own privacy policy. For more details on how the Business User may handle your data, please refer to the Business User's privacy policy.
·You can request that your information be deleted from Link in connection with your "Sold through Link" orders by requesting the deletion of your Link account. To request deletion, please follow the instructions on this page.
·Deleting your Link account will also result in:
·Please note that the Business User may have stored the information provided during checkout (such as your contact and billing details) independently of Link in accordance with their own privacy policy. We recommend reaching out to them directly if you would like them to delete your information as well.
·When using Link you can choose to pay for purchases using Buy Now, Pay Later (BNPL) services or crypto wallets.
·With respect to BNPL, in order to facilitate the transaction we send and receive data from the BNPL provider you choose (i.e., Klarna). During the checkout process, we will notify you of what data will be shared and whom it will be shared with. The Personal Data we share may include your name, address, email, IP address, phone number, date of birth, social security number (we will only collect and share this data if required by your choice of financing), and any other relevant Transaction Data. Stripe will also receive and retain similar information from your choice of BNPL provider for any discrepancies.
·When you select a BNPL provider, you will also be provided with their terms of use and privacy policy. Any data you provide to Link is governed by our Terms of Service and Privacy Policy. Any data we share at your direction, with a BNPL provider of your choice, will be subject to their terms of use and privacy policy.
·While merchants can enable Affirm or Klarna as a payment method, Link users can connect their Link and Klarna accounts. As we add more BNPL providers, we will continue to update this page with any relevant information.
·When you use Link to pay with a supported crypto wallet service, such as Phantom, we will similarly need to share certain Personal Data with the crypto wallet provider. This may include your name, address, date of birth, government-issued ID, and other KYC-related information. At Phantom's direction, this KYC data may be forwarded to their approved third-party partners. Phantom will only forward your data to these partners after obtaining your explicit consent, ensuring you are informed and agree to this onward sharing.
·As with BNPL services, any data we share at your direction with a crypto wallet provider is subject to that provider's terms of use and privacy policy. Data you provide to Link is governed by our Terms of Service and Privacy Policy, while any data shared onward at Phantom's direction will be subject to their terms and privacy policy.
·Currently, Link supports the Phantom crypto wallet. As we add more supported crypto wallet providers, we will update this page with the relevant information.
·Stripe Capital provides Business Users with access to fast, flexible funding so businesses can manage cash flows and invest in growth. Through Stripe Capital for Platforms, Platforms can also enable financing offers to be extended to their users, including their Connected Account. Depending on your business's corporate structure and jurisdiction, you may be eligible for different types of financing.
·In partnership with Stripe Capital, financing is provided by one of our financial partners depending on where your business is located:
·We use existing data linked to your Stripe account to evaluate your business's eligibility to receive an offer for Stripe Capital. In Capital for Platforms, we follow the same approach, except that we will review existing data linked to a Connected Account's Stripe Account to assess their eligibility.
·The following information may be considered prior to the offer of financing in order to determine eligibility, including: Payment processing volume Refund/disputes rate Duration of relationship with Stripe Bank account balances Transaction history
·If your business is based in the US, you may also be asked to link additional data sources, such as business bank accounts or business credit information, in order to receive financing through Stripe Capital. Additionally, the following information may also be processed prior to the offer of financing for your US business: Business credit history
·In the US, Platforms may elect to extend offers for financing to their customers, regardless of whether they process payments through Stripe. In accordance with the Platform's terms with its customers, the Platform may share off-Stripe transaction history and other business information with Stripe in order to assess the business' eligibility for financing. If applicable, the Platform may also share contact information to enable Stripe to notify the business about their financing offer. Any information shared by the Platform will be protected in accordance with Stripe's Privacy Policy. If the business decides to apply for financing, it will be invited to create a Stripe account and its information will be shared with our financial partners as described below. Learn more.
·Where Stripe is satisfied that a business meets particular criteria established by Stripe and our financial partners (as applicable), we, or the Platform, will send the business an email and/or a dashboard notification notifying them of their business's eligibility for potential financing from a financial partner and invite them to apply.
·When a business initiates the application process, Stripe pre-populates the application form with information from the business's Stripe account and requires the business to confirm that it is correct. When you submit an application, your information will be shared with our financial partner in your region.
·This information may include: Company name Business display name Annual revenue Company number Company phone number and address Business URL (or Product Description) MCC (or Industry) Business address Business phone number Business email
·A Representative who has authority to sign a loan agreement on behalf of the company (such as a director, board member, an owner of 25% or more of the company, or otherwise someone with significant management control) may be asked to provide the following personal information as part of the application process and that information will be shared with our financial partner in your region: Name
·We will process your Personal Data in accordance with our legitimate business interests. Analysis of your Personal Data helps us to manage our business in accordance with our legitimate interests. It allows us to:
·We will also process your data where it is necessary for a financing agreement that you have entered into or because you have submitted an application to receive funding and to determine eligibility to enter into a financing agreement with us or with our financial partners.
·We, or the Platform, may send you email marketing communications about Stripe Capital offers, provided we, or the Platform, do so in accordance with applicable law, including any consent requirements.
·Stripe may share your and your Representative's Personal Data with its financial partners in order to determine your eligibility for financing you have requested, or to enable you to apply for financing or as necessary complete and/or service transactions with financial partners who in some cases may purchase the right to receive repayment on your financing. Stripe may also share and obtain information about you, your business and your Representatives from Stripe's service providers and other third parties, including credit reporting agencies, banking partners and information bureaus. If you're a Connected Account, we may also share and receive information about you with your Platform, in accordance with your agreement with them.
·The Stripe entity responsible for your Personal Data will depend on the location of your business. Please see our Privacy Center article here for more information on the data controller that is responsible for Personal Data collected and processed in relation to Stripe Capital. Canada
·This section contains information about Stripe Capital and Stripe Capital for Platforms for Business Users located in Canada (including Quebec).
·When you apply for financing through Stripe Capital or Stripe Capital for Platforms, Stripe transfers your Personal Data to our financial partner, Fundbox Inc, which processes and stores data in the United States. This transfer is necessary to enable Fundbox Inc to process your application, and to provide financing to your business.
·In addition to the information listed above, Stripe processes and shares your Business Number with Fundbox Inc as part of your application.
·Business Users have the option to unsubscribe or opt-out of receiving Capital offers via the link included in Stripe Capital emails. Business Users may also opt-out of dashboard notifications via the settings page of the Stripe Dashboard. If you're a Connected Account using Capital for Platforms, please contact your platform owner to unsubscribe or opt-out of receiving Capital offers. If you have any questions, please contact us.
·Yes. For example, Stripe enables the Business User to import non-Stripe data through the Stripe Dashboard to consolidate their revenue data in one place. Learn more. Separately, Stripe may also obtain your account transactions from your financial account with your consent. Learn more.
·If you have been asked to provide your bank account and other information to process a refund on behalf of your merchant (i.e., our Business User), please visit the webpage here to learn more about our privacy practices for End Customer bank account refunds.
·If you are a Business User that is using or intends to use Stripe to process refunds, please visit the webpage here for additional guidance on privacy considerations for your business.
·Frontier is an advance market commitment (AMC) that aims to accelerate the development of carbon removal technologies by guaranteeing future demand for them. It facilitates purchases from high-potential carbon removal companies on behalf of buyers. Learn more at https://frontierclimate.com/.
·We will collect any information you choose to provide to us, for example, through support tickets, emails or social media. When you respond to Stripe emails or surveys, we collect your email address, name and any other information you choose to include in the body of your email or responses. If you contact us by phone, we will collect the phone number you use to call Stripe, as well as other information you may provide during the call. We will also collect your engagement data such as your registration for, attendance of, or viewing of Stripe events and other interaction with Stripe personnel. See our privacy policy for more information.
·We rely on consent to process your data. Where you proactively reach out to Stripe and provide your data, Stripe will process your data based on Stripe's legitimate business interests (e.g. help answer your queries, and provide customer support). With your permission or where allowed by law, we use your personal data to market our services to you, invite you to participate in our events or surveys, or otherwise communicate with you for our marketing purposes, provided that we do so in accordance with applicable law, including any consent or opt-out requirements.
·We are a global business. Personal Data may be stored and processed in any country where we do business. We may transfer your Personal Data to countries other than your own country, including to the United States. These countries may have data protection rules that are different from your country. When transferring data across borders, we take measures to comply with applicable data protection laws related to such transfer. In certain situations, we may be required to disclose Personal Data in response to lawful requests from Officials (such as law enforcement or security authorities). See our privacy policy for more information.
·You may have choices regarding our collection, use and disclosure of your Personal Data. If you no longer want to receive marketing-related emails from us, you may opt-out via the unsubscribe link included in such emails or as described here. We will try to comply with your request(s) as soon as reasonably practicable. Depending on your location and subject to applicable law, you may have the following rights described here with regard to the Personal Data we control about you.
·EEA and UK . To exercise your rights, you may contact our DPO. If you are a resident of the EEA or we have identified Stripe Payments Europe Limited as your data controller, and believe we process your information within the scope of the General Data Protection Regulation (GDPR), you may direct your questions or complaints to the Irish Data Protection Commission. If you are a resident of the UK, you may direct your questions or concerns to the UK Information Commissioner's Office.
·California . If you are a consumer located in California, please review the California Consumer Privacy Act ("CCPA") section of our Privacy Policy.
·See our privacy policy for additional jurisdiction-specific provisions.
·If you have any questions or complaints, please contact us.
·Yes, Stripe has appointed a Data Protection Officer ("DPO"), who can and they can be reached via email.
·Stripe's Chief Privacy Officer is the person in charge of personal information. You may contact them via email.
·We are committed to protecting personal information and have established policies and procedures that govern our treatment of personal information. These policies and procedures include, among other things, the following:
·The detail below is provided for informational purposes. It is not intended to provide legal advice. Stripe urges Business Users to consult with legal counsel to familiarize themselves with the requirements that govern their specific situations.
·As a global business, Personal Data may be transferred to, and processed, in any country where we do business, where our service providers do business or if you use an international payment method or financial partner service, the countries in which that payment method or financial partner operates.
·We may transfer your Personal Data to countries other than your own country, including to the United States. Stripe relies on a number of data transfer mechanisms to legalize the transfer of Personal Data around the globe.
·Stripe continues to have appropriate safeguards and compliance measures to ensure an adequate level of protection of Personal Data transferred outside the UK, EEA and Switzerland. Stripe's measures may include:
·Stripe respects the privacy of everyone that engages with our products and Services, and we are committed to being transparent about our privacy processes and policies. To learn more about our commitment to privacy and data security, please see our Privacy Policy, the rest of the Stripe Privacy Center, and the Stripe Security Center.
·We also want to highlight some of our supplementary measures to protect our Business Users' data from unauthorized access.
·Stripe employs security controls and maintains and enforces a security program that addresses the management of security. We also perform risk assessments and implement and maintain controls for risk identification, analysis, monitoring, reporting, and corrective action. Stripe maintains and enforces an asset management program that appropriately classifies and controls hardware and software assets throughout their life cycle. In addition, Stripe employees, agents, and contractors acknowledge their data security and privacy responsibilities under Stripe's policies.
·Stripe applies technical and organizational measures that include the following:
·By default, Stripe encrypts data at rest and data in transit. We further protect your data with tools like audit logs, access management policies and certifications as described on our Payments page in the section "Security and compliance at the core". Security controls implemented at Stripe include TLS 1.2 configuration of endpoints for data in transit, TLS and/or SSL encryption for HTTPS and regular testing of infrastructure components. Two-step authentication is available for an extra layer of security at Dashboard login.
·We get requests for access to data from law enforcement, and we review each request with the goal of responding with the minimum amount of required information in response to legitimate, legally mandated requests.
·If you have any questions, please contact us.
·Stripe has certified its participation in the EU-U.S. Data Privacy Framework ("EU-U.S. DPF"), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework. Stripe relies on the DPF to enable international transfers. In case the DPF is invalidated or Stripe is otherwise prevented from relying on the DPF, we incorporate multiple transfer mechanisms to ensure that data transfers can continue. If more than one data transfer mechanism applies, the DPF takes precedence. You can learn more about our certification and read the Stripe Data Privacy Framework Policy at https://stripe.com/legal/data-privacy-framework.
·The EU-U.S. DPF is a legal framework that allows organizations to transfer EEA Personal Data to certified organizations in the U.S. Stripe's Data Transfers Addendum sets out the data transfer mechanisms that Stripe may rely on to carry out international transfers of personal data, including the EU-U.S. DPF. You can learn more about our certification and read the Stripe Data Privacy Framework Policy at https://stripe.com/legal/data-privacy-framework. If you are a Business User and would like to transfer data to us under the DPF, please contact us or your account manager if you have any questions.
·SCCs are legal contracts entered into between parties that are transferring EEA Personal Data outside of the EEA. Stripe may rely on the SCCs for transfers of EEA data in our Services. We have updated our Data Transfer Addendum and agreements to incorporate the SCCs (where applicable).
·You can review our Data Transfers Addendum which includes the latest data transfer mechanisms, including the SCCs, the UK addendum and the Swiss addendum here.
·Cross-Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP) schemes are frameworks designed to facilitate data privacy harmonization across international boundaries, historically within the Asia-Pacific Economic Cooperation (APEC) region but now as a global scheme. CBPR is aimed at organizations handling personal data as a data controller, ensuring compliance with robust privacy standards and enabling secure cross-border data flow. It requires certified organizations to develop compliant privacy policies and practices and undergo independent certification. PRP, on the other hand, is tailored for data processors, establishing standards for how processors manage and secure data on behalf of data controllers. It provides a mechanism for demonstrating compliance with global privacy requirements, promoting trust and accountability.
·Stripe's privacy practices comply with CBPR and PRP systems as evidenced by the CBPR and PRP certifications Stripe has obtained. To view the status of our certifications, please click here (CBPR) and here (PRP).
·Where CBPR and/or PRP are recognized as a valid transfer mechanism under applicable law, Stripe will transfer Personal Data in accordance with the CBPR and PRP certifications Stripe has obtained.
·We have integrated a robust, multi-region infrastructure dedicated to optimizing authentication, authorization, and identity management. This infrastructure spans multiple geographic regions, specifically including our data centers located in the United States and India. By adopting this global approach, we have significantly enhanced the speed and reliability of our Services, allowing users to benefit from faster and more consistent access to their data, regardless of their location. This advancement results in a superior and seamless service experience with reduced latency, which is essential for maintaining high standards of user satisfaction.
·Our focus on global data storage centers around particular categories of Personal Data, strictly limited to aspects of user authentication and security. The specific types of data stored globally include Representative identifying information such as name, location, email address, phone number, date of birth, IP address, and device ID. These elements are integral to various facets of our operations, including login credentials and settings for multi-factor authentication, as well as device information and security challenges relevant to account security. Additionally, session management data, user roles and permissions, team invitations and management, and Single Sign-On (SSO) configurations fall under this umbrella of globally stored data.
·Importantly, this global storage strategy does not extend to any transactional information or other data related to End Customers.
·Depending on your location and subject to applicable law, you may have the following rights: Right to confirmation of processing Right to access Right of rectification/correction Right to data portability Right to restrict processing Right to object to processing
·Please read this section to find out more about specific rights. To submit a request to exercise any of the rights described above, please reach out to us by email, or via our form or by physical addresses listed in Contact Us.
·You have the right to complain to your local data protection authority if you are unhappy with our privacy practices.
·Laws in the various U.S. states may provide different privacy rights. For more information on which rights may be available under the laws in your state, consult the following table:
| Right to confirmation of processing | California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia |
|---|---|
| Right to access | California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia |
| Right to correction | California, Colorado, Connecticut, Delaware, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Virginia |
| Right to data portability | California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia |
| Right to deletion | California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia |
| Right to opt-out of processing for targeted advertising | Colorado, Connecticut, Delaware, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia |
| Right to opt-out from a sale of personal data | California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia |
| Right to opt-out from profiling for certain decisions with legal or similarly significant effects | Colorado, Connecticut, Delaware, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Virginia |
| Right to non-discrimination for exercising your rights | California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia |
| Right to appeal the refusal of a request to exercise your rights | Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Virginia |
| Right to confirm the third parties or categories of third parties to which personal data has been disclosed | Delaware, Maryland, Minnesota, Oregon |
| Right to limit the use and disclosure of sensitive personal data | California |
| Right to opt-out from sharing for cross-context behavioral advertising | California |
·Depending on your location and subject to applicable law, you may have the right to request confirmation of whether Stripe processes Personal Data relating to you, and if so, to request a copy of that Personal Data.
·If you are a Business User, End User, or otherwise have a direct relationship with Stripe (e.g. if you are a merchant, Link user, or if you have verified your identity through Stripe Identity solely for Stripe's own business purposes), you can use our self‐service tool that allows direct users to access their personal data directly: https://privacy.stripe.com/access.
·If you are a Business User or Representative, you may also login in to the Stripe Dashboard to view personal information shared with Stripe.
·If you are the End Customer of a Business User that uses Stripe Services, the Business User would be the correct party to respond to a data subject access request related to your transactional information.
·If you do not wish to use the self-service tool, you may also submit your access request by email, or through our form. Please note that we may need to verify your identity and your relationship with us before we can proceed with your request.
·If you are a Business User or Visitor, you may unsubscribe from Stripe marketing emails here. If you have any questions about how to opt-out of Stripe marketing communications, please contact us here.
·If you are a Link user, you may opt-out from marketing-related emails by using the unsubscribe link in any marketing email you receive, or by managing your subscription preferences in the Link website. To manage your preferences log into your Link account, then navigate to your account settings. Turn "Marketing emails - Receive updates and deals from Link and its partners" on or off. Your email address will be opted out of email marketing communications as soon as possible.
·Individuals in the UK have a right to complain to a data controller if they consider that the data controller has infringed data protection laws.
·If you are a Business User, End User, or otherwise have a direct relationship with Stripe (e.g. if you are a merchant, Link user, or if you have verified your identity through Stripe Identity solely for Stripe's own business purposes), you can exercise your right to complain to Stripe by contacting us by email, or through our form.
·Please note that if you are the End Customer of a Business User that uses Stripe Services and your complaint relates to processing where Stripe acts as a data processor, the Business User would be the correct party to respond to a complaint under UK GDPR and Data Protection Act 2018.
·In certain circumstances, Stripe may be required by law to retain and process your Personal Data even after a deletion request or objection to the processing. For instance, Stripe is required to retain certain Personal Data it receives from its Business Users to satisfy legal obligations under Know Your Customer (KYC) and Anti-Money Laundering (AML) laws.
·Stripe may also rely on compelling legitimate grounds to continue processing your Personal Data. Stripe may act on such grounds, for instance, when it takes steps to prevent fraud and financial crimes. When Personal Data is necessary to enable or maintain the integrity of Stripe's fraud detection and financial models, Stripe may not be able to honor requests to delete or stop processing that data. If Stripe honored such requests, fraudsters might take advantage of its willingness to do so to seek deletion of data related to their past fraudulent activities. Without such data, Stripe would be less able to recognize similar activities in the future.
·To enable Visitors of Stripe.com to see Stripe ads on other sites, we use advertising APIs and server-side pixels. The data that Stripe shares or makes available to enable this advertising include identifiers, internet or other similar network activity, IP addresses, and device characteristics. Any potentially personally identifying details are hashed through cryptographic SHA-256 hashing. Click the below links to learn more about the data that may be shared or made available to enable this feature. You can disable the toggle in the "advertising" section of our cookie settings page at any time.
| Third party service | Data that we may share or make available | Service description | Learn more |
|---|---|---|---|
| Meta | Sign-up information and interactions with Stripe and our products, website activity, IP address, device and browser characteristics, timestamps of visits, cryptographically hashed (SHA-256) email, first name, last name. | The Meta Conversions API is a Meta business tool that creates a direct connection between yourmarketing data and the Meta technologies that optimize ad performance. This helps you touse your own marketing data to optimize ad targeting, decrease cost per action and see amore complete picture of campaign outcomes while respecting people's privacy. | https://www.facebook.com/business/tools/facebook-conversions-api https://developers.facebook.com/docs/marketing-api/conversions-api/ |
| Sign-up information and interactions with Stripe and our products, website activity, IP address, device and browser characteristics, timestamps of visits, cryptographically hashed (SHA-256) email, first name,) last name. | With the Linkedin Conversions API, you can connect both your online and offline data to LinkedIn so you can see how your campaigns influenced actions taken on your website, sales completed over the phone, or leads collected in-person at an event. | https://www.linkedin.com/help/lms/answer/a1655394 | |
| Sign-up information and interactions with Stripe and our products, website activity, IP address, device and browser characteristics, timestamps of visits, cryptographically hashed (SHA-256) email, first name, last name. | The Reddit Conversions API is a server-to-server solution that shares your conversion data directly to Reddit's platform without needing website code. By building a sustainable server-side connection, this integration is more resilient to signal loss and will help deliver stronger campaign performance via improved measurement, targeting, and optimization. | https://business.reddithelp.com/helpcenter/s/article/Conversions-API | |
| X | Sign-up information and interactions with Stripe and our products, website activity, IP address, device and browser characteristics, timestamps of visits, cryptographically hashed (SHA-256) email, first name, last name. | The X Conversions API is a server-to-server solution that shares your conversion data directly to X's platform. By building a sustainable server-side connection, this integration is more resilient to signal loss and will help deliver stronger campaign performance via improved measurement, targeting, and optimization. | https://developer.twitter.com/en/docs/twitter-ads-api/measurement/web-conversions/conversion-api |
| Line | Sign-up information and interactions with Stripe and our products, website activity, IP address, device and browser characteristics, timestamps of visits, cryptographically hashed (SHA-256) email, first name, last name. | Line Conversions API is a server-to-server solution that shares your conversion data directly to Line's platform. By building a sustainable server-side connection, this integration is more resilient to signal loss and will help deliver stronger campaign performance via improved measurement, targeting, and optimization. | https://conversion-api-docs.linebiz.com/en/ |
| Sign-up information and interactions with Stripe and our products, website activity, IP address, device and browser characteristics, timestamps of visits, cryptographically hashed (SHA-256) email. | The Google Tag is a tracking tag for Google's advertising products (Search, Display, YouTube, GA4) enabling advertisers to serve a more personalised ad experience across Google's advertising products. Combined with Google's API solutions, advertisers can share conversion data to enhance on-site activity with offline customer interactions to improve measurement, targeting, and optimization. | https://developers.google.com/tag-platform/tag-manager/server-side/overview https://support.google.com/google-ads/answer/11347292?sjid=13132835489466327554-NC | |
| Demandbase | IP address, timestamps of visit, referrer, page URL, cookie ID, Sign-up information, device and browser characteristics | The Demandbase tag reads the IP address and cookie of each visitor and passes that information to our identification API, which determines which company the visitor works for. In this way, we're able to measure visitors' interest in your company. | https://support.demandbase.com/hc/en-us/articles/115005051743-Understanding-the-Demandbase-Tag |
·Yes. Global Privacy Control (GPC) is a signal that is sent by a web browser on your behalf that communicates your choice to opt-out of sharing for targeted advertisements. If you have enabled GPC on your browser, you will automatically be opted out of any "sharing" when you interact with our site. You can learn more about how to use opt-out preference signals by visiting the Global Privacy Control website.
·Your web browser may allow you to manage your cookie preferences, including deleting or disabling Stripe cookies. If you choose to disable cookies, keep in mind that some features of our Site or Services may not operate as intended. Disabling cookies will not disable the collection of advanced fraud signals, which we use to prevent fraud on Stripe. The collection of this data is controlled by the Business User that integrated with Stripe. If a Business User seeks to disable this data collection, they can find instructions to do so through Stripe's documentation. You can take a look at the help section of your web browser or follow the links below to understand your options for disabling cookies. Google Chrome Microsoft Internet Explorer Microsoft Edge Safari Firefox Opera
·You can learn more about how businesses can disable collection of advanced fraud signals in our documentation for disabling advanced fraud detection.
·You can close your Stripe account from the Settings page on the Dashboard. You can read more about that on our support page: Close a Stripe account.
·Please be aware that we will delete some, but not all, of the information that we hold, for the reasons explained below.
·As a provider of payment services, Stripe is required to comply with many regulations, including anti-terrorism and anti-money laundering laws. These regulations and laws may require Stripe to retain transactional records associated with Business Users for a prescribed period of time after the close of the business relationship. You can read more about our underwriting obligations in our Privacy Policy.
·If you have a Custom Connect account, your account is managed by a Platform / Business User. They are the party responsible for managing payments for you and responding to your query; therefore we recommend reaching out to them for assistance.
·If you have an Express Connect account, your account is managed by a Platform / Business User. They are the party responsible for managing payments for you and responding to your query; therefore we recommend reaching out to them for assistance.
·The Privacy Policy for Stripe Media Services (Media Privacy Policy) describes how Stripe collects and processes Personal Data in order to provide the Stripe Media Services, including Stripe Press, Increment, and Works in Progress. We encourage you to read our Media Privacy Policy to learn more.
·Personal Data may be processed either locally in India or in any other country where we have operations or where we engage service providers, to the extent permitted under applicable laws of India. Where required payment system data will be stored only on servers in India in accordance with the RBI data localization requirements.
·If you have any questions or complaints regarding the treatment of your Personal Data in India, you may contact our Nodal Officer and Grievance Officer: Name - Yogender Singh
·Email Address - complaints-in@stripe.com
·Address - Prestige Tech Pacific Park, 10th Floor, Building 2, Kadubeesanahalli Village, Varthur Hobli, Bangalore East Taluk, Bangalore-560103 Karnataka, India
·For more information about complaint handling, please visit here.
·Separately, for law enforcement requests, please contact LERequests@stripe.com.
·For privacy related questions or concerns, you may also contact Stripe's Data Protection Officer ("DPO") via dpo@stripe.com. If we are unable to address your complaint or grievance, you have the right to escalate the matter to the Data Protection Board of India.
·We are required to inform you that in case of non-compliance with rules and regulations, our Privacy Policy or user agreement, we have the right to terminate your access or usage rights immediately or remove non-compliant information or both, as the case may be.
·We use cookies and similar technologies to (1) ensure that our Services function properly, (2) prevent and detect fraud and violations of our terms of service, (3) understand how Visitors use and engage with our Site, (4) advertise our products and Services, where allowed and, (5) analyze and improve our Services and your Site experience including improved relevancy and navigation, customizing your user experience (such as language preference and region-specific content), and curating content about Stripe and our Services that's tailored to you. Depending on your relationship with Stripe and the domain you are visiting, different cookies apply. For instance some cookies are set on a public Stripe or Link domain, some on the Stripe Dashboard or a Link settings page, and some on the payment page available to End Users who make payments using Stripe Services, including Link.
·Cookies play an important role in helping Stripe provide personal, effective and safe Services. Please be mindful that we change the cookies periodically as we improve or add to our Services. For more information, please see our Cookie Policy.
·Stripe.js is a JavaScript library that businesses use to integrate Stripe and accept online payments (corresponding iOS and Android SDKs enable the same use cases). Stripe uses Stripe.js to facilitate fraud prevention technologies and the use of its Link payment Services on the websites of Business Users.
·For fraud detection, Stripe.js uses cookies, including `__stripe_mid`, `__stripe_sid`, and `m`, to collect signals differentiating legitimate behavior from fraudulent behavior. For example, fraudsters and bots often spend less time on Business Users' pages than legitimate End Customers. We are able to detect this behavior and use it in evaluating the risk that a transaction is fraudulent.
·When you visit a site that uses Stripe, you might see this fraud prevention activity in a privacy report or tracker list on your web browser. Stripe doesn't-and won't-share or sell the fraud data it collects using Stripe.js to advertisers. Stripe works to keep this fraud detection data secure and ensure it does not leave Stripe infrastructure. It is exchanged between the following Stripe-controlled hosts:js.stripe.com, m.stripe.network, and m.stripe.com, and access to this data is tightly restricted to a small number of Stripe employees whose security permissions are regularly reviewed. You can read more about how Stripe uses data for fraud prevention in our Privacy Policy.
·Stripe also uses the Stripe.js library to implement cookies and similar technology such as `pay_sid`, `link.auth_session_client_secret`, and `elements_session` to enable Link to remember users' information for faster checkout across Stripe merchant sites and to collect analytics related to Link's implementation on checkout pages.
·You should regularly review the Stripe cookies that are placed on your website and other data collected by Stripe.js. You should consult your counsel regarding how best to disclose this data collection to your customers, including by updating your cookie banner. But, here is a paragraph you could add to your privacy disclosures if they do not already include such information:
·We use Stripe for payments, analytics, and other business services. Stripe may collect personal data including via cookies and similar technologies. The personal data Stripe collects may include transactional data and identifying information about devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud and loss prevention and detection, authentication, analytics related to the performance of its services, and to enhance and customize the user experience. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.
·Stripe's advanced fraud detection looks at signals about device characteristics and user activity indicators that help distinguish between legitimate and fraudulent transactions. These signals are highly indicative of fraud and power Stripe's fraud prevention systems, such as Radar. The signals are securely transmitted to Stripe's backend by periodically making requests to the m.stripe.com endpoint.
·You can learn more in our documentation for advanced fraud detection.
·Stripe only uses these advanced fraud detection signals to enable secure payments and prevent fraud. We don't use this data to build individual profiles or share or sell it to third-party advertisers.
·You can read more about how we use this data in our Privacy Policy.
·This article aims to provide information about the use of cookies and similar technologies ("cookies") on the websites where you as a merchant may use Stripe Services and how the cookies support the functions and features of Stripe's Services for merchants. For example, your use of certain Stripe Services may load stripe.js. Stripe.js is a javascript library provided by Stripe, and in one of its functions it uses cookies for various purposes including fraud prevention, authentication, and analytics (for the avoidance of doubt, the elements_session analytics cookie is only set in some US states). Please refer to https://stripe.com/cookie-settings for more information. The specific cookies used by stripe.js depend on your configuration with the related Stripe products.
·For example, one of the key features of stripe.js is the fraud prevention system provided by Stripe's Radar product. Radar uses cookies to help businesses reduce chargebacks and losses from fraudulent transactions.
·Please note that the use of cookies may have legal implications depending on the geographical location of your business and customers. As a result, you may need to take appropriate action to ensure compliance with local regulatory requirements related to cookies.
·You should regularly review the Stripe cookies that are placed on your website to ensure that your own privacy disclosures tell your end users about this type of data collection, and also update your cookie disclosure and/or consent banner accordingly after reviewing the cookies placed on your website.
·Here is a paragraph you could add to your privacy disclosures if it does not already include such a disclosure:
·We use Stripe for payments, analytics, and other business services. Stripe may collect personal data including via cookies and similar technologies. The personal data Stripe collects may include transactional data and identifying information about devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud detection, loss prevention, authentication, and analytics related to the performance of its services. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.
·Below is an overview of the specific cookies associated with each product and their respective functions for Embeddable Checkout, Elements, Radar, and Link.
| Cookie Name | Category | Description | Cookie in use when using: |
|---|---|---|---|
| m | Fraud Prevention | Set for fraud prevention purposes and helps us assess the risk associated with an attempted transaction. Learn more about advanced fraud detection. | Radar |
| __stripe_mid | Fraud Prevention | Set for fraud prevention purposes and helps us assess the risk associated with an attempted transaction. Learn more about advanced fraud detection. | Radar |
| __stripe_sid | Fraud Prevention | Set for fraud prevention purposes and helps us assess the risk associated with an attempted transaction. Learn more about advanced fraud detection. | Radar |
| pay_sid | Authentication | Provide a logged-in experience when a consumer uses link.com to make purchases on a merchant site. | Link, Embeddable Checkout, Checkout & Elements |
| __Host-LinkSession | Authentication | Stores consumer credentials to provide a one-click payment experience at checkout. | Link & Elements |
| link.auth_session_client_secret | Authentication | Provide a logged-in experience when a consumer uses Stripe-hosted payment UIs to make purchases and Crypto Onramp to purchase crypto. | Link |
| elements_session | Analytics | The `elements_session` US-only cookie allows us to measure the result of changes we make to the Stripe Elements product and ensure that the performance of the product continues to improve over time. | Embeddable Checkout, Elements & Link |
·Link (formerly known as "Remember Me") lets End Users save and reuse their payment information for faster checkout at thousands of online businesses that use Stripe. When an End User makes a purchase via a Business User (i.e., merchant) that enables Link, the End User can ask Stripe to remember their payment method details, such as credit and debit card details. If an individual chooses to be remembered, Stripe will remember the End User's email address, phone number, shipping address, and payment method details for future Link transactions.
·The payment method details for future transactions may be remembered across multiple Stripe Business Users. Generally, once the cookie is set, the End User may make "1-click" purchases using Link when you check out, which means that Stripe will automatically populate the End User's saved information into their checkout on their behalf, and use the information to complete the transaction faster.
·If the End User enters their phone number or email address during a future Link transaction, Stripe will authenticate the End User by sending the End User a One Time Passcode (OTP), e.g. via an SMS message or email. If the End User correctly enters the OTP, Stripe or the Business User will set a cookie in the End User's browser, indicating that the End User has been authenticated. If the End User does not enter the OTP, or elects to "log out" of their Link session then the cookie won't remember the End User.
·A cookie is only stored in a specific browser on a specific device. If an End User wishes to make 1-click purchases in a different browser or on a different device, they must go through the OTP authentication process for the new browser or device combination.
·After 90 days, it will be necessary for the End User to re-complete the OTP process. The End User may also proactively remove the cookie by clearing cookies in their browser or by selecting the "log out" option when this option is presented in checkout.
·If an End User no longer wishes for Stripe to remember their payment method details when they check out in the future, the End User may use the self-service deletion tool. Alternatively, the End User may also contact Stripe support to make this request.
·The description above describes how an End User may control how their information is stored and used to check out. However, this does not affect the other contexts in which Stripe may store and use End User information. In particular, Stripe may store and use such information as described elsewhere on this Privacy Center - including for purposes such as for advanced fraud detection.
·Based on your integration choice (e.g., for Link in Elements), you may have legal responsibilities associated with cookies and similar technology that Stripe uses for fraud detection and/or authentication purposes.
·You should always check with your legal counsel to understand how you should comply with applicable legal obligations with setting cookies and similar technology. This section has information to keep in mind.
·Stripe cookies or similar technology are set on your domain (e.g. on your checkout flow) from the Stripe.js library. The current Stripe cookies from the Stripe.js library include fraud prevention cookies like `__stripe_mid`, `__stripe_sid`, and `m`, and also end-user authentication cookies like`pay_sid` and `__Host-LinkSession`.
·You should regularly review the Stripe cookies that are placed on your website to ensure that your own privacy disclosures tell your End Users about this type of data collection, and also update your cookie banner accordingly after reviewing the cookies placed on your website. Here is a paragraph you could add to your privacy disclosures if it does not already include such a disclosure:
·We use Stripe for payments, analytics, and other business services. Stripe may collect personal data including via cookies and similar technologies. The personal data Stripe collects may include transactional data and identifying information about devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud detection, loss prevention, authentication, and analytics related to the performance of its services. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.
·Yes, some of the Stripe Sites may implement Google reCAPTCHA Enterprise to help prevent fraud and abuse. Information collected by Google is used to provide and improve reCAPTCHA Enterprise and for general security purposes. Use of reCAPTCHA Enterprise is subject to Google's Privacy Policy and Terms of Use.
·We may also use hCAPTCHA Enterprise to help protect Stripe's Sites and Services from fraud and abuse, including by bots impersonating human beings. When you access Stripe's Sites and Services protected by hCAPTCHA, we may share data, including browser features and certain hashed identifiers with our hCAPTCHA provider Intuition Machines, Inc. To the extent that this data is Personal Data, Intuition Machines processes it on Stripe's behalf as a Data Processor.
·If you have any outstanding privacy questions after reviewing the privacy policy, please don't hesitate to reach out to us by email, or through our form.
·If you'd like to send us physical mail, please send to: Stripe, LLC 354 Oyster Point Boulevard
·South San Francisco, California, 94080, USA Attention: Stripe Legal Stripe Technology Company Limited
·One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland Attention: Stripe Legal
·Visit our security page to learn more about Stripe's security practices. You should contact us immediately if you become aware of any unauthorized use or any other breach of security regarding the Stripe services.