💥 TRENDING: En cz/privacy - Full Archive
Privacy Policy
Last updated: 16 January 2025
This Privacy Policy includes important information about your personal data and we encourage you to read it carefully.
We've recently added a new data controller, Stripe Technology Company Limited, to our Privacy Centre. For an overview of current Stripe data controllers please visit our Privacy Centre.
Welcome
We provide financial infrastructure for the internet. Individuals and businesses of all sizes use our technology and services to facilitate purchases, accept payments, send payouts, and manage online businesses.
This Privacy Policy (“Policy”) describes the Personal Data that we collect, how we use and share it, and details on how you can contact us with privacy-related inquiries. The Policy also outlines your rights and choices as a data subject, including the right to object to certain uses of your Personal Data.
Depending on the activity, Stripe assumes the role of a “data controller” and/or “data processor” (or “service provider”). For more details about our privacy practices, including our role, the specific Stripe entity responsible under this Policy, and our legal bases for processing your Personal Data, please visit our Privacy Center.
Defined Terms
In this Policy, “Stripe”, “we”, “our”, or “us” refers to the Stripe entity responsible for the collection, use, and handling of Personal Data as described in this document. Depending on your jurisdiction, the specific Stripe entity accountable for your Personal Data might vary. Learn More.
“Personal Data” refers to any information associated with an identified or identifiable individual, which can include data that you provide to us, and that we collect about you during your interaction with our Services (such as device information, IP address, etc.).
“Services” refers to the products, services, devices, and applications, that we provide under the Stripe Services Agreement (“Business Services”) or the Stripe Consumer Terms of Service (“End User Services”); websites (“Sites”) like Stripe.com and Link.com; and other Stripe applications and online services. We provide Business Services to entities (“Business Users”). We provide End User Services directly to individuals for their personal use.
“Financial Partners” are financial institutions, banks, and other partners such as payment method acquirers, payout providers, and card networks that we partner with to provide the Services.
Depending on the context, “you” might be an End Customer, End User, Representative, or Visitor:
End Users. When you use an End User Service, such as saving a payment method with Link, for personal use we refer to you as an “End User.”
End Customers. When you are not directly transacting with Stripe, but we receive your Personal Data to provide Services to a Business User, including when you make a purchase from a Business User on a Stripe Checkout page or receive payments from a Business User, we refer to you as an “End Customer.”
Representatives. When you are acting on behalf of an existing or potential Business User – perhaps as a company founder, account administrator for a Business User, or a recipient of an employee credit card from a Business User via Stripe Issuing – we refer to you as a “Representative.”
Visitors. When you interact with Stripe by visiting a Site without being logged into a Stripe account, or when your interaction with Stripe does not involve you being an End User, End Customer, or Representative, we refer to you as a “Visitor.” For example, you are a Visitor when you send a message to Stripe asking for more information about our Services.
In this Policy, “Transaction Data” refers to data collected and used by Stripe to facilitate transactions you request. Some Transaction Data is Personal Data and may include: your name, email address, contact number, billing and shipping address, payment method information (such as credit or debit card number, bank account details, or payment card image chosen by you), merchant and location details, amount and date of purchase, and in some instances, information about what was purchased.
1. Personal Data that we collect and how we use and share it
2. More ways we collect, use and share Personal Data
3. Legal bases for processing data
6. International data transfers
3. Legal bases for processing Personal Data
For purposes of the General Data Protection Regulation (GDPR) and other applicable data protection laws, we rely on a number of legal bases to process your Personal Data. Learn More. For some jurisdictions, there may be additional legal bases, which are outlined in the Jurisdiction-Specific Provisions section below.
a. Contractual and Pre-Contractual Business Relationships. We process Personal Data to enter into business relationships with prospective Business Users and End Users and fulfil our respective contractual obligations with them. These processing activities include:
- Creation and management of Stripe accounts and Stripe account credentials, including the assessment of applications to initiate or expand the use of our Services;
- Creation and management of Stripe Checkout accounts;
- Accounting, auditing, and billing activities; and
- Processing of payments and related activities, which include fraud detection, loss prevention, transaction optimisation, communications about such payments, and related customer service activities.
- Creation and management of Stripe accounts and Stripe account credentials, including the assessment of applications to initiate or expand the use of our Services;
b. Legal Compliance. We process Personal Data to verify the identities of individuals and entities to comply with obligations related to fraud monitoring, prevention, and detection, laws associated with identifying and reporting illicit and illegal activities, such as those under the Anti-Money Laundering ("AML") and Know-Your-Customer (“KYC") regulations, and financial reporting obligations. For example, we may be required to record and verify a Business User’s identity to comply with regulations designed to prevent money laundering, fraud, and financial crimes. These legal obligations may require us to report our compliance to third parties and subject ourselves to third-party verification audits.
c. Legitimate Interests. Where permitted under applicable law, we rely on our legitimate business interests to process your Personal Data. The following list provides an example of the business purposes for which we have a legitimate interest in processing your data:
- Detection, monitoring, and prevention of fraud and unauthorised payment transactions;
- Mitigation of financial loss, claims, liabilities or other harm to End Customers, End Users, Business Users, Financial Partners, and Stripe;
- Determination of eligibility for and offering new Stripe Services (Learn More);
- Response to inquiries, delivery of Service notices, and provision of customer support;
- Promotion, analysis, modification, and improvement of our Services, systems, and tools, as well as the development of new products and services, including enhancing the reliability of the Services;
- Management, operation, and improvement of the performance of our Sites and Services, through understanding their effectiveness and optimising our digital assets;
- Analysis and advertisement of our Services, and related improvements;
- Aggregate analysis and development of business intelligence that enable us to operate, protect, make informed decisions about, and report on the performance of our business;
- Sharing of Personal Data with third party service providers that offer services on our behalf and business partners that help us in operating and improving our business (Learn More);
- Enabling network and information security throughout Stripe and our Services; and
- Sharing of Personal Data among our affiliates.
- Detection, monitoring, and prevention of fraud and unauthorised payment transactions;
d. Consent. We may rely on consent or explicit consent to collect and process Personal Data regarding our interactions with you and the provision of our Services such as Link, Financial Connections, Atlas, and Identity. When we process your Personal Data based on your consent, you have the right to withdraw your consent at any time, and such a withdrawal will not affect the legality of processing performed based on the consent prior to its withdrawal.
e. Substantial Public Interest. We may process special categories of Personal Data, as defined by the GDPR, when such processing is necessary for reasons of substantial public interest and consistent with applicable law, such as when we conduct politically-exposed person checks. We may also process Personal Data related to criminal convictions and offenses when such processing is authorised by applicable law, such as when we conduct sanctions screening to comply with AML and KYC obligations.
f. Other valid legal bases. We may process Personal Data further to other valid legal bases as recognised under applicable law in specific jurisdictions. See the Jurisdiction-specific provisions section below for more information.
4. Your rights and choices
Depending on your location and subject to applicable law, you may have choices regarding our collection, use, and disclosure of your Personal Data:
a. Opting out of receiving electronic communications from us
If you wish to stop receiving marketing-related emails from us, you can opt out by clicking the unsubscribe link included in such emails or as described here. We'll try to process your request(s) as quickly as reasonably practicable. However, it's important to note that even if you opt out of receiving marketing-related emails from us, we retain the right to communicate with you about the Services you receive (such as support and important legal notices) and our Business Users might still send you messages or instruct us to send you messages on their behalf.
b. Your data protection rights
Depending on your location and subject to applicable law, you may have the following rights regarding the Personal Data we process about you as a data controller:
The right to request confirmation of whether Stripe is processing Personal Data associated with you, the categories of personal data it has processed, and the third parties or categories of third parties with which your Personal Data is shared;
The right to request access to the Personal Data Stripe processes about you (Learn More);
The right to request that Stripe rectify or update your Personal Data if it's inaccurate, incomplete, or outdated;
The right to request that Stripe erase your Personal Data in certain circumstances as provided by law (Learn More);
The right to request that Stripe restrict the use of your Personal Data in certain circumstances, such as while Stripe is considering another request you've submitted (for instance, a request that Stripe update your Personal Data);
The right to request that we export the Personal Data we hold about you to another company, provided it's technically feasible;
The right to withdraw your consent if your Personal Data is being processed based on your previous consent;
The right to object to the processing of your Personal Data if we are processing your data based on our legitimate interests; unless there are compelling legitimate grounds or the processing is necessary for legal reasons, we will cease processing your Personal Data upon receiving your objection (Learn More);
The right not to be discriminated against for exercising these rights; and
The right to appeal any decision by Stripe relating to your rights by contacting Stripe’s Data Protection Officer (“DPO”) at [email protected], and/or relevant regulatory agencies.
You may have additional rights, depending on applicable law, over your Personal Data. For example, see the Jurisdiction-specific provisions section under United States below.
c. Process for exercising your data protection rights
To exercise your data protection rights related to Personal Data we process as a data controller, visit our Privacy Center or contact us as outlined below. For Personal Data we process as a data processor, please reach out to the relevant data controller (Business User) to exercise your rights. If you contact us regarding your Personal Data we process as a data processor, we will refer you to the relevant data controller to the extent we are able to identify them.
5. Security and Retention
We make reasonable efforts to provide a level of security appropriate to the risk associated with the processing of your Personal Data. We maintain organisational, technical and administrative measures designed to protect the Personal Data covered by this Policy from unauthorised access, destruction, loss, alteration or misuse. Learn More. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure.
We encourage you to assist us in protecting your Personal Data. If you hold a Stripe account, you can do so by using a strong password, safeguarding your password against unauthorised use and avoiding using identical login credentials you use for other services or accounts for your Stripe account. If you suspect that your interaction with us is no longer secure (for instance, you believe that your Stripe account's security has been compromised), please contact us immediately.
We retain your Personal Data for as long as we continue to provide the Services to you or our Business Users or for a period in which we reasonably foresee continuing to provide the Services. Even after we stop providing Services directly to you or to a Business User that you're doing business with and even after you close your Stripe account or complete a transaction with a Business User, we may continue to retain your Personal Data to:
Comply with our legal and regulatory obligations;
Enable fraud monitoring, detection and prevention activities; and
Comply with our tax, accounting and financial reporting obligations, including when such retention is required by our contractual agreements with our Financial Partners (and where data retention is mandated by the payment methods you've used).
In cases where we keep your Personal Data, we do so in accordance with any limitation periods and record retention obligations imposed by applicable law. Learn More.
6. International Data Transfers
As a global business, it's sometimes necessary for us to transfer your Personal Data to countries other than your own, including the United States. These countries might have data protection regulations that are different from those in your country. When transferring data across borders, we take measures to comply with applicable data protection laws related to such transfer. In certain situations, we may be required to disclose Personal Data in response to lawful requests from officials, such as law enforcement or security authorities. Learn More.
If you are located in the European Economic Area (“EEA”), the United Kingdom ("UK"), or Switzerland, please refer to our Privacy Center for additional details. When a data transfer mechanism is mandated by applicable law, we employ one or more of the following:
Transfers to certain countries or recipients that are recognised as having an adequate level of protection for Personal Data under applicable law.
EU Standard Contractual Clauses approved by the European Commission and the UK International Data Transfer Addendum issued by the Information Commissioner’s Office. You can obtain a copy of the relevant Standard Contractual Clauses. Learn More.
Other lawful methods available to us under applicable law.
Stripe, Inc. complies with the EU-US Data Privacy Framework (“EU-US DPF”), the UK Extension to the EU-US DPF, and the Swiss-US Data Privacy Framework as set forth by the US Department of Commerce and as applicable. Learn More.
Stripe’s privacy practices, as described in this Privacy Policy, comply with the Cross Border Privacy Rules System (“CBPR”) and Privacy Rules for Processor (“PRP”) systems. These systems provide a framework for organisations to ensure protection of personal data transferred among participating economies. Where CBPR and/or PRP are recognised as a valid transfer mechanism under applicable law, Stripe will transfer Personal Data in accordance with the CBPR and PRP certifications Stripe has obtained. More information about the framework can be found here and here. If you have unresolved privacy or data use concerns that we have not addressed satisfactorily, please contact our US based third-party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request. To view the status of our certifications, please click here (CBPR) and here (PRP).
7. Updates and notifications
We may change this Policy from time to time to reflect new services, changes in our privacy practices or relevant laws. The “Last updated” legend at the top of this Policy indicates when this Policy was last materially revised. Any changes are effective the latter of when we post the revised Policy on the Services or otherwise provide notice of the update as required by law.
We may provide you with disclosures and alerts regarding the Policy or Personal Data collected by posting them on our website and, if you are an End User or Representative, by contacting you through your Stripe Dashboard, email address and/or the physical address listed in your Stripe account.
8. Jurisdiction-specific provisions
Australia. “Personal Data” includes “personal information” as defined under applicable privacy laws in Australia, including the Privacy Act 1988 (Cth) as amended from time to time.
- If we use personal information to make automated decisions that could reasonably be expected to significantly affect your rights or interests, we will provide the legally required information and transparency via our Privacy Center, and/or on a case by case basis.
- If you are an Australian resident and dissatisfied with our handling of any complaint you raise under this Policy, you may consider contacting the Office of the Australian Information Commissioner.
- If we use personal information to make automated decisions that could reasonably be expected to significantly affect your rights or interests, we will provide the legally required information and transparency via our Privacy Center, and/or on a case by case basis.
Brazil. You may exercise your rights by contacting our DPO Adi Gilad at [email protected]. Brazilian residents, for whom the Lei Geral de Proteção de Dados Pessoais (“LGPD”) applies, have rights set forth in Article 18 of the LGPD. If the LGPD is applicable to the processing of your Personal Data, you may have the right to:
- Confirm the existence of the data processing;
- Access your Personal Data;
- Correct incomplete, inaccurate or outdated data;
- Anonymise, block, or delete data that is unnecessary, excessive or processed in violation of the LGPD;
- Transfer your data to another service or product provider;
- Delete data processed with your consent;
- Obtain information about the public or private entities with which Stripe has shared your Personal Data;
- Obtain information about how to and the consequences of refusing consent; and
- Withdraw consent.
- Confirm the existence of the data processing;
Canada. As used in this Policy, “applicable law” includes the Federal Personal Information Protection and Electronic Documents Act (“PIPEDA”), the Personal Information Protection Act, SBC 2003 c 63, in British Columbia, the Personal Information Protection Act, SA 2003 c P-6.5, in Alberta, and the Act Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39-1 (“Quebec Private Sector Act”), in Quebec. Learn more. “Personal Data” includes “personal information” as defined under those laws.
- Stripe’s Chief Privacy Officer is the person in charge of personal information, including under the Quebec Private Sector Act. You may contact them via email at privacy\@stripe.com. When Stripe collects Personal Data belonging to Canadian (including Quebec) residents, it transfers that data to data centres in the United States. When Stripe relies on service providers to process Personal Data as described herein, those service providers may also be located outside of Canada or Quebec.
- You have the right to request access or rectification of the Personal Data Stripe holds related to you or to withdraw any consent given to the processing of such personal data. You may exercise those rights by contacting Stripe’s Chief Privacy Officer at privacy\@stripe.com. If you are an End Customer, you should contact the Business User with which you transacted to exercise your rights.
- Stripe’s Chief Privacy Officer is the person in charge of personal information, including under the Quebec Private Sector Act. You may contact them via email at privacy\@stripe.com. When Stripe collects Personal Data belonging to Canadian (including Quebec) residents, it transfers that data to data centres in the United States. When Stripe relies on service providers to process Personal Data as described herein, those service providers may also be located outside of Canada or Quebec.
EEA and UK. You may exercise your rights by contacting our DPO at [email protected]. If you are a resident of the EEA or the Stripe entity accountable for your Personal data is otherwise subject to the GDPR, and you believe our processing of your information contradicts the GDPR, you may direct your questions or complaints to the Irish Data Protection Commission. If you are a resident of the UK, direct your questions or concerns to the UK Information Commissioner’s Office. You also have additional rights under the EU-US DPF and the UK Extension to the EU-US DPF. Learn More.
India. In this Policy, “applicable law” includes the Digital Personal Data Protection Act (“DPDPA”) once the DPDPA enters into effect. Further, the term “data controller” includes “data fiduciaries,” and the term “data subject” includes “data principal,” both as defined in the DPDPA.
- In some cases, and as permitted under the DPDPA, we may rely on “legitimate use” as a legal basis. For example, we might do so when you voluntarily provide your Personal Data to us. Where we are required to obtain your explicit and informed consent, we will do so on a case by case basis. “Consent Managers” as defined under the DPDPA may submit a request to revoke or provide consent using the methods described in the Contact Us section below, or as set out in the following paragraph, or via other means made available by Stripe in the future. We may ask for proof of authorisation and identity before processing such a request.
- You have the right to contact Stripe to nominate another individual, who may, in the event of your death or incapacity, exercise your rights under this Privacy Policy and under the DPDPA and implementing regulations.
- In certain cases, you may be asked to consent to the collection and processing of your Aadhaar number by Stripe India Private Limited and/or its third party verification partner(s). The purpose of this collection is to facilitate the identification verification process as required under applicable laws. Your provision of Aadhaar details is purely voluntary, and you may provide other identification documents as may be accepted by us from time to time. You will not be denied service merely for not submitting Aadhaar details.
- If you have any questions or complaints regarding the processing of your Personal Data in India, or if you want to receive this Policy or communicate with us about privacy in one of India’s official languages, please contact our Nodal and Grievance Officer. Learn More. Alternatively, you may contact our DPO at [email protected]. If we are unable to address your complaint or grievance, you have the right to escalate the matter to the Data Protection Board of India.
- In some cases, and as permitted under the DPDPA, we may rely on “legitimate use” as a legal basis. For example, we might do so when you voluntarily provide your Personal Data to us. Where we are required to obtain your explicit and informed consent, we will do so on a case by case basis. “Consent Managers” as defined under the DPDPA may submit a request to revoke or provide consent using the methods described in the Contact Us section below, or as set out in the following paragraph, or via other means made available by Stripe in the future. We may ask for proof of authorisation and identity before processing such a request.
Indonesia. In this Policy, “applicable law” includes Law No. 11 of 2008 as amended by Law No. 19 of 2016 on Electronic Information and Transactions, Government Regulation No. 71 of 2019 on the Implementation of Electronic Systems and Transactions, and Minister of Communication and Informatics Regulation No. 20 of 2016 on Personal Data Protection in Electronic Systems, and from September 2024, Law No. 27 of 2022 concerning Personal Data Protection (“PDP Law”). If you have any questions or complaints about this Policy, please contact our DPO at [email protected].
Japan. In this Policy, “applicable law” includes the Act on the Protection of Personal Information (“APPI”). When we transfer Personal Data of data subjects in Japan to jurisdictions not recognised as ‘adequate’ by the Personal Information Protection Commission, we enter into written agreements with any third parties located outside of Japan. These written agreements provide rights and obligations equivalent to those provided under the Japanese Act on the Protection of Personal Information. For more information on how we ensure that third parties protect your data and where your data is located, please see above or contact us as described below. For a description of foreign systems and frameworks that may affect the implementation of equivalent measures by the third party, see here. In some cases, and as permitted under the APPI, we may rely on “public interest” as a legal basis, such as fraud detection and loss prevention.
Malaysia. If you have any questions or complaints about this Policy, please contact our DPO at [email protected].
Singapore. In this Policy, “applicable law” includes the Personal Data Protection Act 2012 (“PDPA”) (No. 26 of 2012) as amended from time to time. In some cases, and as permitted under the PDPA, we may rely on “deemed consent” as a legal basis. For example, we do so when you voluntarily provide your personal data to us. If you have any questions or complaints about this Policy, please contact our DPO at [email protected].
Switzerland. In this Policy, “applicable law” includes the Swiss Federal Act on Data Protection (“FADP”), as revised. To exercise your rights under the FADP, please contact our DPO at [email protected]. You may also have additional rights under the Swiss-U.S. Data Privacy Framework. Learn More.
Thailand. In this Policy, “applicable law” includes the Personal Data Protection Act 2019 (“PDPA”). If we rely on certain legal bases (such as “legal obligation” or “contractual necessity” and you do not provide us with your Personal Data, we may not be able to lawfully provide you services. If you have any questions or complaints about this Policy, please contact our DPO at [email protected]. Where required, we have put in place appropriate safeguards for the cross-border transfer of Personal Data from Thailand, including the EU Standard Contractual Clauses as adapted for Thailand data transfers in accordance with the Notification of the Personal Data Protection Committee on Criteria for the Protection of Personal Data Sent or Transferred to a Foreign Country Pursuant to Section 29 of the Personal Data Protection Act, B.E. 2562 B.E. 2566 (2023).
United States. If you are a consumer located in the United States (“US”), we process your personal information in accordance with US federal and state privacy laws. For additional details, please review the information below and see our additional US Privacy Disclosures here. Stripe uses cookies, including advertising cookies, as described in Stripe’s Cookie Policy.
- Your Rights and Choices. As a US consumer and subject to certain limitations under US privacy laws, you may have choices regarding our use and disclosure of your Personal Data. In addition to the above rights, you may also have the rights listed in this section. Please see our Privacy Center to learn more about data subject rights metrics and learn more about the laws under which these rights may apply.
- Exercising the right to know: You have a right to request additional information about the categories of personal information collected, sold, disclosed, or shared; purposes for which this personal information was collected, sold, or shared; categories of sources of personal information; and categories of third parties with whom we disclosed or shared this personal information.
- Exercising the right to opt-out from a sale or sharing: We do not transfer your personal data to third parties in exchange for payment. However, as noted above, we may provide the data to third party partners, such as advertising partners, analytics providers, and social networks, who assist us in advertising our products and Services to you. Because these third parties may use the data Stripe provides for their own purposes, Stripe's provision of data to these parties may be considered a data “sale” or “sharing” (for behavioural advertising) as those terms are defined under the CCPA and other applicable US privacy laws. You can opt out of targeted advertising and any related data “sales” or “sharing” (for behavioural advertising) here.
- Exercising the right to limit the use or sharing of Sensitive Personal Information: We do not sell or share (for behavioural advertising) Sensitive Personal Information as defined by US privacy laws and have not done so in the past 12 months. Learn more about our collection and use of Sensitive Personal Information over the last 12 months here.
- Profiling with legal or similarly significant effects: In the event that we engage in profiling or automated decision-making for which applicable law entitles you to an opt-out we will provide you with notice of how to exercise that opt-out right.
- Appeal: If you wish to appeal any of our decisions regarding a rights request under US privacy laws, you may do so by contacting Stripe’s Data Protection Officer (“DPO”) at [email protected].
- Exercising the right to know: You have a right to request additional information about the categories of personal information collected, sold, disclosed, or shared; purposes for which this personal information was collected, sold, or shared; categories of sources of personal information; and categories of third parties with whom we disclosed or shared this personal information.
- To submit a request to exercise any of the rights described above, please contact us using the methods described in the Contact Us section below. Please note that rights under some US state laws do not apply to Personal Data we collect, process, and disclose when you act as a consumer to obtain financial products or services from Stripe for personal, family, or household purposes. The federal Gramm-Leach Bliley Act may govern how Stripe shares and protects that data instead. See our US Consumer Privacy Notice below for more information.
- We will verify your request by asking you to send it from the email address associated with your account or requiring you to provide information necessary to verify your identity, including name, address, transaction history, photo identification, and other information associated with your account.
- You may designate, in writing or through a power of attorney, an authorised agent to make requests on your behalf to exercise your rights under the CCPA and other applicable US privacy laws. Your agent may submit a request on your behalf by contacting us using the methods described in the Contact Us section below. We may still require you to directly verify your identity and confirm that you gave the authorised agent permission to submit the request.
- Your Rights and Choices. As a US consumer and subject to certain limitations under US privacy laws, you may have choices regarding our use and disclosure of your Personal Data. In addition to the above rights, you may also have the rights listed in this section. Please see our Privacy Center to learn more about data subject rights metrics and learn more about the laws under which these rights may apply.
Global Privacy Control signals. Stripe honours the Global Privacy Control (GPC) opt-out preference signals. Learn More.
9. Contact us
If you have any questions or complaints about this Policy, please contact us. If you are an End Customer (i.e. an individual doing business or transacting with a Business User), please refer to the privacy policy or notice of the Business User for information regarding the Business User’s privacy practices, choices and controls, or contact the Business User directly.
10. US Consumer Privacy Notice
The following Consumer Privacy Notice applies to you if you are an individual who resides in the United States and obtains financial services from Stripe primarily for your own personal, family, or household purposes.
Last updated: 16 January 2025
| FACTS | WHAT DOES STRIPE DO WITH YOUR PERSONAL INFORMATION? |
|---|---|
| Why? | Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect your personal information. Please read this notice carefully to understand what we do. |
| What? | The types of personal information we collect and share depend on the product or service you have with us. This information can include: • Social Security Number • Contact details • Account balances and transaction history • Payment, transaction, and purchase information and history When you are no longer our customer, we continue to share your information as described in this notice. |
| How? | All financial companies need to share customers' personal information to run their everyday business. In the section below, we list the reasons financial companies can share their customers' personal information; the reasons Stripe chooses to share; and whether you can limit this sharing. |
| Reasons we can share your personal information | Does Stripe Share? | Can you limit this sharing? |
|---|---|---|
| For our everyday business purposes – such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus | Yes | No |
| For our marketing purposes – to offer our products and Services to you | Yes | No |
| For joint marketing with other financial companies | Yes | No |
| For our affiliates' everyday business purposes – information about your transactions and experiences | Yes | No |
| For our affiliates' everyday business purposes – information about your creditworthiness | No | We don’t share |
| For our affiliates to market to you | No | We don’t share |
| For non-affiliates to market to you (for data not collected through Financial Connections). | Yes | Yes |
| For non-affiliates to market to you (for data collected through Financial Connections) | No | We don’t share |
| To limit our sharing | Login to your Link account at app.link.com/settings and toggle off data sharing from the Messaging menu. Please note: If you are a new customer, we can begin sharing your information 30 days from the date we sent this notice. When you are no longer our customer, we continue to share your information as described in this notice. However, you can contact us at any time to limit our sharing. |
|---|
| Questions? | Contact us at [email protected] or visit us at https://support.link.com |
|---|
| Who we are | |
|---|---|
| Who is providing this notice? | Stripe, Inc., Stripe Payments Company, and their affiliates that provide consumers services in the US. |
| What we do | |
|---|---|
| How does Stripe protect my personal information? | To protect your personal information from unauthorised access, destruction, loss, alteration, or misuse we use security measures to comply with federal law. These measures include computer safeguards and secured files and buildings. We impose access controls along with ongoing monitoring to prevent data misuse, and we require our service providers to take similar steps to protect your information. |
| How does Stripe collect my personal information? | We collect your personal information, for example, when you • open a Link account; • ask Stripe to process a payment for goods or services; • provide bank account information to Stripe using Financial Connections We also collect your personal information from others, such as affiliates or other companies. |
| Why can’t I limit all sharing? | Federal law gives you the right to limit only • sharing for affiliates’ everyday business purposes – information about your creditworthiness • affiliates from using your information to market to you • sharing for non-affiliates to market to you. State laws and individual companies may give you additional rights to limit sharing. See the Other Important Information section below for more information on your rights under state law. |
| What happens when I limit sharing for an account I hold jointly with someone else? | Your choices will apply to everyone on your account. |
| Definitions | |
|---|---|
| Affiliates | Companies related by common ownership or control. These can be financial and non-financial companies. • Our affiliates include companies operating under the Stripe name, such as Stripe Technology Europe, Ltd. and Stripe Payments UK, Ltd. |
| Non-affiliates | Companies not related by common ownership or control. They can be financial and non-financial companies. • Non-affiliates with which we share personal information include service providers that perform services or functions on our behalf, Business Users with which you choose to transact, partners with which we share data to provide you with services, and advertising partners, analytics providers, and social networks, who assist us in advertising our Services to you. |
| Joint Marketing | A formal agreement between non-affiliated financial companies that together market financial products or services to you. • Our joint marketing partners include financial companies we partner with to provide you with financial services. |
| Other important information |
|---|
Vermont: If your account with us is associated with a Vermont billing address, we will not disclose information about your creditworthiness to our affiliates and will not disclose your personal information, financial information, credit report, or health information to non-affiliated third parties to market to you, other than as permitted by Vermont law, unless you authorise us to make those disclosures. For joint marketing, we will only disclose your name, contact information, and information about your transactions. Additional information concerning our privacy policies can be found in our Privacy Policy and Privacy Center. California: If your account with us is associated with a California billing address, we will not disclose Personal Data we collect about you except to the extent permitted under California law. For instance, we may disclose your Personal Data as necessary to process transactions or provide products and services you request, at your instruction, as required for institution risk control, and to safeguard against fraud, identity theft, and unauthorised transactions. |
For additional information about our privacy practices, please visit the Stripe Privacy Center and Link Privacy Center.