Stripe
Payment processor for e-commerce and mobile applications.
Score
Citation
We may use your Personal Data to assess your eligibility for, and offer you, other End User Services or promote existing End User Services. Where allowed by law (including with your opt-in consent where required), we use and share End User Personal Data with others so that we may market our End User Services to you, including through interest-based advertising.
If you have begun a purchase, we share Personal Data with that Business User in connection with our provision of Services and that Business User may use your Personal Data to market and advertise their products or services, subject to the terms of their privacy policy. Please review your merchant’s privacy policy to learn more, including your rights to stop their use of your Personal Data for marketing purposes.
Where allowed by applicable law, we use and share Representative Personal Data with others so that we may advertise and market our Services to you. Subject to applicable law (including any consent requirements), we may advertise to you through interest-based advertising and emails and seek to measure the effectiveness of our ads.
As allowed by law, we use and share Visitor Personal Data with others so that we may advertise and market our Services to you. Subject to applicable law (including any consent requirements), we may advertise our Services to you through interest-based advertising and emails, and seek to measure the effectiveness of our ads.
Even if there is a reasonable delay before the data is fully deleted (as is common), the data still counts as "permanently deleted" and satisfies the parameters for this question.
Score
Citation
If you have a Stripe user account, you can close your account in the settings of your Stripe dashboard. [...] Once you complete the account closure steps, we will delete your data in accordance with applicable law.
If you signed up for Link on the Link website or when you’ve made a purchase from a business that uses Link, you can delete your account by going to the settings page on the Link website, or by following this guide.
If you are a customer who’s had your identity verified by a Stripe Identity user(s), we need to verify and authenticate your request in order to delete your information. In order to authenticate your request, please send an email to privacy@stripe.com to begin the process. Please include the name and date of birth that you submitted (either by way of ID document or keyed-in data), along with the names and websites of your merchant(s) who verified you via Stripe Identity.
Score
Citation
We share Personal Data as we believe necessary: [...] (v) to respond to valid legal process requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include authorities outside your country of residence.
In certain situations, we may be required to disclose Personal Data in response to lawful requests from officials (such as law enforcement or security authorities).
This may come in the form of outright data sharing or by using local third-party analytics software (such as Google Analytics, which collects a plethora of user information).
Note that whether the policy allows sharing aggregated user data does not affect this question.
If the personal data is encrypted when it passes through the third-party, it does not count as third-party access (as the data is inaccessible to that party).
If personal data has been made public by, for example, posting it to a blog, it does not count as private personal information (and is therefore not considered by this question).
Score
Notes
A list of their sub-processors and service providers can be found here.
Some providers listed, such as Marketo and Google, are used for marketing and analytical tracking purposes, respectively.
Note that all companies operating in the EU are subject to Art. 33 of the GDPR, which requires companies to notify their data protection authority of a data breach within 72 hours of discovering it.
Score
Notes
The policy doesn't seem to mention a data breach policy.
Score
Citation
Last updated: May 17, 2023
Score
Citation
We may provide you with disclosures and alerts regarding the Policy or Personal Data collected by posting them on our website and, if you are an End User or Representative, by contacting you through your Stripe Dashboard, email address and/or the physical address listed in your Stripe account.
Score
Citation
We make reasonable efforts to provide a level of security appropriate to the risk associated with the processing of your Personal Data. We maintain organizational, technical and administrative measures designed to protect Personal Data covered by this Policy against unauthorized access, destruction, loss, alteration or misuse. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure.
Notes
Stripe is a certified PCI Service Provider, though that shouldn't justify their lack of a proper overview of their security practices.
Score
Notes
Sections 1.1b (regarding "End Users"), 1.2b (regarding "End Customers"), 1.3b (regarding "Representatives") and 1.4b (regarding "Visitors") in the policy contain brief overviews of their use and share of personal data.
The entirety of Section 2 is a continuation of their use and share of personal data.
Score
Notes
While their list seems exhaustive in size, it is filled with vague wording like "such as" and "for example", making it difficult to verify so.
Some services allow users to opt-out or opt-in to of non-critical collection or use of personal data, such as collecting data for personalized advertisements.
Score
Notes
Stripe's control over the use of non-critical personal data relies on the user's cookie settings, which are enabled by default in jurisdictions that don't require user consent.
This includes the use of data brokers and independent verification authorities (such as background check providers).
Score
Citation
We may collect information from you, and about you, from Business Users, financial parties and in some cases third parties. For example, to protect our Services, we may receive information from third parties about IP addresses that malicious actors have compromised.
Last Updated
August 8, 2023
Sources
Contributors