Trains on customer data
unclear
“* Training artificial intelligence models to power our Services and protect against fraud and other harm.”
Opt-out mechanism
If you are an End User, Representative, or Visitor, we may communicate with you using the contact information we have about you to provide information about our Services and our affiliates’ services, invite you to participate in our events, surveys, or user research, or otherwise communicate with yo
“If you are an End User, Representative, or Visitor, we may communicate with you using the contact information we have about you to provide information about our Services and our affiliates’ services, invite you to participate in our events, surveys, or user research, or otherwise communicate with you for marketing purposes, in compliance with applicable law, including any consent or opt-out requirements.”
AI features
present
“* Training artificial intelligence models to power our Services and protect against fraud and other harm.”
Model providers named
none named
Not stated in the documents we could read. An absence here is an unknown, not a no.
Retention
not stated
Not stated in the documents we could read. An absence here is an unknown, not a no.
Hosting regions
United States
“When Stripe collects Personal Data belonging to Canadian (including Quebec) residents, it transfers that data to data centers in the United States.”
Subprocessor notice
not stated
Not stated in the documents we could read. An absence here is an unknown, not a no.
Downstream
Who's behind Stripe, as listed in its own subprocessor documents. 6 listed.
Model providers
- none listed
Hyperscalers
- Amazon Web Servicesunstated
Other subprocessors
- DocuSignunstated
- Marketounstated
- Salesforceunstated
- Twiliounstated
- Zoomunstated
Reviewer notes
Extracted by deterministic rules (rules/v1), no language model. Coverage is limited to recognisable clauses and a gazetteer of common subprocessors; absent values mean 'not matched', not 'not present'. training-adjacent sentence found but not classifiable by rules
Documents read
- privacy policy https://stripe.com/privacyHTTP 200 · 2026-09-06
- subprocessors https://stripe.com/legal/service-providersHTTP 200 · 2026-09-06
- dpa https://stripe.com/legal/dpaHTTP 200 · 2026-09-06
Document changes
- high 2026-09-06 · dpa +1 / −1 lines
show diff
+ The Stripe API enables Users to programmatically access the data stored for transfer, excluding PCI-scoped data. The portability process for PCI data to other PCI-DSS Level 1 compliant payment processors can be found at https://stripe..− The Stripe API enables Users to programmatically access the data stored for transfer, excluding PCI-scoped data. The portability process for PCI data to other PCI-DSS Level 1 compliant payment processors can be found at https://stripe.com/docs/security/data-migrations/exports.
Fact changes
- low 2026-09-05 · 0 field change(s), +0/−1 subprocessors, +0 model providers
Corrections
No correction requests. Anyone may dispute a fact with a source; requests and resolutions are public and ledger-entered.
Facts are as stated in Stripe's public documents on the date read. This is a record, not legal advice. Work for Stripe? Claim this profile · Something wrong? Request a correction.