Privacy Policy for Apps Using Stripe
Accepting payments with Stripe means payment details flow through a third-party processor. Your privacy policy needs to explain what payment-related data is collected, who processes it, and that you generally do not store raw card numbers yourself.
Create My Privacy PolicyLast updated July 8, 2026
Why this affects your privacy policy
Stripe handles card data so you usually never see or store the full card number — Stripe does. But you still collect and process related personal data: names, billing addresses, email, and transaction history. Both your obligations and Stripe’s role as a processor belong in your policy.
Data typically processed
| Data type | Details |
|---|---|
| Payment method details | Card or bank data entered by the user, collected and stored by Stripe, not by you. |
| Billing information | Name, billing address, and email tied to the transaction. |
| Transaction records | Amount, currency, timestamp, and status of each payment. |
| Fraud-prevention signals | Device and network data Stripe uses to detect fraud. |
What to disclose
- That payments are processed by a third-party payment processor.
- That card details are handled by the processor and not stored on your own servers.
- The billing data you do collect (name, email, address, transaction history).
- That transaction data may be transferred internationally.
- How long you keep transaction records (often required for tax/accounting).
Example wording
Payments. When you make a purchase, your payment is processed by a third-party payment provider. Your full card details are collected and stored directly by that provider under their own security standards; we do not receive or store your complete card number. We do receive limited information such as your name, email, billing country, and a record of the transaction, which we use to fulfil your order, provide support, and meet legal and accounting obligations.
Sample language only — adapt it to your actual data practices.
Best practices
- → Use Stripe Checkout or Elements so card data never touches your server (reduces PCI scope).
- → Keep transaction records only as long as tax and accounting rules require, then delete.
- → Do not log full card numbers anywhere, ever — even accidentally in error reports.
- → If you use Stripe Radar for fraud, note that fraud-prevention processing occurs.
Generate a policy that already covers Stripe and host it at a permanent URL.
Host Your PolicyFrequently asked questions
Do I need to be PCI compliant if I use Stripe?
Should my privacy policy mention Stripe by name?
What about subscriptions and stored cards?
Related guides
This guide is for general informational purposes only and is not legal advice. Your privacy policy should reflect your actual data practices and applicable legal requirements, which vary by jurisdiction and platform.
Create and host your privacy policy
Fill out a short form, get a permanent HTTPS URL for your app submission.
Create My Privacy Policy