Payment
GDPR Stripe
For “GDPR Stripe”, name the account entity: Stripe Payments Europe, Limited outside the Americas, Stripe, LLC in North or South America. The entry records a processor role on instruction and an independent-controller role for fraud and AML/CFT, a transfer to Stripe, LLC in the United States, and the Active registration of Stripe, LLC.
In an indie stack, Stripe is used for Payment and billing. Entity cited: Stripe Payments Europe, Limited for accounts outside North and South America; Stripe, LLC for accounts located in North or South America. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.
Translation of the French sheet. The facts do not change. The date is the date the official pages were read.
DPA Stripe
Yes. The DPA is part of the Stripe Services Agreement.
Stated role
When Stripe processes on instruction, it acts as the customer's processor, the customer being the controller. Stripe also presents itself as an independent controller for purposes such as fraud, AML/CFT, and operation of the product.
Personal data
The Stripe pages cite in particular payment method and card data, bank account, billing and shipping addresses, name, order description and amount, device identifier, email, IP address and location, tax identifier, customer identifier, and, where applicable, identity documents and facial-recognition data.
Sub-processors of Stripe
Public list of providers, sub-processors, and affiliates.
Transfers outside the EU
Hosting / location
The DPA indicates a transfer to Stripe, LLC in the United States. The privacy policy states that the majority of providers are in the European Union, the United States, and India.
EU–United States Data Privacy Framework
Stripe, LLC is registered. EU-U.S. Data Privacy Framework status: Active. The European entity Stripe Payments Europe, Limited is not the name on that entry.
Cookies
The cookies policy distinguishes essential, functional, and advertising cookies, including third-party analytics and marketing cookies. Non-essential cookies can be refused in Stripe's consent settings.
Typical use, written by StackLégal and not by the vendor: Payment and billing.
History
Last update: October 4, 2026.
First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".
Clause to paste
Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.
Sub-processor clause
Sources
Verified on October 4, 2026.
Frequently asked questions
Is Stripe a processor within the meaning of the GDPR?
When Stripe processes on instruction, it acts as the customer's processor, the customer being the controller. Stripe also presents itself as an independent controller for purposes such as fraud, AML/CFT, and operation of the product.
What DPA does Stripe publish?
Yes. The DPA is part of the Stripe Services Agreement. https://stripe.com/legal/dpa
Which further sub-processors does Stripe publish?
Public list of providers, sub-processors, and affiliates. https://stripe.com/legal/service-providers
Where does Stripe state that it processes data, including outside the EU?
The DPA indicates a transfer to Stripe, LLC in the United States. The privacy policy states that the majority of providers are in the European Union, the United States, and India.
Is Stripe registered under the EU–United States Data Privacy Framework?
Stripe, LLC is registered. EU-U.S. Data Privacy Framework status: Active. The European entity Stripe Payments Europe, Limited is not the name on that entry. https://www.dataprivacyframework.gov/participant/10014
Which personal data does Stripe mention?
The Stripe pages cite in particular payment method and card data, bank account, billing and shipping addresses, name, order description and amount, device identifier, email, IP address and location, tax identifier, customer identifier, and, where applicable, identity documents and facial-recognition data.
Stacks that cite Stripe
These pages assemble the sheets of a common stack and state what to write in the privacy policy.
Often in the same stack
These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.
Related tools
Full pack, from 39 € incl. VAT
The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.