FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Stripe
S

Stripe

EssentialWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Stripe do?

Stripe is a leading global payment processing platform used by millions of businesses to accept online and in-person payments. For European businesses, Stripe processes payment data within the EU, is PCI DSS certified, and provides comprehensive GDPR compliance documentation including DPAs and SCCs. The primary legal basis for payment processing is contract performance. Stripe's fraud detection (Stripe Radar) uses device fingerprinting and behavioural signals, which constitutes additional personal data processing that is justified by legitimate interest and legal obligation.

What is Stripe?

Stripe is a global technology company that builds economic infrastructure for the internet. Its core product is a payment processing platform that enables businesses to accept credit cards, debit cards, bank transfers, buy-now-pay-later options, and dozens of other payment methods online and in person. Stripe also provides products for billing and subscriptions (Stripe Billing), fraud prevention (Stripe Radar), identity verification (Stripe Identity), tax automation (Stripe Tax), and marketplace payments (Stripe Connect).

Personal data processed by Stripe

Stripe processes cardholder data (card number, expiry, CVV), billing addresses, email addresses, IP addresses, device fingerprints (for Stripe Radar fraud detection), transaction history, and for Stripe Identity: government ID images and selfies. The legal basis varies by data category: contract performance for payment processing, legal obligation for AML/KYC requirements, and legitimate interest for fraud prevention.

Stripe.js cookies and fraud detection

Stripe.js sets the __stripe_mid (machine ID, 1 year) and __stripe_sid (session ID, 30 minutes) cookies for fraud prevention via Stripe Radar. These are placed on the payment page domain, not as third-party cookies. The purpose is fraud detection and security, providing a legitimate interest legal basis. Most cookie consent frameworks exempt strictly necessary fraud prevention cookies from consent requirements, but this should be verified with your DPO.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

EU data processing and PCI DSS

Stripe processes European payment transactions within the EU. Stripe is certified PCI DSS Level 1, the highest level of payment card security certification. Stripe''s EU entity (Stripe Payments Europe, Limited) is an authorised payment institution regulated by the Central Bank of Ireland. This EU regulatory status means Stripe is subject to both GDPR and financial services regulation for European transactions.

Practical compliance steps

Sign the Stripe Data Processing Agreement from the Stripe Dashboard. Add Stripe to your privacy policy describing payment data processing, fraud detection, and the legal bases used. Include the Stripe.js fraud prevention cookies in your cookie policy (classified as strictly necessary security cookies). For Stripe Identity deployments, conduct a DPIA for identity document processing. Implement Stripe Customer deletion for erasure requests while respecting financial record retention requirements.

GDPR consent category

Essential

Websites using Stripe must obtain user consent under GDPR regulations.

Legal basisContract performance (Art. 6(1)(b)) for payment processing as part of the purchase transaction. Legal obligation (Art. 6(1)(c)) for fraud prevention, AML, and financial regulatory requirements. Legitimate interest (Art. 6(1)(f)) for fraud detection (Stripe Radar). Consent for any optional marketing analytics features.
Risk levelmedium
Applicable regulationsGDPR, PSD2, PCI DSS, AML/KYC regulations, SCCs for US transfers of non-payment analytics data

DPIA considerations

A DPIA is generally not required for standard Stripe payment processing. It may become relevant for large-scale e-commerce platforms processing payment data at high volume, or for marketplaces where Stripe Connect involves multiple parties sharing financial data.

Sample consent text

Payments on this website are processed by Stripe. When you make a payment, Stripe collects your payment card information and billing details to process your transaction. Stripe also uses device information for fraud prevention. See our privacy policy and Stripe's privacy policy for full details.

Technical details

Tracking methodJavaScript (Stripe.js), payment processing cookies, fraud detection (Stripe Radar), device fingerprinting, browser telemetry for fraud prevention
Server locationUnited States and European Union (Stripe has EU data processing infrastructure)
Data transferred outside the EUStripe is a US-based payment platform with EU data processing infrastructure. Payment data for EU merchants is processed within the EU. Some fraud prevention and analytics functions may involve US processing. Stripe provides GDPR-compliant DPAs and SCCs. Stripe is certified under various financial compliance frameworks.

Third-party domains contacted

stripe.comjs.stripe.comapi.stripe.com

Cookies placed

NameTypeDurationPurpose
__stripe_midpersistent1 yearStripe machine identifier for fraud prevention via Stripe Radar — strictly necessary security cookie
__stripe_sidsession30 minutesStripe session identifier for fraud detection during active payment sessions

Stripe is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

Is Stripe GDPR compliant?

Yes. Stripe provides a GDPR DPA, processes EU payment data within the EU via its Irish-regulated entity, and is PCI DSS Level 1 certified. Sign the Stripe DPA from the Stripe Dashboard before processing EU personal data.

What legal basis applies to Stripe payment processing?

Contract performance (Art. 6(1)(b)) for processing the payment transaction. Legal obligation (Art. 6(1)(c)) for fraud prevention, AML, and financial regulatory record-keeping. Legitimate interest (Art. 6(1)(f)) for Stripe Radar fraud scoring. No consent is required for standard payment processing.

Do Stripe.js cookies require consent?

The __stripe_mid and __stripe_sid cookies are strictly necessary for fraud prevention (Stripe Radar). Most GDPR implementations classify these as strictly necessary security cookies exempt from consent requirements. Verify this classification with your DPO and document the justification.

Does Stripe transfer EU payment data outside the EU?

Stripe processes European payment transactions via its EU-regulated Irish entity within the EU. Some ancillary services (analytics, ML model training) may involve US processing with SCCs. The core payment processing for EU merchants stays within the EU.

How do I add Stripe to my privacy policy?

Describe: that payments are processed by Stripe, the categories of data (payment card details, billing address, device information for fraud detection), the legal bases (contract performance, legal obligation, legitimate interest for fraud prevention), and link to Stripe's privacy policy.

Do I need a DPIA for Stripe?

Generally not for standard payment processing. A DPIA becomes relevant for: Stripe Identity (processing government ID images), large-scale marketplace deployments (Stripe Connect), or platforms processing payments for sensitive goods or services.

How do I handle customer data deletion requests for Stripe?

Delete the Stripe Customer object via the Stripe API (DELETE /v1/customers/{id}). Note that Stripe must retain certain transaction records for legal and financial compliance purposes (typically 7-10 years). Communicate to data subjects that financial transaction records have a mandatory retention period.

Does using Stripe make me GDPR compliant for payments?

Stripe being GDPR-compliant as a processor does not automatically make your platform compliant. You remain the data controller and must: sign the DPA, include Stripe in your privacy policy, have a lawful basis for payment data processing, and handle customer data subject requests appropriately.