Terrakotta procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ California Civil Code Section 1798.83, also known as the "Shine The Light" law permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us using the contact information provided below. ” | Captured 2026-09-25Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “When a data transfer mechanism is mandated by applicable law, we employ one or more of the following: Transfers to certain countries or recipients that are recognized as having an adequate level of protection for Personal Data under applicable law. EU Standard Contractual Clauses approved by the European Commission and the UK International Data Transfer Addendum issued by the Information Commissioner’s Office. You can obtain a copy of the relevant Standard Contractual Clauses. Learn More. Other lawful methods available to us under applicable law. Stripe, Inc. complies with the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework as set forth by the U.S. Department of Commerce and as applicable. Learn More. 7. Updates and notifications We may change this Policy from time to time to reflect new services, changes in our privacy practices or relevant laws. The “Last updated” legend at the top of this Policy indicates when this Policy was last revised. Any changes are effective the latter of when we post the revised Policy on the Services or otherwise provide notice of the update as required by law. We may provide you with disclosures and alerts regarding the Policy or Personal Data collected by posting them on our website and, if you are an End User or Representative, by contacting you through your Stripe Dashboard, email address and/or the physical address listed in your Stripe account. ” | Captured 2026-09-25Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “8. Jurisdiction-specific provisions Australia. If you are an Australian resident and dissatisfied with our handling of any complaint you raise under this Policy, you may consider contacting the Office of the Australian Information Commissioner. Brazil. You may exercise your rights by contacting our DPO at dpo@stripe.com. Brazilian residents, for whom the Lei Geral de Proteção de Dados Pessoais (“LGPD”) applies, have rights set forth in Article 18 of the LGPD. Canada. As used in this Policy, “applicable law” includes the Federal Personal Information Protection and Electronic Documents Act (PIPEDA), the Personal Information Protection Act, SBC 2003 c 63, in British Columbia, the Personal Information Protection Act, SA 2003 c P-6.5, in Alberta, and the Act Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39-1 (Quebec Private Sector Act), in Quebec. Learn more. “Personal Data” includes “personal information” as defined under those laws. Stripe’s Chief Privacy Officer is the person in charge of personal information, including under the Quebec Private Sector Act. You may contact them via email at privacy@stripe.com. When Stripe collects Personal Data belonging to Canadian (including Quebec) residents, it transfers that data to data centers in the United States. When Stripe relies on service providers to process Personal Data as described herein, those service providers may also be located outside of Canada or Quebec. ” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Category K - As long as the user has an account with us ” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Category B - As long as the user has an account with us ” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). No purpose in this notice will require us keeping your personal information for longer than the period of time in which users have an account with us . ” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “Even after we stop providing Services directly to you or to a Business User that you're doing business with, and even after you close your Stripe account or complete a transaction with a Business User, we may continue to retain your Personal Data to: Comply with our legal and regulatory obligations; Enable fraud monitoring, detection, and prevention activities; and Comply with our tax, accounting, and financial reporting obligations, including when such retention is required by our contractual agreements with our Financial Partners (and where data retention is mandated by the payment methods you've used). In cases where we keep your Personal Data, we do so in accordance with any limitation periods and record retention obligations imposed by applicable law. Learn More. 6. International Data Transfers As a global business, it's sometimes necessary for us to transfer your Personal Data to countries other than your own, including the United States. These countries might have data protection regulations that are different from those in your country. When transferring data across borders, we take measures to comply with applicable data protection laws related to such transfer. In certain situations, we may be required to disclose Personal Data in response to lawful requests from officials, such as law enforcement or security authorities. Learn More. If you are located in the European Economic Area (“EEA”), the United Kingdom ("UK"), or Switzerland, please refer to our Privacy Center for additional details. ” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms and/or comply with applicable legal requirements. ” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Category I - As long as the user has an account with us ” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ We will use and retain the collected personal information as needed to provide the Services or for: Category A - As long as the user has an account with us ” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible. ” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ If you are under 18 years of age, reside in California, and have a registered account with the Services, you have the right to request removal of unwanted data that you publicly post on the Services. To request removal of such data, please contact us using the contact information provided below and include the email address associated with your account and a statement that you reside in California. We will make sure the data is not publicly displayed on the Services, but please be aware that the data may not be completely or comprehensively removed from all our systems (e.g. , backups, etc.). ” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ You can ask for the deletion of your personal information. If you ask us to delete your personal information, we will respect your request and delete your personal information, subject to certain exceptions provided by law, such as (but not limited to) the exercise by another consumer of his or her right to free speech, our compliance requirements resulting from a legal obligation, or any processing that may be required to protect against illegal activities. ” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this privacy notice unless otherwise required by law. ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “We share Representatives’ Personal Data with parties specifically authorized by the corresponding Business User, such as Financial Partners servicing a financial product, or third party apps or services the Business User chooses to use alongside our Business Services. Here are common examples of such sharing: Payment method providers, like Visa or WeChat Pay, require information about Business Users and their Representatives who accept their payment methods. This information is typically required during the onboarding process or for processing transactions for these Business Users. Learn More. A Business User may authorize Stripe to share your Personal Data with other Business Users to facilitate the provision of Services through Stripe Connect. The use of Personal Data by a third party authorized by a Business User is subject to the third party’s privacy policy. If you are a Business User who has chosen a name that includes Personal Data (for example, a sole proprietorship or family name in a company name), we will use and share such information for the provision of our Services in the same way we do with any company name. This may include, for example, displaying it on receipts and other transaction-identifying descriptions. Fraud detection and loss prevention. We use Representatives’ Personal Data to identify and manage risks that our Business Services might be used for fraudulent activities causing losses to Stripe, End Users, End Customers, Business Users, Financial Partners, and others. ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Learn more about how we use cookies and similar technologies in Stripe’s Cookie Policy. Our Business Users. When you use Link to make payments, we share your Transaction Data with the Business Users you choose to do business with. Learn More. Furthermore, when you opt to connect your bank account with Stripe, you can also direct Stripe to share your account information with Business Users you do business with. Please note that these Business Users have their own privacy policies, which should describe how they use the information shared with them. Transactions. When you use Link to make payments, we use your Personal Data (such as name, contact information, payment method details) saved with us to complete transactions with Stripe Business Users. We provide such data to Business Users and others you do business with and process it as a Data Processor for those Business Users, as detailed in Section 1.2 of this Policy. Fraud Detection and Loss Prevention. We use your Personal Data collected across our Services (such as Stripe Radar) to detect fraud and prevent financial losses for you, us, and our Business Users and Financial Partners, including detecting unauthorized purchases. We may provide Business Users and Financial Partners that utilize our fraud prevention-related Business Services with Personal Data about you (including your attempted transactions) so that they can assess the fraud or loss risk associated with the transaction. ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “We authorize these service providers to use or disclose the Personal Data we make available to them to perform services on our behalf and comply with relevant legal obligations. We mandate these service providers to contractually commit to ensuring the security and confidentiality of the Personal Data they process on our behalf. The majority of our service providers are based in the European Union, the United States of America, and India. Learn More. Financial Partners. We share Personal Data with certain Financial Partners to provide Services to Business Users seeking such Services as well as offer certain Services in conjunction with these Financial Partners. For instance, we share certain Personal Data about Representatives, such as loan repayment data and contact information, with institutional investors who purchase or provide credit that's secured through the Capital loans we've extended to the Business Users they are associated with. Others with Consent. In some situations, we may not offer a service, but instead refer you to others (like professional service firms that we partner with to deliver the Atlas Service). In these instances, we will disclose the identity of the third party and the information to be shared with them, and seek your consent to share the information. Corporate Transactions. If we enter or intend to enter a transaction that modifies the structure of our business, such as a reorganization, merger, sale, joint venture, assignment, transfer, change of control, or other disposition of all or part of our business, assets, or stock, we may share Personal Data with third parties in connection with such transaction. ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Aggregate analysis and development of business intelligence that enable us to operate, protect, make informed decisions about, and report on the performance of our business; Sharing of Personal Data with third party service providers that offer services on our behalf and business partners that help us in operating and improving our business (Learn More); Enabling network and information security throughout Stripe and our Services; and Sharing of Personal Data among our affiliates. ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We may disclose your personal information with our service providers pursuant to a written contract between us and each service provider. Learn more about how we disclose personal information to in the section, " WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION? " ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ the categories of personal information that we sold, shared, or disclosed for a business purpose; ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties. Learn more about when and with whom we share your personal information . ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ the categories of third parties to whom the personal information was sold, shared, or disclosed for a business purpose; ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Payment Data. We may collect data necessary to process your payment if you make purchases, such as your payment instrument number, and the security code associated with your payment instrument. All payment data is stored by Stripe . You may find their privacy notice link(s) here: Privacy Policy Last updated: January 16, 2024 This Privacy Policy includes important information about your personal data and we encourage you to read it carefully. Welcome We provide financial infrastructure for the internet. Individuals and businesses of all sizes use our technology and services to facilitate purchases, accept payments, send payouts, and manage online businesses. This Privacy Policy (“Policy”) describes the Personal Data we collect, how we use and share it, along with details on how you can reach out to us with privacy-related inquiries. Additionally, the Policy outlines your rights as a data subject and choices you have, including the right to object to certain usages of your Personal Data by us. For further information about our privacy practices, including our Supplemental U.S. Notice, please refer to our Privacy Center. In this Policy, “Stripe”, “we”, “our,” or “us” refers to the Stripe entity responsible for the collection, use, and handling of Personal Data as described in this document. Depending on your jurisdiction, the specific Stripe entity accountable for your Personal Data might vary. Learn More. “Personal Data” refers to any information associated with an identified or identifiable individual, which can include data that you provide to us, and we collect about you during your interaction with our Services (such as device information, IP address, etc.). ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ In Short: We may share information in specific situations described in this section and/or with the following third parties. ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Do we receive any information from third parties? We do not receive any information from third parties. ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Any other entity that buys us or part of our business will have the right to continue to use your Personal Data, but subject to the terms of this Policy. Compliance and Harm Prevention. We share Personal Data when we believe it is necessary to comply with applicable law; to abide by rules imposed by Financial Partners in connection with the use of their payment method; enforce our contractual rights; secure and protect the Services, rights, privacy, safety, and property of Stripe, you, and others, including against malicious or fraudulent activity; and to respond to valid legal requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include authorities outside your country of residence. 3. Legal bases for processing Personal Data For purposes of the General Data Protection Regulation and other applicable data protection laws, we rely on a number of legal bases to process your Personal Data. Learn More. For some jurisdictions, there may be additional legal bases, which are outlined in the Jurisdiction-Specific Provisions section below. a. Contractual and Pre-Contractual Business Relationships. We process Personal Data to enter into business relationships with prospective Business Users and End Users and fulfill our respective contractual obligations with them. These processing activities include: Creation and management of Stripe accounts and Stripe account credentials, including the assessment of applications to initiate or expand the use of our Services; Creation and management of Stripe Checkout accounts; Accounting, auditing, and billing activities; and Processing of payments and related activities, which include fraud detection, loss prevention, transaction optimization, communications about such” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “We also use information about you obtained from third parties like credit bureaus and from our Services to address such risks, including to identify patterns of misuse and monitor for terms of service violations. Stripe may share Representatives' Personal Data with Business Users, our Financial Partners, and third party service providers to verify the information provided by you and identify risk indicators. Learn More. We also use and share Representatives' Personal Data to conduct due diligence, including conducting anti-money laundering and sanctions screening in accordance with applicable law. Advertising. Where allowed by applicable law, we use and share Representatives’ Personal Data with third parties so we can advertise and market our Services. Subject to applicable law, including any consent requirements, we may advertise through interest-based advertising and track the efficacy of such ads. See our Cookie Policy. We do not transfer your Personal Data to third parties in exchange for payment. However, we may provide your data to third party partners, like advertising partners, analytics providers, and social networks, who assist us in advertising our Services. Learn more. We may also use your Personal Data, including your Stripe account activity, to evaluate your eligibility for and offer you Business Services or promote existing Business Services. Learn more. More. For further information about additional ways by which we may use and share Representatives’ Personal Data, please see the More ways we collect, use, and share Personal Data section below. ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “How? All financial companies need to share customers' personal information to run their everyday business. In the section below, we list the reasons financial companies can share their customers' personal information; the reasons Stripe chooses to share; and whether you can limit this sharing. Reasons we can share your personal information Does Stripe Share? Can you limit this sharing For our everyday business purposes – such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus Yes No For our marketing purposes - to offer our products and Services to you Yes No For joint marketing with other financial companies Yes No For our affiliates' everyday business purposes - information about your transactions and experiences Yes No For our affiliates' everyday business purposes - information about your creditworthiness No We don’t share For our affiliates to market to you No We don’t share For nonaffiliates to market to you if you are a Link user Yes Yes For nonaffiliates to market to you if you are a Financial Connections user No We don’t share To limit our sharing Login to your Link account at app.link.com/account and toggle off data sharing from the Account menu. Please note: If you are a new customer, we can begin sharing your information 30 days from the date we sent this notice. When you are no longer our customer, we continue to share your information as described in this notice. ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Our Business Users (and their authorized third parties). We share End Customers' Personal Data with their respective Business Users and parties directly authorized by those Business Users to receive such data. Here are common examples of such sharing: When a Business User instructs Stripe to provide another Business User with access to its Stripe account, including data related to its End Customers, via Stripe Connect. Sharing information that you have provided to us with a Business User so that we can send payments to you on behalf of that Business User. Sharing information, documents, or images provided by an End Customer with a Business User when the latter uses Stripe Identity, our identity verification Service, to verify the identity of the End Customer. The Business Users you choose to do business with may further share your Personal Data with third parties (like additional third party service providers other than Stripe). Please review the Business User’s privacy policy for more information. Advertising by Business Users. If you initiate a purchasing process with a Business User, the Business User receives your Personal Data from us in connection with our provision of Services even if you don't finish your purchase. The Business User may use your Personal Data to market and advertise their products or services, subject to the terms of their privacy policy. Please review the Business User’s privacy policy for more information, including your rights to stop their usage of your Personal Data for marketing purposes. ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “See the Other Important Information section below for more information on your rights under state law. What happens when I limit sharing for an account I hold jointly with someone else? Your choices will apply to everyone on your account. Definitions Affiliates Companies related by common ownership or control. They can be financial and nonfinancial companies. • Our affiliates include companies operating under the Stripe name, such as Stripe Payments Europe, Limited and Stripe Payments UK Ltd. Nonaffiliates Companies not related by common ownership or control. They can be financial and nonfinancial companies. • Nonaffiliates with which we share personal information include service providers that perform services or functions on our behalf, Business Users with which you choose to transact, partners with which we share data to provide you with services, and advertising partners, analytics providers, and social networks, who assist us in advertising our Services to you. Joint Marketing A formal agreement between non-affiliated financial companies that together market financial products or services to you. • Our joint marketing partners include financial companies we partner with to provide you with financial services. Other important information Vermont: If your account with us is associated with a Vermont billing address, we will not disclose information about your creditworthiness to our affiliates and will not disclose your personal information, credit report, or health information to nonaffiliated third parties to market to you, other than as permitted by Vermont law, unless you authorize us to make those disclosures. ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “Customer also acknowledges that Plivo's use of Customer's data and information shall subject to the terms of Plivo's privacy policy found at https://www.plivo.com/privacy , as modified from time to time. All voice calls by Customer using the Plivo Services are subject to carrier regulations within the region of use and the region that the call is made and/or received. Customer acknowledges and agrees that the Service, including Plivo Services, does not allow Customer to access any 911 or similar emergency services. The Service, including Plivo Services, is not intended to replace any primary phone service that may be used to contact emergency services. Notwithstanding anything herein to the contrary, Customer agrees it is fully responsible for and Company hereby disclaims any liability arising from Customer's use of the Plivo Services.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We may need to share your personal information in the following situations: Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company. ” | Captured 2026-09-25Open source →Finding permalink → |
| Tier differences | All applicable tiers | unknown | “ 5.1. General. Customer will pay Company the then applicable fees described in the Order for the Service in accordance with the terms herein (the "Fees"). If Customer's use of the Services requires the payment of additional fees (per the terms of this Agreement), Customer shall be billed for such usage and Customer agrees to pay the additional fees in the manner provided herein. Company reserves the right to change the Fees or applicable charges and to institute new charges and Fees at the end of the Initial Term or then-current Renewal Term, upon fifteen (15) days prior notice to Customer (which may be sent by email). 5.2. Customer authorizes Company to charge Payment Provider upon execution of this Agreement for Customer's Initial Term, and again at the beginning of any Renewal Term for the fees agreed upon. Customer charges may change if Company changes its pricing with notice to Customer. If Customer chooses to terminate this Agreement, Customer's subscription will no longer renew and Company will not charge Customer's payment provider for the subsequent Renewal Term. Upon renewal, if Company does not receive payment from Customer's Payment Provider, (a) Customer agrees to pay all amounts due on its account upon demand and/or (b) Customer agrees that Company may either terminate this Agreement or suspend Customer's access to its account and the Service and continue to attempt to charge Customer's Payment Provider until payment is received (upon receipt of payment, Customer's account will be re-activated). ” | Captured 2026-09-25Open source →Finding permalink → |
| Tier differences | All applicable tiers | unknown | “ 5.3. If Customer believes that Company has billed Customer incorrectly, Customer must contact Company no later than 30 days after the closing date on the first billing statement in which the error or problem appeared, in order to receive an adjustment or credit. Inquiries should be directed to Company's customer support department. 5.4. Company may choose to bill through an invoice, in which case, full payment for invoices issued in any given month must be received by Company thirty (30) days after the mailing date of the invoice. Unpaid amounts are subject to a finance charge of 1.5% per month on any outstanding balance, or the maximum permitted by law, whichever is lower, plus all expenses of collection and may result in immediate termination of Service. Customer shall be responsible for all taxes associated with Services other than U.S. taxes based on Company's net income.” | Captured 2026-09-25Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.