Stripe and PIPEDA: Canadian Payment Data Compliance Guide
Stripe and PIPEDA: what crosses the border, what your privacy policy must disclose, and which duties are yours rather than Stripe's.
Stripe is the dominant payment processor for Canadian SaaS, e-commerce, and subscription businesses. While Stripe handles PCI-DSS compliance for payment card data, PIPEDA creates additional obligations for Canadian businesses using Stripe — particularly around disclosure, cross-border data transfers, and the division of responsibility between your business and Stripe.
Last updated: April 2026
Stripe and PIPEDA: Who's Responsible for What?
The key to understanding your PIPEDA obligations when using Stripe is understanding the data responsibility split:
| Data Element | Who Controls It | Who Is Responsible |
|---|---|---|
| Payment card numbers | Stripe (tokenised) | Stripe (PCI-DSS) |
| Stripe customer object (email, billing address) | Stripe (your direction) | Both you and Stripe |
| Customer name and contact info | Your database | You |
| Transaction history in your system | Your database | You |
| Stripe's own analytics and fraud data | Stripe | Stripe |
The key PIPEDA principle: Under Principle 1 (Accountability), you remain responsible for personal information you transfer to Stripe on your customers' behalf. Stripe acts as a processor for your data — but you are the controller accountable to your customers.
What Stripe Collects About Your Customers
When your customers complete a Stripe checkout or payment, Stripe collects:
- Payment card details (tokenised — you never see raw card numbers)
- Billing name and address
- Email address (if provided to Stripe)
- IP address and browser/device information
- Geolocation data
- Fraud signals and risk scoring data
Stripe uses this data for:
- Processing your customer's payment
- Stripe's own fraud prevention and risk intelligence
- Stripe's own business purposes (with limitations)
Important: Stripe's Privacy Policy governs Stripe's use of the data it collects. Your customers interact with Stripe's interface and Stripe's privacy regime. You should link to Stripe's Privacy Policy in your own.
Your PIPEDA Obligations When Using Stripe
1. Disclose Stripe in Your Privacy Policy
Your privacy policy must disclose that you use Stripe for payment processing and that payment data is processed by Stripe. A clear, plain-language disclosure:
"Payment Processing: We use Stripe, Inc. to process payments. When you make a purchase, your payment information (credit card details, billing address) is transmitted directly to Stripe and is subject to Stripe's Privacy Policy (stripe.com/privacy). We do not store your full payment card details on our servers."
Also disclose:
- That Stripe stores data in the United States
- That Stripe may share data with its financial institution partners
2. Cross-Border Data Transfer Disclosure
Stripe processes payments through infrastructure primarily in the United States (and other jurisdictions). Under PIPEDA:
- Disclose that payment processing involves cross-border data transfer to the US
- Acknowledge that US laws (including surveillance laws broader than Canada's) may apply
For Quebec businesses under Law 25:
- The cross-border transfer to Stripe requires a Privacy Impact Assessment
- Document this PIA (it may be brief for a standard payment processor relationship, but it must exist)
- Stripe offers a Data Processing Addendum (DPA) — execute this with Stripe before processing Quebec customer data
3. Your Customer Data in Stripe Dashboard
Beyond the payment processing itself, you likely have customer data in your Stripe dashboard:
- Customer objects with email addresses and names
- Subscription records
- Invoice history
- Metadata you've added to Stripe objects
This data is your responsibility:
- Ensure it's subject to your data retention policies
- When a customer requests deletion of their data, delete their Stripe customer object as well as your own records
- Restrict access to your Stripe account to authorised staff only
4. Stripe Radar and Fraud Data
Stripe Radar collects device and behavioral signals from every checkout session to assess fraud risk. This constitutes personal information collection by Stripe on your behalf. Disclose in your privacy policy that fraud prevention analysis is conducted on payment transactions.
5. Stripe Connect (for Platform Businesses)
If you use Stripe Connect (marketplaces, platforms where others are paid out):
- Your connected accounts (sellers, service providers) provide personal information to Stripe
- You're responsible for ensuring your platform's connected accounts understand Stripe's data practices
- Your platform's privacy policy should address Stripe Connect data flows
Stripe Setup Checklist for Canadian Businesses
Stripe Account Configuration
- Business information: Ensure your Stripe account has accurate Canadian business information
- Tax configuration: Enable Canadian tax settings (GST/HST/PST as applicable)
- Data Processing Addendum: Sign Stripe's DPA (available in Settings → Business Settings → Compliance)
- Two-factor authentication: Enable 2FA on all Stripe Dashboard accounts
- Role-based access: Use Stripe's team management to restrict Dashboard access by role
Privacy Policy Requirements
Your privacy policy should include:
- Disclosure that Stripe is used for payment processing
- Link to Stripe's Privacy Policy
- Disclosure that payment data is processed and stored in the United States
- Description of what data Stripe may collect (billing address, IP address, fraud signals)
Customer Data Management in Stripe
For PIPEDA access and deletion requests:
When a customer requests their data:
- Export customer object from Stripe (includes billing info, payment methods on file, transaction history)
- Combine with your own records for a complete data package
When a customer requests deletion:
- Delete the Stripe customer object via API or Dashboard
- Note: Stripe retains certain data for fraud prevention and legal purposes — this is covered by Stripe's own policies
- Remove payment methods on file if the customer requests
Security for Your Stripe Integration
PIPEDA Principle 7 (Safeguards) requires appropriate technical security for personal information. For Stripe integrations:
- Use Stripe.js or Stripe Elements — these tokenise card data in the browser, preventing your servers from ever seeing raw card numbers
- Never log card details in your application logs — even partial card numbers should not appear in server logs
- Webhook endpoint security — verify Stripe webhook signatures to prevent spoofed webhook attacks
- Restrict Stripe API key access — use restricted keys with only the permissions needed for each integration
- Enable Stripe Radar — Stripe's fraud prevention reduces fraudulent transactions that could harm customers
Frequently Asked Questions
Q: Stripe says it's PCI-DSS compliant. Does this mean I don't have PIPEDA obligations? A: PCI-DSS covers payment card security — it's separate from PIPEDA. Stripe's PCI compliance means they handle card data securely. But PIPEDA applies to all personal information collected in connection with your business, including the payment transaction data that flows to Stripe.
Q: A customer wants me to delete their payment method and transaction history. What must I do? A: Delete the payment method from Stripe. For transaction history, you may need to retain certain records for tax purposes (CRA requires 7 years for financial records). Inform the customer what is being deleted and what must be retained for legal reasons.
Q: We use Stripe to store customer cards for future purchases. Is this a PIPEDA issue? A: Storing cards for future use (with Stripe's "customer" objects) requires consent. Your checkout flow should disclose that the card will be stored for future purchases and allow the customer to opt out of card storage.
Complete Payment Privacy Compliance
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Start your free trial today — payment privacy compliance that works alongside Stripe.
Related reading: Shopify PIPEDA Compliance | Google Analytics PIPEDA Compliance | PIPEDA Compliance Guide
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
Mailchimp CASL Compliance: Setup Guide for Canadian Businesses
Mailchimp's defaults are not built for CASL. How to set up audiences, record consent, segment lists ...
HubSpot CASL & PIPEDA Compliance for Canadian Businesses
Using HubSpot in Canada? You need CASL-compliant email consent, PIPEDA-compliant data handling, and ...