Version 2026-05-24
Current VersionSummary: Updated to reflect the rollout of Apple in-app purchases on iOS and additional opt-in flows. Added Apple Inc. as a sub-processor for App Store payment processing, restructured the iOS/Android permissions section to list optional permissions invoked by the Stripe SDK (camera, photo library, biometrics, approximate location) and the new opt-in contact-import flow (iOS Contacts / Android READ_CONTACTS), removed absolute "does not collect" claims that no longer fit the optional flows, and noted that account deletion is now available in-app at Settings โ Delete Account.
Key Points:
- Apple Inc. added as a sub-processor for iOS in-app purchase processing (StoreKit)
- Stripe role clarified: Android and web only (cards, Google Pay)
- New ยง2.5 documents opt-in permission flows (contacts, camera, photo library, biometrics, location)
- Android
READ_CONTACTSadded for opt-in "Import from contacts" - iOS permission section expanded to list all Info.plist declarations
- Apple privacy policy added to third-party notices
- Account deletion now available in-app (Settings โ Delete Account)
- Receipt-validation idempotency added to security controls