The Truth About Stripe Connect and Store Privacy. Think Your Stripe Data Is Private? Maybe Not.
Shahjahan JewelΒ ohh, I thought these instructions for the 2ndary connection process had been removed - thank you for the link!!
I'm going to add to my comments here to say that (1) I was already aware that Stripe Connect shares data with the devs (whether that's Automattic or Kajabi, as examples) and that (2) of all the companies I'd be concerned about around this WPManageNinja doesn't even make the list.
As far as Stripe Connect, I really do not like how the connection process takes over the account and usually cannot be fully deleted (and sometimes can't even be partially deleted). So that's why I'm pleased we have alternative connection options.
And I'm seriously studying the US options to get rid of Stripe.
Shahjahan Jewel Thank you very much for offering the traditional Stripe integration as well, making FluentCart viable for us with customers from the EU.
When it comes to GDPR and transfering customer data outside EU:
https://www.simpleanalytics.com/nl/is-avg-conform/stripe
https://usercentrics.com/guides/privacy-policies-of-major-platforms/stripe-privacy-policy/
ps. using local country payment processor is much better when it comes to disputes rather than dealing with US based company when it comes to business located in EU (IMHO).
- Hidden Data Exposure:Β UsingΒ Stripe ConnectΒ (the easy, one-click setup) grants theΒ plugin developerΒ (the Stripe "platform account") the technical ability to view certain store data.
- Data Included:Β The exposed data includesΒ customer names, email addresses, and transaction historyΒ (like sales volume). Credit card numbers areΒ notΒ exposed.
- The Cause:Β This is an unintended side effect of Stripe pushing all developers to use Stripe Connect for better security. Stripe Connect was originally designed for SaaS and marketplaces where this data access is expected.
- Developer Responsibility:Β The developer is likely not checking your data, but theΒ capabilityΒ is there. Store owners should be aware and consider this when choosing plugins and updating their privacy policies.
- The Secure Alternative is Risky:Β The only way to achieve true data isolation from the plugin developer is to useΒ direct API keys. However, this is significantly less secure and risks a major breach if "God mode" API keys are compromised in the WordPress environment.
- Final Assessment:Β The security benefits of Stripe Connect (no leaked API keys) generallyΒ outweighΒ the minimal privacy risk of a trustworthy developerΒ potentiallyΒ seeing transaction data.
- Call to Action:Β The actual pressure should be put on Stripe to create a secure connection method thatΒ does notΒ expose transaction data for self-hosted WordPress plugins.
Here's my question on this as I'm actually looking to update my credit card info for subscription of FluentCRM. If I go to my account in WP Manage Ninja to update the credit card info, where does that get stored? The current payment method says "Stripe" and therefore I'm assuming that because of the Stripe Connect, that if I update my card info there, that this is with Stripe. Does the WP Manage Ninja team see this info. Curious given this conversation thread, and thinking about the words that we might need to include in the "privacy" info on our sites.