Stripe added Microsoft Azure and Snowflake as cloud subprocessors

Stani Mihov

Founder & CEO

·

TL;DR

What changed:

  • Microsoft Azure and Snowflake are now on Stripe's main subprocessor list as cloud service providers for business and end customer data.

  • A new Data Pipeline section lists five cloud providers: AWS, Databricks, Google, Microsoft, and Snowflake.

  • A new section for consumer credit cards adds LoanPro for loan management and January for collections.

  • InscribeAI moved from the Identity section to the general list, and Mitek Systems was removed.

  • Metronome, a company Stripe acquired, is now listed as an affiliate for usage-based billing.

What to do: If you use Stripe and want to object to a new subprocessor, the page gives you 30 days from the September 27 update, which runs to October 27.

The change

Stripe keeps a public list of its subprocessors, service providers, and affiliates: the outside companies and Stripe entities that may process personal data on behalf of the businesses that use Stripe. Stripe's Data Processing Agreement refers to this page as the "Stripe Sub-processors List."

On September 27, 2026, Stripe published a new version of the page, replacing the one dated December 20, 2025. The page includes Stripe's own summary of what changed. Venpo flagged the update the same day, and the redline is on the public change page.

What changed

  • Microsoft Azure as a cloud provider. A new entry lists "Microsoft Corporation (Microsoft Azure)" as a "Cloud Service Provider" for "Business User and Representative data and End Customer data." Microsoft was already on the list, but only to "provide AI technology to improve the quality of user support operations."

  • Snowflake. Snowflake is new to the page, listed as a cloud service provider for "Business User data and End Customer data."

  • Data Pipeline. A new section lists five cloud service providers "for Stripe Data Pipeline": Amazon Web Services, Databricks, Google, Microsoft, and Snowflake. Databricks does not appear anywhere else on the page.

  • Consumer credit cards. A new section, "End Customer Credit Card Services," lists LoanPro Software for "Loan management services" and January Technologies, which "Manages collections relating to credit cards." Both process data of "customers and applicants for a credit card for personal use through a Business User."

  • Identity and checks. InscribeAI moved from the Stripe Identity section to the general list, which Stripe says is because it also uses InscribeAI for other Capital and Financial Connections work. Mitek Systems, previously listed for paper check scanning, was removed.

  • Terminal hardware. A single UK shipping partner was replaced by "various fulfillment and distribution partners," including Federal Express, Flexport, and VeriFone, and the purpose now covers warranty claims and repairs as well as shipping.

  • Affiliates. Metronome Technologies, which Stripe describes as "a company Stripe acquired," is listed for usage-based billing and metering. Stripe Italy S.r.l. replaced the Italian branch, Lemon Squeezy now appears under its new name, Sold Through Link, and references to Stripe, Inc. were removed because the entity "no longer exists."

What the Azure entry does and does not say

The new Azure entry describes Microsoft only as a "Cloud Service Provider," in the same terms as the existing AWS entry. It does not say which Stripe products run on Azure, and the only location it gives is Microsoft's entity country, the United States.

One detail is worth noting for anyone reviewing AI use. The link Stripe attached to the Azure entry points to a Microsoft page about data privacy for its Azure OpenAI service, not to a general Azure privacy page. The entry itself does not mention AI, so if AI processing matters to your review, that is a question to put to Stripe directly rather than an answer the page gives.

What stays the same

The rules around the list did not change. Under the DPA, a business using Stripe "may reasonably object in writing" to a new subprocessor "within 30 days following the update of this page," and if it does not, the new subprocessor "shall be deemed accepted." Stripe also still offers email notifications of subprocessor updates through the communication preferences in the Stripe dashboard.

Some changes add transparency. The page now links to the separate subprocessor lists of TaxJar, Privy, and Bridge, which Stripe acquired, and adds a country for Lob.com. The other identity verification providers, including London Stock Exchange Group and Trulioo, are still listed with the same role.

Why this matters

Stripe processes some of the most sensitive data a business has: its own account details and the payment and personal data of its customers. The subprocessor list decides which outside companies may handle that data, and every addition starts a 30-day clock after which silence counts as acceptance.

For most companies the new names are familiar, and Azure and Snowflake are unlikely to be objectionable on their own. What matters is keeping the record accurate: security questionnaires, customer DPAs, and privacy notices often ask which providers sit behind a payment processor. Subprocessor lists change often, as we saw when SurveyMonkey changed its AI providers and Klaviyo added new subprocessors alongside its DPA update. Keeping up with them is the core of subprocessor monitoring.

Potential impact

For any business that uses Stripe, the update raises four practical questions:

  • Does your own record of Stripe's subprocessors include Microsoft Azure and Snowflake?

  • If you use Stripe Data Pipeline, do you know which of the five listed providers handle your data?

  • If you offer credit cards to your customers through Stripe, do you know that LoanPro and January now process applicant data?

  • Is someone subscribed to Stripe's subprocessor notifications, and who would decide on an objection before October 27?

Short objection windows like this one are among the vendor legal changes that pass unnoticed unless someone is watching.

How Venpo detected it

Venpo monitors Stripe's legal pages as part of continuous vendor risk monitoring. On September 27, it flagged the new version of the subprocessor list and marked each added, moved, and removed entry. The full redline is on the Stripe change page, and every monitored Stripe document is listed on the Stripe vendor profile.

Business outcome

Teams that track Stripe knew about the new subprocessors on the day the page changed, with the full 30-day objection window still ahead of them. That leaves time to update the vendor record, answer questions from their own customers, and raise concerns with Stripe if they have any. The alternative is finding out after October 27, when the new subprocessors already count as accepted.

Key takeaway

Stripe added Microsoft Azure and Snowflake as cloud providers, named five providers for Data Pipeline, and added two partners for consumer credit cards, with 30 days for businesses to object. Because silence counts as acceptance, automated monitoring is what turns a 30-day window into a real choice.

The change

Stripe keeps a public list of its subprocessors, service providers, and affiliates: the outside companies and Stripe entities that may process personal data on behalf of the businesses that use Stripe. Stripe's Data Processing Agreement refers to this page as the "Stripe Sub-processors List."

On September 27, 2026, Stripe published a new version of the page, replacing the one dated December 20, 2025. The page includes Stripe's own summary of what changed. Venpo flagged the update the same day, and the redline is on the public change page.

What changed

  • Microsoft Azure as a cloud provider. A new entry lists "Microsoft Corporation (Microsoft Azure)" as a "Cloud Service Provider" for "Business User and Representative data and End Customer data." Microsoft was already on the list, but only to "provide AI technology to improve the quality of user support operations."

  • Snowflake. Snowflake is new to the page, listed as a cloud service provider for "Business User data and End Customer data."

  • Data Pipeline. A new section lists five cloud service providers "for Stripe Data Pipeline": Amazon Web Services, Databricks, Google, Microsoft, and Snowflake. Databricks does not appear anywhere else on the page.

  • Consumer credit cards. A new section, "End Customer Credit Card Services," lists LoanPro Software for "Loan management services" and January Technologies, which "Manages collections relating to credit cards." Both process data of "customers and applicants for a credit card for personal use through a Business User."

  • Identity and checks. InscribeAI moved from the Stripe Identity section to the general list, which Stripe says is because it also uses InscribeAI for other Capital and Financial Connections work. Mitek Systems, previously listed for paper check scanning, was removed.

  • Terminal hardware. A single UK shipping partner was replaced by "various fulfillment and distribution partners," including Federal Express, Flexport, and VeriFone, and the purpose now covers warranty claims and repairs as well as shipping.

  • Affiliates. Metronome Technologies, which Stripe describes as "a company Stripe acquired," is listed for usage-based billing and metering. Stripe Italy S.r.l. replaced the Italian branch, Lemon Squeezy now appears under its new name, Sold Through Link, and references to Stripe, Inc. were removed because the entity "no longer exists."

What the Azure entry does and does not say

The new Azure entry describes Microsoft only as a "Cloud Service Provider," in the same terms as the existing AWS entry. It does not say which Stripe products run on Azure, and the only location it gives is Microsoft's entity country, the United States.

One detail is worth noting for anyone reviewing AI use. The link Stripe attached to the Azure entry points to a Microsoft page about data privacy for its Azure OpenAI service, not to a general Azure privacy page. The entry itself does not mention AI, so if AI processing matters to your review, that is a question to put to Stripe directly rather than an answer the page gives.

What stays the same

The rules around the list did not change. Under the DPA, a business using Stripe "may reasonably object in writing" to a new subprocessor "within 30 days following the update of this page," and if it does not, the new subprocessor "shall be deemed accepted." Stripe also still offers email notifications of subprocessor updates through the communication preferences in the Stripe dashboard.

Some changes add transparency. The page now links to the separate subprocessor lists of TaxJar, Privy, and Bridge, which Stripe acquired, and adds a country for Lob.com. The other identity verification providers, including London Stock Exchange Group and Trulioo, are still listed with the same role.

Why this matters

Stripe processes some of the most sensitive data a business has: its own account details and the payment and personal data of its customers. The subprocessor list decides which outside companies may handle that data, and every addition starts a 30-day clock after which silence counts as acceptance.

For most companies the new names are familiar, and Azure and Snowflake are unlikely to be objectionable on their own. What matters is keeping the record accurate: security questionnaires, customer DPAs, and privacy notices often ask which providers sit behind a payment processor. Subprocessor lists change often, as we saw when SurveyMonkey changed its AI providers and Klaviyo added new subprocessors alongside its DPA update. Keeping up with them is the core of subprocessor monitoring.

Potential impact

For any business that uses Stripe, the update raises four practical questions:

  • Does your own record of Stripe's subprocessors include Microsoft Azure and Snowflake?

  • If you use Stripe Data Pipeline, do you know which of the five listed providers handle your data?

  • If you offer credit cards to your customers through Stripe, do you know that LoanPro and January now process applicant data?

  • Is someone subscribed to Stripe's subprocessor notifications, and who would decide on an objection before October 27?

Short objection windows like this one are among the vendor legal changes that pass unnoticed unless someone is watching.

How Venpo detected it

Venpo monitors Stripe's legal pages as part of continuous vendor risk monitoring. On September 27, it flagged the new version of the subprocessor list and marked each added, moved, and removed entry. The full redline is on the Stripe change page, and every monitored Stripe document is listed on the Stripe vendor profile.

Business outcome

Teams that track Stripe knew about the new subprocessors on the day the page changed, with the full 30-day objection window still ahead of them. That leaves time to update the vendor record, answer questions from their own customers, and raise concerns with Stripe if they have any. The alternative is finding out after October 27, when the new subprocessors already count as accepted.

Key takeaway

Stripe added Microsoft Azure and Snowflake as cloud providers, named five providers for Data Pipeline, and added two partners for consumer credit cards, with 30 days for businesses to object. Because silence counts as acceptance, automated monitoring is what turns a 30-day window into a real choice.

Real-time change notifications

Stay ahead of every legal change

Get updates, product news and expert tips on navigating legal changes

Stripe updated Terms of Service

Dispute resolution clause now requires mandatory arbitration in all regions

High Impact2 hours ago
AWS modified Privacy Policy

Data retention period extended from 2 years to 5 years for all services

Medium Impact5 hours ago
Shopify revised Acceptable Use Policy

New restrictions on AI-generated content in product descriptions

Review1 day ago
Slack changed Data Processing Agreement

Third-party data sharing expanded to include analytics partners

High Impact1 day ago

Real-time change notifications

Stay ahead of every legal change

Get updates, product news and expert tips on navigating legal changes

Stripe updated Terms of Service

Dispute resolution clause now requires mandatory arbitration in all regions

High Impact2 hours ago
AWS modified Privacy Policy

Data retention period extended from 2 years to 5 years for all services

Medium Impact5 hours ago
Shopify revised Acceptable Use Policy

New restrictions on AI-generated content in product descriptions

Review1 day ago
Slack changed Data Processing Agreement

Third-party data sharing expanded to include analytics partners

High Impact1 day ago