Stripe DPA and payment-compliance record
Vendor: Stripe entity applicable to the AceSense account. Status: ๐ก Standard terms are published; account-specific acceptance, transfer coverage, and production readiness are not evidenced here. Owner: Ops + DPO.
Current scopeโ
AceSense is connected to a Stripe test account and uses Stripe-hosted Checkout and the customer portal. The integration exchanges customer/subscription identifiers and signed lifecycle events. Live payment processing has not been enabled by this audit, and no API keys or account exports belong in this repository.
Authoritative termsโ
- Stripe Data Processing Agreement
- Stripe Services Agreement
- Stripe integration security and PCI guidance
These links show that standard terms and hosted payment controls exist; they do not establish which terms AceSense accepted or prove AceSense's own PCI compliance.
Required before live modeโ
- Confirm the contracting Stripe entity, AceSense legal entity, and account country.
- Record the applicable DPA version/date, acceptance mechanism, transfer terms, and sub-processor list in approved private storage.
- Inventory every field sent in Checkout, portal, customer, and webhook flows; obtain legal approval of the disclosure against that inventory.
- Add Stripe's current test-mode role to the public landing notice (
acesense-landing/public/privacy.html) and in-app notice (acesense-frontend/lib/features/legal/legal_screen.dart) on 2026-07-23. - Determine and complete the merchant's applicable PCI validation/attestation with qualified advice where needed.
- Confirm production account access controls, MFA, roles, webhook destinations, key rotation, logging, retention, deletion, and incident contacts.
- Record the live activation approval here without storing secrets.
Evidence recordโ
| Evidence | Status | Private location / date |
|---|---|---|
| Applicable DPA and transfer terms | Not verified | โ |
| Public/in-app notice implementation | Implemented; legal approval and field-inventory verification open | Landing + Flutter policy files, 2026-07-23 |
| PCI scope and validation | Not verified | โ |
| Production activation approval | Not approved | โ |
Was this page helpful?