Privacy implications of connecting Stripe

When self-hosting Ghost, connecting Stripe shows following warning.

Ghost will be able to see your account data (such as all payment and payout history), including any data created by other businesses you’ve connected. They’ll also be able to create new payments and take other actions for you.

Does this mean one’s Stripe data is accessible by Ghost team?

Asking from a privacy compliance perspective.

I think it’s referring to your Ghost instance, since that’s the thing that’s connecting to stripe :slightly_smiling_face:

1 Like

I am afraid that is not true.
Ghost connect connects using their official Ghost stripe account and they can see your data, which is a huge break in privacy.
The way to avoid this is to add the stripe keys directly without using stripe connect, but I think this has been disabled on the latest version as I cannot longer see the option anywhere.
This goes against the EU laws of privacy… so not sure what are the options we have to avoid using Stripe Connect here.

2 Likes