FORGE Stripe Payment Processing Notice
Effective date: August 15, 2026
Last reviewed against Stripe materials: August 15, 2026
This notice explains the division of responsibilities between Mediator Solutions LLC, operator of FORGE, and Stripe, the payment-services provider used for FORGE subscription and related payment flows.
1. Stripe is the payment processor / payment-services provider
FORGE uses Stripe to provide payment-processing and related billing infrastructure for transactions that are actually routed through Stripe.
Depending on the Stripe product, jurisdiction, and processing purpose, Stripe may act as a processor/service provider on the business user’s instructions, a controller/business for Stripe’s own purposes, or both in different contexts.
Stripe’s current Privacy Center explains that Stripe acts as a processor when it facilitates payment transactions on behalf of and at the direction of a Stripe business user. Stripe also acts as a controller for activities for which Stripe determines the purposes and means, including providing Stripe services, fraud prevention, security, regulatory compliance, and development or improvement of Stripe products.
Stripe is not solely a subprocessor in every circumstance. For payment data, Stripe may have its own legal responsibilities and independent processing purposes.
2. Stripe entity naming
Stripe’s legal entities and roles vary by the customer’s or business user’s location and by the Stripe product involved.
Stripe’s current Privacy Center states that, for users in the Americas, the primary Stripe data-controller entity for most services is Stripe, LLC, while other Stripe entities may be involved for regulated or non-U.S. services.
FORGE public legal text should normally use the brand-level formulation “Stripe” or “Stripe and its applicable affiliates” unless a specific contract, checkout flow, or local legal notice requires naming the exact Stripe entity.
This reduces the risk of hard-coding an entity that becomes inaccurate when Stripe changes its contracting structure or a transaction is processed under another local Stripe entity.
3. Card details are collected through Stripe payment surfaces
Where FORGE uses a Stripe-hosted Checkout page, Stripe-hosted customer portal, Stripe payment element, or another Stripe integration designed to send payment credentials directly to Stripe, full card credentials are collected and processed by Stripe rather than stored in the ordinary FORGE application database.
FORGE may receive limited payment and billing metadata from Stripe, such as:
- Stripe customer identifiers;
- subscription identifiers;
- payment or invoice status;
- billing period information;
- price or product identifiers;
- transaction identifiers;
- payment-method brand and limited non-sensitive details that Stripe returns;
- fraud, failure, dispute, refund, or event status needed to administer the FORGE account.
FORGE should not ask a user to send full card numbers, card security codes, online-banking credentials, or similar sensitive payment credentials through support email, free-form notes, uploads, or ordinary FORGE data-entry fields.
4. PCI DSS is a shared responsibility
Stripe states that it is certified as a PCI Level 1 Service Provider. That fact does not mean that every business using Stripe is automatically “PCI certified” or that a merchant has no PCI obligations.
Stripe’s current integration-security guidance states that PCI compliance is a shared responsibility: Stripe maintains its provider-level compliance, while the business accepting payments must use a PCI-compliant integration and complete the validation or attestation applicable to that business and integration.
FORGE therefore may truthfully say that:
- payment-card processing is routed through Stripe when the Stripe payment flow is used;
- Stripe maintains its own PCI Service Provider Level 1 certification;
- a low-risk Stripe integration can reduce the amount of card data that passes through FORGE systems.
FORGE must not publish a blanket badge or statement that FORGE is PCI certified, Mediator Solutions is PCI Level 1, or using Stripe eliminates all PCI obligations unless we separately have the documentation required to support that exact statement.
5. Recurring subscription disclosure remains our responsibility
Stripe provides subscription billing infrastructure, but Stripe’s Services Agreement places obligations on the Stripe business user for recurring transactions.
Before the initial recurring transaction, FORGE must clearly inform the customer that:
- the transaction is recurring or ongoing;
- the amount or pricing method is disclosed;
- the billing interval is disclosed;
- the method for cancelling recurring billing or the subscription is explained.
The FORGE checkout and pre-checkout disclosure must therefore clearly identify recurring charges before the customer purchases. We should not rely on Stripe’s backend subscription object alone as the customer-facing disclosure.
6. Authorizations and mandates
Where law or payment-method rules require a customer authorization, mandate, agreement for future use of a payment method, or disclosure about merchant-initiated transactions, FORGE is responsible for obtaining and retaining the authorization required of the merchant/business user.
Stripe may provide the technical mechanism for collecting or storing a payment method, but that does not transfer every merchant disclosure or authorization obligation to Stripe.
FORGE must preserve evidence reasonably necessary to demonstrate the customer’s checkout assent, subscription selection, applicable terms, and authorization where required.
7. Cancellation
Stripe provides APIs and a Stripe-hosted customer portal that can support subscription cancellation. FORGE may use those mechanisms as part of the customer experience.
Our customer-facing Terms and Billing Policy determine the commercial effect of cancellation, subject to applicable law and the actual Stripe subscription configuration.
If FORGE represents that cancellation takes effect at the end of the current paid period, the Stripe subscription must be configured consistently with that representation. If FORGE offers immediate cancellation, prorations or refunds, the billing implementation must match the disclosed policy.
A legal policy and a Stripe Dashboard setting must not contradict each other.
8. Refunds
Stripe provides technical mechanisms for initiating refunds, but the merchant remains responsible for its refund policy and for deciding when a refund is due, except where law or card-network rules require a particular outcome.
FORGE must:
- state the refund policy accurately before purchase where required;
- initiate a promised refund through the payment system within the time required by our policy, applicable law, and Stripe rules;
- avoid telling customers that “Stripe decides our refund policy” when that is not true;
- distinguish a Stripe processing limitation from FORGE’s underlying obligation to the customer.
Stripe may delay or refuse execution of a refund instruction in circumstances allowed by its agreement, such as account-balance or risk conditions. That does not automatically extinguish any independent obligation FORGE may owe the customer.
9. Disputes, chargebacks, and reversals
Stripe provides dispute-management tooling and transmits dispute information between the merchant and relevant financial networks. Under Stripe’s Services Agreement, the Stripe business user remains financially responsible for disputes, refunds, reversals, and related amounts unless a dispute is ultimately resolved in the user’s favor under the applicable payment-method rules.
FORGE must therefore maintain enough transaction and assent records to respond to legitimate disputes, such as:
- account email;
- checkout or subscription record;
- Terms version or assent record where available;
- transaction and invoice identifiers;
- service-access records reasonably relevant to fulfillment;
- cancellation and refund communications;
- customer-support correspondence relevant to the dispute.
We must not fabricate evidence, alter transaction history, or submit misleading dispute materials.
10. Stripe Customer Portal
Where enabled, the Stripe-hosted customer portal may allow customers to manage billing information, invoices, payment methods, and subscription cancellation or other subscription settings.
The features actually available depend on our Stripe configuration. Public FORGE copy must not promise a portal capability that is disabled in the Stripe account.
11. Failed payments and retries
Stripe may retry failed subscription payments according to the configuration selected in the Stripe account and the capabilities of Stripe Billing.
FORGE must not state a fixed retry count or automatic-cancellation timeline unless that behavior is actually configured and intended as our commercial policy. Stripe settings can be changed, and Stripe documentation describes configurable retry and cancellation behavior.
Our Billing Policy should therefore use implementation-aware language for payment retries rather than promising a number of retries that the Stripe account does not guarantee.
12. Fraud prevention and payment security
Stripe may process transaction, device, network, account, and payment information for fraud prevention, authentication, security, risk analysis, legal compliance, and operation of Stripe services.
Those activities may be performed by Stripe in its own controller/business role even when Stripe is also processing a payment on FORGE’s instructions.
The FORGE Privacy Policy should disclose that payment providers may independently process information for fraud prevention, security, payment-network compliance, and legal obligations.
13. Taxes
Stripe may provide tax-calculation or tax-related products if separately enabled, but use of Stripe as a payment processor does not by itself mean Stripe assumes all of FORGE’s tax obligations.
FORGE remains responsible for determining the taxes it must collect, report, remit, or disclose unless a specific Stripe product and applicable agreement expressly allocate a particular function to Stripe.
Public copy should not say Stripe handles our taxes merely because Stripe processes the charge.
14. Merchant of record
Using Stripe for payment processing does not, by itself, make Stripe the merchant of record for FORGE.
Unless a separate Stripe product or written agreement expressly provides otherwise, Mediator Solutions LLC remains the seller / contracting business for FORGE, while Stripe provides payment-processing and related services.
FORGE legal text, receipts, billing descriptors, checkout disclosures, and customer support should be consistent with that allocation.
15. Customer support responsibility
Customers may interact with Stripe-hosted payment pages, but ordinary questions about the FORGE subscription, service, cancellation policy, refund eligibility, invoice meaning, account entitlement, or fulfillment remain FORGE customer-support matters unless the issue specifically concerns a Stripe-controlled payment surface or payment-method problem.
We should not route every billing complaint to Stripe simply because Stripe processed the payment.
16. Privacy requests involving Stripe
A customer may have privacy rights against FORGE, Stripe, or both depending on the information and each party’s processing role.
FORGE will address verified requests concerning personal information for which Mediator Solutions is the responsible business/controller. Where a request concerns data Stripe controls for Stripe’s own purposes, the customer may also need to exercise rights directly with Stripe.
Where Stripe processes data only on FORGE’s instructions, we may need to use Stripe’s business-user tools or support channels to carry out the relevant request.
17. No Stripe endorsement claim
Use of Stripe does not authorize FORGE to claim that Stripe endorses, sponsors, certifies, approves, or guarantees FORGE.
Any Stripe trademarks or badges must be used only in accordance with Stripe’s applicable brand and trademark rules.
18. Contact
Mediator Solutions LLC
Email: [email protected]