Merchant-facing decisions translating financial risk into payment access
Stripe
Stripe is a payment provider whose eligibility decisions can determine whether an online business can accept money. Its role in this investigation includes itch.io's reported adult-content restrictions and the use of shared merchant-risk records that can affect a business beyond one transaction.
Stripe supplies payment services to online businesses and makes decisions about which merchants and activities it will support. That places it close to the point where a broad financial policy becomes a concrete problem for a platform: a product category can no longer be sold, a payment method disappears, or a seller must find another way to receive money.
The itch.io case makes this role visible. The platform identified Stripe as its card processor and reported a restriction on content intended for sexual gratification. It also said Stripe asked it to convey that banking partners constrained sexually explicit content even though card-network rules could accommodate appropriately registered adult businesses. The account provides a view of the message received by the platform. The underlying banks and original instruction were not identified in the material obtained.
Stripe also publishes its approach to Mastercard's MATCH database. Its general practice is to disqualify listed merchants, while considering exceptional circumstances supported by documentation, such as identity theft. That is a provider policy applied to information maintained elsewhere. The practical effect can persist beyond the initial business relationship because a later processor may encounter the same risk record during its own screening.
The company's position is therefore more consequential than simply passing transactions along. It assesses eligibility, interprets restrictions and communicates the resulting conditions to customers. For creators and small platforms, those decisions can alter what is economically possible even without a new law aimed at their work. The useful trail runs through the actual restriction, the bank or network condition invoked, and the provider's own policy on exceptions and reconsideration.
Stripe → Stripe published MATCH acceptance practice
publishes general disqualification with exceptions
Stripe generally disqualifies MATCH-listed merchants but will consider documented exceptional circumstances such as identity theft. Consideration does not promise approval.
itch says Stripe asked it to convey that banking partners constrained sexually explicit content despite card-network support for appropriately registered adult content. Bank identity and original instruction missing.
Stripe implementation — MATCH screening and processing access
9 September 2026. The public implementation counterpart establishes a substantial onward effect: Stripe generally declines MATCH-listed merchants while reserving consideration for documented exceptional circumstances. This is evidence of one provider's published practice. It does not establish a Mastercard rule that every provider must reject every listed business, or loss of access to all banking.
The summaries also differ. Section 11.5, page 151, specifies five calendar days under its enumerated termination/awareness triggers, versus Stripe's one working day. Table 11.4, page 157, uses previous-three-month language and a 1.5% threshold for code 04, versus Stripe's monthly 1%; its code 05 period also differs. The manual's awkward period wording is not reconstructed into a new formula here. Section 11.13, pages 155–156, places removal with Mastercard and allows the merchant itself to request removal for cured PCI noncompliance if the acquirer is unwilling or unable, following the stated proof process. That alternative is absent from Stripe's opening acquirer-only summary.
This permits a Steam-specific attributed chain without importing Stripe's itch role. The processors remain unnamed. The existing graph node “Payment-letter addressees” is not their identity. Mastercard's denial and the June 3, 2025 rulebook remain separate retained records. The apparent disagreement could concern who communicated, what was requested, or downstream interpretation of a broad rule; it cannot be resolved by treating either public statement as the missing instruction.
Unknown: September account-by-account rollout coverage; Discord-specific Stripe retention and metadata linkage; implemented Wallet disclosure at the time of an individual test; audit proof of deletion/isolation; precise resolution of the 5CA disagreement. Neither a data-sale motive nor a common NGO/funder directing these Discord changes is established by these records. Discord/k-ID expressly deny selling the relevant user data; those are policy representations, not a forensic audit.
itch says Stripe asked it to convey that banking partners constrained sexually explicit content despite card-network support for appropriately registered adult content. Bank identity and original instruction missing.
Stripe generally disqualifies MATCH-listed merchants but will consider documented exceptional circumstances such as identity theft. Consideration does not promise approval.