What Stripe sees that you do not
Stripe Elements and Payment Intents are designed so the card number never touches your servers — that is what keeps you out of PCI DSS scope. But Stripe still sees the customer's name, email, billing address, IP, browser fingerprint (for Radar fraud scoring), and full transaction history. Your policy must disclose that the data is shared with Stripe directly, even though you never store it yourself.
Stripe Radar
Radar machine-learning fraud detection processes transaction signals across the entire Stripe network. If you enable Radar (most accounts do, by default), your policy must mention it. The generator outputs: "We use Stripe Radar, a fraud-prevention service operated by Stripe, to evaluate the risk of each transaction. Radar processes IP, device fingerprint, billing country, and aggregate signals from the broader Stripe network."