Stripe Connect Express · non-custodial by design

Why payments with Timber are secure and non-custodial.

Timber is a marketplace intermediary, not a bank or wallet. Checkout is created on the creator's connected Stripe Express account. Stripe settles the payment there, and Timber receives only the configured platform application fee. Timber never holds user funds in custody.

Stripe-hosted onboardingStripe-hosted CheckoutVerified webhooks

01 · Onboarding architecture

Your financial details go straight to Stripe.

Timber coordinates the connection; Stripe performs the regulated account onboarding.

01

Start from Discord or the dashboard

A creator runs /payments connect or starts Connect from the web dashboard. Timber creates a Stripe Express account when needed and stores only its account ID.

02

Stripe hosts the onboarding

Timber creates a single-use Stripe account link with a return and refresh URL. The creator is redirected to Stripe's official onboarding experience.

03

Stripe verifies the creator

Banking, tax, identity, and payout details are submitted directly to Stripe. Timber does not receive, view, or intercept those sensitive details.

02 · Data boundaries

A clear line between fulfillment data and financial secrets.

What Timber stores

  • Connected Stripe account ID and onboarding completion status
  • Stripe Checkout session, payment intent, and subscription IDs
  • Customer and order metadata needed for receipts and fulfillment
  • Product metadata used to grant Discord roles or deliver digital keys

What Timber never sees

  • Full credit card numbers or CVVs
  • Bank login credentials or account passwords
  • Private balances or payout controls
  • Transactions outside a creator's Timber storefront

Timber does retain order-related information such as customer email, name, country, payment method label, amounts, currency, and Stripe identifiers so creators can manage transactions and products can be delivered.

03 · Fulfillment integrity

Automated delivery, verified at the boundary.

Timber creates Stripe Checkout sessions for the connected account, includes only the metadata needed for fulfillment, and waits for Stripe's signed webhook. The endpoint verifies the stripe-signature before any handler runs.

Cryptographic signature check

Unverified payloads are rejected with a 400 response.

checkout.session.completed

Records the order and fulfills the product, including Discord roles or digital keys.

invoice.payment_succeeded

Records successful recurring subscription payments.

customer.subscription.deleted

Removes the associated Discord role and cleans up the subscription.

04 · Compliance and control

Stripe handles card data

This implementation delegates card collection to Stripe-hosted Checkout, keeping Timber outside the card-number handling flow and relying on Stripe's PCI-DSS-compliant infrastructure.

Creators keep control

Creators can review payouts in their Stripe Express dashboard and disconnect Timber from server settings when they choose.

No hidden custody

Timber does not maintain a balance, hold a wallet, or move funds through a Timber-controlled account.

What “safe” means here: Timber minimizes its payment-data surface and relies on Stripe's security, identity verification, and compliance infrastructure. No payment system is risk-free, and Stripe remains the regulated payment processor responsible for card and payout handling.