Two pages in your dashboard cover "your account," and they do different jobs. Profile shows who Stripe thinks you are — your billing name, address, and business details. Security is where you actually change your username, password, or email. Knowing which one to open saves a trip to the wrong page.
Everything on the Profile page — name, phone, business name, and address — is read directly from your Stripe customer record, not stored separately on this site. There's nothing to type here; the only action available is an "Edit in Stripe" button that opens Stripe's own hosted billing portal, where those fields actually get changed.
If your account role doesn't include billing access, this page shows a simpler view instead — just your username and account email, with a note that billing and address details aren't available for your role. That's expected, not an error.
Three separate forms, each doing one thing:
3–20 characters, lowercase letters, numbers, and underscores. Sub-accounts can't change their username from this page — that action is blocked outright for any account signed in as a team member rather than the owner.
Only shown if you actually have a password to change. If you signed up or sign in with Google, this card is replaced with a note that password management happens through your Google account instead — there's no local password to update.
This one has a deliberate extra step: it asks for your current password before accepting a new email, even though you're already logged in — a re-check specifically for a change this sensitive. Submitting it doesn't change your email immediately:
Like password, this form doesn't appear at all for Google-SSO accounts — Google manages that email address, not this site.
The Security page also has the switch for two-factor authentication and your trusted-device list. That's covered in full in setting up two-factor authentication — worth reading before you turn it on, since a few of its behaviors (like clearing trusted devices) aren't reversible.