This is the sort of area where interpretation comes into play. Who is controlling and who is processing the different personal data involved there?
Logically, your business controls the personal information about the identity of your customer, and a Stripe token associated with their card or the equivalent. You're also presumably processing that information at least for accounting purposes.
It doesn't make much sense for your business to be considered the controller of the card data that never touches your network, so Stripe ought to be considered the controller in that case, and presumably they are also processing it and potentially passing it on to further parties within the relevant card network infrastructure in order to collect payments for you.
Hopefully a regulator would agree that this is a sensible interpretation of the responsibilities. However, given the mechanics involved, where your customer might not be aware at all that they are even dealing with Stripe when they provide their payment details on your business's web site, this is the kind of area where some official confirmation would be reassuring.