Earlier quoted context omitted.
Depends on which data center you're hosted. The one under US jurisdiction operated by Hetzner US LLC must comply, while the German ones are operating under the GDPR, which has extraterritorial clauses can can deny or challenge the request.
It's not that guaranteed. The reality is that if you have any interest, company or employees in the US you can be coerced to do anything the US government wants. Either legally through courts, or through business influence, or through harassment (e.g. hardcore checks from the IRS). Sorry, Stripe rejects you now because you are high-risk (you have to explain why you refuse to help in criminal cases, though there is a…
I know what you meant, but I think that there are alternatives, even if they are maybe not as good as the ones made in US.
Also, if the goal is to go all in on data sovereignty, so be it - put the companies in the sanctions list. It will only grow.