The Shipyard ✓Download everything
Free kit · No email wall · Every number sourced

The Stripe Survival Kit

Know how close you are to a payout freeze in 60 seconds — and take away the reasons it usually happens.

Payouts on hold. A banner that says your account is under review. A dispute due in 7 days. This kit shows your risk in real numbers, closes the leaks that cause it, and gives you the exact words for each case.

Get your win in 5 minutes ↓See everything inside
What this would cost you
$1,500
What it costs you
$0
  • 60 secDispute Rate Calculator
  • 20 min52-point prevention checklist
  • 15 min each6 dispute response templates
  • 5 minDispute Responder (Claude skill)
  • Read nowThe 48-hour frozen-account plan
  • 1 minSame responder for ChatGPT & Gemini
60 sec
to your dispute rate vs the card-network lines
52
prevention checks across 9 areas
6
dispute responses, one per Stripe category
14
documents in the frozen-account evidence pack
9
customer emails that stop disputes before they start

Your 5-minute win: know your number

Runs 100% in your browser. Nothing is sent anywhere — not even to me.

  1. The calculator below opens with sample data. Replace it with last month's numbers from Stripe: successful payments (Payments → Succeeded) and disputes (Disputes — count all of them, won or lost).
  2. Read your zone and your room: how many more disputes you can take this month before 0.75% and before 1%.
  3. Do the 3 one-minute checks: a statement descriptor customers recognize, a refund policy one click from checkout, your support email on every receipt.
Dispute Rate CalculatorOpen full screen ↗

Everything inside

7 pieces. Each one does one job, in minutes.

📊

Dispute Rate Calculator

Your rate against 6 official Visa, Mastercard and Stripe lines, your risk zone, and how many more disputes you can take this month.

60 secOpen ↗
✅

52-point prevention checklist

Descriptor, policies, checkout, 3DS, Radar, delivery logs, subscriptions, monitoring. Score yourself at the end.

20 minOpen ↗
🛡️

6 dispute response templates

One per Stripe category: what the bank needs to see, evidence mapped to Stripe's fields, and a fill-in rebuttal letter.

15 min eachSee it ↓
🤖

Dispute Responder (Claude skill)

Give it the dispute, the order and your logs. Get fight-or-accept, an evidence plan and a one-page rebuttal. It never invents evidence.

🧊

The 48-hour frozen-account plan

Hour by hour: which of the 4 situations you're in, the evidence pack, the one reply to send, and how to keep selling.

Read nowOpen ↗
💬

Same responder for ChatGPT & Gemini

One paste-in prompt. No install, works in any AI chat.

1 min
✉️

9 customer emails

Receipt, trial and renewal reminders, cancellation, refund, "checkout moved". Each one closes a common reason to dispute.

Copy & pasteOpen ↗

6 dispute responses, 9 customer emails, the 48-hour plan & the 52 checks

Open any of them to read it, or copy the whole thing in one click.

Template 01: Fraudulent (and Unrecognized)

Stripe category: fraudulent · also use for unrecognized Typical codes: Visa 10.4 (card-absent fraud) · Mastercard 4837 (no cardholder authorization), 4863 (does not recognize) · Amex F29, 176

The claim: "I didn't make this purchase" or "I don't recognize this charge." Stripe notes that "unrecognized" is "effectively indistinguishable from the Fraudulent reason" (Stripe).


What the bank needs to see

One or more of these (Stripe: dispute categories):

  • The real cardholder (or someone they authorized, like a family member or employee) made the payment.
  • The payment was authenticated with 3D Secure, so liability shifted to the issuer. Stripe adds the 3DS data for you.
  • You already refunded it.
  • The customer withdrew the dispute or admitted they recognize the charge.
  • Visa only: Compelling Evidence 3.0 (see below).

Fight or accept?

SituationDecision
You see logins and usage after purchase from the same IP/device as the purchase, and the email matches the cardholderFight
Returning customer with 2+ undisputed payments on the same card, 120–364 days old (Visa)Fight with CE 3.0
Payment was 3DS-authenticatedFight (Stripe adds 3DS evidence)
Account was created minutes before purchase, never used, IP country ≠ card country, disposable emailAccept. This is probably real fraud. Revoke access. Add a Radar rule.
Several payments on different cards from the same IP in one hourAccept all of them, revoke access, and look at card testing defenses

Visa Compelling Evidence 3.0 check (2 minutes)

From Stripe: Visa CE 3.0:

  • Visa dispute with network reason code 10.4
  • At least 2 earlier payments on the same payment method, paid and never disputed, not validation charges
  • Those payments are 120 to 364 days before the disputed one
  • All three payments match on 2 main elements (customer purchase IP + device fingerprint or device ID), or 1 main + 1 secondary (shipping address, customer email, customer account ID)
  • Product descriptions for the disputed and earlier payments, and the type set to merchandise or services

If eligible, Stripe usually pre-fills the fields. Don't edit pre-filled CE 3.0 fields: Stripe warns that changes can affect eligibility (Stripe). Still fill in the normal evidence too, in case the CE 3.0 submission is rejected.

Evidence to attach (digital product / SaaS)

EvidenceStripe fieldWhat to put in it
Customer IP at purchasecustomer_purchase_ipFrom your checkout logs or the Stripe payment
Customer namecustomer_nameAs entered at checkout
Customer emailcustomer_email_addressThe account email
Access and activity logsaccess_activity_logLogins, downloads, feature use after payment, with IPs and timestamps. Highlight matches with the purchase IP or device.
Other evidenceuncategorized_file / uncategorized_textDevice location at time of purchase; device ID; earlier undisputed payments on the same card; any proof a household member made it; CVC check result if it failed but was approved or was unchecked
Customer communicationcustomer_communicationAny email from the customer's address after purchase (support requests, replies to onboarding)

Rebuttal letter

Re: Dispute on charge [CHARGE_ID], [AMOUNT] [CURRENCY], [PURCHASE_DATE]

We believe this payment was made by the cardholder, and ask that this dispute be reversed.

[PRODUCT_NAME] is a [one-line description, e.g. "web-based AI writing tool, billed monthly"].
The customer bought [PLAN] on [DATE] at [TIME TZ] using the email [EMAIL].

Timeline
1. [DATE TIME]: Purchase from IP [IP], [CITY/COUNTRY], device [DEVICE/BROWSER]. (Exhibit A)
2. [DATE TIME]: Access email delivered to [EMAIL]. (Exhibit B)
3. [DATE] to [DATE]: [N] logins from the same IP/device as the purchase, using [specific features: e.g. "created 37 documents"]. (Exhibit C)
4. [If applicable] [DATE]: Customer emailed support from [EMAIL] about [topic], confirming they had access. (Exhibit D)
5. [If applicable] The same card paid us on [DATE] and [DATE] without any dispute. (Exhibit E)
6. [DATE]: Dispute opened. No contact from the customer before the dispute. / The customer contacted us on [DATE] and said [summary].

[If 3DS] The payment was authenticated with 3D Secure.
[If CE 3.0] This dispute qualifies for Visa Compelling Evidence 3.0; matching prior transactions are included.

Evidence attached
A. Purchase record with IP and device
B. Delivery email log
C. Account activity log after purchase
D. Customer emails
E. Prior undisputed payments on the same card

We ask that this dispute be reversed in our favor.
[YOUR NAME], [BUSINESS NAME], [SUPPORT EMAIL]

Mistakes that lose this one

  • Sending activity logs that start before the payment, or without IPs.
  • Arguing "the customer agreed to our terms". In a fraud dispute, the question is who paid, not whether the terms were fair.
  • Fighting obvious fraud. You lose the fee, the time, and the rate still goes up.

Prevent the next one

Recognizable descriptor. Receipts with your brand and support email. Collect IP and email on every payment. 3DS for elevated risk. Refund early fraud warnings on small charges.

Made by Dan Shipped — @danshipped. Not legal advice.

Template 02: Product not received

Stripe category: product_not_received Typical codes: Visa 13.1 (merchandise/services not received) · Mastercard 4855 · Amex C08

The claim: "I paid and never got access" or "the service was never provided."


What the bank needs to see

From Stripe: dispute categories:

  • The product was delivered, or isn't due yet (for example, a cohort that starts next month).
  • You already refunded it.
  • The customer withdrew the dispute.

For digital products, Stripe says to "focus on evidence of usage, login, or download", because there's no tracking number.

Fight or accept?

SituationDecision
Logs show login, download, or use after paymentFight
The delivery date hasn't arrived (pre-sale, cohort starts later) and it was stated at purchaseFight
Access email bounced, account never activated, no loginsAccept or refund. Fix your delivery.
Outage or bug blocked access during the period they paid forAccept (or partial refund if they used part of it)

Evidence to attach (digital product / SaaS)

EvidenceStripe fieldWhat to put in it
Customer IP at purchasecustomer_purchase_ip
Customer namecustomer_name
Customer emailcustomer_email_address
Delivery and access logsaccess_activity_logProof the customer accessed or downloaded the product after paying: IPs, timestamps, actions. Include the access email send/delivery log.
Customer communicationcustomer_communicationAny messages. If they never contacted you before disputing, say so clearly.
Otheruncategorized_file / uncategorized_textDevice location and ID; proof the delivery date hasn't arrived yet; if only part was undelivered, show the disputed amount exceeds the undelivered part

Rebuttal letter

Re: Dispute on charge [CHARGE_ID], [AMOUNT] [CURRENCY], [PURCHASE_DATE]

The customer received and used the product. We ask that this dispute be reversed.

[PRODUCT_NAME] is a [digital product / web app]. Access is delivered [instantly by email / by account login] at [URL, as text, not a link].

Timeline
1. [DATE TIME TZ]: Purchase of [PLAN/PRODUCT] by [EMAIL]. (Exhibit A)
2. [DATE TIME TZ]: Access email sent and delivered to [EMAIL]. (Exhibit B)
3. [DATE TIME TZ]: First login / first download from IP [IP]. (Exhibit C)
4. [DATE] to [DATE]: [N] sessions; [specific usage: "downloaded 3 files", "completed 6 of 10 lessons", "made 1,204 API calls"]. (Exhibit C)
5. [DATE]: Dispute opened. The customer did not contact us before opening it. / The customer wrote on [DATE]; we replied within [X] hours. (Exhibit D)

[If not yet due] The purchase was for [cohort/program] starting [DATE], as shown on the checkout page (Exhibit E). The service is not due yet.

Evidence attached
A. Order record
B. Delivery email log
C. Access and usage log after purchase
D. Customer communication (or statement that none was received)
E. Checkout page showing the delivery date [if applicable]

We ask that this dispute be reversed in our favor.
[YOUR NAME], [BUSINESS NAME], [SUPPORT EMAIL]

Mistakes that lose this one

  • "We sent the email" with no proof it was delivered or opened. Show the send log and the first login.
  • Usage logs from a different email than the buyer's, without explaining the link (e.g. a team seat).
  • Links to your app or a Loom video. Banks won't click. Screenshots only.

Prevent the next one

Instant welcome email with a big access button. A "didn't get it? reply here" line on the receipt. Log first login and first download. Chase unactivated accounts at 24 hours.

Made by Dan Shipped — @danshipped. Not legal advice.

Template 03: Not as described (Product unacceptable)

Stripe category: product_unacceptable Typical codes: Visa 13.3 (not as described or defective), 13.5 (misrepresentation) · Mastercard 4853 · Amex C31, C32

The claim: "It's not what was advertised," "it doesn't work," or "it was misrepresented."


What the bank needs to see

From Stripe: dispute categories:

  • The product was accurately represented before purchase.
  • It wasn't defective.
  • You already refunded it, or the customer withdrew the dispute.

Stripe also says to include your refund policy and how you disclosed it. Depending on the network, the issuer "might or might not take this into consideration, but it can't hurt your case".

Fight or accept?

SituationDecision
Your sales page matches what they got, they used it, and they never asked for helpFight
They asked for a refund within your policy window and you didn't give itAccept. Honor your policy next time.
Your page promised results ("make $5k in 30 days")Accept and rewrite the page. Misrepresentation claims are hard to beat, and income claims are a restricted-business risk.
A real bug made the core feature unusable during their periodAccept or partial refund

Evidence to attach (digital product / SaaS)

EvidenceStripe fieldWhat to put in it
Product description as shown before purchaseproduct_description / uncategorized_fileScreenshot of the sales page and checkout as of the purchase date (keep dated archives). Highlight the parts the claim is about.
Customer communicationcustomer_communicationEvery message. If they never contacted you, say so.
Access and usage logsaccess_activity_logShows the product worked and was used: IPs, timestamps, actions
Refund policy + disclosurerefund_policy, refund_policy_disclosureThe policy text, and where it was shown before purchase (checkout screenshot)
Otheruncategorized_file / uncategorized_textIf partly used, show the dispute exceeds the unused value; any replacement or fix you provided; any refund already issued

Rebuttal letter

Re: Dispute on charge [CHARGE_ID], [AMOUNT] [CURRENCY], [PURCHASE_DATE]

The product was described accurately and worked as described. We ask that this dispute be reversed.

What we sold: [PRODUCT_NAME]. Before purchase, the sales page stated: "[exact quote of the key promise]" (Exhibit A, captured [DATE]).
What the customer received: [exactly that: e.g. "access to the web app with features X, Y, Z on the Pro plan"].

Timeline
1. [DATE]: Purchase. The customer accepted our terms, which include our refund policy: "[short quote]" (Exhibit B).
2. [DATE] to [DATE]: The customer used the product [N] times, including [specific actions]. (Exhibit C)
3. [DATE]: [The customer never contacted support before the dispute.] / [The customer asked about X. We replied on DATE with Y.] (Exhibit D)
4. [DATE]: Dispute opened.

The customer's claim is "[cardholder's words from the bank documents]". This does not match the product as described: [one or two factual sentences].

[If applicable] Our policy offers a refund within [N] days of purchase. The customer did not request one during that period.

Evidence attached
A. Sales page and checkout as shown before purchase
B. Terms and refund policy as accepted at checkout
C. Usage log after purchase
D. Customer communication

We ask that this dispute be reversed in our favor.
[YOUR NAME], [BUSINESS NAME], [SUPPORT EMAIL]

Mistakes that lose this one

  • Showing today's sales page instead of the one the customer saw. Archive your pages when you change them.
  • Arguing about the customer's skill ("they didn't use it right"). Show the facts and the usage.
  • Ignoring the bank's text. Answer the specific complaint.

Prevent the next one

Describe features and limits plainly. No outcome promises. Show the plan comparison at checkout. Offer a short no-questions refund window: a refund costs less than a dispute and doesn't touch your rate.

Made by Dan Shipped — @danshipped. Not legal advice.

Template 04: Subscription canceled

Stripe category: subscription_canceled Typical codes: Visa 13.2 (canceled recurring) · Mastercard 4841 · Amex C28

The claim: "I canceled, and you kept charging me." This is the most common category for SaaS and memberships.


What the bank needs to see

From Stripe: dispute categories:

  • The subscription was still active, and the customer knew your cancellation procedure and didn't follow it.
  • Or you already refunded, or the customer withdrew the dispute.

Stripe also lists, for digital products: the controls you give customers to manage automated billing and monitor usage; that the product was used before the billing date; that the customer has the cancellation date wrong (e.g. it was set for a future date); and that a payment was an installment, not a true recurring charge (some networks only allow this reason code for recurring payments).

Fight or accept?

SituationDecision
No cancellation in your system, the customer kept logging in after the chargeFight
They canceled after the renewal charge, and your policy (shown at checkout) says no refunds on renewalsFight, but consider a refund. This is where most "friendly" disputes come from.
They emailed "please cancel" before renewal and you missed itAccept. Fix your support process.
Your app had no self-serve cancel, or it was hiddenAccept and add an in-app cancel button this week
No renewal reminder before an annual chargeProbably accept. Add reminders.

Evidence to attach (digital product / SaaS)

EvidenceStripe fieldWhat to put in it
Cancellation policy as showncancellation_policyThe exact text
How and when it was shown before purchasecancellation_policy_disclosure"Shown in full at checkout above the Subscribe button, and in the confirmation email (Exhibit B)."
Why this charge is validcancellation_rebuttal"No cancellation request was received before the renewal on [DATE]. Self-serve cancellation is available in Settings → Billing."
Renewal notice or continued usecustomer_communicationThe renewal reminder email you sent, and/or proof of use after the date they claim they canceled
Otheruncategorized_file / uncategorized_textBilling controls you offer (cancel button, usage dashboard, spend caps); login log after the claimed cancel date; account audit log showing no cancellation event

Rebuttal letter

Re: Dispute on charge [CHARGE_ID], [AMOUNT] [CURRENCY], renewal on [RENEWAL_DATE]

The subscription was active and was not canceled before this renewal. We ask that this dispute be reversed.

Subscription terms: [PLAN], billed [monthly/yearly] at [PRICE]. At signup on [DATE], the customer actively agreed to recurring billing (Exhibit A: checkout with consent checkbox and full terms).
Cancellation: customers can cancel anytime in Settings → Billing, with one click. Cancellation takes effect at the end of the paid period. This was stated at checkout and in the welcome email (Exhibit B).

Timeline
1. [DATE]: Subscription started; [N] previous renewals were paid without dispute.
2. [DATE]: Renewal reminder sent to [EMAIL], [N] days before the charge, with a cancel link. (Exhibit C)
3. [RENEWAL_DATE]: Renewal charge. No cancellation request existed in our system or support inbox. (Exhibit D: account audit log)
4. [DATE] to [DATE]: The customer logged in [N] times after the renewal and used [features]. (Exhibit E)
5. [DATE]: Dispute opened. [No cancellation or refund request was ever sent to us.]

Evidence attached
A. Checkout terms and consent
B. Welcome email with cancellation instructions
C. Renewal reminder email
D. Account audit log (no cancellation event)
E. Usage after renewal

We ask that this dispute be reversed in our favor.
[YOUR NAME], [BUSINESS NAME], [SUPPORT EMAIL]

Mistakes that lose this one

  • Saying "they could have canceled" when your cancel flow needed an email to support.
  • No proof of consent to recurring billing at signup.
  • No reminder before an annual renewal. Card-network rules require reminders for trials (Visa: at least 7 days before a free or promotional trial ends; Mastercard: 3 to 7 days for digital-goods trials), and Stripe recommends renewal reminders (Stripe).

Prevent the next one

In-app cancel button. Instant cancellation confirmation. Reminder about 7 days before yearly renewals and 2–3 days before monthly ones. Refund in full if someone cancels the day after a renewal.

Made by Dan Shipped — @danshipped. Not legal advice.

Template 05: Duplicate

Stripe category: duplicate Typical codes: Visa 12.6.1 (duplicate processing), 12.6.2 (paid by other means) · Mastercard 4834 · Amex P08, C14

The claim: "I was charged twice for the same thing" or "I already paid another way."


What the bank needs to see

From Stripe: dispute categories:

  • Each payment was for a separate product or service.
  • Or you already refunded, or the customer withdrew the dispute.

Fight or accept?

SituationDecision
Two charges for two different things (e.g. a plan + an add-on, two seats, two months)Fight
An upgrade and a prorated charge that look alikeFight, and explain the proration in one sentence
A real double charge (retry bug, double-click)Accept, refund the duplicate if not already disputed, fix the integration. Stripe says your integration should handle errors without double-charging.
They paid by invoice/bank transfer and also by card for the same thingAccept

Evidence to attach (digital product / SaaS)

EvidenceStripe fieldWhat to put in it
The other charge's IDduplicate_charge_idThe ch_... ID of the payment the customer thinks is the duplicate
Why they're differentduplicate_charge_explanation"Charge 1 was the Pro plan for March. Charge 2 was 500 extra credits bought on March 12."
Receipts for bothduplicate_charge_documentationBoth receipts side by side, each with its line items
Customer communicationcustomer_communicationAny messages
Otheruncategorized_file / uncategorized_textUsage showing both items were delivered (two seats in use, credits consumed); any refund already issued

If no duplicate charge exists, Stripe says you can open All Fields from the gear menu in the Dashboard and give other evidence instead.

Rebuttal letter

Re: Dispute on charge [CHARGE_ID], [AMOUNT] [CURRENCY], [DATE]

These are two separate purchases, not a duplicate. We ask that this dispute be reversed.

Charge 1: [OTHER_CHARGE_ID], [DATE], [AMOUNT], for [ITEM 1]. (Exhibit A)
Charge 2 (disputed): [CHARGE_ID], [DATE], [AMOUNT], for [ITEM 2]. (Exhibit B)

The difference: [one sentence, e.g. "Charge 1 renewed the monthly plan. Charge 2 is a one-time purchase of 500 credits that the customer made from the Billing page at 14:32 UTC."]

Both were delivered: [e.g. "The 500 credits were added at 14:32 UTC and 431 have been used since." (Exhibit C)]

Evidence attached
A. Receipt for charge 1
B. Receipt for charge 2
C. Delivery/usage of the second item

We ask that this dispute be reversed in our favor.
[YOUR NAME], [BUSINESS NAME], [SUPPORT EMAIL]

Mistakes that lose this one

  • Receipts without line items. If both just say "Payment – $29", the bank can't tell them apart.
  • Not checking whether it really was a double charge before fighting.

Prevent the next one

Itemized receipts. Different statement descriptor suffixes per product type (e.g. SHIPPED* PRO PLAN vs SHIPPED* CREDITS). Idempotency keys on payment requests so a retry can't charge twice (Stripe: error handling).

Made by Dan Shipped — @danshipped. Not legal advice.

Template 06: Credit not processed

Stripe category: credit_not_processed Typical codes: Visa 13.6 (credit not processed), 13.7 (canceled merchandise/services) · Mastercard 4860 · Amex C02, C05

The claim: "I was promised a refund and never got it" or "I canceled and should get money back."


What the bank needs to see

From Stripe: dispute categories:

  • You already issued the refund the customer is entitled to.
  • Or the customer isn't entitled to a refund under the policy they were shown.
  • Or the customer withdrew the dispute.

For digital products, Stripe also suggests showing whether the customer used the product in whole or in part, and whether the dispute amount exceeds the unused portion.

Fight or accept?

SituationDecision
You already refunded (full or the agreed partial)Fight, with the refund record. Note: a partially refunded payment can still be disputed for the full amount.
They're outside your refund window, and the policy was shown in full before purchaseFight
You promised a refund by email and didn't send itAccept
Your policy was only a link in the footerProbably accept, and fix checkout. Stripe says a link alone may not count as disclosure (Stripe).

Note: you can't refund outside the dispute process once a dispute exists (Stripe). If you agree with the customer, accept the dispute.

Evidence to attach (digital product / SaaS)

EvidenceStripe fieldWhat to put in it
Refund / cancellation policyrefund_policy, cancellation_policyThe policy text as shown at the time of purchase
How it was shown before purchaserefund_policy_disclosure, cancellation_policy_disclosureCheckout screenshot with the full text and the consent checkbox
Why no (further) refund is owedrefund_refusal_explanation, cancellation_rebuttal"The policy offers refunds within 14 days. The request came on day 41." Or: "A partial refund of $X was issued on DATE for the unused months."
Customer communicationcustomer_communicationThe refund request and your reply
Otheruncategorized_file / uncategorized_textRefund record (Stripe refund ID, date, amount); usage showing the product was used; withdrawal message if any

Rebuttal letter

Re: Dispute on charge [CHARGE_ID], [AMOUNT] [CURRENCY], [PURCHASE_DATE]

[Option A] The refund the customer was entitled to has already been issued.
[Option B] The customer is not entitled to a refund under the policy shown before purchase.
We ask that this dispute be reversed.

Policy shown at checkout: "[exact quote of the refund policy]" (Exhibit A). The customer accepted it on [DATE] by [checking the box / clicking Subscribe].

Timeline
1. [DATE]: Purchase of [PRODUCT/PLAN].
2. [DATE] to [DATE]: Usage: [specific actions]. (Exhibit B)
3. [DATE]: Customer requested a refund, [N] days after purchase. (Exhibit C)
4. [Option A] [DATE]: We refunded [AMOUNT], refund ID [re_...]. It is visible on the customer's statement within [X] business days. (Exhibit D)
   [Option B] [DATE]: We replied explaining the [N]-day refund window and offered [cancellation of future renewals / credit / partial refund]. (Exhibit C)
5. [DATE]: Dispute opened.

Evidence attached
A. Refund policy as shown at checkout, with acceptance
B. Usage log
C. Customer communication
D. Refund record [if applicable]

We ask that this dispute be reversed in our favor.
[YOUR NAME], [BUSINESS NAME], [SUPPORT EMAIL]

Mistakes that lose this one

  • Quoting a refund policy that changed after the purchase.
  • Promising "I'll process your refund" by email and forgetting. That email becomes the customer's best evidence.

Prevent the next one

Refund the same day you agree to. Send a refund confirmation email with the amount and the expected timing (template in templates/customer-messages.md). Keep policy versions with dates.

Made by Dan Shipped — @danshipped. Not legal advice.

The quarterly risk check

Do it this week, then once a quarter and before every launch. Your progress is saved on this device.

The numbers that matter

Write these on a sticky note. They are the lines the card networks use. They are not Stripe's private rules, which nobody outside Stripe knows.

How the rate is counted (this changes the math)

  • Stripe "dispute activity": disputes received in a period ÷ successful payments in that period. This is the version the networks use for their programs (Stripe: measuring disputes).
  • Visa: disputes + fraud reports in a month ÷ transactions in the same month. Count-based (Visa VAMP fact sheet).
  • Mastercard: chargebacks this month ÷ transactions last month (Stripe: monitoring programs). After a big launch month followed by a quiet month, your Mastercard rate can jump even if nothing went wrong.

The thresholds (verified October 2026)

LineWhat happens thereExtra conditionSource
0.5%Visa VAMP "non-compliant" level, as listed by Stripe. Visa may assess fees.VAMP count of 5Stripe
0.75%"The credit card processing industry standard recognizes dispute activity above 0.75% as excessive."A spike can trigger action earlierStripe
1%Mastercard MATCH code 4 (Excessive Chargebacks), applied if an account is terminatedChargebacks ≥ $5,000 in the same monthStripe
1.5%Visa VAMP Excessive Merchant (AP, Canada, EU, US; lowered from 2.2% on April 1, 2026; LAC was already 1.5%)1,500+ fraud + disputes in the monthVisa, Stripe
1.5%Mastercard Excessive Chargeback Merchant (ECM). Fines start in month 2 ($1,000) and rise to $100,000 by month 19.100+ chargebacksStripe
1.8%Visa VMSS code 22 (Excessive Disputes), applied if an account is terminated and you didn't remediate1,000 disputes; ratio by amountStripe
2.2%Visa VAMP Excessive Merchant, CEMEA region150+ count and $75,000+Visa
3%Mastercard High Excessive (HECM). Fines up to $200,000.300+ chargebacksStripe

The small-seller trap. The big programs need 100 or 1,500 disputes a month, so a small SaaS will almost never be fined. Don't relax. The 0.75% line and the MATCH 1% line have no big count minimum. And at low volume, 2 disputes on 150 payments is already 1.3%. Stripe itself says that if you have "fewer than 100 payments per month", one or two fraud disputes can have "a very outsized impact" on your rate (Stripe: best practices).

My working rule (an opinion, not a rule from Stripe): treat 0.5% as yellow, 0.75% as red, and 1% as an emergency. The calculator uses these zones.

What a dispute costs you

In the US, Stripe charges a $15 "dispute received" fee, plus a $15 "dispute countered" fee if you submit evidence. You get the countered fee back if you win. You never get the received fee back (Stripe Support: dispute pricing). Fees differ by country, so check your own pricing page. Add the product you already delivered and the hours you spend. A US $29 sale that you fight and lose costs you $59 ($29 + $15 + $15) plus your time. Even if you win, you're out the $15 received fee, and the dispute still counts toward your rate.

Bonuses

Because one kit should feel like ten.

$300+BONUS #1

The reply Stripe's review team can act on

One complete answer, in their order, with labeled documents. Plus the 14-document evidence pack to build in a calm week.

See it ↓
8 lines, sourcedBONUS #2

The 8 lines, from 0.5% to 3%

Every Visa and Mastercard threshold, how each network counts your rate, and what one lost dispute really costs.

See it ↓
$150BONUS #3

"Checkout moved" emails

Emails 8 and 9: move customers to a new checkout or ask them to re-add a card, without a wave of "I don't recognize this" disputes.

See it ↓
8 more kitsBONUS #4

The Shipyard vault

Every other free kit I've made: Money-Back Kit, Claude OS, First 100 Customers and more.

Open the vault ↓

The full playbook

The deep dives, when you want them.

Why it happens: the real triggersread

A processor isn't trying to punish you. It's protecting itself. When a customer disputes a charge, the money comes out of the processor's side first. If you can't cover it, the processor eats the loss. So risk teams watch for signs that losses are coming.

Stripe says it uses "a combination of machine learning models, heuristics and human reviews" to detect risk (Stripe Unacceptable Risk Policy, updated July 29, 2026). It doesn't publish the exact rules. But its docs name the patterns plainly. Here they are, with sources.

Trigger 1: A sudden, unexplained volume spike

Stripe lists "an unexplainable sharp increase in processing volume" as a reason it places a reserve (Stripe Support: reserves). It also says that "a sudden spike or steep upward trend" can put you in a monitoring program before you reach 0.75% (Stripe: measuring disputes).

Why it scares them: a launch that does $40,000 in 3 days on an account that did $2,000 a month looks like a business that will be gone before its refunds arrive. Card networks let cardholders dispute for up to 120 days, sometimes longer (Stripe: how disputes work). Your processor carries that tail.

What takes the reason away: tell them before it happens (see the checklist), keep your fulfillment proof clean, and keep cash in the account during the 120-day tail.

Trigger 2: High dispute (chargeback) activity

This is the big one. Stripe lists "elevated dispute activity" as a reserve reason (Stripe Support: reserves). Above certain levels, Visa and Mastercard put the account into monitoring programs with fines, and Stripe has to act (Stripe: monitoring programs).

Three facts most founders miss:

  1. Winning doesn't help your rate. "All disputes, whether they're won or lost, count towards your dispute rate" (Stripe: measuring disputes).
  2. Refunds don't count as disputes, but a refund doesn't erase a dispute that already happened. The networks "don't consider refunds when identifying disputes" (Stripe: monitoring programs). Refunding before the customer goes to their bank is what keeps your rate low.
  3. Early fraud warnings count on Visa. Visa's main program (VAMP) adds fraud reports (TC40) to disputes (TC15). The same transaction can be counted twice (Stripe: monitoring programs; Visa VAMP fact sheet).

Trigger 3: A descriptor or website that doesn't match

When the name on the bank statement doesn't match what the customer bought, they think it's fraud. Stripe's advice for both "fraudulent" and "unrecognized" disputes starts with the same line: make your statement descriptor "easily recognizable" and reflect "the URL or business name they would associate with their purchase" (Stripe: dispute categories).

Mismatch also shows up on the risk side. If your Stripe profile says "productivity software" and your site sells a trading course, that gap is exactly what a reviewer looks for. Stripe also says to keep one Stripe account per business: "Each Stripe account should represent a single business" (Stripe: best practices).

Trigger 4: Restricted or prohibited business categories

Stripe keeps a public list of businesses it can't support, or can support only with extra approval (Stripe: Restricted Businesses, updated September 22, 2026). The ones that most often catch digital sellers:

  • "Get rich quick" schemes: investment opportunities or other services that promise high returns to deceive consumers. Many "make $10k/month" courses sit close to this line.
  • Multi-level marketing: commission or recruitment-based selling.
  • Deceptive practices: excessive claims, misleading testimonials, high-pressure sales tactics.
  • Adult content, including AI-generated adult content.
  • Some platform models: platforms that host third-party creators who get paid need extra approval.

Plain SaaS isn't restricted. What gets founders in trouble is the marketing around the product. If your landing page promises income, read that list line by line.

Trigger 5: Missing or hidden policies

Stripe's website checklist asks for a description of what you sell, the currency, customer service contacts ("something besides contact forms"), refund, cancellation and delivery policies, a privacy policy, promotion terms, and a secure checkout (Stripe: website checklist). If a reviewer can't find them, Stripe says it may ask you to add them.

Policies also matter in disputes. Stripe warns that a checkbox containing only a link to your policy may be rejected by the bank as evidence. There must be "reasonable evidence that you presented your customer with a full copy of your policies prior to their purchase" (Stripe: best practices).

Trigger 6: Fraud patterns and card testing

Fraudsters test stolen cards on small checkouts. Digital products with instant delivery and $5 price points are a favorite target. Visa runs a separate "enumeration" monitor for card testing (300,000 attempts and a 20% ratio) (Stripe: monitoring programs). Even far below that level, a wave of declined test charges, followed by fraud warnings and disputes, shows up in your risk profile.

Trigger 7 (new): Being young and growing fast in Asia Pacific

From October 2026, Visa's Merchant Elevated Risk Program (MERP) applies to businesses accepting Visa in Asia Pacific. It looks at new accounts before they have big volume. Visa looks at fraud, disputes and declines together and doesn't publish thresholds. Possible results include backdated fraud disputes, account closure, and a listing other processors can see (Stripe: monitoring programs).

What actually happens: the 4 levels

What you seeWhat it meansCan you still sell?Source
Reserve (fixed or rolling)A % of your funds is held for a set time to cover future refunds and disputes.Yes. "Reserves do not impact a business's ability to continue accepting payments."Stripe Support: reserves
Payouts paused, info requestedStripe needs documents or verification before paying out.Usually yes, while you respond.Your Dashboard banner
Charges or payouts restricted for riskStripe may pause charges, pause payouts, or reverse payments.Maybe not.Unacceptable Risk Policy
Account closedPayouts are typically held for 120 days from the notice email. You can appeal from the Dashboard.No.Unacceptable Risk Policy

The worst case sits past all four: a listing on Mastercard's MATCH or Visa's VMSS list. Those listings last 5 years, and most processors automatically reject listed businesses and owners (Stripe: high-risk merchant lists). Everything in this kit exists so you never get near that.

Prevention: take away every reasonread

Full list: checklists/prevention.md (52 checks). Here's the logic behind it, in 6 layers.

  1. Be recognizable. Descriptor, receipt, and website all use the same name. The customer should never have to wonder "what is this charge?"
  2. Be findable. Support email (not just a form), refund policy, terms, privacy policy, business address. All one click from checkout.
  3. Be clear before the money moves. Price, currency, billing frequency, trial end date, renewal terms, all shown before the card form. A checkbox for the terms with the full text, not only a link.
  4. Make leaving easy. One-click cancellation in the app. Renewal reminders before annual charges. Refund fast when someone asks. Every refund you give is a dispute you don't get.
  5. Log delivery. For digital products there's no tracking number. Your proof is logs: account created, first login, downloads, API calls, with IP addresses and timestamps. Stripe asks for exactly this as access_activity_log (Stripe: dispute categories). Start logging today. You can't create these logs after a dispute arrives.
  6. Watch the dial. Check your dispute rate weekly. Tell Stripe before a launch. Refund obvious fraud before it becomes a dispute.

Radar rules worth testing

Custom rules need a Radar plan that supports them. Test each rule against your past payments before you turn it on, and start with Review before Block. Stripe's rule tester runs on your last 6 months of payments, and you can roll a rule out to a small share of traffic first (Stripe: Radar rules). These examples follow Stripe's documented syntax:

Request 3D Secure if :risk_level: != 'normal' and :amount_in_usd: > 25
Request 3D Secure if is_missing(:seconds_since_card_first_seen:)
Review if :is_disposable_email: and :card_funding: = 'prepaid'
Block if :card_country: != 'US' and :risk_level: = 'elevated'
Block if :is_3d_secure: and not :is_3d_secure_authenticated:

Why 3D Secure matters: if a payment is authenticated with 3DS, liability for most fraud disputes "typically shifts from the seller to the issuer" (Stripe: Radar rules). Two catches. Too much 3DS can lower conversion. And you still receive early fraud warnings, which count in Visa's program (Stripe: best practices).

Stripe also warns EU businesses that the Geo-blocking Regulation limits blocking customers by EU country (Stripe: Radar rules). Check your local rules before you write any country rule.

When to refund an early fraud warning

Stripe's own data: about 40% of Visa and Mastercard early fraud warnings become fraud disputes if you don't refund. Its suggestion is to refund flagged charges roughly at or below your dispute fee, and not to bother above about 135% of it (Stripe: how disputes work). The exception: if your rate is already high, or you have under 100 payments a month, refund more aggressively (Stripe: best practices).

For a SaaS with access you can revoke, refund and revoke. For a $9 template that's already been downloaded, the refund costs less than the dispute.

When a dispute arrives: fight smart, not alwaysread

You get one shot. Stripe sends your response to the bank immediately, and "you can't edit the response or submit more files" (Stripe: respond to disputes). You usually have 7 to 21 days depending on the network, and missing the deadline loses the dispute automatically. The bank then takes 60 to 75 days to decide (Stripe: how disputes work).

Should you fight it?

Fight when you can prove the customer's claim is wrong. Accept (or refund at the inquiry stage) when they're right. Use this quick test:

QuestionIf yes
Did they actually not get access, get charged twice, or ask for a refund your policy promised?Accept. Fix the cause.
Do you have logs showing they used the product after paying?Fight.
Is it a Visa fraud dispute (code 10.4) from a returning customer?Fight. Check Visa Compelling Evidence 3.0 eligibility (below).
Was the payment 3DS-authenticated?Fight. Stripe adds the 3DS proof automatically.
Is the amount smaller than your fees plus an hour of your time?Probably accept, unless you need the win to discourage a repeat abuser.

The 6 templates

Each file in templates/dispute-responses/ gives you: what the bank needs to see, the evidence to attach for SaaS and digital products (mapped to Stripe's evidence fields), a fill-in rebuttal letter, and the mistakes that lose cases.

Stripe categoryTypical Visa / Mastercard codesTemplate
Fraudulent (and Unrecognized)Visa 10.4 · Mastercard 4837, 486301-fraudulent.md
Product not receivedVisa 13.1 · Mastercard 485502-product-not-received.md
Product unacceptable (not as described)Visa 13.3, 13.5 · Mastercard 485303-not-as-described.md
Subscription canceledVisa 13.2 · Mastercard 484104-subscription-canceled.md
DuplicateVisa 12.6.1, 12.6.2 · Mastercard 483405-duplicate.md
Credit not processedVisa 13.6, 13.7 · Mastercard 486006-credit-not-processed.md

Codes from Stripe: dispute categories. Mastercard maps some codes to more than one category, so always read the category Stripe shows on the dispute.

Visa Compelling Evidence 3.0: the one most SaaS founders miss

For Visa fraud disputes with code 10.4, you can point to the customer's own history. You need at least 2 earlier, undisputed payments on the same card, made 120 to 364 days before the disputed one. They must match on 2 main data points (IP address, device fingerprint or device ID), or 1 main plus 1 secondary (shipping address, email, customer account ID) (Stripe: Visa CE 3.0).

A monthly subscriber who suddenly disputes month 7 as "fraud" often qualifies. Stripe auto-fills what it can. Stripe can only see payments it processed, so this is one more reason to collect IP address and email on every payment.

The rules for evidence files

From Stripe: respond to disputes:

  • One file per evidence type. If you have several screenshots, combine them into one multi-page PDF.
  • 4.5 MB total. Mastercard: 19 pages total.
  • No links, videos, or "call me for more info". Banks don't click and don't follow external content.
  • Be short and specific. A one-page letter with labeled exhibits beats a 12-page story.

Let Claude draft it: skills/dispute-responder/

Drop the folder into your Claude skills. Give it the dispute (reason, network code, amount, deadline), the order, your logs, your policies and any emails. It returns:

  1. a fight-or-accept recommendation with the reason,
  2. an evidence checklist mapped to Stripe's evidence fields,
  3. a one-page rebuttal letter, and
  4. the list of files to build, in order.

It's built never to invent evidence. If your data doesn't support a win, it tells you to accept. ChatGPT or Gemini users: paste skills/dispute-responder/PROMPT.md.

The 48-hour plan (summary)read

Full hour-by-hour version: playbooks/frozen-48h.md. The short version:

WhenDo this
Hour 0–1Find out which of the 4 levels you're at (reserve, info request, risk restriction, closure). Screenshot the banner and the email. Don't open a new account or reroute payments in a hurry.
Hour 1–6Answer exactly what was asked, with documents. Build the evidence pack: business docs, product description, policies, delivery logs, dispute history, and an explanation of any volume spike.
Hour 6–12If checkout is affected, switch to your backup checkout and tell customers (template included). Keep fulfilling every existing order.
Hour 12–24Send one clear, complete written explanation through the Dashboard. One message, not ten.
Hour 24–48Follow up once. Refund anything clearly problematic. Lower risk: pause ads, delay the next launch. Plan for the 120-day tail.

The most useful thing you can do about a freeze is to set up the backup before you need it. That's the next chapter.

Going furtherread
  1. Ask Stripe about pre-dispute tools. Visa excludes disputes resolved through pre-dispute products from the VAMP count (Stripe: monitoring programs). Stripe also lists third-party alert services (Ethoca, Verifi) that warn you before a chargeback so you can refund first.
  2. Use separate authorization and capture for risky orders. Cardholders can't dispute an uncaptured authorization, and you can capture up to 7 days later (Stripe: best practices).
  3. Track monitoring-program rates the way the networks do. For US accounts, Stripe suggests counting payments in a calendar month and disputes from the 5th of that month to the 5th of the next (Stripe: monitoring programs). The calculator has a field for this.
  4. Watch your VAMP dashboard. Stripe has a VAMP page under Radar with daily estimates and Visa's monthly data, per descriptor (Stripe: monitoring programs).
  5. One descriptor prefix. Visa identifies accounts by the static part of your descriptor. Several descriptors mean several "accounts" to Visa. Use one static prefix (Stripe: monitoring programs).
  6. Download Stripe's remediation template if you're ever placed in a program. It's linked from the monitoring programs page.
Limits (read this)read
  • This won't stop a review. Reviews happen to clean businesses too, often at volume milestones. This kit lowers the odds of a bad outcome and shortens the time it takes to fix. It doesn't remove the risk.
  • Nobody can guarantee you won't be banned. Be wary of anyone selling that. Processors decide on their own risk models, and they don't publish all of them.
  • Thresholds and fees change. Visa lowered its US/EU threshold from 2.2% to 1.5% on April 1, 2026. Check the linked sources before relying on a number.
  • Templates are starting points, not legal documents. Your refund policy and terms should fit your business and your local consumer laws (for example EU withdrawal rights for digital content, or US state auto-renewal laws). Have a professional review them if you sell at scale.
  • The calculator estimates. Your official rate is whatever Visa, Mastercard, and Stripe calculate, using their timing rules and data, which may differ from yours.
  • This kit is about Stripe, because that's what most of you use. The ideas transfer to other processors; the field names and links don't.

Read the whole guide as one page →

Want this done for you, automatically?

I'm building Chargeback Defender: it watches your Stripe disputes, pulls the order, login and usage data, and drafts the evidence pack for you to approve. Reply YES to my Instagram DM and you're first in line.

Reply YES on Instagram
Copied ✓