The Stripe Survival Kit
Why processors freeze payouts, the 40+ checks that take away their reasons, and the 48-hour plan if it happens to you
For SaaS founders, AI-tool builders, and anyone selling courses, templates, or digital products online.
Not legal or financial advice. This is information and templates, put together from Stripe's public docs and Visa and Mastercard sources. Your processor's agreement and your local laws come first. Nobody can promise your account won't be reviewed, put on a reserve, or closed. That includes me, any consultant, and any tool. What you can do is take away the most common reasons, and be ready if it happens anyway.
Last verified: October 2026. Thresholds and fees change. Every number below links to its source. Check the source before you make a decision that costs money.
What's in this kit
| File | What it does | Time to first result |
|---|---|---|
tools/dispute-rate-calculator.html | Enter 3 numbers and see your dispute rate against the card-network thresholds, your risk zone, and what to do next. Works offline. | 60 seconds |
checklists/prevention.md | 52 checks across your website, checkout, billing, Radar, delivery proof, and monitoring. | 20 minutes for a first pass |
templates/dispute-responses/ | 6 evidence templates, one per dispute category, built for digital products and SaaS. | 15 minutes per dispute |
templates/customer-messages.md | 9 emails that prevent disputes: receipt, trial reminder, renewal reminder, cancellation, refund, and the "we're moving checkout" notice. | Copy and paste |
skills/dispute-responder/ | A Claude skill that drafts your dispute response from the dispute, order, and usage data. Plus a paste-in prompt for ChatGPT or Gemini. | 5 minutes |
playbooks/frozen-48h.md | Hour-by-hour plan for a payout freeze or account review: what to send, which documents, what to tell customers, how to keep selling. | Read it now, use it later |
Start here: your 5-minute win
Most founders find out their dispute rate from an email they didn't want. Find it out yourself, now.
Step 1 (60 seconds). Open tools/dispute-rate-calculator.html in your browser. It loads with sample data. Replace it with last month's numbers from your Stripe Dashboard:
- Successful card payments last month. Dashboard → Payments → filter by date and status "Succeeded".
- Disputes received last month. Dashboard → Disputes. Count all of them, won or lost. The card networks count every dispute, no matter the outcome (Stripe: monitoring programs).
- Early fraud warnings (optional). Dashboard → Radar. Visa counts these too.
Step 2 (60 seconds). Read your zone. The calculator shows where you sit against the lines that matter:
- 0.75%: Stripe says the industry treats dispute activity above this as excessive (Stripe: measuring disputes).
- 1%: one of Mastercard's conditions for the MATCH list (Stripe: high-risk merchant lists).
- 1.5%: Visa's and Mastercard's main "excessive" programs, if you also hit their count minimums.
Step 3 (3 minutes). Do the three checks that prevent the most disputes for digital sellers. Each one takes about a minute:
- Your statement descriptor. Dashboard → Settings → Business details → Public details. Would a customer recognize it on their bank statement 6 weeks from now? "DANSHIPPED.COM" beats "DS LLC". If they don't recognize the charge, it often becomes a "fraud" dispute (Stripe: dispute categories).
- Your refund policy is reachable in one click from the checkout page, and it states the terms in plain words.
- Your support email is on the receipt. Stripe's own advice: send receipts so customers can reply to you instead of calling their bank (Stripe: best practices).
That's it. You now know your number, your distance from the red lines, and you've closed the three most common leaks. Everything below is depth.
Why I wrote this
Good businesses get frozen by their payment provider all the time. Rarely for fraud. Most freezes come from boring, fixable things. A descriptor nobody recognizes. A refund policy hidden in the footer. A launch that 10x'd volume overnight with no warning. This kit is the boring stuff, done properly, in one place.
Chapter 1. Why it happens: the real triggers
A processor isn't trying to punish you. It's protecting itself. When a customer disputes a charge, the money comes out of the processor's side first. If you can't cover it, the processor eats the loss. So risk teams watch for signs that losses are coming.
Stripe says it uses "a combination of machine learning models, heuristics and human reviews" to detect risk (Stripe Unacceptable Risk Policy, updated July 29, 2026). It doesn't publish the exact rules. But its docs name the patterns plainly. Here they are, with sources.
Trigger 1: A sudden, unexplained volume spike
Stripe lists "an unexplainable sharp increase in processing volume" as a reason it places a reserve (Stripe Support: reserves). It also says that "a sudden spike or steep upward trend" can put you in a monitoring program before you reach 0.75% (Stripe: measuring disputes).
Why it scares them: a launch that does $40,000 in 3 days on an account that did $2,000 a month looks like a business that will be gone before its refunds arrive. Card networks let cardholders dispute for up to 120 days, sometimes longer (Stripe: how disputes work). Your processor carries that tail.
What takes the reason away: tell them before it happens (see the checklist), keep your fulfillment proof clean, and keep cash in the account during the 120-day tail.
Trigger 2: High dispute (chargeback) activity
This is the big one. Stripe lists "elevated dispute activity" as a reserve reason (Stripe Support: reserves). Above certain levels, Visa and Mastercard put the account into monitoring programs with fines, and Stripe has to act (Stripe: monitoring programs).
Three facts most founders miss:
- Winning doesn't help your rate. "All disputes, whether they're won or lost, count towards your dispute rate" (Stripe: measuring disputes).
- Refunds don't count as disputes, but a refund doesn't erase a dispute that already happened. The networks "don't consider refunds when identifying disputes" (Stripe: monitoring programs). Refunding before the customer goes to their bank is what keeps your rate low.
- Early fraud warnings count on Visa. Visa's main program (VAMP) adds fraud reports (TC40) to disputes (TC15). The same transaction can be counted twice (Stripe: monitoring programs; Visa VAMP fact sheet).
Trigger 3: A descriptor or website that doesn't match
When the name on the bank statement doesn't match what the customer bought, they think it's fraud. Stripe's advice for both "fraudulent" and "unrecognized" disputes starts with the same line: make your statement descriptor "easily recognizable" and reflect "the URL or business name they would associate with their purchase" (Stripe: dispute categories).
Mismatch also shows up on the risk side. If your Stripe profile says "productivity software" and your site sells a trading course, that gap is exactly what a reviewer looks for. Stripe also says to keep one Stripe account per business: "Each Stripe account should represent a single business" (Stripe: best practices).
Trigger 4: Restricted or prohibited business categories
Stripe keeps a public list of businesses it can't support, or can support only with extra approval (Stripe: Restricted Businesses, updated September 22, 2026). The ones that most often catch digital sellers:
- "Get rich quick" schemes: investment opportunities or other services that promise high returns to deceive consumers. Many "make $10k/month" courses sit close to this line.
- Multi-level marketing: commission or recruitment-based selling.
- Deceptive practices: excessive claims, misleading testimonials, high-pressure sales tactics.
- Adult content, including AI-generated adult content.
- Some platform models: platforms that host third-party creators who get paid need extra approval.
Plain SaaS isn't restricted. What gets founders in trouble is the marketing around the product. If your landing page promises income, read that list line by line.
Trigger 5: Missing or hidden policies
Stripe's website checklist asks for a description of what you sell, the currency, customer service contacts ("something besides contact forms"), refund, cancellation and delivery policies, a privacy policy, promotion terms, and a secure checkout (Stripe: website checklist). If a reviewer can't find them, Stripe says it may ask you to add them.
Policies also matter in disputes. Stripe warns that a checkbox containing only a link to your policy may be rejected by the bank as evidence. There must be "reasonable evidence that you presented your customer with a full copy of your policies prior to their purchase" (Stripe: best practices).
Trigger 6: Fraud patterns and card testing
Fraudsters test stolen cards on small checkouts. Digital products with instant delivery and $5 price points are a favorite target. Visa runs a separate "enumeration" monitor for card testing (300,000 attempts and a 20% ratio) (Stripe: monitoring programs). Even far below that level, a wave of declined test charges, followed by fraud warnings and disputes, shows up in your risk profile.
Trigger 7 (new): Being young and growing fast in Asia Pacific
From October 2026, Visa's Merchant Elevated Risk Program (MERP) applies to businesses accepting Visa in Asia Pacific. It looks at new accounts before they have big volume. Visa looks at fraud, disputes and declines together and doesn't publish thresholds. Possible results include backdated fraud disputes, account closure, and a listing other processors can see (Stripe: monitoring programs).
What actually happens: the 4 levels
| What you see | What it means | Can you still sell? | Source |
|---|---|---|---|
| Reserve (fixed or rolling) | A % of your funds is held for a set time to cover future refunds and disputes. | Yes. "Reserves do not impact a business's ability to continue accepting payments." | Stripe Support: reserves |
| Payouts paused, info requested | Stripe needs documents or verification before paying out. | Usually yes, while you respond. | Your Dashboard banner |
| Charges or payouts restricted for risk | Stripe may pause charges, pause payouts, or reverse payments. | Maybe not. | Unacceptable Risk Policy |
| Account closed | Payouts are typically held for 120 days from the notice email. You can appeal from the Dashboard. | No. | Unacceptable Risk Policy |
The worst case sits past all four: a listing on Mastercard's MATCH or Visa's VMSS list. Those listings last 5 years, and most processors automatically reject listed businesses and owners (Stripe: high-risk merchant lists). Everything in this kit exists so you never get near that.
Chapter 2. The numbers that matter
Write these on a sticky note. They are the lines the card networks use. They are not Stripe's private rules, which nobody outside Stripe knows.
How the rate is counted (this changes the math)
- Stripe "dispute activity": disputes received in a period ÷ successful payments in that period. This is the version the networks use for their programs (Stripe: measuring disputes).
- Visa: disputes + fraud reports in a month ÷ transactions in the same month. Count-based (Visa VAMP fact sheet).
- Mastercard: chargebacks this month ÷ transactions last month (Stripe: monitoring programs). After a big launch month followed by a quiet month, your Mastercard rate can jump even if nothing went wrong.
The thresholds (verified October 2026)
| Line | What happens there | Extra condition | Source |
|---|---|---|---|
| 0.5% | Visa VAMP "non-compliant" level, as listed by Stripe. Visa may assess fees. | VAMP count of 5 | Stripe |
| 0.75% | "The credit card processing industry standard recognizes dispute activity above 0.75% as excessive." | A spike can trigger action earlier | Stripe |
| 1% | Mastercard MATCH code 4 (Excessive Chargebacks), applied if an account is terminated | Chargebacks ≥ $5,000 in the same month | Stripe |
| 1.5% | Visa VAMP Excessive Merchant (AP, Canada, EU, US; lowered from 2.2% on April 1, 2026; LAC was already 1.5%) | 1,500+ fraud + disputes in the month | Visa, Stripe |
| 1.5% | Mastercard Excessive Chargeback Merchant (ECM). Fines start in month 2 ($1,000) and rise to $100,000 by month 19. | 100+ chargebacks | Stripe |
| 1.8% | Visa VMSS code 22 (Excessive Disputes), applied if an account is terminated and you didn't remediate | 1,000 disputes; ratio by amount | Stripe |
| 2.2% | Visa VAMP Excessive Merchant, CEMEA region | 150+ count and $75,000+ | Visa |
| 3% | Mastercard High Excessive (HECM). Fines up to $200,000. | 300+ chargebacks | Stripe |
The small-seller trap. The big programs need 100 or 1,500 disputes a month, so a small SaaS will almost never be fined. Don't relax. The 0.75% line and the MATCH 1% line have no big count minimum. And at low volume, 2 disputes on 150 payments is already 1.3%. Stripe itself says that if you have "fewer than 100 payments per month", one or two fraud disputes can have "a very outsized impact" on your rate (Stripe: best practices).
My working rule (an opinion, not a rule from Stripe): treat 0.5% as yellow, 0.75% as red, and 1% as an emergency. The calculator uses these zones.
What a dispute costs you
In the US, Stripe charges a $15 "dispute received" fee, plus a $15 "dispute countered" fee if you submit evidence. You get the countered fee back if you win. You never get the received fee back (Stripe Support: dispute pricing). Fees differ by country, so check your own pricing page. Add the product you already delivered and the hours you spend. A US $29 sale that you fight and lose costs you $59 ($29 + $15 + $15) plus your time. Even if you win, you're out the $15 received fee, and the dispute still counts toward your rate.
Chapter 3. Prevention: take away every reason
Full list: checklists/prevention.md (52 checks). Here's the logic behind it, in 6 layers.
- Be recognizable. Descriptor, receipt, and website all use the same name. The customer should never have to wonder "what is this charge?"
- Be findable. Support email (not just a form), refund policy, terms, privacy policy, business address. All one click from checkout.
- Be clear before the money moves. Price, currency, billing frequency, trial end date, renewal terms, all shown before the card form. A checkbox for the terms with the full text, not only a link.
- Make leaving easy. One-click cancellation in the app. Renewal reminders before annual charges. Refund fast when someone asks. Every refund you give is a dispute you don't get.
- Log delivery. For digital products there's no tracking number. Your proof is logs: account created, first login, downloads, API calls, with IP addresses and timestamps. Stripe asks for exactly this as
access_activity_log(Stripe: dispute categories). Start logging today. You can't create these logs after a dispute arrives. - Watch the dial. Check your dispute rate weekly. Tell Stripe before a launch. Refund obvious fraud before it becomes a dispute.
Radar rules worth testing
Custom rules need a Radar plan that supports them. Test each rule against your past payments before you turn it on, and start with Review before Block. Stripe's rule tester runs on your last 6 months of payments, and you can roll a rule out to a small share of traffic first (Stripe: Radar rules). These examples follow Stripe's documented syntax:
Request 3D Secure if :risk_level: != 'normal' and :amount_in_usd: > 25
Request 3D Secure if is_missing(:seconds_since_card_first_seen:)
Review if :is_disposable_email: and :card_funding: = 'prepaid'
Block if :card_country: != 'US' and :risk_level: = 'elevated'
Block if :is_3d_secure: and not :is_3d_secure_authenticated:
Why 3D Secure matters: if a payment is authenticated with 3DS, liability for most fraud disputes "typically shifts from the seller to the issuer" (Stripe: Radar rules). Two catches. Too much 3DS can lower conversion. And you still receive early fraud warnings, which count in Visa's program (Stripe: best practices).
Stripe also warns EU businesses that the Geo-blocking Regulation limits blocking customers by EU country (Stripe: Radar rules). Check your local rules before you write any country rule.
When to refund an early fraud warning
Stripe's own data: about 40% of Visa and Mastercard early fraud warnings become fraud disputes if you don't refund. Its suggestion is to refund flagged charges roughly at or below your dispute fee, and not to bother above about 135% of it (Stripe: how disputes work). The exception: if your rate is already high, or you have under 100 payments a month, refund more aggressively (Stripe: best practices).
For a SaaS with access you can revoke, refund and revoke. For a $9 template that's already been downloaded, the refund costs less than the dispute.
Chapter 4. When a dispute arrives: fight smart, not always
You get one shot. Stripe sends your response to the bank immediately, and "you can't edit the response or submit more files" (Stripe: respond to disputes). You usually have 7 to 21 days depending on the network, and missing the deadline loses the dispute automatically. The bank then takes 60 to 75 days to decide (Stripe: how disputes work).
Should you fight it?
Fight when you can prove the customer's claim is wrong. Accept (or refund at the inquiry stage) when they're right. Use this quick test:
| Question | If yes |
|---|---|
| Did they actually not get access, get charged twice, or ask for a refund your policy promised? | Accept. Fix the cause. |
| Do you have logs showing they used the product after paying? | Fight. |
| Is it a Visa fraud dispute (code 10.4) from a returning customer? | Fight. Check Visa Compelling Evidence 3.0 eligibility (below). |
| Was the payment 3DS-authenticated? | Fight. Stripe adds the 3DS proof automatically. |
| Is the amount smaller than your fees plus an hour of your time? | Probably accept, unless you need the win to discourage a repeat abuser. |
The 6 templates
Each file in templates/dispute-responses/ gives you: what the bank needs to see, the evidence to attach for SaaS and digital products (mapped to Stripe's evidence fields), a fill-in rebuttal letter, and the mistakes that lose cases.
| Stripe category | Typical Visa / Mastercard codes | Template |
|---|---|---|
| Fraudulent (and Unrecognized) | Visa 10.4 · Mastercard 4837, 4863 | 01-fraudulent.md |
| Product not received | Visa 13.1 · Mastercard 4855 | 02-product-not-received.md |
| Product unacceptable (not as described) | Visa 13.3, 13.5 · Mastercard 4853 | 03-not-as-described.md |
| Subscription canceled | Visa 13.2 · Mastercard 4841 | 04-subscription-canceled.md |
| Duplicate | Visa 12.6.1, 12.6.2 · Mastercard 4834 | 05-duplicate.md |
| Credit not processed | Visa 13.6, 13.7 · Mastercard 4860 | 06-credit-not-processed.md |
Codes from Stripe: dispute categories. Mastercard maps some codes to more than one category, so always read the category Stripe shows on the dispute.
Visa Compelling Evidence 3.0: the one most SaaS founders miss
For Visa fraud disputes with code 10.4, you can point to the customer's own history. You need at least 2 earlier, undisputed payments on the same card, made 120 to 364 days before the disputed one. They must match on 2 main data points (IP address, device fingerprint or device ID), or 1 main plus 1 secondary (shipping address, email, customer account ID) (Stripe: Visa CE 3.0).
A monthly subscriber who suddenly disputes month 7 as "fraud" often qualifies. Stripe auto-fills what it can. Stripe can only see payments it processed, so this is one more reason to collect IP address and email on every payment.
The rules for evidence files
From Stripe: respond to disputes:
- One file per evidence type. If you have several screenshots, combine them into one multi-page PDF.
- 4.5 MB total. Mastercard: 19 pages total.
- No links, videos, or "call me for more info". Banks don't click and don't follow external content.
- Be short and specific. A one-page letter with labeled exhibits beats a 12-page story.
Let Claude draft it: skills/dispute-responder/
Drop the folder into your Claude skills. Give it the dispute (reason, network code, amount, deadline), the order, your logs, your policies and any emails. It returns:
- a fight-or-accept recommendation with the reason,
- an evidence checklist mapped to Stripe's evidence fields,
- a one-page rebuttal letter, and
- the list of files to build, in order.
It's built never to invent evidence. If your data doesn't support a win, it tells you to accept. ChatGPT or Gemini users: paste skills/dispute-responder/PROMPT.md.
Chapter 5. The 48-hour plan (summary)
Full hour-by-hour version: playbooks/frozen-48h.md. The short version:
| When | Do this |
|---|---|
| Hour 0–1 | Find out which of the 4 levels you're at (reserve, info request, risk restriction, closure). Screenshot the banner and the email. Don't open a new account or reroute payments in a hurry. |
| Hour 1–6 | Answer exactly what was asked, with documents. Build the evidence pack: business docs, product description, policies, delivery logs, dispute history, and an explanation of any volume spike. |
| Hour 6–12 | If checkout is affected, switch to your backup checkout and tell customers (template included). Keep fulfilling every existing order. |
| Hour 12–24 | Send one clear, complete written explanation through the Dashboard. One message, not ten. |
| Hour 24–48 | Follow up once. Refund anything clearly problematic. Lower risk: pause ads, delay the next launch. Plan for the 120-day tail. |
The most useful thing you can do about a freeze is to set up the backup before you need it. That's the next chapter.
Chapter 6. Backup payments: a neutral comparison
A backup isn't disloyalty to Stripe. It's insurance. If your only checkout runs through one account, one review stops your revenue. Here are the 3 kinds of backup and when each makes sense.
Option A: Merchant of record (MoR)
A merchant of record is the legal seller to your customer. The MoR handles sales tax and VAT, takes the payment, deals with disputes and fraud, and pays you out. You give up a higher fee and some control. You get tax compliance and a second payment rail.
Fees verified on official pages, October 2026. Base rates only. Most add fees for international cards, subscriptions, payouts, or currency conversion, so read the full page.
| Provider | Headline fee | Built for | Watch out for | Source |
|---|---|---|---|---|
| Paddle | 5% + 50¢ per checkout transaction | Software: B2B SaaS, consumer apps, games | Doesn't support pure human services (e.g. consulting), physical goods, or several other categories. Check its acceptable use policy. | Pricing, AUP |
| Lemon Squeezy | 5% + 50¢; +1.5% international, +1.5% PayPal, +0.5% subscriptions | Digital products, SaaS, creators | Owned by Stripe. Its January 2026 update says it's moving toward Stripe Managed Payments and admits slower support. Check where it stands before you build on it. | Pricing, Fees, 2026 update |
| Stripe Managed Payments | 3.5% per transaction, on top of standard Stripe processing fees | Digital products: software, SaaS, AI tools, courses, e-books | Fully automated digital products only. No consulting or live 1:1 coaching. Needs an eligibility review. Same company as Stripe, so it's not an independent backup. | Pricing, Eligibility |
| Polar | From 5% + 50¢ (Starter) down to 3.4% + 30¢ (Scale); +1.5% international cards; $15 per dispute; payout fees separate | Developers, SaaS, digital products | Plan-based pricing. Payout fees apply. | Pricing |
| Creem | 3.9% + 40¢ | SaaS and AI products | Smaller tax coverage than older players. Confirm your customers' countries are covered. | Pricing |
| Dodo Payments | 4% + 40¢ US domestic; +1.5% international; +0.5% subscriptions; $30 per dispute | SaaS, digital products, global sellers | Fees stack on international subscriptions. | Pricing |
| Whop | 2.7% + 30¢ domestic cards; +1.5% international; optional add-ons (e.g. +2% tax and remittance, +0.5% billing); $15 per dispute | Digital products, communities, courses, software | You choose whether Whop acts as MoR during setup. All-in cost with add-ons can reach about 6% + 30¢. | Fees, MoR |
When an MoR makes sense: you sell to many countries and don't want to handle VAT. Your product is clearly digital and automated. You want a second rail that's legally and operationally separate from your Stripe account.
When it doesn't: your margins are thin, you sell services with humans in the loop (many MoRs exclude these), or you need full control of the checkout and customer data.
Honest note: an MoR also has a risk team. A business that gets frozen on Stripe for high disputes will likely have the same problem on an MoR. A backup protects you from a false positive or a slow review. It doesn't fix a dispute problem.
Option B: A second processor (same model as Stripe)
You stay the merchant. You open an account with another processor (for example PayPal, Adyen, Braintree, or a local acquirer) and keep it active with a small share of traffic.
- Makes sense when: you have steady volume, clean history, and want the lowest fees. You already handle your own tax.
- Doesn't when: you're new, high-risk, or recently closed. Processors screen applicants against the MATCH and VMSS lists (Stripe: high-risk merchant lists).
- Card data: if you ever leave Stripe, it can export saved card data to another PCI DSS Level 1 processor. It won't export payment history or subscriptions as objects, and cards saved through Link can't be moved (Stripe: payment data export). Your customers may not have to re-enter cards, but you'll rebuild subscriptions on the new side.
Option C: A branded checkout layer on top of a payments account
A checkout layer is not a processor. It gives you the checkout page (your domain, your design, your upsells), and the payment runs through a payments account in your own name. The value is that the checkout is separate from the rail. If the rail changes, your customers' experience doesn't.
Disclosure: I built one. Onyx Checkout gives you a branded checkout on your own domain. Payments go through your own Whop company, with Whop as merchant of record. Onyx takes 0% revenue share. You pay a flat monthly plan, and Whop's own processing fees still apply. Today Onyx is built for Shopify stores, not SaaS. I'm including it because the setup it uses (your checkout, your own isolated merchant account, a separate rail) is the same principle this chapter recommends. A SaaS version is something I'm testing interest for (see the end of this guide). Compare it like any other option, and pick what fits.
Which backup when: a quick decision table
| Your situation | Start with |
|---|---|
| Solo SaaS, global customers, under ~$20k/month, hate tax admin | An MoR as the second rail |
| Established SaaS, mostly one country, clean history | A second processor at 5–10% of traffic |
| Info products or courses with income claims in the marketing | Fix the marketing first. Any backup will review the same pages. |
| Already frozen and need revenue this week | The 48h playbook, then an MoR with a careful, honest application |
| You want to own the checkout and swap rails freely | A checkout layer on top of an account in your own name |
The one rule for every option: keep each business on its own account. Never put another person's sales under your account, and never put yours under theirs. That's how one bad actor takes down everyone.
Going further
- Ask Stripe about pre-dispute tools. Visa excludes disputes resolved through pre-dispute products from the VAMP count (Stripe: monitoring programs). Stripe also lists third-party alert services (Ethoca, Verifi) that warn you before a chargeback so you can refund first.
- Use separate authorization and capture for risky orders. Cardholders can't dispute an uncaptured authorization, and you can capture up to 7 days later (Stripe: best practices).
- Track monitoring-program rates the way the networks do. For US accounts, Stripe suggests counting payments in a calendar month and disputes from the 5th of that month to the 5th of the next (Stripe: monitoring programs). The calculator has a field for this.
- Watch your VAMP dashboard. Stripe has a VAMP page under Radar with daily estimates and Visa's monthly data, per descriptor (Stripe: monitoring programs).
- One descriptor prefix. Visa identifies accounts by the static part of your descriptor. Several descriptors mean several "accounts" to Visa. Use one static prefix (Stripe: monitoring programs).
- Download Stripe's remediation template if you're ever placed in a program. It's linked from the monitoring programs page.
Limits (read this)
- This won't stop a review. Reviews happen to clean businesses too, often at volume milestones. This kit lowers the odds of a bad outcome and shortens the time it takes to fix. It doesn't remove the risk.
- Nobody can guarantee you won't be banned. Be wary of anyone selling that. Processors decide on their own risk models, and they don't publish all of them.
- Thresholds and fees change. Visa lowered its US/EU threshold from 2.2% to 1.5% on April 1, 2026. Check the linked sources before relying on a number.
- Templates are starting points, not legal documents. Your refund policy and terms should fit your business and your local consumer laws (for example EU withdrawal rights for digital content, or US state auto-renewal laws). Have a professional review them if you sell at scale.
- The calculator estimates. Your official rate is whatever Visa, Mastercard, and Stripe calculate, using their timing rules and data, which may differ from yours.
- This kit is about Stripe, because that's what most of you use. The ideas transfer to other processors; the field names and links don't.
Sources (all checked October 2026)
Stripe: Measuring disputes · Monitoring programs · Dispute categories · How disputes work · Respond to disputes · Visa CE 3.0 · Best practices · Radar rules · Statement descriptors · Website checklist · High-risk merchant lists (MATCH/VMSS) · Reserves FAQ · Why Stripe reserves funds · Unacceptable Risk Policy · Restricted Businesses · Dispute pricing (US) · Managed Payments · Managed Payments pricing · Payment data export
Card networks: Visa VAMP fact sheet · Visa trial subscription rules · Mastercard trial requirements (via Braintree)
Merchant of record providers: Paddle · Lemon Squeezy fees · Polar · Creem · Dodo Payments · Whop fees
Want this done automatically?
Everything here works by hand. It also takes time you don't have when a dispute lands at 11pm with a 7-day clock.
I'm building Chargeback Defender: it connects to your Stripe account, reads each new dispute, pulls the order, login and usage data, and drafts the full evidence pack for you to approve. Flat $39/month, not a percentage of what you win back.
And if you sell SaaS and want a branded checkout on your own domain with a backup rail behind it, tell me. That's the SaaS version of Onyx.
Reply YES to the DM (or join the waitlist) and tell me two things: which one you want, and whether a processor has ever frozen you. Your answers decide what I build next.
Follow @danshipped for the next drop.
Made by Dan Shipped — AI & SaaS, shipped. Not legal or financial advice.
Want this done for you, automatically?
I'm building the automatic version. Reply YES to my DM on Instagram and you're first in line.
Open Instagram