Live data from Hacker News

Stripe banned us for payment disputes but we never had a single dispute

justuseapp.com

121–130 of 302 posts

Re: Stripe banned us for payment disputes but we never had a single dispute

#121
The automated email from Stripe is just weird. No, zero, disputes? That's uncanny.

I've run a Stripe.com integration (for a SaaS business). A few times a year somebody disputes a charge. It's usually because they looked at their payment card statement and didn't recognize us when we billed for renewal.

Our policy is

1) try to resolve the dispute in our favor. That mostly works. It's good for our reputation score on Stripe.

2) refund the customer's charge. Always.

3) contact the customer and ascertain whether they want to continue their subscription.

I don't understand zero disputes. That's just not feasible when dealing with the public.

Re: Stripe banned us for payment disputes but we never had a single dispute

#122

Earlier quoted context omitted.

So, if I want to disrupt a competitor all I have to do is hire a bunch of darknet identify thieves and you'll shut down their merchant account?

Yes, if you’re willing to break the law and risk the consequences, you can get up to all sorts of stuff. Same as anything? Like, “So, if I want to disrupt a competitor, all I have to do is hire thugs to smash all their stuff?” Yeah, that’d do it. Good luck.

I think the point is that this attack vector can be pretty anonymous and absolutely deadly to the target company.

This attack is also not protected by insurance, like someone setting fire to your office would be.

It’s fair to explore just how vulnerable a company can be to this type of attack from a malicious competitor.

Re: Stripe banned us for payment disputes but we never had a single dispute

#123

Buddy, your business is selling "privacy cards" and "virtual cards" which hide the identity of the person making the transaction. It's a massive money laundering red flag, it's not at all surprising that Stripe doesn't want to deal with you.

Privacy cards means the cards protect the user's real cards not their identity. If you have ever been hacked or cannot cancel a renegade subscription, you would quickly grasp the need for Privacy cards.

That would be more believable if you didn't specifically call out allowing foreigners to pretend to be from the US to "unlock services": aka - violate the TOS of said service and likely breaking one or more US laws.

Re: Stripe banned us for payment disputes but we never had a single dispute

#124

How are we a "high risk" merchant when our business is not different from Truebill.com (subscription tracking) and Ramp Inc (spend management) a company Stripe recently invested in? The cynical me says there is your answer right there. You are a bit to close to something Stripe invested in, or at least close enough to something they will offer as a service soon.

So much for alternative payment processors being the messiahs to deliver us from the draconian fisting of Apple.

Well at least PayPal has a spotless history of treating their users nicely.

Re: Stripe banned us for payment disputes but we never had a single dispute

#126
post #85

Earlier quoted context omitted.

I don't want to sound too cynical but I don't know of an ombudsman which has binding authority. Here in the Netherlands all ombudsman I know are non-binding. I personally know of 2 dealings with an Ombudsman in the Netherlands. One involved me personally and another one of a good friend. In both cases the ombudsman advised in our favor. In both cases the reaction on the advice was: "Thanks for the advice, ombudsman,…

Ive had an experience with an Ombudsman in the UK. I was stuck in a loop with a major broadband provider in the UK who were giving me the run around. I contacted the ombudsman and within 14 days of my first email the company resolved the issue, (after 4 months of back and forth before that). Despite being non binding, the moment they were involved my problem was resolved.

Yup. Sometimes knowing who to talk to (and access to them) is more important than legal authority to force something.

Re: Stripe banned us for payment disputes but we never had a single dispute

#128

Edwin from Stripe here. (OP, I've just sent you an email and we can talk more over there—I'm terribly sorry for the trouble.) I can't get into too many specifics about an individual business publicly, but unauthorized charges have high potential to be disputed in the near future—and while Stripe itself doesn't have a dispute threshold, the card networks require businesses to keep disputes low. Although that email in…

I understand that you probably don't have the power to directly change anything about this, but what does it even mean when a company says they're "improving how they work with businesses in situations like these".

Every time some big tech company makes promises like these, nothing really ends up changing. The emails always remain vague templates without details from a seemingly anonymous source. Companies end up changing the wording of their email templates, but that's about the only noticeable difference.

I have no doubt that a real human verified the problem and decided to send the email, but I've never seen any big company that swore their dedication to better communication actually change their policies to not make these emails look so... auto-generated. When you're ending a business relationship, even for good reason, you shouldn't come off as a robot.

Such comments on public websites always feel like damage control to me. I'm not claiming your comment is part of some specific damage control operation or anything, but I do wonder if adding that line does much for the credibility of the rest of the post. In my opinion, it adds a layer of corporate pixie dust on top of the rest of your words.

That being said, responding in public, especially in a place like HN, is a pretty brave thing to do, especially with all the other negative threads from others here, so I definitely appreciate the effort you put into this!

Re: Stripe banned us for payment disputes but we never had a single dispute

#129

Funny how this has beeing a tendency last years. Big american corps just banning small users/companies without any reason and not giving them support whatsoever. As a developer this puts a big dent on Stripe's reliability and I'm not advising it to any client. Ever.

I think big companies tend to do this by accident, more out of incompetence than malice. Yet this sort of thing just begs for future draconian government interference. Seems to me a smart company would find a way to not invite that unpleasantness on themselves.

> I think big companies tend to do this by accident, more out of incompetence than malice.

They have bots deciding the future of their users. And when the bots make some kind of mistake they don't give support for the costumer or neither check if the user got wrongly banned. It's some kind of sick blind trust they place on automated systems. Nothing wrong against these systems, but they should have a system in place to check wether these made a mistake or not.

Re: Stripe banned us for payment disputes but we never had a single dispute

#130

Edwin from Stripe here. (OP, I've just sent you an email and we can talk more over there—I'm terribly sorry for the trouble.) I can't get into too many specifics about an individual business publicly, but unauthorized charges have high potential to be disputed in the near future—and while Stripe itself doesn't have a dispute threshold, the card networks require businesses to keep disputes low. Although that email in…

So, if I want to disrupt a competitor all I have to do is hire a bunch of darknet identify thieves and you'll shut down their merchant account?

Great point. This does seem like an important vulnerability.

I think one method of protection would be using Stripes Radar service to screen transactions for malicious patterns.

While it probably won’t catch all fraudulent charges, it’ll catch a bunch. You can use that increase in rejected transactions as a canary to take a closer look at the other transactions coming through.

Does anyone else have ideas on how you can protect yourself from this kind of attack?

Edit: thinking about this more, it would be a pretty expensive attack to attempt. Stolen credit cards aren't cheap, like email addresses are. You'd need a lot of them to attempt the attack and you likely wouldn't succeed.

I think you'd need 1% of the target merchant's transactions to be chargebacks in order to get them kicked off. I'd assume at least 50% of your attempts would get caught before the chargeback even happens, so you'd need at least 2% of their transactions.

Seems like you'd need a large number of cards. Anyone know the value of a stolen card?

Post reply on HN