# Prevention checklist: 52 checks

**How to use it:** do a first pass in 20 minutes. Tick what's done. Put a date next to what isn't. Repeat once a quarter, and before every launch.

Items marked **[S]** come straight from Stripe's docs (source linked at the end of each section). Items marked **[N]** come from card-network rules. Unmarked items are my own practice: common sense for digital sellers, not an official rule.

> Not legal or financial advice. Policies and subscription terms must also follow your local consumer laws. Check them. Last verified: October 2026.

---

## A. Be recognizable (6)

- [ ] **1. Statement descriptor = the name people know.** Your domain or brand, not your legal entity. "DANSHIPPED.COM" beats "DS HOLDINGS LLC". **[S]**
- [ ] **2. Descriptor meets the format rules.** 5–22 Latin characters, at least one letter, none of `< > \ ' " *`, reflects your business (DBA) name. A bare common word doesn't count. **[S]**
- [ ] **3. Short prefix (2–10 characters) set**, if you sell more than one product. Add a dynamic suffix per product (e.g. `SHIPPED* PROMPT KIT`). The full string must still fit 22 characters, including the `*` and the space. **[S]**
- [ ] **4. One static prefix across all descriptors.** Visa identifies your account by the static part of the descriptor. Different prefixes look like separate accounts to Visa. **[S]**
- [ ] **5. One Stripe account per business.** Never run a second brand, a client, or a friend's sales through your account. **[S]**
- [ ] **6. Receipt name, website name, and descriptor match.** A customer who searches the descriptor should land on your site.

Sources: [Statement descriptors](https://docs.stripe.com/get-started/account/statement-descriptors) · [Best practices](https://docs.stripe.com/disputes/prevention/best-practices) · [Monitoring programs](https://docs.stripe.com/disputes/monitoring-programs)

## B. Be findable: website and policies (11)

- [ ] **7. Clear description of what you sell.** What it is, what the customer gets, how they get it. For SaaS: features and limits per plan. **[S]**
- [ ] **8. Prices show the currency explicitly** ("$29 USD", not only "$29"). **[S]**
- [ ] **9. Support contact besides a form.** A real email address at minimum. Stripe asks for "something besides contact forms". **[S]**
- [ ] **10. Refund policy page**: who qualifies, how long, how to ask, how long a refund takes. **[S]**
- [ ] **11. Cancellation policy page** for subscriptions: how to cancel, when it takes effect, what happens to access. **[S]**
- [ ] **12. Delivery policy for digital goods**: "Access is sent by email within 5 minutes. If you don't get it, reply to the receipt." **[S]**
- [ ] **13. Terms of service** that include the refund and cancellation terms (not only a separate page). **[S]**
- [ ] **14. Privacy policy.** **[S]**
- [ ] **15. Business address on the site**, if you have a physical one. **[S]**
- [ ] **16. Promotion and trial terms** shown at the moment someone signs up for the offer. **[S]**
- [ ] **17. No income claims you can't back up.** "Make $10k/month" language is what pushes courses toward Stripe's "get rich quick" category. Same for fake urgency and testimonials you can't verify. **[S]**

Sources: [Website checklist](https://docs.stripe.com/get-started/checklist/website) · [Restricted businesses](https://stripe.com/legal/restricted-businesses)

## C. Be clear before the money moves: checkout (8)

- [ ] **18. Full price shown before the card field**, taxes included where applicable. **[S]**
- [ ] **19. Billing frequency next to the price**: "$19 billed monthly until you cancel."
- [ ] **20. Trial end date in writing at checkout**: "Your trial ends on [DATE]. You'll be charged $X unless you cancel."
- [ ] **21. Express consent to recurring billing.** A checkbox or button the customer actively clicks to agree to the subscription terms. **[S]** **[N]**
- [ ] **22. Full policy text visible at checkout** (inline or in a pop-up), not only a link. Stripe warns that a checkbox with only a link may be rejected as evidence. **[S]**
- [ ] **23. Store proof of acceptance**: timestamp, IP address, version of the terms they accepted.
- [ ] **24. Collect name, email, and billing postal code** on every payment. They help the issuer verify the card and help you win disputes later. **[S]**
- [ ] **25. Pass customer IP and email into Stripe** with each payment. Visa Compelling Evidence 3.0 depends on them. **[S]**

Sources: [Best practices](https://docs.stripe.com/disputes/prevention/best-practices) · [Monitoring programs](https://docs.stripe.com/disputes/monitoring-programs) · [Visa CE 3.0](https://docs.stripe.com/disputes/api/visa-ce3)

## D. Authentication, 3DS and Radar (7)

- [ ] **26. Default Radar rules on.** Don't disable the high-risk block. **[S]**
- [ ] **27. 3DS requested for elevated risk**, e.g. `Request 3D Secure if :risk_level: != 'normal' and :amount_in_usd: > 25`. **[S]**
- [ ] **28. 3DS for cards never seen before** (optional, adds friction): `Request 3D Secure if is_missing(:seconds_since_card_first_seen:)`. **[S]**
- [ ] **29. Block failed 3DS attempts**: `Block if :is_3d_secure: and not :is_3d_secure_authenticated:`. **[S]**
- [ ] **30. One narrow review rule** for your known bad pattern, e.g. `Review if :is_disposable_email: and :card_funding: = 'prepaid'`. **[S]**
- [ ] **31. Every new rule tested first.** Use the rule tester (last 6 months of payments), start with Review instead of Block, and roll out at a small traffic percentage. **[S]**
- [ ] **32. Card-testing defenses on cheap products.** Stripe's website checklist asks you to make sure your payment form isn't vulnerable to card testing **[S]**. Low-priced, instant-delivery checkouts are the usual target. My practice: rate-limit checkout attempts per IP, add a CAPTCHA on public payment forms, and watch for bursts of declines. Stripe has a dedicated card-testing guide linked from the checklist.

Notes: custom rules need a Radar plan that supports them. EU businesses: the Geo-blocking Regulation limits country-based blocking inside the EU.
Sources: [Radar rules](https://docs.stripe.com/radar/rules) · [Website checklist (card testing)](https://docs.stripe.com/get-started/checklist/website)

## E. Delivery proof: logs you'll need later (6)

You can't create these after a dispute arrives. Start now.

- [ ] **33. Log account creation** with timestamp, IP address, and user agent.
- [ ] **34. Log every login** (timestamp, IP, device or user agent). Stripe's evidence field `access_activity_log` asks for exactly this. **[S]**
- [ ] **35. Log feature usage that proves value**: files generated, API calls, credits used, lessons opened, downloads.
- [ ] **36. Log access delivery**: the email with the access link (time sent, delivered, opened if you track it) and the first download.
- [ ] **37. Keep logs at least 18 months.** Disputes usually come within 120 days, but card rules sometimes allow more, and Visa CE 3.0 looks back up to 364 days. **[S]**
- [ ] **38. One-click export per customer.** When a dispute comes in, you want one CSV of that customer's activity, not a database query at midnight.

Sources: [Dispute categories](https://docs.stripe.com/disputes/categories) · [How disputes work](https://docs.stripe.com/disputes/how-disputes-work) · [Visa CE 3.0](https://docs.stripe.com/disputes/api/visa-ce3)

## F. Onboarding and communication (5)

- [ ] **39. Receipt sent on every payment**, with your support email and a reply-to that reaches a human. **[S]**
- [ ] **40. Welcome email within minutes** that says what they bought, how to access it, and how to get help. Templates in `templates/customer-messages.md`.
- [ ] **41. A "getting started" email at day 2–3** for SaaS. People who use the product don't dispute it as "not received".
- [ ] **42. Support replies within 24 hours on business days.** Most "not as described" disputes start as an unanswered email.
- [ ] **43. The customer-facing name stays the same everywhere**: emails, app, receipt, descriptor.

Source: [Best practices](https://docs.stripe.com/disputes/prevention/best-practices)

## G. Subscriptions and cancellation (5)

- [ ] **44. In-app cancel button.** Stripe calls an in-app button "often the best solution". No "email us to cancel". **[S]**
- [ ] **45. Cancellation confirmation email** sent instantly, with the date access ends. **[S]**
- [ ] **46. Trial reminder before the first charge.** Visa requires a reminder at least 7 days before a free or promotional trial ends, with a simple way to cancel. Mastercard requires one 3 to 7 days before the end of trials for digital goods. **[N]**
- [ ] **47. Renewal reminders.** Stripe suggests about 7 days before a yearly renewal and 2–3 days before a monthly one. **[S]**
- [ ] **48. Fair refund on accidental renewals.** If someone cancels the day after being billed, refund in full or pro rata. Stripe suggests exactly this. **[S]**

Sources: [Monitoring programs (best practices section)](https://docs.stripe.com/disputes/monitoring-programs) · [Visa trial rules](https://usa.visa.com/content/dam/VCOM/global/support-legal/documents/visa-new-subscription-rules-flier.pdf) · [Mastercard trial requirements (via Braintree)](https://developer.paypal.com/braintree/articles/guides/recurring-billing/mastercard-requirements)

## H. Refunds and dispute handling (2)

- [ ] **49. Refund obvious fraud immediately** using "Refund as fraud" in the Dashboard, unless 3DS liability shift covers you. For early fraud warnings, Stripe's data says about 40% become disputes. Refund small ones (around your dispute fee or less) and use judgment above that. If your rate is already high, or you do under 100 payments a month, refund more aggressively. **[S]**
- [ ] **50. A written dispute routine.** Who checks disputes, how often, which template, the deadline rule (respond at least 3 days early). Answer inquiries too: an unanswered inquiry can turn into a chargeback that's very hard to win. **[S]**

Sources: [How disputes work](https://docs.stripe.com/disputes/how-disputes-work) · [Best practices](https://docs.stripe.com/disputes/prevention/best-practices)

## I. Monitoring: dispute thresholds to watch (2)

- [ ] **51. Weekly dispute-rate check**, using `tools/dispute-rate-calculator.html` or the Stripe Dashboard (Analytics shows dispute activity; Radar shows dispute rate by charge date). Know your lines:
  - **0.5%**: Visa VAMP "non-compliant" level as listed by Stripe (count of 5).
  - **0.75%**: what Stripe calls the industry line for "excessive".
  - **1%**: Mastercard MATCH code 4 condition (plus $5,000+ in chargebacks that month).
  - **1.5%**: Visa VAMP Excessive (AP, Canada, EU, US, LAC since April 1, 2026; 1,500+ count) and Mastercard ECM (100+ chargebacks).
  - **3%**: Mastercard HECM (300+ chargebacks).
  Also check the VAMP page in your Stripe Dashboard (Radar section), which shows Stripe's daily estimate. **[S]** **[N]**
- [ ] **52. Tell Stripe before a launch or a big change.** A sharp, unexplained volume increase is a listed reason for reserves. Send a short note through support: what you're launching, expected volume, how you deliver, and your refund policy. Keep enough balance in the account during the 120-day dispute tail. **[S]**

Sources: [Measuring disputes](https://docs.stripe.com/disputes/measuring) · [Monitoring programs](https://docs.stripe.com/disputes/monitoring-programs) · [High-risk merchant lists](https://docs.stripe.com/disputes/match) · [Visa VAMP fact sheet](https://corporate.visa.com/content/dam/VCOM/corporate/visa-perspectives/security-and-trust/documents/visa-acquirer-monitoring-program-fact-sheet-2025.pdf) · [Why Stripe reserves funds](https://support.stripe.com/questions/stripe-reserving-funds)

---

## Score yourself

| Ticked | What it means |
|---|---|
| 45–52 | You've removed almost every common reason. Keep the weekly check. |
| 35–44 | Solid. Fix sections E (logs) and G (subscriptions) first; they matter most in disputes. |
| 20–34 | Real exposure. Do A, B and C this week. They take an afternoon. |
| Under 20 | Do the 5-minute win in the README today, then come back. |

*Made by Dan Shipped — @danshipped. Not legal or financial advice.*
