Direct Answer
When a chargeback notification arrives, work through four things before you write a single line of response. 1. Read the category, not the summary. The dispute condition code tells you which timetable applies. Under the Visa Core Rules the fraud and authorization categories run on a different sequence from processing-error and consumer-dispute categories — one of them has no merchant response stage at all. 2. Find the deadline and count it correctly. Visa's rule on counting is explicit: the Processing Date of the preceding event is not counted as one day. Every limit is stated in calendar days, not business days. 3. Pull the evidence the rules name. For digital goods, Visa's compelling-evidence table asks for a description of what was sold and the date it was downloaded, plus at least two identifying records — IP address, device ID, profile email, or proof of account access. Generic "the customer received it" narratives do not map to any listed item. 4. Decide whether to respond at all. Some disputes are cheaper to concede. That is a commercial decision, and it belongs to you — but make it inside the deadline, not after it.
The Chargeback Process: A Complete Step-by-Step Guide for Merchants
Written by Wesley Wang · Reviewed by Junseo · Last updated 8 August 2026
Scope of this guide. The stage-by-stage time limits and evidence requirements are drawn from the Visa Core Rules and Visa Product and Service Rules, 18 April 2026 edition (the "Visa Public" release), cited rule block by rule block — by ID number, edition, and last-updated date — so you can verify any statement against the source rather than take our word for it.
Mastercard runs a separate rulebook, and a section near the end covers what differs. Note the asymmetry in what we can source: Visa publishes its full rules openly, while Mastercard's complete Chargeback Guide sits behind Mastercard Connect login. For Mastercard we work from the publicly available Chargebacks Made Simple Guide (July 2025), which is an overview rather than the rulebook — so that section gives you structural differences and the figures the public document actually states, not a matching deadline table.
The rules belong to the card networks. We are describing them, not interpreting them on the networks' behalf. Where your case turns on a deadline, confirm it against the current rules for the network your transaction ran on.
This guide is written for merchants selling small-ticket, high-frequency products: digital goods, subscriptions, in-game currency, content unlocks. If you are handling large-value B2B invoices, the mechanics still apply but the economics do not.
What to do in the first 72 hours
A chargeback notification starts a clock that is shorter than it looks, and what you do in the first three days determines most of what is still available to you afterwards. Four actions, in order.
1. Read the category, not the summary. The dispute condition code on the notification tells you which timetable applies. Under the Visa Core Rules the fraud and authorization categories run on a different sequence from the processing-error and consumer-dispute categories — and one of them has no merchant response stage at all. Get the code first; everything downstream depends on it.
2. Find the deadline and count it correctly. Visa's counting rule is explicit: the Processing Date of the preceding event is not counted as one day. Every limit is stated in calendar days, not business days. Take the date from the dispute record, not from the day the email reached you.
3. Pull the evidence the rules name. For digital goods, Visa's compelling-evidence table asks for a description of what was sold and the date it was downloaded, plus at least two identifying records — IP address, device ID, profile email, or proof of account access. Generic "the customer received it" narratives do not map to any listed item. Pull the acquirer reference number at the same time, so you and your provider are certainly discussing the same transaction.
4. Decide whether to respond at all. Some disputes are cheaper to concede than to fight, once you price in the staff hours. That is a commercial decision and it belongs to you — but make it inside the deadline rather than after it, because a missed window removes the choice.
Sources: Visa Core Rules and Visa Product and Service Rules, 18 April 2026 edition — §11.2.1 (ID# 0030211), Table 11-1 (ID# 0030212), Table 11-2 (ID# 0030213), Table 11-6 (ID# 0030221). Verified by HaiPay on 6 August 2026.
Who is involved

Party | Role in the dispute | Can you reach them? |
|---|---|---|
Cardholder | Raises the claim with their own bank. May not have contacted you first. | Yes — but realistically only before they file |
Issuer (cardholder's bank) | Decides whether to file, and rules on the merchant's response at first instance | No. You have no channel to the issuer |
Card network (Visa, Mastercard) | Owns the rules, the deadlines, and the systems the case moves through. Rules on arbitration | No |
Acquirer / payment provider | Receives the dispute, passes it to you, files your response into the network's system | Yes — this is your working channel |
Merchant (you) | Supplies evidence and decides whether to contest. Never files directly into the network | — |
The practical consequence: you never argue with the bank that filed the dispute. You assemble records and hand them to your acquirer, who submits them on your behalf inside the network's window. If a case feels unfair, the escalation path is the rules, not persuasion.
One rule is worth knowing because it explains why your provider chases you for evidence: Visa's rules provide that a Member which fails to respond through Visa Resolve Online (VROL) inside the specified timeframe, or which accepts responsibility, closes the dispute cycle and becomes liable for the last amount received from the opposing Member. It cuts both ways — it applies to issuers and acquirers alike — but on your side of the chain it means silence is a decision. (Visa Core Rules §11.2.1, ID# 0030211, p668, Edition April 2026.)
Where merchants actually lose
Read enough merchant forum threads and a pattern shows up. People do not lose disputes because they failed to reply. They lose because they replied with the wrong thing, on the wrong clock, in a category they had misread.
One Stripe user put the useful version of it plainly: the decisive factor was service documentation — usage logs showing the account had actually been used. That is not a clever tactic someone invented. It is close to a line-item in Visa's own compelling-evidence table, which has listed acceptable digital-goods records for years. The gap between what merchants discover by trial and error and what the rulebook already specifies is the single largest avoidable cost in this process.
So this guide is organized around the rulebook, not around folklore.
The seven steps, and the time limit on each

End to end, a dispute moves through seven steps:
- The cardholder contests the charge with their issuing bank.
- The issuer reviews the claim and decides whether a dispute right exists.
- The issuer files the dispute. In Visa's own words, a Dispute is a "Transaction that an Issuer returns to an Acquirer" — it goes back down the chain to your provider. (Visa Core Rules glossary, April 2026 edition.)
- The acquirer notifies you, with the dispute condition code and a deadline.
- You respond with evidence, or concede. This step is the dispute response — the industry calls it representment, because the transaction is literally being re-presented for payment. Visa's rulebook uses "Dispute Response"; Mastercard calls the equivalent stage "Second Presentment." All three names describe the same move.
- Pre-arbitration, if the issuer rejects the response.
- Arbitration, where the network itself decides and assigns the fees.
Two things about that list. First, the whole sequence is slow. Verifi, a Visa solution, states that "the chargeback process can take up to six weeks or six months" — which is why a dispute is an operational problem, not a same-week task. Second — and this is what most summaries flatten — not every category has all seven steps.
Total-duration figure: Verifi, a Visa solution — "What is a chargeback, and why do they get issued?" Retrieved 6 August 2026. Quoted verbatim; the source states two figures rather than a single range.
How Visa counts days
Before any table makes sense, the counting rule. Visa states it directly in §11.2.1: for the purpose of calculating a dispute-related timeframe or time limit, the Processing Date of the preceding event is not counted as one day. The preceding event may be the Transaction, the Dispute, the Dispute Response, a pre-Arbitration attempt, Arbitration, or Compliance.
Two practical consequences. First, your clock starts the day after the triggering event's Processing Date, so a "30 calendar days" limit is not thirty days from the notification landing in your inbox. Second, every limit in the rules is expressed in calendar days — weekends and holidays are inside the count, not outside it.
Source: Visa Core Rules, §11.2.1, ID# 0030211, Edition April 2026, Last Updated April 2026. Verified 6 August 2026.
Fraud and authorization disputes have no merchant response stage
This is the part worth slowing down for, because nearly every general explainer gets it wrong.
For Category 10 (Fraud) and Category 11 (Authorization) disputes, Visa's timetable does not include a Dispute Response stage. The sequence runs from the Dispute straight to a Pre-Arbitration Attempt, which the acquirer must make within 30 calendar days of the Dispute Processing Date. The Pre-Arbitration Response window is 30 calendar days, and Arbitration is 10 calendar days.
For Category 12 (Processing Errors) and Category 13 (Consumer Disputes), the Dispute Response stage does exist: 30 calendar days from the Dispute Processing Date. The Pre-Arbitration Attempt that follows is measured from the Dispute Response Processing Date, not from the original dispute — another 30 calendar days. Then Pre-Arbitration Response 30, Arbitration 10.
Stage | Category 10 (Fraud) & 11 (Authorization) | Category 12 (Processing Errors) & 13 (Consumer Disputes) |
|---|---|---|
Dispute | See the specific dispute condition | See the specific dispute condition |
Dispute Response | Stage does not exist | 30 calendar days from Dispute Processing Date |
Pre-Arbitration Attempt | 30 calendar days from Dispute Processing Date | 30 calendar days from Dispute Response Processing Date |
Pre-Arbitration Response | 30 calendar days | 30 calendar days |
Arbitration | 10 calendar days | 10 calendar days |
Sources: Table 11-1, ID# 0030212, Edition April 2026, Last Updated October 2024 (Categories 10 and 11); Table 11-2, ID# 0030213, Edition April 2026, Last Updated April 2026 (Categories 12 and 13). Verified 6 August 2026.
If you have been working from a "you get 20 to 45 days to respond" rule of thumb, this table is why disputes get missed. The number depends on the category, and in two of the four categories the stage you were planning to use is not there.
The 120-day figure is a per-condition limit, not a universal one
"Cardholders have 120 days to file" circulates as a general rule. It is closer to a common case than a universal one, and the distinction matters when you are working out whether a dispute arrived in time.
In the Visa rules, the filing window is set per dispute condition, and each condition states its own limit and its own starting point. 120 calendar days is the most frequently used value — it governs, among others, EMV liability shift counterfeit and non-counterfeit fraud, other fraud in both card-present and card-absent environments, incorrect currency, cancelled recurring transactions, and counterfeit merchandise. But it is not the only value:
- Dispute Condition 11.1 (Card Recovery Bulletin) — 75 calendar days from the Transaction Processing Date
- Dispute Condition 11.2 (Declined Authorization) — 75 calendar days
- Dispute Condition 11.3 (No Authorization / Late Presentment) — 75 calendar days
- Dispute Condition 12.7 (Invalid Data) — 75 calendar days
The starting point also varies by condition. Most run from the Transaction Processing Date, but Visa Fraud Monitoring Program disputes run from the date of the program report, and some credit-related conditions run from the date on the Credit Transaction Receipt.
The practical version: get the limit from the specific dispute condition on your notification, not from a remembered number. If a dispute looks late, check which condition it was filed under before you conclude it is out of time — the whole authorization category runs 45 calendar days shorter than the figure most people quote.
Sources: Visa Core Rules — Dispute Condition tables in Chapter 11, including 11.1 / 11.2 / 11.3 (75 calendar days) and the 120-calendar-day conditions under 10.x, 12.3, 13.2 and 13.4. Verified against the 18 April 2026 edition on 6 August 2026.
Regional exceptions are narrow, and narrower than they look
The tables above carry footnotes that override the general limits in specific markets. They are worth knowing about, but read the scope carefully — most are not blanket country rules. They apply to a particular transaction type and particular dispute conditions:
Region / market | Scope as written in the rules | Limit | Stage and source |
|---|---|---|---|
CEMEA (Nigeria) | Domestic Transaction | 2 business days | pre-Arbitration Attempt, Table 11-1 |
CEMEA (Egypt) | Domestic ATM Transaction, conditions 12.6 (Duplication/Paid by Other Means) and 13.9 (Non-Receipt of Cash) | 10 calendar days | Table 11-2 |
AP (India) | Domestic ATM Transaction, conditions 12.6 and 13.9 | 6 calendar days | Table 11-2 |
Europe (Poland) | Domestic ATM Transaction, no condition restriction | 20 calendar days | pre-Arbitration Attempt, Table 11-1 |
Europe (Poland) | Domestic ATM Transaction, conditions 12.6 and 13.9 | 20 calendar days | Table 11-2 |
CEMEA (Tanzania) | Domestic Transaction | 20 calendar days | pre-Arbitration Attempt, Tables 11-1 and 11-2 |
CEMEA (Tanzania) | Domestic Transaction | 10 calendar days | pre-Arbitration Response, Tables 11-1 and 11-2 |
The reason categories 10 and 11 have no Dispute Response stage is that Visa routes them through Allocation, where liability is assigned up front, while categories 12 and 13 run through Collaboration, where the acquirer answers first. Note too that the party who files Arbitration differs by category: the acquirer files for 10 and 11, the issuer for 12 and 13.
Note what this means in practice: an ATM-specific exception does not touch your card-absent digital-goods disputes even if you operate in that market. Conversely, Nigeria's domestic limit is written without a condition restriction and is stated in business days rather than calendar days — the one place in this guide where that distinction flips.
If your volume touches any of these markets, take the figure from the current footnote rather than this table, because footnote scope changes between editions more often than the main limits do.
Source: Visa Core Rules, Table 11-2 footnotes, ID# 0030213, Edition April 2026. Verified 6 August 2026.
Where the response is filed
Disputes and responses move through Visa's own systems — VROL and VisaNet — not by email to the issuer. Supporting documentation must be in English or accompanied by an English translation. Until 17 April 2026 the rules carried a carve-out for domestic cases where the issuer and acquirer shared a common language, allowing the English translation to be presented only at the filing of the Arbitration or Compliance case. That provision was written to expire, so treat English documentation as the default and confirm the current position with your acquirer. (Visa Core Rules §11.3.1, p673, Edition April 2026.)
Source: Visa Core Rules §11.3.1, Edition April 2026. Verified 6 August 2026.
What counts as evidence
Visa maintains a table of allowable compelling evidence — a list of record types that qualify, by dispute condition. Two entries matter most to a small-ticket digital business.
Digital goods: description, download date, and two identifiers
For an electronic commerce transaction selling digital goods, Visa's Table 11-6 asks for a description of the merchandise or services and the date it was downloaded — plus two or more of the following:
- IP address
- Device ID
- Purchaser name and email address linked to the customer profile
- Evidence the customer profile was accessed and verified before the Transaction Date
- Evidence the site or app was accessed by the cardholder on or after the Transaction Date
- Evidence the same device and the same Payment Credential were used in an undisputed transaction
This is the item that applies to dispute conditions 10.1, 10.3, and 10.4.
Read that list as a logging specification rather than a paperwork chore. "Two or more" means the records have to exist at the moment of the transaction — you cannot reconstruct a device ID after the fact. If your event log does not currently persist IP, device ID, and post-purchase access timestamps against the order, that is a change to make before your next dispute, not during it.
Source: Visa Core Rules, Table 11-6, item 4, ID# 0030221, Edition April 2026, Last Updated April 2026. Verified 6 August 2026.
Physical delivery: no signature required
Worth knowing if you ship anything alongside digital products. For delivery to the same physical address as the transaction with an AVS match of Y or M, the rules state plainly: "A signature is not required as evidence of delivery."
Merchants routinely assume a signature is the only proof that counts, and skip a dispute they could have answered.
Source: Visa Core Rules, Table 11-6, item 3, ID# 0030221. Verified 6 August 2026.
Why complete evidence still loses
It does, sometimes. Merchants on r/ecommerce and r/shopify describe submitting delivery confirmation, AVS and CVC matches, and a full order timeline, and losing anyway. Two things are true at once here: the issuer makes the decision at first instance, and evidence that does not map to a listed item in the compelling-evidence table for your specific dispute condition carries less weight than evidence that does.
We are not going to tell you what your odds are. Nobody credible can, and any specific win-rate figure you see quoted should make you suspicious of the source. What is within your control is whether the records you submit correspond to what the rules actually name.
Evidence by reason-code family
The two entries above are organized by what you sold. It is worth also reading them by why the dispute was filed, because that is how the notification arrives. Three families cover most of what a small-ticket digital business sees:
Dispute family | Typical conditions | What the rules want from you |
|---|---|---|
Fraud — "I didn't make this purchase" | 10.1, 10.3, 10.4 | The digital-goods item above: description of what was sold, download date, plus two or more of IP address, device ID, profile name and email, pre-transaction profile verification, post-transaction access, or the same device and credential used in an undisputed transaction |
Non-receipt — "I never got it" | 13.1 | Proof of delivery of the digital item — download or access timestamp, activation record, licence issuance. For anything physical, delivery to the transaction address with an AVS match of Y or M, where a signature is not required |
Not as described — "it wasn't what was advertised" | 13.3 | The description the customer actually saw at purchase, alongside evidence of what was delivered. Terms accepted at checkout, the product page as it read on the transaction date, and usage or access records |
Note the shape of this: for fraud you are proving who transacted, for non-receipt you are proving that it arrived, and for not-as-described you are proving what was promised. Three different record sets. A single evidence bundle sent for every dispute type will be under-specified for at least two of them.
Take the condition code from your notification and work back to the family. Categories and conditions are the network's, not ours — confirm the current condition list against the rules for the network your transaction ran on.
Sources: Visa Core Rules, Table 11-6 (Allowable Compelling Evidence) items 3 and 4, p677, ID# 0030221, Edition April 2026; Chapter 11 dispute condition tables. Verified 6 August 2026.
Stage time limits at a glance
Category | Dispute Response | Pre-Arbitration Attempt | Pre-Arbitration Response | Arbitration |
|---|---|---|---|---|
10 — Fraud | No such stage | 30 calendar days from Dispute Processing Date | 30 calendar days | 10 calendar days |
11 — Authorization | No such stage | 30 calendar days from Dispute Processing Date | 30 calendar days | 10 calendar days |
12 — Processing Errors | 30 calendar days from Dispute Processing Date | 30 calendar days from Dispute Response Processing Date | 30 calendar days | 10 calendar days |
13 — Consumer Disputes | 30 calendar days from Dispute Processing Date | 30 calendar days from Dispute Response Processing Date | 30 calendar days | 10 calendar days |
All counts exclude the Processing Date of the preceding event, per §11.2.1. All figures are calendar days. Domestic exceptions above override these.
Sources: Table 11-1 (ID# 0030212) and Table 11-2 (ID# 0030213), Edition April 2026. Verified 6 August 2026.
How Mastercard differs

Everything above is Visa. Mastercard runs a separate rulebook, and the differences are structural rather than cosmetic — a process you have built around Visa's stage names will not map cleanly.
A caveat on sourcing first. Mastercard's full Chargeback Guide is distributed through Mastercard Connect, behind customer login. What is publicly available is the Chargebacks Made Simple Guide (July 2025), a 16-page overview that states on its own cover: "This guide is not a replacement for the suite of manuals, rules, or publications provided by Mastercard." The points below come from that public overview. We are not publishing a Mastercard stage-by-stage time limit table, because the public document does not contain one — anyone showing you a complete Mastercard deadline table sourced to public material is filling in gaps.
Two cycles, not a response stage. Mastercard's chargeback process is described as a two-cycle process: First Chargeback (issuer returns the transaction to the acquirer, funds move automatically — credit to issuer, debit to acquirer), then Second Presentment (acquirer either accepts liability or returns it with supporting documentation). The vocabulary matters when you read a notification: "second presentment" is Mastercard's term for the stage a Visa-trained team would call a dispute response.
Only the issuer can start a chargeback. Stated explicitly. Where no chargeback right exists, the mechanism is a compliance case instead, and either an issuer or an acquirer can file one — available when a Mastercard rule or Standard has been violated and a documented financial loss resulted.
Inaction is a decision. If the acquirer takes no action on a pre-arbitration case, Mastercard moves the funds after 30 calendar days from the pre-arbitration case submission date, and the acquirer carries the loss. Silence is not a neutral option.
Appeals run 45 calendar days. After the Mastercard Dispute Resolution Management team rules on an arbitration case, the party found financially responsible may appeal, and Mastercard must receive it within 45 calendar days of the ruling decision.
Different category names. Mastercard's four categories are Fraud-related, Authorization-related, Point-of-Interaction Error, and Cardholder Disputes. The third has no direct Visa counterpart by name — Visa files comparable situations under Processing Errors.
A digital-goods threshold Visa does not have. Under Cardholder Disputes, Mastercard lists "digital goods purchase of USD 25 or less" as its own dispute condition. If you sell small-ticket digital products, that line is worth knowing: your typical order value may sit inside a condition that exists specifically for it. Visa's rules have no equivalent amount-based digital-goods condition.
Different system. Mastercard disputes and supporting documentation move through Mastercom on Mastercard Connect. Visa uses VROL. Two portals, two workflows, and no shared submission format.
Source: Mastercard, Chargebacks Made Simple Guide, July 2025 — §3.1, §3.2, §4.1, §5.1, §5.2, §5.6, §7.1. Verified by HaiPay on 6 August 2026. Full rules: Mastercard Chargeback Guide, Mastercard Connect (login required).
Chargeback vs refund: not two names for the same thing
These get used interchangeably in conversation, and the confusion is expensive. They are different instruments with different costs, different timetables, and different consequences for your account.
Refund | Chargeback | |
|---|---|---|
Who starts it | You do | The cardholder's issuing bank does |
Where it runs | Your own system | The card network's dispute system |
Can you stop it | It is your decision | No. Once filed, it runs on the network's rules |
How long | Days | Verifi: "up to six weeks or six months" |
What it costs you | The transaction value plus a refund fee — at HaiPay, US$0.30 per refund | The transaction value, a dispute fee, and staff hours. Fees are confirmed in your quote |
Counts toward dispute ratios | No | Yes |
Evidence needed | None | Records that map to the network's compelling-evidence list |
That last row is the one that decides most cases. A refund is a cost. A chargeback is a cost and an entry in your dispute count — which is definitional, since a dispute ratio counts disputes and not refunds. Where the thresholds sit for your account is set in your agreement with us, not by the card network. For a small-ticket order where the customer is clearly unhappy and your records are thin, refunding first is usually the cheaper outcome even when you believe you would win.
Timing matters, though. For Visa dispute categories 10 (Fraud) and 11 (Authorization), the rules address the case where a credit was processed before the dispute: the issuer must either apply that credit to the disputed transaction, or supply the Transaction Identifier or ARN and the Transaction Date that the credit was applied to, and explain why it does not resolve the dispute. So a refund issued before the dispute is on the record and has to be accounted for. Categories 12 and 13 are governed by their own table, so confirm the equivalent item there before generalising. (Visa Core Rules §11.2.2, p669 — the Category 10/11 table; Table 11-2 covers 12/13. Edition April 2026.) We have no public-rule basis for telling you what happens to a refund issued after a dispute is already filed — ask your provider before doing that, rather than assuming it withdraws the case.
What a chargeback actually costs
Our own fees are quote-specific, so the useful numbers here are the public industry ones. Three figures worth holding onto:
- The dispute fee itself. Stripe states a fee of US$15 per chargeback on its own platform, and notes that other processors may charge US$50, or as much as US$100. The fee is charged on top of the disputed transaction value. (Stripe, "Chargebacks 101," last updated 16 March 2026. Retrieved 6 August 2026.)
- Total cost around 2.5× the sale price. ChargebackGurus: "When you factor in transaction fees, marketing costs, operational expenses and chargeback fees, the average 'true cost' of a chargeback is 2.5 times the sale price (essentially $250 on a $100 sale.)" Note this figure comes from a 2023 article. (ChargebackGurus, "Are Chargebacks a Cost of Doing Business in 2023?")
- US$3.75 per US$1 charged back. Quoted by Stripe, and originally from the LexisNexis True Cost of Fraud study — so read it as a fraud-cost multiplier from that study rather than as Stripe's own measurement. (LexisNexis, via Stripe, "Chargebacks 101.")
Those are third-party figures, not HaiPay's pricing, and they come from three different parties measuring three different things — do not add them together. What they agree on is the direction: the sticker cost is the dispute fee, and the real cost is a multiple of the order value. On a small-ticket digital product, a single dispute can consume the margin on dozens of clean orders.
At HaiPay, chargeback and other refund-related fees are confirmed in your quote — we do not publish a single figure, because it depends on your configuration. Processing starts at 2.5% + $0.30. See card processing for what the card product covers.
Chargeback prevention, in the order that pays
Treat this as chargeback management rather than one-off firefighting — the same instrumentation serves every future dispute. Prevention is cheaper than representment for a structural reason: a dispute costs you the fee and the operational time whether you win or lose it, and the multipliers above are why.
What moves the number, roughly in order of leverage:
Make the billing descriptor recognizable. A large share of consumer-dispute filings start with someone not recognizing a line on a statement. It is a low-effort fix, and it is often the last one anyone gets to.
Refund before it becomes a dispute. A merchant-initiated refund at HaiPay is US$0.30 per refund, against the third-party dispute-fee and multiplier figures above. See the comparison table earlier on this page — on a low-value order the arithmetic rarely favors fighting.
Log for the evidence table, not for your own debugging. See the digital-goods list above. Instrument once.
Use authentication where it fits. 3-D Secure changes how certain fraud disputes are handled. It also adds friction, and for small-ticket high-frequency flows that trade-off is real — worth deciding deliberately rather than by default.
Watch decline codes as an early signal. Patterns in declines often precede patterns in disputes.
Know which lane you are in. Refunds and chargebacks are different instruments with different costs and different consequences.
Common failure modes, and what to do instead
Missing the deadline because you counted from the notification. The clock runs from the Processing Date of the preceding event, and that date is excluded from the count. Take the date from the dispute record, not from your inbox.
Preparing a Dispute Response for a Category 10 or 11 case. The stage does not exist there. The next move belongs to the acquirer as a pre-arbitration attempt. Preparing the wrong artifact wastes the window.
Submitting a narrative instead of records. "The customer clearly used the product" is a claim. An access log with a timestamp on or after the transaction date is a listed item. Submit the second.
Treating 120 calendar days as a universal filing window. It is the most frequently used value, not a blanket one. Conditions 11.1, 11.2, 11.3 and 12.7 give the issuer 75 calendar days, and the start point is not always the Transaction Processing Date. Check the individual dispute condition.
Filing in the wrong language. Documentation goes through VROL in English, or with an English translation attached.
Escalating on principle. Pre-arbitration and arbitration have their own fees, and merchants report losing both the fee and the disputed amount when a case goes against them. Escalate on the strength of your records, not on how unfair the case feels.
Letting the dispute be the first sign of a problem. Merchants on r/Banking describe chargebacks arriving as the first indication anything was wrong with an order. If your support channel is hard to find, disputes become your support channel.
Reason codes: the overview

Visa organizes dispute conditions into four categories:
Category | Covers |
|---|---|
10 | Fraud |
11 | Authorization |
12 | Processing Errors |
13 | Consumer Disputes |
For merchants selling digital goods and subscriptions, the conditions under Category 13 come up most often — 13.1 Merchandise/Services Not Received and 13.3 Not as Described or Defective Merchandise/Services in particular, which begin at pages 744 and 758 of the April 2026 rules. Cardholders and issuers will sometimes quote the code directly; forum threads show people reporting a dispute "coded as 13.3" without being told what that means operationally.
One product note that matters when you are debugging a dispute: HaiPay passes the card network's original code through to you. We do not map network codes onto a proprietary internal taxonomy, which means the code you see in your dashboard is the code the network issued, and you can look it up in the rules directly. Note that doc.haipay.net does not currently host a chargeback code list — it carries error_response_appendix and cashin_code_list.
Scripts for your support team
Four situations, four openings. Adapt the voice; keep the structure. Every one of these describes mechanism and next steps only — none of them promises an outcome, and none should.
1. Customer says they do not recognize the charge.
"Thanks for flagging this. The charge on your statement appears as [descriptor] — that's us. It was for [product] on [date], on a card ending [last four]. If that doesn't match anything you recognize, tell me and I'll refund it now rather than have you go through your bank, which takes longer for both of us."
2. Customer has already filed a dispute.
"I can see the dispute your bank opened. Once it's filed, the process runs on your bank's timetable and the card network's rules, so I can't cancel it from my side. [template script] What I can do is share the records we have. If you'd rather withdraw it and take a refund directly, contact your bank — that's usually faster."
3. Subscription customer disputes a renewal.
"That charge was the renewal on [date] for the [plan] subscription started on [date]. I've cancelled it so nothing further is charged. On the renewal itself, tell me how you'd like to handle it and I'll sort it out."
4. Internal handoff on a dispute you plan to answer.
"Dispute condition [code], category [10/11/12/13]. Response stage: [exists / does not exist for this category]. Deadline: [date], counted from the [event] Processing Date of [date], excluding that date. Records attached: [list]. Records missing: [list]."
Sources
Every rule statement above is cited inline by section and rule ID so you can check it yourself. These are the documents those citations point to.
- Visa — "Visa Core Rules and Visa Product and Service Rules," 18 April 2026 (PDF, 923 pages). Every §11 and §13 citation on this page resolves against this edition.
- Visa — Dispute Resolutions (business support). Visa's own merchant-facing summary of the dispute process.
- Mastercard — "Chargebacks Made Simple Guide," July 2025 (16 pages). A high-level public overview, not the full Chargeback Guide. Mastercard's site blocks automated access, so we have not linked it; request it through your acquirer or Mastercard Connect.
- Stripe — "Chargebacks 101," last updated 16 March 2026. Source of the per-dispute fee figures quoted in the cost section.
- ChargebackGurus — "Are Chargebacks a Cost of Doing Business in 2023?" Source of the 2.5x figure, and dated 2023.
- Verifi, a Visa solution — chargebacks and disputes FAQ. Source of the "up to six weeks or six months" timeline.
- LexisNexis Risk Solutions — True Cost of Fraud. Origin of the 3.75x multiplier, which we cite as quoted by Stripe rather than from the report itself.
The rules belong to the card networks. We describe them and point you at the primary text; where our reading and your acquirer's differ, your acquirer's governs your account.
FAQ
It depends on the category. For Visa Categories 12 and 13, the Dispute Response window is 30 calendar days from the Dispute Processing Date. Categories 10 and 11 have no Dispute Response stage — the next step is a pre-arbitration attempt by the acquirer within 30 calendar days. The Processing Date of the preceding event is not counted as one day. (Visa Core Rules, Tables 11-1 and 11-2, April 2026 edition.)
Related HaiPay surfaces
Explore the payment stack
Reason codes
Chargeback Reason Codes
Every Visa dispute condition by category, with what each one requires from a merchant.
Refunds
Chargeback vs Refund
Two different instruments with different costs. When to refund and when to answer.
Authentication
3-D Secure for Merchants
What authentication changes about fraud disputes, and the friction it adds.
Declines
Credit Card Decline Codes
Decline patterns often precede dispute patterns. How to read them.
Classification
MCC Codes
How your merchant category code is assigned and where it affects risk handling.
Need help mapping your payment stack?
Talk to HaiPay about acquiring, orchestration, local methods, and payout workflows.
Contact us