The Chargeback Process: A Complete Step-by-Step Guide for Merchants

A working guide to the chargeback process for merchants selling small-ticket digital goods, subscriptions, and in-game content. It follows a dispute from the cardholder's first claim through representment, pre-arbitration, and arbitration, and cites the time limit for each stage directly from the Visa Core Rules — including the stage that Visa's fraud and authorization categories do not have.

Updated Aug 10, 2026Intermediate28-min readby Wesley WangReviewed by WeiJun TangFraud & Risk

Direct Answer

When a chargeback notification arrives, work through four things before you write a single line of response. 1. Read the category, not the summary. The dispute condition code tells you which timetable applies. Under the Visa Core Rules the fraud and authorization categories run on a different sequence from processing-error and consumer-dispute categories — one of them has no merchant response stage at all. 2. Find the deadline and count it correctly. Visa's rule on counting is explicit: the Processing Date of the preceding event is not counted as one day. Every limit is stated in calendar days, not business days. 3. Pull the evidence the rules name. For digital goods, Visa's compelling-evidence table asks for a description of what was sold and the date it was downloaded, plus at least two identifying records — IP address, device ID, profile email, or proof of account access. Generic "the customer received it" narratives do not map to any listed item. 4. Decide whether to respond at all. Some disputes are cheaper to concede. That is a commercial decision, and it belongs to you — but make it inside the deadline, not after it.

Scope of this guide. The stage-by-stage time limits and evidence requirements are drawn from the Visa Core Rules and Visa Product and Service Rules, 18 April 2026 edition (the "Visa Public" release), cited rule block by rule block — by ID number, edition, and last-updated date — so you can verify any statement against the source rather than take our word for it.

Mastercard runs a separate rulebook, and a section near the end covers what differs. Note the asymmetry in what we can source: Visa publishes its full rules openly, while Mastercard's complete Chargeback Guide sits behind Mastercard Connect login. For Mastercard we work from the publicly available Chargebacks Made Simple Guide (July 2025), which is an overview rather than the rulebook — so that section gives you structural differences and the figures the public document actually states, not a matching deadline table.

The rules belong to the card networks. We are describing them, not interpreting them on the networks' behalf. Where your case turns on a deadline, confirm it against the current rules for the network your transaction ran on.

This guide is written for merchants selling small-ticket, high-frequency products: digital goods, subscriptions, in-game currency, content unlocks. If you are handling large-value B2B invoices, the mechanics still apply but the economics do not.

What to do in the first 72 hours

A chargeback notification starts a clock that is shorter than it looks, and what you do in the first three days determines most of what is still available to you afterwards. Four actions, in order.

1. Read the category, not the summary. The dispute condition code on the notification tells you which timetable applies. Under the Visa Core Rules the fraud and authorization categories run on a different sequence from the processing-error and consumer-dispute categories — and one of them has no merchant response stage at all. Get the code first; everything downstream depends on it.

2. Find the deadline and count it correctly. Visa's counting rule is explicit: the Processing Date of the preceding event is not counted as one day. Every limit is stated in calendar days, not business days. Take the date from the dispute record, not from the day the email reached you.

3. Pull the evidence the rules name. For digital goods, Visa's compelling-evidence table asks for a description of what was sold and the date it was downloaded, plus at least two identifying records — IP address, device ID, profile email, or proof of account access. Generic "the customer received it" narratives do not map to any listed item. Pull the acquirer reference number at the same time, so you and your provider are certainly discussing the same transaction.

4. Decide whether to respond at all. Some disputes are cheaper to concede than to fight, once you price in the staff hours. That is a commercial decision and it belongs to you — but make it inside the deadline rather than after it, because a missed window removes the choice.

Sources: Visa Core Rules and Visa Product and Service Rules, 18 April 2026 edition — §11.2.1 (ID# 0030211), Table 11-1 (ID# 0030212), Table 11-2 (ID# 0030213), Table 11-6 (ID# 0030221). Verified by HaiPay on 6 August 2026.

Who is involved

Diagram showing the five parties in a chargeback — cardholder, issuer, card network, acquirer and merchant — and which parties the merchant can reach directly.

Party

Role in the dispute

Can you reach them?

Cardholder

Raises the claim with their own bank. May not have contacted you first.

Yes — but realistically only before they file

Issuer (cardholder's bank)

Decides whether to file, and rules on the merchant's response at first instance

No. You have no channel to the issuer

Card network (Visa, Mastercard)

Owns the rules, the deadlines, and the systems the case moves through. Rules on arbitration

No

Acquirer / payment provider

Receives the dispute, passes it to you, files your response into the network's system

Yes — this is your working channel

Merchant (you)

Supplies evidence and decides whether to contest. Never files directly into the network

The practical consequence: you never argue with the bank that filed the dispute. You assemble records and hand them to your acquirer, who submits them on your behalf inside the network's window. If a case feels unfair, the escalation path is the rules, not persuasion.

One rule is worth knowing because it explains why your provider chases you for evidence: Visa's rules provide that a Member which fails to respond through Visa Resolve Online (VROL) inside the specified timeframe, or which accepts responsibility, closes the dispute cycle and becomes liable for the last amount received from the opposing Member. It cuts both ways — it applies to issuers and acquirers alike — but on your side of the chain it means silence is a decision. (Visa Core Rules §11.2.1, ID# 0030211, p668, Edition April 2026.)

Where merchants actually lose

Read enough merchant forum threads and a pattern shows up. People do not lose disputes because they failed to reply. They lose because they replied with the wrong thing, on the wrong clock, in a category they had misread.

One Stripe user put the useful version of it plainly: the decisive factor was service documentation — usage logs showing the account had actually been used. That is not a clever tactic someone invented. It is close to a line-item in Visa's own compelling-evidence table, which has listed acceptable digital-goods records for years. The gap between what merchants discover by trial and error and what the rulebook already specifies is the single largest avoidable cost in this process.

So this guide is organized around the rulebook, not around folklore.

The seven steps, and the time limit on each

Seven-step flowchart of the chargeback process, from the cardholder contesting a charge through representment to arbitration, showing which party acts at each step.

End to end, a dispute moves through seven steps:

  1. The cardholder contests the charge with their issuing bank.
  2. The issuer reviews the claim and decides whether a dispute right exists.
  3. The issuer files the dispute. In Visa's own words, a Dispute is a "Transaction that an Issuer returns to an Acquirer" — it goes back down the chain to your provider. (Visa Core Rules glossary, April 2026 edition.)
  4. The acquirer notifies you, with the dispute condition code and a deadline.
  5. You respond with evidence, or concede. This step is the dispute response — the industry calls it representment, because the transaction is literally being re-presented for payment. Visa's rulebook uses "Dispute Response"; Mastercard calls the equivalent stage "Second Presentment." All three names describe the same move.
  6. Pre-arbitration, if the issuer rejects the response.
  7. Arbitration, where the network itself decides and assigns the fees.

Two things about that list. First, the whole sequence is slow. Verifi, a Visa solution, states that "the chargeback process can take up to six weeks or six months" — which is why a dispute is an operational problem, not a same-week task. Second — and this is what most summaries flatten — not every category has all seven steps.

Total-duration figure: Verifi, a Visa solution — "What is a chargeback, and why do they get issued?" Retrieved 6 August 2026. Quoted verbatim; the source states two figures rather than a single range.

How Visa counts days

Before any table makes sense, the counting rule. Visa states it directly in §11.2.1: for the purpose of calculating a dispute-related timeframe or time limit, the Processing Date of the preceding event is not counted as one day. The preceding event may be the Transaction, the Dispute, the Dispute Response, a pre-Arbitration attempt, Arbitration, or Compliance.

Two practical consequences. First, your clock starts the day after the triggering event's Processing Date, so a "30 calendar days" limit is not thirty days from the notification landing in your inbox. Second, every limit in the rules is expressed in calendar days — weekends and holidays are inside the count, not outside it.

Source: Visa Core Rules, §11.2.1, ID# 0030211, Edition April 2026, Last Updated April 2026. Verified 6 August 2026.

Fraud and authorization disputes have no merchant response stage

This is the part worth slowing down for, because nearly every general explainer gets it wrong.

For Category 10 (Fraud) and Category 11 (Authorization) disputes, Visa's timetable does not include a Dispute Response stage. The sequence runs from the Dispute straight to a Pre-Arbitration Attempt, which the acquirer must make within 30 calendar days of the Dispute Processing Date. The Pre-Arbitration Response window is 30 calendar days, and Arbitration is 10 calendar days.

For Category 12 (Processing Errors) and Category 13 (Consumer Disputes), the Dispute Response stage does exist: 30 calendar days from the Dispute Processing Date. The Pre-Arbitration Attempt that follows is measured from the Dispute Response Processing Date, not from the original dispute — another 30 calendar days. Then Pre-Arbitration Response 30, Arbitration 10.

Stage

Category 10 (Fraud) & 11 (Authorization)

Category 12 (Processing Errors) & 13 (Consumer Disputes)

Dispute

See the specific dispute condition

See the specific dispute condition

Dispute Response

Stage does not exist

30 calendar days from Dispute Processing Date

Pre-Arbitration Attempt

30 calendar days from Dispute Processing Date

30 calendar days from Dispute Response Processing Date

Pre-Arbitration Response

30 calendar days

30 calendar days

Arbitration

10 calendar days

10 calendar days

Sources: Table 11-1, ID# 0030212, Edition April 2026, Last Updated October 2024 (Categories 10 and 11); Table 11-2, ID# 0030213, Edition April 2026, Last Updated April 2026 (Categories 12 and 13). Verified 6 August 2026.

If you have been working from a "you get 20 to 45 days to respond" rule of thumb, this table is why disputes get missed. The number depends on the category, and in two of the four categories the stage you were planning to use is not there.

The 120-day figure is a per-condition limit, not a universal one

"Cardholders have 120 days to file" circulates as a general rule. It is closer to a common case than a universal one, and the distinction matters when you are working out whether a dispute arrived in time.

In the Visa rules, the filing window is set per dispute condition, and each condition states its own limit and its own starting point. 120 calendar days is the most frequently used value — it governs, among others, EMV liability shift counterfeit and non-counterfeit fraud, other fraud in both card-present and card-absent environments, incorrect currency, cancelled recurring transactions, and counterfeit merchandise. But it is not the only value:

  • Dispute Condition 11.1 (Card Recovery Bulletin) — 75 calendar days from the Transaction Processing Date
  • Dispute Condition 11.2 (Declined Authorization) — 75 calendar days
  • Dispute Condition 11.3 (No Authorization / Late Presentment) — 75 calendar days
  • Dispute Condition 12.7 (Invalid Data) — 75 calendar days

The starting point also varies by condition. Most run from the Transaction Processing Date, but Visa Fraud Monitoring Program disputes run from the date of the program report, and some credit-related conditions run from the date on the Credit Transaction Receipt.

The practical version: get the limit from the specific dispute condition on your notification, not from a remembered number. If a dispute looks late, check which condition it was filed under before you conclude it is out of time — the whole authorization category runs 45 calendar days shorter than the figure most people quote.

Sources: Visa Core Rules — Dispute Condition tables in Chapter 11, including 11.1 / 11.2 / 11.3 (75 calendar days) and the 120-calendar-day conditions under 10.x, 12.3, 13.2 and 13.4. Verified against the 18 April 2026 edition on 6 August 2026.

Regional exceptions are narrow, and narrower than they look

The tables above carry footnotes that override the general limits in specific markets. They are worth knowing about, but read the scope carefully — most are not blanket country rules. They apply to a particular transaction type and particular dispute conditions:

Region / market

Scope as written in the rules

Limit

Stage and source

CEMEA (Nigeria)

Domestic Transaction

2 business days

pre-Arbitration Attempt, Table 11-1

CEMEA (Egypt)

Domestic ATM Transaction, conditions 12.6 (Duplication/Paid by Other Means) and 13.9 (Non-Receipt of Cash)

10 calendar days

Table 11-2

AP (India)

Domestic ATM Transaction, conditions 12.6 and 13.9

6 calendar days

Table 11-2

Europe (Poland)

Domestic ATM Transaction, no condition restriction

20 calendar days

pre-Arbitration Attempt, Table 11-1

Europe (Poland)

Domestic ATM Transaction, conditions 12.6 and 13.9

20 calendar days

Table 11-2

CEMEA (Tanzania)

Domestic Transaction

20 calendar days

pre-Arbitration Attempt, Tables 11-1 and 11-2

CEMEA (Tanzania)

Domestic Transaction

10 calendar days

pre-Arbitration Response, Tables 11-1 and 11-2

The reason categories 10 and 11 have no Dispute Response stage is that Visa routes them through Allocation, where liability is assigned up front, while categories 12 and 13 run through Collaboration, where the acquirer answers first. Note too that the party who files Arbitration differs by category: the acquirer files for 10 and 11, the issuer for 12 and 13.

Note what this means in practice: an ATM-specific exception does not touch your card-absent digital-goods disputes even if you operate in that market. Conversely, Nigeria's domestic limit is written without a condition restriction and is stated in business days rather than calendar days — the one place in this guide where that distinction flips.

If your volume touches any of these markets, take the figure from the current footnote rather than this table, because footnote scope changes between editions more often than the main limits do.

Source: Visa Core Rules, Table 11-2 footnotes, ID# 0030213, Edition April 2026. Verified 6 August 2026.

Where the response is filed

Disputes and responses move through Visa's own systems — VROL and VisaNet — not by email to the issuer. Supporting documentation must be in English or accompanied by an English translation. Until 17 April 2026 the rules carried a carve-out for domestic cases where the issuer and acquirer shared a common language, allowing the English translation to be presented only at the filing of the Arbitration or Compliance case. That provision was written to expire, so treat English documentation as the default and confirm the current position with your acquirer. (Visa Core Rules §11.3.1, p673, Edition April 2026.)

Source: Visa Core Rules §11.3.1, Edition April 2026. Verified 6 August 2026.

What counts as evidence

Visa maintains a table of allowable compelling evidence — a list of record types that qualify, by dispute condition. Two entries matter most to a small-ticket digital business.

Digital goods: description, download date, and two identifiers

For an electronic commerce transaction selling digital goods, Visa's Table 11-6 asks for a description of the merchandise or services and the date it was downloaded — plus two or more of the following:

  • IP address
  • Device ID
  • Purchaser name and email address linked to the customer profile
  • Evidence the customer profile was accessed and verified before the Transaction Date
  • Evidence the site or app was accessed by the cardholder on or after the Transaction Date
  • Evidence the same device and the same Payment Credential were used in an undisputed transaction

This is the item that applies to dispute conditions 10.1, 10.3, and 10.4.

Read that list as a logging specification rather than a paperwork chore. "Two or more" means the records have to exist at the moment of the transaction — you cannot reconstruct a device ID after the fact. If your event log does not currently persist IP, device ID, and post-purchase access timestamps against the order, that is a change to make before your next dispute, not during it.

Source: Visa Core Rules, Table 11-6, item 4, ID# 0030221, Edition April 2026, Last Updated April 2026. Verified 6 August 2026.

Physical delivery: no signature required

Worth knowing if you ship anything alongside digital products. For delivery to the same physical address as the transaction with an AVS match of Y or M, the rules state plainly: "A signature is not required as evidence of delivery."

Merchants routinely assume a signature is the only proof that counts, and skip a dispute they could have answered.

Source: Visa Core Rules, Table 11-6, item 3, ID# 0030221. Verified 6 August 2026.

Why complete evidence still loses

It does, sometimes. Merchants on r/ecommerce and r/shopify describe submitting delivery confirmation, AVS and CVC matches, and a full order timeline, and losing anyway. Two things are true at once here: the issuer makes the decision at first instance, and evidence that does not map to a listed item in the compelling-evidence table for your specific dispute condition carries less weight than evidence that does.

We are not going to tell you what your odds are. Nobody credible can, and any specific win-rate figure you see quoted should make you suspicious of the source. What is within your control is whether the records you submit correspond to what the rules actually name.

Evidence by reason-code family

The two entries above are organized by what you sold. It is worth also reading them by why the dispute was filed, because that is how the notification arrives. Three families cover most of what a small-ticket digital business sees:

Dispute family

Typical conditions

What the rules want from you

Fraud — "I didn't make this purchase"

10.1, 10.3, 10.4

The digital-goods item above: description of what was sold, download date, plus two or more of IP address, device ID, profile name and email, pre-transaction profile verification, post-transaction access, or the same device and credential used in an undisputed transaction

Non-receipt — "I never got it"

13.1

Proof of delivery of the digital item — download or access timestamp, activation record, licence issuance. For anything physical, delivery to the transaction address with an AVS match of Y or M, where a signature is not required

Not as described — "it wasn't what was advertised"

13.3

The description the customer actually saw at purchase, alongside evidence of what was delivered. Terms accepted at checkout, the product page as it read on the transaction date, and usage or access records

Note the shape of this: for fraud you are proving who transacted, for non-receipt you are proving that it arrived, and for not-as-described you are proving what was promised. Three different record sets. A single evidence bundle sent for every dispute type will be under-specified for at least two of them.

Take the condition code from your notification and work back to the family. Categories and conditions are the network's, not ours — confirm the current condition list against the rules for the network your transaction ran on.

Sources: Visa Core Rules, Table 11-6 (Allowable Compelling Evidence) items 3 and 4, p677, ID# 0030221, Edition April 2026; Chapter 11 dispute condition tables. Verified 6 August 2026.

Stage time limits at a glance

Category

Dispute Response

Pre-Arbitration Attempt

Pre-Arbitration Response

Arbitration

10 — Fraud

No such stage

30 calendar days from Dispute Processing Date

30 calendar days

10 calendar days

11 — Authorization

No such stage

30 calendar days from Dispute Processing Date

30 calendar days

10 calendar days

12 — Processing Errors

30 calendar days from Dispute Processing Date

30 calendar days from Dispute Response Processing Date

30 calendar days

10 calendar days

13 — Consumer Disputes

30 calendar days from Dispute Processing Date

30 calendar days from Dispute Response Processing Date

30 calendar days

10 calendar days

All counts exclude the Processing Date of the preceding event, per §11.2.1. All figures are calendar days. Domestic exceptions above override these.

Sources: Table 11-1 (ID# 0030212) and Table 11-2 (ID# 0030213), Edition April 2026. Verified 6 August 2026.

How Mastercard differs

Infographic comparing Mastercard's First Chargeback and Second Presentment process with Visa's Dispute and Dispute Response flow, showing the merchant response stage and automatic fund transfer.

Everything above is Visa. Mastercard runs a separate rulebook, and the differences are structural rather than cosmetic — a process you have built around Visa's stage names will not map cleanly.

A caveat on sourcing first. Mastercard's full Chargeback Guide is distributed through Mastercard Connect, behind customer login. What is publicly available is the Chargebacks Made Simple Guide (July 2025), a 16-page overview that states on its own cover: "This guide is not a replacement for the suite of manuals, rules, or publications provided by Mastercard." The points below come from that public overview. We are not publishing a Mastercard stage-by-stage time limit table, because the public document does not contain one — anyone showing you a complete Mastercard deadline table sourced to public material is filling in gaps.

Two cycles, not a response stage. Mastercard's chargeback process is described as a two-cycle process: First Chargeback (issuer returns the transaction to the acquirer, funds move automatically — credit to issuer, debit to acquirer), then Second Presentment (acquirer either accepts liability or returns it with supporting documentation). The vocabulary matters when you read a notification: "second presentment" is Mastercard's term for the stage a Visa-trained team would call a dispute response.

Only the issuer can start a chargeback. Stated explicitly. Where no chargeback right exists, the mechanism is a compliance case instead, and either an issuer or an acquirer can file one — available when a Mastercard rule or Standard has been violated and a documented financial loss resulted.

Inaction is a decision. If the acquirer takes no action on a pre-arbitration case, Mastercard moves the funds after 30 calendar days from the pre-arbitration case submission date, and the acquirer carries the loss. Silence is not a neutral option.

Appeals run 45 calendar days. After the Mastercard Dispute Resolution Management team rules on an arbitration case, the party found financially responsible may appeal, and Mastercard must receive it within 45 calendar days of the ruling decision.

Different category names. Mastercard's four categories are Fraud-related, Authorization-related, Point-of-Interaction Error, and Cardholder Disputes. The third has no direct Visa counterpart by name — Visa files comparable situations under Processing Errors.

A digital-goods threshold Visa does not have. Under Cardholder Disputes, Mastercard lists "digital goods purchase of USD 25 or less" as its own dispute condition. If you sell small-ticket digital products, that line is worth knowing: your typical order value may sit inside a condition that exists specifically for it. Visa's rules have no equivalent amount-based digital-goods condition.

Different system. Mastercard disputes and supporting documentation move through Mastercom on Mastercard Connect. Visa uses VROL. Two portals, two workflows, and no shared submission format.

Source: Mastercard, Chargebacks Made Simple Guide, July 2025 — §3.1, §3.2, §4.1, §5.1, §5.2, §5.6, §7.1. Verified by HaiPay on 6 August 2026. Full rules: Mastercard Chargeback Guide, Mastercard Connect (login required).

Chargeback vs refund: not two names for the same thing

These get used interchangeably in conversation, and the confusion is expensive. They are different instruments with different costs, different timetables, and different consequences for your account.


Refund

Chargeback

Who starts it

You do

The cardholder's issuing bank does

Where it runs

Your own system

The card network's dispute system

Can you stop it

It is your decision

No. Once filed, it runs on the network's rules

How long

Days

Verifi: "up to six weeks or six months"

What it costs you

The transaction value plus a refund fee — at HaiPay, US$0.30 per refund

The transaction value, a dispute fee, and staff hours. Fees are confirmed in your quote

Counts toward dispute ratios

No

Yes

Evidence needed

None

Records that map to the network's compelling-evidence list

That last row is the one that decides most cases. A refund is a cost. A chargeback is a cost and an entry in your dispute count — which is definitional, since a dispute ratio counts disputes and not refunds. Where the thresholds sit for your account is set in your agreement with us, not by the card network. For a small-ticket order where the customer is clearly unhappy and your records are thin, refunding first is usually the cheaper outcome even when you believe you would win.

Timing matters, though. For Visa dispute categories 10 (Fraud) and 11 (Authorization), the rules address the case where a credit was processed before the dispute: the issuer must either apply that credit to the disputed transaction, or supply the Transaction Identifier or ARN and the Transaction Date that the credit was applied to, and explain why it does not resolve the dispute. So a refund issued before the dispute is on the record and has to be accounted for. Categories 12 and 13 are governed by their own table, so confirm the equivalent item there before generalising. (Visa Core Rules §11.2.2, p669 — the Category 10/11 table; Table 11-2 covers 12/13. Edition April 2026.) We have no public-rule basis for telling you what happens to a refund issued after a dispute is already filed — ask your provider before doing that, rather than assuming it withdraws the case.

What a chargeback actually costs

Our own fees are quote-specific, so the useful numbers here are the public industry ones. Three figures worth holding onto:

  • The dispute fee itself. Stripe states a fee of US$15 per chargeback on its own platform, and notes that other processors may charge US$50, or as much as US$100. The fee is charged on top of the disputed transaction value. (Stripe, "Chargebacks 101," last updated 16 March 2026. Retrieved 6 August 2026.)
  • Total cost around 2.5× the sale price. ChargebackGurus: "When you factor in transaction fees, marketing costs, operational expenses and chargeback fees, the average 'true cost' of a chargeback is 2.5 times the sale price (essentially $250 on a $100 sale.)" Note this figure comes from a 2023 article. (ChargebackGurus, "Are Chargebacks a Cost of Doing Business in 2023?")
  • US$3.75 per US$1 charged back. Quoted by Stripe, and originally from the LexisNexis True Cost of Fraud study — so read it as a fraud-cost multiplier from that study rather than as Stripe's own measurement. (LexisNexis, via Stripe, "Chargebacks 101.")

Those are third-party figures, not HaiPay's pricing, and they come from three different parties measuring three different things — do not add them together. What they agree on is the direction: the sticker cost is the dispute fee, and the real cost is a multiple of the order value. On a small-ticket digital product, a single dispute can consume the margin on dozens of clean orders.

At HaiPay, chargeback and other refund-related fees are confirmed in your quote — we do not publish a single figure, because it depends on your configuration. Processing starts at 2.5% + $0.30. See card processing for what the card product covers.

Chargeback prevention, in the order that pays

Treat this as chargeback management rather than one-off firefighting — the same instrumentation serves every future dispute. Prevention is cheaper than representment for a structural reason: a dispute costs you the fee and the operational time whether you win or lose it, and the multipliers above are why.

What moves the number, roughly in order of leverage:

Make the billing descriptor recognizable. A large share of consumer-dispute filings start with someone not recognizing a line on a statement. It is a low-effort fix, and it is often the last one anyone gets to.

Refund before it becomes a dispute. A merchant-initiated refund at HaiPay is US$0.30 per refund, against the third-party dispute-fee and multiplier figures above. See the comparison table earlier on this page — on a low-value order the arithmetic rarely favors fighting.

Log for the evidence table, not for your own debugging. See the digital-goods list above. Instrument once.

Use authentication where it fits. 3-D Secure changes how certain fraud disputes are handled. It also adds friction, and for small-ticket high-frequency flows that trade-off is real — worth deciding deliberately rather than by default.

Watch decline codes as an early signal. Patterns in declines often precede patterns in disputes.

Know which lane you are in. Refunds and chargebacks are different instruments with different costs and different consequences.

Common failure modes, and what to do instead

Missing the deadline because you counted from the notification. The clock runs from the Processing Date of the preceding event, and that date is excluded from the count. Take the date from the dispute record, not from your inbox.

Preparing a Dispute Response for a Category 10 or 11 case. The stage does not exist there. The next move belongs to the acquirer as a pre-arbitration attempt. Preparing the wrong artifact wastes the window.

Submitting a narrative instead of records. "The customer clearly used the product" is a claim. An access log with a timestamp on or after the transaction date is a listed item. Submit the second.

Treating 120 calendar days as a universal filing window. It is the most frequently used value, not a blanket one. Conditions 11.1, 11.2, 11.3 and 12.7 give the issuer 75 calendar days, and the start point is not always the Transaction Processing Date. Check the individual dispute condition.

Filing in the wrong language. Documentation goes through VROL in English, or with an English translation attached.

Escalating on principle. Pre-arbitration and arbitration have their own fees, and merchants report losing both the fee and the disputed amount when a case goes against them. Escalate on the strength of your records, not on how unfair the case feels.

Letting the dispute be the first sign of a problem. Merchants on r/Banking describe chargebacks arriving as the first indication anything was wrong with an order. If your support channel is hard to find, disputes become your support channel.

Reason codes: the overview

Decision tree mapping common chargeback reason codes for fraud, non-receipt and not-as-described disputes to the evidence needed to prove who transacted, that delivery occurred, or what was promised.

Visa organizes dispute conditions into four categories:

Category

Covers

10

Fraud

11

Authorization

12

Processing Errors

13

Consumer Disputes

For merchants selling digital goods and subscriptions, the conditions under Category 13 come up most often — 13.1 Merchandise/Services Not Received and 13.3 Not as Described or Defective Merchandise/Services in particular, which begin at pages 744 and 758 of the April 2026 rules. Cardholders and issuers will sometimes quote the code directly; forum threads show people reporting a dispute "coded as 13.3" without being told what that means operationally.

One product note that matters when you are debugging a dispute: HaiPay passes the card network's original code through to you. We do not map network codes onto a proprietary internal taxonomy, which means the code you see in your dashboard is the code the network issued, and you can look it up in the rules directly. Note that doc.haipay.net does not currently host a chargeback code list — it carries error_response_appendix and cashin_code_list.

Scripts for your support team

Four situations, four openings. Adapt the voice; keep the structure. Every one of these describes mechanism and next steps only — none of them promises an outcome, and none should.

1. Customer says they do not recognize the charge.

"Thanks for flagging this. The charge on your statement appears as [descriptor] — that's us. It was for [product] on [date], on a card ending [last four]. If that doesn't match anything you recognize, tell me and I'll refund it now rather than have you go through your bank, which takes longer for both of us."

2. Customer has already filed a dispute.

"I can see the dispute your bank opened. Once it's filed, the process runs on your bank's timetable and the card network's rules, so I can't cancel it from my side. [template script] What I can do is share the records we have. If you'd rather withdraw it and take a refund directly, contact your bank — that's usually faster."

3. Subscription customer disputes a renewal.

"That charge was the renewal on [date] for the [plan] subscription started on [date]. I've cancelled it so nothing further is charged. On the renewal itself, tell me how you'd like to handle it and I'll sort it out."

4. Internal handoff on a dispute you plan to answer.

"Dispute condition [code], category [10/11/12/13]. Response stage: [exists / does not exist for this category]. Deadline: [date], counted from the [event] Processing Date of [date], excluding that date. Records attached: [list]. Records missing: [list]."

Sources

Every rule statement above is cited inline by section and rule ID so you can check it yourself. These are the documents those citations point to.

The rules belong to the card networks. We describe them and point you at the primary text; where our reading and your acquirer's differ, your acquirer's governs your account.

FAQ

  • It depends on the category. For Visa Categories 12 and 13, the Dispute Response window is 30 calendar days from the Dispute Processing Date. Categories 10 and 11 have no Dispute Response stage — the next step is a pre-arbitration attempt by the acquirer within 30 calendar days. The Processing Date of the preceding event is not counted as one day. (Visa Core Rules, Tables 11-1 and 11-2, April 2026 edition.)

Related HaiPay surfaces

  • Reason codes

    Chargeback Reason Codes

    Every Visa dispute condition by category, with what each one requires from a merchant.

  • Refunds

    Chargeback vs Refund

    Two different instruments with different costs. When to refund and when to answer.

  • Authentication

    3-D Secure for Merchants

    What authentication changes about fraud disputes, and the friction it adds.

  • Declines

    Credit Card Decline Codes

    Decline patterns often precede dispute patterns. How to read them.

  • Classification

    MCC Codes

    How your merchant category code is assigned and where it affects risk handling.

Need help mapping your payment stack?

Talk to HaiPay about acquiring, orchestration, local methods, and payout workflows.

Contact us