On this page
Use the environment to choose the first records to inspect.
TransactionRecords to inspect firstDo not overclaim
Card present: chip or tapPOS entry mode, terminal record, receipt, authorization resultA chip read is not a complete identity proof
Card present: keyed or swipedReceipt, authorization, staff notes, terminal resultA signature alone may not answer a fraud claim
Card not present: online checkoutAVS/CVV results, 3-D Secure, account history, IP/device, order and delivery recordsA matching IP or device is not the same as cardholder admission
Digital account purchaseLogin, download, access, and customer communication recordsAn access log must be tied to the disputed transaction

For an in-person transaction

Gather the transaction trail

  • Receipt showing date, amount, and items or service
  • POS record showing how the payment was captured
  • Terminal or authorization record available from your processor
  • Staff or appointment record connecting the sale to the customer
  • Any pickup, delivery, or service-completion record
  • Customer communication about the transaction or later issue

For an online transaction

Use the authorization evidence guide for payment checks and account-history evidence for digital records. Pair those signals with what happened after payment: fulfillment, delivery, account access, or support. The strongest packet answers both “was this payment authorized?” and “what did this customer do with the purchase?”

Route the case by the claim, not the technology

If the customer says they never made the purchase, lead with authorization and identity-linked records. If they recognize the purchase but dispute delivery or quality, use the corresponding reason guide. Do not bury a non-fraud answer under a pile of fraud signals.

Build an authorization packet