The email says a customer has disputed an order. You open it, and the money is already gone from your next payout, along with a fee. Shopify chargebacks land this way for every merchant on Shopify Payments, and the questions come in the same order every time: what does this cost, can I win it, and how do I stop the next one.
The first two have short answers. The third is where most of the advice goes wrong, because Shopify's fraud analysis and Shopify Protect look at orders, and the person filing your third chargeback this quarter is not an order.
What happens when the chargeback lands
The cardholder's bank opens the dispute, Shopify passes it to you, and two amounts leave your balance at once. The disputed order total is withdrawn immediately and the chargeback fee is deducted on top: $15 USD in the United States, £10 GBP in the United Kingdom, $25 AUD in Australia, and €15 EUR in most of the EU, per the per-country table on Shopify's chargeback process page.
The fee comes back if you win. Shopify's wording on that page is direct: "If you win the chargeback, then the fee is returned to you." The overview page hedges that this "might" depend on your country or region, so if you are outside the US, check your payout history after your first win rather than assume.
You then get a window to respond. Shopify describes it as usually 7 to 21 days. The card network sets it, and the deadline shown in your admin is the one that counts. Miss it and the cardholder wins by default.
Evidence is one shot. Shopify's resolve-a-chargeback page says: "After evidence is submitted, you can't make changes or provide additional information." The issuer then reviews, which Shopify says can take up to 75 days.
So the true cost of a lost $120 chargeback is the $120, the fee, the product and postage you already sent, and the hour you spent on evidence the bank did not read. That arithmetic is why "fight everything" is bad advice.
Reading the fraud analysis panel for what it is
Every credit card order on Shopify gets a fraud analysis with a low, medium, or high recommendation. Shopify says the recommendation comes from machine learning "trained on historical transactions across all Shopify stores," and its fraud analysis documentation lists the indicators: whether the card passed AVS, whether the CVV was correct, details about the IP address, and whether the customer tried more than one card.
Each of those is a check on one order. What each is computed from tells you what a repeat offender has to change to pass it.
AVS match. The issuer compares the billing street number and postal code to the address on file. A stolen card bought with the cardholder's billing address attached passes on the first try. A friendly-fraud buyer using their own card always passes.
CVV match. Full card dumps include it. Your own card obviously includes it.
IP distance from shipping address. Shopify's fraud prevention guidance suggests mapping billing and shipping addresses to eyeball the distance. The IP side is trivial to change with a residential proxy, and the honest cases that trip it, a gift to a relative or an order from a work VPN, are the ones you least want to cancel.
Payment attempts. Multiple cards on one checkout is a strong signal for card testing and a weak one for a person who mistyped their expiry. It says nothing about a buyer who paid cleanly and will dispute in six weeks.
Prior orders and email risk. This is the only person-shaped indicator on the panel, and it keys on the email. A new Gmail address has no history. That is the whole problem.
The panel is a chargeback risk estimate for this order, computed mostly from this order. "Cancel every high-risk order" treats it as a verdict. It cancels the traveler and the VPN user, and it lets through the person who got flagged once, learned what tripped it, and came back with a matching billing address and a fresh email. Treat the indicator as one input into a person-level decision.
The chargebacks you can win and the ones you can't
Card networks tag every dispute with a reason code, and the code decides what evidence the issuer will look at. The ones that dominate ecommerce are the fraud codes: Visa 10.4, "Other Fraud, Card-Absent Environment," described in Chargebacks911's reason code reference, and Mastercard 4837, "No Cardholder Authorization." Both mean the cardholder claims they did not make this purchase.
Shopify surfaces these as "fraudulent" or "unrecognized" in the admin. Its reasons page recommends the same four things for both: the date and time the order was fulfilled, the billing information the customer used, the IP address and country, and shipping and tracking information.
Read what the issuer is being asked to decide. For a fraud code, the question is whether the cardholder participated. A screenshot of your refund policy does not speak to that. Tracking that shows delivery to the AVS-matched billing address, with a signature, does. So does a history of prior orders from the same person that were never disputed.
That last point is now a formal rule. Under Visa's Compelling Evidence 3.0, laid out in Visa's merchant readiness guide, a merchant can answer a 10.4 dispute by showing two prior undisputed transactions from the same cardholder, between 120 and 365 days old, that share at least two data elements with the disputed order. The elements are user ID, IP address, shipping address, and device ID, and one of the two matches must be the IP or the device. Email is not on the list. Visa built its friendly-fraud defense on the keys that survive a new account.
Now the honest part. A fraud-code chargeback on an order you shipped without tracking, or with tracking to an address that does not match billing, is not winnable in any useful sense. The issuer has a cardholder attestation on one side and nothing on the other. Spend that hour on the disputes where you have delivery proof, and accept the rest quickly.
The non-fraud codes are a different fight. "Product not received" turns on the delivery scan. "Credit not processed" turns on whether you can show when the customer saw the refund policy. "Subscription canceled" turns on cancellation logs. These are winnable with paperwork, and losing them usually means the paperwork was missing.
Building the evidence submission
You get one submission and the reviewer at the bank has minutes, not hours. Shopify's guidance is to format documents so they can be viewed without zooming, in high contrast that prints in black and white, because some banks still receive evidence by fax. Treat it as a one-page case with exhibits.
Shopify pre-fills product details, carrier and tracking, shipping and billing address, fulfillment time, and the customer's IP and country. What you add depends on the reason code.
For fraudulent and unrecognized:
- Carrier tracking with the delivery scan, and the signature if you paid for one. Delivered-to-billing-address is the strongest line in the file.
- The AVS and CVV result in plain words: "billing postal code matched the issuer's record."
- Prior undisputed orders from the same customer, with dates, IP, and shipping address, so a CE3.0-style match is visible to the reviewer.
- Any message from the customer after the fact. A "where is my package" email from the person who later says they never ordered is decisive.
For product not received: tracking with delivery confirmation, next to the shipping address as the customer entered it.
For credit not processed and subscription canceled: the policy text, the timestamp it was accepted at checkout, and the refund or cancellation log.
The mistakes that lose winnable disputes are mundane. A wall of screenshots with no summary. The refund policy attached to a fraud code. A missed deadline because the email went to an inbox nobody watches. And the big one: fulfilling high-value orders without tracking, then discovering the order cannot be defended at all.
Shopify Protect covers orders, not people
Shopify Protect is free and worth turning on. It is also much narrower than the name suggests.
The eligibility rules, from Shopify's protected-orders page: a US store with a US Shopify Payments account, an order processed through Shop Pay, physical products only, fulfilled with tracking from a supported carrier within 7 days, and in transit within 10 days. Digital products, in-store pickup, Shop Pay Installments, and subscription renewals are out.
On an order that qualifies, Shopify covers "fraudulent" and "unrecognized" chargebacks only. Its page on chargebacks under Protect says the disputed amount and the fee are credited to you immediately and Shopify handles the dispute. It also says Protect "doesn't protect against" the other categories, so an item-not-received dispute on a protected order is yours to fight as usual.
Put those filters together. Protect applies to the Shop Pay slice of your US, physical, fast-shipped, non-subscription orders, and within that slice, to the fraud-coded disputes. For a store selling digital goods or outside the US it is zero.
And it does nothing about the buyer. Protect reimburses the loss on one order. The person who filed it can order again tomorrow with a different card, and if that one is not Shop Pay, you pay in full.
The repeat offender
The Shopify Community is full of the same story. A merchant posting as 0fficial5hop wrote "i received a lot of chargeback from same buyer please help me," putting the loss at around €4,000. In another thread, shopfy-2020 described an international customer who placed several orders and disputed them weeks after delivery. The moderator's answer in the first thread was accurate and unhelpful: the bank decides, submit your evidence.
The standard blocks fail against this person for specific reasons.
An email block fails because emails are free. A new address takes thirty seconds and resets the "prior orders" indicator to zero, which makes the second order look cleaner than the first.
An IP block fails in both directions. The offender switches networks or uses a proxy. Meanwhile the IP you blocked is a carrier-grade NAT shared by a few thousand people on the same mobile network, and you have just blocked them too. IP tells you something about the connection and nothing reliable about the person.
An address block fails because addresses are easy to vary without moving: "Apt 4" becomes "#4", or the parcel goes to a neighbor. When a poster in an older thread asked for a shared blocklist, dylanpierce gave the correct objection: "Customers move addresses and names aren't unique."
What survives a new account is what the person cannot cheaply replace. The card, represented by the processor's card fingerprint, which is stable across merchants and re-entries. The device, represented by a browser fingerprint, which has to be deliberately changed rather than logged out of. The phone number, which costs money to rotate and which most friendly-fraud buyers never rotate because they do not think of themselves as fraudsters. Link accounts on those keys and the "new" customer with the fresh Gmail is the same node in the graph as the one that cost you a fee last month. The device fingerprinting post covers the device side.
This is the mechanism Portreeve is built on. It is built for businesses running their own checkout (custom storefronts, headless Shopify, SaaS billing), not as a Shopify app, so a stock Shopify checkout cannot call it inline. Where it can be called, one request at checkout_attempt returns allow, review, or block with reason codes in under 100 ms. The identity graph links accounts across hashed keys including card fingerprint, device fingerprint, and phone, and confirmed abuse on one account marks the whole linked cluster, while IP stays a soft signal that never links accounts on its own. A review never blocks the buyer: the order proceeds, and a later deny arrives by signed webhook. When a chargeback comes in you report it through the feedback API so the next order from that cluster is scored against it. Card numbers never reach Portreeve, only the processor's card fingerprint and funding type. The verdict handling reference covers the rest.
Even on a stock Shopify checkout you can apply the same logic by hand. Tag the customer record when a chargeback lands. When a new order arrives, compare the card's last four and expiry, the phone, and the shipping address against tagged customers before you compare the email. Shopify Flow can hold fulfillment on matches for manual review. It is slower than a graph and it works.
Where to put the control
Chargebacks are a lagging indicator. The dispute arrives 30 to 90 days after the order, and the fraud analysis you looked at on day one was scored without knowledge of what that buyer did at three other stores. Whatever you build needs to score the person at the checkout attempt, keep scoring after the sale, and learn from every dispute.
Flag at checkout, block rarely. A false block costs a sale and, for a returning customer, a relationship. A false flag costs a few minutes of review. So the default for uncertain signals is to let the order through and hold fulfillment, not to decline. Reserve hard blocks for a card fingerprint or device already linked to a confirmed chargeback. That is what lets you flag aggressively without hurting real buyers.
Review after the sale, before the ship. Most of your ability to win a dispute is decided at fulfillment: tracking, signature, matching delivery address. A review step between payment and shipment is where you upgrade shipping on a flagged order, or refund and cancel a high-confidence match before product leaves the building.
Feed every chargeback back. A chargeback that only updates your bank balance is wasted data. Each one should mark the customer, the card, the device, and the phone, so the next order that shares any of them is scored against it. The chargeback fraud post goes into why the feedback loop matters more than the initial model.
Stop fighting the unwinnable ones. Accept the fraud-code dispute with no delivery proof on day one, record it, and move on. Fight the ones with tracking to a matching address, prior undisputed orders, or a customer message.
The fraud analysis panel will keep telling you about orders. Your fee is being paid to people.
If you run your own checkout and want the person-level scoring wired in, you can sign up for Portreeve on the free tier with no card required.