A chargeback is not a refund requested from the merchant. It is a reversal initiated by the customer's bank, and the merchant learns about it after the money has gone.
The process begins with the issuer
A cardholder disputes a transaction with the bank that issued the card. That bank assesses the claim against network rules and, if it accepts it, debits the acquirer.
The acquirer recovers the amount from the merchant, usually immediately and often with a handling fee attached. The funds are withdrawn before any defence has been heard.
The merchant is therefore in the position of reclaiming money already taken, rather than defending a payment it still holds.
Reason codes determine the evidence needed
Every dispute carries a code describing the alleged problem: goods not received, goods not as described, a duplicate charge, or a transaction the cardholder did not authorise.
Each code has a different evidentiary standard. Proof of delivery answers a non-receipt claim and does nothing for one alleging the item was faulty.
Responses that submit generic documentation fail routinely, not because the merchant was wrong, but because the material did not address the specific code.
Deadlines are strict and short
Network rules set fixed windows for each stage. A merchant that misses the response deadline loses automatically regardless of the underlying facts.
Because notification travels through the acquirer, the usable time is shorter than the published window. Delay at any intermediate step consumes the merchant's share.
Rules, time limits and available stages differ between card networks and by jurisdiction, and they are revised periodically.
Fraud liability depends on the authentication used
For remote transactions, liability for unauthorised use commonly rests with the merchant rather than the issuer, which is the opposite of in-person card use.
Where additional cardholder authentication has been applied, that liability can shift back toward the issuer. The precise allocation is governed by scheme rules and local regulation.
This is why authentication requirements, however much friction they add at checkout, materially change who bears the loss on a disputed sale.
Rates matter beyond the individual loss
Acquirers and networks monitor the ratio of disputes to transactions. Merchants exceeding thresholds enter monitoring programmes with additional fees and remediation requirements.
Persistent breaches can end in the loss of card acceptance, which for an online business is equivalent to closing.
Which is why prevention work, clear descriptors, responsive customer service and accurate delivery tracking, is usually worth more than winning individual cases.