LatchPay

Fraud and chargebacks

How the fraud rules work

Points per rule, review at 40 (charged, then held) and decline at 80 (never charged), five recommended rules, and the opt-in automatic refunds.

Updated

Points, review, decline

Every rule that matches a checkout adds its points; the sum is the checkout's score. Two thresholds on Fraud & risk decide what happens, with recommended defaults of 40 for review and 80 for decline:

  • Review (score at or above 40): the buyer pays as usual. The Shopify order gets the tag latchpay-review and waits in the review queue until you approve or reject it. Nothing is refunded by itself.
  • Decline (score at or above 80): the checkout stops before any payment is created. The buyer sees one plain sentence, "We could not complete this payment. Please contact the store.", in their language; it never names a rule.

A rule can also force a decision on its own (Hold for review, Decline) regardless of the score; the decline score is always at least the review score.

The five recommended rules

  1. First order over an amount: 30 points

    The buyer's email never paid with you before and the order is over 1,000 in your store currency (the amount is editable).

  2. Billing country differs from shipping: 25 points

    Compared from the addresses on the checkout, and again from the card's billing country after the charge.

  3. Visitor country differs from shipping: 25 points

    The buyer's country as the hosting platform reports it at the moment of paying; unknown or placeholder countries never fire this rule.

  4. Repeat orders from one email: 40 points

    Three or more paid checkouts from the same email within 24 hours, counting this one.

  5. Previous chargeback: decline

    A dispute or pre-dispute alert exists on an earlier order of this email with you. Forced decline, 80 points.

Each rule can be switched off, given other points or another outcome, removed, or added again; Reset to recommended restores this set. A rule that forces a decision still adds its points.

When the rules run

  • At Pay now, after the final quote and before anything is reserved or charged. A decline creates no Whop payment.
  • Once more when Whop confirms the payment, with what only the payment knows (the card's billing country). A review found here holds the order; a decline found here is where the first automatic refund applies.

Automatic refunds (off by default)

Two switches, both off unless you turn them on

Refund automatically when a decline is found after the charge: LatchPay asks Whop for a full refund, once, and marks the order rejected with the tag latchpay-declined-refunded. Off: the order waits in the queue instead.

Refund automatically on an early fraud warning or pre-dispute alert: when the card issuer warns before a chargeback, LatchPay asks Whop for a full refund, once, and only up to the limit you set. A refund made in time usually stops the chargeback. Rapid-dispute-resolution alerts never trigger it.

Both need the payment:manage permission on your Whop business; without it the switches are disabled with a Re-approve on Whop link. Every automatic refund runs at most once per payment, never for more than what is left of it, and is logged on the order. Alerts found by a Sync from Whop are stored only; the refund runs on the live alert alone, so switching it on later never refunds old alerts.

What the rules look at

Only data LatchPay already holds for your store: this checkout's amount and addresses, your earlier sessions, orders and disputes for the same email, and the buyer's two-letter country from the hosting platform's header. The IP address itself is never stored, nothing is shared with a third party, and the score is used for this decision only.

Still stuck?

Tell us what you see and which store it is about. We reply by email, usually within a day.