Paayed Beta is live! Beta users are by invite only | Thank you for being part of our early access program.

Fraud & Security

Everything you need to know about protecting your business from fraud, managing disputes, and keeping your account secure.

Paayed uses multiple layers of security to protect every transaction you process.

PCI DSS compliance

Paayed is certified PCI DSS Level 1 compliant. This means all card data is encrypted, tokenised, and stored securely. Your business never handles raw card numbers.

3D Secure authentication

All online transactions are protected by 3D Secure 2 (3DS2). This adds an extra verification step for the cardholder, reducing fraud and shifting liability away from your business.

Real-time fraud screening

Every transaction passes through Paayed’s fraud detection engine before it is processed. Suspicious transactions are flagged or blocked automatically based on risk signals.

A chargeback occurs when a cardholder disputes a transaction with their bank. The disputed amount is temporarily reversed while the case is investigated.

How chargebacks work

  1. The cardholder contacts their bank to dispute a charge
  2. The bank notifies Paayed and debits the disputed amount from your next settlement
  3. You receive a notification in your Paayed dashboard with details of the dispute
  4. You have 14 days to submit evidence defending the transaction
  5. The bank reviews the evidence and makes a decision

Common chargeback reasons

  • Fraudulent: The cardholder says they did not authorise the transaction
  • Product not received: The customer claims they did not receive the goods or service
  • Not as described: The product or service did not match what was advertised
  • Duplicate charge: The customer was charged more than once

Submitting strong evidence is the best way to win a chargeback dispute.

Viewing disputes

Go to Disputes in your dashboard. Each dispute shows the transaction details, reason code, deadline for response, and current status.

Submitting evidence

  1. Click Respond on the dispute
  2. Upload supporting documents: receipts, delivery confirmations, customer correspondence, signed contracts
  3. Add a written explanation of the transaction
  4. Click Submit before the deadline

Best evidence to include

  • Proof of delivery (tracking number, signed receipt)
  • Customer communication showing they authorised the purchase
  • Your terms and conditions or refund policy
  • Screenshots of the order confirmation sent to the customer

Paayed’s fraud engine applies rules to every transaction to identify and block fraudulent payments.

Built-in rules

  • Velocity checks: Blocks multiple rapid transactions from the same card
  • Geographic mismatch: Flags transactions where the card country differs from the IP address country
  • BIN checks: Identifies high-risk card issuer patterns
  • Amount thresholds: Flags unusually large transactions for manual review

Custom rules

Contact Paayed support to configure custom fraud rules for your business. For example, you can set maximum transaction amounts, restrict certain countries, or require 3DS for all transactions above a threshold.

Protect your Paayed account with strong authentication and access controls.

Two-factor authentication (2FA)

Enable 2FA in Settings > Security. Once enabled, you will need to enter a code from your authenticator app each time you log in. All team members should enable 2FA.

Strong passwords

Use a unique password of at least 12 characters with a mix of letters, numbers, and symbols. Do not reuse passwords from other services.

Session management

Paayed automatically logs you out after 30 minutes of inactivity. You can view and revoke active sessions in Settings > Security > Active Sessions.

Control what each team member can see and do in your Paayed account.

Available roles

  • Owner: Full access to all features, settings, and billing
  • Admin: Full access except billing and account deletion
  • Manager: Can process payments, manage invoices, and view reports
  • Staff: Can process payments and view transactions only
  • View Only: Can view dashboard and reports but cannot take any actions

Managing team members

Go to Settings > Team to invite new members, change roles, or remove access. Changes take effect immediately.

Activity logging

All actions taken by team members are logged in Settings > Activity Log with the user’s name, action, and timestamp.

Paayed handles all sensitive card data so your business does not have to.

Tokenisation

When a customer enters their card details, Paayed immediately tokenises the data. The token is a random string that represents the card but cannot be used to reconstruct the card number. Your systems never store or process raw card data.

Encryption

All data transmitted between your customer’s browser and Paayed’s servers is encrypted using TLS 1.2 or higher. Card data at rest is encrypted using AES-256.

Your PCI obligations

Because Paayed handles card data on your behalf, your PCI compliance requirements are minimal. You need to ensure your website uses HTTPS and that you do not store card details in your own systems (emails, spreadsheets, databases).

Friendly fraud occurs when a legitimate customer makes a purchase and then disputes the charge with their bank.

Common scenarios

  • The customer forgot about the purchase
  • A family member made the purchase without their knowledge
  • The customer wants a refund but contacts their bank instead of you
  • The customer received the goods but claims they did not

Prevention strategies

  • Clear billing descriptor: Set your business name as the billing descriptor in Settings > Business Profile so customers recognise charges on their statement
  • Order confirmations: Send immediate email confirmations with order details
  • Delivery tracking: Use tracked delivery for physical goods
  • Easy refund process: Make it simple for customers to request refunds directly, reducing the incentive to file a chargeback

Paayed monitors your account for unusual patterns and alerts you when something looks wrong.

Alert types

  • Unusual transaction volume: A sudden spike in transactions compared to your normal pattern
  • High-value transaction: A single transaction significantly above your average
  • Multiple declined cards: Several failed attempts from the same IP address
  • New device login: A team member logs in from an unrecognised device or location

How alerts are delivered

Alerts are sent via email and appear as notifications in your Paayed dashboard. Critical alerts (such as suspected account compromise) are also sent via SMS if you have a phone number on file.

Responding to alerts

Review each alert in your dashboard. You can mark it as resolved, block the flagged card, or contact Paayed support for assistance.

Protect your business from customers who abuse the refund process.

Warning signs

  • Repeated refund requests from the same customer
  • Claims of non-delivery despite tracking showing delivery
  • Requests to refund to a different card or account
  • Purchasing high-value items and immediately requesting refunds

Paayed safeguards

Refunds are always returned to the original payment method. Paayed does not allow refunds to be redirected to a different card or bank account.

Refund policies

Display your refund policy clearly on your website and include it in your invoice terms. A clear policy helps you defend against unjustified chargeback claims.

Paayed is fully compliant with UK GDPR and the Data Protection Act 2018.

What data Paayed stores

  • Customer name and email (for invoicing and receipts)
  • Tokenised card data (not the actual card number)
  • Transaction records (amount, date, status)
  • Your business details and team member accounts

Data access requests

If a customer requests access to their data under GDPR, you can export their transaction history from Customers > [Customer Name] > Export Data.

Data deletion

Customer records can be deleted on request, subject to legal retention requirements. Financial transaction records must be retained for 7 years under UK law, but personal identifiers can be anonymised.

Data processing agreement

A Data Processing Agreement (DPA) is available in Settings > Legal for your records.