u/Realistic-Ad452

Stripe closed my 6 week old lodging business citing risky payments. The "risky payments" were declines its own risk system generated on my verified guests. Full dated timeline + what I'd do differently.

One lost $750 chargeback led to my payment processor closing my six week old lodging business's account, holding my guests' money past its own written deadline, and then telling me it couldn't release funds it had already refunded. Full timeline, and what I would do differently.

TL;DR: Six week old lodging business. One $750 deposit chargeback lost on an AVS mismatch. Four days later an automated risk intervention was added on top of the normal fraud screening. The normal screening had already caught the real fraud on its own. The intervention blocked only verified guests, one of them about fifteen times, and nothing else. Stripe refused in writing to override it, then closed the account citing high risk activity from those blocks. Pulled a service member's already paid out booking back from my bank, missed its own written refund deadline by six days, refunded the day after a BBB complaint, then sent a formal response saying it could not release funds it had already released. Same day it closed my direct application, it approved the same business through Booking.com, and that account is still open. Never a human in the loop. Not on MATCH, which is the one thing that went right. Lessons at the bottom. Short version: turn on AVS decline, never charge deposits, keep two acquirers, and do not build a small business on a rail that can be revoked by a model and appealed to a queue.

I am a Navy veteran and I own a small guest house in Tampa, Florida. Five rooms. I launched in mid June and take bookings through Airbnb, Booking.com, Expedia, Vrbo, and directly. I used Stripe for the direct and Vrbo side.

July 17. A guest who had stayed for five nights filed a chargeback on her $750 security deposit. I contested it with full documentation including the signed rental agreement. I lost on a single point: an AVS address mismatch on the original charge. Everything else in the file was beside the point. That was my process failure and I will come back to it, because it is lesson one.

Let me give credit first, because it matters to what comes next. Stripe's standard fraud screening, the thing every account has, worked. On July 15 it stopped a $1,600 booking attempt from the group connected to the disputed stay. On the evening of July 21 it stopped three attempts to book a $1,400 stay under a name that matched a felony record. Real fraud, correctly blocked, by the normal system, on its own. That is what it is for and it did its job.

July 21. Later that same day, my account was placed under an additional automated risk intervention, layered on top of the screening that was already working. Here is the thing I want other owners to understand about that layer: from the moment it was applied, it did not block a single fraudulent transaction. Every block it produced was a verified guest.

July 22 and 23. It blocked a verified Airbnb guest, already in my house, trying to pay a $300 security deposit. He tried about fifteen times across three cards. Every attempt was blocked. The next day it blocked another Airbnb guest, in town for the bar exam, trying to pay the same deposit. These were not risky transactions. They were guests with confirmed reservations paying for rooms they were standing in. The fraud had already been caught. The intervention had nothing left to catch except my customers.

July 24. I asked for the intervention to be reviewed. Stripe confirmed in writing that it would not be overridden.

July 28. The account was closed, citing "elevated high risk payment activity." Stripe also pulled $1,376.96 back out of my bank account: the proceeds of an active duty Coast Guard officer's booking that had already been paid out to me. Here is the part I want other owners to sit with: the high risk activity included the declines the intervention had itself generated on my verified guests. The system blocked good customers, then cited those blocks as evidence. There was no person anywhere in that loop, and I could not get one inserted.

The closure notice said refunds on affected payments would be issued five days after processing stopped. That made the deadline August 2.

August 1. Two things happened the same day that I still cannot reconcile. Booking.com's payments onboarding opened a brand new Stripe account for this same business, with identical information, and it passed. I then opened an account directly on stripe.com with the same information, and it was closed within hours as high risk. Same business, same documents, same day, two opposite answers. As I write this on August 17, the Booking.com one is still open and green.

August 2. The refund deadline passed. Nothing was refunded.

August 7. The Coast Guard officer, whose $1,418.70 stay had been force refunded by the closure and who had rebooked through Airbnb, contacted me asking where his money was. Ten days after Stripe had taken it back out of my account to refund him, he still did not have it. I had no ability to refund him and no date to give him. Stripe's own support chat that day told me his two charges and a third guest's $300 deposit, $1,697.96 in total, "should have been automatically refunded" under the closure process. It could not tell me why they had not been. I filed a BBB complaint that afternoon.

August 8. All three refunds were issued. The day after the complaint. Eleven days after the closure. Six days past the deadline in their own notice.

August 12. I tried to register on a venue rental platform for a different part of the business and was blocked. That platform runs on Stripe underneath. I had not known that. It was resolved a couple of days later, but for two days an unrelated line of business was closed to me by a decision I could not appeal.

August 14. Stripe's formal response arrived. It restated the reason as payments that "did not appear to have been authorized by the customer." It said Stripe was "unable to release these funds as of now." The funds had been refunded six days earlier. It also said, and this is the one sentence in the whole saga that mattered most: I was not added to MATCH, the card network list that makes a business effectively unbankable for five years. If you ever end up here, ask that question first and get the answer in writing before you do anything else.

August 17. I was told the position is firm and they will not engage further. So I have stopped asking. I am writing it down instead.

What I would tell another small business owner, in the order it would have saved me money:

1. Turn on decline for AVS mismatch. Today. I lost a dispute I should have won, with a signed agreement in the file, on that single field. I learned the rule existed after I lost. It costs you a handful of legitimate transactions a year and it is the whole ballgame on disputes.

2. Never take a security deposit as a charge. Take a hold, or sell a damage waiver. A charged deposit is the transaction most likely to be disputed, and if you lose, it starts the sequence below.

3. Understand the loop. One lost dispute can trigger automated risk treatment on top of the fraud screening you already have. In my case the screening had already caught the fraud; the treatment caught only good customers. Its declines on those customers were then cited as the risk that closed me. There does not have to be a human anywhere in the chain, and asking for one goes to the same queue.

4. Have two payment rails at two different acquirers before you need them. I had one. When it went, my direct channel and Vrbo went with it, and so did a platform I did not know was built on it. If you are on a payment facilitator, understand that your account can be revoked instantly and that a "final response" can arrive that says funds are held when they have already been refunded.

5. The balance is not yours until it is in your bank. Sweep daily if you can. Do not let a float build.

6. Everything in writing. Save it offline as you go. Chat transcripts, emails, the closure notice with its refund promise. That refund promise and a support chat admission are what moved $1,697.96 in one day after nothing else had.

7. Public and regulatory channels work when support does not. Not an accusation, just what happened: the refunds landed the day after a BBB complaint. Nothing before that moved anything.

I am not asking anyone for anything here. My guests were made whole, which was the part that actually mattered, and my business runs today on channels that pay me directly.

But I will say the conclusion plainly, because it is the reason I wrote this. We will not use Stripe again, for this business or any other we operate, under any circumstances, regardless of what any future review says. Not because of one bad outcome. Because of the shape of it. A processor that lets a model take an action, declines to let a person review it, cites the model's own output as the reason, misses its own written deadline, and then issues a final response saying it cannot release funds it released six days earlier is not a partner that supports its merchants.

For a small business, that is not a risk you manage. It is one you remove.

If you are small and you are on Stripe, I am not telling you to leave. I am telling you to open the second account today, sweep your balance daily, turn on the AVS rule, and read your closure terms now, while you can still do something about them. Do it before you need it. I did it after.

reddit.com
u/Realistic-Ad452 — 3 days ago
▲ 4 r/stripe

Stripe closed my 6 week old lodging business citing risky payments. The "risky payments" were declines its own risk system generated on my verified guests. Full dated timeline + what I'd do differently.

One lost $750 chargeback led to my payment processor closing my six week old lodging business's account, holding my guests' money past its own written deadline, and then telling me it couldn't release funds it had already refunded. Full timeline, and what I would do differently.

TL;DR: Six week old lodging business. One $750 deposit chargeback lost on an AVS mismatch. Four days later an automated risk intervention was added on top of the normal fraud screening. The normal screening had already caught the real fraud on its own. The intervention blocked only verified guests, one of them about fifteen times, and nothing else. Stripe refused in writing to override it, then closed the account citing high risk activity from those blocks. Pulled a service member's already paid out booking back from my bank, missed its own written refund deadline by six days, refunded the day after a BBB complaint, then sent a formal response saying it could not release funds it had already released. Same day it closed my direct application, it approved the same business through Booking.com, and that account is still open. Never a human in the loop. Not on MATCH, which is the one thing that went right. Lessons at the bottom. Short version: turn on AVS decline, never charge deposits, keep two acquirers, and do not build a small business on a rail that can be revoked by a model and appealed to a queue.

I am a Navy veteran and I own a small guest house in Tampa, Florida. Five rooms. I launched in mid June and take bookings through Airbnb, Booking.com, Expedia, Vrbo, and directly. I used Stripe for the direct and Vrbo side.

July 17. A guest who had stayed for five nights filed a chargeback on her $750 security deposit. I contested it with full documentation including the signed rental agreement. I lost on a single point: an AVS address mismatch on the original charge. Everything else in the file was beside the point. That was my process failure and I will come back to it, because it is lesson one.

Let me give credit first, because it matters to what comes next. Stripe's standard fraud screening, the thing every account has, worked. On July 15 it stopped a $1,600 booking attempt from the group connected to the disputed stay. On the evening of July 21 it stopped three attempts to book a $1,400 stay under a name that matched a felony record. Real fraud, correctly blocked, by the normal system, on its own. That is what it is for and it did its job.

July 21. Later that same day, my account was placed under an additional automated risk intervention, layered on top of the screening that was already working. Here is the thing I want other owners to understand about that layer: from the moment it was applied, it did not block a single fraudulent transaction. Every block it produced was a verified guest.

July 22 and 23. It blocked a verified Airbnb guest, already in my house, trying to pay a $300 security deposit. He tried about fifteen times across three cards. Every attempt was blocked. The next day it blocked another Airbnb guest, in town for the bar exam, trying to pay the same deposit. These were not risky transactions. They were guests with confirmed reservations paying for rooms they were standing in. The fraud had already been caught. The intervention had nothing left to catch except my customers.

July 24. I asked for the intervention to be reviewed. Stripe confirmed in writing that it would not be overridden.

July 28. The account was closed, citing "elevated high risk payment activity." Stripe also pulled $1,376.96 back out of my bank account: the proceeds of an active duty Coast Guard officer's booking that had already been paid out to me. Here is the part I want other owners to sit with: the high risk activity included the declines the intervention had itself generated on my verified guests. The system blocked good customers, then cited those blocks as evidence. There was no person anywhere in that loop, and I could not get one inserted.

The closure notice said refunds on affected payments would be issued five days after processing stopped. That made the deadline August 2.

August 1. Two things happened the same day that I still cannot reconcile. Booking.com's payments onboarding opened a brand new Stripe account for this same business, with identical information, and it passed. I then opened an account directly on stripe.com with the same information, and it was closed within hours as high risk. Same business, same documents, same day, two opposite answers. As I write this on August 17, the Booking.com one is still open and green.

August 2. The refund deadline passed. Nothing was refunded.

August 7. The Coast Guard officer, whose $1,418.70 stay had been force refunded by the closure and who had rebooked through Airbnb, contacted me asking where his money was. Ten days after Stripe had taken it back out of my account to refund him, he still did not have it. I had no ability to refund him and no date to give him. Stripe's own support chat that day told me his two charges and a third guest's $300 deposit, $1,697.96 in total, "should have been automatically refunded" under the closure process. It could not tell me why they had not been. I filed a BBB complaint that afternoon.

August 8. All three refunds were issued. The day after the complaint. Eleven days after the closure. Six days past the deadline in their own notice.

August 12. I tried to register on a venue rental platform for a different part of the business and was blocked. That platform runs on Stripe underneath. I had not known that. It was resolved a couple of days later, but for two days an unrelated line of business was closed to me by a decision I could not appeal.

August 14. Stripe's formal response arrived. It restated the reason as payments that "did not appear to have been authorized by the customer." It said Stripe was "unable to release these funds as of now." The funds had been refunded six days earlier. It also said, and this is the one sentence in the whole saga that mattered most: I was not added to MATCH, the card network list that makes a business effectively unbankable for five years. If you ever end up here, ask that question first and get the answer in writing before you do anything else.

August 17. I was told the position is firm and they will not engage further. So I have stopped asking. I am writing it down instead.

What I would tell another small business owner, in the order it would have saved me money:

1. Turn on decline for AVS mismatch. Today. I lost a dispute I should have won, with a signed agreement in the file, on that single field. I learned the rule existed after I lost. It costs you a handful of legitimate transactions a year and it is the whole ballgame on disputes.

2. Never take a security deposit as a charge. Take a hold, or sell a damage waiver. A charged deposit is the transaction most likely to be disputed, and if you lose, it starts the sequence below.

3. Understand the loop. One lost dispute can trigger automated risk treatment on top of the fraud screening you already have. In my case the screening had already caught the fraud; the treatment caught only good customers. Its declines on those customers were then cited as the risk that closed me. There does not have to be a human anywhere in the chain, and asking for one goes to the same queue.

4. Have two payment rails at two different acquirers before you need them. I had one. When it went, my direct channel and Vrbo went with it, and so did a platform I did not know was built on it. If you are on a payment facilitator, understand that your account can be revoked instantly and that a "final response" can arrive that says funds are held when they have already been refunded.

5. The balance is not yours until it is in your bank. Sweep daily if you can. Do not let a float build.

6. Everything in writing. Save it offline as you go. Chat transcripts, emails, the closure notice with its refund promise. That refund promise and a support chat admission are what moved $1,697.96 in one day after nothing else had.

7. Public and regulatory channels work when support does not. Not an accusation, just what happened: the refunds landed the day after a BBB complaint. Nothing before that moved anything.

I am not asking anyone for anything here. My guests were made whole, which was the part that actually mattered, and my business runs today on channels that pay me directly.

But I will say the conclusion plainly, because it is the reason I wrote this. We will not use Stripe again, for this business or any other we operate, under any circumstances, regardless of what any future review says. Not because of one bad outcome. Because of the shape of it. A processor that lets a model take an action, declines to let a person review it, cites the model's own output as the reason, misses its own written deadline, and then issues a final response saying it cannot release funds it released six days earlier is not a partner that supports its merchants.

For a small business, that is not a risk you manage. It is one you remove.

If you are small and you are on Stripe, I am not telling you to leave. I am telling you to open the second account today, sweep your balance daily, turn on the AVS rule, and read your closure terms now, while you can still do something about them. Do it before you need it. I did it after.

reddit.com
u/Realistic-Ad452 — 3 days ago

Stripe blocked my legitimate customers from paying, told me in writing they wouldn't lift it, then closed my account for the "risk signals" those blocks created

Small boutique lodging business in Tampa — four guest rooms and a whole-home option in a historic house. Veteran-owned, licensed, first year operating. Stripe was our first and only processor, opened July 3 through our property management software.

July 17: A guest who left roughly a thousand dollars in damages disputed her $750 security deposit as "fraudulent." July 21: I lost the dispute — despite a signed rental agreement, ID on file, and photo evidence — on an AVS mismatch. So I ate the damages and the deposit.

Reasonably, I tightened my Radar settings and enabled 3DS to protect myself going forward.

July 22–23: Two legitimate Airbnb guests, on two different cards, within 24 hours, were blocked trying to pay their security deposits. Real bookings, real people, standard hospitality practice.

I contacted support asking for one thing: an override so I could collect security deposits on third-party platform bookings.

July 24, from Stripe's Risk team, verbatim:

"After a thorough review of your account, our Risk team has determined that the Dynamic Threshold Intervention (RDTI) will remain in place... certain charges... may continue to be blocked. ...we are unable to provide an override for these restrictions at this time, including for security deposits from third-party platforms such as Airbnb."

So Stripe confirmed in writing that they were blocking my legitimate customers, and that they would not stop.

July 28 — four days later — my account was closed for presenting an "unacceptable level of risk."

Here's what I can't get past: the "elevated number of high-risk payments" Stripe cited were the payments Stripe's own system was blocking. A fraudster's dispute raised my risk score, Stripe responded by blocking my real customers, those blocked charges became evidence of risk, and that evidence justified closing me.

Since then: four identical "your account will remain closed" emails. Two Dashboard appeals with EIN verification, articles of incorporation, bank statements — both rejected with no specific reason. Replies to Stripe bounce back saying "your request has not reached our support team." I have never spoken to a human.

Stripe is now reversing payments on confirmed, prepaid guest reservations for future stays — including one for a U.S. Coast Guard officer I had to personally explain this to. The closure notice states any balance remaining after reversals "will not be made available to you."

What I'm asking for:

A specific, written reason for the closure

Release of any positive balance, with an accounting of every reversal

Written confirmation of whether a MATCH/TMF listing was filed, and the reason code, so an incorrect one can be disputed

I'm not asking Stripe to keep me. I'm asking to be told what the problem was — and not to have a small business destroyed by a feedback loop between an automated risk system and a fraudster.

Happy to provide documentation. Will update if Stripe responds.

Title: Stripe blocked my legitimate customers from paying, told me in writing they wouldn't lift it, then closed my account for the "risk signals" those blocks created

Small boutique lodging business in Tampa — four guest rooms and a whole-home option in a historic house. Veteran-owned, licensed, first year operating. Stripe was our first and only processor, opened July 3 through our property management software.

July 17: A guest who left roughly a thousand dollars in damages disputed her $750 security deposit as "fraudulent." 

July 21: I lost the dispute — despite a signed rental agreement, ID on file, and photo evidence — on an AVS mismatch. So I ate the damages and the deposit.

Reasonably, I tightened my Radar settings and enabled 3DS to protect myself going forward.

July 22–23: Two legitimate Airbnb guests, on two different cards, within 24 hours, were blocked trying to pay their security deposits. Real bookings, real people, standard hospitality practice.

I contacted support asking for one thing: an override so I could collect security deposits on third-party platform bookings.

July 24, from Stripe's Risk team, verbatim:

>

So Stripe confirmed in writing that they were blocking my legitimate customers, and that they would not stop.

July 28 — four days later — my account was closed for presenting an "unacceptable level of risk."

Here's what I can't get past: the "elevated number of high-risk payments" Stripe cited were the payments Stripe's own system was blocking. A fraudster's dispute raised my risk score, Stripe responded by blocking my real customers, those blocked charges became evidence of risk, and that evidence justified closing me.

Since then: four identical "your account will remain closed" emails. Two Dashboard appeals with EIN verification, articles of incorporation, bank statements — both rejected with no specific reason. Replies to Stripe bounce back saying "your request has not reached our support team." I have never spoken to a human.

Stripe is now reversing payments on confirmed, prepaid guest reservations for future stays — including one for a U.S. Coast Guard officer I had to personally explain this to. The closure notice states any balance remaining after reversals "will not be made available to you."

What I'm asking for:

  1. specific, written reason for the closure
  2. Release of any positive balance, with an accounting of every reversal
  3. Written confirmation of whether a MATCH/TMF listing was filed, and the reason code, so an incorrect one can be disputed

I'm not asking Stripe to keep me. I'm asking to be told what the problem was — and not to have a small business destroyed by a feedback loop between an automated risk system and a fraudster.

Happy to provide documentation. Will update if Stripe responds.

Edit: does anyone know what the heck is going on with the supposed "gold standard" in payments processing? How do I avoid this in the future?

reddit.com
u/Realistic-Ad452 — 20 days ago