What records might an online payment provider hold?¶
An online payment provider may hold account, transaction, device and security records that do not appear in bank or card statements.
Avoid the dangerous assumption¶
The dangerous assumption is that the visible transaction history is the provider’s complete evidential record.
Relevant account records may include customer details, account IDs, email addresses, phone numbers, verification status, linked bank accounts, cards and payment handles.
Transaction records may include amounts, currencies, sender and recipient accounts, merchant details, fees, refunds, reversals, withdrawals and internal references.
Access records may include login timestamps, IP addresses, devices, sessions, authentication methods, failed logins and security changes.
The provider may also retain funding-source records, wallet-token details, risk alerts, account restrictions, customer-support contacts, payout destinations and records of account recovery.
Internal transfers may not appear individually in linked bank records.
Preserve every known user ID, payment handle, transaction ID, email address, phone number, date range and linked account detail.
Ask the provider to explain which timestamps and statuses represent initiation, completion, reversal or withdrawal.
Where several accounts are involved, identify both sides of the transfer and the eventual external destination.
Do not assume the registered customer operated every transaction.
The account may be shared, compromised or active across several devices and sessions.
Likewise, provider verification at account opening does not prove personal use at a later time.
When reporting, separate customer registration, account access, transaction movement and personal attribution.
Operational takeaway¶
Request online payment providers for complete account, access, funding, transaction, security and withdrawal records rather than relying only on the visible account history.