A chargeback packet travels from merchant to acquirer to card scheme, and sometimes to the issuing bank — each link needs a different slice of it, and together they would see everything. PCI DSS v4.0 draws two hard lines on the bundle: no sensitive authentication data (Req. 3.3) and no full PAN where a truncated one will do (Req. 3.4). Where the disputed purchase was made on a credit card between £100 and £30,000, Consumer Credit Act 1974 s.75 makes the card issuer jointly liable alongside the retailer — a fact that shapes what evidence actually matters. Under the Payment Services Regulations 2017, a customer generally has up to thirteen months from the debit date to flag an unauthorised transaction, and an unresolved dispute can be referred to the Financial Ombudsman Service.
When this applies
An online retailer receives a chargeback over a disputed delivery. The evidence bundle includes the delivery note, the order email, the customer's IP address, and — by accident — the full card number from the payment confirmation. That last item does not belong in the packet.
How anonym.plus handles it
- Open the bundle in anonym.plus on your device.
- Local OCR reads scanned slips and printed emails.
- The tool flags card digits, names, and contacts.
- Keep the order ID and proof-of-delivery you cite.
- Swap or black out the confirmed items.
- Save the clean files locally.
What you need to provide
- The packet (PDF, image, DOCX).
- An operator (Replace keeps the evidence readable).
- Optional batch for a multi-page bundle.
PII & financial identifiers detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Account | CREDIT_CARD | ending 1111 → [CARD] |
| Names | PERSON | buyer Hughes → [BUYER] |
| Contact | EMAIL_ADDRESS | hughes@example.co.uk → [EMAIL] |
| Location | LOCATION | delivery address → [ADDRESS] |
| Amount | MONEY | £219.00 → [AMOUNT] |
| Dates | DATE_TIME | order date → [DATE] |
Compliance achieved
- Keeps sensitive authentication data out of the bundle, per PCI DSS v4.0 Req. 3.3.
- Supplies the card number only in the truncated form Req. 3.4 allows, so the chain never sees the full PAN.
- Keeps the order ID and delivery proof the case needs, relevant where Consumer Credit Act 1974 s.75 ties the issuer's liability to the underlying purchase.
- Keeps the transaction reference intact so the case stays traceable within the Payment Services Regulations 2017 notification window.
- Offline handling keeps the evidence off any server.
Anonymise chargeback packets offline — see plans & start free →
Limitations & cautions
A bundle often mixes scans and native files, so OCR may miss a digit on a weak image. Review the flags before you submit. The tool does not judge the merits of a dispute.
Frequently asked questions
Will the order ID survive the pass?
Yes. Allow-list the order ID and delivery proof so they stay while card and customer fields are removed. Those are usually the facts that decide a chargeback, not the buyer's full card number or address.
Why does s.75 of the Consumer Credit Act matter to a chargeback?
Where a purchase between £100 and £30,000 was made on a credit card, s.75 makes the card issuer jointly and severally liable with the retailer for a breach of contract or misrepresentation. That shared liability is often the reason a card issuer, not just the retailer, ends up reviewing the same evidence bundle.
What if the customer disputes it well after the sale?
Under the Payment Services Regulations 2017, a customer generally has up to thirteen months from the debit date to report an unauthorised transaction, and can refer an unresolved complaint to the Financial Ombudsman Service. Keep the transaction reference and date legible so the case stays traceable throughout that window.