The dispute with no order snapshot
A cardholder disputes a purchase weeks after delivery. The team has a successful payment status but no order snapshot or delivery event. The success status shows that a provider processed the payment; it does not show what was bought or delivered. Evidence must be captured while each step happens.
Capture facts at each step
Record the payment ID, order ID, approved amount, customer action, event time, provider response, and delivery proof. Keep the source event and a normalized record. Use server time for internal events and retain the provider timestamp separately.
Protect the record from later edits
Limit write access, log changes, and store original provider messages in protected storage. OWASP says application logs can support audit trails and investigations, but incoming events from another trust zone can be forged or changed. Verify their source before using them as evidence.
Build a dispute timeline
Make one export that joins payment, fulfillment, refunds, and support contacts by stable IDs. Mark missing events as missing. Test the export with a sample case so staff can find proof without broad access to customer data.
Record provenance for each item
For each export field, state its source: provider event, checkout snapshot, delivery system, refund journal, or staff note. Keep source time and export time separate. A staff note added after a dispute is useful context, but it must not appear as a fact captured at checkout. Mark missing records as missing rather than reconstructing them from a later customer profile. The packet should have a manifest of file IDs and hashes so a second reviewer can compare it with retained originals.
Select evidence for the dispute
Open a case with dispute ID, transaction reference, reason, response deadline, owner, and next action. Use the deadline shown by the provider for that case. A delivery record answers a non-delivery claim; an approval record answers a claim about authorization; a provider refund result answers a missing-refund claim. Include the records that support the disputed fact and mark missing records plainly.
For order O-44, build an index with item ID, source system, capture time, file digest, and the claim it supports. A digest lets a reviewer compare an export with a protected original. It does not prove that delivery happened or that the original record was honest. Case PAY-05 edits the live order after the snapshot; the export must preserve the earlier version and show the later edit with its own time.
Paystack links evidence upload to the dispute ID and transaction reference. Check both before upload and save the submitted file ID and receipt. Test an expired upload URL and a rejected upload; both need a visible open task before the case deadline. Evidence integrity helps the review, but it cannot guarantee the dispute outcome.
Evidence to retain
Keep the protected order snapshot, authenticated provider event, delivery record, refund history, and export audit event. Use the verification method documented for that provider. Note any missing fact in the dispute timeline.
Sources
Put this into practice
Take one closed order and try to build its timeline today. The missing records tell the team what to capture at the next payment. See our third-party vendor risk and payment gateway testing service. To check a live flow, request a security review.