Why We Verify Orders When Billing and Shipping Addresses Don't Match: The Law, the Card Networks, and the Real Risk

Every so often, a customer at HAJEX pays for an order, gets the confirmation email, and then hears from us again a few hours later asking them to verify their payment before we ship. Almost every time, the reaction is the same: "I already paid. My card went through. Isn't asking for more proof after that illegal?" It's a fair question, and it deserves a real answer instead of a form-letter brush-off — so here is the full picture: what's actually happening technically, why we (and most of the online retail industry) do it, what the law and the card networks actually say, who carries the risk, and the honest pros and cons for a business like ours.

What actually happens when you pay online

When you hand your card to a cashier in a store, the cashier can look at the card, check the signature, and in some cases ask for photo ID before the sale ever completes — that's a "card-present" transaction. Online, none of that happens. Your card is never physically presented to anyone. Instead, the payment gateway checks two things: the CVV (the 3-digit code on the back) and the AVS, or Address Verification System, which compares the billing address and postal code you typed in against the address your card issuer has on file. Both checks come back as one of a handful of results — full match, partial match, or no match — and neither one actually confirms you're the real cardholder. A stolen card number and CVV are frequently sold together on fraud markets precisely because CVV alone proves nothing except that whoever is checking out has the numbers off the back of the card, stolen or not.

This is why, industry-wide, roughly 70% of all card fraud losses now come from card-not-present transactions rather than in-store swipes or taps. Online retail inherited a much weaker verification tool than physical retail ever had, and AVS/CVV mismatches — especially combined with a shipping address that's different from the billing address on file — are the single most common fingerprint of a stolen card being used to order goods before the real cardholder even notices.

Why the billing/shipping mismatch specifically gets flagged

Plenty of legitimate orders have different billing and shipping addresses — gifts, a recent move, a business ordering to a warehouse, a card registered to a rural or PO Box address. We know that, and it's exactly why a mismatch alone doesn't get an order cancelled. But it is the specific combination that fraud-scoring systems, payment processors, and our own review flag, because it's also the exact pattern a stolen card follows: order placed with someone else's card details, shipped somewhere the real cardholder has no connection to, before the theft is reported. For higher-value orders like ours — dumbbells, racks, and plates that can run into the hundreds or thousands of dollars — that pattern is worth a five-minute check before a pallet leaves the warehouse.

Why we use a third-party verification service instead of doing it ourselves

When an order is flagged, we don't ask our own staff to collect and store your government ID or card photos — we route verification through a third-party identity verification provider whose only job is confirming that the person completing checkout is genuinely the cardholder. There are two reasons for this. First, data minimization: under Canada's federal privacy law (PIPEDA), a business can collect personal information for a reasonable, disclosed purpose like fraud prevention, but it has to limit what it collects and how long it keeps it. A dedicated verification processor is built around exactly that — it confirms a match and doesn't hand us a folder of your ID photos to sit on a shared drive indefinitely. Second, it's simply safer for you: the fewer businesses holding a copy of your driver's licence, the smaller your exposure if any one of them has a data breach.

How many businesses actually do this

This is not a HAJEX-specific policy invented to slow you down. It's standard practice across online retail: roughly half of all e-commerce merchants now use a dedicated identity verification service as a core part of their fraud prevention stack, and about 55% use credit card verification services on top of that. Among merchants who've adopted these tools, roughly 80% outsource to a specialized third-party provider rather than build verification in-house, for the same data-minimization reasons above. It's common enough that most major payment processors — including the one behind our own checkout — build address-mismatch flags directly into their risk scoring by default.

Is it actually legal to ask for verification after you've paid?

Yes — and the confusion usually comes from applying in-store credit card rules to an online, card-not-present purchase, where they don't apply the same way. The rule most people have heard — "a store can't refuse a signed card just because you won't show ID" — is a face-to-face retail rule from Visa and Mastercard's card acceptance standards. It exists to stop a cashier from turning away a customer at the till over ID they're not required to check. It was never written for online orders, because there's no card being physically presented and no signature to compare in the first place.

For online transactions, Visa's own merchant rules explicitly carve out a different situation: a merchant may request additional identifying information from a cardholder, and can require it when that information is genuinely needed to complete the transaction — which shipping verification on a mismatched address squarely is. Authorization is also not the same as final settlement. When your card is authorized at checkout, the funds are placed on hold — they aren't actually captured and finalized until we fulfill the order. That gap is exactly the window every online retailer uses to catch fraud before goods and money both walk out the door, and using it isn't a violation of anything — it's the mechanism the payment system is built around.

What the card networks and banks actually require of us

This is the part most customers never see, because it's happening on our side of the transaction, not yours. Visa and Mastercard both hold merchants — not banks, not cardholders — liable for the vast majority of card-not-present fraud losses, because there's no chip or signature to shift that liability the way there is in a physical store. If a stolen card is used to buy from us and the real cardholder disputes it later, we lose the merchandise, we lose the payment, and we're charged a chargeback fee on top of it. Both networks also track every merchant's dispute ratio: Visa's fraud-and-dispute monitoring threshold dropped from 2.2% to 1.5% as of April 2026, and card-scheme rules now require processors to keep combined fraud-and-dispute ratios under 0.5% of card-not-present volume as of January 2026. Cross that threshold too often and a merchant faces escalating fines, and eventually loses the ability to accept cards at all. Verifying a suspicious order before shipping isn't optional risk management for a business our size — it's the difference between staying able to accept Visa and Mastercard at all, and not.

Who's actually at risk here

Us, financially — a successful chargeback on a stolen-card order costs us the product, the payment, and a fee, with no recourse once the goods have shipped. The real cardholder — the person whose card was actually stolen has their name attached to a fraudulent purchase, has to dispute it with their bank, and in the meantime a stranger may have received hundreds of dollars of equipment in their name. You, if you're the one flagged — a short delay and a mildly annoying verification step, in exchange for protection if it's genuinely your card being misused by someone else. Verification exists because all three of those outcomes are worse than a five-minute check.

The honest pros and cons for us as a business

Pros: it keeps our chargeback ratio under network monitoring thresholds so we can keep accepting cards at all; it protects real cardholders whose stolen card details would otherwise ship product to a fraudster; it protects us from the direct financial loss of shipping high-value equipment against a payment that gets reversed weeks later; and outsourcing it to a third party keeps us from ever having to store your ID ourselves.

Cons: it adds friction and a delay to a small number of genuine orders — people who moved recently, who are shipping a gift, or whose card is simply registered to an old address; it costs us staff time and a per-check fee to the verification provider; and, as you're reading this article, it clearly creates confusion and occasional frustration among honest customers who feel like they're being accused of something. We think the trade-off is worth it, but we don't pretend it's free of downside on either side of the transaction.

Frequently asked questions

"Isn't it illegal to ask me for verification after my payment already went through?" No. Authorization holds funds; it doesn't finalize the sale, and no law grants a purchase immunity from a fraud review simply because a card was authorized. The face-to-face "can't require ID for a signed card" rule that people usually cite doesn't govern online, card-not-present transactions in the first place.

"My card and CVV already proved it's me — why isn't that enough?" A CVV proves whoever is checking out has the digits printed on the back of a card. It doesn't prove that person is the legitimate cardholder, because stolen card numbers are almost always sold with the CVV included. It's the weakest form of verification the payment system has, which is exactly why AVS and additional checks exist as a backstop.

"Plenty of people ship to a different address than their billing address — why single that out?" We agree, and a mismatch by itself doesn't stop an order. It's flagged because it's also the most common footprint of stolen-card fraud, not because we assume bad intent. The verification step exists to tell the two apart quickly.

"Why don't you just ask me directly instead of using a third party?" So we never have to hold a copy of your government ID ourselves. A dedicated verification provider confirms the match and minimizes what personal data either of us has to retain, which is safer for you than an untrained retail team storing ID photos on a shared drive.

"What happens if I don't want to verify?" The order is cancelled and refunded in full — nothing is shipped, and nothing is charged. We'd rather lose a sale than ship against a payment we can't confirm, in either direction.

A note from us, directly

Here's something worth saying plainly, as the people who actually run this store: one of the most common objections we hear is "my statement already shows the charge went through, so why do you need anything else from me?" We understand why that feels like proof. But here's the uncomfortable truth — that is word-for-word the same argument a scammer using a stolen card makes. A pending authorization shows up on a bank statement whether the card was used by its rightful owner or by someone who stole the number an hour earlier. From our side of the screen, a real customer saying "it's already charged, why verify" and a fraudster saying the exact same thing produce an identical-looking order: a pending transaction on a mismatched address, waiting for a decision. There is no way to tell the two apart from the words alone — that's precisely why a neutral, third-party check exists, instead of us simply taking either kind of customer's word for it.

So our honest recommendation to shoppers, anywhere, not just with us: if a legitimate business asks you to verify a flagged order through a proper, established process, that's a sign the business is protecting you and its own ability to keep operating — not a reason to get upset. Getting angry and refusing to cooperate looks, from the merchant's side, exactly like what a scammer does when asked to prove they're real. Working with a store's verification step, rather than against it, is what actually gets your order moving again quickly.

In practice, this also isn't a repeating tax on customers who've already proven themselves. When someone doesn't want to work with us on a flagged order at all, we do cancel and refund it and place that email/card on a standing verification requirement going forward. But for shoppers who do verify once, we don't make you do it again — once your identity has been confirmed against a specific ID or email, future orders on that same profile go through without a repeat check. The friction is a one-time cost of doing business safely, not a recurring inconvenience.

The bottom line

This isn't a HAJEX quirk — it's standard practice across online retail, built around real card network rules, real chargeback liability, and a payment system that was never designed to fully verify a cardholder online the way a cashier can in person. If your order gets flagged, it's a five-minute step, not an accusation, and it exists to protect you as much as it protects us.

Questions about an order or a verification request? Check our Payment Policy and FAQ pages, or reach us directly through our contact page.