Most active commenters
  • elliekelly(7)
  • theptip(3)

←back to thread

1624 points yaythefuture | 25 comments | | HN request time: 2.205s | source | bottom

Saw https://news.ycombinator.com/item?id=32261868 from a couple weeks ago and figured I'd share my own story.

3 weeks ago, I woke up to a pissed off customer telling me her payments were broken. My startup uses Stripe Connect to accept payments on behalf of our clients, and when I looked into it, I found that Stripe had decided to deactivate her account. Reason listed: 'Other'.

Great.

I contact Stripe via chat, and I learn nothing. Frontline support says "we'll look into it." Days go by, still nothing. Meanwhile, this customer is losing a massive amount of business and suffering.

After a few days, my team and I go at them from as many angles as possible. We're on the phone, we're on Twitter, we're reaching out to connections who work there / used to work there, and of course, we reach out to patio11. All of these support channels give us nothing except "we've got a team looking into it". But Stripe's frontline seems to be prohibited from offering any other info, I assume for liability reasons. "We wouldn't want to accidentally tell you the reason this happened, and have it be a bad one."

We ask: 1. Why was this account flagged? "I don't have that information" 2. What can we do to get this fixed? "I don't have access to that information. 3. Who does? "I don't have access to that information" 4. What can you do about this? "I've escalated your case. It's being reviewed."

I should mention at this point that I've been running this business since 2016, my customers have been more or less the same since then, and I've had (back when it was apparently possible) several phone conversations with Stripe staff about my business model. They know exactly who our customers are and what services we offer, and have approved it as such.

After a week of templated email responses and endless anxiety, we finally got an email from Stripe letting us know that they had reviewed the account and reactivated it. We never got a reason for why any of this had happened, despite asking for one multiple times. Oh well, still good news right? Except nope, this was only the beginning.

This morning I woke up to an email that about 35% of my client accounts had been deactivated and were "Under review", the kicker here being that one of those accounts is the same one they already reviewed last week! This is either the work of incompetent staff or (more likely) a bad algorithm. No reasonable human could make this mistake after last week's drama.

So currently, my product doesn't work for 35% of my customers. Cue torrent of pissed off customer emails.

And the best part is, this time I have an email from Stripe this time: Apparently these accounts are being flagged, despite the notes on our file, and despite the review completed literally last week, as not in compliance with Stripe's ToS. They suggest that if I believe this was done in error, I should reach out to customer support. Oh, you mean the same customer support that can't give me literally any information at all other than "We have a team looking into it"? The same customer support that won't give me any estimates as to how long it's going to take to put this fire out? The same customer support that literally looked into this a week ago and found no issues!?

I feel like I'm going crazy over here. These accounts have hundreds of thousands of dollars in them being held hostage by an utterly incompetent team / algorithm that seems to lack any and all empathy for the havoc they wreak on businesses when they pull the rug out from under them with no warning, nor for the impact they have on customers when they all of a sudden lose all ability to make money. And all that for an account that has been using Stripe for nearly 7 years without issue!

This goes so far beyond "customer support declining at scale." If lack of customer support means that critical integrations start to fail, that's not a customer support failure, that's a fundamental business failure.

Show context
vertis ◴[] No.32854986[source]
The worst part about these type of cases is not being able to get a straight answer. There is a whole subset of big tech that has taken the "you must be a fraudster therefore we can't unfuck the situation" approach to customer support.

It's an arms race with fraudsters that eventually sucks in legitimate businesses.

replies(7): >>32855290 #>>32855358 #>>32855842 #>>32855954 #>>32856643 #>>32857733 #>>32860938 #
1. elliekelly ◴[] No.32855842[source]
I hate seeing comments like this because Stripe’s hands are tied here. Anytime a bank or payment processor has frozen or shut down an account and you’re getting stonewalled it’s almost guaranteed to be an AML related issue and it’s against the law for them to tip a customer off that their account is being or might be investigated for suspicious activity. This isn’t Stripe deciding that you’re a fraudster and so you’re undeserving of help. This is Stripe doing business in compliance with the law. I’m not saying that makes it acceptable but if you’re upset about the behavior described in this post call your Senators and Representative to complain about the Bank Secrecy Act and the USA PATRIOT Act; they’re to blame for this sort of frustrating non-response.
replies(5): >>32855952 #>>32856144 #>>32856505 #>>32858101 #>>32861104 #
2. vertis ◴[] No.32855952[source]
Sure, and my experience is outside finance (more spam and fraud prevention).

Even if it is government under the hood you have to know what you're accused of. Not American so I doubt the US political system is interested in hearing from me, but I agree that's the only way of solving the deeper AML problems.

replies(1): >>32856255 #
3. theptip ◴[] No.32856144[source]
> it’s against the law for them to tip a customer off that their account is being or might be investigated for suspicious activity

What law do you think forbids this? In my experience running global payments through multiple rails, on an OFAC/risk ping you typically get a request for enhanced due diligence, which normally looks to the payee like “send me a picture of your drivers license”.

The most common result is that O Bin Laden (matching the OFAC list) is actually Oscar bin Laden; with further info you disambiguate the payee from the OFAC listed entity and are allowed to transact.

I have never encountered a reg that says you are obliged to ghost your customer.

replies(2): >>32856553 #>>32856708 #
4. elliekelly ◴[] No.32856255[source]
> Even if it is government under the hood you have to know what you're accused of.

This is exactly why the whole process is suspect. The government farms out the policing of certain financial crimes onto the financial institutions as a prerequisite for operating the business. If the government came along and froze your bank account you’d have a right to ask why and a right to get some answers. But instead the government pawns the responsibility off onto businesses and then prohibits those businesses from telling you why.

And so the BSA and Patriot Act effectively allow the government to take your property and take away your right to confront the government about why they took your property. And it’s all on merely a vague suspicion of misconduct. No proof whatsoever.

I can’t help but laugh at the irony— the federal government laundering their otherwise unconstitutional activities through the banks.

replies(2): >>32856590 #>>32857450 #
5. abigail95 ◴[] No.32856505[source]
I don't think that's accurate.

I do some payments that are ridiculously suspect but legal.

I have never been completely blackholed and given robot responses, any time a problem comes up.

Stripe is lower margin than other banks/payment providers, so they don't look very hard.

They have a very strong incentive to throw away troublesome customers, which they do.

I don't think it's right to say Stripe's "hands are tied".

They could spend more to identify false positives, but they don't.

If I used Stripe for all of my transactions I would be blocked. I know this because I have 100% confirmed this from an inside source at Stripe and at a countries central bank.

Yet somehow I have and continue to maintain accounts with other banks without breaking the law.

6. elliekelly ◴[] No.32856553[source]
The Bank Secrecy Act. And I don’t “think” it. I know it.
replies(3): >>32856645 #>>32860456 #>>32862706 #
7. abigail95 ◴[] No.32856590{3}[source]
I'm trying to understand your position here:

You think AML/KYC laws, as they currently exist, are unconstitutional?

edit:

That's a fine position to have, but it's a fringe one, and I don't think you should be offering it as a reason why Stripe does what it does that's generally accepted by everyone else.

replies(3): >>32856806 #>>32858401 #>>32864007 #
8. theptip ◴[] No.32856645{3}[source]
Which bit of the BSA?

edit: As I re-read the thread I see that I am thinking more of onboarding KYC, as opposed to this case which would be ongoing-activity investigation. So that would explain the difference in expectations here. Still interested in learning more about the regs for ongoing investigations if you have time to share!

replies(1): >>32856907 #
9. iso20022 ◴[] No.32856708[source]
In the UK at least, section 333A of the Proceeds of Crime Act 2002? (Disclaimer: not a lawyer)

See https://www.lawsociety.org.uk/topics/anti-money-laundering/t...

replies(1): >>32856788 #
10. ◴[] No.32856788{3}[source]
11. elliekelly ◴[] No.32856806{4}[source]
No. I don’t think it’s unconstitutional which is why I said “otherwise unconstitutional”. And you’re (perhaps deliberately) completely misunderstanding and conflating my two comments. I am quite confident that OP’s problems with Stripe are AML related which is not at all a “fringe” position.
replies(1): >>32860492 #
12. elliekelly ◴[] No.32856907{4}[source]
The bit at 31 USC § 5318(g)(2)(A) under the title “Notification prohibited.” FinCEN has also promulgated confidentiality rules thereunder. I don’t have a pincite for that but I believe it’s tucked amongst their record keeping rules.
replies(1): >>32868999 #
13. smsm42 ◴[] No.32857450{3}[source]
Interesting to notice the censorship of speech on social media is implemented the same way. The government does not remove undesirable information directly, instead it calls up all major platforms "for a chat" and tells them to voluntarily remove it, or face Congressional hearings and likely further unpleasantries down the road. An offer they can not refuse. Looks like they think they found a loophole in the Constitution and they are going to mine it for all the power they can get from it.
14. CogitoCogito ◴[] No.32858101[source]
Wouldn’t that only apply to investigations by e.g. Fincen? How many of these are just internal risk triggers by Stripe? Why would they have to stonewall you in those cases?

(Obviously it’s quite difficult to know the ratio of cases like these involving government investigations and those involving their own internal risk procedures.)

15. hnburnsy ◴[] No.32858401{4}[source]
Those laws certainly feel like guilty until proven innocent or in many cases, guilty no chance to prove innocence.
replies(1): >>32861645 #
16. bigiain ◴[] No.32860456{3}[source]
While this is clearly "a thing", I would be a fine bottle of wine that the OP's issue is not one of those things, and is just some dumb algorithmic or overworked fraud prevention contractor problem.

I would bet that 99.9% of the Stripe (and Paypal) horror stories that get posted almost weekly are _not_ federal money laundering or terrorism financing investigations with legal secrecy provisions imposed on the payment processor.

17. bigiain ◴[] No.32860492{5}[source]
> I am quite confident that OP’s problems with Stripe are AML related

I'm curious as to why you think that? Is this a way way more common thing than I expect? Or is "My startup uses Stripe Connect to accept payments on behalf of our clients" a raging red AML flag I don't recognise (I've never done that, so it could easily be)?

replies(1): >>32865186 #
18. matiasfernandez ◴[] No.32861104[source]
>almost guaranteed

The issue most people in this thread are talking about exists in the almost. If it was always guaranteed, then there would not be so much evidence to the contrary.

19. JetAlone ◴[] No.32861645{5}[source]
Exactly. Not fringe. Part of the normal struggle for existence.
20. numair ◴[] No.32862706{3}[source]
Unless you are a federal prosecutor, law enforcement officer, or bank executive that has actively worked on a Bank Secrecy Act case, I don't think you can authoritatively state that this sort of cowboy-style, "Move Fast and Break Things" way of blitz-scaling revenues while downscaling customer service favored by companies such as Stripe has ANYTHING to do with the Bank Secrecy Act.

If anything, I would bet that regulators would be concerned about the fact that companies such as Stripe have triggered a race to the bottom whereby underwriting has become an after-the-fact exercise that can severely damage and/or kill a high-growth SME. The old way, where you filled out a ton of paperwork, provided every bit of information possible about you and your business, and then went back and forth with a human to get approval, was a much more stable way to business. But alas, when you've got former bank governors on your payroll and political mega-PAC donors on your cap table, people don't scrutinize very much.

replies(1): >>32865001 #
21. veqq ◴[] No.32864007{4}[source]
It'd be unconstitutional, were the government in charge, without due process.
22. elliekelly ◴[] No.32865001{4}[source]
I am indeed more than qualified to “authoritatively state this”. Even by the ridiculous standards you’ve outlined. And I would be more than happy to take that bet.
replies(1): >>32865244 #
23. elliekelly ◴[] No.32865186{6}[source]
I’m confident it’s an AML issue because they’re getting stonewalled which is standard operating procedure when a Suspicious Activity Report has been filed. I don’t think using Stripe Connect is the red flag.

The thing with SARs is that they tend to be cascading as OP described. So if I (innocently and totally coincidentally) do a transaction with someone who has been flagged for suspicious activity my account might now be flagged as “higher risk” for suspicious activity and will be monitored more closely.

And, if they decide they’ve found suspicious activity in my account then everyone who does business with me is at risk of having their accounts flagged as “higher risk” for closer monitoring and so on.

And the bank isn’t allowed to tip anyone off because if any of those accounts are actually laundering money they might suddenly withdraw it and then the “lead” from the SAR is moot. It’s actually a crime to notify someone about the suspicious transaction(s). Which is why you get stonewalled.

24. numair ◴[] No.32865244{5}[source]
So you’re stating that you have been involved in a situation in which a merchant account was frozen due to circumstances involving the Bank Secrecy Act? I just want to be completely certain that this is the assertion?
25. theptip ◴[] No.32868999{5}[source]
Thanks!

For anyone following along, text at https://www.fincen.gov/resources/statutes-and-regulations/ba... > https://www.govinfo.gov/content/pkg/USCODE-2020-title31/pdf/....

This is for SARs (Suspicious Activity Reports). (At least, that's the one I've encountered before, there may be other forms too).