By Ryan Richardson · Published 8 October 2026
A buyer who genuinely paid never receives their product, or disputes a charge claiming non-delivery, and there's no clean record to settle the question either way.
Trigger delivery exclusively from the payment webhook, with the handler built to be idempotent against retried events. Deliver through a signed link rather than an attachment, on the confirmation screen immediately and by email within about a minute. Log every download or open event, with timestamp, buyer address and order ID, as a standing practice rather than something built only after a dispute happens.
Check what event currently triggers your delivery: if it's a browser reaching a thank-you page rather than a payment-provider webhook, that's the first gap. Check whether your delivery email sends the file as an attachment; if so, replace it with a signed link. Check whether you have a download log with a timestamp per purchase; if not, build one before your next dispute arrives, not after.
| Claim | Value | Source |
|---|---|---|
| Why delivery must trigger from the webhook, not a browser reaching a thank-you page | browsers close mid-transaction, and a round trip you depend on will eventually fail someone who genuinely paid | THE BOOK FULL.md Piece 16, line 1794 |
| Why email attachments are the wrong delivery mechanism | delivering as an email attachment loses both the delivery record and the signal needed to know whether someone opened it | Measured in Real Money, Field Manual |
| What the download log should capture and why | every download or open event with a timestamp, buyer address and order id; the difference between a defensible dispute and a lost one | Measured in Real Money, Field Manual |