Work
A 24-hour hold on the seller's share
Sellers were paid one day after each sale, so a buyer with a bad code could still be refunded.
↓
Why a code can't be refunded in kind
Once a buyer has read a code, it cannot be taken back. If the code was already used or is invalid, the only remedy is money.
The order
- Buyers paid from a prepaid balance, topped up by crypto deposit or through a payment gateway.
- Placing an order ran in one database transaction: the balance was debited, the codes marked sold, the order record created. The codes were returned in the response and emailed through a queue.
- The seller's share was credited to a pending balance, not the seller's own.
The hold
- 24 hours was set as a buffer: time for a buyer to find a bad code and raise a dispute, and for the dispute to be resolved, before the money moved.
- For those 24 hours the buyer could open one dispute on the order.
- An hourly job released pending amounts older than 24 hours. Sellers waited 24–25 hours per sale.
- Manual-delivery orders unfulfilled at 24 hours were refunded by a second job.
- A dispute had no timeout. Closing it set the order back to pending, and the next hourly run paid the seller.
Where the clock started
The hold first counted from the time the order was placed. A code a seller delivered by hand at hour 23 left the buyer one hour to check it. The clock was changed to count from fulfillment.
Left open
A refund put the codes back on sale. Nothing recorded that a previous buyer had seen them.
Up next
An ffmpeg relay between every camera and Cloudflare→