Security & Privacy
How to Safely Shop Online: A Calm, Practical Guide
A friendly, jargon-free guide to shopping online safely, covering trusted stores, secure payments, spotting fake deals, and protecting your details.
Security & Privacy
A friendly, jargon-free guide to shopping online safely, covering trusted stores, secure payments, spotting fake deals, and protecting your details.
The single most protective decision you make when shopping online is not where you buy but how you pay. Pay with a credit card or a tokenized wallet like Apple Pay or Google Pay, and you keep the legal power to reverse the charge; everything else in this guide simply lowers the odds you ever need to use it.
Fraud protection is not evenly distributed across payment types. The gap between them is written into law and card-network rules, and it is large.
In the United States, credit cards fall under the Fair Credit Billing Act (FCBA), which caps your liability for unauthorized charges at $50 — and virtually every major issuer voluntarily makes that $0. You also get chargeback rights: if an item never arrives or arrives "not as described," you can dispute it through Visa, Mastercard, or Amex and have the charge provisionally reversed while it is investigated.
Debit cards are governed instead by the Electronic Fund Transfer Act (Regulation E), and the protection is weaker in a way that matters. Your liability depends on how fast you report: $50 if you notify the bank within two business days, up to $500 within 60 days, and potentially unlimited after that. Worse, a debit charge pulls real money out of your checking account immediately, so even a "successful" dispute means waiting to be repaid.
In the UK, Section 75 of the Consumer Credit Act goes further still: for any single item costing between £100.01 and £30,000, your credit card issuer is jointly liable with the seller, so you can claim from the bank even if the retailer vanishes. Debit and lower-value purchases fall back on the voluntary chargeback scheme, which is useful but not a legal guarantee.
The practical rule: use a credit card for anything you cannot afford to lose, and never a bank transfer.
You can add a second layer that hides your real card number entirely.
Both mean a data breach at a shop cannot expose the card in your wallet.
Known retailers like Amazon, Best Buy, or John Lewis carry little risk. The judgment call is the unfamiliar store you reached through an ad on Instagram, TikTok, or a Google Shopping result.
Scammers rely on you glancing, not reading. Two attacks are common:
amaz0n-deals.com, paypa1.com, nikeoutlet-sale.net. The real brand almost never sells from a hyphenated or "outlet" subdomain you have never heard of.xn--) in the address bar. If a familiar-looking name suddenly renders as xn--80ak6aa92e.com, close the tab.If you arrived via a link in an email or ad, do not click through to pay. Open a new tab and type the store's name yourself, or use a search engine, so you know the address is genuine.
Spend 90 seconds before entering any details:
The padlock and https:// in your address bar confirm the connection uses TLS encryption, so data you send is scrambled in transit and cannot be casually intercepted. That is the minimum bar, not a seal of trustworthiness.
The crucial thing most people misunderstand: encryption says nothing about the seller's honesty. Free certificates from services like Let's Encrypt mean most scam sites now show a valid padlock too. So treat the padlock as necessary but never sufficient, and be alarmed by its absence: a checkout page on plain http:// should stop you entirely.
Avoid entering card details over open public Wi-Fi. Because TLS already encrypts the payment, the bigger risk is a spoofed hotspot; using your phone's mobile data, or a reputable VPN, sidesteps it.
Fraudulent listings share a recognizable fingerprint. The core trick is pairing a price that is too good with pressure that stops you thinking.
https:// and the checkout is not on a bare IP address.It can be, because it hides your card number from the merchant and adds its own Purchase Protection for items that never arrive or are not as described. But that protection only covers "Goods and Services" payments — never send "Friends and Family" to a seller, and remember disputes go through PayPal's process rather than your card issuer's.
Contact your card issuer or bank immediately, using the number on the back of the card, and ask to dispute the charge and freeze or reissue the card. With a credit card your liability is capped (usually at $0), and the sooner you report a debit charge the more of your Regulation E protection you keep.
The platform's own buyer protection (Amazon's A-to-z Guarantee, eBay's Money Back Guarantee) covers you if you pay through the site and the item does not arrive or is wrong. The risk appears when a seller tries to move you off the platform to "save fees" — that voids the protection, so always keep the conversation and payment on the marketplace.
No. TLS already encrypts your payment on any decent connection, so a VPN is optional. Its main value is on untrusted public Wi-Fi, where it guards against a spoofed hotspot — but using mobile data achieves the same thing for free.
Keep reading
A reassuring, jargon-free guide to spotting fake online stores, covering the warning signs in prices, contact details, payment options, and reviews.
A calm, jargon-free guide to protecting your privacy on your phone, covering app permissions, location sharing, lock screens, and trimming back data tracking.