Lesson 13

Compliance, Payments and Trust for an Overseas OPC

Running a purely domestic website has its own rules. Running an overseas-facing one-person internet company means simultaneously navigating privacy regulations from multiple jurisdictions, payment platform risk policies, international tax obligations, refund laws that vary by country, and the harder social problem: convincing strangers in other countries that you are a real, trustworthy business.

This lesson covers all five areas — and gives you a practical minimum-viable-compliance framework for each stage of growth.

Part 1 Privacy Compliance — Not Just a Policy Page

The Wrong Question and the Right One

Wrong: "Does my website have a privacy policy?"

Right: "What data am I actually collecting? Why? Who gets it? How long do I keep it? Can a user refuse or delete it?"

GDPR: Broader Than Most Small Sites Realize

GDPR applies not only to EU-based companies. If you actively offer goods or services to people inside the EU, or monitor their behavior, GDPR may apply to you regardless of where you are located.

The core principles: collect data lawfully, for a specific stated purpose, with minimum necessary scope, for a defined retention period, with security in place, and with the ability to demonstrate accountability.

Cookie Consent: The Logic Many Sites Get Backwards

Under EU rules, strictly necessary cookies (login sessions, shopping carts) generally do not require prior consent. Analytics and advertising cookies typically do.

The common mistake: GA4 starts loading the moment the page opens. Then below the fold there is a "Accept cookies?" banner. The consent comes after the tracking. That logic is reversed.

Right flow: EU visitor arrives → sees cookie choices → selects preferences → then the non-necessary tools (analytics, advertising) are activated. Consent before tracking, not after.

CCPA: Don't Panic Unless You Meet the Thresholds

CCPA currently applies primarily to for-profit businesses with annual gross revenue over ~$26.6M, or those that buy/sell/share the personal information of 100,000+ consumers per year, or that earn 50%+ of annual revenue from selling or sharing personal data.

An early OPC is very far from most of those thresholds. Still, from day one, practice: collect less, explain more, don't sell data, provide a contact channel for questions, delete when asked.

That is good product design, not just legal compliance.

Your Privacy Policy Must Reflect Reality

A privacy policy copied from a generic template and never updated is worse than useful — it may not match what you actually do, and a mismatch is itself a compliance problem.

Include: who you are, why you collect data, your legal basis, which third-party services receive data (GA4, payment processors, email platforms), cross-border data transfers, retention periods, and how users can exercise their rights.

Part 2 Payment Platform Health — Transparency, Not Tricks

The Right Mental Model

Searching for "how to avoid Stripe/PayPal account freezes" often leads to the wrong place: how to work around risk detection. The right question is different:

How do I make my business look, to any risk system, exactly like what it genuinely is — a transparent, low-risk, legitimate merchant?

What a Healthy Merchant Account Looks Like

A customer who sees an unrecognised name on their credit card statement and files a chargeback is not your enemy — they are a signal that your billing statement name and customer communication need work. Fix the signal, not the symptom.

Part 3 Tax — Payment ≠ Compliance

The Gap Most Founders Miss

PayPal processes your sale. The money arrives. Everything seems fine.

Payment ≠ tax handled. Payment, VAT/GST/Sales Tax, and your income tax obligation are three separate things. The payment processor handles the first. You are responsible for the other two.

Digital Products and International VAT/GST

If you sell a digital product (PDF report, premium tool unlock, downloadable content) to customers in Germany, France, Australia, the UK, and Canada, those five jurisdictions may each have different VAT/GST rules for digital services sold to consumers.

The EU has an OSS (One Stop Shop) mechanism that simplifies multi-country VAT filing for some cross-border digital sales. Other countries have their own thresholds and registration requirements.

Three Paths as You Scale

Early stage: Self-monitor, research as you approach thresholds Mid stage: Accounting software + tax tool (e.g. Quaderno, TaxJar) Later stage: Merchant of Record platform — they handle tax collection and remittance as part of processing the payment

At $0 revenue, don't spend six months studying 195 countries' tax laws. Do set a reminder to revisit tax obligations before your first consistent cross-border digital product sales.

Part 4 Refunds — "No Refunds" Is Not Always Enforceable

Why "All Sales Final" Is Not Enough

Many independent developers write "No refunds" and feel protected. In some markets, that clause is not legally enforceable against consumer rights.

In the EU, consumers generally have a 14-day withdrawal right for distance purchases. For digital content there is an important exception: if the consumer explicitly requests immediate delivery and explicitly acknowledges they lose the withdrawal right once delivery begins, the right can be waived. The key word is explicitly — buried in terms of service is not sufficient.

If you sell instantly delivered digital content, consider building the acknowledgment into checkout: a clear checkbox that states the user requests immediate delivery and understands the withdrawal right is forfeited. The design of checkout is a compliance decision, not just a UX decision.

Part 5 Building Trust with Overseas Users

What a First-Time Visitor Is Really Asking

A user in the US considering a $4.99 purchase from a small website they found today is thinking:

Is this real or a scam? Who made this? If something goes wrong, who do I contact? Will they charge me again without asking? Can I get a refund? What exactly am I buying? Has anyone else used this?

Your Contact page, About page, Refund Policy, and build-in-public track record answer those questions before the user has to ask.

Reviews: The Right Way to Use Trustpilot

Review platforms explicitly prohibit: inviting only satisfied customers, incentivising positive reviews with discounts or gifts, writing your own reviews, or removing bad reviews by offering refunds.

The correct approach: invite all customers uniformly with neutral language ("Please share your honest experience"). Respond thoughtfully to negative reviews. A profile with 17 reviews at 4.6 stars is often more credible than 17 five-star reviews that all sound identical.

Google Business Profile: Online-Only Sites Don't Qualify

Google's current policy states that online-only businesses generally do not meet the eligibility criteria for Google Business Profile, which requires in-person customer interaction. Do not create a business listing with a fabricated office address to appear more legitimate — that creates platform risk, not trust.

Community Distribution: Earned, Not Pushed

The least effective approach: posting your link in multiple subreddits with "I built this amazing tool, check it out." The likely result is spam flags and bans.

The effective approach: become genuinely useful in the community first. Answer questions in depth. When a link is relevant, include it as a resource, not the point. This is earned distribution — the opposite of spam distribution — and it compounds over time.

The Trust Formula

Trust = Transparency × Consistency × Time

Transparency

Who you are. What you sell. How to contact you. Real numbers, real results, real failures.

Consistency

Website, payment, product, and customer support all tell the same story.

Time

Not launched yesterday and gone tomorrow. Months and years of uninterrupted presence.

Summary Minimum Viable Compliance by Stage
StageWhat to do now
$0 — live sitePrivacy policy (real, not template), Cookie notice, Terms, Contact page, honest product description, verified identity on payment accounts
Adding analytics / adsCookie consent flow: consent before analytics fires, not after
First paid productRefund policy, clear purchase description, order confirmation email, support email, billing statement name matches your product
Cross-border digital salesResearch VAT/GST thresholds for your top-traffic countries; set up tax tool or consider Merchant of Record
Growing order volumeMonitor dispute rate; document fulfillment process; backup payment method; review Stripe/PayPal prohibited businesses list
Real customer baseStructured review invitation process; respond to all reviews; update privacy policy as data practices change

Six Things to Carry From This Lesson

  1. Privacy compliance is not a page — it's knowing what data flows where and why.
  2. Collect less data. That is safer than writing a longer policy.
  3. Payment account health comes from transparency and low disputes, not anti-ban tricks.
  4. Receiving payment and handling tax are two separate obligations.
  5. Refund rules vary by market. "No Refunds" is not universally enforceable.
  6. Trust with overseas users accumulates through transparency, consistency, and time. None of those can be faked quickly.

"Compliance is not the fine print at the bottom of the page. Sometimes it reaches all the way into how you design checkout."

Discuss this lesson on GitHub →