7 karma · joined August 14, 2012
In the stolen card scenario you describe (a type of payment fraud), the e-commerce merchant is actually liable. In other words, if that card is reported stolen by the cardholder after the goods are shipped out, the merchant loses the revenue. This is b/c for online credit card transactions, they are categorized as "card not present" transactions, since the merchant can't be as certain the actual cardholder made the purchase. If the transaction had occurred in a physical store, the card company would be liable.
We use the time zone of the customer rather than of the website for scoring riskiness. Sorry if that wasn't clear.
As for customers including birth years in their emails, you're correct that this would be counter to the general trend. However, a fraud detection system like Sift has many data points on which to score a customer. Hopefully, the person would otherwise look benign and thus not have a very high overall score.
At Sift Science, a user is flagged based on a combination of many different factors. So while a transaction 3-10 minutes after signup is associated with increased risk of fraud, a user typically has to match many different patterns to be flagged as an overall risk.