Skip to content
Guide9 min read

Photo Timestamp Verification in Refund Disputes

What EXIF timestamps and GPS geolocation on a photo actually prove in a refund dispute, how to verify them, and why they remain trivially fakeable.

CheckFile Team
CheckFile Teamยท
Illustration for Photo Timestamp Verification in Refund Disputes โ€” Guide

Summarize this article with

A DateTimeOriginal field and GPS coordinates embedded in a photo's EXIF metadata only record what the device claims about when and where the picture was taken โ€” both are declarative values that any free tool can rewrite in seconds, with no visible trace left in the file. For a support or fraud team processing refund claims, that gap matters directly: the "proof" photo a customer submits for a damaged item or a missing delivery does not establish the real capture time or location until it has been cross-checked against other signals.

This article is provided for informational purposes and does not constitute legal advice. Dispute-handling procedures should be adapted to each business's contractual framework and, in cases of serious doubt, supplemented with further verification.

What photo timestamp and geolocation data actually record

EXIF (Exchangeable Image File Format) embeds three distinct date fields (DateTimeOriginal, DateTimeDigitized, ModifyDate), the device make and model, the software that last touched the file, and GPS coordinates if location services were enabled at capture. That location data can come from satellite GPS, cell-tower triangulation, or Wi-Fi positioning โ€” three sources that can each be altered before the file is ever shared. Nothing in the file format itself guarantees these fields reflect reality; they are self-declared values written by the device or the software that produced the file.

How to verify a photo's timestamp and location step by step

Verification follows four repeatable steps for a team handling claims at volume. First, extract the metadata with a tool such as ExifTool, which reads EXIF, XMP and IPTC fields in a single pass. Second, compare the three timestamps against each other: a ModifyDate several days after DateTimeOriginal with no declared legitimate edit is worth a closer look. Third, check whether the implied time zone of the timestamp is consistent with the GPS longitude on file โ€” a time offset that does not match the claimed location's longitude often means only one of the two fields was edited. Fourth, cross-reference the GPS position against the delivery or return address on the claim.

Forensic examiners prioritise time-zone anomalies: a DateTimeOriginal that conflicts with the GPS timestamp, or an offset that doesn't match the claimed location's time zone, is one of the more reliable indicators of tampering, according to TimeStamp Camera's technical breakdown of how EXIF data gets faked. That cross-check is not something a reviewer can spot at a glance across dozens of daily claims, which is exactly why systematic extraction at intake matters.

Why these fields can be faked in seconds

No advanced technical skill is needed to rewrite a capture date or GPS coordinates. Consumer-grade apps let anyone drop a pin on a map to set an arbitrary position, then apply the desired timestamp to an already-existing photo, without leaving a detectable tampering indicator inside the file itself.

Field faked Typical tool What should flag it for review
DateTimeOriginal Free EXIF editor, mobile app Mismatch with ModifyDate or the order date, with no declared edit
GPS coordinates Fake-location app, map pin drop Position inconsistent with the delivery address on file
Implied time zone Manual edit of only one field (date or GPS) Time offset inconsistent with the claimed longitude
Device make/model Text field rewrite Model inconsistent with the observed image quality

Explore further

Discover our practical guides and resources to master document compliance.

Explore our guides

When EXIF isn't enough: qualified timestamping

A qualified electronic timestamp, applied at the moment of capture by a Trust Service Provider on an approved trust list, carries a legal presumption of accuracy and is far harder to dispute than an EXIF field a customer's own device can rewrite after the fact, per the retained UK framework derived from the EU eIDAS Regulation (EU) No 910/2014 on electronic identification and trust services, implemented in the UK through the Electronic Identification and Trust Services for Electronic Transactions Regulations 2016. Unlike EXIF, the time value is applied by an independent third party, not the customer's own device, which makes it enforceable even when the other side disputes the claim.

For low-volume dispute handling, this distinction rarely matters โ€” EXIF extraction is enough for a first pass. For higher-stakes claims (high-value goods, a customer account with a repeated dispute history, amounts near a chargeback threshold), the evidentiary weight of a qualified timestamp justifies the added cost, particularly if the case risks ending up in a small claims court.

How refund policies use the timestamp window

Nearly every return or refund policy sets a reporting window โ€” flag a defect within 5, 14 or 30 days of delivery, for example. The "proof" photo is then meant to confirm the defect existed within that window, which ties the reliability of its timestamp directly to the refund decision.

Signifyd estimates that 11% of online returns in 2025 qualified as return policy abuse, according to Signifyd's 2026 ecommerce return policy best-practice data โ€” a high enough share to justify systematic checks rather than default trust in photos submitted just outside an apparent deadline. Photo fraud in refund claims is no longer limited to a doctored timestamp, either: AI-generated fake receipts and proof photos rose from 0% of detected fraudulent documents in 2024 to 14% by late 2025, and human reviewers miss around 75% of high-quality AI-generated fakes, according to Truthscan's analysis of image-based fraud in refund workflows.

In the UK, the contractual basis for a refund on faulty goods runs through the Consumer Rights Act 2015, which gives consumers a 30-day short-term right to reject faulty goods and a longer repair-or-replace window beyond that. A retailer refusing a refund still needs a proportionate justification: rejecting every photo lacking usable EXIF risks penalising legitimate claims, while accepting every submission without a check exposes the business to the abuse volume documented above.

What support teams actually ask on forums

Three questions come up repeatedly on e-commerce and customer-support forums. First: does a photo sent over WhatsApp arriving with zero metadata mean something is wrong? No โ€” most messaging apps strip EXIF during compression, so this proves nothing on its own and should trigger a secondary check rather than an automatic rejection. Second: can an EXIF date be edited without it showing? Yes, no visual indicator appears in the file after a rewrite with a free tool, which is exactly why a single field should never be treated as conclusive. Third, a more operational question: should a claim be denied purely because the photo has no GPS tag? No โ€” location services are commonly disabled by default for privacy reasons, so a missing GPS tag is common on genuinely unedited photos too.

GPS coordinates embedded in a photo count as personal data under UK GDPR once they can be linked to an identifiable person, a point the Information Commissioner's Office makes clear in its guidance on location data, which means any team using this metadata in dispute handling needs a defined lawful basis and retention period.

Building a review process that doesn't rely on EXIF alone

A manual check works for a single claim but becomes impractical for a team handling dozens of refund disputes a day. Our approach cross-checks EXIF extraction against multi-layer structural analysis and cross-document consistency, rather than treating a single metadata field as sufficient proof. This is the same logic covered in more depth in our analysis of what EXIF metadata can and can't prove.

A simple operational checklist limits both failure modes โ€” rejecting a legitimate claim too fast, or trusting a manipulated photo too readily.

  1. Extract metadata systematically at intake, before any doubt arises.
  2. Never treat a single field as a verdict. A suspicious date or a missing GPS tag should trigger a secondary check, not an automatic rejection.
  3. Log the submission channel (direct upload, messaging app, email) before concluding a missing-metadata case is unusual.
  4. Cross-check EXIF against structural file analysis and cross-document consistency, rather than stopping at one signal type.
  5. Record every check performed so the decision can be justified if the customer disputes it later.

Beyond this first filter, a photo with internally consistent timestamp and GPS data can still originate from content generated or edited by AI advanced enough to reproduce plausible metadata. For higher-stakes claims, our dedicated deepfake and AI-generated document detection page adds a forensic layer built with our partner Label4, designed as a complement to your existing controls rather than a guarantee of catching every possible fake. Our complete guide to photo evidence in e-commerce claims covers the rest of the dispute workflow, and our document verification guide covers verification methods beyond a single photo.

Teams handling claims at scale can review our banking and KYC solutions for cases with a regulatory dimension, while our security page details the data-processing architecture and our pricing page outlines volumes by plan.

Frequently Asked Questions

Is a photo with no EXIF data automatically suspicious?

No. Most messaging apps, including WhatsApp, strip EXIF metadata during compression, so missing metadata is common even on genuine photos. It should trigger a secondary check, not an automatic rejection.

Can a photo's GPS location be changed without it showing?

Yes. Consumer-grade apps let anyone set an arbitrary position on an existing photo without leaving a visible trace in the file, which is exactly why a single GPS field should never count as definitive proof.

Is a qualified timestamp necessary for every refund dispute?

No. For most low-stakes claims, extracting and cross-checking EXIF is enough for a first review. A qualified timestamp becomes worthwhile for high-value claims or accounts with a repeated dispute history.

How do you spot a suspicious time-zone mismatch between a date and a GPS position?

By comparing the timestamp's implied time zone against the longitude in the GPS coordinates. An offset inconsistent with the claimed location usually means only one of the two fields was edited manually while the other kept its original value.

Should a refund always be denied if the photo has no geolocation data?

No. Many devices disable location services by default for privacy reasons, which makes missing GPS data common on entirely legitimate photos. Denying refunds on that basis alone penalises a significant share of genuine customers.

Stay informed

Get our compliance insights and practical guides delivered to your inbox.

Explore further

Discover our practical guides and resources to master document compliance.