5 mistakes that kill new online stores in Serbia before their first sale

We've helped dozens of Serbian businesses launch online payments. Some go live in two weeks. Others take months. The difference isn't their product or their budget — it's the mistakes they make before they even talk to us.
Here are five we see again and again.
1. No HTTPS — the deal-breaker nobody mentions
Your website runs on http://. No padlock in the browser. You think it doesn't matter because "it's just a small shop."
It matters enormously:
- No bank will give you acquiring without HTTPS. It's a hard requirement for processing card payments.
- Google penalises HTTP sites in search rankings. You're invisible to people searching for your products.
- Browsers show warnings — "Not Secure" in the address bar. Customers leave before seeing your first product.
- Customer data is exposed — names, addresses, emails sent in plain text.
The fix costs zero. Let's Encrypt provides free SSL certificates, and most hosting providers install them with one click. If your hosting doesn't support it, switch hosting — it's cheaper than losing every customer who sees a security warning.
2. Treating the business bank account as an afterthought
You built the website, chose products, hired a photographer. Then you try to connect payments and discover you need a business bank account (tekući račun) at a Serbian bank. Opening one takes 5–10 business days. Some banks take longer.
Meanwhile, your store sits there — live, looking professional, completely unable to accept money.
Fix it early. Open your business account in parallel with building the website. You need:
- Company registration documents
- PIB (tax identification number)
- Founder's personal documents
- Proof of address
Start this process on day one, not on launch day.
3. Building a custom checkout instead of using a hosted page
"My developer will build a beautiful custom payment form that matches our brand." This sounds reasonable until you realise what it actually means:
- You need PCI DSS compliance — a security standard that costs thousands to certify and maintain. If card data touches your server, you're responsible for its security.
- You need to handle 3D Secure flows — redirect to bank, callback handling, timeout management.
- You need to support multiple card types — Visa, Mastercard, DinaCard each have quirks.
- You need error handling for dozens of decline codes, network timeouts, and edge cases.
A hosted payment page handles all of this. The customer is redirected to a secure, pre-built page. Card data never touches your server. 3D Secure works automatically. You focus on selling, not on security certifications.
The result looks just as professional. The customer spends 10 seconds on the payment page and comes back to your site.
4. Forgetting about mobile
You tested your store on a laptop. It looks great. You launch. Then you check analytics after a month and discover that 70% of visitors are on phones — and your conversion rate on mobile is one-third of desktop.
Why? Because:
- Product images load slowly on mobile data
- The checkout form requires horizontal scrolling
- Buttons are too small to tap accurately
- The cart doesn't save when switching between browser tabs
Mobile-first means mobile-first. Test on a phone before you test on a laptop. Load your checkout over 4G, not WiFi. Try to complete a purchase with one thumb while standing on a bus. If it's frustrating, your customers feel the same frustration — and they leave.
5. Launching without a return policy
Serbian consumer protection law (Zakon o zaštiti potrošača) gives online buyers the right to return products within 14 days without stating a reason. This isn't optional — it's the law.
If your store doesn't have a visible return policy:
- Customers don't trust you enough to buy
- If they do buy and want to return, you have no process — chaos follows
- You're legally exposed to complaints with the consumer protection authority
- Your chargeback rate goes up because customers dispute through their bank instead of through you
Write a clear return policy. Put it in the footer, link to it from the checkout page, and mention it on product pages. It should cover:
- Return window (minimum 14 days by law)
- How to initiate a return
- Who pays for return shipping
- Refund timeline
A good return policy doesn't increase returns — it increases purchases.
The pattern
All five mistakes share something: they're boring. Nobody gets excited about SSL certificates, bank accounts, or return policies. Entrepreneurs want to pick products, design logos, and write Instagram captions.
But the boring stuff is what separates a website from a business. A website that can't accept payments is a brochure. A website without HTTPS is a liability. A store without a return policy is a lawsuit waiting to happen.
Do the boring stuff first. Then do the fun stuff. Your store will thank you.
In short
- No HTTPS = no payments, no SEO, no customer trust. Get a free SSL certificate.
- No business bank account = can't receive payments. Open it on day one.
- Custom checkout = PCI compliance nightmare. Use a hosted payment page.
- Desktop-only testing = losing 70% of your audience. Test on a phone first.
- No return policy = legal exposure + low trust + high chargebacks. Write one today.