Any possibility that they're connecting with a subdomain ("www.example.com") but the post-payment landing page is not ("example.com"). This could lose the session ID cookie unless you set your PHP config for session.cookie_domain to ".example.com" (note the leading dot).
"Please give us a simple answer, so that we don't have to think, because if we think, we might find answers that don't fit the way we want the world to be."
~ Terry Pratchett in Nation
Bookmarks