We're creating a marketplace where expect lots of buyers for digital goods ranging from $1 to $10.
Now obviously there are people who initiate chargebacks (costs $15!) without even communicating with the seller and sometimes intentionally to save money (fraud).
I'm wondering if it would be legal and ethical to create a blacklist of these customers who repeatedly initiate chargebacks and share this list with a few other businesses privately on their request? No, not the whole list, but a searchable with a combination of email the last-4 digits of the card.
Here are your (reasonable) options:
Disclosing information about the user is extremely thorny, especially if it's financial information. Limited disclosure is either going to be useless, or a possible PII breach / PCI compliance issue.
If you absolutely must put something on the site saying why transactions with a user have been canceled, keep it simple. "User was banned due to terms of service violation" is the usually the most you should say publicly, and "banned" is usually ample.
IIRC, contesting chargebacks when you can demonstrate good faith on your part and/or bad faith on the customer's part can do a lot to help your record and to harm the customer's record with the card company, even if the particular transaction is ruled on in the customer's favor. Running up more than a few chargebacks in a year will likely flag a review (/ rate hike / account suspension / etc.).