Fraud Guard
The problem it solves
Section titled “The problem it solves”Shopify’s “one use per customer” limit counts per code and account — and every new email address is a new account. So a person who signs up again (name+1@gmail.com, a fresh Outlook address, a guest checkout) is a brand-new customer as far as Shopify is concerned. They can redeem your welcome offer repeatedly, or work through a bulk code set one “customer” at a time. Nothing gets hacked; they just keep signing up.
Fraud Guard looks at the person behind the accounts, and blocks the second redemption before the order exists.
Activating
Section titled “Activating”Open Fraud Guard and hit Activate now. Two things happen:
- Protection switches on immediately, with email and phone matching enabled.
- PromoLock reads up to the last 365 days of your discounted orders — so repeat redeemers are recognized from day one, not just from today forward. This takes a few minutes on most stores, up to a couple of hours on very high-volume ones. You can leave the page; protection keeps getting stronger as more history loads.
After that, everything stays up to date by itself as orders come in.
What gets checked at checkout
Section titled “What gets checked at checkout”When a customer applies a code, Fraud Guard asks two questions:
- Has this person already redeemed this code under a different account? This works for any code on your store — native Shopify discounts, other apps’ codes, and PromoLock’s — as long as the discount is set to once-per-customer. A deliberately multi-use code is never touched.
- Has this person already redeemed any code from the same bulk set? One person gets one code per set, no matter how many codes they hold. This set-wide guard is exclusive to PromoLock bulk sets — a unique-code campaign minted elsewhere can’t get it.
A match is rejected right on the discount field, before the order is placed. Everything else passes untouched.
The settings
Section titled “The settings”Block discount fraud
Section titled “Block discount fraud”The master switch. Off means nothing is checked — the sections below configure how matching works when it’s on.
Exact match
Section titled “Exact match”Matches on hard identifiers. Two checkboxes, both on by default:
- Email — alias tricks collapse to one identity:
j.ohn+deal@gmail.comandjohn@gmail.comcount as the same customer, andgmail.com/googlemail.comare treated as one. - Phone — numbers are compared after normalizing, so spacing and country-code formatting don’t matter.
Similar match
Section titled “Similar match”Catches the fraudster who varies everything slightly. The Name + Address rule flags a redemption when the buyer’s name and shipping address are both close to someone who already redeemed the code.
“Close” is up to you — Matching strictness has a dial for First name, Last name, and Address, each with three settings:
| Setting | Example (first name “James”) |
|---|---|
| Exact | Matches only “James” — not “Jaimes” |
| Balanced (default) | Matches the typo “Jaimes” — not “Michael” |
| Loose | Matches variants like “Jamie” — not “Michael” |
Live examples under each dial show exactly what your chosen setting would and wouldn’t match, using real sample values — set it, read the example, and you know what you’ve configured.
When in doubt, the sale goes through
Section titled “When in doubt, the sale goes through”If a fraud check can’t be completed for any reason, the code is allowed. Only a definite match blocks a redemption. A blocked checkout costs you more than a leaked discount, so Fraud Guard never stands between a legitimate customer and their order.
Data handling
Section titled “Data handling”Redemption records are kept for a rolling 365 days, then deleted automatically. Records for cancelled orders are removed when the cancellation is seen, and customer-deletion (GDPR) requests remove that customer’s records. Details in the Privacy Policy and DPA.
Related reading
Section titled “Related reading”- Fraud-proof every one-per-customer code — the full deployment playbook
- Bulk codes — fraud protection for sets
