Skip to content

Fraud Guard

Shopify’s “one use per customer” limit counts per code and account — and every new email address is a new account. So a person who signs up again (name+1@gmail.com, a fresh Outlook address, a guest checkout) is a brand-new customer as far as Shopify is concerned. They can redeem your welcome offer repeatedly, or work through a bulk code set one “customer” at a time. Nothing gets hacked; they just keep signing up.

Fraud Guard looks at the person behind the accounts, and blocks the second redemption before the order exists.

Open Fraud Guard and hit Activate now. Two things happen:

  1. Protection switches on immediately, with email and phone matching enabled.
  2. PromoLock reads up to the last 365 days of your discounted orders — so repeat redeemers are recognized from day one, not just from today forward. This takes a few minutes on most stores, up to a couple of hours on very high-volume ones. You can leave the page; protection keeps getting stronger as more history loads.

After that, everything stays up to date by itself as orders come in.

When a customer applies a code, Fraud Guard asks two questions:

  • Has this person already redeemed this code under a different account? This works for any code on your store — native Shopify discounts, other apps’ codes, and PromoLock’s — as long as the discount is set to once-per-customer. A deliberately multi-use code is never touched.
  • Has this person already redeemed any code from the same bulk set? One person gets one code per set, no matter how many codes they hold. This set-wide guard is exclusive to PromoLock bulk sets — a unique-code campaign minted elsewhere can’t get it.

A match is rejected right on the discount field, before the order is placed. Everything else passes untouched.

The master switch. Off means nothing is checked — the sections below configure how matching works when it’s on.

Matches on hard identifiers. Two checkboxes, both on by default:

  • Email — alias tricks collapse to one identity: j.ohn+deal@gmail.com and john@gmail.com count as the same customer, and gmail.com/googlemail.com are treated as one.
  • Phone — numbers are compared after normalizing, so spacing and country-code formatting don’t matter.

Catches the fraudster who varies everything slightly. The Name + Address rule flags a redemption when the buyer’s name and shipping address are both close to someone who already redeemed the code.

“Close” is up to you — Matching strictness has a dial for First name, Last name, and Address, each with three settings:

Setting Example (first name “James”)
Exact Matches only “James” — not “Jaimes”
Balanced (default) Matches the typo “Jaimes” — not “Michael”
Loose Matches variants like “Jamie” — not “Michael”

Live examples under each dial show exactly what your chosen setting would and wouldn’t match, using real sample values — set it, read the example, and you know what you’ve configured.

If a fraud check can’t be completed for any reason, the code is allowed. Only a definite match blocks a redemption. A blocked checkout costs you more than a leaked discount, so Fraud Guard never stands between a legitimate customer and their order.

Redemption records are kept for a rolling 365 days, then deleted automatically. Records for cancelled orders are removed when the cancellation is seen, and customer-deletion (GDPR) requests remove that customer’s records. Details in the Privacy Policy and DPA.