Stop repeat signup rewards: Define eligibility by account, person or clear unit in terms; Issue benefit once using durable records and atomic checks; Review disputes with rate limits and manual review where needed
Image: Loyalty Marketing Guide

Loyalty Fraud

Part of Loyalty fraud and abuse

Preventing repeated signup incentives

Define one-time eligibility, prevent duplicate reward issues and review repeat-signup signals without rejecting legitimate members.

Prevent repeat signup rewards by defining who qualifies once, recording each issue and checking eligibility before value is posted. Decide whether 'once' means per account, person or another clearly stated unit. The control must enforce the rule members were actually offered.

Define eligibility

State the qualifying action: account creation, contact verification, a first eligible purchase or another specified step. Say when the benefit becomes available and whether a closed, merged or reactivated account can receive it again.

Apply the rule across online, in-store and manual joining routes. Staff-issued exceptions need an eligibility check and a recorded reason.

An email address alone is a weak basis for a one-per-person offer because one person can use several addresses. A shared address, phone or network also does not establish that two members are the same person. Treat those connections as review signals.

Eligibility Units: Account vs Person-Level Rules

  • One-per-account rulePrevents multiple rewards on the same account but does not guarantee one per person. Risk of abuse via multiple accounts by one individual.
  • One-per-person ruleRequires stronger identity verification. Must consider shared contact details (email, phone, network) as signals—not proof—of identity. Manual review needed for ambiguous cases.

Issue the benefit once

Use a promotion identifier and the eligibility unit defined in the terms. Keep a durable record of pending and completed issues and the action that qualified the member. Make the eligibility check and issue decision atomic so simultaneous requests cannot both post value.

A retry should return the existing result rather than create another credit. If a qualifying purchase is later cancelled or refunded, apply the published rule and record any reversal separately.

A one-per-account control does not enforce a one-per-person promise across multiple accounts. If the offer uses a person-level rule, decide what evidence can fairly establish a prior claim and provide manual review where the match is uncertain.

Email verification can reduce automated account creation, but it cannot prove that one person has only one email address. Stronger checks add effort and personal-data collection. For organisations covered by Australian privacy law, collect only personal information reasonably necessary for the purpose.

Review disputed claims

Watch claims, qualifying actions and repeat attempts together. Check campaign and store activity before interpreting a signup spike. Use rate limits or a review queue where apparent automation warrants them, while leaving a route for genuine members to complete enrolment.

When declining a claim, explain the applicable rule and offer a way to correct a matching error. Review shared contact details, account merges and failed earlier issues individually. Two people using one family email may have separate entitlements under a person-level offer, but the program's published terms and account design determine the outcome.

Key Compliance & Security Considerations

  • Australian Privacy Principle (APP) 3Only collect personal information reasonably necessary for the stated purpose.
  • ACCC Guidance on Loyalty SchemesPromotions must be transparent and fair; terms must be clear and enforceable.
  • OWASP Business Logic SecurityControl logic must prevent abuse through automated or repeated actions.
  • Bot Management Best PracticeImplement rate limits and review queues to detect and manage automated signup attempts.

More from Loyalty Fraud

Loyalty Fraud

Loyalty fraud and abuse

Map loyalty abuse risks across signup, earning, redemption and staff access, then investigate unusual activity without treating alerts as proof.