Preventing Promo Code and Coupon Abuse
A tutorial on stopping promo and coupon abuse on Shopify, covering multi-account signups, referral gaming, one-per-customer enforcement, and the detection controls that catch it.

A generous welcome discount is a growth lever until a handful of people turn it into a business. Promo and coupon abuse quietly erodes margin: the same person claims "new customer" savings ten times, referral bonuses get farmed, and one-per-customer codes get stacked. Here's how the abuse works and how to shut it down without punishing real shoppers.
The four common abuse patterns
1. Multi-account signups. One person creates many accounts, each with a fresh email, to claim a first-order or welcome discount repeatedly. Free email domains and plus-addressing ([email protected]) make this trivial.
2. Referral abuse. Self-referral rings where a user refers their own second account, or coordinated groups that refer each other to farm credits, drain referral budgets fast.
3. One-per-customer bypass. Codes meant for a single use per shopper get reused across accounts, guest checkouts, and slightly varied addresses.
4. Code leakage. A private or influencer code meant for a segment ends up posted on a coupon aggregator site and gets hammered by strangers.
Each pattern has different tells, so effective prevention combines Shopify's native limits with detection of the signals abusers can't easily fake.
Start with Shopify's native discount controls
Before any tooling, tighten what Shopify gives you for free. In Discounts, set:
- Usage limits: "Limit number of times this discount can be used in total" and "Limit to one use per customer." The per-customer limit ties to the customer account, which blocks the laziest reuse.
- Minimum purchase requirements so a discount can't be applied to a token order.
- Customer eligibility: restrict codes to specific segments (e.g. subscribers) instead of anyone with the link.
- Expiry dates so a leaked code has a short shelf life.
- Combination rules: disable stacking so codes can't be piled together.
These controls stop casual abuse. The problem is they key off the *account* and the *code*, and determined abusers just make new accounts.
Enforce "one per customer" that actually holds
To make one-per-customer real, you have to recognize the *same person* across different accounts. That means looking past the email at signals that are costly to change:
- Payment fingerprint: the same card or PayPal account across "different" customers.
- Shipping address: the same delivery address with cosmetic variations (apt vs. #, added spaces).
- Device fingerprint: the same browser/device claiming the new-customer discount repeatedly.
- IP and network: many first-order discounts from one IP or subnet in a short window.
When two or three of these match across accounts, you're almost certainly looking at one person. That's the moment to hold or cancel the order for review rather than fulfill another "welcome" discount.
Catch multi-account and velocity abuse
Velocity is the loudest signal. Legitimate new customers trickle in; abusers arrive in bursts. Watch for:
- Multiple first-order discounts from one IP or device within minutes or hours.
- Sequential or plus-addressed emails (
buyer1@,buyer2@,buyer+a@). - Anonymizing networks: discounts claimed via VPN, proxy, or Tor are a strong abuse flag, since real bargain hunters rarely hide their network.
- New-account-to-first-order time near zero repeatedly from the same fingerprint.
This is where a fraud app earns its place. Shieldy — Fraud Filter can block or flag orders by IP, country, VPN, proxy, Tor, and bot signals, and score orders with AI so repeat multi-account claims and velocity bursts surface before you ship. Because it can enforce rules at the checkout level using Shopify Functions, you can stop an abusive discount order from completing rather than clawing it back afterward.
Shut down referral gaming
Referral programs need their own guardrails:
- Delay the reward until the referred order ships and clears the return window, so self-referrals that get refunded never pay out.
- Block self-referral by matching device, payment, and address between referrer and referee.
- Cap rewards per account and per device/IP over a rolling period.
- Require a real purchase, not just a signup, before any credit.
A referral ring almost always shares infrastructure (device, network, or payment instrument). Detecting those overlaps kills most of it.
Handle leaked codes
For codes that escape into the wild:
- Set total usage caps so a leaked code burns out quickly.
- Use unique, single-use codes for influencers and email campaigns instead of one shared string.
- Monitor for a sudden usage spike on a code that should be low-volume; that's your leak alarm.
- Rotate high-value codes on a schedule.
Build the workflow
Put it together as a repeatable process:
- Set native limits on every discount: per-customer use, minimums, expiry, no stacking.
- Instrument detection for device, payment, address, IP, and network signals.
- Auto-flag or block orders that match known abuse patterns (multi-account, velocity, anonymized network).
- Delay referral payouts until orders clear.
- Review the flags weekly, tune thresholds, and watch for new patterns.
Keep real customers happy
The goal is to stop abuse without adding friction for genuine shoppers. Keep thresholds conservative so first-time buyers aren't blocked, use flag-for-review rather than hard-block on borderline cases, and make legitimate one-per-customer denials explain themselves ("this code has already been used on your account"). Done well, prevention is invisible to honest customers and expensive only for the people gaming you.
Tired of watching one person claim your welcome discount ten times? See how IP, device, and AI-based controls stop promo abuse on the Shieldy pricing page.
Protect your Shopify store today
Install Shieldy free — block fraud, bots, and VPNs in under 5 minutes.
Install on Shopify — Free


