Fraud protection
Affiliate programs attract a few kinds of abuse: affiliates buying through their own link to earn commission on their own orders, orders paid with stolen cards that come back as chargebacks, and discount codes that leak to coupon sites. Sprout Affiliate has a rule for each. They are in the app under Settings > Fraud detection, and they are on every plan, Free included.
This page describes each rule: what it checks, when it holds an order, what you see, and how it is set when you install.
Every rule holds, nothing is rejected for you
Every order rule on this page works the same way. When an order matches, Sprout Affiliate holds it and flags it for you to decide. A held order is never approved automatically, even when auto-approve is on. It is never rejected for you either. You open it and choose Approve or Reject.
The reason is shown as a badge next to the order on the Referral orders page and the Payouts page, and in the merchant phone app. If an order matches more than one rule, the badge shows the first that applies, in this order: test, canceled or unpaid, then an open chargeback, then self-referral, then Shopify risk, then an order burst, then a new affiliate's first orders.
A flagged order waits in its own Flagged orders section at the top of the Payouts page, and under a Flagged tab on that affiliate's own payout page. Both appear only while something is flagged. Each order there is listed on its own with its own Approve and Reject. Approve all, and the Approve button beside an affiliate in Pending, never include a flagged order, so every one is decided by itself.
The order's own page has a Fraud checks card with a row for every rule you have on, each showing what that rule found for this order. The rules run while an order waits for approval. They are not run again on an order that has been paid.
No usage fee is charged on an order while it is held. The fee is billed when an order is approved, and never on an order you reject.
0 turns a number field off. The IP address rules for applications are a second card on the same tab.
| Setting | Reason shown on a held order | Default |
|---|---|---|
| Hold orders where the buyer's name matches the affiliate | Possible self-referral | On for new stores |
| Hold orders placed from the affiliate's own IP address | Possible self-referral (same address) | On for new stores |
| Hold orders Shopify rates medium or high risk | Shopify rates this order high risk, or Shopify rates this order medium risk | On for new stores |
| Take back commission on charged-back orders | Chargeback open | On for new stores |
| Orders to review by hand for each new affiliate | One of this affiliate's first orders | 0 (off) |
| Hold an affiliate's orders beyond this many in 24 hours | Many orders from this affiliate in 24 hours | 0 (off) |
| Days to wait before approving orders automatically (Settings > General) | Approves automatically on YYYY-MM-DD | 0 (approve at once) |
| Anti-leak discount protection | None. A code-only order is not credited at all. | Off |
Self-referral by name
Switch: Hold orders where the buyer's name matches the affiliate.
Sprout Affiliate compares the customer's name on the Shopify order with the affiliate's name. It compares the whole name and ignores upper and lower case, so "Jane Smith" matches "jane smith". It does not match "Jane A. Smith" or "J. Smith". A match holds the order with the reason Possible self-referral.
The name comes from Shopify, through the Customers permission you approve at install. If an order has no customer name, nothing is compared and the order is not held by this rule.
On the order's Fraud checks card this rule shows whether the names match, differ, or the customer's name is not available.
Default: on for new stores.
Self-referral by IP address
Switch: Hold orders placed from the affiliate's own IP address.
An IP address is the address a device's internet connection is identified by. Sprout Affiliate records the address each affiliate applied from. It compares that address with two others:
- the address of the referral link visit that led to the order, and
- the address of the browser the buyer checked out from, which Shopify records on the order.
Because the second comparison uses the order itself, it covers orders placed with the affiliate's discount code as well as orders that came through their link. A match holds the order with the reason Possible self-referral (same address).
An unknown address is never treated as a match. An affiliate with no signup address on file is never matched: for example one who joined before Sprout Affiliate recorded addresses, or one you added or imported yourself. The same goes for a visit or an order with no address. Shopify gives the app the checkout address together with the customer's name, so if Shopify withholds customer details, only the link visit is compared.
People in one household, office, or public Wi-Fi network can share an address, and so can customers of some mobile networks. That is why this rule holds rather than rejects. Look at the order before you decide. It also works the other way: an affiliate who orders over mobile data instead of their home connection will not match.
Sprout Affiliate does not show IP addresses anywhere in the app. It uses them only for these checks. The privacy policy says how long they are kept.
Default: on for new stores.
The warning tag in Shopify
Referred orders already get a tag in your Shopify admin: Sprout_order by default, plus the affiliate's name. You can change both in Settings > Links, in the Order tags card.
When an order matches either self-referral rule, Sprout Affiliate also adds the tag Sprout_possible_self_referral. It is added when the order is placed, whatever your other tag settings say, so you can see the warning in Shopify's order list and review the order before you ship it. Filter your Shopify orders by that tag to find them.
Three limits. The tag is only added when the order arrives already credited to an affiliate, so an order credited later, through the Web Pixel's report, does not get it. If the check cannot run at that moment, no tag is added, but Sprout Affiliate still holds the order when it next reads your orders. And the tag is never removed: it stays on the order after you approve it.
The other rules on this page do not add a tag. Shopify already shows its own risk rating and any chargeback on the order in your Shopify admin.
Orders Shopify rates as risky
Switch: Hold orders Shopify rates medium or high risk.
Shopify runs its own fraud analysis on many orders, and shows the result on the order in your Shopify admin. With this switch on, an order Shopify rates medium or high risk is held with the reason Shopify rates this order medium risk or Shopify rates this order high risk. A low-risk order is not held.
Shopify does not analyse every order. It mainly analyses orders paid through Shopify Payments. An order with no analysis is not held by this rule.
Sprout Affiliate only holds the commission. What to do about the order itself, including cancelling it if Shopify recommends that, is up to you in Shopify.
Default: on for new stores.
Chargebacks
Switch: Take back commission on charged-back orders.
A chargeback is when a buyer's bank reverses a card payment. With this switch on:
- While a chargeback is open, the order's commission is held with the reason Chargeback open.
- If you win it, the hold is lifted and the order goes through your normal approval settings.
- If you lose it or accept it, the order is treated like a full refund. If the commission has not been paid yet, it drops to $0. If it has been paid, Sprout Affiliate raises a clawback: a row named "order name refund" with a negative commission. Once approved, it comes off that affiliate's next payout, the same way a refund does. See Refunds and clawbacks. The usage fee on that sale is credited back, as it is for a refund.
A bank inquiry, a question from the bank that comes before a chargeback, does not hold anything until it becomes a chargeback.
Sprout Affiliate reads the chargebacks Shopify records on the order, which means chargebacks on orders paid through Shopify Payments. A chargeback handled only by another payment provider is not seen. For those, refund the order in Shopify or reject the referral to take the commission back.
Default: on for new stores.
A new affiliate's first orders
Number field: Orders to review by hand for each new affiliate. It takes 0 to 100. 0 is off, and that is the default.
Set it to 3, for example, and each affiliate's first 3 referral orders wait for you with the reason One of this affiliate's first orders, even with auto-approve on. After that, their orders follow your normal approval settings. It is a way to look at a new affiliate's first sales before you trust them.
Order bursts
Number field: Hold an affiliate's orders beyond this many in 24 hours. It takes 0 to 1000. 0 is off, and that is the default.
Sprout Affiliate counts each affiliate's referral orders over any 24 hours. Orders up to your number go through as normal. Orders beyond it are held with the reason Many orders from this affiliate in 24 hours. A sudden flood of orders from one affiliate is a common sign of card testing or fake orders.
Set it above what your busiest honest affiliate brings in on a good day, so a real launch or a sale does not park every order.
Waiting before automatic approval
Field: Days to wait before approving orders automatically, in Settings > General, in the Affiliate approvals card. It takes 0 to 365, and the default is 0.
When automatic approval is on, each referral order waits that many days after it was placed before it is approved. Until then it shows Approves automatically on YYYY-MM-DD, a date in your store's timezone. Refunds and chargebacks that arrive in that time are applied before any commission is owed, so you are not paying out and then taking it back.
The wait applies wherever automatic approval is on: the store switch, or a program or an affiliate set to approve automatically. With automatic approval off you approve every order yourself, and the wait does nothing. Your own Approve click never waits, so you can let one order through early. The usage fee is billed when the order is approved, so it waits too.
IP address rules for applications
The second card on Settings > Fraud detection, IP address rules, is about affiliate applications rather than orders. Sprout Affiliate records the IP address each application is submitted from.
Affiliate accounts allowed per IP address takes 0 to 100. 0 is off, and that is the default. When an application would go over the limit for its address, it is held for you instead of being approved automatically. It is never rejected. The reason is written into your private note on that affiliate, for example: "Sprout Affiliate held this application for review: 3 affiliate accounts share the address it came from, and the limit on Settings > Fraud detection is 2." This applies to customer referral programs too, which otherwise approve everyone at once. Affiliates with no recorded address are not counted.
Blocked IP addresses takes up to 200 addresses, one per line. Each must be a single IPv4 or IPv6 address; ranges and host names are refused when you save. A blocked address:
- cannot apply. The applicant sees "We can't accept this application." and is not told why.
- earns no referral through the Web Pixel. When a checkout from a blocked address reports a referral, it is not recorded.
One limit: an order credited through a discount code, or through the referral saved on the cart, is still credited, because that route does not check the blocklist. The self-referral rules and your own review cover those orders.
Anti-leak discount protection
Switch: Anti-leak discount protection, in the same card as the order rules. It is on every plan, Free included, and it is off by default.
With it on, a discount code alone earns nothing. The buyer must also have arrived through an affiliate's link. If the click names a different affiliate from the code, that affiliate is credited. If there is no click at all, nobody is paid and the order does not appear in Referral orders. This is what stops a code posted to a coupon site from paying commission on sales the affiliate did not send. Expect fewer credited orders once you turn it on. How anti-leak affects tracking.
Protections that are always on
These need no setting:
- Unsettled orders are never approved for you. Test orders, canceled orders, and orders whose payment has not gone through (pending, voided, or expired) wait in Pending with the reason Test order, Order canceled, or Payment pending and the like. You can still approve one by hand.
- Refunds reduce or take back commission. An unpaid order's commission follows the refund down, to $0 for a full refund. If the commission was already paid, a clawback comes off the affiliate's next payout. See Refunds and clawbacks.
- Applications wait for you. "Auto-approve new affiliates" in Settings > General is off by default, so every application needs your approval.
- You can pull any order back. Move back to pending on an approved order keeps it pending, whatever your auto-approve settings say.
What Sprout Affiliate does not do
- It never rejects or cancels an order on its own. Every rule holds the commission for you to decide.
- It does not touch the Shopify order. It does not cancel, refund, or stop fulfilment of the order. Whether to ship is your decision. The warning tag and Shopify's own risk rating are there to help you make it.
- It does not stop anyone buying. An affiliate's discount code keeps working at checkout, and a blocked IP address can still place orders.
- It does not match buyers by email address. Reading a buyer's email address needs Shopify's Protected Customer Data access for email, which Sprout Affiliate does not request.
- It cannot catch everything. An affiliate who uses a different name and a different internet connection passes both self-referral rules. The wait before approval, the review of new affiliates' first orders, and the chargeback rule are there for what gets through.
A stricter setup
If your store has had trouble with fake orders or chargebacks before, this is a reasonable place to start:
- Keep both self-referral switches, the Shopify risk switch, and the chargeback switch on.
- Set Orders to review by hand for each new affiliate to a small number, such as 3.
- Set Hold an affiliate's orders beyond this many in 24 hours a little above what your busiest affiliate normally sells in a day.
- Set Days to wait before approving orders automatically to at least your return window.
- Turn on Anti-leak discount protection if your codes have turned up on coupon sites.
- Leave Auto-approve new affiliates off, or set Affiliate accounts allowed per IP address to 1 or 2.
- Before you ship, check your Shopify orders for the
Sprout_possible_self_referraltag.
On the phone
The merchant side of the phone app (Growth plan and above) has three of these switches under Settings, Fraud protection: self-referral by name, self-referral by IP address, and anti-leak. Everything else on this page is set on the web only: the Shopify risk and chargeback switches, the two number fields, the wait before automatic approval, and the IP address rules. A held order shows its reason in the phone's order list, and you can approve or reject it there.