← All docs

Fraud protection

Affiliate programs attract a few kinds of abuse: affiliates buying through their own link to earn commission on their own orders, orders paid with stolen cards that come back as chargebacks, and discount codes that leak to coupon sites. Sprout Affiliate has a rule for each. They are in the app under Settings > Fraud detection, and they are on every plan, Free included.

This page describes each rule: what it checks, when it holds an order, what you see, and how it is set when you install.

Every rule holds, nothing is rejected for you

Every order rule on this page works the same way. When an order matches, Sprout Affiliate holds it and flags it for you to decide. A held order is never approved automatically, even when auto-approve is on. It is never rejected for you either. You open it and choose Approve or Reject.

The reason is shown as a badge next to the order on the Referral orders page and the Payouts page, and in the merchant phone app. If an order matches more than one rule, the badge shows the first that applies, in this order: test, canceled or unpaid, then an open chargeback, then self-referral, then Shopify risk, then an order burst, then a new affiliate's first orders.

A flagged order waits in its own Flagged orders section at the top of the Payouts page, and under a Flagged tab on that affiliate's own payout page. Both appear only while something is flagged. Each order there is listed on its own with its own Approve and Reject. Approve all, and the Approve button beside an affiliate in Pending, never include a flagged order, so every one is decided by itself.

The order's own page has a Fraud checks card with a row for every rule you have on, each showing what that rule found for this order. The rules run while an order waits for approval. They are not run again on an order that has been paid.

No usage fee is charged on an order while it is held. The fee is billed when an order is approved, and never on an order you reject.

Settings › Fraud detection › Fraud protection, as a new store finds it
Hold orders where the buyer's name matches the affiliateOn
Hold orders placed from the affiliate's own IP addressOn
Hold orders Shopify rates medium or high riskOn
Take back commission on charged-back ordersOn
Anti-leak discount protectionOff
Orders to review by hand for each new affiliate
0
Hold an affiliate's orders beyond this many in 24 hours
0

0 turns a number field off. The IP address rules for applications are a second card on the same tab.

SettingReason shown on a held orderDefault
Hold orders where the buyer's name matches the affiliatePossible self-referralOn for new stores
Hold orders placed from the affiliate's own IP addressPossible self-referral (same address)On for new stores
Hold orders Shopify rates medium or high riskShopify rates this order high risk, or Shopify rates this order medium riskOn for new stores
Take back commission on charged-back ordersChargeback openOn for new stores
Orders to review by hand for each new affiliateOne of this affiliate's first orders0 (off)
Hold an affiliate's orders beyond this many in 24 hoursMany orders from this affiliate in 24 hours0 (off)
Days to wait before approving orders automatically (Settings > General)Approves automatically on YYYY-MM-DD0 (approve at once)
Anti-leak discount protectionNone. A code-only order is not credited at all.Off
Already using Sprout Affiliate? The four switches marked "On for new stores" may be off on your store. The two self-referral switches keep whatever you had set before, and the Shopify risk and chargeback switches start off. Open Settings > Fraud detection and turn on the ones you want.

Self-referral by name

Switch: Hold orders where the buyer's name matches the affiliate.

Sprout Affiliate compares the customer's name on the Shopify order with the affiliate's name. It compares the whole name and ignores upper and lower case, so "Jane Smith" matches "jane smith". It does not match "Jane A. Smith" or "J. Smith". A match holds the order with the reason Possible self-referral.

The name comes from Shopify, through the Customers permission you approve at install. If an order has no customer name, nothing is compared and the order is not held by this rule.

On the order's Fraud checks card this rule shows whether the names match, differ, or the customer's name is not available.

Default: on for new stores.

Self-referral by IP address

Switch: Hold orders placed from the affiliate's own IP address.

An IP address is the address a device's internet connection is identified by. Sprout Affiliate records the address each affiliate applied from. It compares that address with two others:

Because the second comparison uses the order itself, it covers orders placed with the affiliate's discount code as well as orders that came through their link. A match holds the order with the reason Possible self-referral (same address).

An unknown address is never treated as a match. An affiliate with no signup address on file is never matched: for example one who joined before Sprout Affiliate recorded addresses, or one you added or imported yourself. The same goes for a visit or an order with no address. Shopify gives the app the checkout address together with the customer's name, so if Shopify withholds customer details, only the link visit is compared.

People in one household, office, or public Wi-Fi network can share an address, and so can customers of some mobile networks. That is why this rule holds rather than rejects. Look at the order before you decide. It also works the other way: an affiliate who orders over mobile data instead of their home connection will not match.

Sprout Affiliate does not show IP addresses anywhere in the app. It uses them only for these checks. The privacy policy says how long they are kept.

Default: on for new stores.

The warning tag in Shopify

Referred orders already get a tag in your Shopify admin: Sprout_order by default, plus the affiliate's name. You can change both in Settings > Links, in the Order tags card.

When an order matches either self-referral rule, Sprout Affiliate also adds the tag Sprout_possible_self_referral. It is added when the order is placed, whatever your other tag settings say, so you can see the warning in Shopify's order list and review the order before you ship it. Filter your Shopify orders by that tag to find them.

Three limits. The tag is only added when the order arrives already credited to an affiliate, so an order credited later, through the Web Pixel's report, does not get it. If the check cannot run at that moment, no tag is added, but Sprout Affiliate still holds the order when it next reads your orders. And the tag is never removed: it stays on the order after you approve it.

The other rules on this page do not add a tag. Shopify already shows its own risk rating and any chargeback on the order in your Shopify admin.

Orders Shopify rates as risky

Switch: Hold orders Shopify rates medium or high risk.

Shopify runs its own fraud analysis on many orders, and shows the result on the order in your Shopify admin. With this switch on, an order Shopify rates medium or high risk is held with the reason Shopify rates this order medium risk or Shopify rates this order high risk. A low-risk order is not held.

Shopify does not analyse every order. It mainly analyses orders paid through Shopify Payments. An order with no analysis is not held by this rule.

Sprout Affiliate only holds the commission. What to do about the order itself, including cancelling it if Shopify recommends that, is up to you in Shopify.

Default: on for new stores.

Chargebacks

Switch: Take back commission on charged-back orders.

A chargeback is when a buyer's bank reverses a card payment. With this switch on:

A bank inquiry, a question from the bank that comes before a chargeback, does not hold anything until it becomes a chargeback.

Sprout Affiliate reads the chargebacks Shopify records on the order, which means chargebacks on orders paid through Shopify Payments. A chargeback handled only by another payment provider is not seen. For those, refund the order in Shopify or reject the referral to take the commission back.

Default: on for new stores.

A new affiliate's first orders

Number field: Orders to review by hand for each new affiliate. It takes 0 to 100. 0 is off, and that is the default.

Set it to 3, for example, and each affiliate's first 3 referral orders wait for you with the reason One of this affiliate's first orders, even with auto-approve on. After that, their orders follow your normal approval settings. It is a way to look at a new affiliate's first sales before you trust them.

Order bursts

Number field: Hold an affiliate's orders beyond this many in 24 hours. It takes 0 to 1000. 0 is off, and that is the default.

Sprout Affiliate counts each affiliate's referral orders over any 24 hours. Orders up to your number go through as normal. Orders beyond it are held with the reason Many orders from this affiliate in 24 hours. A sudden flood of orders from one affiliate is a common sign of card testing or fake orders.

Set it above what your busiest honest affiliate brings in on a good day, so a real launch or a sale does not park every order.

Waiting before automatic approval

Field: Days to wait before approving orders automatically, in Settings > General, in the Affiliate approvals card. It takes 0 to 365, and the default is 0.

When automatic approval is on, each referral order waits that many days after it was placed before it is approved. Until then it shows Approves automatically on YYYY-MM-DD, a date in your store's timezone. Refunds and chargebacks that arrive in that time are applied before any commission is owed, so you are not paying out and then taking it back.

The wait applies wherever automatic approval is on: the store switch, or a program or an affiliate set to approve automatically. With automatic approval off you approve every order yourself, and the wait does nothing. Your own Approve click never waits, so you can let one order through early. The usage fee is billed when the order is approved, so it waits too.

IP address rules for applications

The second card on Settings > Fraud detection, IP address rules, is about affiliate applications rather than orders. Sprout Affiliate records the IP address each application is submitted from.

Affiliate accounts allowed per IP address takes 0 to 100. 0 is off, and that is the default. When an application would go over the limit for its address, it is held for you instead of being approved automatically. It is never rejected. The reason is written into your private note on that affiliate, for example: "Sprout Affiliate held this application for review: 3 affiliate accounts share the address it came from, and the limit on Settings > Fraud detection is 2." This applies to customer referral programs too, which otherwise approve everyone at once. Affiliates with no recorded address are not counted.

Blocked IP addresses takes up to 200 addresses, one per line. Each must be a single IPv4 or IPv6 address; ranges and host names are refused when you save. A blocked address:

One limit: an order credited through a discount code, or through the referral saved on the cart, is still credited, because that route does not check the blocklist. The self-referral rules and your own review cover those orders.

Anti-leak discount protection

Switch: Anti-leak discount protection, in the same card as the order rules. It is on every plan, Free included, and it is off by default.

With it on, a discount code alone earns nothing. The buyer must also have arrived through an affiliate's link. If the click names a different affiliate from the code, that affiliate is credited. If there is no click at all, nobody is paid and the order does not appear in Referral orders. This is what stops a code posted to a coupon site from paying commission on sales the affiliate did not send. Expect fewer credited orders once you turn it on. How anti-leak affects tracking.

Protections that are always on

These need no setting:

What Sprout Affiliate does not do

A stricter setup

If your store has had trouble with fake orders or chargebacks before, this is a reasonable place to start:

  1. Keep both self-referral switches, the Shopify risk switch, and the chargeback switch on.
  2. Set Orders to review by hand for each new affiliate to a small number, such as 3.
  3. Set Hold an affiliate's orders beyond this many in 24 hours a little above what your busiest affiliate normally sells in a day.
  4. Set Days to wait before approving orders automatically to at least your return window.
  5. Turn on Anti-leak discount protection if your codes have turned up on coupon sites.
  6. Leave Auto-approve new affiliates off, or set Affiliate accounts allowed per IP address to 1 or 2.
  7. Before you ship, check your Shopify orders for the Sprout_possible_self_referral tag.

On the phone

The merchant side of the phone app (Growth plan and above) has three of these switches under Settings, Fraud protection: self-referral by name, self-referral by IP address, and anti-leak. Everything else on this page is set on the web only: the Shopify risk and chargeback switches, the two number fields, the wait before automatic approval, and the IP address rules. A held order shows its reason in the phone's order list, and you can approve or reject it there.