How loyalty cards leak, and how to stop it
Loyalty fraud is rarely dramatic. It is a rubber stamp bought online, a code shared in a group chat, or a member of staff rounding up because they are not sure. Together these usually cost more than the scheme was ever designed to give away.
Start your free trial →Forgery is the paper problem
A rubber stamp that matches yours costs a few euros and takes a week to arrive, and there is no version of a paper card that defends against it. This is not a rare edge case in busy areas — it is the single largest leak in most paper schemes, and it is invisible to you.
Sharing is the printed-QR problem
A QR code printed on a sticker never changes, so one photograph is a permanent free stamp for anyone who has it. Schemes that move from paper to a printed code usually make the leak worse rather than better, because copying is now effortless and leaves no trace.
Rounding up is the staff problem
The quietest leak is a member of staff who is unsure and gives the benefit of the doubt, several times a week, for a year. Nobody is doing anything wrong, and that is why it never gets noticed — the fix is a system where there is no judgement call to make.
The three leaks
Almost all loyalty leakage falls into three buckets, in rough order of size.
1. Forged stamps
A rubber stamp matching yours is a cheap online purchase. There is no countermeasure available to a paper card — a foil sticker or an unusual ink slows it down slightly and gets copied too. The scheme is running on the honesty of everyone who ever saw the card.
2. Shared or copied codes
This is the leak that businesses create for themselves when they move to a printed QR code, believing they have modernised. A static code is a shared secret that every past customer holds forever, and a single photo in a group chat is unlimited free stamps with nothing to trace.
3. Rounding up
The invisible one. A customer says they had six, staff cannot check, and the answer is yes. Or a card is lost and a replacement gets a few stamps as an apology. Individually all reasonable; over a year, this alone can shift an effective ten-stamp card to nearer seven.
What actually closes each
| Leak | Paper | Printed QR | Regenerating QR |
|---|---|---|---|
| Forged stamps | No defence | Closed | Closed |
| Shared codes | n/a | No defence | Closed |
| Rounding up | No defence | Partial | Closed |
The row that matters is the middle one. Moving from paper to a printed code fixes forgery and immediately opens a worse hole, which is why the detail of whether the code changes is the whole design.
Codes that close all three are:
- Single-use — consumed by the first scan.
- Short-lived — expired after thirty seconds regardless.
- Regenerated — a new one the instant the previous is used.
What no system fixes
Be realistic: a member of staff who deliberately scans the kiosk for a friend who bought nothing will succeed, in the same way they could hand over a free coffee. That is a staffing question rather than a loyalty one. What a digital card does is remove every passive leak — the ones that happen without anyone deciding to do anything wrong — which is where nearly all the money actually goes.
The mistakes that are still yours to make
- Printing the QR code. Cheaper, and it breaks the whole thing.
- Leaving the kiosk unattended where people can scan without buying.
- Setting no expiry on the codes, which is the same as printing them.
The questions everyone asks
How common is loyalty card fraud really?
Common enough to matter, though rarely organised. It is mostly ordinary customers taking an opportunity that is sitting in front of them — a photographed code shared with a colleague, or a duplicate stamp. The volume comes from how easy it is, not from anyone setting out to defraud you.
Does a digital card eliminate it completely?
It closes the three big leaks — forging, sharing and rounding up — because codes are single-use, expire in thirty seconds and are counted by the system rather than judged by a person. What it cannot stop is a member of staff deliberately scanning a code for someone who did not buy anything.
What about someone scanning a code twice?
Each code is consumed by the first scan and a new one replaces it immediately, so a second attempt on the same code returns an expired message. To get another stamp, a customer would have to be standing in front of your screen again for a fresh one.
Should I be worried about customers sharing codes in a group chat?
Not with codes that expire after thirty seconds. By the time a screenshot is posted and someone opens it, the code is dead. This is precisely the attack that printed QR codes are defenceless against and that regenerating codes are designed around.
$29/month · 7-day free trial
Unlimited stamps · Unlimited customers · No per-scan fees
Start your free trial →