Guide

How loyalty cards leak, and how to stop it

Loyalty fraud is rarely dramatic. It is a rubber stamp bought online, a code shared in a group chat, or a member of staff rounding up because they are not sure. Together these usually cost more than the scheme was ever designed to give away.

Start your free trial →
7-day free trial · No credit card required

Forgery is the paper problem

A rubber stamp that matches yours costs a few euros and takes a week to arrive, and there is no version of a paper card that defends against it. This is not a rare edge case in busy areas — it is the single largest leak in most paper schemes, and it is invisible to you.

Sharing is the printed-QR problem

A QR code printed on a sticker never changes, so one photograph is a permanent free stamp for anyone who has it. Schemes that move from paper to a printed code usually make the leak worse rather than better, because copying is now effortless and leaves no trace.

Rounding up is the staff problem

The quietest leak is a member of staff who is unsure and gives the benefit of the doubt, several times a week, for a year. Nobody is doing anything wrong, and that is why it never gets noticed — the fix is a system where there is no judgement call to make.

The questions everyone asks

How common is loyalty card fraud really?

Common enough to matter, though rarely organised. It is mostly ordinary customers taking an opportunity that is sitting in front of them — a photographed code shared with a colleague, or a duplicate stamp. The volume comes from how easy it is, not from anyone setting out to defraud you.

Does a digital card eliminate it completely?

It closes the three big leaks — forging, sharing and rounding up — because codes are single-use, expire in thirty seconds and are counted by the system rather than judged by a person. What it cannot stop is a member of staff deliberately scanning a code for someone who did not buy anything.

What about someone scanning a code twice?

Each code is consumed by the first scan and a new one replaces it immediately, so a second attempt on the same code returns an expired message. To get another stamp, a customer would have to be standing in front of your screen again for a fresh one.

Should I be worried about customers sharing codes in a group chat?

Not with codes that expire after thirty seconds. By the time a screenshot is posted and someone opens it, the code is dead. This is precisely the attack that printed QR codes are defenceless against and that regenerating codes are designed around.

$29/month · 7-day free trial

Unlimited stamps · Unlimited customers · No per-scan fees

Start your free trial →