How to prevent affiliate self-referral fraud on Stripe
Self-referral lets a partner earn commission on their own subscription. Compare buyer and partner by email, Stripe card fingerprint and IP, then hold payouts.
Muzahid Maruf, FounderUpdated
On this page
Explore with AI
Opens this article inside the chosen assistant with a ready-made prompt.
Affiliate self-referral fraud is a partner earning commission on their own purchase, through their own link or coupon code.
You prevent it by comparing partner and buyer on email, Stripe card fingerprint, IP and device, then holding flagged commission until the dispute window closes.
At 25% commission on a $99 monthly plan, the partner pays $99 and earns $24.75, so the plan costs them $74.25 a month.
| Self-referred accounts | Commission each month | Commission over 12 months |
|---|---|---|
| 1 | $24.75 | $297 |
| 10 | $247.50 | $2,970 |
| 50 | $1,237.50 | $14,850 |
| 100 | $2,475 | $29,700 |
Commission paid at 25% of a $99 plan, if every account stays subscribed for 12 months.
Key takeaways
- A self-referral leaves a real click, cookie and payment, so compare partner and buyer on 4 signals: email, card fingerprint, IP and device.
- Card networks typically allow disputes for 120 days, and one lost $99 dispute costs $138.75 with the $24.75 commission and $15.00 fee.
- Stripe's Charge has no IP address, so log it yourself, and use a match to start a review.
The click, the cookie and the Stripe payment are all real, so the tracking looks clean. Cookie stuffing and bot clicks distort the click data (attribution fraud detection), and a self-referral shows up only when you compare partner and buyer.
Three kinds of self-referral, and only one is fraud
The Rewardful Help Center sorts self-referrals into legitimate, accidental and fraudulent cases. Only the third deserves a penalty, and a first offense with no hiding signals gets a conversation.
| Kind | What it looks like | What to do |
|---|---|---|
| Legitimate | An agency resells through its own link | Allow it in the partner terms |
| Accidental | A partner tests their own link, then buys with the cookie still set | Reverse the commission, no penalty |
| Fraudulent | Someone joins to buy at a discount: 30% commission on a $100 plan makes it $70 a month | Reverse it and remove the partner |
Categories from Rewardful's article on self-referrals. The actions are my recommendations.
What affiliate self-referral fraud leaves in your Stripe data
A click is easier to fake than a payment, so the identity evidence sits on the Stripe side. Read these 5 signals together, because each can be beaten.
A partner paid on a coupon code leaves no click, so coupon code tracking leans on the first 3 rows.
| Signal | Where to read it | Strength | Caveat |
|---|---|---|---|
customer_details.email on the Checkout Session | Strong on a match | Lowercase both, strip any +tag, and drop the dots in Gmail addresses | |
| Card fingerprint | payment_method_details.card.fingerprint on the Charge | Strong on a match | Apple Pay and Google Pay may return a tokenized number |
| Name and ZIP | billing_details.name and billing_details.address.postal_code | Soft | A different name or ZIP beats it |
| IP address | Your own server log | Soft | A match can be 2 strangers behind one NAT |
| Device | Your own cookie and fingerprint | Strong for the cookie, soft for the fingerprint | Set the cookie from your server, because Safari Intelligent Tracking Prevention deletes script-written storage after 7 days of no user interaction |
Field names are from Stripe's Charge and PaymentMethod references. The Safari limit is from WebKit's tracking prevention page.
IP address: log it yourself and never reject on it alone
The Charge has no IP field, and the Radar Review object keeps its ip_address on the review.
Log the buyer's IP when you create the Stripe Checkout Session and store a salted hash, because IP addresses can count as personal data (affiliate compliance for FTC and GDPR).
Step 1: Write the rule into the partner terms and vet applicants
Write the 3 kinds into your affiliate terms: which you allow, which you reverse, and that a partner who hides a self-referral loses the account and unpaid earnings.
Be wary of an applicant with no site or audience whose first sale arrives within days, and use TrackRev's "Review each application" mode to decide each one.
Step 2: Record identity at the click and at checkout
Store 4 values with every click: the partner ID, a click ID, a hashed IP and a device ID. At Stripe Checkout, pass the click ID as client_reference_id and the partner as subscription metadata (Stripe metadata attribution).
const session = await stripe.checkout.sessions.create({ mode: "subscription", line_items: [{ price: PRICE_ID, quantity: 1 }], client_reference_id: clickId, subscription_data: { metadata: { partner_id: partnerId, click_id: clickId } }, success_url: SUCCESS_URL, cancel_url: CANCEL_URL,}); // Stripe does not give you the checkout IP, so keep your own record.// hashIp, clientIp and saveCheckoutContext are your helpers.await saveCheckoutContext(session.id, { ipHash: hashIp(clientIp(req)), deviceId });Step 3: Compare the partner with the buyer when the charge succeeds
On charge.succeeded, match the card fingerprint against the partner's own customer record and their other referrals. Hold the commission on a normalized email, card fingerprint or device cookie match.
Hold any 2 of IP, device fingerprint, name and ZIP for review, and pay a single soft match after logging it.
| Example | Plan price | Commission at 25% | What matched | Action |
|---|---|---|---|---|
| 1 | $99 | $24.75 | Normalized email and card fingerprint | Hold and flag it |
| 2 | $99 | $24.75 | IP only, a coworking space | Pay and keep the log |
| 3 | $49 | $12.25 | IP and billing ZIP | Hold for review |
| 4 | $199 | $49.75 | Nothing | Pay |
| 5 | $99 | $24.75 | The partner's own device cookie | Hold, probably their own purchase |
| 6 | $199 | $49.75 | A card that 3 other referrals from the same partner also used | Hold, likely one person |
| 7 | $39 | $9.75 | Apple Pay, no other signal | Pay |
| 8 | $49 | $12.25 | Name and device fingerprint | Hold for review |
| 9 | $99 | $24.75 | An agency partner the terms allow | Pay |
| 10 | $39 | $9.75 | Cardholder name and ZIP | Hold for review |
Ten example conversions run through the rule above. Example 7 is the wallet blind spot.
function normalizeEmail(email: string): string { const [local, domain] = email.trim().toLowerCase().split("@"); const base = local.split("+")[0]; return domain === "gmail.com" ? base.replaceAll(".", "") + "@" + domain : base + "@" + domain;} type Party = { email: string; ipHash?: string; deviceId?: string; postalCode?: string; cardFingerprints: string[];}; export function selfReferralSignals(partner: Party, buyer: Party): string[] { const hits: string[] = []; if (normalizeEmail(partner.email) === normalizeEmail(buyer.email)) hits.push("email"); if (partner.cardFingerprints.some((f) => buyer.cardFingerprints.includes(f))) hits.push("card"); if (partner.deviceId && partner.deviceId === buyer.deviceId) hits.push("device"); if (partner.ipHash && partner.ipHash === buyer.ipHash) hits.push("ip"); if (partner.postalCode && partner.postalCode === buyer.postalCode) hits.push("zip"); return hits;}Step 4: Hold commission past the refund and dispute window
Detection misses someone with a second card and browser, and a hold catches the rest because unpaid commission can still be reversed. A 30-day hold pays commission on sales that cardholders can still dispute.
| Stripe dispute fact | Value |
|---|---|
| Cardholder may file a dispute | Typically within 120 days of the payment |
| Local payment methods such as Klarna and PayPal | Typically up to 180 days |
| You respond to the issuer | Usually within 7 to 21 days |
| Issuer decides | Usually 60 to 75 days later |
| Latest final result | About day 216 (120 + 21 + 75) |
| Fee for each dispute received | $15.00, about 15% of a $99 payment, plus a further $15.00 if you counter, returned when you win |
From Stripe's dispute documentation and US pricing page. The 216 is my arithmetic.
A partner can buy on a stolen card, get paid, and leave you holding the dispute.
The hold decides whether commission is part of the loss, and a refund after payout leaves the $24.75 to recover from the partner (refund clawbacks).
| A $99 payment is disputed | Payment | Stripe fee | Commission | You lose |
|---|---|---|---|---|
| Lost after the partner was paid | $99 | $15.00 | $24.75 | $138.75 |
| Lost while the commission was held | $99 | $15.00 | $0 | $114.00 |
| Won after the partner was paid | $0 | $15.00 | $24.75 | $39.75 |
| Won while the commission was held | $0 | $15.00 | $0 | $15.00 |
Lost rows assume you do not counter. A won dispute means you countered, and Stripe returns the $15.00 countered fee but keeps the $15.00 received fee.
The cost of a long hold is partner patience. At $24.75 a month and a 120-day hold, a new partner has $99 pending by the time the first $24.75 clears.
My compromise is 30 to 60 days once a program has a clean history, and 120 days while it is new.
Step 5: Review flagged commissions and reverse the bad ones
Show a person the matched signals and both emails. Allow a legitimate case, reverse an accidental one without penalty, and for a fraudulent one reverse the commission, remove the partner and check their other commissions.
Tell the partner why, or a silent reversal costs you an honest one who tripped an IP rule.
What your affiliate tool already checks
On Rewardful or FirstPromoter, the card comparison from step 3 is yours to add, because neither help article lists a card check.
| Tool | Automatic self-referral check | What happens next | Source date |
|---|---|---|---|
| Rewardful | Several methods it does not disclose | An email asks you to choose Looks good or Looks suspicious | February 2022 |
| FirstPromoter | Same email or same IP, plus referrals from 11 paid ad sources | A warning icon, a Fraud check filter and a cap above which approval is manual | May 21, 2026 |
| TrackRev, credit programs | 3 checks: same-browser marker, device fingerprint, same IP on a different device | The grant is written as revoked with a reason, and an admin can override it | October 2026 |
| TrackRev, cash commissions | None automatic | You review, then mark a commission void or fraud before it joins a payout batch | October 2026 |
Self-referral handling as each vendor documents it. Sources: Rewardful, FirstPromoter and TrackRev's own documentation.
What TrackRev does and does not do
Cash commissions run none of those 3 checks.
The controls act before money moves: the approval mode from step 1, a Customers page showing each referred customer beside the partner who referred them, 6 commission statuses including void and fraud, and automatic reversal on refunds.
A program's Hold period runs from 0 to 180 days and defaults to 0, and payouts are batches you run yourself, so run one only when its commissions are older than your window.
A commission already on a batch cannot be changed, so review first.
trackrev commissions list --status pending --partner <partner-id>
trackrev commissions void <commission-id> --status fraud --yes| Plan | Price | Workspaces | Tracked domains | Affiliate program | Commission tracked a month |
|---|---|---|---|---|---|
| Free | $0 | 1 | Not applicable | Not included (50 links, 1,000 events a month) | Not applicable |
| Indie | $29 a month ($348 over 12 months) | 1 | 1 | Included | No cap |
| Growth | $299 a year (about $25 a month) | Up to 10 | Up to 10 | Included | No cap |
Indie bills monthly only and Growth bills yearly only. Neither plan caps the commission tracked, so voiding a fraudulent commission never affects a limit. Growth covers up to 10 sites from one account, with unlimited team members to share the review of flagged commissions, and each program on either plan sets its own hold from 0 to 180 days.
FirstPromoter documents an automatic email and IP self-referral flag, and TrackRev has none for cash commissions. TrackRev is SaaS affiliate software with link tracking and revenue attribution built in, and the affiliate program page lists its commission controls.
Found this useful? Share it.
Frequently asked questions
- A partner buying through their own link or coupon so the program pays them a share. Some programs allow agencies to resell that way, so not every case is fraud.
- No, because a second address defeats an exact match. Compare email domains too, since a buyer on the partner's company domain is a coworker or the partner, and add the card fingerprint.
- Release the commission, record which signal fired, tell the partner, and write any agency exception into your terms.
- A signup reward has no payment to fingerprint, so compare email, IP, device and a same-browser marker at signup. TrackRev's credit programs run 3 such checks automatically.
- In TrackRev it does, automatically. Commission already paid, such as $24.75 on a $99 sale, has to be recovered from the partner, for example by deducting it from a later payout.
- No. Its documentation says cash commissions skip the 3 checks that credit programs use, so you review them and mark a bad one void or fraud.

Written by
Founder, TrackRev.io & Contant.io
Muzahid Maruf founded TrackRev.io, SaaS affiliate software with no limit on tracked revenue, and Contant.io. He writes about affiliate programs.
Writes about Marketing attribution · Link tracking · Revenue analytics · SaaS growth
Stop guessing where your revenue comes from.
Set up TrackRev in about five minutes. The free plan covers 1,000 events a month, no card needed.
Start free