How to prevent affiliate self-referral fraud on Stripe

Self-referral lets a partner earn commission on their own subscription. Compare buyer and partner by email, Stripe card fingerprint and IP, then hold payouts.

Muzahid Maruf — Founder of TrackRev.io

Muzahid MarufUpdated

Affiliate fraud · 8 min read
On this page
  1. 01Three kinds of self-referral, and only one is fraud
  2. 02What affiliate self-referral fraud leaves in your Stripe data
  3. 03How to prevent affiliate self-referral fraud, step by step
  4. 04What your affiliate tool already checks

Explore with AI

Opens this article inside the chosen assistant with a ready-made prompt.

Affiliate self-referral fraud is a partner earning commission on their own purchase, through their own link or coupon code.

You prevent it by comparing partner and buyer on email, Stripe card fingerprint, IP and device, then holding flagged commission until the dispute window closes.

At 25% commission on a $99 monthly plan, the partner pays $99 and earns $24.75, so the plan costs them $74.25 a month.

Self-referred accountsCommission each monthCommission over 12 months
1$24.75$297
10$247.50$2,970
50$1,237.50$14,850
100$2,475$29,700

Commission paid at 25% of a $99 plan, if every account stays subscribed for 12 months.

Key takeaways

  • A self-referral leaves a real click, cookie and payment, so compare partner and buyer on 4 signals: email, card fingerprint, IP and device.
  • Card networks typically allow disputes for 120 days, and one lost $99 dispute costs $138.75 with the $24.75 commission and $15.00 fee.
  • Stripe's Charge has no IP address, so log it yourself, and use a match to start a review.

The click, the cookie and the Stripe payment are all real, so the tracking looks clean. Cookie stuffing and bot clicks distort the click data (attribution fraud detection), and a self-referral shows up only when you compare partner and buyer.

Three kinds of self-referral, and only one is fraud

The Rewardful Help Center sorts self-referrals into legitimate, accidental and fraudulent cases. Only the third deserves a penalty, and a first offense with no hiding signals gets a conversation.

KindWhat it looks likeWhat to do
LegitimateAn agency resells through its own linkAllow it in the partner terms
AccidentalA partner tests their own link, then buys with the cookie still setReverse the commission, no penalty
FraudulentSomeone joins to buy at a discount: 30% commission on a $100 plan makes it $70 a monthReverse it and remove the partner

Categories from Rewardful's article on self-referrals. The actions are my recommendations.

What affiliate self-referral fraud leaves in your Stripe data

A click is easier to fake than a payment, so the identity evidence sits on the Stripe side. Read these 5 signals together, because each can be beaten.

A partner paid on a coupon code leaves no click, so coupon code tracking leans on the first 3 rows.

SignalWhere to read itStrengthCaveat
Emailcustomer_details.email on the Checkout SessionStrong on a matchLowercase both, strip any +tag, and drop the dots in Gmail addresses
Card fingerprintpayment_method_details.card.fingerprint on the ChargeStrong on a matchApple Pay and Google Pay may return a tokenized number
Name and ZIPbilling_details.name and billing_details.address.postal_codeSoftA different name or ZIP beats it
IP addressYour own server logSoftA match can be 2 strangers behind one NAT
DeviceYour own cookie and fingerprintStrong for the cookie, soft for the fingerprintSet the cookie from your server, because Safari Intelligent Tracking Prevention deletes script-written storage after 7 days of no user interaction

Field names are from Stripe's Charge and PaymentMethod references. The Safari limit is from WebKit's tracking prevention page.

IP address: log it yourself and never reject on it alone

The Charge has no IP field, and the Radar Review object keeps its ip_address on the review.

Log the buyer's IP when you create the Stripe Checkout Session and store a salted hash, because IP addresses can count as personal data (affiliate compliance for FTC and GDPR).

Address typeWhat to hashWhy
IPv4The whole addressCarrier-grade NAT, a Best Current Practice in RFC 6888 (April 2013), lets an ISP share one address among many subscribers
IPv6The first 64 bitsRFC 4941 temporary addresses (September 2007) change the last 64 bits over time

How to prevent affiliate self-referral fraud, step by step

Step 1: Write the rule into the partner terms and vet applicants

Write the 3 kinds into your affiliate terms: which you allow, which you reverse, and that a partner who hides a self-referral loses the account and unpaid earnings.

Be wary of an applicant with no site or audience whose first sale arrives within days, and use TrackRev's "Review each application" mode to decide each one.

Step 2: Record identity at the click and at checkout

Store 4 values with every click: the partner ID, a click ID, a hashed IP and a device ID. At Stripe Checkout, pass the click ID as client_reference_id and the partner as subscription metadata (Stripe metadata attribution).

TypeScript, creating the Checkout Session
const session = await stripe.checkout.sessions.create({  mode: "subscription",  line_items: [{ price: PRICE_ID, quantity: 1 }],  client_reference_id: clickId,  subscription_data: { metadata: { partner_id: partnerId, click_id: clickId } },  success_url: SUCCESS_URL,  cancel_url: CANCEL_URL,}); // Stripe does not give you the checkout IP, so keep your own record.// hashIp, clientIp and saveCheckoutContext are your helpers.await saveCheckoutContext(session.id, { ipHash: hashIp(clientIp(req)), deviceId });

Step 3: Compare the partner with the buyer when the charge succeeds

On charge.succeeded, match the card fingerprint against the partner's own customer record and their other referrals. Hold the commission on a normalized email, card fingerprint or device cookie match.

Hold any 2 of IP, device fingerprint, name and ZIP for review, and pay a single soft match after logging it.

ExamplePlan priceCommission at 25%What matchedAction
1$99$24.75Normalized email and card fingerprintHold and flag it
2$99$24.75IP only, a coworking spacePay and keep the log
3$49$12.25IP and billing ZIPHold for review
4$199$49.75NothingPay
5$99$24.75The partner's own device cookieHold, probably their own purchase
6$199$49.75A card that 3 other referrals from the same partner also usedHold, likely one person
7$39$9.75Apple Pay, no other signalPay
8$49$12.25Name and device fingerprintHold for review
9$99$24.75An agency partner the terms allowPay
10$39$9.75Cardholder name and ZIPHold for review

Ten example conversions run through the rule above. Example 7 is the wallet blind spot.

TypeScript, the comparison
function normalizeEmail(email: string): string {  const [local, domain] = email.trim().toLowerCase().split("@");  const base = local.split("+")[0];  return domain === "gmail.com" ? base.replaceAll(".", "") + "@" + domain : base + "@" + domain;} type Party = {  email: string;  ipHash?: string;  deviceId?: string;  postalCode?: string;  cardFingerprints: string[];}; export function selfReferralSignals(partner: Party, buyer: Party): string[] {  const hits: string[] = [];  if (normalizeEmail(partner.email) === normalizeEmail(buyer.email)) hits.push("email");  if (partner.cardFingerprints.some((f) => buyer.cardFingerprints.includes(f))) hits.push("card");  if (partner.deviceId && partner.deviceId === buyer.deviceId) hits.push("device");  if (partner.ipHash && partner.ipHash === buyer.ipHash) hits.push("ip");  if (partner.postalCode && partner.postalCode === buyer.postalCode) hits.push("zip");  return hits;}

Step 4: Hold commission past the refund and dispute window

Detection misses someone with a second card and browser, and a hold catches the rest because unpaid commission can still be reversed. A 30-day hold pays commission on sales that cardholders can still dispute.

Stripe dispute factValue
Cardholder may file a disputeTypically within 120 days of the payment
Local payment methods such as Klarna and PayPalTypically up to 180 days
You respond to the issuerUsually within 7 to 21 days
Issuer decidesUsually 60 to 75 days later
Latest final resultAbout day 216 (120 + 21 + 75)
Fee for each dispute received$15.00, about 15% of a $99 payment, plus a further $15.00 if you counter, returned when you win

From Stripe's dispute documentation and US pricing page. The 216 is my arithmetic.

A partner can buy on a stolen card, get paid, and leave you holding the dispute.

The hold decides whether commission is part of the loss, and a refund after payout leaves the $24.75 to recover from the partner (refund clawbacks).

A $99 payment is disputedPaymentStripe feeCommissionYou lose
Lost after the partner was paid$99$15.00$24.75$138.75
Lost while the commission was held$99$15.00$0$114.00
Won after the partner was paid$0$15.00$24.75$39.75
Won while the commission was held$0$15.00$0$15.00

Lost rows assume you do not counter. A won dispute means you countered, and Stripe returns the $15.00 countered fee but keeps the $15.00 received fee.

The cost of a long hold is partner patience. At $24.75 a month and a 120-day hold, a new partner has $99 pending by the time the first $24.75 clears.

My compromise is 30 to 60 days once a program has a clean history, and 120 days while it is new.

Step 5: Review flagged commissions and reverse the bad ones

Show a person the matched signals and both emails. Allow a legitimate case, reverse an accidental one without penalty, and for a fraudulent one reverse the commission, remove the partner and check their other commissions.

Tell the partner why, or a silent reversal costs you an honest one who tripped an IP rule.

What your affiliate tool already checks

On Rewardful or FirstPromoter, the card comparison from step 3 is yours to add, because neither help article lists a card check.

ToolAutomatic self-referral checkWhat happens nextSource date
RewardfulSeveral methods it does not discloseAn email asks you to choose Looks good or Looks suspiciousFebruary 2022
FirstPromoterSame email or same IP, plus referrals from 11 paid ad sourcesA warning icon, a Fraud check filter and a cap above which approval is manualMay 21, 2026
TrackRev, credit programs3 checks: same-browser marker, device fingerprint, same IP on a different deviceThe grant is written as revoked with a reason, and an admin can override itOctober 2026
TrackRev, cash commissionsNone automaticYou review, then mark a commission void or fraud before it joins a payout batchOctober 2026

Self-referral handling as each vendor documents it. Sources: Rewardful, FirstPromoter and TrackRev's own documentation.

What TrackRev does and does not do

Cash commissions run none of those 3 checks.

The controls act before money moves: the approval mode from step 1, a Customers page showing each referred customer beside the partner who referred them, 6 commission statuses including void and fraud, and automatic reversal on refunds.

A program's Hold period runs from 0 to 180 days and defaults to 0, and payouts are batches you run yourself, so run one only when its commissions are older than your window.

A commission already on a batch cannot be changed, so review first.

TrackRev CLI, reviewing and marking a commission
trackrev commissions list --status pending --partner <partner-id>
trackrev commissions void <commission-id> --status fraud --yes
PlanPriceWorkspacesTracked domainsAffiliate programCommission tracked a month
Free$01Not applicableNot included (50 links, 1,000 events a month)Not applicable
Indie$29 a month ($348 over 12 months)11IncludedNo cap
Growth$299 a year (about $25 a month)Up to 10Up to 10IncludedNo cap

Indie bills monthly only and Growth bills yearly only. Neither plan caps the commission tracked, so voiding a fraudulent commission never affects a limit. Growth covers up to 10 sites from one account, with unlimited team members to share the review of flagged commissions, and each program on either plan sets its own hold from 0 to 180 days.

FirstPromoter documents an automatic email and IP self-referral flag, and TrackRev has none for cash commissions. TrackRev is SaaS affiliate software with link tracking and revenue attribution built in, and the affiliate program page lists its commission controls.

Found this useful? Share it.

PostLinkedIn

Frequently asked questions

Muzahid Maruf — Founder of TrackRev.io

Written by

Muzahid Maruf

Founder, TrackRev.io & Contant.io

Muzahid Maruf founded TrackRev.io, SaaS affiliate software with no limit on tracked revenue, and Contant.io. He writes about affiliate programs.

Writes about Marketing attribution · Link tracking · Revenue analytics · SaaS growth

Stop guessing where your revenue comes from.

Set up TrackRev in about five minutes. The free plan covers 1,000 events a month, no card needed.

Start free