Skip to content

Discount-Code & Affiliate Sales Mastery · Reporting, payouts and protecting integrity · lesson 9 of 12 · 15 min

Avoiding fraud, self-dealing and policy violations

Why integrity is non-negotiable

Affiliate and code programmes work only if brands can trust the data. Fraud — deliberate or careless — harms brands, honest creators and customers. Platforms and brands use increasingly sophisticated checks, and consequences range from reversed commissions and account suspension to legal action. Integrity is also your long-term competitive advantage: trusted sellers get the best campaigns.

Common forms of fraud and self-dealing

1. Self-purchasing (self-dealing) Buying with your own code or link to earn commission, then keeping or returning the product. Unless a programme explicitly allows it, this is a violation.

2. Incentivised or paid orders Paying friends or family to buy with your code, or refunding them afterwards. This creates fake sales.

3. Fake or duplicate reporting Submitting orders that didn't happen, reporting the same order twice, or claiming others' sales.

4. Code leaking and coupon-site abuse Posting your code on coupon sites or forums where the programme forbids it, capturing sales you didn't influence.

5. Cookie stuffing and click fraud Forcing tracking cookies onto users without a genuine click, or using bots to generate clicks.

6. Brand-bidding and impersonation Running ads on the brand's name, or pretending to be the brand's official account.

7. Fake engagement Buying followers, likes or comments to appear more influential in order to win campaigns.

8. Misleading claims Inventing results, testimonials or scarcity to push sales.

Grey areas — ask first

  • Buying for yourself because you genuinely want the product: fine to buy, but don't use your own code unless the brief allows it.
  • Family members who genuinely want the product: rules vary. Many programmes exclude household purchases. Check the brief or ask.
  • Sharing your code in a WhatsApp group you belong to: fine if members opted in and group rules allow promotion; disclose the commercial relationship.

When in doubt, ask the platform's support before acting, and keep a record of the answer.

Red flags from others

Be wary of anyone offering:

  • "Guaranteed orders" to boost your numbers.
  • Services to buy followers or engagement.
  • Schemes to "share codes" among creators to inflate sales.
  • Requests to pay upfront to join a "premium" affiliate programme.

These can involve you in fraud or be scams targeting creators.

What happens when fraud is detected

Consequences typically include reversed commissions, withheld payouts, removal from campaigns and platforms, reputational damage with brands, and in serious cases, legal liability. Detection methods include purchase-pattern analysis, device and address matching and return-rate monitoring — which is why "small" self-dealing is rarely invisible.

Worked scenario

Kiran is close to a bonus tier. A friend offers to buy five items with Kiran's code if Kiran reimburses her, then return them after the validation period. Kiran declines: this would be incentivised fake orders, likely to be detected, and would put her account and reputation at risk. Instead, she posts a genuine comparison video, which brings in several real orders — not enough for the bonus this time, but her record stays clean and the brand renews her for the next campaign.

Building a personal integrity policy

Write down your rules, for example:

  1. I only promote products I've tested or am honest about not having tested.
  2. I never buy with my own code unless the brief allows it.
  3. I never pay or reimburse anyone to buy.
  4. I only report orders with evidence.
  5. I disclose every commercial relationship.
  6. I ask before acting in grey areas.

How brands detect fraud (and why "small" cheating is rarely invisible)

Understanding the brand side helps you stay clear of false alarms too.

| Control | What it catches | What it means for you | |---|---|---| | Validation period set longer than the returns window | Buy-then-return schemes | Commission confirms only after returns close | | Address, device, payment and IP matching | Self-purchase, household orders, friends reimbursed | Do not use your code for your own orders unless allowed | | Velocity rules (many orders in minutes from one source) | Bots, coordinated fake orders | Sudden spikes may be reviewed; keep evidence of the post that caused a genuine spike | | Code-leak monitoring on coupon sites and extensions | Leaked vanity codes | Never post your code on coupon sites; report leaks you find | | New-customer-only or single-use codes | Code sharing, repeat abuse | Understand which orders count before promising | | Brand-term search monitoring | Brand bidding | Do not run ads on the brand's name unless explicitly allowed | | Return-rate and chargeback monitoring per creator | Misleading promotion | High reversals invite review |

Browser extensions and "last-click hijacking". In 2025 Google tightened the Chrome Web Store's affiliate ads policy after public complaints that some coupon extensions replaced creators' affiliate tracking at checkout. Since enforcement began in June 2025, extensions must disclose affiliate programmes, require user action before applying an affiliate link, code or cookie, and only do so when the user gets a direct benefit. If your sales vanish at checkout, tell the brand; they can compare order paths.

Hands-on: spot suspicious patterns in your own code data

If a brand shares order-level data for your code (without personal details), a quick check shows whether your code has leaked or is being abused.

import csv
from collections import Counter
from datetime import datetime

# Expected columns (no personal data needed): order_id,created_at (ISO),country,new_customer (yes/no),refunded (yes/no)
with open("code_orders.csv", newline="", encoding="utf-8") as f:
    orders = list(csv.DictReader(f))

by_hour = Counter(datetime.fromisoformat(o["created_at"]).strftime("%Y-%m-%d %H:00") for o in orders)
countries = Counter(o["country"] for o in orders)
refund_rate = sum(o["refunded"] == "yes" for o in orders) / max(len(orders), 1)

print("Busiest hours:", by_hour.most_common(3))
print("Countries:", countries.most_common(5))
print(f"Refund rate: {refund_rate:.0%}")
# Red flags: a burst of orders at an hour when you posted nothing; countries you never promote to;
# a refund rate far above your usual. Any of these can mean a leaked code - tell the brand.

Reporting fraud you see

If you find your code on a coupon site, spot someone impersonating you, or are offered "guaranteed orders", screenshot it and report it to the platform or brand. Brands trust creators who flag problems early.

Do and don't

Do read prohibited behaviours in every brief. Do ask when unsure. Do report suspected fraud or scams to the platform.

Don't self-purchase without permission. Don't buy engagement. Don't accept "guaranteed order" offers.

Video lecture: Avoiding fraud, self-dealing and policy violations

Lecture coming soon · 14 chapters · about 8 minutes. Read the full transcript below.

  1. Avoiding fraud and self-dealing
  2. Why integrity matters
  3. The shop-assistant analogy
  4. Common forms
  5. How brands detect
  6. Last-click hijacking
  7. Grey areas: ask first
  8. Example 1: Kiran
  9. Example 2 (illustrative): leaked code
  10. Watch me do it: leak check
  11. Red flags from others
  12. Why brands use code controls
  13. Your integrity policy
  14. Recap + try this now

Lecture transcript

Avoiding fraud and self-dealing

You're three orders short of a bonus tier. A friend messages: I'll buy five with your code, you pay me back, and I'll return them after the returns window. Easy money, right? It isn't. In this lecture you'll learn the common forms of affiliate fraud and self-dealing, how brands detect them, the grey areas where you should ask first, how to spot when your own code has leaked, and how to write a personal integrity policy that protects your income for years.

Why integrity matters

Why does this matter? Affiliate and code programmes only work if brands can trust the data. Fraud, deliberate or careless, harms brands, honest creators and customers. Consequences range from reversed commissions and withheld payouts to removal from platforms and, in serious cases, legal action. And integrity compounds. Brands talk to each other and to agencies. The creators with clean records get the best campaigns.

The shop-assistant analogy

Here's the analogy. Self-dealing is like a shop assistant who earns commission on sales and then buys everything with their own staff card. The till says sales are great. The owner is paying commission on money that was never really made. It feels small from the inside. From the owner's side, it's theft. That's how brands see self-purchases, reimbursed orders and fake reports.

Common forms

The common forms. Self-purchasing: buying with your own code to earn commission, unless the programme explicitly allows it. Incentivised orders: paying or reimbursing friends or family to buy. Fake or duplicate reporting. Code leaking: posting your code on coupon sites or forums where it's banned, capturing sales you didn't influence. Cookie stuffing and click fraud: forcing tracking without a genuine click, or using bots. Brand bidding and impersonation. Buying fake followers or engagement. And misleading claims: invented results, testimonials or scarcity.

How brands detect

How do brands catch it? More ways than most people think. They set the validation period longer than the returns window, so buy-then-return schemes never confirm. They match addresses, devices, payment details and networks, which catches self-purchases and reimbursed friends. They watch for bursts of orders in minutes, which catches bots. They monitor coupon sites and browser extensions for leaked codes. And they track each creator's return and chargeback rates. Small cheating is rarely invisible.

Last-click hijacking

There's a newer threat, and this one works against you. Some browser coupon extensions have been accused of replacing a creator's affiliate tracking at the last moment of checkout, taking credit for sales the creator drove. In twenty twenty-five, Google tightened the Chrome Web Store's rules: since enforcement began that June, extensions must disclose affiliate programmes, require user action before applying an affiliate link, code or cookie, and only do so when the user gets a direct benefit. If your sales seem to vanish at checkout, tell the brand. They can check order paths.

Grey areas: ask first

Now the grey areas, where the answer is: ask first. Buying something for yourself because you genuinely want it is fine, but don't use your own code unless the brief allows it. Family members who genuinely want the product: many programmes exclude household purchases, so check or ask. Sharing your code in a WhatsApp group you belong to: fine if members opted in and the group allows promotion, and you disclose. In every grey area, ask the platform's support before acting, and keep a record of the answer.

Example 1: Kiran

First example. Kiran is close to a bonus tier. A friend offers to buy five items with Kiran's code, if Kiran reimburses her, and return them after validation. Kiran declines. It would be incentivised fake orders, very likely detected by address and payment matching, and it would put her account and reputation at risk. Instead, she posts an honest comparison video. It brings in several real orders. Not enough for the bonus this time. But her record stays clean, and the brand renews her for the next campaign.

Example 2 (illustrative): leaked code

Second example, a realistic business scenario with illustrative details. A Lahore creator's code suddenly shows sixty orders overnight, when he posted nothing. Great news? He's suspicious, and asks the brand for anonymised order data. The quick check from the lesson shows most orders arrived between two and four in the morning, from customers the brand already had, many using a coupon extension. His code had leaked to a coupon site. He reports it the same day. The brand reverses those orders, issues him a new single-use code system for email, and thanks him. Illustratively, his next contract came with a higher rate, because he'd proved he protects the programme.

Watch me do it: leak check

Watch me do it. The brand has shared an anonymised export of orders on my code: order ID, time, country, new customer or not, and refunded or not. No names. I run the short Python script from the lesson. It prints the busiest hours, the top countries and the refund rate. Busiest hour: seven p m on Tuesday, which is exactly when my tutorial went live. Good. Countries: Pakistan and the UAE, where I promote. Good. Refund rate: eight percent, close to my usual. No red flags. If there had been a burst at an hour I didn't post, or countries I never promote to, I'd have emailed the brand with the output attached.

Red flags from others

Common mistakes often start with offers from others. Guaranteed orders to boost your numbers. Services selling followers or engagement. Schemes to share codes between creators to inflate sales. Requests to pay upfront to join a premium affiliate programme. Some of these involve you in fraud. Others are simply scams aimed at creators. Either way, screenshot them and report them to the platform.

Why brands use code controls

It helps to understand why brands choose certain code types. Single-use codes, one per buyer, make leaking pointless, because each code works once. New-customer-only codes stop existing customers who were going to buy anyway from triggering your commission. Minimum order values and excluding gift cards stop cheap abuse. None of these are personal. They protect the programme's economics, which keeps it running for honest creators like you. So if a brand moves you to single-use codes for your email list, that's often a sign they trust you with a bigger channel, not less.

Your integrity policy

Finally, write your personal integrity policy. Six lines is enough. I only promote products I've tested, or I'm honest that I haven't. I never buy with my own code unless the brief allows it. I never pay or reimburse anyone to buy. I only report orders with evidence. I disclose every commercial relationship. And I ask before acting in grey areas. Keep it where you'll see it when you accept campaigns. It makes the tempting moments easy.

Recap + try this now

Recap. Self-purchasing, reimbursed orders, fake reports, leaked codes, cookie stuffing and fake engagement are fraud or violations, and brands detect them with validation periods, matching, velocity rules and monitoring. Watch for extensions hijacking your credit, and check your own code data for leaks. In grey areas, ask first and keep the answer. Try this now: write your six-line integrity policy, and ask one brand for an anonymised export of your code's orders to run the leak check. Next, payouts, commission statements and tax.

Key takeaways

  • Self-purchasing, paid orders, fake reports, code leaking and fake engagement are fraud or violations.
  • Detection is sophisticated; consequences include reversals, bans and legal liability.
  • In grey areas, ask the platform first and keep a record.
  • A written personal integrity policy protects your income and reputation.

Try it

Write your own five- or six-point personal integrity policy and keep it somewhere you'll see it when accepting campaigns.