Paper coupons get photocopied. Invoice-based trade schemes drown in paperwork and disputes. Brands that want to reward the people who buy, recommend or install their products need something that can be counted, once, per product. A serialized code on each pack can do that, and it brings its own fraud risks that have to be designed for from the start.
Why unit identity makes loyalty work
A product's GTIN says what the product is; every pack of the same item shares it. A reward programme needs to know which pack was claimed, so that the same pack cannot be claimed twice. That needs a unique serial number per unit, which is what serialization provides.
With a serialized QR code on or inside each pack, a scan becomes a claim: "this unit, claimed by this person, at this time and place". The brand's server checks the claim against its records and either credits a reward or explains why not. Because the code carries product identity rather than a campaign URL, the same code can also lead to product information, warranty or authenticity checks. We describe that broader idea in how one product identity can lead to product info, warranty, loyalty and traceability.
In GS1 terms, a resolver can offer a loyalty destination as one of several links for a product. The GS1 Web Vocabulary includes link types such as gs1:loyaltyProgram and gs1:promotion for this purpose. Links set at product level can apply to every serial of that product, so the brand does not have to configure each unit.
Two kinds of programme
Consumer loyalty
Consumers scan after purchase to collect points, enter a draw or receive a small reward. Values per scan are usually modest, and the main benefit to the brand is a direct relationship after the sale, often for the first time. See why connected packaging can create a direct brand relationship.
Channel-partner loyalty
In many categories the person choosing the product is not the end customer. An electrician picks the cable brand; a painter recommends the paint; a counter salesperson at a hardware shop steers the choice. Trade programmes reward these channel partners for each product they buy, sell or install.
Take Volta Cables, a fictional cable maker. Each coil carries a serialized code inside the packaging. An electrician scans it after opening the coil on site and earns points that can later be redeemed. Saffron Paints, a fictional paint brand, prints a code under each bucket lid for painters, and a separate code on the outer carton that the retailer scans when stock arrives.
Trade programmes create real value for the brand: they show which partners use which products, in which areas, and they reward the people who influence sales. They also tend to attract more fraud, because rewards are often larger and partners can handle many products.
How loyalty programmes get abused
Common patterns, in roughly the order brands meet them:
- Code harvesting. Someone with access to stock, in a warehouse, a shop or a transport depot, scans codes from products that have not been sold or used.
- Code sharing. Photos of unclaimed codes are passed around messaging groups and claimed by whoever is fastest.
- Guessing. If serials are sequential, valid codes can be calculated rather than collected.
- Multiple accounts. One person registers many accounts to get around per-account limits.
- Leaked codes. Codes from a print supplier, misprints or scrapped stock are claimed as if they were sold product.
- Collusion. A retailer and an installer agree to claim on products that never changed hands.
Controls that keep a programme honest
No single control stops all of these. Programmes that work layer several:
| Control | What it addresses |
|---|---|
| Random, non-sequential serials | Guessing |
| One claim per code (and for points, once per code per user) | Repeat claims of the same pack |
| Codes placed inside the pack or under a lid | Harvesting from unsold stock |
| Codes activated only after factory confirmation | Leaked misprints and scrapped stock |
| Rate limits per account and per device | Bulk claiming from harvested or shared codes |
| Checks against the intended market of each unit | Claims far from where the product was shipped |
| Verified contact details per account | Multiple accounts |
| Review of flagged accounts before payout | Everything the automated rules miss |
The last control matters most. Automated rules should mark claims as pending, not reject people outright, and a person should review unusual accounts before money or gift cards leave the programme. Clear published rules, such as what counts as a valid claim and when points expire, make those reviews fair and defensible.
Loyalty fraud and counterfeiting also overlap. A code claimed twice may be a shared photo, or it may be a copied code on a fake product. Feeding loyalty anomalies into the same monitoring used for authentication gives brand-protection teams more signals. See how serialized QR codes support anti-counterfeit programmes.
Personal data and consent
The product code itself carries no personal information. Personal data enters when someone registers to collect rewards: a name, a phone number, payout details, perhaps a location.
Good practice is to ask only for what the programme needs, explain why, get consent before collecting it, and keep it separate from the product records the code points to. Precise location should be optional and requested with the person's permission, not collected silently. Partners should be able to see their own history and ask for their data to be deleted where the law gives them that right.
Designing for the long term
Loyalty campaigns change every season; packaging stays in the market for months or years. Keep the code on the pack tied to the product identity and let the programme rules change behind it. Then a code printed today can still lead somewhere useful after the current campaign ends.
See how serialized codes support channel loyalty programmes