Members & privacy

Identity, guest earnings, duplicate merging, account states, and the privacy controls members hold themselves.

Identity: the email + mobile pair

One member per email and one per mobile number, per program. Email anchors the account; a mobile added later upgrades the same account in place. Search members by email, mobile, member ID or referral code.

Guests earn before they join

A checkout email is enough: guests accumulate pending earnings that become theirs the moment they sign up with that email — through the portal or the API. Nothing is lost between first purchase and signup; buying activity even counts toward tier standing.

Duplicates & merging

The duplicate scanner (Members page) flags accounts whose emails collapse to the same alias (dots and +tags) or that share phone digits. Merging transfers the duplicate's balance to the cent as an audited adjustment pair, re-points its order history so tier standing unifies, and retires the duplicate with a pointer to the survivor. "Not a duplicate" is remembered — the pair is never flagged again.

Exampleriya@gmail.com and r.iya+promo@gmail.com → flagged; the older account keeps the history, one click merges.

Account states

Prospect (guest, unclaimed) → registered/active → possibly suspended or deleted. Suspended and deleted members cannot earn, redeem or sign in — on any surface, portal or API. Their orders still record as plain revenue.

Privacy in the member's hands

The portal's Privacy page holds the marketing-consent toggle (off unless they opt in; transactional email like sign-in links always works — branded, from your verified sender; see Getting started), their optional birthday, and "Download my data" — a self-service JSON export of their profile, ledger, orders and redemptions. Every change and every export is audited.

Good to knowEvery ledger line a member sees explains itself in plain language — earned, pending, expired, clawed back and why. Trust is a feature.

Next: Referrals & fraud