Members & privacy
Identity, guest earnings, duplicate merging, account states, and the privacy controls members hold themselves.
Identity: the email + mobile pair
One member per email and one per mobile number, per program. Email anchors the account; a mobile added later upgrades the same account in place. Search members by email, mobile, member ID or referral code.
Guests earn before they join
A checkout email is enough: guests accumulate pending earnings that become theirs the moment they sign up with that email — through the portal or the API. Nothing is lost between first purchase and signup; buying activity even counts toward tier standing.
Duplicates & merging
The duplicate scanner (Members page) flags accounts whose emails collapse to the same alias (dots and +tags) or that share phone digits. Merging transfers the duplicate's balance to the cent as an audited adjustment pair, re-points its order history so tier standing unifies, and retires the duplicate with a pointer to the survivor. "Not a duplicate" is remembered — the pair is never flagged again.
riya@gmail.com and r.iya+promo@gmail.com → flagged; the older account keeps the history, one click merges.Account states
Prospect (guest, unclaimed) → registered/active → possibly suspended or deleted. Suspended and deleted members cannot earn, redeem or sign in — on any surface, portal or API. Their orders still record as plain revenue.
Privacy in the member's hands
The portal's Privacy page holds the marketing-consent toggle (off unless they opt in; transactional email like sign-in links always works — branded, from your verified sender; see Getting started), their optional birthday, and "Download my data" — a self-service JSON export of their profile, ledger, orders and redemptions. Every change and every export is audited.
Next: Referrals & fraud →