Limit one per customer on Shopify, enforced at checkout. New-customer offers, lifetime limits, and rewards from one identity engine.
Shopify's native limit checks an email. OfferGuard checks five identity signals, so a new customer discount goes to actual new customers and a one-per-customer limit holds across fresh emails, new accounts, and guest checkout. Native referrals and loyalty run on the same verdict. All of it under 100ms.
New customer discounts, applied automatically
The guard recognizes first-time buyers and rolls out whatever you set up. Free shipping, welcome gift, intro discount, BOGO. Happens automatically. No code for them to enter, nothing to share.
Stop repeat buyers from reusing new-customer offers
Different email? Same person. Guest checkout? Still caught. Changed their address? Doesn't matter. The guard sees through it and blocks the offer, warns them, or charges full price.
Product-level offer rules: free shipping, percent off, intro pricing
Discount by product at checkout. Free shipping for subscribers. Special price for tagged customers. BOGO on first subscription. You write the rules, the guard enforces them at checkout. Automatically.
One customer profile across emails, devices, and guest checkouts
The guard links orders together even when the buyer uses different emails, checks out as a guest, or creates a new account each time. You see one customer, not five fake ones.
Vet new customers before the offer applies
A “new customer” rule is an identity verification step at checkout. The buyer is never asked for anything extra, and it finishes before the checkout can progress.
1. Every enabled signal is checked against your order history
Email is always checked. Phone, shipping address, billing address, IP, device, and visitor cookie are switched on per rule, so a gift-friendly welcome offer can vet by email alone while a sample SKU vets by everything.
2. One match to a completed order means returning
Each matching signal is recorded as its own reason, “not new by phone”, “not new by device”, so you can see exactly why a buyer failed and tune the rule. No scores to interpret.
3. Verified new gets the reward, returning gets the rule's verdict
A signed reward token is minted for a verified new buyer and applied by the discount function. A returning buyer gets whatever you chose: block, warn, or the order at full price with the reward withheld.
Returning-only rules work the same way in reverse: require a prior purchase before a loyalty price applies.
Limit one per customer by email, phone, address, household, IP, or device
“Per customer” means whatever you define it to mean. Each cap is a separate setting on the rule. Set one, or stack several so a buyer has to change every detail at once to get a second order through.
Per email address
Normalized first: Gmail dots and plus aliases stripped, googlemail folded into gmail, relay addresses from Apple, DuckDuckGo, and Firefox flagged. [email protected] and [email protected] count as one.
Per phone number
Matched on the last ten digits, so +1, 001, spaces, and dashes make no difference. The phone at guest checkout is the same signal as the phone on a logged-in account.
Per shipping address (one per household)
Compared at building level after expanding street abbreviations, removing unit designators, and collapsing ZIP+4. Apt 4B and #4B are the same door. Optional Google Address Validation canonicalizes the rest.
Per billing address
Checked separately from the shipping address and cross-matched against both on past orders. A fresh ship-to with the cardholder's usual billing address is still caught.
Per IP address
The connecting IP is recorded on every checkout. Useful as a second signal, weak on its own because of shared networks and mobile carriers.
Per device
A passive fingerprint from screen, timezone, hardware, and browser client hints, collected by the web pixel from the first page view. Incognito mode does not change it.
Per visitor cookie
A first-party cookie that lives 365 days and is carried into the order. Cleared cookies fall back to the device signal, so the two are kept separate.
Per customer account
For logged-in buyers the Shopify customer ID is one more cap, so a returning account cannot claim a first-order offer even with a new email on file.
Per order
Cap the quantity of a gated product per order inside the cart validation function. This is the only limit Shopify enforces natively, and here it runs alongside the lifetime caps.
Per country
Rewards carry an optional list of up to 50 countries. Free shipping for new customers in the US and Canada only, full price everywhere else, without a separate rule per market.
Address matching in depth: one per household on Shopify. Why the native setting fails: limit one per customer explained.
Block, warn, or strip the reward and keep the sale: actions set per rule
Five verdicts at checkout, five actions after the order. Each rule picks its own, so a sample SKU can block while a welcome discount simply drops to full price.
At checkout
Block
Stop the checkout for the protected product. The buyer can still buy everything else in the store.
Warn
Show a message, let the order continue, keep the flag in the decision log.
Withhold incentive
The order goes through at full price. Only the reward is dropped. The default for welcome offers, where losing the sale costs more than the discount.
Invalidate code
Remove a gated discount code the moment it is entered. Referral and new-customer codes only work for the people they were meant for.
Allow and reward
Verified new. Free shipping, a percentage off, a fixed amount, or a product discount applies automatically, no code needed.
After the order
Tag
Order and customer tags you choose, ready for admin filters and your own Shopify Flow automations.
Risk assessment
A high, medium, or low risk assessment written to the order, visible in Shopify admin.
Hold fulfillment
Pause the fulfillment order until someone reviews it. Nothing ships by accident.
Cancel
Cancel automatically, refund or void, restock, with a staff note that says which rule fired.
Silent mode
Turn the customer-facing banner off and run every side effect quietly. The buyer sees nothing, you see everything.
No discount codes to leak, share, or abuse
Discount codes are unreliable. They conflict with each other, they only allow one per checkout, customers forget to enter them, they can't handle conditional logic like “only if this is your first order” or “only if you're subscribed.” And on top of that, they leak. OfferGuard replaces the whole system. The guard decides at checkout who gets the offer based on who they are. Fully automatic.
Discount codes
- Only one code per checkout
- Conflicts with other discounts
- Customers forget to enter them
- Can't check if someone is new
- Leak on social media
- Manual setup per campaign
Honor system
- “New customers only” in the description
- No enforcement at all
- Anyone can buy it
- You find out too late
OfferGuard
- No codes, nothing to enter
- Stacks with any other discount
- Applied automatically at checkout
- Knows who's new and who isn't
- Nothing to leak or share
- Set it once, runs forever
How buyers get around “limit one per customer,” and how each attempt is caught
People try all kinds of tricks to grab new-customer offers again. The guard has seen them all.
They use a different email
Same phone, same device, same address. The guard doesn't care what email they used.
They check out as a guest with no account
The guard has been watching since their first page view. No account needed to recognize them.
They use a Gmail dot trick or plus alias
[email protected] and [email protected]? Same inbox. The guard knows.
They change their shipping address
Same device, same phone. A new address doesn't make them a new person.
They use a disposable email
The guard blocks known throwaway email domains and relay addresses (Apple Hide My Email, DuckDuckGo, Firefox Relay) on sight.
They use private browsing
The guard was tracking their device from the first page view. Incognito doesn't erase that.
They try everything at once — new email, new phone, VPN, different browser
Multiple signals still overlap. The guard connects the dots and flags it.
Post-purchase risk analysis: tag, hold, alert
The guard doesn't clock out after checkout. It scores every order for risk and takes whatever action you set up.
Auto-tag orders
Tag suspicious orders so you can filter them in Shopify admin or trigger Shopify Flow automations.
Risk scoring
Every order gets a risk score based on the buyer's profile. See it right on the order page.
Hold fulfillment
Pause shipping on flagged orders until your team reviews them. No risky packages going out.
Alert your team
Get notified when something looks off. Order notes explain exactly what the guard saw and why.
Why Shopify's native limits and other apps go blind in guest checkout
Other apps don't know who the customer is. They rely on discount codes and logged-in accounts. If someone checks out as a guest, those apps are blind. And the average customer already knows how to get around traditional protection. New email, new address, VPN, incognito mode — this isn't hacker stuff anymore, it's common knowledge. OfferGuard was built for that reality.
Other apps
- Don't know who the customer is
- Only work if the customer is logged in
- Rely on discount codes to deliver offers
- Blind at guest checkout
- Can't tell new customers from returning ones
- No way to enforce “first order only”
OfferGuard
- Knows who the buyer is, every time
- Works at guest checkout, no account needed
- No discount codes, fully automatic
- Identifies returning buyers even with new emails
- Runs server-side inside Shopify's checkout
- Under 100ms, nobody notices
Questions merchants ask about limiting offers per customer
What are the five identity signals?
Email (with Gmail-alias and disposable-domain detection), phone (E.164 plus last-10-digit matching for guest checkouts), shipping address (zip-tokenized, billing cross-matched), client IP, and a passive device fingerprint built without third-party cookies.
Does this work in guest checkout?
Yes. Every signal except the customer-account email is collected during guest checkout. The device fingerprint and cookie are set on first page view, so a buyer who later checks out as guest still maps to their prior profile.
How does the reward side differ from Smile or Bubblehouse?
Smile, Bubblehouse, LoyaltyLion issue points and credits trusting the identity at checkout. OfferGuard runs both the fraud verdict and the reward decision in the same call, so points only mint to verified buyers.
What about the Apple Wallet pass?
Enterprise plans ship a native .pkpass with the buyer points balance, share-and-earn code, and live order status on the lock screen. Push updates go through APNs — no SMS bill.
Can OfferGuard enforce "limit one per customer" for life, not just per checkout?
Yes. Shopify's native setting and most quantity-limit apps enforce per cart or per discount code, so the buyer checks out and comes straight back. OfferGuard checks the buyer's full order history at checkout, so a one-per-customer or one-per-household limit holds across repeat orders, new emails, and guest checkout.
How fast is the verdict at checkout?
Sub-100ms p50 for the standard 5-signal evaluation. The decision runs server-side via a checkout extension and a Rust cart-submit Discount Function — it cannot be bypassed client-side.
How do I limit one item per customer on Shopify?
Shopify has no native lifetime limit per customer. The discount setting "limit to one use per customer" checks the email or customer account, and the cart quantity limit caps a single order, so the same buyer can order again minutes later. In OfferGuard you pick the product, set max purchases per email, phone, address, or device to 1, and the cart validation function enforces it at checkout for guests and logged-in buyers alike.
Can you limit the number of items a customer can buy on Shopify?
Per order, yes: Shopify's add-to-cart limit or OfferGuard's per-order quantity cap on gated products. Across orders, only an identity-based rule works. OfferGuard counts previous orders matched by email, phone, shipping and billing address, IP, device, and visitor cookie, and blocks when the cap is reached.
How do I limit a discount to one per household?
Cap purchases per shipping address. Addresses are compared at building level after expanding street abbreviations, dropping unit designators, and collapsing ZIP+4, so "123 Main Street Apt 4B" and "123 Main St #4B" count as one household. The One per customer template pairs the address cap with an email cap.
Can I limit a discount by country or location?
Rewards can carry a country allow-list, so free shipping or a percentage off only applies to buyers shipping to the countries you choose. Block and warn rules are identity-based rather than location-based; use Shopify Markets or the Shipping Rules feature for location-specific pricing and rates.
What does "limit 1 per customer" mean on a Shopify store?
The merchant intends each person to buy the product or claim the offer once. Whether that holds depends on how "person" is defined. Defined by email, it fails as soon as the buyer uses a second address. Defined by phone, address, device, and cookie together, it holds across new emails, new accounts, and guest checkout.
What happens when a repeat buyer reaches checkout with a new-customer offer?
Whatever the rule says. Most merchants pick "withhold incentive": the order completes at full price, the reward is dropped, and a short banner explains that the offer is for first orders. Stricter rules block the checkout for that product, or warn and let it through. Either way the decision is logged with the signals that fired.
How does OfferGuard verify that a customer is new?
By comparing the checkout against completed orders on every signal the rule enables: normalized email, phone, shipping and billing address, IP, device fingerprint, and visitor cookie. A single match to a previous order marks the buyer as returning. It is identity verification without asking the customer for anything, and it works in guest checkout.