All articles Fraud & ATO

Delivery-App Coupon Farming in Latin America

New-user discounts drive growth for delivery apps: a large discount on the first order, free delivery for the first month, a referral credit for both sides. In Latin American markets, where several apps compete hard for the same neighborhoods, these offers are generous and change often. That makes them worth farming.

The farming pattern is well established. One person, or a small crew, creates new accounts repeatedly, takes the welcome discount on each, and often orders to the same few addresses. Some resell the discounted orders. The losses are spread across thousands of small orders, which is why the problem tends to get noticed late.

How the farm works

The account is the thing being multiplied, so every check that keys on an account attribute gets rotated:

  • Phone numbers. Prepaid SIMs are inexpensive, and virtual numbers that receive SMS OTPs are sold online. “One promo per phone number” is the control farmers expect and plan around.
  • Emails. Free and unlimited, as always.
  • Payment. Where cash on delivery or prepaid cards are accepted, there’s no stable card to link accounts by.
  • Addresses. Small variations (“Apto 3”, “apartamento 3”, “dpto. 3”), or a neighbor’s address and a walk.
  • The app itself. App-cloning tools let one Android phone run several isolated copies of the same app, each with its own storage and session. Emulators on a PC go further, and some farms run racks of cheap phones.

What stays constant is the hardware. A farmer can buy SIMs cheaply. Buying a new phone for every order would wipe out the discount.

Make the device the unit of the promo

The core control is simple: one welcome discount per device, enforced on the server at the moment the discount would apply.

  1. The mobile app identifies the device with the Prynt SDK (iOS, Android, Flutter and React Native are available) and sends the requestId with signup and with checkout.
  2. At signup, your server fetches the event and records the visitorId on the account. After the account exists, it attaches the account id as linkedId.
  3. At first-order checkout, before applying the discount, the server checks how many accounts that device already has.
const event = await prynt.getEvent(checkout.pryntRequestId);
const otherAccounts = event.accountsOnDevice.accounts
  .filter((a) => a.linkedId !== customer.id).length;

const welcomeEligible =
  otherAccounts === 0 &&
  event.decision !== 'block' &&
  !customer.welcomeUsed;

if (!welcomeEligible) {
  checkout.removePromo('WELCOME', { reason: 'device_already_used_offer' });
}

Note what this does not do: it doesn’t stop the order. The customer can still order at full price. A family sharing one phone or a new roommate on a borrowed device isn’t locked out. They just don’t get a second welcome discount, and that’s the whole point of the offer’s terms.

accountsOnDevice.truncated tells you when the device has more accounts than the list returned. For a promo check, any non-zero count of other accounts is already the answer. Promo abuse prevention covers other offer types, such as stacking, recurring codes and loyalty points.

Integrity signals for cloned apps and emulators

Device limits only work if one physical phone looks like one device. Farms work around that with cloned app instances and emulators, and the mobile integrity signals catch much of it. Not every cloning tool repackages the app, so treat these signals as one layer next to the device limit, not a guarantee. The server-side event for a native identification includes:

Smart SignalWhat it indicatesReason code
clonedAppRepackaged or side-loaded copy of the app: installer isn’t an app store, package name differs from the one you ship, or a debuggable buildCLONED_APP
emulatorNot a physical handsetVIRTUAL_MACHINE
rooted / jailbrokenOS integrity compromisedROOTED_OR_JAILBROKEN
fridaInstrumentation hooking into the appINSTRUMENTATION
attestationApp Attest / Play Integrity token present and verifiedFAILED_ATTESTATION when verification fails

The SDK collects these, and the server scores them, so a modified client can’t simply report false. Attestation verification against Apple and Google needs a one-time server configuration with your app’s keys. Until that’s set up, the token is recorded as present but unverified.

Use the signals with the promo rule, not instead of it:

const ss = event.smartSignals || {};
const suspiciousEnvironment =
  ss.clonedApp?.result || ss.emulator?.result || ss.frida?.result;

if (suspiciousEnvironment) {
  checkout.removePromo('WELCOME', { reason: 'untrusted_app_environment' });
  // the order itself can proceed; promos need a trusted device
}

A rooted phone on its own is weaker evidence. Some enthusiasts root their phones for unrelated reasons. Treat it as a reason for review rather than an automatic refusal. Detecting emulators on mobile goes deeper on the emulator side.

Referral credits: the second door

Once welcome discounts are guarded, farms move to referral programs: the referrer and the new account are the same person on the same device, and both sides collect a credit. The same data answers it. If the new account’s device already holds the referrer’s account, or any account at all, the referral reward shouldn’t pay out. Check at payout time, not just at signup, because farms often age accounts before cashing in. Referral fraud detection at signup has the full pattern.

Address and courier patterns

Device signals pair well with your own operational data:

  • Many devices delivering to one normalized address within a short period.
  • New accounts whose first order is the maximum the promo allows.
  • Couriers repeatedly delivering welcome orders to the same handful of addresses.

None of these is conclusive alone. Combined with a device that has opened several accounts, they make a strong case for review and a clear audit trail.

Language and local context

Keep customer-facing messages in the customer’s language and neutral in tone: “Esta promoción ya se usó en este dispositivo” or “Esta promoção já foi usada neste aparelho” works better than an accusation. Some regional privacy laws, such as Brazil’s LGPD, apply to device data. Fraud prevention is a recognized purpose, but your notice should still say that device information is used to enforce promotion terms.

Wrap-up

Move the welcome offer from “one per phone number” to “one per device”. Check it on the server at checkout, and treat cloned-app and emulator signals as reasons to withhold the promo, not the order. Farmers can keep rotating SIMs, but each rotation no longer comes with a new discount.

Try it free

Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.

Keep reading