Protection

Rules and settings

Velocity, one-order-per-IP, COD-only mode, and cancel vs flag actions.

Open Apps → AppsTint → Store Protection to configure rules.

Master switch

SettingPurpose
Enable protectionMaster on/off for screening (app must also be activated on Apps grid)
COD onlyOnly screen orders paid with Cash on Delivery — prepaid cards are skipped
COD only is on by default. Turn it off if you want velocity and blocklist rules to apply to all payment methods.

Velocity rule

Catches bots placing many orders in a short time.

SettingTypical starting value
Max orders3
Window30 minutes
ActionFlag (then Cancel when tuned)
Auto-blocklistOn — adds IP/email/phone to blocklist after a velocity trip

Counts orders that share the same IP, email, or phone within the window.

One order per IP

Blocks a second order from the same IP within a time window.

SettingTypical value
Window24 hours
ActionFlag or Cancel

Useful for COD stores seeing duplicate fake orders from one connection.

Blocklist action

When an order matches a blocklist entry (IP, email, phone, or address keyword):

ActionResult
FlagTag order for manual review
CancelAuto-cancel on Shopify

Notifications

Notify customer on cancel — send Shopify's standard cancellation email when an order is auto-cancelled. Off by default; enable when you are confident in your rules.

Cancel vs flag

ActionBest for
FlagTuning phase — review in Shopify before fulfilling
CancelConfirmed fraud — unpaid COD you will never fulfil

Paid orders you might fulfil should use Flag unless you are certain.

Dashboard

The overview shows last 30 days: orders screened, caught, cancelled, and current blocklist size.

Next step

Blocklist and protection log →