Protection
Rules and settings
Velocity, one-order-per-IP, COD-only mode, and cancel vs flag actions.
Open Apps → AppsTint → Store Protection to configure rules.
Master switch
| Setting | Purpose |
|---|---|
| Enable protection | Master on/off for screening (app must also be activated on Apps grid) |
| COD only | Only screen orders paid with Cash on Delivery — prepaid cards are skipped |
COD only is on by default. Turn it off if you want velocity and blocklist rules to apply to all payment methods.
Velocity rule
Catches bots placing many orders in a short time.
| Setting | Typical starting value |
|---|---|
| Max orders | 3 |
| Window | 30 minutes |
| Action | Flag (then Cancel when tuned) |
| Auto-blocklist | On — adds IP/email/phone to blocklist after a velocity trip |
Counts orders that share the same IP, email, or phone within the window.
One order per IP
Blocks a second order from the same IP within a time window.
| Setting | Typical value |
|---|---|
| Window | 24 hours |
| Action | Flag or Cancel |
Useful for COD stores seeing duplicate fake orders from one connection.
Blocklist action
When an order matches a blocklist entry (IP, email, phone, or address keyword):
| Action | Result |
|---|---|
| Flag | Tag order for manual review |
| Cancel | Auto-cancel on Shopify |
Notifications
Notify customer on cancel — send Shopify's standard cancellation email when an order is auto-cancelled. Off by default; enable when you are confident in your rules.
Cancel vs flag
| Action | Best for |
|---|---|
| Flag | Tuning phase — review in Shopify before fulfilling |
| Cancel | Confirmed fraud — unpaid COD you will never fulfil |
Paid orders you might fulfil should use Flag unless you are certain.
Dashboard
The overview shows last 30 days: orders screened, caught, cancelled, and current blocklist size.