JustBrowser
Use Cases11 min read

Gift-Card and Coupon Stacking at Scale: The Account-Linking Problem

JustBrowser Platform Team·

The order confirmation email came through at 2:47 PM. By 3:12 PM — twenty-five minutes later — all four orders were voided. No explanation beyond "unable to process your order at this time." The $340 in stacked first-order coupons across four accounts? Gone. Gift cards sitting in accounts that were probably already flagged.

Welcome to 2026.

I've messed this up myself. Thought I was clever. Wasn't. The fraud detection systems retailers use now are genuinely impressive — and I say that as someone who'd prefer they weren't. They connect dots between accounts you'd swear are separate.

Look, I'm not here to tell you whether you should do this. The ethics are your business. If you're going to operate in this ToS-grey space, though, you should at least understand how detection actually works.

The Pain: Your "Separate" Accounts Aren't Separate

You've probably heard the basics. Different email addresses. Different shipping addresses (maybe friends, family, or reshipping services). Different payment methods. New browser profile for each account. Maybe even different IP addresses through proxies or VPNs.

And it still doesn't work. Orders voided. Accounts banned in clusters. Gift card balances — poof.

Here's the thing: retailers moved past the obvious stuff years ago. They're linking accounts through your browser's fingerprint now.

When you visit Target.com or Walmart.com or Best Buy's checkout page, their fraud detection partners — companies like Forter, Sift, and FingerprintJS — collect 40+ parameters from your browser. Canvas rendering hashes. WebGL shaders and GPU signatures. Your system's font list. AudioContext waveforms. Screen resolution and color depth. Navigator properties. Timezone and language settings.

Combined, these create a fingerprint that's statistically unique to your machine. It doesn't matter if you're in incognito mode. It doesn't matter if you cleared your cookies. It doesn't matter if you're using a VPN. The fingerprint persists across all of it.

So when you create Account #2 on the same computer, even with a fresh email and a different credit card, the retailer's systems see the same device fingerprint. Linked. When you add Account #3, Account #4, Account #5 — all linked. The retailer now knows what you're doing, even if they wait until checkout to act on it.

The timing is intentional. They let you load up your cart, apply the promo codes, enter the gift card numbers, go through the whole checkout flow. Then void everything at once. Maximum frustration, maximum deterrent effect.

Effective, honestly. Annoying as hell, but effective.

Why The Obvious Fixes Don't Work

The first thing most people try is incognito mode. Or Firefox instead of Chrome. Or clearing all browser data between accounts.

None of this touches fingerprinting. Not even close.

Incognito mode prevents cookies and history from persisting. That's it. Your canvas fingerprint — the unique way your GPU renders a specific image that detection scripts generate invisibly — is identical in incognito. WebGL parameters don't change. Font list stays the same. You're still you, just without cookies.

Switching browsers helps slightly more, because Firefox and Chrome generate different fingerprints by default. But if you're running three accounts on Chrome and two on Firefox, you now have two fingerprint clusters instead of one. And sophisticated detection systems track browser-level patterns too — the timing of your mouse movements, your typing cadence, how you scroll. Forter has published research on this. The browser is only one layer.

VPNs and proxies address a different problem. They change your IP address, which matters for geo-based restrictions and basic IP blocking. But retailers have largely moved past IP-only linking. IPs are shared, dynamic, and easily spoofed — they know this. The fingerprint is the anchor now.

Plus, many VPN and proxy IP ranges are flagged by default. Commercial VPN exit nodes? Well-documented. Datacenter IPs from AWS, DigitalOcean, similar providers? Trip fraud scoring immediately. Even residential proxies — which rotate through real ISP IPs — can trigger flags if the retailer's systems detect geo mismatches. Your timezone says EST but your IP says California? That's a flag.

The payment-linking problem is harder to solve than most people realize, too. Using different credit cards helps, but not if they're all under your name. Payment processors share fraud signals. If one retailer flags your card, others in that processor's network might see it. And some retailers track card BINs — the first six digits that identify the issuing bank — watching for patterns where multiple "different" accounts all use cards from the same small credit union.

Virtual cards from services like VeloCards help here because each card has a distinct number, distinct BIN (from their issuing partners), and isn't tied to your personal name on file. But virtual cards solve the payment graph, not the device fingerprint. You need both.

The Approach That Actually Works

Real account separation requires three isolation layers working together. Miss any one and you're exposed. I learned this the expensive way.

Layer 1: Device fingerprint isolation. Each account needs a browser profile with a completely different fingerprint — not just different cookies, but different canvas rendering, different WebGL parameters, different font lists, different AudioContext values. These parameters need to be internally consistent (your canvas fingerprint should match your WebGL fingerprint should match your system fonts) or detection systems flag the inconsistency as tampering.

This is what antidetect browsers do at the engine level. JustBrowser uses a modified Chromium build with native C++ patches that generate genuinely different rendering outputs per profile. It's not an extension that tries to spoof values (detection systems check for extension presence). It's the browser engine itself producing different outputs.

Layer 2: Network isolation. Each account needs its own IP address, ideally residential, geo-matched to the account's supposed location. If Account #1 claims to ship to Chicago, its IP should come from Illinois. Mismatches between shipping address and IP geo are a signal.

Residential proxies are the standard. Datacenter IPs? Nearly useless — Forter, Sift, and similar services maintain datacenter IP databases and automatically elevate risk scores. Some operators use mobile proxies (4G/5G connections that cycle through carrier IP pools), which work well but cost more. Your call on the tradeoff.

Layer 3: Payment isolation. Each account needs its own payment method that can't be linked to the others. Virtual cards accomplish this. Physical prepaid cards work too but are operationally annoying — trust me, I've done the Walgreens runs. Whatever you use, the payment method for Account #1 should never touch Account #2. No sharing. Ever.

There's also a Layer 0 that people overlook: behavioral consistency. Each account should behave like a real customer. That means logging in occasionally outside of checkout. Browsing products you don't buy. Adding things to wishlists. Letting the account "age" for a few weeks before hitting promos hard. Detection systems build behavioral profiles; accounts that only ever appear during promotions and only ever apply maximum discounts look suspicious because that's not how real customers behave. Our account warmup guide covers this in more detail.

Implementation: What This Actually Looks Like

Let's say you want to run 10 retail accounts across Target, Walmart, and Best Buy for gift card and coupon stacking.

Setup phase:

  1. Create 10 JustBrowser profiles, each with distinct fingerprint parameters. Profiles are unlimited on the one plan ($9.99/mo), and the 7-day trial doesn't cap them either, so 10 is no different from 3. Assign each profile to one account.

  2. Configure each profile with its own residential proxy. Most residential proxy services let you purchase dedicated IPs or sticky sessions. Match the geo to where each account will claim to ship. Budget around $3-5/month per IP for decent residential quality.

  3. Create virtual cards for each account through VeloCards or a similar service. Each card should have a different cardholder name if possible (some services allow this), or at minimum a distinct card number.

  4. Create email addresses for each account. ProtonMail or similar for privacy, one email per account. Don't use Gmail aliases ([email protected]) — retailers know that trick and link them. For scaled email management, tools like JustEmails can help organize multiple inboxes.

Warmup phase:

  • Let each account age for 2-4 weeks before major activity
  • Log in occasionally, browse products, maybe add items to cart without checking out
  • Make one small, full-price purchase to establish payment history
  • Build a profile that looks like a normal customer, not a bot or stacker

Operating phase:

  • When a promo drops, access each account only through its dedicated profile
  • Don't rush through checkout — real customers browse, compare, hesitate
  • Space orders across hours or days if possible; 10 accounts all checking out within 5 minutes is a pattern
  • Vary shipping addresses across accounts (this is operationally harder but reduces linking)

And here's the uncomfortable truth: even with perfect isolation, accounts can still get banned. Retailers update detection constantly. A configuration that worked last month might get flagged next month. This is a cat-and-mouse game, and — I'll be honest — the mouse doesn't always win.

I've had setups I was proud of get nuked overnight. No warning. That's the game.

The isolation strategy limits blast radius. If Account #3 gets banned, Accounts #1, #2, and #4-10 survive. Without isolation, one ban cascades to everything. That's the value proposition — not immunity, but containment.

The ToS-Grey Reality

I'm not going to pretend this is unambiguously fine. It's not.

Retailer Terms of Service almost universally prohibit creating multiple accounts to exploit promotional offers. Target's terms explicitly state that promotional discounts are limited to one per household. Walmart's terms prohibit "circumventing purchase limits." Best Buy's terms give them the right to cancel orders that violate their policies without explanation.

None of this is illegal in a criminal sense. You're not committing fraud by using a first-order coupon multiple times — you're violating a contract (the ToS) that you probably didn't read. The consequences are civil, not criminal: order cancellation, account bans, loss of gift card balances, and potential blacklisting from future orders.

But. There's a spectrum here, and I think it matters.

Someone who runs 5 accounts to save a few hundred dollars a year on household purchases is annoying to retailers but not causing material harm. Someone who runs 500 accounts to systematically drain promotional budgets is causing real financial damage. My opinion? Those are different things. But retailers can't easily distinguish between these cases, so they apply detection and enforcement broadly.

Where you fall on that spectrum is your call. I'm just explaining how the detection works.

And if you're doing this at scale — actually running it as a business, reselling gift cards, arbitraging promo codes — you should probably talk to a lawyer about your specific situation. This post isn't legal advice. I make browser software.

Frequently Asked Questions

How do retailers detect multiple accounts using the same device?

Retailers use device fingerprinting services like FingerprintJS, Forter, and Sift that generate a unique identifier from 40+ browser parameters — canvas rendering, WebGL hashes, font lists, AudioContext signatures, screen dimensions, and more. When two accounts share the same fingerprint, they get flagged as linked. This happens at checkout, during promo code entry, and on gift card redemption pages.

Can VPNs and incognito mode prevent coupon-stacking detection?

No. VPNs only change your IP address, and incognito mode only clears cookies. Neither affects browser fingerprinting, which operates at a deeper level by reading hardware and rendering characteristics. Retailers specifically watch for VPN IP ranges and datacenter IPs, treating them as higher-risk signals. To avoid fingerprint linking, you need a browser that generates genuinely different fingerprint parameters per profile.

Usually yes — there's nothing illegal about buying gift cards at a discount or using coupons. But it typically violates retailer Terms of Service, which allow them to void orders, ban accounts, and claw back promotional value. The activity exists in a ToS-grey zone: not fraud in a criminal sense, but a policy violation that carries real account and financial consequences.

Outcomes range from mild to severe. Best case: one order gets voided, you lose the promo discount. Medium case: all linked accounts get banned simultaneously, losing any stored gift card balances and accumulated rewards. Worst case: retailer flags the linked accounts as fraud, potentially affecting your real personal accounts, and reports to chargeback fraud databases that other retailers can access.


Try JustBrowser

Native Chromium antidetect browser — not extension-based. Real C++ engine patches at the canvas / WebGL / audio / font / screen layer, so 40+ identity parameters are genuine, not faked. REST API for Playwright, Puppeteer, Selenium. $9.99/month or $99.99/year. 7-day free trial, card required — cancel any time in the seven days and you are not charged. Unlimited profiles.

Get started → · How it differs from Multilogin / GoLogin / AdsPower

Ready to manage multiple accounts?

Seven days free, then $9.99/month — one plan, everything included.

We'd like to use Google Analytics, a Google service, to understand how our website is used. It sets two cookies in your browser and runs only if you click Accept. You can change your choice at any time with Cookie settings. Cookie Policy

Sign-in cookies and the cookie that remembers this choice are always on; the website needs them to work.

Google Analytics, a Google service, helps us understand how our website is used. It sets two cookies, _ga and _ga_TVZHQ99TZW. It is now onoff in this browser. If your browser sends a Global Privacy Control or Do Not Track signal, it stays off. Cookie Policy