PROGRAMMABLE LOYALTY

A point ledger designed for real ecosystems.

From transaction validation and configurable rules to cross-merchant redemption, affiliate settlement, exception handling and analytics.

PalmPay Loyalty Engine business and technical architecture
WALLET LEDGER

Monetary value

Merchant-specific prepaid balance, top-up, hold, debit, credit, refund and reconciliation.

POINT LEDGER

Program value

Pending, available, reserved, redeemed, expired, revoked, reversed and locked points.

01

Loyalty foundations

Points are a governed program value, not wallet money.

Merchant-specific point accounts

A customer can hold independent point balances for each merchant chain or program.

Separate value domains

Monetary wallet ledger and point ledger never share a balance or state machine.

Program ownership

Issuer, eligible merchants, rights, expiry, limits and settlement are explicit.

Auditability

Every earn, reserve, redeem, release, reverse, expire, revoke and adjustment is traceable.

02

Earn rules and lifecycle

Validated transactions become controlled point entries.

Eligibility

Payment success, no refund, correct merchant/product/program, minimum amount, campaign period and fraud status.

Formula

Eligible amount × earn rate plus tier/campaign bonus, subject to cap and rounding.

Lifecycle

Pending → Available → Reserved → Redeemed, with Expired, Revoked, Reversed and Locked branches.

Maker-checker

Rates, budgets, cross-merchant exchange, mass adjustment and recovery require approval.

03

Redemption models

Three models share one central control plane.

Internal

Use points within the issuing merchant or chain, with minimum points and maximum invoice coverage.

Cross-merchant

Use source-chain points at an approved destination merchant through an exchange ratio and settlement agreement.

Affiliate

Exchange points for an approved external benefit while PalmPay retains the point ledger and audit.

No double spending

Reserve first, confirm benefit, redeem on success or release on failure.

04

Exceptions and reconciliation

Financially meaningful loyalty needs failure-safe operations.

Refund after earn

Reverse related points; handle already-redeemed points through policy, negative balance or manual review.

Failed redemption

Release Reserved points back to Available when payment, voucher or partner confirmation fails.

Merchant suspension and risk

Block earn/redeem, freeze affected points and route suspicious transactions to review.

Settlement-ready reports

Opening liability, issued, redeemed, expired, reversed, closing liability, payable and receivable.

05

Portals, APIs and analytics

Business users and developers see the same governed model.

Portal modules

Dashboard, campaign, earn/redeem rules, tiers, affiliate, ledger, exceptions, reconciliation, approvals and reports.

API domains

Programs, campaigns, rules, point accounts, transactions, redemptions, exchange rates and reconciliation.

Business events

payment.completed, loyalty.points.pending, credited, reserved, redeemed, released, expired and reconciliation.completed.

KPIs

Earn rate, redemption, breakage, liability, repeat purchase, campaign conversion, fraud/reversal and cross-merchant usage.

RULE GOVERNANCE & OPERATIONS

What an enterprise loyalty program must decide before launch

Rule evaluation order

PalmPay evaluates merchant eligibility, excluded categories, product conditions, campaign priority, member tier, daily and monthly caps, duplicate detection, fraud status and rounding in a deterministic order. Every rule decision should record the rule version and effective time so finance, customer care and audit can reproduce the outcome.

Point liability and settlement

The issuing merchant defines the economic obligation behind points. Cross-merchant and affiliate use requires a clear conversion rate, funding owner, settlement period, fees, breakage policy, tax treatment, dispute process and responsibility when the destination merchant cannot fulfil the benefit.

Customer transparency

The PalmPay Client should show available, pending, reserved and expiring points by merchant, the rule that created each entry, redemption value, restrictions and a complete history. Changes to material terms require controlled notice and, where applicable, renewed acceptance.

Operational controls

Bulk adjustments, reopening expired points, changing exchange rates, suspending a merchant and closing a reconciliation period should use maker-checker approval, reason codes and immutable evidence. Fraud teams need controls for velocity, circular transactions, repeated refunds, device anomalies and coordinated account behavior.

How are points handled after a refund?

The related earn transaction is reversed. If the customer already spent those points, the program applies its approved negative-balance, recovery or manual-review policy without rewriting prior ledger history.

Can one chain use another chain's points?

Yes, only when both merchants have an approved cross-merchant agreement, active conversion table, budget and reconciliation arrangement. The point ledger remains centrally controlled.

Are points the same as wallet money?

No. Points are program value governed by loyalty terms. Monetary wallet balance is a separate ledger linked to the merchant-specific prepaid model.

Which teams use the Loyalty Engine?

Marketing configures campaigns, finance monitors liability and settlement, operations resolves exceptions, customer care investigates history, risk reviews suspicious activity and administrators approve high-impact changes.

MOBILE-ID / TRUSTED PALMPAY

Design a loyalty program

Mobile-ID will map commercial objectives to point liability, rules, portals, APIs, events, reconciliation and acceptance evidence.

Design a loyalty program