Referral program rules

Share the movement without hiding the rules.

These rules explain who can refer, how links and attribution work, when discounts apply, how recurring shares are recorded, and how reversals, fraud review, and payouts work.

Server-issued links

An eligible member receives an opaque referral code bound to their account. Typed names, emails, or client-created codes do not establish attribution.

Exact offer capture

The link identifies the code, offer key, offer version, and membership term. A signed first-party cookie keeps that exact relationship for a limited time.

Ledger before payout

Eligible sales and renewals create append-only allocation events. Refunds and lost disputes create linked reversals. Payout requires a separate approved system.

1. Purpose

Reward honest membership sharing

The referral program is intended to reward eligible members who introduce a new person to an eligible paid membership. It is not compensation for a health result, medical claim, protocol, provider referral, investment, recruitment chain, or sale of personal health data.

A share percentage shown on a page does not create an earning right. The exact approved referral contract, active program entry, eligible order, confirmed payment, and allocation ledger must all agree.

2. Who can participate

Eligibility comes from current account state

  • The source member must have current active or approved grace membership access.
  • The program, default membership term, offer, economic contract, and referral code must all be active.
  • The referred person must be a new eligible member under the approved rule.
  • Self-referral is not allowed. A person cannot refer their own account or another account they control.
  • Existing-member, household, employee, contractor, provider, coach, related-party, and geographic eligibility remain owner and counsel decisions.
  • A code can be revoked. Revocation stops new captures after the approved effective point, but treatment of a valid earlier capture must follow the final rule.
3. Link and capture

Keep attribution first-party and exact

  1. The signed-in eligible member asks the server to issue or return their current opaque referral code with an idempotency key.
  2. The canonical path includes the code, offer key, offer version, and membership term. All account views must return the same path.
  3. A visitor opens that path on the canonical secure host.
  4. The server verifies the current code, source membership, program, offer, and term, then sets a signed, secure, HTTP-only, SameSite Lax first-party cookie with a defined expiration.
  5. The visitor signs in or creates an account and explicitly claims the referral before an eligible purchase.
  6. The service refuses self-referral, changed relationships, expired capture, wrong offer, wrong term, or conflicting prior claim.

The program version shown in your account explains attribution order, code-entry overrides, multi-device and cross-domain handling, and Support corrections.

4. Discount and recurring share

Separate the buyer benefit from the member share

Economic partWhat controls itWhat you see
Buyer discountApproved contract, active benefit, exact provider coupon or discount binding, amount or percentage, duration, currency behavior, and non-stack rule.The buyer benefit appears only when the exact active offer and discount agree.
Initial member shareConfirmed eligible payment, approved share basis, source member identity, contract rate, order line, allocation event, refund rule, and fraud state.Confirmed allocations appear separately from payable or paid amounts.
Recurring member shareConfirmed renewal invoice, active source and referred relationships under the approved rule, current contract, exact period, allocation event, and later reversal support.Eligible renewals use the share rate shown in the active program terms, including the 5% recurring design where offered.
PayoutApproved payout provider, identity and eligibility checks, tax workflow, minimum and schedule, reserve, negative balance, currency, fees, statements, failed-payout recovery, and support.Payable and paid amounts remain separate, with payout status visible.
5. Allocation basis

Define what the percentage is applied to

The final contract must state whether the share is calculated from item price before or after discounts, credits, taxes, refunds, payment fees, and currency conversion. The same basis must be used for the initial order, renewals, partial refunds, full refunds, and lost disputes.

Each allocation records the order or invoice, period, beneficiary, source relationship, contract, basis amount, rate, amount, currency, and provider event. A reversal points to the original allocation and records the new negative delta. Replays cannot double pay or double reverse.

6. What the member sees

Do not call unpayable ledger value cash

The account should show the active or revoked code, canonical link, program version, captures or conversions allowed by the approved privacy rule, gross eligible allocations, reversals, net ledger amount, paid amount, payout state, holds, and support path.

Your account separates pending, held, payable, paid, and reversed amounts. A value is never called cash or income before it becomes payable.

7. Sharing conduct

Share honestly

  • Say that the link is a referral link and that the sharer may receive a benefit if an eligible purchase is completed.
  • Use only current approved descriptions, prices, capabilities, and evidence claims.
  • Do not promise diagnosis, cure, guaranteed outcome, personal medical care, or provider endorsement.
  • Do not use spam, purchased lists, deceptive ads, impersonation, hidden redirects, fake reviews, cookie stuffing, self-referral, account farming, or coercion.
  • Do not collect or expose another person's health, payment, or account information to make a referral.
  • Do not present referral sharing as employment, investment income, or a guaranteed business opportunity.
8. Holds, reversals, and review

Preserve evidence before changing money

Eligible allocations can remain in a pending or held state during an approved refund window, dispute period, identity review, or fraud review. A confirmed refund or lost dispute reverses the matching amount. A won dispute can restore the eligible state only through a new event linked to the original chain.

Your account shows hold reasons, review timing, appeal options, reserves, negative balances, offsets, program status, and how later renewals are handled.

9. Privacy

Show enough to explain, not enough to expose

The source member does not need the referred person's private health information, payment details, private email, or account activity. The account should use aggregate counts and opaque transaction references unless a more detailed disclosure is approved and necessary. Referral cookies and claim records follow the approved privacy notice and retention schedule.

10. What the referral system records

The program is live only when the whole chain is real

The referral record follows code issue and reuse, the canonical link, capture and expiration, new-member claims, self-referral and conflict checks, buyer discounts, initial and renewal shares, reversals, disputes, fraud holds, account reporting, payouts, recovery, privacy limits, and reconciliation.