Guides/Scoping a prize promotion
What agencies should define before building an instant-win promotion
A brief says "on-pack promotion, 2 million packs, win a trip". The backend needs about forty more answers.
This is the list, grouped the way the configuration is grouped, with a line on why each one matters. Most
of it is the client's decision; getting it in writing before anything is built is the cheapest week of the
project.
Campaign
| Define |
Why it matters |
| Start and end dates, and the timezone |
Entries outside the window are refused. Winning Moments are laid out across it, so the window
shapes the whole prize release.
|
| Countries |
Determines the legal terms, the languages for messages, and whether one campaign or one per
market.
|
| Expected entries |
Sizes the code batches and feeds the simulation that shows how prizes will fall. Typically 5 to
25% of packs sold.
|
| Peak traffic |
TV spots and launch days arrive as spikes. Winning Moments stop a spike draining prizes, but your
site and backend still have to stay up.
|
| Entry channels |
Typed code on a web page, QR scan to a hosted page, in-app via your backend, or several at once.
Each is a batch format and an integration path.
|
Codes
| Define |
Why it matters |
| Number required |
Usually the number of packs plus a margin for print waste. Sets the plan: up to 250,000, up to
2,000,000, or above.
|
| Code length |
Ten characters from a 28-character alphabet is the default and is unguessable at any volume.
Shorter codes fit small packs but shrink the margin against guessing.
|
| Print format |
Alphanumeric codes, digit-only codes, or QR tokens with a scan URL. Numeric codes need more length
for the same volume. Once typed codes are generated for a production campaign, length and alphabet
lock.
|
| Number of print batches |
One batch per print run or source, so a lost or misprinted run can be revoked on its own. Batches
are unlimited; total codes are what the plan counts.
|
| Free-entry or alternative-entry source |
Where the law requires a no-purchase route, it is usually a separate small batch so its entries
can be reported apart.
|
Mechanics
| Define |
Why it matters |
| Prize tiers |
Each tier has its own quantity, release rule, fulfilment method and verification. Rank them: the
top ranks can be forced to manual approval by the security profile.
|
| Prize quantities |
One Winning Moment is generated per prize. Quantities can be raised or lowered on a live campaign,
with a reason, but never below what has already been won.
|
| Winning Moment distribution |
Even across the window, late-stage (the last 30%), or uniform random, per tier, optionally inside
a narrower window. This decides whether small prizes flow all summer and the trip waits for the
final week. See how Winning Moments work.
|
| Claim deadlines |
Per tier: a date after which the prize is no longer awarded, and a claim period after which a
winner who has not collected loses the claim.
|
| Unawarded-prize handling |
Moments nobody reached by the end are reported as unawarded. Decide now whether they are rolled
into a final draw, donated, or simply not given, because the terms have to say.
|
Participant rules
| Define |
Why it matters |
| Entries per person |
A cap per rolling window of up to 31 days, on a participant reference you choose. There is no
whole-campaign cap today, so a twelve-week campaign uses something like 10 per 31 days.
|
| Entries per day |
A rolling window, for example 3 per 24 hours or 10 per week. Windows run up to 31 days. |
| Anonymous versus identified participants |
LuckLogic needs only an opaque participant_id: a CRM id, a hashed
email, a device id. If the campaign is anonymous, limits fall back to IP address, which is weaker
on shared networks. Decide whether limits are worth asking for an identifier.
|
Claims
| Define |
Why it matters |
| Automatic approval |
Digital vouchers and QR-verified in-store prizes approve themselves on win, so the consumer gets
something immediately.
|
| Manual approval |
Shipped and high-value prizes wait for a person. Decide who: the brand in the Brand Portal, or
your team through the API.
|
| In-store collection |
Which stores, whether to record the location, and whether staff check ID or just the claim QR with
Verify.
|
| Shipping |
Who collects the address (it stays in your systems), who ships, and how the claim is marked
fulfilled.
|
| External fulfilment |
A fulfilment house fed by prize.claimed webhooks needs the event, a
retry-safe receiver and a way to mark claims fulfilled.
|
Security
| Define |
Why it matters |
| Security profile |
Standard, enhanced or high-value. The profile sets the per-IP rate, the invalid-code budget,
captcha, which ranks need manual approval and the default claim period. Pick by prize value, not
by campaign size.
|
| Rate limits |
Per participant (yours to set), per IP on public pages and per API key (from the profile). Agree
the numbers with the client so "too many attempts" screens are expected, not a surprise.
|
| Invalid-code handling |
How many wrong codes before an address is cooled off, and what the consumer sees. Codes are
unguessable; the budget exists so nobody gets to try.
|
| Captcha |
Required on the public page for enhanced and high-value profiles. If the campaign site is yours,
decide whether your own bot protection covers the entry form.
|
| Traffic expectations |
Tell us the peak if it is unusual. The per-key ceiling exists to protect everyone; a planned spike
is easy to accommodate when known.
|
Reporting
| Define |
Why it matters |
| Client access |
Which brand users get the Brand Portal, in which role: brand admin, fulfilment staff or auditor.
They see their client's campaigns and nothing else.
|
| Audit export |
The entry log is queryable per campaign for 12 months. Decide whether the client wants it exported
at the end, and who is allowed to see participant references in it.
|
| Winner export |
Claims are listable per campaign with status, tier, token and timestamps. Names and addresses are
not in LuckLogic, so a winner list joins your records to the claim tokens.
|
| Reconciliation |
For every tier, won equals fulfilled plus expired plus still-open. Decide who signs it off and
when, because claim periods often outlast the campaign.
|
Integration
| Option |
When |
| API |
You have a backend and want every screen under your control. Your server calls
POST /v1/redemptions with a secret key. See the
on-pack API guide.
|
| Widget |
A campaign page with no backend. One script tag and a publishable key locked to the campaign and
your origins.
|
| Hosted page |
The fastest launch. A branded page per campaign on our domain; print its URL or QR on pack.
Messages per outcome, locale and tier are configurable.
|
They can be mixed. A campaign can take QR scans on the hosted page and typed codes through your own site
at the same time, against the same prize pool.
Configure a campaign in Sandbox
The fastest way to turn this list into decisions is to configure the campaign while the client is in the
room. The Sandbox is free, holds up to 5,000 test codes, and the simulation shows how the prize table
would play out before anyone commits to it.