Guides/Scoping a prize promotion

What agencies should define before building an instant-win promotion

A brief says "on-pack promotion, 2 million packs, win a trip". The backend needs about forty more answers. This is the list, grouped the way the configuration is grouped, with a line on why each one matters. Most of it is the client's decision; getting it in writing before anything is built is the cheapest week of the project.

Campaign

Define Why it matters
Start and end dates, and the timezone Entries outside the window are refused. Winning Moments are laid out across it, so the window shapes the whole prize release.
Countries Determines the legal terms, the languages for messages, and whether one campaign or one per market.
Expected entries Sizes the code batches and feeds the simulation that shows how prizes will fall. Typically 5 to 25% of packs sold.
Peak traffic TV spots and launch days arrive as spikes. Winning Moments stop a spike draining prizes, but your site and backend still have to stay up.
Entry channels Typed code on a web page, QR scan to a hosted page, in-app via your backend, or several at once. Each is a batch format and an integration path.

Codes

Define Why it matters
Number required Usually the number of packs plus a margin for print waste. Sets the plan: up to 250,000, up to 2,000,000, or above.
Code length Ten characters from a 28-character alphabet is the default and is unguessable at any volume. Shorter codes fit small packs but shrink the margin against guessing.
Print format Alphanumeric codes, digit-only codes, or QR tokens with a scan URL. Numeric codes need more length for the same volume. Once typed codes are generated for a production campaign, length and alphabet lock.
Number of print batches One batch per print run or source, so a lost or misprinted run can be revoked on its own. Batches are unlimited; total codes are what the plan counts.
Free-entry or alternative-entry source Where the law requires a no-purchase route, it is usually a separate small batch so its entries can be reported apart.

Mechanics

Define Why it matters
Prize tiers Each tier has its own quantity, release rule, fulfilment method and verification. Rank them: the top ranks can be forced to manual approval by the security profile.
Prize quantities One Winning Moment is generated per prize. Quantities can be raised or lowered on a live campaign, with a reason, but never below what has already been won.
Winning Moment distribution Even across the window, late-stage (the last 30%), or uniform random, per tier, optionally inside a narrower window. This decides whether small prizes flow all summer and the trip waits for the final week. See how Winning Moments work.
Claim deadlines Per tier: a date after which the prize is no longer awarded, and a claim period after which a winner who has not collected loses the claim.
Unawarded-prize handling Moments nobody reached by the end are reported as unawarded. Decide now whether they are rolled into a final draw, donated, or simply not given, because the terms have to say.

Participant rules

Define Why it matters
Entries per person A cap per rolling window of up to 31 days, on a participant reference you choose. There is no whole-campaign cap today, so a twelve-week campaign uses something like 10 per 31 days.
Entries per day A rolling window, for example 3 per 24 hours or 10 per week. Windows run up to 31 days.
Anonymous versus identified participants LuckLogic needs only an opaque participant_id: a CRM id, a hashed email, a device id. If the campaign is anonymous, limits fall back to IP address, which is weaker on shared networks. Decide whether limits are worth asking for an identifier.

Claims

Define Why it matters
Automatic approval Digital vouchers and QR-verified in-store prizes approve themselves on win, so the consumer gets something immediately.
Manual approval Shipped and high-value prizes wait for a person. Decide who: the brand in the Brand Portal, or your team through the API.
In-store collection Which stores, whether to record the location, and whether staff check ID or just the claim QR with Verify.
Shipping Who collects the address (it stays in your systems), who ships, and how the claim is marked fulfilled.
External fulfilment A fulfilment house fed by prize.claimed webhooks needs the event, a retry-safe receiver and a way to mark claims fulfilled.

Security

Define Why it matters
Security profile Standard, enhanced or high-value. The profile sets the per-IP rate, the invalid-code budget, captcha, which ranks need manual approval and the default claim period. Pick by prize value, not by campaign size.
Rate limits Per participant (yours to set), per IP on public pages and per API key (from the profile). Agree the numbers with the client so "too many attempts" screens are expected, not a surprise.
Invalid-code handling How many wrong codes before an address is cooled off, and what the consumer sees. Codes are unguessable; the budget exists so nobody gets to try.
Captcha Required on the public page for enhanced and high-value profiles. If the campaign site is yours, decide whether your own bot protection covers the entry form.
Traffic expectations Tell us the peak if it is unusual. The per-key ceiling exists to protect everyone; a planned spike is easy to accommodate when known.

Reporting

Define Why it matters
Client access Which brand users get the Brand Portal, in which role: brand admin, fulfilment staff or auditor. They see their client's campaigns and nothing else.
Audit export The entry log is queryable per campaign for 12 months. Decide whether the client wants it exported at the end, and who is allowed to see participant references in it.
Winner export Claims are listable per campaign with status, tier, token and timestamps. Names and addresses are not in LuckLogic, so a winner list joins your records to the claim tokens.
Reconciliation For every tier, won equals fulfilled plus expired plus still-open. Decide who signs it off and when, because claim periods often outlast the campaign.

Integration

Option When
API You have a backend and want every screen under your control. Your server calls POST /v1/redemptions with a secret key. See the on-pack API guide.
Widget A campaign page with no backend. One script tag and a publishable key locked to the campaign and your origins.
Hosted page The fastest launch. A branded page per campaign on our domain; print its URL or QR on pack. Messages per outcome, locale and tier are configurable.

They can be mixed. A campaign can take QR scans on the hosted page and typed codes through your own site at the same time, against the same prize pool.

Configure a campaign in Sandbox

The fastest way to turn this list into decisions is to configure the campaign while the client is in the room. The Sandbox is free, holds up to 5,000 test codes, and the simulation shows how the prize table would play out before anyone commits to it.

Keep reading