---
title: "Protecting travel bookings with device recognition — TraceTail"
description: "Loyalty-point farming, booking fraud with stolen cards and price-scraping bots: how travel sites can use a visitor ID against each."
url: https://tracetail.io/blog/travel-hospitality-fraud-prevention
updated: 2026-10-04
---

# Protecting travel bookings with device recognition

Loyalty-point farming, booking fraud with stolen cards and price-scraping bots: how travel sites can use a visitor ID against each.

_TraceTail Team · published January 2, 2025 · updated October 4, 2026 · 2 min read_

Travel and hospitality sites face a particular mix of fraud: loyalty points farmed and stolen, bookings paid with stolen cards, referral bonuses abused, and bots scraping prices. A visitor ID, which stays the same across sessions and new accounts, helps with most of it.

## Loyalty program fraud

Loyalty points are effectively currency, which makes programs a target:

- **Point farming**: opening many accounts to collect sign-up bonuses
- **Account takeover**: signing in to real members' accounts to spend their points
- **Laundering**: moving points through chains of throwaway accounts

Identify the browser at enrollment and send the visitor ID with the request:

```javascript
import { TraceTail } from '@tracetail/js';

const tracetail = new TraceTail({ apiKey: 'YOUR_API_KEY', endpoint: 'https://tracetail.io/api' });
const { visitorId } = await tracetail.generateFingerprint();

await fetch('/api/loyalty/enroll', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({ email, visitorId }),
});
```

If one visitor ID has already enrolled several members, hold the sign-up bonus for review.

## Booking fraud

A typical stolen-card booking looks like this:

1. A new account, created behind a VPN
2. A high-value booking paid with a stolen card
3. A quick change of traveler name, or a transfer of the booking

The first step isn't as anonymous as it seems. If a visitor ID is linked to earlier chargebacks, that's a strong signal:

```javascript
// Your backend
async function bookingRisk(visitorId, amount) {
  const chargebacks = await db.bookings.count({ visitorId, status: 'charged_back' });
  let score = 0;
  if (chargebacks > 0) score += 60;
  if (amount > 2000) score += 15;
  return { score, review: score > 70 };
}
```

## Price-scraping bots

Scrapers aren't fraud in the strict sense, but they cost infrastructure and undercut your pricing. With an API key, each identification includes TraceTail's flag for automated browsers such as headless Chrome and WebDriver, and the visitor ID lets you rate-limit by device rather than by IP address.

## Limits

- **Shared computers** in hotel lobbies and airports give different guests the same visitor ID. Don't block on the ID alone there.
- **Native apps** need native device signals; TraceTail's SDK runs in web browsers.
- **Organized rings** with many real people on many real devices need payment checks, identity verification and booking-pattern analysis as well.
- **Forged IDs.** The visitor ID is computed in the visitor's browser and sent by your own page, so treat it as a strong signal rather than proof: an attacker who controls their browser can send any ID they like, including one they learned from a victim.

## Where to start

The highest-value places to identify the device are:

1. Loyalty enrollment and sign-in
2. Checkout and payment
3. Account changes: email address, password and traveler names

The SDK computes the visitor ID in milliseconds, and TraceTail recognizes returning visitors with 99.6% accuracy. Start with the free 1,000 requests a month. [Read the docs](https://tracetail.io/docs) or [try the live demo](https://tracetail.io/live-demo).

Tags: Travel, Loyalty fraud, Booking fraud
