星耀联城POINTS TERMS

积分价值条款规则 · POINT VALUE TERMS & RULES

03PAGE 3 / 3

风控、会员后台、利润与实施验收RISK, MEMBER & ADMIN TOOLS, PROFIT & ACCEPTANCE

本页规定反作弊、会员和管理后台、利润保护、分阶段开发、自动化验收,以及不影响现有系统的实施要求。This page defines anti-abuse controls, member and admin tools, profit protection, phased delivery, automated acceptance, and safe implementation boundaries.

09RULE

防作弊和风险控制FRAUD & RISK CONTROLS

  1. 必须检测:同一交易重复通知、同一客户短时间大量交易、同一商家异常拆单、商家用自己的银行卡在自己店内刷卡、交易后迅速退款。

    Detect duplicate transaction notices, rapid high-volume activity by one member, suspicious merchant split transactions, self-spending at a merchant’s own store, and rapid post-transaction refunds.
  2. 必须排除或审查:礼品卡、现金等价物、转账、取现、伪造Webhook、修改前端金额、重放第三方通知和多账户套取积分。

    Exclude or review gift cards, cash equivalents, transfers, cash withdrawals, forged webhooks, browser-side amount tampering, replayed provider events, and multi-account reward abuse.
  3. 所有第三方Webhook必须验证签名,使用唯一事件ID防止重复处理,并保存原始事件审计记录。

    Every provider webhook must verify its signature, use a unique event ID for idempotency, and retain the original event for audit.
  4. Webhook必须异步处理并支持失败重试;重复通知不得重复发积分。

    Webhook processing must be asynchronous with failure retries, and repeated delivery must never duplicate points.
10RULE

会员前台MEMBER EXPERIENCE

  1. “我的积分”页面必须显示:当前可用积分、待确认积分、已使用积分、即将到期积分和积分欠额。

    My Points must show available, pending, redeemed, expiring, and negative point balances.
  2. 必须显示积分收入记录、积分使用记录、退款和撤销记录。

    It must show earning history, redemption history, refunds, and reversals.
  3. 必须显示已绑定银行卡末四位,以及绑定、解绑和重新授权入口。

    It must show the last four digits of linked cards and provide link, unlink, and reauthorization controls.
  4. 必须提供积分规则,以及参加积分活动的商品和商家。

    It must provide the point rules and list participating items and merchants.
  5. 前台统一说明:“每完成$1合格消费获得1积分。星耀联城购物时,1积分可抵扣$1,单笔订单最高使用50%积分,其余金额及税费、运费需要现金支付。具体以商品页面显示的积分规则为准。”

    Standard disclosure: “Earn 1 point for every completed $1 of qualifying spend. At XinggClub, 1 point may redeem $1, with points covering no more than 50% of an order. The remaining amount, taxes, and shipping require cash payment. Item-specific rules apply.”
11RULE

管理后台ADMINISTRATION

  1. 管理员可以查看积分发行总量、可用积分余额、已使用/撤销/过期积分、积分对应的现金销售额、商品毛利和积分带来的复购率。

    Administrators may view total issuance, available balances, redeemed/reversed/expired points, cash sales associated with points, item margin, and point-driven repeat purchase rate.
  2. 管理员可以设置商品积分比例和活动倍率、冻结异常账户、人工调整积分、审批特殊调整并导出报表。

    Administrators may set item redemption percentages and campaign multipliers, freeze risky accounts, adjust points, approve exceptional adjustments, and export reports.
  3. 人工修改积分必须填写原因、记录操作人和修改前后余额、生成积分流水并保留审计日志。

    Manual point adjustments require a reason, operator identity, before-and-after balances, a ledger entry, and an audit log.
  4. 不允许直接修改数据库余额。

    Direct database balance edits are prohibited.
12RULE

利润保护PROFIT PROTECTION

  1. 后台必须为每件商品计算:现金收入-商品成本-支付手续费-配送成本-运营成本=预计利润。

    For every item, calculate estimated profit as cash revenue minus item cost, payment fees, delivery cost, and operating cost.
  2. 如果使用积分后预计利润低于管理员设置的最低利润,系统必须自动降低可用积分或禁止该商品使用积分,并在后台显示风险警告。

    If points would reduce estimated profit below the administrator’s minimum, automatically lower the usable points or disable points for that item and display an admin warning.
  3. 不允许因为固定50%积分规则导致商品亏损;前台保持简单,后台负责利润保护。

    The 50% standard must not force an item into a loss. The customer experience stays simple while the server protects margin.
13RULE

开发阶段DELIVERY PHASES

  1. 第一阶段:检查现有网站技术架构、数据库、会员、商品、购物车和支付功能;备份数据库;建立积分总账;完成积分商城和50%积分+50%现金结账;使用测试积分和测试订单验证;不连接真实外部银行卡交易。

    Phase 1: inspect the current architecture, database, members, products, cart, and payments; back up the database; build the ledger and points-store checkout; validate with test points and orders; do not connect live external card transactions.
  2. 第二阶段:建立银行卡Token绑定界面、交易Provider Adapter、Webhook接收和签名验证;使用供应商Sandbox完成退款、重复事件和异常交易测试。

    Phase 2: build tokenized card linking, the transaction Provider Adapter, webhook intake, and signature verification; use the provider sandbox to test refunds, duplicate events, and abnormal transactions.
  3. 第三阶段:取得正式数据接口和合规批准后连接生产环境;先向内部测试会员和少量商品开放;核对积分、现金、退款和财务报表;稳定后再逐步扩大。

    Phase 3: connect production only after formal data access and compliance approval; start with internal members and a small item set; reconcile points, cash, refunds, and financial reports before gradual expansion.
14RULE

验收测试ACCEPTANCE TESTS

  1. $100商品、0积分=现金$100;30积分=现金$70+30积分;50积分=现金$50+50积分;100积分仍只能使用50积分。

    For a $100 item: 0 points means $100 cash; 30 points means $70 cash plus 30 points; 50 points means $50 cash plus 50 points; 100 points still allows only 50 points.
  2. 不参加积分的商品不能使用积分;混合购物车必须逐项计算;税费和运费不能使用积分。

    Nonparticipating items reject points, mixed carts calculate item by item, and points cannot cover taxes or shipping.
  3. Pending交易不能使用积分;外部交易入账后按照$1=1积分发放;同一交易重复Webhook不得重复发积分。

    Pending transactions cannot be redeemed; posted external transactions earn at $1 equals 1 point; duplicate webhooks cannot duplicate rewards.
  4. 全额退款和部分退款必须正确恢复或扣回积分。

    Full and partial refunds must correctly restore redeemed points and reverse earned points.
  5. 支付失败后释放锁定积分;两个设备同时结账不能重复使用同一批积分。

    Payment failure releases reserved points, and simultaneous checkout on two devices cannot spend the same points twice.
  6. 前端篡改价格或积分数量无效;管理员调整积分必须产生完整审计记录。

    Browser-side price or point tampering has no effect, and every administrator adjustment creates a complete audit trail.
15RULE

实施安全要求IMPLEMENTATION SAFETY

  1. 不得修改现有会员、AI匹配、商家认领、Jiean跳转和数据库中的其他业务功能;新功能尽量模块化。

    Do not change existing membership, AI matching, merchant claims, Jiean navigation, or unrelated database functions. Keep the new system modular.
  2. 实施前必须检查现有代码和数据库结构并备份数据库;数据库迁移必须可以安全回滚,不得删除现有数据。

    Inspect the existing code and schema and back up the database before implementation. Migrations must be safely reversible and must not delete existing data.
  3. 不得把测试数据写入正式会员账户。

    Test data must never be written into real member accounts.
  4. 未连接真实交易供应商时不得伪造正式功能,也不得宣传已经可以读取全部银行卡消费。

    Do not simulate a live external-card feature or advertise universal card-spend access before a real provider is connected.
  5. 完成后必须运行测试并提供结果,明确说明哪些功能可以正式使用、哪些仍然需要第三方银行卡交易接口。

    Run and report tests after implementation, clearly separating production-ready features from those still requiring an external card-transaction provider.
  6. 必须先完成现有系统检查和实施方案,确认不会影响现有功能后,再分阶段开发。

    Complete the current-system review and implementation plan first, confirm existing features are protected, and only then develop in phases.