
A cannabis reward that pushes a product below a permitted price floor, reaches an ineligible customer, or uses unapproved health language can create more risk than the repeat purchase it generates. Loyalty program compliance for cannabis and CBD brands requires a controlled launch process because product rules, promotional pricing, age eligibility, privacy, and marketing rules can vary by product and market.
Short answer: A compliant program starts with a market-by-market approval matrix. Define eligible customers, approved products, reward mechanics, pricing limits, messaging channels, and disclosures before configuring Shopify or Mage. This framework is not legal advice. Use it to organize counsel’s review.
Why loyalty program compliance for cannabis and CBD brands requires a different launch process
The same reward can be treated differently by state
A percentage discount may be permitted in one market and restricted by a pricing rule in another. New York, for example, permits adult-use retailers to use discounts, coupons, loyalty programs, and bundled deals only when they do not result in below-market pricing, according to state guidance.
A standard points-to-discount rule can therefore fail when a customer redeems it. Review the product, market, price calculation, taxes, audience, and message before approving a reward.
Cannabis retail and CBD are not one compliance category
Cannabis dispensaries, hemp-derived CBD stores, topical products, ingestibles, and non-cannabinoid merchandise should not share one assumed rule set. Shopify permits US merchants to sell hemp and hemp-derived CBD only when they meet applicable federal, state, and local requirements, according to its hemp requirements.
CBD positioning also needs separate review. Shopify prohibits unapproved medicinal, disease-related, or therapeutic marketing claims.
Loyalty creates several compliance touchpoints
A loyalty program combines purchase history, rewards, discounts, account data, email, SMS, checkout, and sometimes in-store redemption. Treat it as a product, promotion, data, and messaging workflow rather than a simple coupon.
“Cannot say enough good things about the team at Mage Loyalty, one of the absolute best organizations we have ever worked with, full stop! So glad we connected with them, completely redid our loyalty program, new concepts, use of loyalty, increasing user engagement, showing us where we were not valuing our best customers, just WOW, amazing team!”


Read the West Coast Goalkeeping case study →
Step 1: Build a state-by-state compliance matrix before choosing rewards
| Market and license | Product category | Customer eligibility | Approved reward mechanics | Restrictions | Approved channels | Required disclosures | Source and review date | Owner |
|---|---|---|---|---|---|---|---|---|
| State and license type | Cannabis, CBD, topical, ingestible, non-cannabinoid | Enrollment, earning, redemption | Counsel-approved rewards | Pricing, giveaways, claims, stacking | Website, email, SMS, POS | Terms, privacy, age notices | Official source and date | Legal or compliance lead |
Create a row for every state, locality, license type, and product category where requirements differ. Record:
- Who may enroll, earn, redeem, view offers, and receive marketing messages.
- Approved products, shipping or delivery markets, and POS rules.
- Each proposed mechanic, including points, store credit, amount-off rewards, percentage discounts, free shipping, free products, referrals, and VIP perks.
- Price floors, tax treatment, stacking restrictions, giveaway rules, and required disclosures.
- The official source, reviewer, and next review date.
New York’s guidance uses a market-value calculation based on 1.5 times the wholesale price paid for the specific product or unit. That is why the matrix needs pricing math, not just approved campaign copy.
If a market rule cannot be validated, exclude that market until it is approved.
Step 2: Design the program around eligibility, redemption, and pricing controls
| Mechanic | What it can do | Approval question | Control |
|---|---|---|---|
| Points | Track approved customer activity | What can points buy and where? | Limit earning and redemption to approved products and markets |
| Store credit | Present loyalty value as currency | Does redemption affect pricing rules? | Review checkout outcome and disclosures |
| Percentage discount | Reduce eligible order value | Could it create below-market pricing? | Use only approved rates and audiences |
| Free product | Offer one unit at no charge | Is it permitted as a reward? | Require product- and market-specific approval |
| Referral reward | Reward an advocate and friend | Are sharing and issuance timing allowed? | Delay issuance until approved conditions are met |
Choose the reward currency after mapping the rules
Do not start with points. Start with eligibility, pricing, redemption, and communications controls. Risk usually appears when a balance becomes a discount, free product, public promotion, or targeted message.
Mage supports fixed amount off, percentage off, free shipping, free product, points, and store credit rewards. Review each mechanic separately. Read more about points versus store credit, but do not assume either currency is universally safer.
Mage’s loyalty store-credit mode is a Mage-internal ledger. It should not be described as Shopify-native store credit.
Set limits and test refund outcomes
Use the approved matrix to set customer limits, product exclusions, maximum reward values, and minimum purchases where required. Shopify supports amount-off, percentage, buy-X-get-Y, and free-shipping discounts through discount codes or automatic discounts, as documented in its discount guidance.
The availability of a discount type does not make it lawful for a regulated product. New York guidance restricts promotions that make cannabis effectively free, encourage overconsumption, or use game-like mechanisms that may appeal to people under 21.
Mage can delay referral rewards until after a return window or another configured delay. It also reverses points proportionally after partial refunds and reduces spend-based tier totals. Validate those outcomes before launch.
Step 3: Separate loyalty enrollment from marketing consent
Joining a loyalty program should not be treated as blanket consent for email, SMS, profiling, advertising, or every use of purchase history.
Your privacy policy and loyalty terms should explain:
- What data the program collects and why.
- How long information is retained and which providers receive it.
- Reward expiration, program changes, account access, deletion, and opt-out processes.
- The difference between joining the program and consenting to promotional messages.
Shopify can support a marketing-consent checkbox at customer account sign-in and checkout in supported configurations, according to its customer account customization guidance. Use that control for marketing consent, not as a replacement for loyalty terms.
Mage can sync loyalty points, tiers, and events to connected email and SMS platforms. A SMS loyalty integration can support customer properties and events, but SMS consent, audience suppression, and compliance remain the merchant’s responsibility. Mage does not send SMS itself.
For SMS, document the opt-in method, privacy-policy disclosure, terms, message frequency, data-rate language, opt-out instructions, and support contact details required by Shopify’s SMS requirements.
Step 4: Put loyalty content through the approved marketing workflow
Review every customer-facing surface: loyalty page, Rewards Widget, account sidebar, referral page, product-page earning copy, checkout content, POS prompts, email, and SMS.
Use adult-appropriate creative and language. Avoid copy, games, or offers that could appeal to people below the applicable minimum age or encourage overconsumption.
CBD reward content needs the same claim review as product pages. Review reward names, referral templates, testimonials, email copy, and product-linked banners for unapproved therapeutic or disease claims.
Mage Canvas controls customer-facing loyalty, referral, account, and wishlist surfaces. Use it to publish approved content, not to bypass the approval matrix. Keep a versioned record of the creative, audience, market, dates, reward rule, disclosures, and reviewer for every campaign.
Step 5: Configure Shopify and Mage for a controlled launch
| Control | Shopify | Mage | Merchant or legal team |
|---|---|---|---|
| Product and market eligibility | Catalog and market setup | Approved loyalty configuration | Define approved scope |
| Earning and rewards | Checkout discount behavior | Earning rules and reward types | Approve mechanics and disclosures |
| Test launch | Customer and order testing | Test Mode | Validate outcomes |
| In-store redemption | Shopify POS | POS loyalty tile | Train staff and review procedures |
| Communications | Consent and audience controls | Events and loyalty-data sync | Approve templates and suppression rules |
Enable the Mage Loyalty app embed on the live theme before expecting storefront features to appear. Then configure the Loyalty, Account Sidebar, and Rewards Widget sections around the approved matrix.
Use Mage Test Mode with a restricted test list before launch. Only customers on that list can earn, redeem, or trigger connected integration events while testing.
Create only approved earning rules and reward types. Do not add social engagement rules, public referral incentives, bonus campaigns, or VIP perks until their confirmation process, disclosures, and audience restrictions have been reviewed.
Connect email and SMS workflows only after consent, audience eligibility, templates, and suppression rules are approved. A points-earned event should not automatically become an SMS campaign for every customer.
Points expiry is off by default in Mage. Leave it off until its disclosure and reminder approach are approved.
Test rewards at Shopify Checkout and, where relevant, Shopify POS. Mage’s POS tile lets staff look up a customer, view points and rewards, and redeem for the current transaction. Test partial and full refunds, excluded products, eligibility rules, reward stacking, delayed referrals, and storefront visibility by market.
For related implementation guidance, see Shopify loyalty apps for CBD and wellness brands.
Step 6: Monitor compliance and create an audit trail after launch
Mage Analytics can show loyalty-attributed revenue, redemption rate, outstanding points balance, active members, returning customer metrics, member CLV, and purchase frequency. These measures do not prove compliance, but they show how the program behaves after launch. Review Mage Analytics after changes to campaigns, markets, or reward rules.
Monitor rewards that are claimed but not used, balances growing faster than redemptions, and patterns that conflict with the approved program design.
Referral reporting can identify blocked attempts based on configured fraud signals, including self-referrals, duplicate accounts, alias blocking, shared IPs, repeat devices, and rapid referral bursts. Review those exceptions alongside market eligibility rules, especially when a referral campaign offers regulated-product discounts.
Maintain a change log for reward rules, terms, privacy disclosures, audiences, creative, state availability, and integration changes. Include the date, owner, approver, reason, and affected markets.
Cannabis and CBD loyalty program pre-launch checklist
Legal and market controls
- Each market has a documented source, owner, review date, and approved product scope.
- Minimum age, eligibility, shipping, and redemption rules are defined and tested.
- Pricing floors, taxes, stacking, discounts, free products, and giveaways have approval.
Customer and data controls
- Privacy policy and loyalty terms describe data use, retention, customer rights, and program changes.
- Email and SMS audiences are permissioned for the intended message type.
- CBD claims and testimonials have been screened for therapeutic or disease claims.
Reward and checkout controls
- Mage Test Mode has been used with a restricted test list.
- Checkout, POS, refunds, excluded products, delayed rewards, and expiry settings have been tested.
- The loyalty store-credit ledger is described accurately and not presented as Shopify-native store credit.
Messaging and monitoring controls
- Campaign assets, audiences, dates, and disclosures have an approval record.
- Analytics, referral exceptions, points liability, and change logs have assigned owners.
Frequently asked questions
Are loyalty programs legal for cannabis and CBD brands?
Loyalty programs for cannabis and CBD brands can be legal in some markets, but legality depends on product category, jurisdiction, license type, reward mechanics, pricing, age eligibility, advertising, and communications. New York permits certain loyalty programs while restricting below-market pricing and specific promotional practices.
Can cannabis and CBD brands offer points or store credit?
Cannabis and CBD brands can use points or store credit only after reviewing what happens at redemption in each market. The review should cover price-floor rules, taxes, free-product restrictions, giveaways, stacking, and disclosures. Mage supports both points and a Mage-internal store-credit loyalty mode, but neither is an automatic legal safe harbor.
How do age restrictions apply to a cannabis loyalty program?
Age restrictions apply to who may enroll, earn, redeem, view promotions, and receive communications from a cannabis loyalty program. Define market-specific eligibility rules and test them across storefront and POS experiences. Shopify and Mage do not independently provide universal cannabis age verification.
Can cannabis and CBD brands send loyalty offers by SMS?
Cannabis and CBD brands may send loyalty offers by SMS when they meet applicable consent and telecommunications requirements. The program needs documented opt-in, privacy disclosures, message frequency, data-rate language, opt-out instructions, support contact information, and audience suppression. Mage can sync loyalty data to SMS platforms, but it does not send SMS directly.
Can CBD loyalty emails mention health benefits?
CBD loyalty emails should not use blanket health-benefit language unless the claim has the required substantiation and approvals. Review product copy, loyalty pages, reward emails, referral messages, testimonials, and promotional banners before publishing.
How should a Shopify merchant audit a cannabis loyalty program?
A Shopify merchant should audit market rules, product scope, age eligibility, rewards, pricing behavior, consent, creative, refunds, referral exceptions, points liability, and campaign changes on a recurring schedule. Use Mage Test Mode before launch and Analytics after launch to identify operational exceptions and document how the program behaves.
Ready to see Mage in action? Book a demo.
Graeme is the co-founder at Mage Loyalty. He heads product development, from complex loyalty migrations and large-scale data handling to building the features shaping the future of loyalty on Shopify.
















