Phia co-founders Phoebe Gates and Sophia Kianni pushed for features in the e-commerce startup’s software that took credit for sales it didn’t drive, according to internal communications and people with knowledge of the matter.
The founders were aware of the practice for at least seven months, going back to December, according to the people and messages posted on the company’s internal Slack channels that were shared with Bloomberg News. The people asked not to be identified as they were not authorised to discuss the issue.
That timetable runs counter to public remarks by the company, which said on July 8 that it had only become aware of the situation "within the last 24 hours.”
Phia bills itself as a "personal shopping assistant” that helps users find the lowest prices on a broad range of clothes and fashion accessories. It operates a browser extension that, when used as part of the online checkout process, can quickly find discount codes for products and save shoppers money. When a shopper uses Phia’s product to help make a purchase, the company earns a commission from the retailer for helping drive the sale.
But Phia’s browser extension was also designed to report that the startup drove a sale even when its product was never used – a practice that resulted in increased commissions, Bloomberg reported in July. The company said at the time that the problem stemmed from a software bug that had only been discovered on the day it was contacted by Bloomberg.
In reality, Kianni and Gates, the daughter of billionaire Microsoft Corp co-founder Bill Gates, were aware of features that, without user intent, set a web tracking device known as a cookie into the checkout process for online sales, according to the people and Slack messages. Two people with knowledge of the matter said the exchanges referenced in this story are no longer visible to Phia employees.
The strategy, which is broadly prohibited by Phia’s commercial partners, was implemented at least as far back as December, the internal chats show, and involved purchases made on the websites of several major retailers, including Nike, Gap and Nordstrom. A Bloomberg review of Phia’s historical source code confirmed these features existed.
"Any features causing misattributions were immediately removed over a month ago on July 7,” a Phia spokesperson said. "We are reviewing every transaction, we are fully committed to and have already begun issuing all transaction reversals to brand partners as a result of any misattribution, and we are hiring a head of compliance to make sure something like this never happens again.”
The spokesperson added that the company will continue to connect shoppers to discount offers. "We will learn from this and want to ensure our users have the best possible shopping experience, with features like our new digital closet and more to come,” the spokesperson said.
Nike, Gap and Nordstrom did not respond to requests for comment.
These techniques, known as "cookie stuffing,” were responsible for a significant portion of Phia’s sales, according to an internal revenue chart seen by Bloomberg. After Phia disabled the features in early July, average daily revenue at the company dropped from about US$80,000 (RM327,240) to between US$10,000 (RM40,905) and US$28,000 (RM114,534), the chart shows. A Slack message posted by a Phia data scientist on July 7 and reviewed by Bloomberg estimated that cookie stuffing accounted for about 51% of the merchandise value Phia claimed credit for selling in June.
A Phia spokesperson said that part of the revenue decline was because the company disabled most of its monetisation efforts at that time, not just the cookie stuffing features. The spokesperson said that the information shared by the data scientist was also inaccurate and was from a preliminary analysis that used "an incorrect methodology that overstated the potential impact.”
Ben Edelman, an advertising consultant who has spent more than two decades exposing what he describes as deceptive marketing practices, reviewed Phia’s source code as well as data from impacted merchants. He also analysed three "cookie stuffing” features Phia used, and corroborated Bloomberg’s analysis.
"These additional findings reveal a multipart effort designed to inflate Phia revenue despite lack of benefit to merchants,” Edelman said. "Phia should have spent more time learning the contracts to which they were bound and less time building tricks for quick profit.” A Phia spokesperson declined to comment on Edelman’s analysis.
Phia, which raised US$35mil (RM143mil) in venture funding from several prominent investors in January, has already started to pay back some commissions to retailers.
Affiliate network Impact.com, responsible for distributing commissions to publishers like Phia, said it had suspended the startup from its marketplace after Bloomberg’s initial report last month. It is also reallocating commissions that had been attributed to the startup, but not yet paid out, since June 20.
It’s possible that Phia will have to issue additional refunds given the company’s "cookie stuffing” strategy was going on longer than initially reported.
Cookie stuffing
In the affiliate marketing industry, businesses and individuals – like social media influencers – can earn commissions by driving sales on behalf of a brand. To ensure that they get credit for the sale, the affiliate sets a cookie with a unique tracking identifier on the shopper’s browser during the sales process as proof of their involvement, a method known in the industry as "dropping a cookie.” In order for an affiliate to drop a cookie, the shopper must have intentionally interacted with the affiliate, for example, clicking on its referral link or using a coupon code it suggests.
Phia’s prohibited practice of automatically dropping a cookie without any user interaction was initially discovered by Bloomberg after a review of its mobile browser extension across more than 50 websites. The tests found that during the checkout process, Phia opened a background tab and injected its own cookie into the sales process, overriding legitimate referrals from other publishers.
Phia said it fixed the issue in July after outreach from Bloomberg, adding that the company had only discovered it in "the last 24 hours.”
But an internal dashboard, a screenshot of which was seen by Bloomberg, shows that what Phia called a bug was actually a feature named "enable coupon auto drop,” which could be turned on and off remotely by Phia. The feature was initially switched on starting Dec 10 and wasn’t switched off until July 7, the day Bloomberg first reached out to Phia for comment. Two people familiar with the matter confirmed that the dashboard switch meant the feature was live.
Phoebe Gates was aware of features that automatically set cookies from at least Dec 18, according to an internal Slack discussion reviewed by Bloomberg and confirmed by people familiar with the matter. In a conversation with developers, Gates saw that Phia wasn’t generating as much commission as expected from Etsy, one of its retail partners, and became concerned that cookies were not being automatically set across retailers.
Phia’s browser extension has a box that automatically pops up on retailers’ websites during the online checkout process to offer discount coupons. If a shopper clicks to use one of the coupons, Phia is entitled to a commission for helping drive the sale. Gates wanted to verify that Phia’s cookie was being dropped automatically when the box popped up even if the shopper didn’t click to use a coupon, according to two of the people. This would allow Phia to take the credit and commission for the total value of products sold, known as gross merchandise value.
"worried this is an issue across the board,” Gates wrote in a company Slack channel on Dec 18. "can u confirm auto pop for cookie drop is live on ALL sites w a coupon to confirm we are monetizing on all gmv.”
In the Slack conversation, a Phia developer noted there was a problem with the pop-up not working but confirmed that cookies were automatically set when the pop-up surfaced, even if the shopper didn’t use a coupon. Gates responded to reconfirm her desire that Phia automatically take credit for every sale. "but regardless we should capture every transaction if the cookie drop was working,” she replied.
Phia said Gates was concerned with the fact the coupon pop-up was broken, which meant users weren’t seeing coupons. This would "also decrease attributed purchases to Phia,” the spokesperson added.
Publishers like Phia are prohibited from dropping cookies automatically unless a shopper clicks on a Phia link or uses a coupon offered by the company, according to rules set out in platform partners’ contracts. The rules are designed to create a level playing field for affiliate marketers and ensure that retailers are only paying commissions to the company that drove the shopper to the website to make the purchase.
Phia built other features that similarly dropped a cookie without the shopper intentionally clicking on its coupons or links. One was internally dubbed "passive trigger” and was active from October to July, according to a review of Phia’s source code. The feature dropped a cookie automatically every two hours on any "top 1000 website” where the user had previously interacted with Phia, according to Slack messages between co-founder Kianni and software engineers. This allowed Phia to drop cookies at regular intervals, potentially replacing other referrers’ cookies and giving it a higher chance of winning the commission.
A second feature, deployed around the same time, set a cookie if the shopper clicked anywhere on the page after the Phia pop-up box appeared on the checkout screen – including if the user tried to close the pop-up.
Phia declined to comment on the features.
At one point, Kianni proposed a feature that dropped a cookie when a user tried to close a different Phia pop-up. A colleague told Kianni that Google’s Chrome Extension policy prohibits companies from dropping an affiliate cookie on "dismiss events” – for example, trying to close a pop-up. Kianni initially conceded the company shouldn’t drop a cookie if a user decided to "click ‘X’” to close the pop-up, before adding: "I guess we could say that the user is trying to open us and roll it back if they complain,” she replied on Slack.
A Phia spokesperson said this feature "never got implemented or launched.”
The colleague told Kianni that dropping a cookie on a swipe-away action wouldn’t make much difference since the company was already utilising "passive trigger,” which dropped a cookie automatically every two hours.
"Whatever we can do to keep these cookies dropping will be amazing thank you,” Kianni wrote. – Bloomberg
