Appearance
Users
Manage every account on your site from one place: look up customers, check their spend and wallet balances, add or deduct site credit, reset passwords and 2FA, lock suspicious accounts, handle GDPR erasure requests, review possible duplicate accounts, and invite new admins to help run your site.
Where to find it: Admin → Users (/admin/users).
The page has up to three tabs, depending on your role:
- Users — every account on your site (customers and staff).
- Account Flags — groups of possibly linked accounts detected by the nightly check, with a badge showing how many need review. See Account Flags.
- Admin Invitations — invite and manage new admin accounts (Admins only).
The active tab is reflected in the address bar, so you can bookmark or share a link that opens a specific tab directly.
Find a user
Three cards at the top summarise your user base: Total Users, Admins, and Verified Users (customers who have verified their email address).
Below the cards, the New customers by source panel shows where recent registrations came from — a marketing campaign, a referring site (like facebook.com or google.com), or direct (typed your address in, used a bookmark, or arrived some other untraceable way). Switch the period between the last 7, 30 or 90 days, and click any source bar to filter the user list below to just those customers (click it again to clear the filter). Attribution is collected automatically from campaign links and ad clicks; customers who registered before this feature existed count as direct.
To find a specific account:
- Type a name or email address into the search box (Search by email or name...). Results update as you type.
- Optionally narrow by role using the dropdown — All, Customer, Admin, Shop Manager, or Marketing.
- Tick Show archived if the account you're looking for may have been archived — archived rows appear greyed out.
The list shows one row per user:
| Column | What it shows |
|---|---|
| User | Name. A green ID card icon means the customer is ID verified (hover it to confirm). Sortable by first name. |
| Email address. A green tick means the email address is verified. Sortable. | |
| Source | Where the customer came from when they registered: the campaign source (with medium and campaign name where tracked) or the referring site. Shows "Direct" when nothing was tracked. |
| Spend | Cash paid by card on completed orders. Spending covered by wallet credit isn't included, so a customer who pays with credit or winnings can show £0.00. When there's activity, an up/down arrow appears — hover it to see the Site P/L figure (green "Site is ahead" or red "Customer is ahead"). Admins only. |
| Credit | Site credit balance. Click the amount to open that customer's credit wallet history. Sortable. Admins and Shop Managers. |
| Cash | Withdrawable cash balance. Click the amount to open their cash wallet history. Sortable. Admins and Shop Managers. |
| Actions | View, and — depending on your role and the account — edit, archive, login-as, and delete icons. |
Columns your role can't see are left out entirely: a Shop Manager sees Credit and Cash but no Spend column, and a Marketing user sees none of the three money columns.
The action icons on each row:
- View user details — opens the full profile panel (always available).
- Edit user — opens the profile in edit mode (Admins only; hidden for archived users).
- Archive user (orange box icon) — permanently redacts personal data; see Archive a customer. Only shown for accounts that can be archived.
- Login as this user — impersonate the customer; see Log in as a customer. Greyed out on your own account.
- Delete user — only appears for accounts the platform can safely remove outright (for example test accounts). For real customers with history, use Archive instead. Deletion cannot be undone, and you cannot delete your own account.
View a customer's profile
Click the view icon on any row to open the user details panel. From top to bottom it shows:
- Basic Information — name, email, date of birth, mobile number, plus a header line with the User ID, Member Since date, Last Login, and the IP address they registered from.
- Account & Verification — role, email verified, ID verified, 2FA status, email and SMS marketing consent, and the password reset control.
- Address — their saved postal address.
- Lifetime Value (Admins only) — Cash Spent (card payments on completed orders; wallet credit spending isn't included, so a customer who pays with credit or winnings can show £0.00) with the completed order count, and the Site P/L figure: your position on that customer, i.e. cash they've paid by card minus what their wins have cost you (fulfilled physical prizes and card refunds). Green means the site is ahead, red means the customer is ahead. For customers migrated from a previous platform, a line below the total shows how much of it was imported (e.g. "£500.00 imported from previous platform").
- Credit Wallet and Cash Wallet — current balance, an adjustment form, and the most recent transactions with a View All button for full history.
- Prizes — their most recent prizes with fulfilment badges (Completed, Processing, Pending, Awaiting, Cancelled). A count next to the heading shows the total and how many are still awaiting a prize choice. View All opens the full list.
- Orders — their most recent orders with status badges. The count next to the heading shows every order the customer has ever placed, with a breakdown of how many completed and how many are still in progress — so it can be higher than the completed order count under Lifetime Value. Click an order to open it in full — see Orders.
- Responsible Play — self-exclusion and spend limit status; see Check a customer's responsible play status.
- Possible Linked Accounts — only appears when the nightly linked-accounts check has grouped this customer with others; see Review possible linked accounts.
The footer holds the account-level actions: Lock Account / Unlock Account, Archive, Login as User, and Edit User.
Spot a blocked email address
A red no-entry icon next to the email address means the address is on the email block list and won't receive any emails from your site. Hover the icon to see why (hard bounce, soft bounce, or spam complaint) and when it was recorded. This is the first thing to check when a customer says they aren't getting order confirmations or marketing. Manage the block list under Logs.
Edit a customer's details
You need to be an Admin to edit users, and archived records cannot be edited.
- Open the user's profile and click Edit User (or use the edit icon on their row).
- Update any of: first name, last name, email, date of birth, mobile number, address, role, email verified, ID verified, and email/SMS marketing consent.
- Click Update User.
Things to know:
- Email is their login address — change it only to correct a genuine mistake.
- Date of birth must make the customer at least 18 years old.
- Mobile number and postcode must be valid UK formats if provided.
- Changing the Role or toggling ID Verified prompts for your authenticator code before saving — see Step-up authentication. Ordinary detail edits don't.
- Ticking Email Verified manually marks the address as verified without the customer clicking a verification email — useful as a last resort when a verification email genuinely can't reach them (see Troubleshooting).
Roles and permissions
Every account has one role. Customer is the default for everyone who registers on your site; the three staff roles grant access to the admin area:
| Area | Admin | Shop Manager | Marketing |
|---|---|---|---|
| Competitions | Full | View only | — |
| Entries | Full | Full | — |
| Orders | Full | View only | — |
| Winners | Full | View and update (no draws) | — |
| Instant wins | Full | Full | — |
| Users | Full | View only | View only |
| Filter the users export by competition entered | Full | Full | — |
| Customer spend & P/L (list, profile, export) | Full | — | — |
| Customer wallet balances (list and export columns) | Full | Full | — |
| Wallets & adjustments | Full | Full | — |
| ID verification | Full | Full (including decisions) | — |
| Marketing | Full | Full | Full |
| Pages & content | Full | — | Full |
| Media | Full | Full | Full |
| Analytics | Full | View | View |
| Tags | Full | Full | — |
| Webhooks | Full | Full | — |
| Admin invitations | Yes | — | — |
| Impersonation (login as user) | Yes | — | — |
| Archive / delete users | Yes | — | — |
| Settings & everything else | Yes | — | — |
Controls you don't have permission for are simply hidden — a Shop Manager, for instance, won't see the Edit or Delete icons on user rows, and won't see the Admin Invitations tab at all.
Change a user's role
- Open the user's profile and click Edit User.
- Pick the new role from the Role dropdown.
- Click Update User and enter your authenticator code when prompted.
Only Admins can edit users, so only Admins can change roles — and granting the Admin role specifically is restricted to Admins. There's no separate "Super Admin" role: Admin is the top role and carries every permission.
Step-up authentication
The most sensitive actions ask you to confirm your identity even though you're already logged in. A Confirm Your Identity dialog appears asking for the 6-digit code from your authenticator app; it submits automatically once you've typed all six digits, and cancelling abandons the action.
Actions that prompt for a code:
- Inviting a new admin
- Changing a user's role
- Marking a user as ID verified (or revoking it)
- Resetting a customer's password
- Viewing a customer's bank details on a withdrawal — see Wallets & Withdrawals
If you change a role and toggle ID verified in the same edit, you're only asked once. If you mistype the code, you'll be told it was incorrect and can try again.
Add or deduct site credit or cash
Use this for goodwill gestures, correcting mistakes, or returning money after a failed withdrawal. Both wallets work the same way and any staff member with wallet access (Admin or Shop Manager) can adjust them.
- Open the customer's profile.
- Scroll to Credit Wallet (site credit) or Cash Wallet (withdrawable cash).
- In the Credit Adjustment / Cash Adjustment form, enter the amount — positive to add, negative to deduct.
- Enter a Reason (required, at least 3 characters). Write something a colleague could understand later, e.g. "Manual credit for customer service issue" — it appears in the wallet's transaction history.
- Click Apply.
The balance updates immediately and the adjustment appears in the recent transactions list. Adjustment forms are hidden on archived records. For the wider picture on wallets, bonuses, and withdrawals, see Wallets & Withdrawals.
View a customer's wallet history
Two ways in:
- From the user list, click the amount in the Credit or Cash column.
- From the profile panel, click View All next to either wallet's recent transactions.
The history panel lists every transaction with a running balance, and can be filtered by type — credit wallets show Purchase, Purchase Bonus, Deduction, Instant Win Prize, Main Prize, Admin Adjustment, and Refund; cash wallets show Cash Prize, Cash Alternative, Admin Adjustment, and Withdrawal.
Cash transactions that came from a win show View Competition and View Order links beneath them in the profile panel, so you can trace a prize payment straight back to its source.
Verify a customer's ID manually
If you've checked a customer's identity document outside the platform (for example over email), you can mark them as ID verified without a document upload:
- Open their profile.
- In Account & Verification, click the Verify ID button next to the unverified badge.
- Enter your authenticator code when prompted.
The badge flips to verified and the green ID icon appears next to their name in the user list. Admins and Shop Managers can do this. For document uploads submitted through the site, use the review queue instead — see ID Verification.
Reset a customer's password
There is no "send a reset email" button here — instead the platform generates a strong password for you to pass on. This is the right tool when a customer is locked out and can't receive email.
- Open the customer's profile and click Reset next to Password (Admins only; unavailable on archived records).
- A panel opens with a generated password. Use the eye icon to reveal it, Copy to copy it, or Regenerate if you want a different one.
- Click Confirm reset. If prompted, enter your authenticator code.
- On success, share the password with the customer — Copy password copies just the password, Copy message copies a ready-made message including their email address and a reminder to change it after logging in.
The new password works immediately. Always tell the customer to change it once they're back in.
Reset a customer's 2FA
When a customer has lost their authenticator app and can't log in:
- Open their profile.
- In Account & Verification, the 2FA field shows Enabled — click Reset next to it.
- Confirm in the dialog.
Their two-factor authentication is switched off and they can log in with just their password. Encourage them to set 2FA up again from their account settings. Verify you're really talking to the account holder before doing this — it removes a security layer.
Log in as a customer (impersonation)
To see the site exactly as a customer does — their wallet, entries, orders, and account pages — use Login as User (Admins only):
- Click the person icon on their row, or open their profile and click Login as User in the footer.
- Confirm in the dialog.
- You're switched to their account and taken to your site's homepage. A yellow banner across the top reads "Impersonation Mode: Logged in as [name]" the whole time.
- Click Exit Impersonation in the banner to return to your own admin account.
You can't impersonate yourself (the button is greyed out on your own account), and archived users can't be impersonated.
Lock or unlock an account (suspension)
Locking is how you suspend an account — for suspected fraud, abusive behaviour, or while you investigate something. It takes effect immediately.
- Open the user's profile and click Lock Account in the footer.
- Choose a Lock Duration: 1 Hour, 24 Hours (the default), 7 Days, 30 Days, or Permanent.
- Enter a Reason for Lock (required).
- Click Lock Account.
The customer is logged out of all sessions on the spot and cannot access the platform until the duration ends or you unlock them. Admin accounts cannot be locked this way.
To lift a lock early, open the profile and click Unlock Account, then confirm. The customer can log straight back in.
The same lock dialog is available from the linked-accounts review panel, so you can lock accounts directly while investigating a flag — see Account Flags.
Archive a customer (GDPR erasure)
Archiving is the platform's "right to be forgotten" tool. It permanently redacts all of the customer's personal data while keeping the anonymised order and entry records your accounts need.
- Click the orange archive icon on their row, or open their profile and click Archive in the footer.
- Read the confirmation carefully — it names the customer and warns that the redaction cannot be undone and that they will no longer be able to log in.
- Click Archive Customer.
After archiving:
- The record is read-only — a banner at the top of the profile shows when it was archived, and editing, locking, impersonation, and wallet adjustments are all removed.
- The customer cannot log in.
- There is no restore. Archiving is permanent, so double-check you have the right account before confirming.
Only Admins can archive, and the option only appears on accounts that are eligible. To find archived records later, tick Show archived above the user list — they appear greyed out and you can still open them to view their (redacted) history.
Review possible linked accounts
The platform runs a nightly check for accounts that appear to belong to the same person. When a customer is part of a detected group, a Possible Linked Accounts card appears on their profile showing:
- how many accounts are in the group and a % match confidence score,
- evidence chips explaining why they were grouped (stronger evidence in red, weaker in yellow),
- a red Possible exclusion circumvention badge when one of the linked accounts is self-excluded — treat these as urgent.
Click View to open the full review panel, where you can compare the accounts and lock any of them. The complete queue of flagged groups lives on this page's Account Flags tab — see Account Flags for the review workflow.
Check a customer's responsible play status
The Responsible Play section of the profile shows, where set:
- Exclusion status — Excluded (currently active) or Expired, with the exclusion type (24 Hours, 7 Days, 30 Days, or Permanent), when it ends, and when it was set.
- Monthly spend limit — the limit, what they've spent this month, what's remaining, and a usage percentage that turns amber at 80% and red at 100%.
If neither is set, it reads "No restrictions set". For the site-wide register and managing exclusions, see Responsible Play.
Export users to CSV
Use exports for SMS or email marketing lists, compliance requests, or offline analysis.
Click Export at the top right of the page.
Either use a quick preset or pick fields yourself:
- SMS Marketing Export — selects First Name, Last Name, and Phone Number, and switches on the "SMS consent only" filter, giving you a ready-to-use, consent-safe texting list.
- Full Export — selects every field available to you.
- Or tick individual fields across the Contact, Address, Consent, Account, and Financial groups (names, email, phone, address lines, consent flags and dates, role, verification flags, created/last login dates, wallet balance, total spent, total orders, last order date).
The Financial group follows the same rules as the list columns: Wallet Balance is available to Admins and Shop Managers, while Total Spent, Total Orders, and Last Order Date are Admin-only. Fields your role can't export simply aren't offered, and Full Export skips them too — so a Marketing user's Full Export contains no financial data.
Optionally apply filters: SMS consent only (opted in with a valid phone number), Marketing consent only (email opt-in), and Verified users only.
The SMS Marketing Export preset and the SMS consent only filter are hidden if you have switched SMS marketing off under Settings → General → SMS Marketing; the SMS Consent fields stay available as a historical record.
Optionally set an Order date range (Admins only, since it affects only the three Admin-only spend fields). When set, Total Spent, Total Orders, and Last Order Date only count orders placed within those dates; leave it empty for lifetime figures. Imported spend from a previous platform has no order dates, so it is included in lifetime Total Spent but not in a date-ranged export.
Optionally narrow the export to Competitions entered. Search for the competitions you want and tick as many as you need, and the file will only contain people who entered at least one of them. Every competition on your site is listed, including ones that have already ended, so you can go back to an old draw and pull out the people who took part.
Someone counts as having entered once they hold a ticket in that competition, however they got it. Free postal entries count, because they become real tickets on your site. Tickets that were never paid for, or that were later cancelled, do not count.
This filter ignores the order date range, and looks across all time. If you tick three competitions, you get everyone who entered any one of them, not only people who entered all three.
This filter is available to Admins and Shop Managers. A list of who entered a particular draw is entrant information, so it is limited to the roles that are already trusted with your entries. Marketing users do not see it, and can still export your customer list without it. You can pick up to 25 competitions at once.
Click Export CSV. The file downloads immediately. When you have filtered by a single competition, its name is included in the file name so you can tell your lists apart later.
You must select at least one field. For marketing sends themselves, see Marketing.
A word on phone numbers
If you tick Phone Number without switching on SMS consent only, your site shows an amber note reminding you that the file may include people who have not opted in to SMS marketing. It is a reminder, not a block: the export still runs, because there are good reasons to pull phone numbers that have nothing to do with marketing, such as contacting a winner. Just be sure that whatever you do with the file matches what those customers agreed to.
Build an SMS list for one competition
Click SMS Marketing Export to select the name and phone fields and switch on "SMS consent only", then tick the competition you want under Competitions entered and export. You get a texting list of everyone who entered that competition and has opted in to SMS, ready to send to your entrants about the draw or a follow-up offer.
Build a repeat-buyer segment
Tick Email, Total Orders, and Total Spent, set the order date range to the last four weeks, then export and keep the rows with two or more orders. That gives you your most engaged recent customers for a focused campaign.
Invite a new admin
Give a colleague their own admin login rather than sharing yours — every action is then attributable to the right person. Only Admins can send invitations.
- Go to the Admin Invitations tab.
- Click Invite Admin.
- Enter their email address and click Send Invitation.
- Enter your authenticator code when prompted.
An invitation email goes to that address with a personal acceptance link. The invitation appears in the table with its Status (Pending, Accepted, Expired, or Revoked), who sent it (Invited By), when it was Created, and when it Expires.
The invitation creates a full Admin account. If the new colleague should have a narrower role, let them accept first, then change their role to Shop Manager or Marketing — see Change a user's role.
What the invitee sees
The link in the email opens an Accept Admin Invitation page on your site:
- The page verifies the link, then shows who invited them and the email address the invitation was sent to.
- They fill in their First Name, Last Name, and a Password, with a live checklist confirming the password rules: at least 12 characters, contains a letter, contains a number. A confirm-password field warns if the two don't match.
- They click Create Admin Account and see a success screen with a Continue to Login button.
If the link is expired, revoked, or otherwise invalid, they see an Invitation Invalid message instead of the form. If they open the page without using the emailed link, they're told to use the link from their email.
Revoke an invitation
To withdraw a pending invitation — wrong address, or the person no longer needs access:
- Find the invitation in the table (only Pending rows show an action; everything else shows a dash).
- Click the revoke (✕) icon and confirm.
The link stops working immediately and the row's status changes to Revoked. Revoking an invitation does not affect accounts that have already been created — to remove an existing admin's access, change their role back to Customer instead.
An invitation expired or went astray — send a fresh one
There is no resend button. Instead:
- Link expired — the status is already Expired, so simply click Invite Admin and send a new invitation to the same address.
- Still pending but the email never arrived, or you want to restart — revoke the pending invitation first, then send a new one. (You can't have two live invitations playing against each other for the same person.)
Each new invitation gets a fresh link and a fresh expiry date.
Troubleshooting
A customer says they aren't receiving emails
- Open their profile and look for a red no-entry icon next to their email address — if present, the address is on the block list (hover for the reason: hard bounce, soft bounce, or spam complaint). Manage the block list under Logs.
- Check the email logs under Logs to confirm whether messages were sent and what happened to them.
- Ask them to check spam and confirm the address on their account is spelled correctly — fix it via Edit User if not.
- For a verification email specifically, as a last resort you can tick Email Verified in Edit User to verify them manually — only once you're satisfied the address is really theirs.
A customer can't log in
- Locked account — open their profile; if the footer shows Unlock Account, they're locked. Unlock them if appropriate.
- Lost authenticator — if 2FA shows Enabled, use the 2FA Reset button so they can log in with just their password.
- Forgotten password and can't receive email — use the password reset flow and share the generated password securely.
- Archived account — archived customers can never log in; archiving is permanent.
A new admin says their invitation link doesn't work
Check the invitation's status on the Admin Invitations tab:
- Expired — send a fresh invitation.
- Revoked — someone withdrew it; send a fresh one if access is still wanted.
- Accepted — the account already exists; they should just log in (use the password reset flow if they've forgotten their password).
- Pending — make sure they're using the exact link from the email (opening the page without it shows "No Invitation Token"). If it still fails, revoke and re-invite.
I can't see the Admin Invitations tab, or the Edit/Delete buttons
Your role doesn't include that permission — only Admins can invite admins, edit users, impersonate, archive, or delete. Ask an Admin to make the change, or to upgrade your role if it's something you need regularly.
"Login as User" is greyed out
You're looking at your own account — you can't impersonate yourself. It's also unavailable on archived users.
The step-up dialog says my code was incorrect
Codes are time-based, so a code that sat on screen too long may have rolled over. Wait for your authenticator app to show a fresh 6-digit code and try again.