Skip to content

How it works

From receiptto ownership,in ten stages.

Each stage in plain words, and what actually happens underneath.

  1. 01

    Purchase

    You buy something from a supported brand, as you always do.

    Nothing on-chain yet. STOCKBACK never touches the payment.

  2. 02

    Evidence

    You scan the merchant's signed QR, or photograph a paper receipt.

    Tier 1: a merchant-signed receipt (Ed25519 over every field; simulated merchant in this demo). Tier 2: tesseract.js OCR in the browser, every field editable, so authenticity is not established.

  3. 03

    Attestation

    The attester checks the evidence and signs a claim.

    For merchant receipts the attester first verifies the merchant signature, expiry and prior use. It then signs the EIP-712 digest with Ed25519 (Stylus verifier) or ECDSA. Keys never reach the browser.

  4. 04

    Commitment

    Your purchase becomes a fingerprint with no personal data.

    claimId = EIP-712 hash of claimant, brand, merchant hash, salted receipt hash, amount, currency, time and deadline.

  5. 05

    Nullifier

    The receipt can only ever be used once, by anyone.

    nullifier = keccak256(tag, merchantId, receiptHash). Independent of wallet and amount, so re-issuing a receipt doesn't help.

  6. 06

    Verification

    The signature is checked on-chain.

    ReceiptCommitmentRegistry calls IReceiptVerifier.verify(digest, attestation). The active verifier is a Rust contract on Arbitrum Stylus checking strict Ed25519.

  7. 07

    Eligibility

    Brand, currency, amount and date must fit the program.

    EligibilityPolicy: brand active, INR, ₹100 to ₹5,00,000, purchase within 30 days and not in the future; optional jurisdiction adapter.

  8. 08

    Reward

    Your reward is calculated by public rules.

    RewardPolicy: amount × rate × multiplier, clipped to the per-claim cap; per-wallet and per-brand daily caps; paid only from sponsor budget.

  9. 09

    Brand vault

    The reward goes into that brand's vault, in your name.

    RewardPool deposits the brand asset into its admin-less ERC-4626 BrandVault and mints shares to you. Steps 4 to 9 are one transaction.

  10. 10

    Ownership

    You hold shares you control. Redeem them any time.

    Portfolio reads vault balances live; activity reads registry events. Nobody but you can move your shares.

Try it with a demo receipt. It takes under a minute, on real testnet.

Scan a receipt