Dataset + notes — Dec 2024 / Dec 2025

Honey's public store list: 173.9K shops, most with no affiliate deal

Honey's own extension has to fetch a store directory. We saved it. 173.9K rows. 84.4% have no affiliate URL. MegaLag's videos cover the cookie swap; this page is the table behind those claims. Alleged, not adjudicated.

✍️ By Germanas Latvaitis📊 173.9K stores analyzed🔄 Updated Dec 24, 2025⏱️ 45 min read
PayPal Honey Under the Lens - 173,871 Stores Database Analysis by EcomScout
173.9K
Total Stores in Dataset
84.4%
Added Without Consent
283.8M
Monthly Users Tracked
27.2K
Paying Partners

Partnership Distribution

No Consent: 146.7K
Official Partners: 27.2K
Gold Partners: 45.5K
⚠️
146.7K stores
have their data collected without affiliate partnership
✓
27.2K stores
are official Honey affiliate partners

What Honey actually is

A Chrome/Firefox add-on that tries coupon codes at checkout. Peak install base was about 17 million. PayPal closed the deal in January 2020 at $4 billion (announced November 2019). The product pitch is "free savings." The money is affiliate payouts and shopping graphs.

Creators were paid to push the install. Same creators often run their own Amazon/NordVPN/merchant links. Last-click rules mean whoever wrote the cookie last gets paid. MegaLag showed Honey writing that cookie at checkout even when no code applied. People call that cookie stuffing. Honey calls it applying deals.

I did not reverse the extension. I dumped the store index the extension already downloads, then lined it up against MegaLag part 1 (Dec 2024) and part 2 (SSD / CookieGate, Dec 2025).

How the Alleged Scam Works

Networks pay the last affiliate cookie before purchase. Honey sits on the checkout page, so it is last by construction. Reported sequence:

The Alleged Commission Diversion Process

  1. 1
    User clicks affiliate link:

    A viewer clicks a creator's affiliate link (e.g., from a YouTube video), which places an affiliate tracking cookie on their browser.

  2. 2
    User browses and adds to cart:

    The user shops on the website and adds items to their cart. The creator's affiliate cookie is still active.

  3. 3
    Honey activates at checkout:

    At checkout, Honey pops up and "searches for codes," even if there are no valid codes available.

  4. 4
    Cookie is replaced:

    During this process, Honey replaces the creator's affiliate cookie with its own, claiming the "last click" attribution.

  5. 5
    Honey allegedly receives the commission:

    When the user completes the purchase, Honey reportedly receives the affiliate commission instead of the creator who actually drove the sale.

"Honey reportedly takes a 97.5% cut of affiliate commissions. Users get back just 2.5% as 'Honey Gold' rewards. So when Honey allegedly diverts a $10 commission from a creator, users get roughly $0.25."

About This Dataset: Honey's Publicly Available Store Data

The extension cannot guess 170k+ domains. It asks Honey's API for the list: name, URL, country, whether an affiliate link exists, Gold flag, coupon counts. Same payload every client gets.

We stored that payload. 173.9K stores. Search box is at the bottom of this page.

What the Dataset Contains

Store Information: Name, URL, country, category
Affiliate Status: Whether the store has a partnership
Gold Status: Premium partnership tier indicator
Traffic Analytics: Monthly shopper counts and store traffic (30-day)
Coupon Data: Number of codes, application counts
UGC Indicators: Whether codes were user-submitted
Savings Claims: Reported savings amounts
Affiliate Networks: Which networks Honey uses

Data Analysis: 173.9K Stores Exposed

84.4% — 146.7K of 173.9K — have an empty affiliate field. Honey still lists them and still collects codes from checkouts on those domains. I cannot prove a given merchant never emailed Honey. The field is empty. That is the fact.

Stores by Country

United States
71.1K
United Kingdom
28.6K
Germany
15.5K
Australia
14.3K
Canada
10.7K
Netherlands
5.8K
France
5.1K
Italy
4.3K

Top Affiliate Networks

Awin
8.0K
ShareASale
5.6K
Impact Radius
2.7K
CJ Affiliate
2.2K
Rakuten (LinkShare)
1.7K
TradeTracker
1.5K
45.5K
Gold Partners
51.0K
Stores with Coupons
1.7K
User-Submitted Codes
$1.7M
Monthly "Savings"

Top Stores by Monthly Shoppers

StoreCountryShoppersStatus
Microsoft
https://www.microsoft.com
🇺🇸 US7.0MNo Consent
ChatGPT
https://chatgpt.com
🇺🇸 US6.2MNo Consent
Apple
https://www.apple.com
🇺🇸 US4.4MPartner
Netflix
https://www.netflix.com
🇺🇸 US3.8MNo Consent
Walmart
https://www.walmart.com/shop/deals
🇺🇸 US2.9MNo Consent
Canva
https://www.canva.com
🇦🇺 AU2.7MNo Consent
Target
https://www.target.com
🇺🇸 US2.0MNo Consent
USPS
https://www.usps.com
🇺🇸 US1.7MNo Consent
Best Buy
https://www.bestbuy.com
🇺🇸 US1.6MNo Consent
Disney+
https://www.disneyplus.com
🇺🇸 US1.5MNo Consent
🆕 New Evidence from MegaLag Part 2 (Dec 2025)

CookieGate: Honey's Secret Compliance Evasion System

MegaLag part 2 (December 2025) named a flag in the client: SSD — Selective StandDown. Affiliate networks already require a stand-down after someone else's link. SSD decides whether Honey actually obeys that, based on who you look like.

⚠️

The Dieselgate of Affiliate Marketing

MegaLag compared this to the Volkswagen Dieselgate scandal. VW programmed cars to detect when they were being tested and only then reduce emissions. Honey's SSD system allegedly does the same: it detects compliance testers and behaves correctly only for them, while continuing the fraud for real users.

How the SSD System Works

After a CJ / Awin / Rakuten click, Honey should leave that cookie alone. SSD adds a quiz first:

The SSD Decision Tree

  1. 1
    Detect Affiliate Link

    Honey detects the user clicked an affiliate link (e.g., from Commission Junction, Awin, Rakuten)

  2. 2
    Run User Profile Checks

    Instead of standing down, Honey runs tests to determine if the user is a "safe" target:

    • • Account Age: Is the account older than 30 days?
    • • Points Balance: Does the user have cashback points (originally 501, now 65,000)?
    • • Logged In Status: Is the user logged into Honey?
    • • Email Check: Does the email contain "test"?
  3. 3
    Cookie Surveillance (GCA Check)

    This is the most invasive part: Honey scans your browser for cookies from affiliate networks (Commission Junction, Awin, Impact, etc.). If any are found, Honey assumes you're an industry insider and behaves correctly.

  4. 4
    Decision: Stand Down or Override

    If you pass all checks (high engagement, no industry cookies), Honey considers you "safe to steal from" and ignores stand-down rules. If you fail any check, Honey behaves compliantly.

Evidence from the Data

Our database analysis backs up MegaLag's findings about Honey's coupon manipulation:

1,536
Brands with UGC Blocked

User-submitted coupons disabled. Brands control the narrative

14,505
Stores with Hidden Coupons

Expired codes marked "hidden" but still shown to users

473
Monetization Notes

Internal notes about coupon restrictions per brand

Where Honey's Coupons Really Come From

Honey markets itself as "scanning millions of codes from the internet." The data tells a different story:

Coupon Source Distribution

User Submitted (USER)
28,559 (33%)
Manual Entry (MANUAL)
25,370 (29%)
Awin Network (AW)
12,918 (15%)
FMTC Feed
3,502 (4%)
Other Networks (CJ, IR, PHG, etc.)
~16,000 (19%)

Key insight: 62% of coupons come from users and manual entry, not automated scraping. This lines up with what MegaLag found: Honey's "millions of codes" marketing was misleading.

The Stand-Down Timer Manipulation

Archived versions of Honey's code from the Wayback Machine show the stand-down timer was originally just 6 minutes (360 seconds). After MegaLag's first video went viral in December 2024, they quietly bumped it to 1 hour (3600 seconds).

Why this matters: A 6-minute window is absurdly short. If a user clicks your affiliate link, browses for 7 minutes, then checks out, Honey would override your tracking and take the commission. Even the current 1-hour window is questionable. Most affiliate networks use a 24-hour or 30-day attribution window.

Ryan Hudson's Response Falls Apart

After MegaLag's Part 1, Honey co-founder Ryan Hudson posted a Reddit response claiming Honey only removed employee discounts and always required replacement codes of equal value. MegaLag took these claims apart point by point:

  • Honey's own Shopify app documentation showed merchants could freely remove any codes
  • Database notes reveal Honey disabled entire coupon sources at brands' requests
  • UGC blocking on 1,536 partnered brands contradicts "always find the best deal" marketing
  • Monetization notes document Honey knowingly violating affiliate network coupon clauses
"Based on these notes, it appears that Honey would join a brand's affiliate program, note their coupon policies, then intentionally break them for as long as they could get away with it."MegaLag, Part 2 Investigation

Expert Verification

MegaLag brought in Ben Edelman, a Harvard security researcher known for exposing major affiliate fraud. Edelman independently verified the findings:

"Your findings are on target. Honey stands down, but only sometimes... A program that detects testers and hides from testers is incredibly frustrating. It indicates bad faith in the testing process. The network should be angry."

Ben Edelman, Harvard Security Researcher

On potential criminal charges, Edelman noted the behavior could constitute wire fraud: misrepresenting that commissions were payable to Honey when they were owed to other affiliates. He cautioned that corporate criminal prosecution is rare in the US.

Who actually loses money

Creators first. You send a link, the viewer already has Honey, checkout overwrites you. LTT promoted Honey for years and only killed the deal after a staffer confirmed the override — even with no deal found. MrBeast took the sponsorship checks; his other merch links sat on the same browsers.

Merchants next. 146.7K rows here have no partner flag. Staff codes and influencer uniques still show up in the coupon fields. Chip at Maiden Cookware asked to be removed and got a partnership pitch instead. Another merchant, same Honey employee, got a takedown a month earlier.

Shoppers get Gold scraps and a browse history. DateRequests.org pulled 2,500 pages for one GDPR request covering three months. The 2.5% Gold kickback on a hijacked $10 commission is twenty-five cents.

Affected Creators: Documented Case Studies

I am not going to invent a victim count. These three are on tape or in email.

LTT

Linus Tech Tips

19M+ subscribers • Tech reviews & tutorials

Ended Partnership

What happened: Linus Media Group promoted Honey since 2017. They had no idea Honey was overriding their own affiliate links. It took several years to figure it out.

Discovery: A forum user raised concerns in 2020, but it was ignored. In 2022, an LMG employee confirmed: "If someone clicked on an affiliate link and then they used Honey and searched for a deal, Honey will override that tracking link even if they don't find you a deal. That didn't jive with us, so we ended the partnership."

Significance: If a tech-savvy team with deep affiliate marketing experience took years to notice, how many smaller creators are still losing money without knowing?

Estimated Impact: With millions of viewers using their affiliate links for tech purchases (average order $200-500), LTT likely lost hundreds of thousands of dollars during their Honey partnership years.

🎬

MrBeast

340M+ subscribers • Honey's #1 sponsor

Highest Impact

Scale of Promotion: MrBeast's Honey sponsorships hit 3+ billion views, more than one-third of Honey's total YouTube sponsored views. Honey's former president said: "Every kid in America knows what Honey is."

The Irony: MrBeast earned millions from sponsorship fees. But his audience's later purchases through his other merch / partner links sat on browsers that already had Honey.

Audience Demographics: MrBeast's audience skews heavily toward minors (13-17), which raises serious concerns about Honey collecting data from children who installed the extension.

Key Quote from Honey's President: "Every kid in America was telling their moms and dads they needed to download Honey in order to save money."
Joanne Bradford, Former Honey President

🔍

MegaLag's Commission Test

Investigative journalist • Documented proof

Verified Test

The Experiment: MegaLag set up his own NordVPN affiliate account (40% commission) and made two identical purchases. One with Honey Gold on, one without.

Without Honey Gold:
$35.00
Commission received ✓
With Honey Gold:
$0.00
Commission stolen ✗

What Honey Gave Back: After allegedly taking the $35 commission, Honey rewarded the "consumer" (MegaLag himself) with 89 Honey Gold points = $0.89. That's a 97.5% profit margin for doing nothing.

The Math: Honey took $35.00, gave back $0.89 (2.5%), and pocketed $34.11 (97.5%) on a transaction they had zero role in generating.

Other Notable Affected Creators

Marques Brownlee (MKBHD)

19M subs • Tech reviews with high-value affiliate links

Desiree Machado

Was 14 years old when sponsored • Back-to-school content

Minecraft/Roblox Channels

Primarily child audiences • Honey's target demographic

Gamers Nexus

Lead plaintiff in class action lawsuit against PayPal

17 million installs. I will not multiply that by a made-up take-rate and call it a finding. The NordVPN $35 → $0 test is enough to show the mechanism. Scale is a lawsuit problem, not a blog-math problem.

Estimated Industry-Wide Creator Losses

The box below is napkin math. I put it here because people ask "how big." It is not a measurement. Inputs are industry averages plus this table's shopper field.

📊 Creator Loss Estimation Model

Data Points from Our Research

Affiliated stores in database:27.2K
Monthly Honey shoppers (30d):283.8M
Stores with Gold cashback:26.3K
Industry avg commission rate:8-15%
Estimated hijack rate:~80%

Estimated Creator Losses

Estimated Monthly Stolen Commissions
$12-25M
Based on transaction volume & avg commission
Estimated Annual Creator Losses
$150-300M
Industry-wide impact since 2017
Total Since PayPal Acquisition (2020)
$500M-1B+
Cumulative stolen commissions

Assumptions I plugged in

Change any of these and the $150–300M/year band moves. I have not seen Honey's ledger.

  • ~8% of shoppers run Honey or a clone (install-base folklore, not a panel)
  • Affiliate AOV $75–150
  • Commission 8–12%
  • Override on 70–90% of checkouts where Honey is open — MegaLag's tests, not a census
  • Shopper field in this dump: 283.8M / 30 days across 173.9K rows

I did not split that band into "tech vs fashion vs lifestyle." Those splits would be fanfic. Tech carts are larger (LTT, MKBHD). Fashion is more frequent. I do not have Honey's GMV by vertical.

Commission Loss Calculator

Same assumptions as above. Plug your own AOV if you sell $400 GPUs instead of $40 shirts.

Commission Loss Calculator

Estimate how much you may be losing due to Honey

Total monthly sales from affiliate links

Average purchase amount

Typical: 5-15% for most programs

Industry estimate: 5-12% of users

💡 What Can You Do?

  • Warn your audience about Honey's practices and recommend uninstalling
  • Use affiliate networks with "standdown" rules that protect against cookie hijacking
  • Consider joining the class action lawsuits against PayPal
  • Implement coupon code protection on your own store if applicable
  • Document your losses for potential legal claims

Honey's Harvested Coupon Codes and User-Generated Codes

1.7K stores in this dump have a UGC/user-submitted coupon flag. Codes typed at checkout get POSTed to Honey before the "share?" prompt — MegaLag showed that in the iOS client. Clicking Don't Share is late.

Staff discounts, one-use influencer codes, VIP strings. Once they sit in the public list, your channel report in Shopify is garbage for those orders.

How Honey Allegedly Harvests Private Codes

When a Honey user types a coupon code at checkout, Honey sends that code to their servers before asking for consent. Source code from their iOS app confirmed this.

Even clicking "Don't Share" doesn't help. Honey already captured the code. Their privacy policy says they collect "coupons, promo codes, and deals you found," giving them cover to take the data regardless of what the user chooses.

Small Business Extortion: Pay Up or Suffer

Standard reply after a takedown ask: partner with us and you can control the codes. Chip Malt (Maiden Cookware) published the thread. Friends-and-family code leaked; he wanted off the list.

Email Exchange: Maiden Cookware vs. Honey

Chip (CEO, Maiden Cookware):

"Please remove us from your app. You've scraped a private friends and family code from our checkout and put it on the platform for others to use. We've lost a bunch of revenue."

Honey's Response (4 days later):

"In order to protect the Honey experience for our users, we typically do not remove codes unless we have a working relationship. We'd love to discuss how we can work more closely and partner with your brand."

Chip:

"We don't offer affiliate deals to coupon sites. We'd like to be removed from your site and extension completely."

Honey's Response (months later, after repeated leaks):

"We proudly host a consistent shopping experience for all Honey shoppers. Therefore, we cannot disable Honey for individual stores and never have."

That was a lie. Another business owner, Andrew from Target Texture Supply, shared his email exchanges with the same Honey employee. That employee successfully removed his store from the platform, just one month before telling Chip it was "impossible."

"Nine times out of 10, the response is: join our affiliate program and you'll have more granular control. Merchants feel like they're being blackmailed or extorted."Marketing industry expert on Honey's practices

146.7K rows with no affiliate URL. Leak a code, then sell the cleanup. Call it what you want; the emails are above.

Data Collection: 2,500 Pages of Your Shopping History

Honey's site said they don't sell your data. DateRequests.org (Germany) filed a GDPR access request anyway. One user, three months: 2,500+ pages.

What Honey Collected (From Just One User)

📊
2,500+ pages

of web activity in just 3 months

🔍
Every page visited

on any store Honey "supports"

🕐
Precise timestamps

of every browsing session

📍
Geolocation data

device IDs, OS information

Twenty-seven page views were enough to reconstruct products, order IDs, a disputed order, a family plan, Airbnb dates, and a game serial in the query string. Full URLs, not hashed events.

The Honey "Privacy" Contradiction

Honey's website promised users: "We never sell or share your data." But to their merchant partners, Honey employees bragged: "We have all sorts of tools... we're really kind of following the shopper where they go and we're with them every step of the way."

2015 pitch deck already listed behavioral data, stores visited, products viewed, purchase history as the "unfair advantage." PayPal did not invent that.

2024: PayPal's ad network. They said 400 million users. Honey is one of the pipes.

Targeting Minors: The MrBeast Connection

Privacy policy: adults 18+, no knowing collection from children. Then they paid MrBeast.

His Honey spots passed 3 billion views — MegaLag's tally is more than a third of Honey's sponsored YouTube inventory. That audience is not 35-year-old coupon hobbyists.

MrBeast's Honey Ad Script

"I have a challenge for all of you. Go to every computer in your house, your mom's, your dad's, your sister's, your brother's computer, and install Honey."

This ad directly encouraged children to install data-tracking software on every device in their household, including computers belonging to other family members.

But MrBeast wasn't the only child-focused channel Honey sponsored. They paid for sponsorships on:

  • Minecraft channels, games played mostly by children
  • Roblox channels, median user age under 13
  • Cartoon and animation channels, clearly aimed at young audiences
  • A 14-year-old influencer, Desiree Machado, whose "Back to School" video was Honey-sponsored

COPPA / GDPR-K care about parental consent. I am not a lawyer. The ad script and the 18+ clause do not fit in the same paragraph without someone sweating.

The $4 Billion Question: Why Did PayPal Pay So Much?

$4 billion. YouTube was $1.65B, Instagram $1B, Twitch $970M. People keep stacking those because a coupon add-on should not cost more than all three. It did.

PayPal did not buy a code scraper. They bought checkout-adjacent telemetry on tens of millions of browsers.

What PayPal Really Bought

👥
17 Million Active Users

Each one tracked across every online store they visit

🛒
Complete Shopping Journeys

What users browse, compare, abandon, and purchase

🎯
"Cross-Shopping" Intelligence

Which competitors users compare before buying

💵
Price Sensitivity Data

"How much they are willing to pay," from Honey's own pitch deck

"Honey's unique data allows us to predict what each user is about to buy, when they intend to purchase, and how much they are willing to pay."Honey's 2015 investor pitch deck

Ex-staff described "cross-shopping" reports: how many other shops the same browser hit before converting. That is a pricing and ads product, not a coupon product.

PayPal Ads, 2024. The install was free because the session was not.

Explore the Full Dataset: 173.9K Stores

Search your domain. If it's here, it's here. 173.9K rows.

Complete Store Database

173.9K stores with aggregated analytics data

Filter:
Showing 0-0 of 0 stores

Loading stores...

If you are in the table

Creators: stop the Honey pre-roll. Ask the network what their stand-down window actually is. Keep payout CSVs if a lawyer later wants them. I am not that lawyer.

Store owners: search the grid above. GDPR/DSAR if you are in the EU. One-time codes for influencers so a leaked string dies. Honey's takedown email is a sales call — Chip's thread is the template.

Everyone else: uninstall it. Use the creator's link if you were going to buy anyway. Capital One Shopping / Rakuten / the next clone do a version of the same last-click trick.

References & Sources

This investigation builds on the work of independent journalists and researchers who first exposed Honey's practices. Watch these videos for the full story:

Shopify Intelligence Platform

Stores. Products. Apps. One platform.

Research competitors, discover trending products, find suppliers, and track what's working across the entire Shopify ecosystem. Start free — no credit card.

Explore More Tools