Internal communications and software records at Phia, the personal shopping startup co-founded by

Bill Gates daughter Phoebe Gates and Sophia Kianni, indicate that the founders were allegedly aware of software features designed to claim unauthorised sales commissions at least seven months before the company publicly blamed the practice on a sudden âsoftware bug.â Citing internal Slack messages and source code reviews, Bloomberg reports that the practice, which is known in the affiliate marketing industry as âcookie stuffingâ, was active as early as December.

The timeline contradicts a public statement issued by the company on July 8, which claimed leadership had only discovered the tracking behavior âwithin the last 24 hoursâ.

Internal slack records detail âAuto Dropâ features

Phia operates as a browser extension designed to help shoppers automatically find discount codes and compare prices at online checkout counters. In exchange, partner retailers pay the platform an affiliate commission when its software helps convert a sale.

However, internal chats accessed by the publication reveal that Phia implemented automated features that injected its tracking cookies into a shopperâs checkout session without requiring any user interaction, such as clicking a deal link or applying a coupon code, the Bloomberg report says. By dropping tracking identifiers automatically, Phia claimed credit and commissions for transactions it did not drive, a practice that is strictly prohibited by commercial network contracts and partner agreements.

The report further claims that Slack discussions from December show Gates enquiring about whether automated cookie insertion was active across partner sites. In one exchange, Gates asked developers to confirm that âauto pop for cookie drop is live on ALL sites w a coupon to confirm we are monetizing on all gmv [gross merchandise value].â

Code reviews suggest 'automatic refresh of tracking cookies'

Additional source code reviews showed secondary features, including a âpassive triggerâ that automatically refreshed tracking cookies every two hours on top retail sites, which essentially increased the likelihood that Phia would overwrite competing referral links and secure the payout.

This alleged âunauthorisedâ attribution strategy generated a substantial portion of the company's daily income. Following the deactivation of these features in early July, Phiaâs average daily revenue dropped from approximately $80,000 to between $10,000 and $28,000, the report said.

An internal analysis conducted by a company data scientist in July estimated that unauthorised cookie insertion accounted for roughly 51% of the total merchandise value Phia claimed credit for selling in June.

A spokesperson for Phia disputed the internal revenue estimates, stating the preliminary analysis relied on an âincorrect methodology.â The company attributed the broader drop in daily income to its decision to pause wider monetisation tools during an internal review.