Earlier quoted context omitted.
Hard to know what to say here, but we (Yell Labs) have built what appears to be the exact same solution to this problem that punchd have. As far as I can tell we started at around the same time but from London, UK. And we have our own patent applications (that I was unhappy about submitting because I don't agree that they were non-obvious, and that punchd did the same thing elsewhere at the same time is evidence of t…
We are using a lot of signals too. GPS is the only one we talk about :) You're right, it is a very delicate line between catching as many cheaters as possible while avoiding false-positives. We like to err on the side of false-negatives as much as possible.
And I'm sure you've also looked into whether the QR code could be generated per transaction (they could be, but does this place too high a cost-burden on the merchant and if a new device is used to display the generated codes is that going to meet local food hygiene standards for food outlets - and if existing devices are used such as printing on the receipts of their EPOS, is that accommodated by EPOS software).
We also looked into watermarking some signal from a sensor to prove that they were there, then we discovered Shopkick doing this with their noise emitter (a novel approach). We're unsure whether this is the best approach (requires another power point in the merchant, a mount point, installation, and if the emitted signal is dynamic then it requires a connection).
It's an interesting thing for sure... the best thing we've done to date is launch in a student bar with an alcohol deal, there is nothing that generates great data for security like letting compsci students hammer it with the reward of free beer. It's effectively our bug bounty... defeat our system and get a beer (or several) and strongly incentivises us to not have them defeat it.