marivc

iFood · 2022

Handshake: reliability with low friction

The challenge wasn't adding one more step to the courier's flow. It was making sure every order reached the right person without compromising speed, experience, or scale.

My role
Senior Product Designer
Latam Logistics
Company
iFood
Year
2022
MobileResearchLogistics

Summary

At iFood, an order goes through a simple sequence: a courier arrives at the restaurant, picks up the order, and heads out for delivery. But two of these moments had no validation mechanism at all.

At arrival, some couriers confirmed presence before actually reaching the restaurant, compromising key operational metrics. At pickup, there was no reliable way to guarantee the right courier picked up the right order. Without that proof, two problems coexisted: fraud and theft on one side, and honest order mix-ups in the rush of the operation on the other.

As the Product Designer on the team, I led the research, ideation, and validation of two new flows in the courier journey, creating new validation points that increased operational reliability without compromising the courier experience.

The problem

The problem had scale. Every month, thousands of orders were affected by the absence of these validation mechanisms. With no way to prove who had arrived at the restaurant and who had picked up each order, the operation lost reliability. Some of the losses came from fraud, some from honest mistakes handing over the order — and iFood fully absorbed the cost of cancelled orders in both cases.

  • 9,700 orders/month cancelled due to lack of pickup validation.
  • 886 orders/month linked to parcel theft.
  • 0.68% of orders had courier/order mismatches at pickup.
  • 100% of cancelled order value was absorbed by iFood.

Challenge

Create two new validation points in the courier's journey, making sure the right courier picked up the right order, at the right restaurant, without adding friction to the operation, compromising the courier experience, or impacting metrics like Contact Rate.

Approach

01

People before technology

I started by interviewing couriers to understand where the operation was actually failing. The conversations revealed two important gaps: there was no reliable way to validate arrival at the restaurant or order pickup. They described both fraud schemes already known in the field and order mix-ups that happened by accident, when several similar bags went out at once.

02

Understand the cause before discussing solutions

I facilitated ideation sessions with engineering and designers from the Restaurant and Consumer teams. Before discussing technology, we used 5 Whys to identify the root cause of the problems and align on a single solution for the whole journey.

03

Validate the hypothesis before scaling

Before building any solution, we needed to prove that a new flow would actually reduce both fraud and order mix-ups, increasing the operation's reliability. The priority was validating behavior before investing in implementation.

04

Start with the lowest risk

We chose to start with restaurant-arrival validation, a flow with lower potential impact on the Contact Rate. The learnings from this first step became the foundation for designing order-pickup validation.

05

Learn before scaling

The first test ran in January 2022, during the lunch rush, at two McDonald's restaurants chosen for opposite operational profiles: the busiest location in the network and a shopping-mall unit. There the question was about behavior, not metrics: couriers understood the flow, did not see it as an extra step, and recognized the value of preventing another courier from taking the order.

06

Let the microtimes prove the hypothesis

The second test, at seven locations, answered one specific question: what happens to the DRE (heading to the restaurant) and NRE (at the restaurant) microtimes once arrival is validated? Contact Rate jumped from about 5% to 12% at activation and soon stabilized — a learning curve, not rejection. And NRE nearly halved (from 5.7 to 2.8 minutes at the most critical location) while DRE rose, confirming the fake check-in and revealing the operation's real microtimes.

07

Address every risk before scaling

The tests exposed operational risks, and each one became a change in the flow. A damaged camera auto-cancelled and reallocated the order, with support unable to fix the status: we allowed the status to change automatically via ticket, validating location through the geofence. Restaurants that did not rotate the code or kept the QR out of sight slowed the operation: we created a guide explaining the benefits of keeping it visible and up to date. And large chains with multiple identifiers per store got one defined main ID.

08

Scale in waves

With the risks addressed, the rollout moved in waves: activation across all McDonald's locations over one month, followed by expansion to the remaining key-account (KA) locations. Only then, with check-in consolidated and the lessons absorbed, did we move to the journey's second flow: validating order pickup at checkout.

Interactive prototype

The end-to-end happy path: arrive at the restaurant, scan the QR code on the wall to check in, and finish with the receipt code at checkout.

Check-in user flow (MVP)

I designed the flow to validate the courier's arrival at the restaurant: a main path in three steps and alternative routes to handle exceptions, prioritizing a trust-based approach before applying any penalty.

Courier arrivesat the restaurantScans the QR codeon the wallValidcode?Check-inconfirmedRight store'scode?Automatic check-inafter a few minutesTells us whathappenedTalk tosupportyesnoyesno

Design decisions

Decisions scoped for the MVP: validate the solution's value with the smallest possible investment before evolving into a more robust version.

  1. 01

    QR code on the wall, not in the app

    To validate physical presence at the restaurant, the courier scans a QR code fixed on-site. The solution keeps technological complexity to the bare minimum: a simple, cheap, and scalable interaction for a problem spanning millions of deliveries.

  2. 02

    Rotating QR codes

    To prevent a photo of the code from being reused later, each restaurant has multiple QR codes that rotate by date. This makes fake check-in attempts harder without adding friction for the courier.

  3. 03

    A code on the receipt, not another QR

    The check-in taught us that phone-camera quality and condition made QR scanning unreliable. So checkout used an alphanumeric code printed on the receipt itself: the employee shares it, the courier types it, and validation releases the order — no camera required.

  4. 04

    Errors handled with trust

    Not every error signals a fraud attempt. An outdated code at the right store can be auto-validated after a few minutes, while invalid attempts get multiple chances before any penalty. The flow assumes good faith until there are real signs of abuse.

Results

Faster prep time

McDonald's saw a 7-point drop in prep time already in the pilot

Hypothesis confirmed

NRE dropped and DRE rose, proving out the false check-in and unlocking real microtimes

R$260 million

In monthly orders protected against checkout fraud

Checkout user flow (MVP)

Checkout demanded more control than check-in: losses happen precisely where courier and order meet, whether through bad faith or plain mistake. Here validation moves from the wall to the receipt: the restaurant employee shares a four-character alphanumeric code, the courier types it to confirm they have the right order, and the employee validates — with the same tolerance for error before any block.

Courier arrivesat the restaurantStaff shares thealphanumeric codeValidcode?Picks up the orderand deliversAttemptsleft?Tries againTalk tosupportyesnoyesno

The best design does not always live on a screen. In Handshake, the interface was a QR code on the restaurant wall and the impact was measured in the right order reaching the right hands.

Next project

Atelier: when a Design System stops being a library and becomes infrastructure