The service could send a special "auth" key along as parameter when forwarding. E.g.: http://example.com/secret.php?key=dh498
In secret.php on your server you could then ask the Gumroad API (via another http request) how often this key was already used and deny or allow access. This would be super easy to implement for the seller - just paste in ~5 lines of PHP code.