Guide
Hands typing on a laptop with an e-commerce website open, showcasing online shopping.
Photo: Shoper .pl

Your Shopify traffic jumps, your conversion rate falls, and a paid app suddenly says you have used up your monthly views. Yet orders have barely changed. Before upgrading the app or rebuilding your store, separate three questions: what is reaching your storefront, what Shopify includes in its reports, and what the app counts toward its allowance. Suspicious traffic can affect each differently. Cleaning up an analytics report does not automatically restore an app’s quota, and a traffic spike alone does not prove that every extra visitor is a bot.

A traffic spike is a clue, not a diagnosis

Start with the time the increase began. Record the affected dates, landing pages, referrers, countries, and devices, then compare them with orders and revenue for the same period. Look for concentrated bursts, repeated visits to a small group of pages, or a sharp increase without corresponding customer activity. Shopify lists unusual sessions, customer behavior, and analytics anomalies as potential signs of automation. These observations justify investigating; they do not identify the operator or prove a security breach.

A country label is not enough to classify a visitor. VPNs, proxies, and data-center routing can complicate location data, while legitimate campaigns can also bring unfamiliar traffic. Check whether a promotion, app installation, theme change, or tracking adjustment happened at the same time. Preserve screenshots and exports before changing settings. Evidence from a consistent date range is more useful to support teams than a broad statement that the store is full of bots.

Separate customer performance from report noise

Open Analytics > Reports and choose a session-related report that supports the Human or bot session controls. Use the Human filter to review recognized customer activity, or add the dimension to compare the classifications. Keep the same date range and filter when comparing periods. Shopify’s classification is conservative, so some automated sessions can remain in the human group. A filtered report is a better starting point for investigation, not a guarantee that every remaining visit is a person.

Consider a simplified example: 1,000 human sessions with 20 sessions completing checkout produce a 2% conversion rate. Add 3,000 non-converting automated sessions and the combined rate falls to 0.5%, even though those 20 customer conversions have not changed. These are hypothetical figures. Avoid cutting a campaign or redesigning a product page based only on a diluted percentage; review orders, revenue, and the quality of customer sessions together.

Check whether Shopify changed the measurement

Shopify documents a session-measurement rollout from September 21 to 23, 2026. Identified bot sessions are excluded from session-related reports by default after the update, while unrecognized bots can still be counted. Session grouping also changes, which can move session totals and conversion rates without changing total orders or sales. If your comparison crosses this rollout, treat it as a measurement change and establish a baseline after the update.

This does not explain every traffic surge, and it cannot explain an incident that predates the rollout. It is a reason to check the dates before concluding that store performance changed. The Home page and Live View do not offer the adjustable human-or-bot filter available in supported reports. Different analytics tools can also use different counting rules, so compare equivalent metrics rather than expecting every dashboard to match.

Ask the app developer what a billable view means

The paid app’s allowance is a separate investigation. A view could mean a page load, a widget impression, a session, or another event defined by the developer. Ask for the exact definition, the allowance’s reset date, whether repeat events count, and how recognized automated traffic is handled. Also ask whether the app relies on Shopify Analytics or its own tracking. Do not assume that changing a Shopify report filter changes the app’s usage meter.

Send the developer the date range, usage screenshots, affected pages, and the matching Shopify report. Ask whether they can review the events, exclude demonstrably invalid usage, or offer a credit. That is a request for investigation, not an entitlement to a refund. Shopify directs merchants to the app developer for third-party app refund requests. An upgrade prompt does not establish that an overage has already been charged; check the app plan and Settings > Billing to distinguish an exhausted allowance from an actual pending or paid charge.

Control costs while you investigate

Before accepting a higher plan, confirm what happens when the allowance runs out: does the app pause its feature, require an upgrade, or continue under an approved usage-charge arrangement? Shopify supports spending limits for some usage-billed apps, but that is different from a fixed plan’s included-view quota. Where a spending limit is available, inspect the existing approval before raising it. If the app bills outside Shopify, review its own subscription controls as well.

If the app is nonessential, consider pausing or removing it while support investigates, after checking what functionality and data you would lose. Uninstalling stops future Shopify app billing cycles but may leave a charge that has already been generated; externally billed subscriptions require cancellation with the developer. Estimate the feature’s business value from legitimate use. Paying more can be sensible when real customers need the service, but an unexplained usage spike is a reason to verify the meter first.

Reduce the impact without promising a universal block

Shopify already uses Cloudflare protection for storefront requests. Its hCaptcha protection helps with spam on forms and customer account pages, while additional checkout bot protection is a Shopify Plus feature. Those controls address particular kinds of activity; they do not establish how a third-party app bills views. Avoid treating a country block, another app, or a platform migration as a guaranteed cure, and preserve useful access for customers and legitimate crawlers.

For the next few days, keep a simple record of human-classified sessions, completed orders, revenue, and the app’s usage counter over matching time windows. If the app counter rises sharply while customer activity stays steady, give the developer that comparison and ask for an explanation. If customer activity also changes, investigate that alongside the suspicious traffic. The goal is a trustworthy view of store performance and a clear account of what you are paying for before making the next spending decision.

A.
Back to articles