Help · Bot Wars

Telling a person from a bot

“More human than human.”

A good bot looks more human than most people do: a believable name, a real address, a tidy checkout. So the app never judges how anybody looks. It asks what your store saw them do.

The app treats somebody as a checkout bot when a checkout your Shopify store reported for them shows the signs of a bot, their consent and verified identity were not on record before it, they have never ordered from your Shopify store, they have no Shopify tags, your storefront has not seen them browsing, and nobody on your team has said otherwise.

All of these have to be true at once:

Ticking the box to get your email at the checkout itself changes nothing: a bot that ticked the box is still a bot.

A person reaches your checkout by shopping. A bot skips the shopping and goes straight for the checkout, and that leaves marks in your store’s own record of how the checkout came about. The check reads those marks, and only those.

Each of the other facts proves nothing on its own. Plenty of real people have no tags, and plenty never order. It is all of them together, around a checkout a machine made, that the check looks for.

The signs of a bot come from real bot traffic hitting real stores, and we do not publish them. A bot that knew exactly what we look for could be built to avoid it, so the list stays private and keeps working for you.

What we do say is what is never a sign, below, and that every sign comes from your Shopify store’s own record of a checkout.

Some things look odd and still never make anybody a bot:

Checkouts from before the app began keeping these details carry no signs at all. Nobody is held on one of those.

Every sign of a bot comes from your Shopify store’s own record of a checkout, never from anything typed into a form or sent from a browser. And a checkout only counts against somebody new to you: if their consent or their verified identity was on record before it, they are never held because of it.

So a stranger who types one of your customers’ addresses into a checkout cannot get that customer held. The one fact your storefront’s tracking adds, seeing somebody browse your store, can only ever count in a person’s favor.

There is no score behind any of this, and nothing judges how anybody looks. The facts in The bot check, fact by fact decide it, and nothing else does.

Whether somebody is a bot is a separate question from whether their identity is confirmed, and from whether they gave consent. A checkout bot usually has both: your store’s record of the checkout confirms the address, and ticking the box at checkout records consent. That is why the bot check exists on its own.

Verified identity means an address came from your store’s own records, or your store has since backed it up. A profile that reads Not confirmed yet, an address somebody typed that nothing from your store has backed up, is already never emailed and excluded from every count, bot or not. The Verified identity page explains both marks.

Consent is the person’s own answer about hearing from you. The bot check never changes it, in either direction: holding a bot back records nothing about consent, and letting a person through gives them none they did not give.

Rarely, a real person will match the check: somebody new to you whose way into your checkout happened to look like a machine’s, who has never ordered from your Shopify store, has no Shopify tags and was not seen browsing.

That is why the check only ever holds marketing back, and never deletes anybody on a guess. When you recognize somebody, choosing This is a person lets them through, and Letting a real person through explains it.