Help · Bot Wars
Telling a person from a bot
“More human than human.”
A good bot looks more human than most people do: a believable name, a real address, a tidy checkout. So the app never judges how anybody looks. It asks what your store saw them do.
The bot check, fact by fact
The app treats somebody as a checkout bot when a checkout your Shopify store reported for them shows the signs of a bot, their consent and verified identity were not on record before it, they have never ordered from your Shopify store, they have no Shopify tags, your storefront has not seen them browsing, and nobody on your team has said otherwise.
All of these have to be true at once:
- A checkout with the signs of a bot. Your store’s own record of a checkout for them shows signs that a machine, not a person, made it. A checkout you imported from another tool, or one only your storefront’s tracking saw, never counts.
- New to you at that checkout. Their consent, by email or by text, and their verified identity were not already on record before that checkout. Somebody your store already knew is never held because of a checkout.
- No order. They have never placed an order in your Shopify store — including any order from before you installed the app, and any order you imported from another tool that came from your Shopify store. Anybody who has bought from your Shopify store is never a checkout bot. An imported order from anywhere else does not count.
- No Shopify tags. Not one tag from your store has reached their profile.
- Not seen browsing. Your storefront has not seen them browsing your store before a checkout. Being seen browsing lets them through.
- Not marked. Nobody on your team has chosen This is a person on their profile.
Ticking the box to get your email at the checkout itself changes nothing: a bot that ticked the box is still a bot.
More human than human: why the checkout gives a bot away
A person reaches your checkout by shopping. A bot skips the shopping and goes straight for the checkout, and that leaves marks in your store’s own record of how the checkout came about. The check reads those marks, and only those.

Each of the other facts proves nothing on its own. Plenty of real people have no tags, and plenty never order. It is all of them together, around a checkout a machine made, that the check looks for.
The signs we keep to ourselves
The signs of a bot come from real bot traffic hitting real stores, and we do not publish them. A bot that knew exactly what we look for could be built to avoid it, so the list stays private and keeps working for you.
What we do say is what is never a sign, below, and that every sign comes from your Shopify store’s own record of a checkout.
What is never a sign
Some things look odd and still never make anybody a bot:
- Your storefront not seeing them. Shoppers who decline a cookie banner, block tracking, or use a strict browser are never seen. That is most real shoppers in some stores, so not being seen never counts against anybody.
- Shopify’s own buy-now links. A buy-now link you made in Shopify and shared in an email, a post or an advert is how real shoppers often arrive. It is never a sign.
- A fast checkout. Browsers and Shopify fill in addresses for people in seconds. How quickly an address was filled in counts nowhere, ever.
Checkouts from before the app began keeping these details carry no signs at all. Nobody is held on one of those.
Why only facts from your store count
Every sign of a bot comes from your Shopify store’s own record of a checkout, never from anything typed into a form or sent from a browser. And a checkout only counts against somebody new to you: if their consent or their verified identity was on record before it, they are never held because of it.
So a stranger who types one of your customers’ addresses into a checkout cannot get that customer held. The one fact your storefront’s tracking adds, seeing somebody browse your store, can only ever count in a person’s favor.
There is no score behind any of this, and nothing judges how anybody looks. The facts in The bot check, fact by fact decide it, and nothing else does.
Verified identity and consent are separate questions
Whether somebody is a bot is a separate question from whether their identity is confirmed, and from whether they gave consent. A checkout bot usually has both: your store’s record of the checkout confirms the address, and ticking the box at checkout records consent. That is why the bot check exists on its own.
Verified identity means an address came from your store’s own records, or your store has since backed it up. A profile that reads Not confirmed yet, an address somebody typed that nothing from your store has backed up, is already never emailed and excluded from every count, bot or not. The Verified identity page explains both marks.
Consent is the person’s own answer about hearing from you. The bot check never changes it, in either direction: holding a bot back records nothing about consent, and letting a person through gives them none they did not give.
A real person can look like a bot
Rarely, a real person will match the check: somebody new to you whose way into your checkout happened to look like a machine’s, who has never ordered from your Shopify store, has no Shopify tags and was not seen browsing.
That is why the check only ever holds marketing back, and never deletes anybody on a guess. When you recognize somebody, choosing This is a person lets them through, and Letting a real person through explains it.