The dashboard said conversion was falling. Orders had not moved. If that is a sentence you have said out loud this quarter, the two numbers are not arguing about your business. They are arguing about the bottom half of a ratio — the session count — and about how much automated traffic is sitting inside it.
A conversion rate is one number divided by another. Grow the denominator without growing the numerator, and the rate falls, whether or not a single customer behaved differently. That is exactly what non-converting bot traffic does, and both platforms you look at — Shopify Analytics and Google Analytics 4 — now handle it, but by different rules.
Shopify now separates human and bot sessions
Shopify tracks every session on your store and labels it as coming from a human or a bot, based on all the events in that session. In reports that support it, there is a Human or bot session dimension and a matching filter, and Shopify states plainly what filtering bots out does to your numbers: higher conversion rates from removing non-converting bot sessions, lower total session counts, and more accurate campaign and product-page metrics.
The classifier is deliberately conservative. Shopify says it would rather miss some bots than label a real customer a bot. In its own example, a session with four bot events and two human events is still classified as human, because the overall session is judged on the whole pattern, not the majority event.
Two limits matter in practice. Bot filtering applies only to session-related metrics, so orders, sales and customers are untouched. And the classification is not retroactive: it applies only to sessions from 7 October 2025 onwards, so any comparison that reaches back before that date cannot be filtered the same way on both sides.
Then, between 21 and 23 September 2026, Shopify changed the default. When the session measurement update reached a store, identified bot sessions began to be filtered out of session-related reports by default, and a session began to be counted by continued customer activity instead of ending at midnight UTC; a session now ends after 30 minutes of inactivity. Shopify’s instruction for reading the change is as direct as it gets: use the post-update period as your new baseline, and if your session-based metrics moved while orders and sales did not, the measurement changed rather than your store.
GA4 was already excluding bots, quietly
GA4 does not wait for you to filter. Traffic from known bots and spiders is excluded automatically, identified through a combination of Google research and the International Spiders and Bots List maintained by the Interactive Advertising Bureau. And here is the part that matters for reconciliation: you cannot disable that exclusion, and you cannot see how much known-bot traffic was excluded.
So GA4’s session counts are already net of one class of bot — the known one. A sophisticated scraper that presents as a real browser is not on that list, and will be counted. GA4 gives you no dashboard for that; the only way to find it is to look at behaviour.
Your own team’s traffic is a separate problem with a separate tool. GA4 can identify internal traffic by IP address through the traffic_type parameter, then exclude it with a data filter. Note the word “filter”: once a GA4 data filter is active, its effect on the data is permanent — the excluded events are never processed and never appear in your reports or in BigQuery. Up to 10 data filters are allowed per property, and one can take 24 to 36 hours to apply.
Why your Shopify and GA4 conversion rates will never match exactly
Put the two together and the reason is obvious. Shopify removes bots using its own event-based classifier over the whole session. GA4 removes known bots from a published list and nothing else, then leaves the rest to you. There is no shared session definition, no shared bot list and no shared clock. The two systems are not measuring the same denominator, so their conversion rates are two platform-specific ratios, not one truth.
The numbers that do not move — orders, sales and customer counts — are the control. When a rate and a session count disagree with those, the rate and the session count are the ones under suspicion.
The check you can run today
Comparison table — scroll horizontally to see all columns
| What you are seeing | Most likely cause | Where to look |
|---|---|---|
| Conversion rate down, sessions up, orders flat | Non-converting bot sessions in the denominator | Shopify: set Human or bot session filter to Bot |
| Rate or sessions stepped around 21–23 Sep 2026 | Shopify session measurement update | Shopify’s update notice; reset to a post-update baseline |
| GA4 and Shopify rates far apart | Different bot filtering and session definitions | Compare both denominators; use orders as the control |
| Sessions from countries you do not sell to, near-zero engagement | Scrapers GA4 did not classify | GA4 Explore: zero-engagement, single-page, direct, by country |
| Your own visits and your agency’s visits show up | Internal traffic not filtered | GA4 internal traffic → data filter |
In Shopify, open Analytics > Reports, choose a sessions-based report, open Controls, and set the Human or bot session filter to Bot to see the bot share, to Human for the customer view, or add it as a dimension to compare both in one report. Shopify’s worked example starts at 1,000 sessions and 35 completed checkouts — a 3.5% headline rate — then splits into 750 human sessions at 4% and 250 bot sessions at 2%, which is the difference between a rate that describes customers and a rate that describes traffic.
In GA4, because the known bots are already gone, you are hunting the ones that were counted. Build an exploration of sessions with zero engagement time, a single page and a direct source, and look at the share by country. Channels or sources with engagement near zero and a session duration of a couple of seconds are the suspects. For your own traffic, define internal IPs first, test the data filter, and only then activate it — remembering that activation is permanent.
How I verify this in real implementations
On a headless Shopify rebuild for a US retailer, after delivery I went back and checked a claim before repeating it. Looking at the property’s sessions over twelve months, one country accounted for about 100,120 sessions — roughly a sixth of everything the property recorded — at six seconds and one page each, with zero sales and zero leads. It had been running since August 2025, and it had been quietly making the store’s conversion rate look worse than it was. I reported it to the client at no charge, and a “country with no sales” detector became a standing line in their daily dashboard.
The same engagement taught me why this check comes first. A figure I could have used to flatter the rebuild — a large drop in the share of direct traffic — turned out to sit on a baseline that contained a bot day. Because that made the number unsound, I refused to quote it, and the honest figures are the ones built on orders and refunds instead. A denominator you have not cleaned is a claim you cannot defend.
I have also done this on smaller reporting work as long as I have been in analytics: building GA views and filters whose whole purpose was to remove bot and internal traffic so the dashboard a client made decisions on was clean. In one early reporting engagement, replacing a paid reporting tool with a clean dashboard saved the client in excess of $800 a year.
“I was previously paying $70 per month for a reporting tool… This means in just 2 hrs work, [he] has saved me in excess of $800 per year.”
— Jeran M., Built to Convert
Common failure modes
- Reading the conversion rate as the customer conversion rate. It is a ratio that includes whatever automated traffic got through. Read the human-only number before drawing a conclusion.
- Assuming GA4 removed every bot. It removes known bots and stops. Scrapers that present as browsers are still in the denominator.
- Expecting to see what GA4 excluded. You cannot; the exclusion is invisible and cannot be disabled.
- Comparing across 21–23 September 2026 without resetting the baseline. That is a measurement change, not a performance change.
- Reaching back before 7 October 2025 for a filtered comparison. Bot classification does not apply to those sessions.
- Activating a GA4 data filter without testing it. Data filters are permanent, and a bad one removes real data you cannot recover.
- Pausing campaigns on a rate that bots moved. Check Shopify’s human split and orders before you change a budget.
Limitations
- Shopify’s classifier is conservative. Some bots are left in on purpose, so the human number is a better estimate, not a guarantee.
- Bot filtering touches only session-based metrics. Orders, sales and customer counts are never filtered, which is why they are the control.
- GA4’s known-bot exclusion is fixed. You cannot broaden it, measure it, or switch it off.
- Internal-traffic data filters are permanent and capped at 10 per property, with a 24–36 hour delay before they take effect.
- The two platforms will still disagree after you clean both. Different lists and different session logic are the reason, and forcing them to match would be fiction.
- This covers technical implementation, not legal or privacy advice.
When you don’t need this
If your orders, sessions and conversion rate move together, bot traffic is unlikely to be the story — the more probable problem is attribution, where the sale happened but no platform got the credit, which is a different fix. If you only want a straight answer about whether a rate is real, a single working session on one property settles it faster than any project. And if your store is small enough that a handful of sessions swings the rate anyway, the fix is a longer comparison window, not a bot project.
I can build this for you
This is the use case Tracking Breaks and Nobody Notices: Tracking Watch — Daily Reconciliation, Upload Alerts, Live Reports.
It starts with a free discussion: describe your task, and I will tell you whether bots are moving your number, or whether you are looking at a measurement change or an attribution problem — before anything is rebuilt.
Typical route: a Working Session (USD 195 / EUR 185) answers “is this rate real?” on one property; a read-only Tracking Health Check (USD 395 / EUR 375) turns it into a written verdict; and if you want the bot split and the reconciliation watched every day rather than checked once, that is Tracking Watch as a Technical Partnership at USD 1,000 / EUR 950 per month.
Describe your task.