Seatext library / BotRefund evidence
How to Use BotRefund to Associate Sessions With Ad Attribution
To associate sessions with ad attribution using BotRefund, install the BotRefund tracking script on your website to capture platform-specific click IDs (such as Meta click IDs or Google GCLIDs) alongside every visitor's behavioral data....
✓ Built for advertisers who need clear, refund-ready traffic evidence.
To use BotRefund to associate sessions with ad attribution, install the BotRefund tracking script on your website to capture platform-specific click identifiers (such as Meta click IDs or Google GCLIDs) alongside every visitor's behavioral data. This links each on-site session directly to the exact ad campaign, ad set, and creative that drove the visit, so you can tie suspicious bot activity to specific paid traffic sources for refund claims.
Once attribution data is captured, BotRefund cross-references session behavior (like unnatural form completion speed, zero scrolling, or robotic mouse movements) with the associated ad metadata to build a clear, session-by-session evidence trail. This trail is formatted to meet Google and Meta's requirements for invalid traffic refund requests, so you can prove which paid clicks were non-human without losing context of where those clicks came from.
Why Session Attribution Matters for Ad Refunds
Ad platforms like Google and Meta only issue refunds for invalid traffic when you can show exactly which clicks were fraudulent. A generic traffic report is not enough. You need click IDs, campaign names, timestamps, and behavioral proof tied to each session. Without session-level attribution, you cannot map a bot visit back to the specific ad that brought it. That means you cannot file a precise claim, and the platform will likely deny it. BotRefund solves this by capturing attribution at the moment the visitor lands, then layering 110-plus behavioral, browser, hardware, and network checks on top of that same session record.
How BotRefund Captures Attribution Data
The BotRefund script reads URL parameters added by ad platforms when auto-tagging is enabled. For Google Ads, that is the GCLID. For Meta, it is the fbclid or other click ID. If auto-tagging is off, the script falls back to UTM parameters you place on your ad links. It stores the campaign name, ad set, creative, placement, and timestamp alongside the click ID. This happens client-side in the browser, so the data reflects what the visitor actually experienced, not just what the server logged. The script also records the full session replay, including mouse movements, scroll depth, form interactions, and timing between events. All of this stays linked to the original attribution metadata.
Prerequisites Before You Start
Before you can associate sessions with attribution in BotRefund, you need three things in place: an active Google Ads or Meta Ads account with auto-tagging enabled (or consistent UTM parameters applied to all ad links), administrative access to your website's codebase to install the BotRefund script, and a BotRefund account with your site registered. You do not need to replace your existing analytics, ad tracking, or edge security tools — BotRefund works alongside all of these without requiring a migration. The script is under 10 kilobytes and loads asynchronously, so it does not affect core web vitals or page speed for real visitors.
Step 1: Install the BotRefund Tracking Script
The first step is to add BotRefund's lightweight tracking script to your website's global header. This ensures the script loads on every page, including ad landing pages and conversion confirmation pages, so no session data is missed. To install:
- Log in to your BotRefund dashboard and navigate to the "Sites" section.
- Select your website and copy the unique site script provided.
- Paste the script into the
<head>section of your website's HTML, or add it via your tag manager if you use Google Tag Manager or a similar tool. - Publish the changes to your site.
The script automatically captures platform click IDs (GCLIDs for Google, Meta click IDs for Facebook/Instagram) from URL parameters or auto-tagging, no extra configuration required. It also begins running 110-plus independent checks on every session, including biometric and behavioral signals like scrollbar width leaks, clean context iframe mismatches, ghost click detection, honeypot trap interactions, robotic linear mouse movements, absence of humanlike mouse tremor, superhuman input speed under one millisecond, grid-aligned movement patterns, absence of clicks or scrolling, and unnatural session durations.
Step 2: Verify Attribution Data Is Capturing Correctly
After installing the script, run a quick test to confirm attribution is working as expected:
- Click on one of your live Google or Meta ads to visit your landing page.
- Open the BotRefund dashboard and find your test session in the live session log.
- Confirm that the session shows the correct campaign name, ad set, creative, and click ID attached to the visit.
- If you have a conversion action (like a form submit), complete that action and confirm the conversion event is linked to the same attribution data in the dashboard.
A common mistake here is forgetting to add the BotRefund script to conversion confirmation pages, which leads to conversion events being untied to the original ad click. Double-check that the script loads on all pages where you track conversions. The dashboard shows a live feed of sessions with their attribution tags, so you can verify in real time.
Step 3: Review Flagged Sessions Tied to Paid Attribution
BotRefund automatically runs 110-plus behavioral, browser, hardware, and network checks on every session. When a session is flagged as high-confidence bot traffic, it retains the full attribution context linked to the original ad click. You can use the dashboard's filter tools to view flagged sessions by campaign, ad set, creative, placement, device, or geographic region to identify patterns of invalid traffic, such as a spike in bot form submissions from a single ad creative. The system reaches 99 percent confidence when cross-referencing all signals, and each finding includes a session-by-session explanation instead of a generic invalid-traffic estimate.
Step 4: Generate Refund-Ready Reports for Ad Platforms
When you're ready to file an invalid traffic refund claim with Google or Meta, BotRefund compiles all flagged sessions linked to your campaigns into a formatted report that includes click IDs, campaign details, timestamps, session recordings, and a signal-by-signal breakdown of why each session was flagged as bot traffic. These reports are structured to match the format Google and Meta's review teams require, so you can submit them directly with your claim to improve your chances of approval. Across 2,500-plus brands audited, 83 percent of clients recover funds from Google and Meta. The high approval rate comes from three things: 99 percent bot-detection confidence, reports built in a format platform teams can review, and deep experience negotiating successful claims.
Understanding BotRefund's Detection Signals
BotRefund does not rely on a single signal. It combines over 100 independent checks across five categories: biometric and behavioral interactions, evasion and anti-stealth traps, browser and device consistency, network context, and navigation flow. For example, the Scrollbar Width Leak check looks for a mismatch that a real browsing session does not normally create. The Clean Context Iframe check detects when automation tools patch or hide browser APIs. Ghost click detection catches click activity that happens without the natural sequence of human intent. Honeypot trap interactions watch for bots that respond to hidden or intentionally deceptive page elements. Robotic linear mouse movements flag unnaturally straight pointer paths. Absence of humanlike mouse tremor looks for the tiny imperfections and jitter typical of human movement. Superhuman input speed identifies interactions faster than a person could realistically perform. Grid-aligned movement patterns detect movement that snaps to precise lines or blocks instead of natural curves. Absence of clicks or scrolling highlights sessions that stay too static to match a real browsing journey. Unnatural session durations catch visit lengths that are too short, too long, or too uniform to be human. A single anomaly is not a bot verdict. Privacy tools, travel, corporate networks, and unusual devices can produce unexpected behavior for genuine people. BotRefund keeps each signal as evidence — not a verdict — and cross-checks it against independent browser, network, device, and behavior data. The AI prediction model weighs the complete pattern instead of trusting a raw rule.
Practical Scenarios: When to Use Session Attribution
Session attribution is most valuable in three scenarios. First, when you see a steady cost per lead in Ads Manager but your sales team receives unreachable contacts, copied messages, or enquiries that never progress. This gap between reported leads and actual outcomes often signals bot traffic or form spam. Second, when you suspect competitor click fraud draining your budget. Bots can click ads repeatedly to exhaust daily spend, especially on high-CPC keywords. Third, when you need to protect your Meta Pixel or Google Ads conversion tracking from pixel poisoning. Invalid conversions train the platform's optimization algorithms on bad data, raising acquisition costs and lowering ROAS. In each case, BotRefund's session-level attribution lets you isolate the exact campaigns, creatives, and placements driving invalid traffic, so you can pause them, adjust targeting, or file refund claims with evidence.
Decision Criteria: Is BotRefund Right for Your Setup?
Consider BotRefund if you run paid campaigns on Google or Meta and want to recover wasted spend. It fits teams that already have auto-tagging or UTMs in place and can add a script to their site. It does not require replacing Cloudflare, your WAF, or your analytics stack — it adds a marketing-focused evidence layer on top. If your main need is DDoS mitigation or edge firewall rules, compare infrastructure alternatives instead. If your need is proving invalid paid traffic and getting refunds, BotRefund's 50-plus detection vectors, 99 percent confidence threshold, and refund-ready report format are built for that job. The FinTrust case study shows a neobank recovering $140,000 with a 14 percent bot click rate and an 18 percent conversion rate increase after suppressing automated browser emulation signals.
Key Facts About BotRefund Session Attribution
| Feature | Detail |
|---|---|
| Supported ad platforms | Google Ads, Meta (Facebook/Instagram) ads |
| Attribution data captured | Click IDs (GCLIDs, Meta click IDs), campaign name, ad set, creative, placement, timestamp |
| Bot detection confidence | 99% when cross-referencing 110+ behavioral, browser, hardware, and network signals |
| Refund success rate | 83% of clients recover funds from Google and Meta across 2,500+ audited brands |
| Report format | Matches Google and Meta's required format for invalid traffic claims, includes session recordings and signal reasoning |
| Compatibility | Works alongside existing analytics tools (Google Analytics, Meta Pixel) and edge protection (like Cloudflare) without migration |
| Data retention | 12 months by default, aligning with most ad platform refund claim windows |
| Script size | Under 10KB, loads asynchronously, no impact on core web vitals |
Limitations of Session Attribution With BotRefund
There are a few key limitations to keep in mind when using BotRefund for session attribution association:
- BotRefund only captures attribution data for sessions that occur after the script is installed. You cannot retroactively associate pre-installation sessions with ad attribution.
- If your ad platform's auto-tagging is disabled and you do not use consistent UTM parameters across all ads, click IDs may not pass to your site, leading to incomplete attribution data.
- BotRefund's default configuration collects evidence and flags bot sessions; real-time bot blocking is an optional add-on feature that must be enabled separately if you want to prevent invalid traffic from reaching your site in the first place.
- BotRefund does not guarantee refund approval, as final decisions on invalid traffic claims rest entirely with Google and Meta's review teams.
- Server-side bot audits that rely only on IP addresses, request headers, and user-agent data struggle to detect advanced botnets. BotRefund's client-side approach fills that gap but requires the script to load in the visitor's browser.
Frequently Asked Questions
- Do I need to change my existing ad tracking to use BotRefund's attribution association? No. BotRefund works alongside your existing Meta Pixel, Google Ads tags, and analytics tools without requiring you to modify or replace current tracking setups.
- Can BotRefund associate sessions with attribution for campaigns that use manual UTM parameters? Yes, as long as your UTM parameters include campaign, ad set, and creative identifiers, BotRefund will capture those values alongside click IDs to tie sessions to specific ads.
- How long does BotRefund retain session and attribution data? Session data, including attribution metadata and behavioral evidence, is retained for 12 months by default, which aligns with most ad platform refund claim windows.
- Will BotRefund's script affect my website's page load speed? No. The script is lightweight (under 10KB) and loads asynchronously, so it does not impact core web vitals or user experience for real visitors.
- Can I filter flagged bot sessions by specific ad placements or creatives? Yes. The BotRefund dashboard lets you filter flagged sessions by campaign, ad set, creative, placement, device, and geographic region to pinpoint exactly where invalid traffic is coming from.
- What is the difference between server-side and client-side bot audits? Server-side audits look at server log files, monitoring IP addresses, request headers, and user-agent data. They catch basic scraper bots but struggle with advanced botnets. Client-side audits analyze the visitor's browser behavior, capturing mouse movements, scroll patterns, timing, and rendering details that server logs cannot see.
- How does BotRefund help with Google Ads invalid activity credits? Google issues credits for invalid activity automatically in some cases, but many fraudulent clicks go undetected by their systems. BotRefund captures GCLIDs with behavioral evidence and generates audit-ready refund dispute reports formatted for Google's review process, increasing the chance of a successful manual claim.
- Can BotRefund prevent pixel poisoning on Meta? Yes. By suppressing conversion events for automated browser emulation signals, BotRefund ensures Meta's AI trains only on verified human conversions, protecting your pixel from learning from bot traffic.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.