Seatext library / BotRefund evidence

How to Use BotRefund to Protect Conversion Signals

BotRefund protects conversion signals by installing client-side tracking that captures 110+ behavioral, browser, hardware, network, and attribution signals per session. It suppresses bot-driven conversion events before they reach Meta and Google pixels, preserves click...

Built for advertisers who need clear, refund-ready traffic evidence.

BotRefund protects conversion signals by placing a lightweight script on your landing pages that observes every visitor session after a paid click. The script evaluates 110+ independent signals — pointer movement, scroll behavior, input timing, browser consistency, network context, and attribution identifiers — and scores each session with up to 99% confidence. When a session crosses the bot threshold, BotRefund can suppress the conversion event so it never fires to Meta Pixel or Google Ads tags, keeping your optimization data clean. At the same time, it captures the click ID, timestamp, campaign hierarchy, and a full session recording, then packages that evidence into a report structure that Google and Meta reviewers already expect.

To start, you add the BotRefund snippet to every page that receives paid traffic, connect your ad accounts so the system can match sessions to click IDs, and choose which conversion events to guard (lead forms, purchases, sign-ups, custom events). The dashboard then shows flagged sessions side-by-side with your CRM outcomes, letting you verify that suppressed events match the contacts your sales team cannot reach. Once the evidence pile is large enough, you submit the refund-ready report through the platform's invalid-activity flow or let BotRefund's team negotiate on your behalf — their 2,500+ audits yield an 83% recovery rate.

What conversion signals are at risk

Conversion signals are the events you tell ad platforms to optimize for: form submissions, button clicks, page views tagged as leads, purchase completions, or any custom event fired from your pixel or tag manager. When bots trigger these events, three things happen at once. First, you pay for clicks that cannot become customers. Second, the platform's bidding model learns to chase the same low-quality placements, audiences, and creatives that produced the fake conversions. Third, your CRM fills with unreachable contacts — disconnected numbers, invalid email domains, repeated addresses — wasting sales time and distorting downstream metrics like cost per qualified opportunity.

Meta campaigns are especially exposed because they serve across Facebook, Instagram, and partner inventory at high volume. A lead campaign can receive accidental taps, low-intent traffic, automated browsing, and deliberate fraud from affiliate payouts or publisher scripts. Google Ads faces similar pressure from data-center IPs, VPNs, click farms, and impression-refresh bots. In both cases, the platform's built-in filters catch only a fraction; the rest poisons your pixel and inflates reported performance.

How BotRefund identifies invalid traffic

BotRefund does not rely on IP blocklists or user-agent strings alone. Instead, it runs 106+ client-side checks inside the visitor's browser, each producing an independent piece of evidence. Examples include the Scrollbar Width Leak (detecting mismatches between reported and actual scrollbar dimensions), Clean Context Iframe (spotting patched or hidden browser APIs that automation tools leave behind), ghost-click detection (clicks without the natural human intent sequence), honeypot-trap interactions (bots responding to hidden page elements), robotic linear mouse movements, superhuman input speed under 1 millisecond, grid-aligned movement patterns, absence of human-like mouse tremor, and unnatural session durations.

No single check decides the verdict. Each signal feeds an AI prediction model that weighs the complete pattern across browser, network, device, and behavior dimensions. Privacy tools, corporate networks, travel, and unusual devices can create anomalies for real people, so BotRefund treats every signal as evidence — not a verdict — and cross-checks it against the full context. The outcome is a session-level classification with up to 99% confidence, plus a plain-language explanation of which signals fired and why they matter.

Step-by-step implementation

  1. Add the BotRefund snippet to every paid landing page. Place it in the <head> so it loads before your pixel and tag-manager events. The script is asynchronous and does not block page rendering.
  2. Connect Meta and Google ad accounts in the BotRefund dashboard. This lets the system match each session to its click ID (fbclid, gclid, wbraid, gbraid), campaign, ad set, creative, and placement.
  3. Select the conversion events to protect. Choose from standard events (Lead, Purchase, CompleteRegistration, Contact) or map custom events from your tag manager. BotRefund will intercept the event fire, evaluate the session in real time, and only allow the event through if the session passes the human threshold.
  4. Set suppression rules. Decide whether to block the event entirely, send a "null" conversion value, or flag it for review. Most teams start with a shadow mode — logging flagged sessions without suppressing — to verify accuracy against CRM outcomes.
  5. Run a shadow-period audit (7–14 days). Compare BotRefund's flagged sessions against your CRM contactability data: disconnected phones, bounced emails, no-show rates, and sales-team feedback. This validates the model before you let it modify live conversion signals.
  6. Enable live suppression. Once the shadow audit confirms alignment, switch to active mode. BotRefund now prevents bot sessions from firing conversion pixels in real time.
  7. Export refund-ready reports monthly or quarterly. Each report includes click IDs, campaign details, timestamps, session recordings, and signal-by-signal reasoning formatted for Google and Meta invalid-activity review teams.

Protecting Meta conversion signals

Meta's pixel fires on every matched event, and its delivery system optimizes toward the events it sees. If bot leads fire the Lead event, Meta learns to serve more impressions to the placements, audiences, and creatives that produced those leads. BotRefund stops this by evaluating the session before the Lead event reaches the pixel. The script captures the fbclid, matches it to the campaign hierarchy, and runs the 110+ signal checks. If the session is classified as automated, the Lead event is suppressed; the pixel never receives it. Your reported lead count drops, but the remaining leads are contactable — sales teams at FinTrust saw an 18% conversion-rate increase after suppression began.

BotRefund also preserves attribution for the suppressed events. The click ID, timestamp, placement, and device data stay in the audit log, so you can still analyze which campaigns attracted the invalid traffic and adjust targeting without losing the forensic trail. This matters because Meta's invalid-traffic review expects click-level evidence, not aggregate estimates.

Protecting Google Ads conversion signals

Google Ads uses GCLIDs (and newer GBRAID/WBRAID parameters) to tie conversions back to clicks. BotRefund captures these identifiers on landing-page arrival, then monitors the full session. When a conversion event fires — whether from a form submit, button click, or enhanced conversion — BotRefund checks the session score. Automated sessions are blocked from sending the conversion to Google's tag. The result: your conversion column reflects only human actions, Smart Bidding trains on real outcomes, and you avoid the "conversion lag" that occurs when Google's automated filters retroactively remove invalid conversions days later.

Google's invalid-activity credit system reimburses advertisers for clicks it determines are not genuine user interest — repeated manual clicks, automated tools, accidental mobile taps, data-center IPs, impression fraud, and competitor click fraud. However, Google's detection is server-side and misses client-side automation that mimics human behavior. BotRefund's client-side evidence (session recordings, behavioral signals, click IDs) fills that gap. The platform accepts refund claims backed by this evidence format; BotRefund's team has negotiated 2,500+ such claims with an 83% approval rate.

Verification and ongoing monitoring

After live suppression is on, treat the BotRefund dashboard as a quality-control layer, not a set-and-forget filter. Weekly, review the flagged-session list against three CRM signals: contactability rate (calls connected / leads received), qualification rate (SQLs / leads), and sales-cycle velocity. If contactability improves but qualification drops, you may be suppressing borderline sessions — adjust the confidence threshold. If a new campaign shows a sudden spike in flagged sessions, check placement-level breakdowns; audience expansion or new creative formats often attract different bot profiles.

Quarterly, export the refund-ready report and submit it through Google's invalid-activity form or Meta's ad-quality appeal flow. Include the session recordings and signal breakdowns; platform reviewers prioritize claims with click-level, session-level evidence. BotRefund's team can handle the submission and follow-up if you prefer not to manage the negotiation directly.

Key facts

CapabilityDetailSource
Signal coverage110+ behavioral, browser, hardware, network, and attribution signals per sessionS2
Detection confidenceUp to 99% confidence when session evidence supports itS2, S3, S5
Conversion suppressionReal-time interception of Meta Pixel and Google Ads conversion events for flagged sessionsS7, S8
Evidence capturedClick IDs (fbclid, gclid, gbraid, wbraid), campaign hierarchy, timestamps, session recordings, signal-by-signal reasoningS2, S6
Report formatRefund-ready reports structured for Google and Meta review teamsS2, S6
Recovery rate83% of clients recover funds across 2,500+ auditsS2
Case-study resultFinTrust recovered $140,000 (14% of ad spend) and increased conversion rate 18%S8
Pixel protectionPrevents pixel poisoning by blocking bot conversion events before they fireS4, S6

Limitations and when this does not apply

BotRefund protects conversion signals on pages you control. It cannot suppress events that fire server-side (e.g., offline conversion imports, CRM-to-platform APIs) unless you route those through a client-side gate. It does not replace server-side fraud infrastructure — DDoS mitigation, WAF rules, or edge bot management — and works alongside them. The 99% confidence figure applies when the full signal cluster supports it; edge cases (privacy browsers, corporate proxies, unusual devices) may produce lower-confidence sessions that require manual review. Refund approval is ultimately decided by Google and Meta; BotRefund provides evidence and negotiation support, not a guarantee. The 83% recovery rate reflects historical audits, not a promise for every account.

FAQ

How long does the shadow audit take before I can trust live suppression?

Most teams run 7–14 days. Compare BotRefund's flagged sessions against your CRM contactability and qualification data. When the flagged set matches the contacts your sales team cannot reach, you have validation.

Does BotRefund slow down my landing pages?

The snippet loads asynchronously and adds negligible weight. It does not block rendering or interfere with Core Web Vitals.

Can I protect only some conversion events and not others?

Yes. You choose which events to guard in the dashboard — standard events (Lead, Purchase, etc.) or custom events from your tag manager.

What if a real user gets flagged as a bot?

The model treats every signal as evidence, not a verdict, and cross-checks 106+ independent checks. False positives are rare, but the shadow period lets you catch them before live suppression. You can also whitelist known IP ranges or user segments.

Do I need to submit refund claims myself?

You can. BotRefund generates the report in the format Google and Meta expect. Their team can also submit and negotiate on your behalf — they've handled 2,500+ claims.

How does this differ from Cloudflare or other edge bot protection?

Edge tools block traffic before it reaches your server. BotRefund observes the visitor journey after the click, preserves attribution, protects conversion pixels, and builds refund evidence. Many advertisers run both: edge for infrastructure protection, BotRefund for ad-quality evidence.

What happens to the click IDs for suppressed conversions?

They are retained in the audit log with full session context. You can still analyze which campaigns, placements, and creatives attracted invalid traffic without polluting your optimization signals.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more