Seatext library / BotRefund evidence

What Data Does BotRefund Collect at Each Touchpoint for Attribution Analysis?

BotRefund collects click IDs, UTM parameters, affiliate IDs, device and behavioral signals, timestamps, referrer data, and hashed identifiers at every touchpoint from click to conversion. It uses this data to reconstruct the full attribution...

Built for advertisers who need clear, refund-ready traffic evidence.

BotRefund tracks a specific set of data points at each stage of a user's journey from an affiliate click through to conversion. In short, it collects the click ID, timestamp, referrer, UTM parameters, device fingerprint, hashed IP, affiliate ID, offer ID, creative ID, and custom parameters. All of this is hashed or encrypted at rest, so raw personal data is never stored in a readable form.

These data points are not collected in one single event. BotRefund installs a lightweight tracking script on your site that monitors every session from first click to final conversion, building a complete attribution path. This article explains exactly what is captured, why each field matters, and where the limitations are.

What Exactly Does BotRefund Collect?

The core data set covers both identity and behavior. Here is the full list you should expect to see in your payout reports:

  • Click ID – a unique identifier for each ad click (e.g., GCLID, FBCLID) that links back to the specific ad and placement.
  • Timestamp – the exact date and time of the click and of the conversion, used to calculate click-to-conversion timing.
  • Referrer – the page or site that sent the user, helping to confirm whether the click came from an expected source.
  • UTM parameters – campaign, source, medium, content, and term values that define the marketing context of the click.
  • Device fingerprint – a set of browser and hardware signals that create a stable, pseudo-identifier for the device.
  • Hashed IP – an anonymized version of the IP address used to check for unusual patterns without storing the raw address.
  • Affiliate ID – the identifier of the affiliate claimed credit for the conversion, reconstructed directly from the UTM data.
  • Offer ID – the specific offer or product page that the user interacted with.
  • Creative ID – the exact ad creative the user originally engaged with.
  • Custom parameters – any additional tracking fields you or your affiliate network append to the click URL.

These data points are collected via a JavaScript snippet placed on your site. The script runs from the moment of arrival and captures events like page views, clicks, scrolls, and form submissions, all tied to the click ID.

The Touchpoints: Where Each Data Point Is Captured

Attribution analysis is not a single moment. It is a sequence of events. Here is how BotRefund splits the journey:

1. Click Event (The Entry Point)

When a user clicks an affiliate or ad link, the click ID, timestamp, UTM parameters, referrer, and hashed IP are recorded. The device fingerprint is also captured at this instant. This is the anchor for all future data.

2. Landing Page Load

As soon as the page loads, BotRefund's script fires. It reads the UTM parameters and click ID from the URL and stores them in the session. It also records the loading time and any related performance data, which can later help spot unusual behavior.

3. User Interaction (Behavioral Tracking)

Every meaningful action on the page is logged: mouse movements, scroll depth, time on page, click patterns, and any form field interactions. These behavioral signals are the core of BotRefund's fraud detection. For example, ghost clicks, grid-aligned pointer paths, and superhuman speed are all captured as raw data.

4. Conversion Event

When a user completes a purchase, signup, or other conversion, the script records the timestamp and pairs it with the original click ID. It also captures the affiliate ID and offer ID at that moment, as well as any conversion-specific custom parameters.

5. Payout Reconciliation

Before payout, BotRefund cross-references the captured data with your payout CSV or affiliate platform. It matches each conversion to the correct affiliate ID and click ID, then assigns a score: approve, review, hold, or reject.

How BotRefund Uses This Data for Attribution Path Analysis

The main purpose of collecting all this data is to reconstruct the full attribution path and detect manipulation. BotRefund looks for patterns like:

  • Last-click hijacking – an affiliate drops a cookie just before conversion to steal credit from the true driver.
  • Cookie stuffing – hidden images or iframes place tracking cookies without the user's knowledge.
  • Coupon extension overwrites – browser extensions inject affiliate cookies at the moment of purchase.

None of these look like bot traffic. They involve real human sessions. Only by examining the full path can you see that the commission was claimed unfairly. BotRefund analyzes the sequence of events, the timing between clicks, and the consistency of device and behavioral data to flag anomalies.

Key Facts at a Glance

Data PointPurposeHow It Is Collected
Click IDLinks ad click to conversionFrom URL parameters (e.g., GCLID, FBCLID)
UTM parametersIdentify campaign, source, mediumFrom the click URL
Affiliate IDAssign commission creditReconstructed from UTM data
Device fingerprintIdentify device consistencyBrowser and hardware signals
Hashed IPDetect network patternsIP address hashed at capture
Behavioral signalsDistinguish human from botJavaScript event tracking
TimestampMeasure click-to-conversion timingRecorded at each event
ReferrerConfirm source legitimacyHTTP referrer header

Source: BotRefund affiliate protection page.

Limitations and Privacy Considerations

No tracking system is perfect, and BotRefund is transparent about its limitations. A single behavioral anomaly is not a bot verdict; it is only evidence. As the company explains, “Privacy tools, travel, corporate networks, and unusual devices can produce unexpected behavior for genuine people.” This means data must be cross-checked across multiple independent signals before making a decision.

Another limitation is that the script runs client-side. If a user has JavaScript disabled or uses a privacy-focused browser that blocks third-party scripts, some data will not be captured. Similarly, if an affiliate uses a server-side redirect that strips UTM parameters, the attribution path may be incomplete. BotRefund works with the data it can see—it cannot fill gaps that are never sent to the server.

Data security is also a constraint. Because raw IP addresses and full device fingerprints are sensitive, BotRefund hashes or encrypts them at rest. This protects user privacy but also means that some geolocation or device analysis cannot be done in real time; it happens after hashing, which can reduce accuracy for certain edge cases.

Common Misconceptions About Attribution Data

One common mistake is thinking that more data always means better attribution. But if the data is not structured, it can create false positives. For example, a user on a corporate network might have a shared IP address, which could trigger a false “bot” signal if you only look at IP. That is why BotRefund cross-checks each signal against others.

Another misconception is that attribution data is only needed at the conversion moment. In reality, the entire path matters. The click that happened 30 minutes before a conversion is just as important as the final redirect. Without the full path, you cannot detect last-click hijacking.

Finally, many people think that attribution data is only used for fraud detection. Actually, it is also used for payout reconciliation and dispute resolution. When you hold a commission, you need evidence that holds up. BotRefund provides this evidence, not just a score.

Frequently Asked Questions

Does BotRefund store raw IP addresses?

No. Raw IP addresses are hashed immediately after capture, so you never see the full address in reports. This protects user privacy and helps you stay compliant with data protection laws like GDPR.

Can I use BotRefund without an affiliate platform integration?

Yes. BotRefund can start by reading UTM and click IDs from your traffic alone. For exact payout reconciliation, you can upload a payout CSV or connect your platform later.

What happens if UTM parameters are missing from a click?

If UTM parameters are stripped, BotRefund cannot reconstruct the affiliate ID from that click. In that case, the conversion may be flagged as “review” rather than “approve” until you verify it manually.

How long does it take to set up the tracking script?

BotRefund claims you can add the script to your website in about one minute. No credit card is required to start a free audit, which runs on a live call.

Does BotRefund work for both Google and Meta ads?

Yes. BotRefund logs click IDs from both GCLID (Google) and FBCLID (Meta) and uses them for attribution and refund dispute reports.

How to Get Started

If you want to see what BotRefund can do with your own data, the next step is a free audit. You add the script to your site, and BotRefund runs a live analysis during a scheduled call. After that, you will receive a report that scores every affiliate conversion and provides evidence for any holds or rejections.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

How BotRefund Can Help You Control Attribution Data

BotRefund gives you visibility into every step of a user's journey from click to conversion, not just the final event. With its lightweight tracking script, you get behavioral signals, device data, and full attribution paths. You can then reconstruct affiliate IDs and click IDs directly from UTM data, so you do not need a platform integration to start auditing.

However, BotRefund's accuracy depends on the data being available. If UTM parameters are stripped or JavaScript is blocked, the attribution path will be incomplete, and some conversions may be flagged for manual review rather than automatically approved. This is why BotRefund cross-checks multiple signals and treats any single anomaly as evidence, not a verdict.

Start free audit