Seatext library / BotRefund evidence

What documentation do you need to submit a successful bot click refund claim?

To get a bot click refund, you need an evidence package that connects each disputed click to technical signals, abnormal behavior, and a policy violation. That includes invalid-traffic reports, IP logs, device fingerprint data,...

Built for advertisers who need clear, refund-ready traffic evidence.

To submit a successful bot click refund claim, you need more than a suspicion. You need an evidence package that connects each disputed click to technical signals, abnormal behavior, and a policy violation. In practice, that means invalid-traffic reports, IP logs, device fingerprint data, timestamped click maps, and a short written explanation that shows the pattern.

Platforms do not hand out refunds because you ask politely. They respond to specific charges backed by specific evidence. The rest of this guide walks through the exact documentation you need and how to organize it into a claim that a Google or Meta reviewer can follow.

What counts as proof of a bot click?

Proof falls into three layers. The strongest claims use all three.

  • Platform records: invalid-activity reports, click IDs, and billing data from Google Ads or Meta.
  • Server-side logs: IP addresses, user agents, request headers, and timestamps from your hosting or analytics.
  • Client-side behavioral evidence: mouse movement, session length, scrolling, honeypot hits, and interaction speed collected in the browser.

Google itself defines invalid activity as clicks or impressions that are not the result of genuine user interest. Automated tools, repeated manual clicks, accidental taps, data-center IPs, and click fraud meant to exhaust your budget all fall into that category. But the platform catches only part of it. Client-side logs give you the extra signals that server logs miss.

The documentation checklist

Here is the exact set of documents and records you should assemble before you open a dispute.

  1. Invalid-traffic or invalid-activity report from the platform. Export this from Google Ads or Meta Ads Manager. It shows which clicks the platform already flagged and may have auto-credited.
  2. Click IDs. GCLID for Google Ads and FBCLID for Meta. These IDs let the platform locate the exact auction and match your evidence to a specific charge.
  3. IP logs with timestamps. For each disputed click, record the IP address, user agent, and the exact date and time the click landed on your site.
  4. Device fingerprint data. Collect browser and device identifiers, including operating system, browser version, screen size, and installed fonts. Bots often reuse the same fingerprint across thousands of clicks.
  5. Behavioral event logs. These are the client-side signals that prove a human did not perform the click: superhuman input speed (under 1 ms), grid-aligned pointer movement, absence of mouse tremor, no scrolling, and sessions that are too short or too uniform.
  6. Honeypot and trap interactions. If your website uses hidden fields or deceptive links, record any bot that interacted with them. That interaction is a direct sign of automation.
  7. A claim narrative and summary table. Write a short explanation that shows the pattern. Attach a spreadsheet with one row per click, arranged in chronological order, with all the raw data.

How to build a refund claim: step-by-step

Before you start, make sure you have three things: full access to the ad account where the clicks happened, a way to see raw click data (platform reports, server logs, or a client-side tracker), and a specific list of clicks to contest. Do not submit a broad complaint like 'traffic seems fake'.

  1. Pull the platform's invalid-traffic report. Google Ads shows invalid activity separately. Meta has a manual billing dispute system. Identify which clicks are already credited and which ones need a claim.
  2. Capture click IDs. For every click you plan to contest, record the GCLID or FBCLID. You can usually get these from your ad platform, analytics, or a client-side script.
  3. Gather server-side or client-side logs. Build a table that includes timestamp, IP address, user agent, device fingerprint, and page URL for each click.
  4. Add behavioral evidence. This is what separates a vague complaint from a documented case. Note the session length, mouse path, scrolling, dwell time, and any honeypot interactions.
  5. Create a timeline for each click. Line up the ad server timestamp with your logs. If they do not match, that misalignment becomes part of the evidence.
  6. Write a concise claim narrative. Explain which policy was violated, how many clicks were affected, and the total wasted spend. Keep it under one page. Then attach the data table.
  7. Submit through the platform's official process. For Google Ads, use the invalid activity credit request form. For Meta, use the billing dispute flow. Save a copy of the submission and note the case number.

Verification step: Before hitting submit, check that each disputed click has at least two independent signals. One suspicious IP is weak. A data-center IP plus superhuman input speed is strong. Also confirm every timestamp in your logs matches the platform's click timestamp.

What Google and Meta look for

Google's invalid activity system catches obvious patterns like rapid clicking, duplicate click signatures, known bad IPs, and abnormal click patterns. But it does not catch everything. BotRefund notes that Google offers credits for invalid activity only if you know how the system works, and that refunds happen almost exclusively when an advertiser contests specific charges with specific evidence.

Meta's manual dispute process is separate. Social ads are served passively, so bot networks can click them without search intent. Click farms, residential proxy botnets, and low-quality publisher placements are common sources. Meta expects you to show client-side behavioral evidence, not just server logs, because advanced bots hide inside normal residential IPs.

Key facts about bot click refunds

FactDetail
Typical bot share of paid clicksIndustry audits put automated traffic between 9% and 20% of paid clicks.
Refund success rate83% of refund claims filed by BotRefund are approved by ad platforms.
Detection confidenceBotRefund identifies non-human traffic with 99% confidence.
Recovery volumeOver $100 million in wasted ad spend has been recovered across client accounts.
Brands auditedMore than 2,500 brands have been audited, from fintech enterprises to DTC brands.
Setup effortOne script tag, installed in about one minute, with no ad-account access required.
Pricing model$0 upfront on enterprise recovery; fees come out of what is recovered.

Why refund claims get rejected

Most rejected claims have one or more of these problems:

  • No click IDs. A reviewer cannot find the charge you are disputing.
  • Only server logs. Advanced bots use residential proxies and look like normal users.
  • No behavioral signal. A timestamp and IP alone rarely prove automation.
  • Vague narrative. 'This traffic is bad' is not evidence.
  • Missing deadlines. Claims filed too late are automatically denied.
  • Broad complaints. Trying to contest an entire campaign instead of specific clicks.

Also understand the limits: not every invalid click is refundable. Platforms auto-credit some traffic and reject others. Small budgets may not justify the time it takes to prepare a case. And if your evidence is clean but the platform still says no, you can appeal, but there is no guarantee.

Terminology you will see in claim forms

  • Invalid activity: clicks or impressions that a platform decides are not from genuine user interest.
  • GCLID: Google Click ID, a unique identifier for a click on a Google Ads ad.
  • FBCLID: Facebook Click ID, the same type of identifier for a Meta ad click.
  • Ghost click: click activity that happens without the natural sequence of human intent.
  • Honeypot: a hidden page element that only bots see and interact with.
  • Device fingerprint: a set of browser and device attributes used to identify a specific machine.
  • Residential proxy: a real home internet address that makes a bot look like a normal user.

Frequently asked questions

Do I need legal documents or notarized proof?

No. Platforms want technical evidence and a clear narrative, not legal certification. A spreadsheet of timestamps, IPs, click IDs, and behavioral signals is more useful than a notarized statement.

What if I don't have a click fraud tool?

You can start with server logs and platform invalid-activity reports. You will likely miss advanced bots that live on residential proxies, because those look like normal users. A client-side behavioral tracker fills that gap.

Can I claim refunds for clicks from more than a year ago?

It depends on the platform and the claim channel. Google Ads has allowed refunds for spend dating back to 2017 in some BotRefund cases. Check current policy and your billing statements before building the claim.

How far back can I go with Meta refunds?

Meta's manual billing dispute system generally works on recent charges. Check Ads Manager for the exact dispute window because it can change.

Will filing a refund hurt my ad account?

No, but it can trigger a review of your account. Keep your evidence organized so the review goes in your favor.

What is the difference between an invalid activity credit and a manual refund?

An invalid activity credit is issued automatically by Google when its systems detect a problem. A manual refund is what you get when you file a dispute with evidence. Most advanced bot clicks require the manual route.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

How BotRefund can help

BotRefund helps you skip the hardest part of a refund claim: proving the clicks were non-human. The service installs as one script tag on your site in about a minute, with no ad-account access required. It then logs invalid traffic with 99% confidence, captures GCLIDs and FBCLIDs, and generates compliance-ready dispute reports. BotRefund uses behavioral signals like ghost clicks, honeypot traps, superhuman input speed, and VPN detection to build the evidence package. It negotiates directly with Google and Meta on your behalf, and it only charges a fee from the spend it recovers. GDPR-aligned data handling means you can use its logs in a dispute without exposing customer data.

Get my free bot audit