Seatext library / BotRefund evidence
What Data Does BotRefund Collect? Complete Visitor Data Inventory
BotRefund collects IP address, user agent, browser fingerprint, mouse movements, click patterns, scroll behavior, session duration, referral source, and device characteristics from each visitor — but no personally identifiable information. This inventory explains what...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
BotRefund collects a focused set of technical and behavioral data points from each visitor: IP address, user agent, browser fingerprint, mouse movements, click patterns, scroll behavior, session duration, referral source, and device characteristics. None of these are personally identifiable information (PII). The entire dataset exists to answer one question: is this visitor human or automated?
Every signal is captured by a lightweight tracking script installed on the client's website. BotRefund then cross-checks each signal against independent browser, network, device, and behavior data, and feeds the complete pattern into an AI model that classifies the visit as human or bot. No single data point decides the verdict — the pattern as a whole does.
The complete data inventory
The table below lists every data point BotRefund captures, what it measures, and how it is generally classified under GDPR and CCPA. The legal tags are general context, not a BotRefund compliance guarantee.
| Data point | What it measures | GDPR / CCPA classification |
|---|---|---|
| IP address | Network origin of the visit | Personal data under GDPR; personal information under CCPA |
| User agent | Browser and operating system identification | Device identifier; may be personal data in context |
| Browser fingerprint | Unique browser configuration details | Device identifier; may be personal data in context |
| Mouse movements | Pointer path, tremor, speed, and curvature | Behavioral data; generally not personal data when anonymized |
| Click patterns | Click timing, sequence, and ghost-click detection | Behavioral data; generally not personal data when anonymized |
| Scroll behavior | Scrolling activity, depth, and pause patterns | Behavioral data; generally not personal data when anonymized |
| Session duration | Visit length and time-on-page patterns | Behavioral data; generally not personal data when anonymized |
| Referral source | UTM parameters and click IDs (GCLID, FBCLID) | Attribution data; may include platform identifiers |
| Device characteristics | Hardware, screen, and display properties | Device identifier; may be personal data in context |
The pattern to notice: network and device signals are collected, but they are not used to build a personal profile. They exist to detect automation patterns.
What each signal reveals about bot behavior
Every collected data point serves a specific detection purpose. Here is how each one works in practice.
Mouse movements
BotRefund flags unnaturally straight pointer paths that rarely appear in real user sessions. It also looks for the tiny imperfections and jitter typical of human movement. A robotic linear path with no tremor is a strong automation clue. The system also flags superhuman input speed — interactions that happen faster than a person could realistically perform, such as under 1 millisecond.
Click patterns
Ghost click detection catches click activity that happens without the natural sequence of human intent. A real user pauses, moves, then clicks. A bot can fire clicks without any preceding navigation or intent.
Scroll behavior
Real visitors scroll to read. They stop, they go back up, they slow down on interesting sections. BotRefund highlights sessions that stay too static to match a real browsing journey — no scrolling at all, or a uniform, mechanical scroll speed.
Session duration
Unnatural session durations are a reliable tell. BotRefund catches visit lengths that are too short, too long, or too uniform to be human. A session that always lasts exactly 42 seconds across hundreds of visits is not a coincidence.
Device characteristics
Device data includes hardware, screen, and display properties. Automated browsers often report unusual or inconsistent device configurations. A headless browser may claim a screen size that no real device has.
Browser and network signals
BotRefund cross-checks behavioral signals against independent browser, network, and device data. This includes the browser fingerprint, user agent, and network-level signals such as IP reputation and proxy detection.
Referral and attribution data
BotRefund reads UTM parameters and click IDs — such as GCLID and FBCLID — to reconstruct which affiliate ID and click ID drove each conversion. This is essential for catching attribution manipulation, like last-click hijacking or cookie stuffing.
How BotRefund combines signals into a verdict
BotRefund uses 106 independent checks to build a reliable picture of whether a visit is human or automated. Each check adds one objective fact about the visit. Then the system tests whether other signals support the same story.
This corroboration matters. A single anomaly is not a bot verdict. Privacy tools, travel, corporate networks, and unusual devices can produce unexpected behavior for genuine people. So BotRefund keeps each signal as evidence — not a verdict — and cross-checks it against independent browser, network, device, and behavior data.
Finally, the prediction AI weighs the complete pattern instead of trusting a raw rule. This is how BotRefund reaches 99% accuracy in classifying visits.
The privacy boundary: what is not collected
BotRefund does not collect personally identifiable information. No names, email addresses, phone numbers, or contact details are captured as part of the visitor profiling process.
This boundary has real consequences for compliance. Because the data is limited to technical and behavioral signals — and is not used to build a personal profile — the dataset sits in a lighter regulatory category than marketing data. That said, some collected items such as IP address are classified as personal data under GDPR on their own. The practical difference is purpose: the data is used for fraud detection, not for identifying or profiling a specific individual.
Why the data inventory matters for compliance
If you run a website that handles traffic from the EU or California, you need to know what your vendors collect. GDPR requires transparency about data processing. CCPA gives consumers the right to know what personal information is collected and why.
BotRefund's approach simplifies this. The data points are fixed and documented. There is no free-form collection of user content, no tracking of names or contact details, and no cross-referencing against external identity databases. This makes it easier to describe the processing in a privacy policy, a data processing agreement, or a record of processing activities.
It also means the data has a defined lifespan tied to its purpose. Once a session is classified as human or bot and the evidence is logged for a refund claim or affiliate decision, the data has served its function.
Key facts at a glance
| Fact | Detail |
|---|---|
| Independent checks per visit | 106 |
| Detection accuracy | 99% |
| Setup time | About one minute to add the script |
| Data categories | Behavioral signals, device data, browser and network data, attribution path |
| PII collected | None |
| Attribution data captured | UTM parameters and click IDs |
Limitations: when these data points are not enough
BotRefund's data collection is designed for bot detection, but it has boundaries you should understand.
First, privacy tools, travel, corporate networks, and unusual devices can produce unexpected behavior for genuine people. A visitor using a strict VPN or a corporate proxy may look anomalous. BotRefund handles this by cross-checking signals rather than trusting a single flag, but it does mean some legitimate users may be flagged for manual review.
Second, click-level behavioral data catches bots in the traffic, but it does not catch all fraud. BotRefund's affiliate protection page is explicit about this: the most expensive commissions come from real sessions where an affiliate manipulates the attribution path in the final seconds before conversion. Last-click hijacking, cookie stuffing, and coupon-extension overwrites do not show up as bot traffic. They look like legitimate conversions.
Third, not every bad lead is a bot. A weak campaign can attract real people who are not ready to buy. Bot traffic and form spam leave repeatable technical and behavioral patterns, but treating every unresponsive contact as fraud can cause you to exclude a valuable audience. BotRefund's data collection supports an audit workflow — it does not replace human judgment about lead quality.
Finally, the 99% accuracy figure reflects the full pattern analysis across all 106 checks. A smaller subset of signals is less reliable. If you are reviewing a single data point in isolation, treat it as a clue, not a conclusion.
FAQ
Does BotRefund collect names or email addresses?
No. BotRefund does not collect personally identifiable information. It collects technical and behavioral signals such as IP address, device characteristics, mouse movements, and click patterns.
Is an IP address considered personal data under GDPR?
Yes, an IP address is generally classified as personal data under GDPR. BotRefund collects it for fraud detection purposes but does not use it to build a personal profile or identify a specific individual.
How long does BotRefund keep visitor data?
The source materials do not specify a retention period. Contact BotRefund for their specific data retention policy if you need this for your privacy documentation.
Can BotRefund detect bots without collecting behavioral data?
No. Behavioral signals like mouse movement, click patterns, and scroll behavior are the core of the detection system. The AI model needs the complete pattern across browser, network, device, and behavior evidence to reach high accuracy.
Does BotRefund use cookies for detection?
The source materials describe a lightweight tracking script that captures behavioral and device signals. BotRefund's affiliate protection page also mentions tracking cookies in the context of cookie stuffing fraud — which is a fraud pattern BotRefund detects — not as part of its own data collection.
What is the difference between BotRefund's data and Google Analytics data?
Google Analytics collects similar raw data for audience insights and marketing measurement. BotRefund collects a narrower set of signals for a single purpose: distinguishing human visitors from bots. The data is used to build evidence for refund claims and commission decisions, not to profile audiences.
Can a VPN or corporate network cause a false bot flag?
Yes. Privacy tools, travel, corporate networks, and unusual devices can produce unexpected behavior for genuine people. BotRefund handles this by cross-checking signals — a single anomaly is not treated as a bot verdict.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.